Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.DS-02 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-02: The confidentiality, integrity, and availability of data-in-transit are protected The confidentiality, integrity, and availability of data-in-transit are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 137 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-18(1) Authentication and Encryption AU-9 Protection of Audit Information IA-5(2) Public Key-Based Authentication MP-5 Media Transport SC-13 Cryptographic Protection SC-23 Session Authenticity SC-28(1) Cryptographic Protection SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection SI-4(4) Inbound and Outbound Communications Traffic AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-18(1) Authentication and Encryption AU-9 Protection of Audit Information IA-5(2) Public Key-Based Authentication MP-5 Media Transport SC-13 Cryptographic Protection SC-23 Session Authenticity SC-28(1) Cryptographic Protection SC-7(4) External Telecommunications Services SC-7(8) Route Traffic to Authenticated Proxy Servers SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection SI-4(4) Inbound and Outbound Communications Traffic 1.2.6 1.2.6 Security features for insecure services in use 1.4.5 1.4.5 Internal IP and routing disclosure limited 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 2.2.7 2.2.7 Non-console administrative access encrypted 2.3.2 2.3.2 Wireless encryption keys changed on triggers 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 4.2.2 4.2.2 PAN secured when sent by end-user messaging 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 9.4.3 9.4.3 Securing media sent outside the facility NIST800-AC-4 AC-4 Information Flow Enforcement NIST800-PE-4 PE-4 Access Control for Transmission NIST800-PM-17 PM-17 Protecting Controlled Unclassified Information on External Systems NIST800-SC-13 SC-13 Cryptographic Protection NIST800-SC-40 SC-40 Wireless Link Protection NIST800-SC-8 SC-8 Transmission Confidentiality and Integrity NIST800-SI-7 SI-7 Software, Firmware, and Information Integrity SP800-53-SC System and Communications Protection Family CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-13.5 Manage Access Control for Remote Assets CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.13 Deploy a Data Loss Prevention Solution CIS-4.6 Securely Manage Enterprise Assets and Software 5.14 Information transfer 6.7 Remote working 8.12 Data leakage prevention 8.20 Networks security 8.21 Security of network services 8.24 Use of cryptography 8.33 Test information 5.14 Information transfer 6.7 Remote working 8.12 Data leakage prevention 8.20 Networks security 8.21 Security of network services 8.24 Use of cryptography 6.10 Communications security 6.10.2 Information transfer 6.7.1 Cryptographic controls 7.4.9 PII transmission controls 7.5 PII sharing, transfer, and disclosure 8.4.3 PII transmission controls ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet ANSSI-HYG-21 Use Secure Protocols Wherever They Exist ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working ASD37-14 Block spoofed emails (Very Good) ASD37-17 TLS encryption between email servers (Limited) ASD37-27 Outbound data loss prevention (Very Good) ISM-0465 Evaluated encryption for sensitive data in transit ISM-0469 Encrypting data in transit ISM-1781 Encrypting all data over network infrastructure ASBv3-DP-7 Use a secure certificate management process ASBv3-NS-9 Connect on-premises or cloud network privately DP-3 Encrypt sensitive data in transit 03.13.08 Transmission Confidentiality and Integrity 03.13.10 Cryptographic Key Establishment and Management 03.13.11 Cryptographic Protection SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal 4(c)(ii) Sec. 4(c)(ii) Enable encrypted DNS wherever clients and servers support it 4(d)(i) Sec. 4(d)(i) Enforce encrypted, authenticated transport between email clients and servers 4(e)(i) Sec. 4(e)(i) Enable transport encryption by default for voice, video and messaging ADMF-5.2 Apply technical, procedural and physical safeguards ADMF-5.3 Protect data across the data lifecycle BE-CF-08 Cryptographic protection of data BE-CF-10 Transmission confidentiality and integrity C5-COS-08 Policies for data transmission C5-CRY-02 Encryption of data for transmission (transport encryption) Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications PR.DS-2 PR.DS-2: Data-in-transit is protected PR.DS-5 PR.DS-5: Protections against data leaks are implemented PR.DS-2 PR.DS-2: Data-in-transit is protected PR.DS-5 PR.DS-5: Protections against data leaks are implemented AUCDR-IS-2 Secure the network and systems within the data environment MYHR-CUD-4 Records not held or taken outside Australia 161R1-SC-8 Transmission Confidentiality and Integrity 3.1.3e Employ Secure Information Transfer Solutions Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 137 it maps to, and the evidence behind each claim, over MCP and REST.