NIST 800-53 Rev 5

424 controls available

SC-13lowmoderatehigh

Cryptographic Protection

System and Communications Protection

Control Statement

Determine the {{ insert: param, sc-13_odp.01 }} ; and Implement the following types of cryptography required for each specified cryptographic use: {{ insert: param, sc-13_odp.02 }}.

Discussion

Cryptography can be employed to support a variety of security solutions, including the protection of classified information and controlled unclassified information, the provision and implementation of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances but lack the necessary formal access approvals. Cryptography can also be used to support random number and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. For example, organizations that need to protect classified information may specify the use of NSA-approved cryptography. Organizations that need to provision and implement digital signatures may specify the use of FIPS-validated cryptography. Cryptography is implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Framework
NIST SP 800-53 Rev 5
Family
System and Communications Protection
Baselines
low, moderate, high

Related Frameworks

4 paths across 2 frameworks
NIST 800-1711 mapping
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI3 mappings
CCI-002449
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002450
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004900
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

141 STIGs reach this control through 3 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

3 STIGs

Operating System — Server

35 STIGs
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-133 of 375 findings match
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-173 of 448 findings match
Show 27 more STIGs in this category →
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-191 of 103 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-191 of 216 findings match

Operating System — Mainframe

4 STIGs
Mainframe Product Security Requirements Guide
V3R42025-09-104 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-054 of 193 findings match
CA IDMS Security Technical Implementation Guide
V2R12024-09-131 of 74 findings match

Operating System — Mobile

2 STIGs

Network Device

30 STIGs
Application Layer Gateway Security Requirements Guide
V2R32025-09-157 of 160 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-225 of 41 findings match
Router Security Requirements Guide
V5R22025-09-105 of 123 findings match
Show 22 more STIGs in this category →
BIND 9.x Security Technical Implementation Guide
V3R22026-02-251 of 73 findings match
BIND 9.x Security Technical Implementation Guide
22024-02-151 of 70 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-191 of 119 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-071 of 32 findings match

Database

23 STIGs
Database Security Requirements Guide
V4R52026-02-264 of 142 findings match
Database Security Requirements Guide
42024-12-044 of 142 findings match
Show 15 more STIGs in this category →

Web / Application Server

14 STIGs
Application Server Security Requirements Guide
V4R42025-09-103 of 137 findings match
Application Server Security Requirements Guide
42025-02-113 of 128 findings match
Show 6 more STIGs in this category →
Web Server Security Requirements Guide
V4R42025-09-101 of 126 findings match
Web Server Security Requirements Guide
42025-02-121 of 124 findings match

Virtualization / Container

10 STIGs
Container Platform Security Requirements Guide
V2R42025-09-103 of 188 findings match
Container Platform Security Requirements Guide
22025-05-153 of 187 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-103 of 198 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-062 of 193 findings match
Show 2 more STIGs in this category →

Endpoint Security Management

11 STIGs
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-202 of 34 findings match
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-142 of 98 findings match
Central Log Server Security Requirements Guide
V3R42026-02-121 of 127 findings match
Show 3 more STIGs in this category →
Central Log Server Security Requirements Guide
32024-12-041 of 125 findings match

Productivity Application

6 STIGs

Uncategorized

3 STIGs