# SC-16 Transmission of Security and Privacy Attributes

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Associate [Assignment: organization-defined security and privacy attributes] with information exchanged between systems and between system components.
Guidance: Security and privacy attributes can be explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes are abstractions that represent the basic properties or characteristics of an entity with respect to protecting information or the management of personally identifiable information. Attributes are typically associated with internal data structures, including records, buffers, and files within the system. Security and privacy attributes are used to implement access control and information flow control policies; reflect special dissemination, management, or distribution instructions, including permitted uses of personally identifiable information; or support other aspects of the information security and privacy policies. Privacy attributes may be used independently or in conjunction with security attributes.

## Enhancements (3)
- SC-16(01) Integrity Verification
- SC-16(02) Anti-spoofing Mechanisms
- SC-16(03) Cryptographic Binding
Each enhancement's statement: /api/v1/controls/SC-16?fields=enhancements

## Clauses by framework (19 frameworks)
- nist_csf_2: PR.DS-02
- anssi: Hygiene.24, RGS.2.2, SecNumCloud.14.2
- osfi_b13: B-13.3.2
- finma_circular: IV.C(63)
- gdpr: Art.32(1)(a)
- dora: Art.9(3)
- fisc: FISC.T12
- hkma_tme1: TME1.9.3
- dnb_good_practice: DNB.2.2, DNB.18.5
- cra: CRA.I.2f
- qatar_nia: CS
- sa_js2: JS2-6.1
- bcbs_239: Principle 3, Principle 7
- cpmi_pfmi: PFMI.P22
- ffiec_is: II.C.5
- iosco_cyber: PROT-3
- common_criteria: CC Part 2 — FDP
- hitrust_csf: 07.b
- lloyds_ms: BP2.2, MS6.1
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-16
- Clauses only: /api/v1/controls/SC-16?fields=mappings
- Page for people: /controls/sc-16/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
