SC-8: Transmission Confidentiality And Integrity
Control Family:
PF v1.0 References:
Threats Addressed:
Next Version:
- NIST Special Publication 800-53 Revision 5:
- SC-8: Transmission Confidentiality and Integrity
Control Statement
The information system protects the [Selection (one or more): confidentiality; integrity] of transmitted information.
Supplemental Guidance
This control applies to both internal and external networks and all types of information system components from which information can be transmitted (e.g., servers, mobile devices, notebook computers, printers, copiers, scanners, facsimile machines). Communication paths outside the physical protection of a controlled boundary are exposed to the possibility of interception and modification. Protecting the confidentiality and/or integrity of organizational information can be accomplished by physical means (e.g., by employing protected distribution systems) or by logical means (e.g., employing encryption techniques). Organizations relying on commercial providers offering transmission services as commodity services rather than as fully dedicated services (i.e., services which can be highly specialized to individual customer needs), may find it difficult to obtain the necessary assurances regarding the implementation of needed security controls for transmission confidentiality/integrity. In such situations, organizations determine what types of confidentiality/integrity services are available in standard, commercial telecommunication service packages. If it is infeasible or impractical to obtain the necessary security controls and assurances of control effectiveness through appropriate contracting vehicles, organizations implement appropriate compensating security controls or explicitly accept the additional risk.
Control Enhancements
SC-8(1): Cryptographic Or Alternate Physical Protection
Baseline(s):
- Moderate
- High
The information system implements cryptographic mechanisms to [Selection (one or more): prevent unauthorized disclosure of information; detect changes to information] during transmission unless otherwise protected by [Assignment: organization-defined alternative physical safeguards].
SC-8(2): Pre / Post Transmission Handling
Baseline(s):
The information system maintains the [Selection (one or more): confidentiality; integrity] of information during preparation for transmission and during reception.
SC-8(3): Cryptographic Protection For Message Externals
Baseline(s):
The information system implements cryptographic mechanisms to protect message externals unless otherwise protected by [Assignment: organization-defined alternative physical safeguards].
SC-8(4): Conceal / Randomize Communications
Baseline(s):
The information system implements cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by [Assignment: organization-defined alternative physical safeguards].