03.13.08: Transmission and Storage Confidentiality
Control Family:
Threats Addressed:
Previous Version:
- NIST Special Publication 800-171 Revision 2:
- 3.13.8: Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
Incorporates the following controls from the previous version of the control set: 3.1.13: Employ cryptographic mechanisms to protect the confidentiality of remote access sessions, 3.8.6: Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards, 3.13.16: Protect the confidentiality of CUI at rest.
Requirements
- Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI during transmission and while in storage.
Discussion
This requirement applies to internal and external networks and any system components that can transmit CUI, including servers, notebook computers, desktop computers, mobile devices, printers, copiers, scanners, facsimile machines, and radios. Unprotected communication paths are susceptible to interception and modification. Encryption protects CUI from unauthorized disclosure during transmission and while in storage. Cryptographic mechanisms that protect the confidentiality of CUI during transmission include TLS and IPsec. Information in storage (i.e., information at rest) refers to the state of CUI when it is not in process or in transit and resides on internal or external storage devices, storage area network devices, and databases. Protecting CUI in storage does not focus on the type of storage device or the frequency of access to that device but rather on the state of the information. This requirement relates to 03.13.11.