AC-17(2): Protection of Confidentiality and Integrity Using Encryption
Control Family:
Parent Control:
CSF v2.0 References:
Threats Addressed:
Baselines:
- Moderate
- High
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- AC-17(2): Protection Of Confidentiality / Integrity Using Encryption
Control Statement
Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
Supplemental Guidance
Virtual private networks can be used to protect the confidentiality and integrity of remote access sessions. Transport Layer Security (TLS) is an example of a cryptographic protocol that provides end-to-end communications security over networks and is used for Internet communications and online transactions.
OT Discussion
Encryption-based technologies should be used to support the confidentiality and integrity of remote access sessions. While OT devices often lack the ability to support modern encryption, additional devices (e.g., VPNs) can be added to support these features. This control should not be confused with SC-8 – Transmission Confidentiality and Integrity, which discusses confidentiality and integrity requirements for general communications, including between OT devices.