SC-8 Transmission Confidentiality and Integrity
System and Communications Protection family. 11 Control Correlation Identifiers map to this control, and 44 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to SC-8 |
|---|---|---|
| Microsoft Windows Server 2019 | V3 | 10 |
| Microsoft Windows 11 | V2 | 10 |
| Microsoft Windows Server 2022 | V2 | 10 |
| Microsoft Windows 10 | V3 | 6 |
| Red Hat Enterprise Linux 9 | V2 | 6 |
| Red Hat Enterprise Linux 8 | V2 | 2 |
Control Correlation Identifiers mapped to SC-8
| CCI | Definition | Rev |
|---|---|---|
| CCI-002418 | Protect the confidentiality and/or integrity of transmitted information. | 5, 4 |
| CCI-002419 | The organization defines the alternative physical safeguards to be employed when cryptographic mechanisms are not implemented to protect information during transmission. | 4 |
| CCI-002420 | Maintain the confidentiality and/or integrity of information during preparation for transmission. | 5, 4 |
| CCI-002421 | Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission. | 5, 4 |
| CCI-002422 | Maintain the confidentiality and/or integrity of information during reception. | 5, 4 |
| CCI-002423 | Implement cryptographic mechanisms to protect message externals unless otherwise protected by organization-defined alternative physical controls. | 5, 4 |
| CCI-002424 | Defines the alternative physical controls to be employed when cryptographic mechanisms to conceal or randomize communication patterns are not implemented. | 5, 4 |
| CCI-002425 | Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by organization-defined alternative physical controls. | 5, 4 |
| CCI-002427 | Defines the alternative physical controls to be employed to protect message externals when cryptographic mechanisms are not implemented. | 5, 4 |
| CCI-004893 | Implement organization-defined protection distribution system to prevent unauthorized disclosure of information, and/or detect changes to information during transmission. | 5 |
| CCI-004894 | Defines the protected distribution system for preventing unauthorized disclosure of information, and/or detect changes to information during transmission. | 5 |
STIG rules that implement SC-8
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205820 | WN19-DC-000320 | medium | Windows Server 2019 domain controllers must require LDAP access signing. |
| V-205821 | WN19-SO-000060 | medium | Windows Server 2019 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled. |
| V-205822 | WN19-SO-000070 | medium | Windows Server 2019 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to enabled. |
| V-205823 | WN19-SO-000080 | medium | Windows Server 2019 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled. |
| V-205824 | WN19-SO-000110 | medium | Windows Server 2019 must be configured to require a strong session key. |
| V-205825 | WN19-SO-000160 | medium | Windows Server 2019 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled. |
| V-205826 | WN19-SO-000170 | medium | Windows Server 2019 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled. |
| V-205827 | WN19-SO-000190 | medium | Windows Server 2019 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled. |
| V-205828 | WN19-SO-000200 | medium | Windows Server 2019 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled. |
| V-205829 | WN19-00-000260 | medium | Windows Server 2019 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process. |
| V-220914 | WN10-SO-000035 | medium | Outgoing secure channel traffic must be encrypted or signed. |
| V-220915 | WN10-SO-000040 | medium | Outgoing secure channel traffic must be encrypted when possible. |
| V-220916 | WN10-SO-000045 | medium | Outgoing secure channel traffic must be signed when possible. |
| V-220919 | WN10-SO-000060 | medium | The system must be configured to require a strong session key. |
| V-220925 | WN10-SO-000100 | medium | The Windows SMB client must be configured to always perform SMB packet signing. |
| V-220927 | WN10-SO-000120 | medium | The Windows SMB server must be configured to always perform SMB packet signing. |
| V-230526 | RHEL-08-040160 | medium | All RHEL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. |
| V-244549 | RHEL-08-040159 | medium | All RHEL 8 networked systems must have SSH installed. |
| V-253255 | WN11-00-000010 | medium | Windows 11 domain-joined systems must have a Trusted Platform Module (TPM) enabled. |
| V-253256 | WN11-00-000015 | medium | Windows 11 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS. |
| V-253257 | WN11-00-000020 | medium | Secure Boot must be enabled on Windows 11 systems. |
| V-253364 | WN11-CC-000055 | medium | Simultaneous connections to the internet or a Windows domain must be limited. |
| V-253438 | WN11-SO-000035 | medium | Outgoing secure channel traffic must be encrypted or signed. |
| V-253439 | WN11-SO-000040 | medium | Outgoing secure channel traffic must be encrypted. |
| V-253440 | WN11-SO-000045 | medium | Outgoing secure channel traffic must be signed. |
| V-253443 | WN11-SO-000060 | medium | The system must be configured to require a strong session key. |
| V-253449 | WN11-SO-000100 | medium | The Windows SMB client must be configured to always perform SMB packet signing. |
| V-253451 | WN11-SO-000120 | medium | The Windows SMB server must be configured to always perform SMB packet signing. |
| V-254263 | WN22-00-000260 | medium | Windows Server 2022 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process. |
| V-254416 | WN22-DC-000320 | medium | Windows Server 2022 domain controllers must require LDAP access signing. |
| V-254450 | WN22-SO-000060 | medium | Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled. |
| V-254451 | WN22-SO-000070 | medium | Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled. |
| V-254452 | WN22-SO-000080 | medium | Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled. |
| V-254455 | WN22-SO-000110 | medium | Windows Server 2022 must be configured to require a strong session key. |
| V-254460 | WN22-SO-000160 | medium | Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled. |
| V-254461 | WN22-SO-000170 | medium | Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled. |
| V-254463 | WN22-SO-000190 | medium | Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled. |
| V-254464 | WN22-SO-000200 | medium | Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled. |
| V-257978 | RHEL-09-255010 | medium | All RHEL 9 networked systems must have SSH installed. |
| V-257979 | RHEL-09-255015 | medium | All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. |
| V-257994 | RHEL-09-255090 | medium | RHEL 9 must force a frequent session key renegotiation for SSH connections to the server. |
| V-258040 | RHEL-09-291040 | medium | RHEL 9 wireless network adapters must be disabled. |
| V-258230 | RHEL-09-671010 | high | RHEL 9 must enable FIPS mode. |
| V-258242 | RHEL-09-672050 | medium | RHEL 9 must implement DOD-approved encryption in the bind package. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/SC-8. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.