← Controls / SC

SC-16 Transmission of Security and Privacy Attributes

System and Communications Protection

Description

Associate [Assignment: organization-defined security and privacy attributes] with information exchanged between systems and between system components.

Supplemental Guidance

Security and privacy attributes can be explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes are abstractions that represent the basic properties or characteristics of an entity with respect to protecting information or the management of personally identifiable information. Attributes are typically associated with internal data structures, including records, buffers, and files within the system. Security and privacy attributes are used to implement access control and information flow control policies; reflect special dissemination, management, or distribution instructions, including permitted uses of personally identifiable information; or support other aspects of the information security and privacy policies. Privacy attributes may be used independently or in conjunction with security attributes.

Changes from Rev 4

Title changed from 'Transmission of Security Attributes' Parameter adds 'and privacy'  Discussion expanded to provide detailed explanation of attributes

Enhancements (3)

What NIST adds to this control. Select one to read its statement.

SC-16(01) Integrity Verification

Verify the integrity of transmitted security and privacy attributes.

SC-16(02) Anti-spoofing Mechanisms

Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.

SC-16(03) Cryptographic Binding

Implement [Assignment: organization-defined mechanisms or techniques] to bind security and privacy attributes to transmitted information.

MITRE ATT&CK Techniques (5)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Persistence 2 Command & Control 3

Compliance Mappings

NIST CSF 2.0

PR.DS-02

ANSSI

Hygiene.24RGS.2.2SecNumCloud.14.2

FINMA Circular 2023/1

IV.C(63)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(a)

EU DORA

Art.9(3)

FISC Security Guidelines

FISC.T12

HKMA TM-E-1

TME1.9.3

DNB Good Practice

DNB.2.2DNB.18.5

EU CRA

CRA.I.2f

Qatar NIA

CS

SA JS2

JS2-6.1

IOSCO Cyber Resilience

PROT-3

BCBS 239

Principle 3Principle 7

CPMI-IOSCO PFMI

PFMI.P22

FFIEC IS

II.C.5

Common Criteria

CC Part 2 — FDP

Lloyd's Minimum Standards

BP2.2MS6.1

HITRUST CSF v11

07.b

ISO 17799 (legacy)

7.2.210.8.210.9.2

COBIT 4.1 (legacy)

DS5.11