Back to catalog
NET-09NETNetwork Security
Session Integrity
Description
Mechanisms exist to protect the authenticity and integrity of communications sessions.
Cross-Mappings
140 paths across 4 frameworks
Cross-Mappings
NIST 800-531 mapping
SC-23
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-1711 mapping
3.13.15
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-001184
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG93 mappings
SV-104265r1_ruleSymantec ProxySG must use Transport Layer Security (TLS) to protect the authenticity of communications sessions.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R3 · disa_xccdf · related
SV-204762r1043178_ruleThe application server must be configured to mutually authenticate connecting proxies, application servers or gateways.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-204957r396006_ruleThe ALG must protect the authenticity of communications sessions.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-205182r1043178_ruleThe DNS implementation must protect the authenticity of communications sessions for zone transfers.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V4R2 · disa_xccdf · related
SV-205182r961110_ruleThe DNS implementation must protect the authenticity of communications sessions for zone transfers.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205183r1043178_ruleThe DNS implementation must protect the authenticity of communications sessions for dynamic updates.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V4R2 · disa_xccdf · related
SV-205183r961110_ruleThe DNS implementation must protect the authenticity of communications sessions for dynamic updates.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205184r1043178_ruleThe DNS implementation must protect the authenticity of communications sessions for queries.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V4R2 · disa_xccdf · related
SV-205184r961110_ruleThe DNS implementation must protect the authenticity of communications sessions for queries.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-207222r608988_ruleThe VPN Gateway must use FIPS 140-2 compliant mechanisms for authentication to a cryptographic module.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
+83 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer