to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

System and Communications Protection

Monitor, control, and protect communications at system boundaries.

System and communications protection is the second largest family and the home of encryption, network boundaries, session protection and FIPS-validated cryptography. It has more five-point requirements than any family except access control, and 3.13.11 carries one of the two partial-credit rules.

  1. 3.13.1 Guard your boundaries SC Level 1 5 pt
  2. 3.13.2 Design with security in mind SC Level 2 5 pt
  3. 3.13.3 Separate admin interfaces from user interfaces SC Level 2 1 pt
  4. 3.13.4 Prevent leakage through shared resources SC Level 2 1 pt
  5. 3.13.5 Put public services in their own subnet SC Level 1 5 pt
  6. 3.13.6 Deny by default SC Level 2 5 pt
  7. 3.13.7 Block split tunneling SC Level 2 1 pt
  8. 3.13.8 Encrypt CUI in transit SC Level 2 3 pt
  9. 3.13.9 Drop connections when sessions end SC Level 2 1 pt
  10. 3.13.10 Manage your encryption keys SC Level 2 1 pt
  11. 3.13.11 Use FIPS-validated cryptography SC Level 2 3 or 5 pt
  12. 3.13.12 Control cameras and microphones SC Level 2 1 pt
  13. 3.13.13 Control mobile code SC Level 2 1 pt
  14. 3.13.14 Control VoIP SC Level 2 1 pt
  15. 3.13.15 Protect session authenticity SC Level 2 5 pt
  16. 3.13.16 Encrypt CUI at rest SC Level 2 1 pt