Frameworks / Sigstore - Software Artifact Signing and Verification / SIGSTORE-3 What else in your programme already covers this This control maps to 76 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements QRCM-1.2 Quantum-Vulnerable Identification QRCM-3.1 Hybrid Solution Deployment (2025-2030) QRCM-4.2 TLS 1.3 Adoption AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection CJIS-8 Media Protection CJIS-9 System and Communications Protection ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) BSI-08 Cryptographic protection of data FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management SA-PDPL-13 Encryption of personal data SBD-DEV-04 Phishing-Resistant Authentication IM8-CLD.2 Cloud Security Controls ISMSP-SYS-02 Encryption Implementation TURKEYKVKK-2 Information Notice and Data Subject Rights VIETNAMPDP-2 Consent and Notice Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.