System and Communications Protection
Monitor, control, and protect communications at system boundaries.
System and communications protection is the second largest family and the home of encryption, network boundaries, session protection and FIPS-validated cryptography. It has more five-point requirements than any family except access control, and 3.13.11 carries one of the two partial-credit rules.
- 3.13.1 Guard your boundaries
- 3.13.2 Design with security in mind
- 3.13.3 Separate admin interfaces from user interfaces
- 3.13.4 Prevent leakage through shared resources
- 3.13.5 Put public services in their own subnet
- 3.13.6 Deny by default
- 3.13.7 Block split tunneling
- 3.13.8 Encrypt CUI in transit
- 3.13.9 Drop connections when sessions end
- 3.13.10 Manage your encryption keys
- 3.13.11 Use FIPS-validated cryptography
- 3.13.12 Control cameras and microphones
- 3.13.13 Control mobile code
- 3.13.14 Control VoIP
- 3.13.15 Protect session authenticity
- 3.13.16 Encrypt CUI at rest