← Back to catalog
SI-4(10)

Visibility of Encrypted Communications

System and Information Integrity (SI)
Baselines
Low · Not includedModerate · Not includedHigh · Included
Description

Make provisions so that [assignment] is visible to [assignment].

Discussion

Organizations balance the need to encrypt communications traffic to protect data confidentiality with the need to maintain visibility into such traffic from a monitoring perspective. Organizations determine whether the visibility requirement applies to internal encrypted traffic, encrypted traffic intended for external destinations, or a subset of the traffic types.

Implementation guidance

No content available.

CSF 2.0 crosswalk

No CSF mappings exist for this control.