NIST 800-171 v2

110 security requirements available

3.13.15Derived Requirement

System and Communications Protection

Security Requirement

Protect the authenticity of communications sessions.

Discussion

Authenticity protection includes protecting against man-in-the-middle attacks, session hijacking, and the insertion of false information into communications sessions. This requirement addresses communications protection at the session versus packet level (e.g., sessions in service-oriented architectures providing web-based services) and establishes grounds for confidence at both ends of communications sessions in ongoing identities of other parties and in the validity of information transmitted. [SP 800-77], [SP 800-95], and [SP 800-113] provide guidance on secure communications sessions.

Framework
NIST SP 800-171 Rev 2
Family
System and Communications Protection
Requirement Type
derived

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
SC-23
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-001184
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

167 STIGs reach this control through 7 CCIs via 800-53 control SC-23. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

6 STIGs

Operating System — Server

16 STIGs
Show 8 more STIGs in this category →
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-061 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-161 of 283 findings match
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-171 of 448 findings match

Operating System — Mainframe

5 STIGs

Network Device

36 STIGs
Application Layer Gateway Security Requirements Guide
V2R32025-09-155 of 160 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-194 of 119 findings match
Show 28 more STIGs in this category →
Network Device Management Security Requirements Guide
V5R32025-02-113 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-103 of 105 findings match
Router Security Requirements Guide
V5R22025-09-103 of 123 findings match
Router Security Requirements Guide
52024-05-283 of 108 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-222 of 41 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-111 of 53 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-071 of 32 findings match

Database

16 STIGs
Database Security Requirements Guide
V4R52026-02-264 of 142 findings match
Database Security Requirements Guide
42024-12-044 of 142 findings match
Show 8 more STIGs in this category →

Web / Application Server

30 STIGs
Web Server Security Requirements Guide
V4R42025-09-1011 of 126 findings match
Web Server Security Requirements Guide
42025-02-1211 of 124 findings match
Application Server Security Requirements Guide
V4R42025-09-106 of 137 findings match
Application Server Security Requirements Guide
42025-02-116 of 128 findings match
Show 22 more STIGs in this category →

Virtualization / Container

23 STIGs
Kubernetes Security Technical Implementation Guide
V2R62026-02-1216 of 92 findings match
Kubernetes Security Technical Implementation Guide
22025-05-1616 of 94 findings match
Container Platform Security Requirements Guide
V2R42025-09-101 of 188 findings match
Container Platform Security Requirements Guide
22025-05-151 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-061 of 193 findings match
Show 15 more STIGs in this category →
Virtual Machine Manager Security Requirements Guide
V2R32025-09-101 of 198 findings match

Cloud / Identity Service

2 STIGs

Endpoint Security Management

21 STIGs
Show 13 more STIGs in this category →
Central Log Server Security Requirements Guide
V3R42026-02-121 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-041 of 125 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-041 of 55 findings match
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-201 of 34 findings match
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-141 of 98 findings match

Productivity Application

9 STIGs

Uncategorized

3 STIGs