← Back to catalog
SC-13

Cryptographic Protection

System and Communications Protection (SC)
Baselines
Low · IncludedModerate · IncludedHigh · Included
Description

Determine the [assignment] ; and Implement the following types of cryptography required for each specified cryptographic use: [assignment].

Discussion

Cryptography can be employed to support a variety of security solutions, including the protection of classified information and controlled unclassified information, the provision and implementation of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances but lack the necessary formal access approvals. Cryptography can also be used to support random number and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. For example, organizations that need to protect classified information may specify the use of NSA-approved cryptography. Organizations that need to provision and implement digital signatures may specify the use of FIPS-validated cryptography. Cryptography is implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Implementation guidance

No content available.

CSF 2.0 crosswalk
PR.DS-01The confidentiality, integrity, and availability of data-at-rest are protectedProtect
PR.DS-02The confidentiality, integrity, and availability of data-in-transit are protectedProtect
PR.DS-10Protect