|
controlSC-13

Cryptographic Protection (SC-13)

Determine the [organization-defined] ; and Implement the following types of cryptography required for each specified cryptographic use: [organization-defined].

Security Baselines

LOWMODERATEHIGH
communicationsencryptionboundary-protectionnetwork

Why These Connect

Maps To8

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports42

These related controls work together — a change to one may affect the others.

Mitigates1

This control helps defend against or reduce the risk of the linked threat technique.

Enhances4

These enhancements add specific capabilities or refinements to the base control.

Threat Coverage(1 ATT&CK techniques)

Cross-Framework Mappings(8)

PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule2 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(2)

Assignmentorganization-defined cryptographic uses
Assignmentorganization-defined types of cryptography

Control Enhancements(4)