Frameworks / ASD Strategies to Mitigate Cyber Security Incidents / ASD37-17 ASD Strategies to Mitigate Cyber Security Incidents
Preventing Malware Delivery and Execution
ASD Strategies to Mitigate Cyber Security Incidents ASD37-17: TLS encryption between email servers (Limited) TLS encryption between email servers to protect the confidentiality of emails in transit between organisations.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 237 controls across 144 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism PQC-5 Cryptographic Inventory and PQC Migration Roadmap PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements QRCM-1.2 Quantum-Vulnerable Identification QRCM-3.1 Hybrid Solution Deployment (2025-2030) QRCM-4.2 TLS 1.3 Adoption AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection C5-COS-08 Policies for data transmission C5-CRY-02 Encryption of data for transmission (transport encryption) CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-3.10 Encrypt Sensitive Data in Transit CJIS-8 Media Protection CJIS-9 System and Communications Protection SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection 5.14 Information transfer 8.24 Use of cryptography 5.14 Information transfer 8.24 Use of cryptography ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-2 Information Security Program (ISP) - Section 4 NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NDPA-1 Applicability, Scope, and Carve-Outs NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-7 Cross-Border Data Transfers and International Cooperation 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.2 4.2.2 PAN secured when sent by end-user messaging PTESPHASE-2 Intelligence Gathering (OSINT) PTESPHASE-3 Threat Modeling CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management US-ITAR-EAR-DS-01 Technical Data Protection US-ITAR-EAR-DS-02 Cloud and Storage APPI-A34 Request for Correction, Addition or Deletion DP-3 Encrypt sensitive data in transit BSI-08 Cryptographic protection of data BE-CF-08 Cryptographic protection of data LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour Part11.30 Controls for open systems (21 CFR §11.30) FFIEC-09 Encryption and key management FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines GhCSA-Service-Provider-Licensing-Professional Cybersecurity Service Provider Licensing and Professional Accreditation HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation MT-CDPA-Universal-Opt-Out-Mechanism-1-January-2025-GPC-Global-Privacy-Control-Mandatory-Recognition Montana CDPA Universal Opt-Out Mechanism + 1 January 2025 + GPC + Global Privacy Control + Mandatory Recognition STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition 161R1-SC-8 Transmission Confidentiality and Integrity 03.13.08 Transmission Confidentiality and Integrity NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NHPA-6 Reasonable Data Security and Breach Response NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-3 API Security Standards, mTLS, and Encryption ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-2 SCA Exemptions and Risk-Based Authentication NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SHAREASSESS-3 Network Security, Endpoint, Data Protection SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal SOC-CY-C2 Encryption and Data Protection SA-PDPL-13 Encryption of personal data IM8-CLD.2 Cloud Security Controls ISMSP-SYS-02 Encryption Implementation TAIWAN-2 Consent, Notice, Sensitive Data TEXASTDPSA-2 Consumer Rights TURKEYKVKK-2 Information Notice and Data Subject Rights URUGUAY-3 Sensitive Data, Health Data, Children VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-2 Consumer Rights Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Preventing Malware Delivery and Execution You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done? ASD Strategies to Mitigate Cyber Security Incidents ASD37-17 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 237 it maps to, and the evidence behind each claim, over MCP and REST.