{"data":{"id":"SC-13","name":"Cryptographic Protection","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. Determine the [Assignment: organization-defined cryptographic uses]; and\nb. Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography for each specified cryptographic use].","supplemental_guidance":"Cryptography can be employed to support a variety of security solutions, including the protection of classified information and controlled unclassified information, the provision and implementation of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances but lack the necessary formal access approvals. Cryptography can also be used to support random number and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. For example, organizations that need to protect classified information may specify the use of NSA-approved cryptography. Organizations that need to provision and implement digital signatures may specify the use of FIPS-validated cryptography. Cryptography is implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.","enhancements":[{"id":"SC-13(01)","name":"FIPS-validated Cryptography","withdrawn":true,"incorporated_into":["SC-13"]},{"id":"SC-13(02)","name":"NSA-approved Cryptography","withdrawn":true,"incorporated_into":["SC-13"]},{"id":"SC-13(03)","name":"Individuals Without Formal Access Approvals","withdrawn":true,"incorporated_into":["SC-13"]},{"id":"SC-13(04)","name":"Digital Signatures","withdrawn":true,"incorporated_into":["SC-13"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-13","name":"Cryptographic Protection","description":"a. Determine the [Assignment: organization-defined cryptographic uses]; and\nb. Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography for each specified cryptographic use].","discussion":"Cryptography can be employed to support a variety of security solutions, including the protection of classified information and controlled unclassified information, the provision and implementation of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances but lack the necessary formal access approvals. Cryptography can also be used to support random number and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. For example, organizations that need to protect classified information may specify the use of NSA-approved cryptography. Organizations that need to provision and implement digital signatures may specify the use of FIPS-validated cryptography. Cryptography is implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.","related_controls":["AC-02","AC-03","AC-07","AC-17","AC-18","AC-19","AU-09","AU-10","CM-11","CP-09","IA-03","IA-05","IA-07","IA-13","MA-04","MP-02","MP-04","MP-05","SA-04","SA-08","SA-09","SC-08","SC-12","SC-20","SC-23","SC-28","SC-40","SI-03","SI-07"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Control text adds 'need to determine cryptographic protection in addition to implementing' Single previous parameter split into two separate parameters: Determine the specific cryptographic uses and types of cryptography for each specified cryptographic use"}},"compliance_mappings":{"iso_27001_2022":["A.8.24","A.8.26"],"iso_27002_2022":["8.24"],"cobit_2019":[],"pci_dss_v4":["2.2.7","3.5","4.1","4.2"],"nist_csf_2":["PR.DS-01","PR.DS-02","PR.DS-10"],"cis_controls_v8":["CIS 16.11"],"soc2_tsc":["CC6.1","CC6.6-POF2","CC6.7"],"finos_ccc":["CCC-C01"],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(h)","Art. 21(2)(j)"],"apra_cps_234":["Para 22-23"],"mas_trm":["10","14"],"pra_op_resilience":["SS2/21-11.1"],"bsi_grundschutz":["CON.1"],"anssi":["Hygiene.12","Hygiene.19","RGS.2.3","SecNumCloud.11.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.C(63)","IV.C(64)"],"gdpr":["Art.5(1)(f)","Art.32(1)(a)","Rec.83"],"dora":["Art.9(3)"],"bio2":["8.24"],"rbi_csf":["ITGRCA.16"],"fisc":["FISC.T4","FISC.T8","FISC.T11","FISC.T12"],"lgpd_bcb":["BCB.Art.3","BCB.OpenFinance","BCB.PIX","LGPD.Art.46"],"hkma_tme1":["TME1.8.5","TME1.9.1","TME1.9.3","TME1.10.1","TME1.10.2","TME1.10.3","TME1.11.2"],"mlps_2":["8.1.2.2","8.1.4.8","8.1.10.7"],"dnb_good_practice":["DNB.18.3","DNB.18.5"],"cra":["CRA.I.2e"],"swift_cscf":["SWIFT.2.1","SWIFT.2.4A"],"cbb_tm":["TM-9"],"cbuae":["CR-5","CR-8"],"nca_ecc":["2-4","2-8"],"qatar_nia":["CS"],"sama_csf":["3.4","4.3"],"uae_ia":["T8"],"bog_cisd":["CISD-IX","CISD-VI","CISD-XI"],"bom_ctrm":["3.4","3.13"],"cbe_csf":["CTO-2","CTO-3","CTO-5"],"cbn_csf":["Part3.3","Part3.4","Part5.2"],"popia":["s19"],"sa_js2":["JS2-8.3"],"bcbs_239":["Principle 3","Principle 11"],"bot_cyber":["Ch2.3","Ch2.7","Ch9.1"],"cpmi_pfmi":["CG.PR","PFMI.P22"],"eba_ict":["3.8(b)"],"ecb_croe":["CROE.2.3.3"],"ffiec_is":["II.C.13(b)","II.C.15(c)","II.C.16","II.C.19"],"hipaa_sr":["§164.312(a)(1)","§164.312(a)(2)(iv)","§164.312(e)(1)","§164.312(e)(2)(ii)"],"iosco_cyber":["PROT-3"],"nydfs_500":["500.15"],"sebi_cscrf":["DATALOC","EMAIL-SEC","PR.DS"],"cmmc_2":["SC"],"nerc_cip":["CIP-012-1"],"nrc_73_54":["RG5.71-A-SC"],"tsa_psd":[],"ieee_1686":["5.5"],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 8"],"awia":[],"iaea_nss":["Sec 5.6"],"pci_pts":["C","D","E","J"],"fips_140":["FIPS 140-3 §7.2","FIPS 140-3 §7.3","FIPS 140-3 §7.9"],"cbest":["CBEST.9"],"tiber_eu":[],"pci_hsm":["3","4","5","9"],"common_criteria":["CC Part 2 — FCS"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.30","§11.300(d)"],"fda_cyber":["SA-2"],"hitrust_csf":["01.c","10.c"],"iso_27799":["10.1","13.2","H.2","H.5"],"lloyds_ms":["BP2.1"],"naic_ds":["4-encryption","4B"],"nhs_dspt":["NDG-1.1","NDG-9.6"],"pra_ss1_23":[],"solvency_ii":["DR.266-DataSec","EIOPA-ICT-4.7"],"owasp_masvs_v2":["MASVS-AUTH-2","MASVS-CRYPTO-1","MASVS-NETWORK-1","MASVS-RESILIENCE-2","MASVS-RESILIENCE-3","MASVS-RESILIENCE-4"],"csa_ccm_v4":["CEK-01","CEK-03","CEK-04","CEK-05","CEK-06","CEK-07","CEK-10","DSP-10","LOG-10","UEM-08"],"csa_aicm":["AIS-14","CEK-01","CEK-03","CEK-04","CEK-05","CEK-06","CEK-07","CEK-10","DSP-10","DSP-22","LOG-10","MDS-06","UEM-08"],"ccss_v9":["1.01.2","1.01.6","1.02.1","1.02.2","1.03.1"],"mica":["Art.40(1)","Art.55(1)","Art.63(1)","Art.67(1)","Art.76(1)"],"basel_sco60":["SCO60.11","SCO60.21","SCO60.23","SCO60.51","SCO60.61","SCO60.63","SCO60.64","SCO60.66","SCO60.71"],"bssc":["GSP-13","KMS-01","KMS-02","KMS-03","KMS-08","NOS-08"],"sec_custody_digital":["SEC-CD-02","SEC-CD-03","SEC-CD-06","SEC-CD-07","SEC-CD-08"],"dpdpa":["Act.8(5)","Rules.6(1)(a)","Rules.Sch1.B.2","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1005","name":"Data from Local System","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting sensitive data at rest using FIPS-validated cryptographic modules ensures that adversaries who access local system storage cannot read the collected data without the decryption keys."},{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Encrypting removable media using approved cryptographic mechanisms ensures that adversaries who gain physical access to portable storage cannot read sensitive organizational data."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Enforcing approved encryption standards for data in transit ensures that even if adversaries intercept exfiltrated data on C2 channels, the content remains protected by validated cryptography."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Mandating encryption for all data in transit eliminates the effectiveness of exfiltration over unencrypted protocols by ensuring sensitive data is never transmitted in cleartext."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Implementing strong cryptographic protocols for wireless communications (WPA3, 802.1X with EAP-TLS) prevents adversaries from intercepting credentials and data through evil twin wireless access points."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.26 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.DS-01, PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-006","SP-007","SP-013","SP-019","SP-020","SP-024","SP-026","SP-028","SP-029","SP-030","SP-032","SP-033","SP-034","SP-039","SP-040","SP-041","SP-050","SP-051","SP-052","SP-053","SP-054"]}}