San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

SC-8 Transmission Confidentiality and Integrity

System and Communications Protection family. 11 Control Correlation Identifiers map to this control, and 44 STIG rules implement those CCIs.

1CAT I (high)
43CAT II (medium)
0CAT III (low)
11CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to SC-8
Microsoft Windows Server 2019V310
Microsoft Windows 11V210
Microsoft Windows Server 2022V210
Microsoft Windows 10V36
Red Hat Enterprise Linux 9V26
Red Hat Enterprise Linux 8V22

Control Correlation Identifiers mapped to SC-8

CCIDefinitionRev
CCI-002418Protect the confidentiality and/or integrity of transmitted information.5, 4
CCI-002419The organization defines the alternative physical safeguards to be employed when cryptographic mechanisms are not implemented to protect information during transmission.4
CCI-002420Maintain the confidentiality and/or integrity of information during preparation for transmission.5, 4
CCI-002421Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission.5, 4
CCI-002422Maintain the confidentiality and/or integrity of information during reception.5, 4
CCI-002423Implement cryptographic mechanisms to protect message externals unless otherwise protected by organization-defined alternative physical controls.5, 4
CCI-002424Defines the alternative physical controls to be employed when cryptographic mechanisms to conceal or randomize communication patterns are not implemented.5, 4
CCI-002425Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by organization-defined alternative physical controls.5, 4
CCI-002427Defines the alternative physical controls to be employed to protect message externals when cryptographic mechanisms are not implemented.5, 4
CCI-004893Implement organization-defined protection distribution system to prevent unauthorized disclosure of information, and/or detect changes to information during transmission.5
CCI-004894Defines the protected distribution system for preventing unauthorized disclosure of information, and/or detect changes to information during transmission.5

STIG rules that implement SC-8

RuleSTIG IDSeverityRequirement
V-205820WN19-DC-000320mediumWindows Server 2019 domain controllers must require LDAP access signing.
V-205821WN19-SO-000060mediumWindows Server 2019 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
V-205822WN19-SO-000070mediumWindows Server 2019 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled.
V-205823WN19-SO-000080mediumWindows Server 2019 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
V-205824WN19-SO-000110mediumWindows Server 2019 must be configured to require a strong session key.
V-205825WN19-SO-000160mediumWindows Server 2019 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
V-205826WN19-SO-000170mediumWindows Server 2019 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
V-205827WN19-SO-000190mediumWindows Server 2019 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
V-205828WN19-SO-000200mediumWindows Server 2019 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
V-205829WN19-00-000260mediumWindows Server 2019 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process.
V-220914WN10-SO-000035mediumOutgoing secure channel traffic must be encrypted or signed.
V-220915WN10-SO-000040mediumOutgoing secure channel traffic must be encrypted when possible.
V-220916WN10-SO-000045mediumOutgoing secure channel traffic must be signed when possible.
V-220919WN10-SO-000060mediumThe system must be configured to require a strong session key.
V-220925WN10-SO-000100mediumThe Windows SMB client must be configured to always perform SMB packet signing.
V-220927WN10-SO-000120mediumThe Windows SMB server must be configured to always perform SMB packet signing.
V-230526RHEL-08-040160mediumAll RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
V-244549RHEL-08-040159mediumAll RHEL 8 networked systems must have SSH installed.
V-253255WN11-00-000010mediumWindows 11 domain-joined systems must have a Trusted Platform Module (TPM) enabled.
V-253256WN11-00-000015mediumWindows 11 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.
V-253257WN11-00-000020mediumSecure Boot must be enabled on Windows 11 systems.
V-253364WN11-CC-000055mediumSimultaneous connections to the internet or a Windows domain must be limited.
V-253438WN11-SO-000035mediumOutgoing secure channel traffic must be encrypted or signed.
V-253439WN11-SO-000040mediumOutgoing secure channel traffic must be encrypted.
V-253440WN11-SO-000045mediumOutgoing secure channel traffic must be signed.
V-253443WN11-SO-000060mediumThe system must be configured to require a strong session key.
V-253449WN11-SO-000100mediumThe Windows SMB client must be configured to always perform SMB packet signing.
V-253451WN11-SO-000120mediumThe Windows SMB server must be configured to always perform SMB packet signing.
V-254263WN22-00-000260mediumWindows Server 2022 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process.
V-254416WN22-DC-000320mediumWindows Server 2022 domain controllers must require LDAP access signing.
V-254450WN22-SO-000060mediumWindows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled.
V-254451WN22-SO-000070mediumWindows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled.
V-254452WN22-SO-000080mediumWindows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled.
V-254455WN22-SO-000110mediumWindows Server 2022 must be configured to require a strong session key.
V-254460WN22-SO-000160mediumWindows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled.
V-254461WN22-SO-000170mediumWindows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled.
V-254463WN22-SO-000190mediumWindows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled.
V-254464WN22-SO-000200mediumWindows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled.
V-257978RHEL-09-255010mediumAll RHEL 9 networked systems must have SSH installed.
V-257979RHEL-09-255015mediumAll RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
V-257994RHEL-09-255090mediumRHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
V-258040RHEL-09-291040mediumRHEL 9 wireless network adapters must be disabled.
V-258230RHEL-09-671010highRHEL 9 must enable FIPS mode.
V-258242RHEL-09-672050mediumRHEL 9 must implement DOD-approved encryption in the bind package.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-8. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.