SC-23 Session Authenticity
System and Communications Protection family. 7 Control Correlation Identifiers map to this control, and 27 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to SC-23 |
|---|---|---|
| Kubernetes | V2 | 16 |
| Microsoft Windows Server 2019 | V3 | 3 |
| Microsoft Windows 10 | V3 | 3 |
| Microsoft Windows Server 2022 | V2 | 3 |
| Microsoft Windows 11 | V2 | 2 |
Control Correlation Identifiers mapped to SC-23
| CCI | Definition | Rev |
|---|---|---|
| CCI-001184 | Protect the authenticity of communications sessions. | 5, 4 |
| CCI-001185 | Invalidate session identifiers upon user logout or other session termination. | 5, 4 |
| CCI-001188 | Generate a unique session identifier for each session with organization-defined randomness requirements. | 5, 4 |
| CCI-001189 | Defines randomness requirements for generating unique session identifiers. | 5, 4 |
| CCI-001664 | Recognize only session identifiers that are system-generated. | 5, 4 |
| CCI-002469 | Defines the certificate authorities allowed to be used for verification of the establishment of protected sessions. | 5, 4 |
| CCI-002470 | Only allow the use of organization-defined certificate authorities for verification of the establishment of protected sessions. | 5, 4 |
STIG rules that implement SC-23
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205648 | WN19-PK-000010 | medium | Windows Server 2019 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store. |
| V-205649 | WN19-PK-000020 | medium | Windows Server 2019 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems. |
| V-205650 | WN19-PK-000030 | medium | Windows Server 2019 must have the US DoD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems. |
| V-220903 | WN10-PK-000005 | medium | The DoD Root CA certificates must be installed in the Trusted Root Store. |
| V-220905 | WN10-PK-000015 | medium | The DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. |
| V-220906 | WN10-PK-000020 | medium | The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. |
| V-242418 | CNTR-K8-001400 | medium | The Kubernetes API server must use approved cipher suites. |
| V-242419 | CNTR-K8-001410 | medium | Kubernetes API Server must have the SSL Certificate Authority set. |
| V-242420 | CNTR-K8-001420 | medium | Kubernetes Kubelet must have the SSL Certificate Authority set. |
| V-242421 | CNTR-K8-001430 | medium | Kubernetes Controller Manager must have the SSL Certificate Authority set. |
| V-242422 | CNTR-K8-001440 | medium | Kubernetes API Server must have a certificate for communication. |
| V-242423 | CNTR-K8-001450 | medium | Kubernetes etcd must enable client authentication to secure service. |
| V-242424 | CNTR-K8-001460 | medium | Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service. |
| V-242425 | CNTR-K8-001470 | medium | Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service. |
| V-242426 | CNTR-K8-001480 | medium | Kubernetes etcd must enable client authentication to secure service. |
| V-242427 | CNTR-K8-001490 | medium | Kubernetes etcd must have a key file for secure communication. |
| V-242428 | CNTR-K8-001500 | medium | Kubernetes etcd must have a certificate for communication. |
| V-242429 | CNTR-K8-001510 | medium | Kubernetes etcd must have the SSL Certificate Authority set. |
| V-242430 | CNTR-K8-001520 | medium | Kubernetes etcd must have a certificate for communication. |
| V-242431 | CNTR-K8-001530 | medium | Kubernetes etcd must have a key file for secure communication. |
| V-242432 | CNTR-K8-001540 | medium | Kubernetes etcd must have peer-cert-file set for secure communication. |
| V-242433 | CNTR-K8-001550 | medium | Kubernetes etcd must have a peer-key-file set for secure communication. |
| V-253429 | WN11-PK-000015 | medium | The DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. |
| V-253430 | WN11-PK-000020 | medium | The US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems. |
| V-254442 | WN22-PK-000010 | medium | Windows Server 2022 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store. |
| V-254443 | WN22-PK-000020 | medium | Windows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems. |
| V-254444 | WN22-PK-000030 | medium | Windows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-23. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.