Frameworks / NIST SP 800-66 Rev 2 / 164.312(e)(1) NIST SP 800-66 Rev 2
Technical
NIST SP 800-66 Rev 2 164.312(e)(1): Transmission Security (Standard) Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network. NIST recommends encrypted transport, secure email, and validated VPN.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 67 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 1.2.6 Security features for insecure services in use 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 2.2.7 2.2.7 Non-console administrative access encrypted 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 6.4.2 6.4.2 Automated web attack detection and prevention CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.13 Deploy a Data Loss Prevention Solution CIS-4.4 Implement and Manage a Firewall on Servers ASBv3-GS-4 Define and implement network security strategy ASBv3-NS-8 Detect and disable insecure services and protocols ASBv3-NS-9 Connect on-premises or cloud network privately DP-3 Encrypt sensitive data in transit NS-2 Secure cloud services with network controls SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet ANSSI-HYG-21 Use Secure Protocols Wherever They Exist ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working AC-17 Remote Access SC-1 Policy and Procedures SC-8 Transmission Confidentiality and Integrity AC-17 Remote Access SC-1 Policy and Procedures SC-8 Transmission Confidentiality and Integrity 6.10.1 Network security management 6.10.2 Information transfer 6.7.1 Cryptographic controls C5-COS-08 Policies for data transmission C5-CRY-02 Encryption of data for transmission (transport encryption) 5.14 Information transfer 8.20 Networks security 5.14 Information transfer 8.20 Networks security ASD37-17 TLS encryption between email servers (Limited) AUCDR-IS-2 Secure the network and systems within the data environment NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected 3.1.3e Employ Secure Information Transfer Solutions Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technical Query this from an agent The graph holds this control, the 67 it maps to, and the evidence behind each claim, over MCP and REST.