{
    "control": "SC-8",
    "title": "Transmission Confidentiality and Integrity",
    "ccis": [
        {
            "cci": "CCI-002418",
            "definition": "Protect the confidentiality and/or integrity of transmitted information."
        },
        {
            "cci": "CCI-002419",
            "definition": "The organization defines the alternative physical safeguards to be employed when cryptographic mechanisms are not implemented to protect information during transmission."
        },
        {
            "cci": "CCI-002420",
            "definition": "Maintain the confidentiality and/or integrity of information during preparation for transmission."
        },
        {
            "cci": "CCI-002421",
            "definition": "Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission."
        },
        {
            "cci": "CCI-002422",
            "definition": "Maintain the confidentiality and/or integrity of information during reception."
        },
        {
            "cci": "CCI-002423",
            "definition": "Implement cryptographic mechanisms to protect message externals unless otherwise protected by organization-defined alternative physical controls."
        },
        {
            "cci": "CCI-002424",
            "definition": "Defines the alternative physical controls to be employed when cryptographic mechanisms to conceal or randomize communication patterns are not implemented."
        },
        {
            "cci": "CCI-002425",
            "definition": "Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by organization-defined alternative physical controls."
        },
        {
            "cci": "CCI-002427",
            "definition": "Defines the alternative physical controls to be employed to protect message externals when cryptographic mechanisms are not implemented."
        }
    ],
    "rules_mapped": 44,
    "rules": [
        {
            "rule": "V-220914",
            "stig_id": "WN10-SO-000035",
            "title": "Outgoing secure channel traffic must be encrypted or signed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-220915",
            "stig_id": "WN10-SO-000040",
            "title": "Outgoing secure channel traffic must be encrypted when possible.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-220916",
            "stig_id": "WN10-SO-000045",
            "title": "Outgoing secure channel traffic must be signed when possible.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-220919",
            "stig_id": "WN10-SO-000060",
            "title": "The system must be configured to require a strong session key.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-220925",
            "stig_id": "WN10-SO-000100",
            "title": "The Windows SMB client must be configured to always perform SMB packet signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-220927",
            "stig_id": "WN10-SO-000120",
            "title": "The Windows SMB server must be configured to always perform SMB packet signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-253255",
            "stig_id": "WN11-00-000010",
            "title": "Windows 11 domain-joined systems must have a Trusted Platform Module (TPM) enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002421"
            ]
        },
        {
            "rule": "V-253256",
            "stig_id": "WN11-00-000015",
            "title": "Windows 11 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002421"
            ]
        },
        {
            "rule": "V-253257",
            "stig_id": "WN11-00-000020",
            "title": "Secure Boot must be enabled on Windows 11 systems.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002421"
            ]
        },
        {
            "rule": "V-253364",
            "stig_id": "WN11-CC-000055",
            "title": "Simultaneous connections to the internet or a Windows domain must be limited.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002418"
            ]
        },
        {
            "rule": "V-253438",
            "stig_id": "WN11-SO-000035",
            "title": "Outgoing secure channel traffic must be encrypted or signed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-253439",
            "stig_id": "WN11-SO-000040",
            "title": "Outgoing secure channel traffic must be encrypted.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-253440",
            "stig_id": "WN11-SO-000045",
            "title": "Outgoing secure channel traffic must be signed.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-253443",
            "stig_id": "WN11-SO-000060",
            "title": "The system must be configured to require a strong session key.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002418"
            ]
        },
        {
            "rule": "V-253449",
            "stig_id": "WN11-SO-000100",
            "title": "The Windows SMB client must be configured to always perform SMB packet signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002418"
            ]
        },
        {
            "rule": "V-253451",
            "stig_id": "WN11-SO-000120",
            "title": "The Windows SMB server must be configured to always perform SMB packet signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002418"
            ]
        },
        {
            "rule": "V-205820",
            "stig_id": "WN19-DC-000320",
            "title": "Windows Server 2019 domain controllers must require LDAP access signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205821",
            "stig_id": "WN19-SO-000060",
            "title": "Windows Server 2019 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205822",
            "stig_id": "WN19-SO-000070",
            "title": "Windows Server 2019 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205823",
            "stig_id": "WN19-SO-000080",
            "title": "Windows Server 2019 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205824",
            "stig_id": "WN19-SO-000110",
            "title": "Windows Server 2019 must be configured to require a strong session key.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205825",
            "stig_id": "WN19-SO-000160",
            "title": "Windows Server 2019 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205826",
            "stig_id": "WN19-SO-000170",
            "title": "Windows Server 2019 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205827",
            "stig_id": "WN19-SO-000190",
            "title": "Windows Server 2019 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205828",
            "stig_id": "WN19-SO-000200",
            "title": "Windows Server 2019 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-205829",
            "stig_id": "WN19-00-000260",
            "title": "Windows Server 2019 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002420",
                "CCI-002422"
            ]
        },
        {
            "rule": "V-254263",
            "stig_id": "WN22-00-000260",
            "title": "Windows Server 2022 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002420",
                "CCI-002422"
            ]
        },
        {
            "rule": "V-254416",
            "stig_id": "WN22-DC-000320",
            "title": "Windows Server 2022 domain controllers must require LDAP access signing.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254450",
            "stig_id": "WN22-SO-000060",
            "title": "Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254451",
            "stig_id": "WN22-SO-000070",
            "title": "Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254452",
            "stig_id": "WN22-SO-000080",
            "title": "Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254455",
            "stig_id": "WN22-SO-000110",
            "title": "Windows Server 2022 must be configured to require a strong session key.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254460",
            "stig_id": "WN22-SO-000160",
            "title": "Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254461",
            "stig_id": "WN22-SO-000170",
            "title": "Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254463",
            "stig_id": "WN22-SO-000190",
            "title": "Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-254464",
            "stig_id": "WN22-SO-000200",
            "title": "Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-230526",
            "stig_id": "RHEL-08-040160",
            "title": "All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002418"
            ]
        },
        {
            "rule": "V-244549",
            "stig_id": "RHEL-08-040159",
            "title": "All RHEL 8 networked systems must have SSH installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002418"
            ]
        },
        {
            "rule": "V-257978",
            "stig_id": "RHEL-09-255010",
            "title": "All RHEL 9 networked systems must have SSH installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002418",
                "CCI-002420",
                "CCI-002421",
                "CCI-002422"
            ]
        },
        {
            "rule": "V-257979",
            "stig_id": "RHEL-09-255015",
            "title": "All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002418",
                "CCI-002420",
                "CCI-002421",
                "CCI-002422"
            ]
        },
        {
            "rule": "V-257994",
            "stig_id": "RHEL-09-255090",
            "title": "RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000068",
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-258040",
            "stig_id": "RHEL-09-291040",
            "title": "RHEL 9 wireless network adapters must be disabled.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001443",
                "CCI-001444",
                "CCI-002418",
                "CCI-002421"
            ]
        },
        {
            "rule": "V-258230",
            "stig_id": "RHEL-09-671010",
            "title": "RHEL 9 must enable FIPS mode.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000068",
                "CCI-000877",
                "CCI-002418",
                "CCI-002450"
            ]
        },
        {
            "rule": "V-258242",
            "stig_id": "RHEL-09-672050",
            "title": "RHEL 9 must implement DOD-approved encryption in the bind package.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002418",
                "CCI-002422"
            ]
        }
    ]
}