# SC-23 Session Authenticity

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Protect the authenticity of communications sessions.
Guidance: Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of communications sessions in the ongoing identities of other parties and the validity of transmitted information. Authenticity protection includes protecting against "man-in-the-middle" attacks, session hijacking, and the insertion of false information into sessions.

## Enhancements (3)
- SC-23(01) Invalidate Session Identifiers at Logout
- SC-23(03) Unique System-generated Session Identifiers
- SC-23(05) Allowed Certificate Authorities
Withdrawn by NIST: SC-23(02) (now in AC-12(01)); SC-23(04) (now in SC-23(03)).
Each enhancement's statement: /api/v1/controls/SC-23?fields=enhancements

## Patterns that use it (12)
- Critical (3): SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-048 Offensive AI and Deepfake Defence (draft)
- Important (6): SP-005 SOA Internal Service Usage Pattern; SP-029 Zero Trust Architecture; SP-030 API Security; SP-039 Client-Side Encryption and Data Privacy; SP-046 External Attack Surface Management; SP-050 Mobile Security Architecture (draft)
- Standard (3): SP-016 DMZ Module; SP-023 Industrial Control Systems; SP-040 Post-Quantum Cryptography and Quantum Readiness

## Clauses by framework (44 frameworks)
- nist_csf_2: PR.AA-04. OSA's own, not in NIST's crosswalk: PR.AA-04
- finos_ccc: CCC-C01
- mas_trm: 14
- anssi: Hygiene.12, Hygiene.24, SecNumCloud.10.5
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(63)
- gdpr: Art.32(1)(a), Art.32(1)(b)
- dora: Art.9(3)
- rbi_csf: Annex1.9
- fisc: FISC.T8, FISC.T12
- lgpd_bcb: BCB.OpenFinance, BCB.PIX
- hkma_tme1: TME1.8.4, TME1.10.1
- dnb_good_practice: DNB.18.4
- cbb_tm: TM-8
- nca_ecc: 2-5
- qatar_nia: CS
- sama_csf: 3.8
- uae_ia: T8
- bog_cisd: CISD-IX
- bom_ctrm: 3.13
- cbe_csf: CTO-5
- cbn_csf: Part5.2
- bot_cyber: Ch2.4, Ch8.2, Ch9.1
- cpmi_pfmi: PFMI.P22
- eba_ict: 3.8(b)
- ffiec_is: II.C.6, II.C.9, II.C.13(b), II.C.16
- hipaa_sr: §164.312(e)(1)
- nydfs_500: 500.12
- cmmc_2: SC
- nerc_cip: CIP-012-1
- nrc_73_54: RG5.71-A-SC
- ieee_1686: 5.5, 5.8
- iaea_nss: Sec 5.6
- pci_pts: E
- pci_hsm: 3
- common_criteria: CC Part 2 — FRU/FTA/FTP
- fda_21_cfr_11: §11.30, §11.300(d)
- fda_cyber: SA-2
- hitrust_csf: 01.b
- iso_27799: 9.5, H.5
- lloyds_ms: BP2.1
- owasp_masvs_v2: MASVS-AUTH-1, MASVS-AUTH-3, MASVS-NETWORK-1, MASVS-NETWORK-2
- bssc: GSP-13
- sec_custody_digital: SEC-CD-03
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-23
- Clauses only: /api/v1/controls/SC-23?fields=mappings
- Page for people: /controls/sc-23/
