# SC-13 Cryptographic Protection

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Determine the [Assignment: organization-defined cryptographic uses]; and b. Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography for each specified cryptographic use].
Guidance: Cryptography can be employed to support a variety of security solutions, including the protection of classified information and controlled unclassified information, the provision and implementation of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances but lack the necessary formal access approvals. Cryptography can also be used to support random number and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. For example, organizations that need to protect classified information may specify the use of NSA-approved cryptography. Organizations that need to provision and implement digital signatures may specify the use of FIPS-validated cryptography. Cryptography is implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

## Enhancements (none current)
Withdrawn by NIST: SC-13(01) (now in SC-13); SC-13(02) (now in SC-13); SC-13(03) (now in SC-13); SC-13(04) (now in SC-13).

## Patterns that use it (22)
- Critical (14): SP-007 Wireless- Public Hotspot Pattern; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-020 Email Transport Layer Security (TLS) Pattern; SP-024 iPhone Pattern; SP-026 PCI Full Environment; SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-039 Client-Side Encryption and Data Privacy; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-050 Mobile Security Architecture (draft); SP-051 Tokenised Asset Security Architecture (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft); SP-053 Zero-Knowledge Proof Architecture (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (7): SP-001 Client Module; SP-002 Server Module; SP-006 Wireless- Private Network Pattern; SP-013 Data Security Pattern; SP-029 Zero Trust Architecture; SP-030 API Security; SP-034 Cyber Resilience
- Standard (1): SP-028 Secure DevOps Pipeline Pattern

## Clauses by framework (78 frameworks)
- iso_27001_2022: A.8.24, A.8.26
- iso_27002_2022: 8.24
- pci_dss_v4: 2.2.7, 3.5, 4.1, 4.2
- nist_csf_2: PR.DS-01, PR.DS-02, PR.DS-10
- cis_controls_v8: CIS 16.11
- soc2_tsc: CC6.1, CC6.6-POF2, CC6.7
- finos_ccc: CCC-C01
- nis2: Art. 21(2)(h), Art. 21(2)(j)
- apra_cps_234: Para 22-23
- mas_trm: 10, 14
- pra_op_resilience: SS2/21-11.1
- bsi_grundschutz: CON.1
- anssi: Hygiene.12, Hygiene.19, RGS.2.3, SecNumCloud.11.1
- osfi_b13: B-13.3.2
- finma_circular: IV.C(63), IV.C(64)
- gdpr: Art.5(1)(f), Art.32(1)(a), Rec.83
- dora: Art.9(3)
- bio2: 8.24
- rbi_csf: ITGRCA.16
- fisc: FISC.T4, FISC.T8, FISC.T11, FISC.T12
- lgpd_bcb: BCB.Art.3, BCB.OpenFinance, BCB.PIX, LGPD.Art.46
- hkma_tme1: TME1.8.5, TME1.9.1, TME1.9.3, TME1.10.1, TME1.10.2, TME1.10.3, TME1.11.2
- mlps_2: 8.1.2.2, 8.1.4.8, 8.1.10.7
- dnb_good_practice: DNB.18.3, DNB.18.5
- cra: CRA.I.2e
- swift_cscf: SWIFT.2.1, SWIFT.2.4A
- cbb_tm: TM-9
- cbuae: CR-5, CR-8
- nca_ecc: 2-4, 2-8
- qatar_nia: CS
- sama_csf: 3.4, 4.3
- uae_ia: T8
- bog_cisd: CISD-IX, CISD-VI, CISD-XI
- bom_ctrm: 3.4, 3.13
- cbe_csf: CTO-2, CTO-3, CTO-5
- cbn_csf: Part3.3, Part3.4, Part5.2
- popia: s19
- sa_js2: JS2-8.3
- bcbs_239: Principle 3, Principle 11
- bot_cyber: Ch2.3, Ch2.7, Ch9.1
- cpmi_pfmi: CG.PR, PFMI.P22
- eba_ict: 3.8(b)
- ecb_croe: CROE.2.3.3
- ffiec_is: II.C.13(b), II.C.15(c), II.C.16, II.C.19
- hipaa_sr: §164.312(a)(1), §164.312(a)(2)(iv), §164.312(e)(1), §164.312(e)(2)(ii)
- iosco_cyber: PROT-3
- nydfs_500: 500.15
- sebi_cscrf: DATALOC, EMAIL-SEC, PR.DS
- cmmc_2: SC
- nerc_cip: CIP-012-1
- nrc_73_54: RG5.71-A-SC
- ieee_1686: 5.5
- api_1164: Sec 8
- iaea_nss: Sec 5.6
- pci_pts: C, D, E, J
- fips_140: FIPS 140-3 §7.2, FIPS 140-3 §7.3, FIPS 140-3 §7.9
- cbest: CBEST.9
- pci_hsm: 3, 4, 5, 9
- common_criteria: CC Part 2 — FCS
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.30, §11.300(d)
- fda_cyber: SA-2
- hitrust_csf: 01.c, 10.c
- iso_27799: 10.1, 13.2, H.2, H.5
- lloyds_ms: BP2.1
- naic_ds: 4-encryption, 4B
- nhs_dspt: NDG-1.1, NDG-9.6
- solvency_ii: DR.266-DataSec, EIOPA-ICT-4.7
- owasp_masvs_v2: MASVS-AUTH-2, MASVS-CRYPTO-1, MASVS-NETWORK-1, MASVS-RESILIENCE-2, MASVS-RESILIENCE-3, MASVS-RESILIENCE-4
- csa_ccm_v4: CEK-01, CEK-03, CEK-04, CEK-05, CEK-06, CEK-07, CEK-10, DSP-10, LOG-10, UEM-08
- csa_aicm: AIS-14, CEK-01, CEK-03, CEK-04, CEK-05, CEK-06, CEK-07, CEK-10, DSP-10, DSP-22, LOG-10, MDS-06, UEM-08
- ccss_v9: 1.01.2, 1.01.6, 1.02.1, 1.02.2, 1.03.1
- mica: Art.40(1), Art.55(1), Art.63(1), Art.67(1), Art.76(1)
- basel_sco60: SCO60.11, SCO60.21, SCO60.23, SCO60.51, SCO60.61, SCO60.63, SCO60.64, SCO60.66, SCO60.71
- bssc: GSP-13, KMS-01, KMS-02, KMS-03, KMS-08, NOS-08
- sec_custody_digital: SEC-CD-02, SEC-CD-03, SEC-CD-06, SEC-CD-07, SEC-CD-08
- dpdpa: Act.8(5), Rules.6(1)(a), Rules.Sch1.B.2, Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-13
- Clauses only: /api/v1/controls/SC-13?fields=mappings
- Page for people: /controls/sc-13/
