Frameworks / NIST SP 800-66 Rev 2 / 164.312(e)(2)(i) NIST SP 800-66 Rev 2
Technical
NIST SP 800-66 Rev 2 164.312(e)(2)(i): Integrity Controls for Transmission (Addressable) Implement security measures to ensure electronically transmitted ePHI is not improperly modified without detection until disposed of. NIST recommends authenticated TLS, signed messages, and integrity validation on receipt.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 32 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies 6.7.1 Cryptographic controls 7.4.9 PII transmission controls 8.4.3 PII transmission controls C5-COS-08 Policies for data transmission C5-CRY-02 Encryption of data for transmission (transport encryption) CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-3.10 Encrypt Sensitive Data in Transit SC-23 Session Authenticity SC-8 Transmission Confidentiality and Integrity SC-23 Session Authenticity SC-8 Transmission Confidentiality and Integrity 8.21 Security of network services 8.24 Use of cryptography 03.13.08 Transmission Confidentiality and Integrity 03.13.15 Session Authenticity DP-3 Encrypt sensitive data in transit 5.14 Information transfer NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected 161R1-SC-8 Transmission Confidentiality and Integrity 3.1.3e Employ Secure Information Transfer Solutions NIST800-SC-8 SC-8 Transmission Confidentiality and Integrity 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technical Query this from an agent The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.