SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC6.7: CC6.7 Restricting and protecting information in transmission, movement and removal

Transmission, movement and removal of information are limited to users and processes, inside or outside, that are authorised, and the information is protected while it moves. Points of focus: data loss prevention processes and tools limit who can send, move or remove information; encryption or secured channels protect data beyond connectivity points; portable media (USB sticks, backup tapes) are encrypted and physically protected as appropriate; and endpoint devices that are information assets, such as phones, tablets, laptops, desktops and sensors, are protected (the 2022 revision widened this from mobile devices).

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 215 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 30 controls

FedRAMP High · 24 controls

  • AC-17 Remote Access
  • AC-18(1) Authentication and Encryption
  • AC-19 Access Control for Mobile Devices
  • AC-20(2) Portable Storage Devices Restricted Use
  • AC-21 Information Sharing
  • AC-3 Access Enforcement
  • AC-4 Information Flow Enforcement
  • AC-4(21) Physical or Logical Separation of Information Flows
  • CA-3 Information Exchange
  • CA-9 Internal System Connections
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • MA-4 Nonlocal Maintenance
  • MP-5 Media Transport
  • MP-7 Media Use
  • PE-16 Delivery and Removal
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-23 Session Authenticity
  • SC-28(1) Cryptographic Protection
  • SC-7(4) External Telecommunications Services
  • SC-7(5) Deny by Default Allow by Exception
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SC-8 Transmission Confidentiality and Integrity
  • SC-8(1) Cryptographic Protection

FedRAMP Moderate · 24 controls

  • AC-17 Remote Access
  • AC-18(1) Authentication and Encryption
  • AC-19 Access Control for Mobile Devices
  • AC-20(2) Portable Storage Devices Restricted Use
  • AC-21 Information Sharing
  • AC-3 Access Enforcement
  • AC-4 Information Flow Enforcement
  • AC-4(21) Physical or Logical Separation of Information Flows
  • CA-3 Information Exchange
  • CA-9 Internal System Connections
  • CP-9(8) System Backup | Cryptographic Protection (CP-9(8))
  • MA-4 Nonlocal Maintenance
  • MP-5 Media Transport
  • MP-7 Media Use
  • PE-16 Delivery and Removal
  • SC-12 Cryptographic Key Establishment and Management
  • SC-13 Cryptographic Protection
  • SC-23 Session Authenticity
  • SC-28(1) Cryptographic Protection
  • SC-7(4) External Telecommunications Services
  • SC-7(5) Deny by Default Allow by Exception
  • SC-7(8) Route Traffic to Authenticated Proxy Servers
  • SC-8 Transmission Confidentiality and Integrity
  • SC-8(1) Cryptographic Protection

CMMC 2.0 · 20 controls

PCI DSS 4.0 · 14 controls

  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.3.2 1.3.2 Outbound CDE traffic restricted
  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 10.1.1 10.1.1 Requirement 10 policies and procedures maintained and in use
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 3.7.2 3.7.2 Secure distribution of cryptographic keys
  • 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks
  • 4.2.1.1 4.2.1.1 Inventory of trusted transmission keys and certificates
  • 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography
  • 4.2.2 4.2.2 PAN secured when sent by end-user messaging
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 9.4.1 9.4.1 Physical security of all media
  • 9.4.3 9.4.3 Securing media sent outside the facility
  • 9.4.5 9.4.5 Inventory logs of electronic media

ISO 27001:2022 · 12 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.14 Information transfer
  • 5.15 Access control
  • 6.7 Remote working
  • 7.10 Storage media
  • 7.9 Security of assets off-premises
  • 8.12 Data leakage prevention
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks
  • 8.24 Use of cryptography
  • 8.3 Information access restriction

ISO 27002:2022 · 11 controls

  • 5.14 Information transfer
  • 6.7 Remote working
  • 7.10 Storage media
  • 7.9 Security of assets off-premises
  • 8.12 Data leakage prevention
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks
  • 8.24 Use of cryptography
  • 8.3 Information access restriction
  • 8.33 Test information

CIS Controls v8 · 9 controls

  • CIS-11.3 Protect Recovery Data
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-3.10 Encrypt Sensitive Data in Transit
  • CIS-3.13 Deploy a Data Loss Prevention Solution
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-3.9 Encrypt Data on Removable Media
  • CIS-6.7 Centralize Access Control

HIPAA Security Rule · 7 controls

ISO 27701:2019 · 7 controls

  • 6.10 Communications security
  • 6.10.2 Information transfer
  • 6.5.3 Media handling
  • 6.7 Cryptography
  • 6.7.1 Cryptographic controls
  • 7.4.9 PII transmission controls
  • 8.4.3 PII transmission controls

NIST SP 800-66 Rev 2 · 7 controls

  • NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-171 Rev 3 · 5 controls

  • ANSSI-HYG-15 Protect Against Threats Related to Removable Media
  • ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet
  • ANSSI-HYG-21 Use Secure Protocols Wherever They Exist
  • ANSSI-HYG-31 Encrypt Sensitive Data, in Particular on Equipment That May Be Lost
  • ASD37-13 Control removable storage media (Very Good)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-26 Software firewall - outbound (Very Good)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASBv3-NS-9 Connect on-premises or cloud network privately
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • DP-3 Encrypt sensitive data in transit
  • IM-4 Authenticate server and services

C5 (Germany) · 4 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-COS-08 Policies for data transmission
  • C5-CRY-01 Policy for the use of encryption procedures and key management
  • C5-CRY-02 Encryption of data for transmission (transport encryption)
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AUCDR-IS-3 Securely manage information assets over their lifecycle

NIS2 Directive · 2 controls

  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources
  • 3.1.3e Employ Secure Information Transfer Solutions

AICPA SOC 3 · 1 control

  • SOC3-LOGICAL-ACCESS Logical Access

APPI · 1 control

  • AEO-9 Information Exchange, Access and Confidentiality

DORA · 1 control

GDPR · 1 control

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC6.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 215 it maps to, and the evidence behind each claim, over MCP and REST.