NIST 800-53 Rev 5

424 controls available

SC-8moderatehigh

Transmission Confidentiality and Integrity

System and Communications Protection

Control Statement

Protect the {{ insert: param, sc-08_odp }} of transmitted information.

Discussion

Protecting the confidentiality and integrity of transmitted information applies to internal and external networks as well as any system components that can transmit information, including servers, notebook computers, desktop computers, mobile devices, printers, copiers, scanners, facsimile machines, and radios. Unprotected communication paths are exposed to the possibility of interception and modification. Protecting the confidentiality and integrity of information can be accomplished by physical or logical means. Physical protection can be achieved by using protected distribution systems. A protected distribution system is a wireline or fiber-optics telecommunications system that includes terminals and adequate electromagnetic, acoustical, electrical, and physical controls to permit its use for the unencrypted transmission of classified information. Logical protection can be achieved by employing encryption techniques. Organizations that rely on commercial providers who offer transmission services as commodity services rather than as fully dedicated services may find it difficult to obtain the necessary assurances regarding the implementation of needed controls for transmission confidentiality and integrity. In such situations, organizations determine what types of confidentiality or integrity services are available in standard, commercial telecommunications service packages. If it is not feasible to obtain the necessary controls and assurances of control effectiveness through appropriate contracting vehicles, organizations can implement appropriate compensating controls.

Framework
NIST SP 800-53 Rev 5
Family
System and Communications Protection
Baselines
moderate, high

Related Frameworks

4 paths across 2 frameworks
NIST 800-1711 mapping
3.13.8
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI3 mappings
CCI-002418
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002419
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002421
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

144 STIGs reach this control through 11 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

7 STIGs

Operating System — Server

43 STIGs
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-197 of 216 findings match
Show 35 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-174 of 448 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-133 of 375 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-191 of 103 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-061 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-161 of 283 findings match

Operating System — Mainframe

1 STIG
CA IDMS Security Technical Implementation Guide
V2R12024-09-134 of 74 findings match

Network Device

19 STIGs
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-194 of 119 findings match
BIND 9.x Security Technical Implementation Guide
V3R22026-02-251 of 73 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-221 of 41 findings match
Show 11 more STIGs in this category →
F5 NGINX Security Technical Implementation Guide
V1R12026-01-071 of 32 findings match
Router Security Requirements Guide
V5R22025-09-101 of 123 findings match

Database

16 STIGs
Database Security Requirements Guide
V4R52026-02-262 of 142 findings match
Database Security Requirements Guide
42024-12-042 of 142 findings match
Show 8 more STIGs in this category →

Web / Application Server

27 STIGs
Web Server Security Requirements Guide
V4R42025-09-1012 of 126 findings match
Web Server Security Requirements Guide
42025-02-1212 of 124 findings match
Application Server Security Requirements Guide
V4R42025-09-105 of 137 findings match
Application Server Security Requirements Guide
42025-02-115 of 128 findings match
Show 19 more STIGs in this category →

Virtualization / Container

16 STIGs
Virtual Machine Manager Security Requirements Guide
22024-12-064 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-104 of 198 findings match
Container Platform Security Requirements Guide
V2R42025-09-103 of 188 findings match
Container Platform Security Requirements Guide
22025-05-153 of 187 findings match
Show 8 more STIGs in this category →

Cloud / Identity Service

2 STIGs

Endpoint Security Management

12 STIGs
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-204 of 34 findings match
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-143 of 98 findings match
BlackBerry UEM Security Technical Implementation Guide
V2R12020-12-041 of 16 findings match
Central Log Server Security Requirements Guide
V3R42026-02-121 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-041 of 125 findings match
Show 4 more STIGs in this category →

Uncategorized

1 STIG