Information is protected, whatever the means of connection, through security measures and the management procedures that go with them: only authorised devices, set up to require a password, may reach corporate information and the network; network filtering such as firewalls and intrusion detection enforces policy on traffic coming in and going out; approved security protocols are applied to connections; network equipment is configured securely; information is encrypted in transit according to its classification; a connectivity security policy is based on risk assessment and business requirements; trusted mechanisms support sending and receiving securely; and periodic penetration testing and system security testing establish whether network and system protection is adequate.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.