Frameworks / NIST SP 800-53 Rev 5 / NIST800-SC-8 What else in your programme already covers this This control maps to 130 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 1.2.6 Security features for insecure services in use 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 2.2.7 2.2.7 Non-console administrative access encrypted 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 4.2.2 4.2.2 PAN secured when sent by end-user messaging 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 6.10 Communications security 6.10.2 Information transfer 6.3.2 Mobile devices and teleworking 6.7 Cryptography 6.7.1 Cryptographic controls 7.4.9 PII transmission controls 8.4.3 PII transmission controls 8.5.1 Basis for PII transfer between jurisdictions 8.5.7 Engagement of a subcontractor to process PII 5.14 Information transfer 7.12 Cabling security 7.9 Security of assets off-premises 8.12 Data leakage prevention 8.20 Networks security 8.21 Security of network services 8.24 Use of cryptography SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-PI1.2 PI1.2 Controls over system inputs SOC2-PI1.3 PI1.3 Controls over system processing SOC2-PI1.4 PI1.4 Controls over output delivery 5.14 Information transfer 6.7 Remote working 8.12 Data leakage prevention 8.20 Networks security 8.21 Security of network services 8.24 Use of cryptography CIS-12.3 Securely Manage Network Infrastructure CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-3.10 Encrypt Sensitive Data in Transit CIS-4.6 Securely Manage Enterprise Assets and Software CIS-9.5 Implement DMARC AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-18(1) Authentication and Encryption SC-28(1) Cryptographic Protection SC-7(4) External Telecommunications Services AC-17(2) Protection of Confidentiality and Integrity Using Encryption AC-18(1) Authentication and Encryption SC-28(1) Cryptographic Protection SC-7(4) External Telecommunications Services ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet ANSSI-HYG-21 Use Secure Protocols Wherever They Exist ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working ASBv3-NS-9 Connect on-premises or cloud network privately DP-3 Encrypt sensitive data in transit C5-COS-08 Policies for data transmission C5-CRY-02 Encryption of data for transmission (transport encryption) B.4.3 B.4.3 Communication Protocol B.4.4 B.4.4 Communications Over Internet/Public Networks Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected 3(e)(i)(A) Sec. 3(e)(i)(A) (now 3(c)(i)(A)) Protect civil space command and control 4(c)(ii) Sec. 4(c)(ii) Enable encrypted DNS wherever clients and servers support it ASD37-17 TLS encryption between email servers (Limited) ADMF-5.2 Apply technical, procedural and physical safeguards AUCDR-IS-2 Secure the network and systems within the data environment EN303645-5.5 Communicate securely 161R1-SC-8 Transmission Confidentiality and Integrity 03.13.08 Transmission Confidentiality and Integrity 3.1.3e Employ Secure Information Transfer Solutions SC-8 SC-8 Transmission Confidentiality and Integrity SC-8 SC-8 Transmission Confidentiality and Integrity PTES-2.3 Encrypt sensitive communications and the final report in transit Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SC - System and Communications Protection You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-SC-8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 130 it maps to, and the evidence behind each claim, over MCP and REST.