PR.DS-02: The confidentiality, integrity, and availability of data-in-transit are protected
Threats Addressed:
Previous Version:
- NIST Cybersecurity Framework v1.1:
- PR.DS-2: Data-in-transit is protected
Incorporates the following subcategorys from the previous version of the framework: PR.DS-2: Data-in-transit is protected, PR.DS-5: Protections against data leaks are implemented.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
Ex1: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of network communications
Ex2: Automatically encrypt or block outbound emails and other communications that contain sensitive data, depending on the data classification
Ex3: Block access to personal email, file sharing, file storage services, and other personal communications applications and services from organizational systems and networks
Ex4: Prevent reuse of sensitive data from production environments (e.g., customer records) in development, testing, and other non-production environments
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
AU-16: Cross-organizational Audit Logging
Employ [Assignment: organization-defined methods] for coordinating [Assignment: organization-defined audit information] among external organizations when audit information is transmitted across organizational boundaries.
CA-3: Information Exchange
Approve and manage the exchange of information between the system and other systems using [Assignment (one or more): interconnection security agreements, information exchange security agreements, memoranda of understanding or agreement, service level agreements, user agreements, non-disclosure agreements, [Assignment: organization-defined type of agreement] ]; Document, as part of each exchange agreement, the interface characteristics, security and…
SC-4: Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
SC-7: Boundary Protection
Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; Implement subnetworks for publicly accessible system components that are [Assignment: physically, logically] separated from internal organizational networks; and Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged…
SC-8: Transmission Confidentiality and Integrity
Protect the [Assignment (one or more): confidentiality, integrity] of transmitted information.
SC-11: Trusted Path
Provide a [Assignment: physically, logically] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the user and the following security functions of the system, including at a minimum, authentication and re-authentication: [Assignment: organization-defined security functions].
SC-12: Cryptographic Key Establishment and Management
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements].
SC-13: Cryptographic Protection
Determine the [Assignment: organization-defined cryptographic uses] ; and Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography].
SC-16: Transmission of Security and Privacy Attributes
Associate [Assignment: organization-defined security and privacy attributes] with information exchanged between systems and between system components.
SC-40: Wireless Link Protection
Protect external and internal [Assignment: organization-defined wireless links] from the following signal parameter attacks: [Assignment: organization-defined types of signal parameter attacks or references to sources for such attacks].
SC-43: Usage Restrictions
Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined components] ; and Authorize, monitor, and control the use of such components within the system.
SI-3: Malicious Code Protection
Implement [Assignment (one or more): signature-based, non-signature-based] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code; Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures; Configure malicious code protection mechanisms to: Perform periodic scans of the system…
SI-4: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives] ; and Unauthorized local, network, and remote connections; Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; Invoke internal monitoring capabilities or deploy monitoring devices:…
SI-7: Software, Firmware, and Information Integrity
Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Assignment: organization-defined software, firmware, and information] ; and Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Assignment: organization-defined actions].
NIST SP 800-171 Revision 3.0
03.12.05: Information Exchange
Approve and manage the exchange of CUI between the system and other systems using [Selection (one or more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements; other types of agreements]. Document interface characteristics, security requirements, and responsibilities for each system as part of the exchange…
03.13.01: Boundary Protection
Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. Connect to external systems only through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational…
03.13.04: Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
03.13.06: Network Communications — Deny by Default — Allow by Exception
Deny network communications traffic by default, and allow network communications traffic by exception.
03.13.08: Transmission and Storage Confidentiality
Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI during transmission and while in storage.
03.13.10: Cryptographic Key Establishment and Management
Establish and manage cryptographic keys in the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].
03.13.11: Cryptographic Protection
Implement the following types of cryptography to protect the confidentiality of CUI: [Assignment: organization-defined types of cryptography].
03.14.02: Malicious Code Protection
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures. Configure malicious code protection mechanisms to: Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from…
03.14.06: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.
Cloud Controls Matrix v4.0
CEK-03: Data Encryption
Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.
CEK-04: Encryption Algorithm
Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.
CEK-19: Key Compromise
Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.
DCS-02: Off-Site Transfer Authorization Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable authorization. Review and update the policies and procedures at least annually.
DSP-10: Sensitive Data Transfer
Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.
DSP-17: Sensitive Data Protection
Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.
HRS-04: Remote and Home Working Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
IPY-03: Secure Interoperability and Portability Management
Implement cryptographically secure and standardized network protocols for the management, import and export of data.
IVS-03: Network Security
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating controls.
IVS-07: Migration to Cloud Environments
Use secure and encrypted communication channels when migrating servers, services, applications, or data to cloud environments. Such channels must include only up-to-date and approved protocols.
LOG-02: Audit Logs Protection
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
LOG-09: Log Protection
The information system protects audit records from unauthorized access, modification, and deletion.
UEM-05: Endpoint Management
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-11: Data Loss Prevention
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.
Critical Security Controls Version 8.1
3.10: Encrypt Sensitive Data in Transit
Encrypt sensitive data in transit. Example implementations can include: Transport Layer Security (TLS) and Open Secure Shell (OpenSSH).