NIST SP 800-53 Revision 5.1 HIGH
SC System Communications Protection

NIST SP 800-53 Revision 5.1 HIGH SC-23: Session Authenticity

Protect authenticity of communications sessions.

What else in your programme already covers this

This control maps to 24 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 4 controls

  • 4.2.1 Strong cryptography and security protocols are implemented as follows to safeguard PAN during transmission over open, public networks: • Only trusted keys and certificates are accepted. • Certificates used to safeguard PAN during transmission
  • 8.4.1 MFA is implemented for all non-console access into the CDE for personnel with administrative access
  • 8.4.2 MFA is implemented for all non-console access into the CDE
  • 8.5.1 MFA systems are implemented as follows: • The MFA system is not susceptible to replay attacks. • MFA systems cannot be bypassed by any users, including administrative users unless specifically documented, and authorized by

CIS Controls v8 · 2 controls

  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected

SOC 2 · 2 controls

  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.7 Transmission of data is restricted to authorized users
  • IM-4 Authenticate server and services

C5 (Germany) · 1 control

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 8.21 Security of network services

ISO 27002:2022 · 1 control

  • 8.21 Security of network services

ISO 27701:2019 · 1 control

  • 6.11.1 Security requirements of information systems

NIST SP 800-172 · 1 control

  • 3.5.1e Identification of Systems, Components, and Devices

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SC System Communications Protection

Query this from an agent

The graph holds this control, the 24 it maps to, and the evidence behind each claim, over MCP and REST.