SC-13 Cryptographic Protection
System and Communications Protection
Description
a. Determine the [Assignment: organization-defined cryptographic uses]; and b. Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography for each specified cryptographic use].
Supplemental Guidance
Cryptography can be employed to support a variety of security solutions, including the protection of classified information and controlled unclassified information, the provision and implementation of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances but lack the necessary formal access approvals. Cryptography can also be used to support random number and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. For example, organizations that need to protect classified information may specify the use of NSA-approved cryptography. Organizations that need to provision and implement digital signatures may specify the use of FIPS-validated cryptography. Cryptography is implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
Changes from Rev 4
Control text adds 'need to determine cryptographic protection in addition to implementing' Single previous parameter split into two separate parameters: Determine the specific cryptographic uses and types of cryptography for each specified cryptographic use
Enhancements (0)
NIST has withdrawn every enhancement this control had.
Patterns that use this control (22)
Grouped by the emphasis each pattern gives it.
Critical (14)
- SP-007 Wireless- Public Hotspot Pattern
- SP-019 Secure Ad-Hoc File Exchange Pattern
- SP-020 Email Transport Layer Security (TLS) Pattern
- SP-024 iPhone Pattern
- SP-026 PCI Full Environment
- SP-032 Modern Authentication
- SP-033 Passkey Authentication
- SP-039 Client-Side Encryption and Data Privacy
- SP-040 Post-Quantum Cryptography and Quantum Readiness
- SP-050 Mobile Security Architecture (draft)
- SP-051 Tokenised Asset Security Architecture (draft)
- SP-052 Decentralised Identity & Verifiable Credentials (draft)
- SP-053 Zero-Knowledge Proof Architecture (draft)
- SP-054 CBDC and Digital Currency Infrastructure (draft)
Important (7)
Standard (1)
MITRE ATT&CK Techniques (5)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.