SC-08 Transmission Confidentiality and Integrity
System and Communications Protection
Description
Protect the [Selection (one or more): confidentiality; integrity] of transmitted information.
Supplemental Guidance
Protecting the confidentiality and integrity of transmitted information applies to internal and external networks as well as any system components that can transmit information, including servers, notebook computers, desktop computers, mobile devices, printers, copiers, scanners, facsimile machines, and radios. Unprotected communication paths are exposed to the possibility of interception and modification. Protecting the confidentiality and integrity of information can be accomplished by physical or logical means. Physical protection can be achieved by using protected distribution systems. A protected distribution system is a wireline or fiber-optics telecommunications system that includes terminals and adequate electromagnetic, acoustical, electrical, and physical controls to permit its use for the unencrypted transmission of classified information. Logical protection can be achieved by employing encryption techniques. Organizations that rely on commercial providers who offer transmission services as commodity services rather than as fully dedicated services may find it difficult to obtain the necessary assurances regarding the implementation of needed controls for transmission confidentiality and integrity. In such situations, organizations determine what types of confidentiality or integrity services are available in standard, commercial telecommunications service packages. If it is not feasible to obtain the necessary controls and assurances of control effectiveness through appropriate contracting vehicles, organizations can implement appropriate compensating controls.
Enhancements (5)
What NIST adds to this control. Select one to read its statement.
SC-08(01) Cryptographic Protection ModerateHigh
Implement cryptographic mechanisms to [Selection (one or more): prevent unauthorized disclosure of information; detect changes to information] during transmission.
SC-08(02) Pre- and Post-transmission Handling
Maintain the [Selection (one or more): confidentiality; integrity] of information during preparation for transmission and during reception.
SC-08(03) Cryptographic Protection for Message Externals
Implement cryptographic mechanisms to protect message externals unless otherwise protected by [Assignment: organization-defined alternative physical controls].
SC-08(04) Conceal or Randomize Communications
Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by [Assignment: organization-defined alternative physical controls].
SC-08(05) Protected Distribution System
Implement [Assignment: organization-defined protected distribution system] to [Selection (one or more): prevent unauthorized disclosure of information; detect changes to information] during transmission.
Patterns that use this control (24)
Grouped by the emphasis each pattern gives it.
Critical (10)
- SP-005 SOA Internal Service Usage Pattern
- SP-006 Wireless- Private Network Pattern
- SP-007 Wireless- Public Hotspot Pattern
- SP-015 Secure Remote Working
- SP-029 Zero Trust Architecture
- SP-030 API Security
- SP-032 Modern Authentication
- SP-040 Post-Quantum Cryptography and Quantum Readiness
- SP-050 Mobile Security Architecture (draft)
- SP-054 CBDC and Digital Currency Infrastructure (draft)
Important (12)
- SP-008 Public Web Server Pattern
- SP-011 Cloud Computing Pattern
- SP-013 Data Security Pattern
- SP-017 Secure Network Zone Module
- SP-022 Board of Directors Room
- SP-033 Passkey Authentication
- SP-039 Client-Side Encryption and Data Privacy
- SP-042 Third Party Risk Management
- SP-047 Secure Agentic AI Frameworks
- SP-051 Tokenised Asset Security Architecture (draft)
- SP-052 Decentralised Identity & Verifiable Credentials (draft)
- SP-053 Zero-Knowledge Proof Architecture (draft)
MITRE ATT&CK Techniques (20)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.