{"data":{"id":"SC-23","name":"Session Authenticity","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Protect the authenticity of communications sessions.","supplemental_guidance":"Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of communications sessions in the ongoing identities of other parties and the validity of transmitted information. Authenticity protection includes protecting against \"man-in-the-middle\" attacks, session hijacking, and the insertion of false information into sessions.","enhancements":[{"id":"SC-23(01)","name":"Invalidate Session Identifiers at Logout","statement":"Invalidate session identifiers upon user logout or other session termination.","baselines":[]},{"id":"SC-23(02)","name":"User-initiated Logouts and Message Displays","withdrawn":true,"incorporated_into":["AC-12(01)"]},{"id":"SC-23(03)","name":"Unique System-generated Session Identifiers","statement":"Generate a unique session identifier for each session with [Assignment: organization-defined randomness requirements] and recognize only session identifiers that are system-generated.","baselines":[]},{"id":"SC-23(04)","name":"Unique Session Identifiers with Randomization","withdrawn":true,"incorporated_into":["SC-23(03)"]},{"id":"SC-23(05)","name":"Allowed Certificate Authorities","statement":"Only allow the use of [Assignment: organization-defined certificate authorities] for verification of the establishment of protected sessions.","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-23","name":"Session Authenticity","description":"Protect the authenticity of communications sessions.","discussion":"Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of communications sessions in the ongoing identities of other parties and the validity of transmitted information. Authenticity protection includes protecting against \"man-in-the-middle\" attacks, session hijacking, and the insertion of false information into sessions.","related_controls":["AU-10","SC-08","SC-10","SC-11"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["PR.AA-04"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":["CCC-C01"],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["14"],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.12","Hygiene.24","SecNumCloud.10.5"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(63)"],"gdpr":["Art.32(1)(a)","Art.32(1)(b)"],"dora":["Art.9(3)"],"bio2":[],"rbi_csf":["Annex1.9"],"fisc":["FISC.T8","FISC.T12"],"lgpd_bcb":["BCB.OpenFinance","BCB.PIX"],"hkma_tme1":["TME1.8.4","TME1.10.1"],"mlps_2":[],"dnb_good_practice":["DNB.18.4"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-8"],"nca_ecc":["2-5"],"qatar_nia":["CS"],"sama_csf":["3.8"],"uae_ia":["T8"],"bog_cisd":["CISD-IX"],"bom_ctrm":["3.13"],"cbe_csf":["CTO-5"],"cbn_csf":["Part5.2"],"bot_cyber":["Ch2.4","Ch8.2","Ch9.1"],"cpmi_pfmi":["PFMI.P22"],"eba_ict":["3.8(b)"],"ffiec_is":["II.C.6","II.C.9","II.C.13(b)","II.C.16"],"hipaa_sr":["§164.312(e)(1)"],"nydfs_500":["500.12"],"cmmc_2":["SC"],"nerc_cip":["CIP-012-1"],"nrc_73_54":["RG5.71-A-SC"],"tsa_psd":[],"ieee_1686":["5.5","5.8"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":["Sec 5.6"],"pci_pts":["E"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":["3"],"common_criteria":["CC Part 2 — FRU/FTA/FTP"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.30","§11.300(d)"],"fda_cyber":["SA-2"],"hitrust_csf":["01.b"],"iso_27799":["9.5","H.5"],"lloyds_ms":["BP2.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":["MASVS-AUTH-1","MASVS-AUTH-3","MASVS-NETWORK-1","MASVS-NETWORK-2"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":["GSP-13"],"sec_custody_digital":["SEC-CD-03"],"dpdpa":[]},"attack_techniques":[{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity mechanisms using TLS mutual authentication and session tokens ensure that application-layer protocol communications are established with verified endpoints, not adversary C2 infrastructure."},{"id":"T1185","name":"Browser Session Hijacking","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity controls including session token binding, secure cookie attributes, and anti-CSRF protections prevent adversaries from hijacking authenticated browser sessions to access protected resources."},{"id":"T1535","name":"Unused/Unsupported Cloud Regions","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity mechanisms that validate cloud service endpoints and enforce regional session policies detect and prevent adversary operations from unused or unsupported cloud regions."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Mutual TLS authentication and session integrity verification protect communications sessions from adversary-in-the-middle attacks by ensuring both endpoints are cryptographically verified before data exchange."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity mechanisms that validate encryption endpoints and enforce certificate verification ensure encrypted channels terminate at authorized servers rather than adversary-controlled interception points."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity protections that detect inconsistent session state or anomalous debugging artifacts help identify adversary attempts to evade debugger-based analysis through session manipulation."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"TLS certificate validation and session pinning for web protocol communications prevent adversaries from establishing C2 channels through web protocols by impersonating legitimate HTTPS endpoints."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity controls for file transfer protocols ensure that FTP/SFTP sessions are established with verified servers, preventing adversary interception through protocol impersonation."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"SMTP/IMAP session authentication and TLS enforcement ensure mail protocol communications are established with verified mail servers, preventing C2 through mail protocol impersonation."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC validation and DNS-over-HTTPS/TLS ensure DNS query authenticity, preventing adversaries from manipulating DNS responses to redirect C2 communications or poison resolver caches."},{"id":"T1550.004","name":"Web Session Cookie","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity controls including secure cookie attributes (Secure, HttpOnly, SameSite), token binding, and session fingerprinting prevent adversaries from reusing stolen web session cookies."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity protections including SMB signing and Extended Protection for Authentication prevent adversaries from relaying NTLM authentication through LLMNR/NBT-NS poisoning attacks."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity mechanisms that verify endpoint identity at the network layer prevent adversaries from intercepting communications through ARP cache poisoning and traffic redirection."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity controls that validate DHCP server identity and enforce authenticated network configuration prevent adversaries from redirecting traffic through spoofed DHCP responses."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity mechanisms including 802.1X authentication and server certificate validation prevent adversaries from establishing evil twin wireless access points for credential interception."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity protections that verify the integrity of security telemetry channels prevent adversaries from blocking indicators by impersonating or disrupting authenticated monitoring sessions."},{"id":"T1562.009","name":"Safe Mode Boot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity checks that validate boot environment integrity detect when adversaries force Safe Mode boot to bypass security tools that rely on authenticated session establishment."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"SSH session authenticity controls including host key verification, strict mode enforcement, and session encryption prevent adversaries from hijacking SSH connections for lateral movement."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Session authenticity verification for symmetric encrypted channels ensures that shared keys are exchanged with authenticated endpoints, preventing adversaries from establishing parallel encrypted C2 sessions."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Certificate validation and pinning for asymmetric encrypted channels ensures that TLS connections are established with verified servers, preventing adversary interception through rogue certificates."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-005","SP-016","SP-023","SP-029","SP-030","SP-032","SP-033","SP-039","SP-040","SP-046","SP-048","SP-050"]}}