Frameworks / NIST SP 800-53 Rev 5 / NIST800-SC-13 NIST SP 800-53 Rev 5
SC - System and Communications Protection
NIST SP 800-53 Rev 5 NIST800-SC-13: SC-13 Cryptographic Protection a. Determine the [Assignment: organization-defined cryptographic uses]; and b. Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography for each specified cryptographic use].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 231 controls across 102 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 1.2.6 Security features for insecure services in use 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 10.1.2 10.1.2 Roles for logging and monitoring assigned and understood 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 3.5.1 3.5.1 Stored PAN rendered unreadable 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes 3.6.1.1 3.6.1.1 Service provider cryptographic architecture documented 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse 3.7.1 3.7.1 Generation of strong cryptographic keys AC-17(2) Protection of Confidentiality and Integrity Using Encryption CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-2(8) Access to Accounts Replay Resistant SC-13 Cryptographic Protection SC-28(1) Cryptographic Protection SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection AC-17(2) Protection of Confidentiality and Integrity Using Encryption CP-9(8) System Backup | Cryptographic Protection (CP-9(8)) IA-2(8) Access to Accounts Replay Resistant SC-13 Cryptographic Protection SC-28(1) Cryptographic Protection SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection CIS-11.3 Protect Recovery Data CIS-16.11 Leverage Vetted Modules or Services for Application Security Components CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.11 Encrypt Sensitive Data at Rest CIS-3.6 Encrypt Data on End-User Devices CIS-3.9 Encrypt Data on Removable Media CNSA2-CMVP FIPS 140-3 Validated Modules (CMVP) CNSA2-HASH Hashing: SHA-384 or SHA-512 CNSA2-SIG Digital Signatures: ML-DSA-87 CNSA2-SWSIG Software/Firmware Signing: LMS or XMSS CNSA2-SYM Symmetric Encryption: AES-256 6.10 Communications security 6.7 Cryptography 6.7.1 Cryptographic controls 7.4.9 PII transmission controls 8.4.3 PII transmission controls ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required ASBv3-DP-6 Use a secure key management process DP-3 Encrypt sensitive data in transit DP-4 Enable data at rest encryption by default ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected QRCM-1.2 Quantum-Vulnerable Identification QRCM-3.1 Hybrid Solution Deployment (2025-2030) QRCM-4.2 TLS 1.3 Adoption AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection C5-CRY-01 Policy for the use of encryption procedures and key management C5-CRY-03 Encryption of sensitive data for storage CJIS-8 Media Protection CJIS-9 System and Communications Protection 8.11 Data masking 8.24 Use of cryptography ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control PTESPHASE-2 Intelligence Gathering (OSINT) PTESPHASE-3 Threat Modeling CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management US-ITAR-EAR-DS-01 Technical Data Protection US-ITAR-EAR-DS-02 Cloud and Storage ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) MALABO-Art7 Security of Electronic Transactions and Electronic Signatures AUCDR-IS-2 Secure the network and systems within the data environment BSI-08 Cryptographic protection of data FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption SC-13 SC-13 Cryptographic Protection SC-13 SC-13 Cryptographic Protection SC-13 SC-13 Cryptographic Protection NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGOB-3 API Security Standards, mTLS, and Encryption ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-2 SCA Exemptions and Risk-Based Authentication NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SHAREASSESS-3 Network Security, Endpoint, Data Protection SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC-CY-C2 Encryption and Data Protection SA-PDPL-13 Encryption of personal data IM8-CLD.2 Cloud Security Controls ISMSP-SYS-02 Encryption Implementation TAIWAN-2 Consent, Notice, Sensitive Data TEXASTDPSA-2 Consumer Rights 4(f)(ii) Sec. 4(f)(ii) Support TLS 1.3 or a successor by 2 January 2030 URUGUAY-3 Sensitive Data, Health Data, Children VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-2 Consumer Rights Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SC - System and Communications Protection You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-SC-13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 231 it maps to, and the evidence behind each claim, over MCP and REST.