San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

SC-23 Session Authenticity

System and Communications Protection family. 7 Control Correlation Identifiers map to this control, and 27 STIG rules implement those CCIs.

0CAT I (high)
27CAT II (medium)
0CAT III (low)
7CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to SC-23
KubernetesV216
Microsoft Windows Server 2019V33
Microsoft Windows 10V33
Microsoft Windows Server 2022V23
Microsoft Windows 11V22

Control Correlation Identifiers mapped to SC-23

CCIDefinitionRev
CCI-001184Protect the authenticity of communications sessions.5, 4
CCI-001185Invalidate session identifiers upon user logout or other session termination.5, 4
CCI-001188Generate a unique session identifier for each session with organization-defined randomness requirements.5, 4
CCI-001189Defines randomness requirements for generating unique session identifiers.5, 4
CCI-001664Recognize only session identifiers that are system-generated.5, 4
CCI-002469Defines the certificate authorities allowed to be used for verification of the establishment of protected sessions.5, 4
CCI-002470Only allow the use of organization-defined certificate authorities for verification of the establishment of protected sessions.5, 4

STIG rules that implement SC-23

RuleSTIG IDSeverityRequirement
V-205648WN19-PK-000010mediumWindows Server 2019 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.
V-205649WN19-PK-000020mediumWindows Server 2019 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.
V-205650WN19-PK-000030mediumWindows Server 2019 must have the US DoD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.
V-220903WN10-PK-000005mediumThe DoD Root CA certificates must be installed in the Trusted Root Store.
V-220905WN10-PK-000015mediumThe DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
V-220906WN10-PK-000020mediumThe US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
V-242418CNTR-K8-001400mediumThe Kubernetes API server must use approved cipher suites.
V-242419CNTR-K8-001410mediumKubernetes API Server must have the SSL Certificate Authority set.
V-242420CNTR-K8-001420mediumKubernetes Kubelet must have the SSL Certificate Authority set.
V-242421CNTR-K8-001430mediumKubernetes Controller Manager must have the SSL Certificate Authority set.
V-242422CNTR-K8-001440mediumKubernetes API Server must have a certificate for communication.
V-242423CNTR-K8-001450mediumKubernetes etcd must enable client authentication to secure service.
V-242424CNTR-K8-001460mediumKubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service.
V-242425CNTR-K8-001470mediumKubernetes Kubelet must enable tlsCertFile for client authentication to secure service.
V-242426CNTR-K8-001480mediumKubernetes etcd must enable client authentication to secure service.
V-242427CNTR-K8-001490mediumKubernetes etcd must have a key file for secure communication.
V-242428CNTR-K8-001500mediumKubernetes etcd must have a certificate for communication.
V-242429CNTR-K8-001510mediumKubernetes etcd must have the SSL Certificate Authority set.
V-242430CNTR-K8-001520mediumKubernetes etcd must have a certificate for communication.
V-242431CNTR-K8-001530mediumKubernetes etcd must have a key file for secure communication.
V-242432CNTR-K8-001540mediumKubernetes etcd must have peer-cert-file set for secure communication.
V-242433CNTR-K8-001550mediumKubernetes etcd must have a peer-key-file set for secure communication.
V-253429WN11-PK-000015mediumThe DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
V-253430WN11-PK-000020mediumThe US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
V-254442WN22-PK-000010mediumWindows Server 2022 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.
V-254443WN22-PK-000020mediumWindows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.
V-254444WN22-PK-000030mediumWindows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-23. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.