NIST 800-53 r5 · Controls catalogue · Family SC
SC-8Transmission Confidentiality and Integrity
Protect the {{ insert: param, sc-08_odp }} of transmitted information.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (10)
- aws-config-elb-tls-https-listeners-only ELB / ALB listeners use HTTPS or TLS AWS::ElasticLoadBalancingV2::Listener partial protect enforce
- aws-config-alb-http-to-https-redirection-check Alb Http To Https Redirection Check AWS::ElasticLoadBalancingV2::LoadBalancer partial protect enforce
- aws-config-api-gw-ssl-enabled Api Gw Ssl Enabled AWS::ApiGateway::Stage partial protect enforce
- aws-config-elasticsearch-node-to-node-encryption-check Elasticsearch Node To Node Encryption Check AWS::OpenSearchService::Domain partial protect enforce
- aws-config-elb-acm-certificate-required Elb Acm Certificate Required AWS::ElasticLoadBalancing::LoadBalancer partial protect enforce
- aws-config-elbv2-acm-certificate-required Elbv2 Acm Certificate Required AWS::ElasticLoadBalancingV2::LoadBalancer partial protect enforce
- aws-config-opensearch-https-required Opensearch Https Required AWS::OpenSearchService::Domain partial protect enforce
- aws-config-opensearch-node-to-node-encryption-check Opensearch Node To Node Encryption Check AWS::OpenSearchService::Domain partial protect enforce
- aws-config-redshift-require-tls-ssl Redshift Require Tls Ssl AWS::Redshift::Cluster partial protect enforce
- aws-config-s3-bucket-ssl-requests-only S3 Bucket Ssl Requests Only AWS::S3::Bucket partial protect enforce CIS §2.1.1Hub S3.5
ATT&CK techniques this control mitigates (19)
- T1020.001 Traffic Duplication Exfiltration
- T1040 Network Sniffing Credential Access, Discovery
- T1090 Proxy Command And Control
- T1090.004 Domain Fronting Command And Control
- T1550.001 Application Access Token Lateral Movement
- T1550.004 Web Session Cookie Lateral Movement
- T1552.007 Container API Credential Access
- T1557 Adversary-in-the-Middle Credential Access, Collection
- T1557.001 Name Resolution Poisoning and SMB Relay Credential Access, Collection
- T1557.002 ARP Cache Poisoning Credential Access, Collection
- T1557.003 DHCP Spoofing Credential Access, Collection
- T1557.004 Evil Twin Credential Access, Collection
- T1602 Data from Configuration Repository Collection
- T1602.001 SNMP (MIB Dump) Collection
- T1602.002 Network Device Configuration Dump Collection
- T1622 Debugger Evasion Stealth, Discovery
- T1685 Disable or Modify Tools Defense Impairment
- T1688 Safe Mode Boot Defense Impairment
- T1689 Downgrade Attack Defense Impairment
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-319 | Cleartext Transmission of Sensitive Information | 1,000+ | The control explicitly requires confidentiality protection for transmitted information, preventing cleartext exposure of sensitive data. |
CWE-614 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute | 65 | Enforcing confidentiality on transmitted sensitive cookies requires the Secure attribute, preventing exposure on insecure channels. |
CWE-300 | Channel Accessible by Non-Endpoint | 55 | Confidentiality and integrity protections on the transmission channel directly reduce the ability of non-endpoint actors to access or tamper with the data. |
CWE-924 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel | 44 | The control directly mandates integrity protection for transmitted information, addressing failures to enforce message integrity in transit. |
CWE-523 | Unprotected Transport of Credentials | 25 | Requiring protected transport for credentials directly mitigates unprotected credential transmission over networks. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-25735 UPD | 8.9 | 9.1 | 0.5062 | good |
CVE-2025-54309 KEV UPD | 8.9 | 9.0 | 0.9436 | good |
CVE-2025-13315 UPD | 8.9 | 9.8 | 0.3253 | good |
CVE-2023-39245 UPD | 7.4 | 9.8 | 0.0059 | good |
CVE-2024-3596 UPD | 7.4 | 9.0 | 0.1486 | good |
CVE-2025-34271 | 7.4 | 9.8 | 0.0069 | good |
CVE-2025-26199 UPD | 7.3 | 9.8 | 0.0049 | good |
CVE-2025-32880 UPD | 7.3 | 9.8 | 0.0040 | good |
CVE-2025-4378 UPD | 7.3 | 10.0 | 0.0029 | good |
CVE-2025-69270 | 7.2 | 9.8 | 0.0029 | partial |
CVE-2026-48902 UPD | 7.2 | 9.8 | 0.0025 | good |
CVE-2026-74880 | 7.2 | 9.8 | 0.0031 | partial |
CVE-2025-47419 UPD | 7.0 | 10.0 | 0.0028 | good |
CVE-2025-52921 UPD | 7.0 | 9.9 | 0.0048 | good |
CVE-2026-76244 | 7.0 | 9.1 | 0.0022 | good |
CVE-2024-12378 UPD | 6.9 | 9.1 | 0.0050 | good |
CVE-2024-44730 UPD | 6.8 | 9.1 | 0.0043 | good |
CVE-2024-6515 UPD | 6.8 | 9.6 | 0.0040 | good |
CVE-2024-1509 UPD | 6.8 | 9.1 | 0.0036 | good |
CVE-2025-8037 UPD | 6.7 | 9.1 | 0.0022 | good |
CVE-2025-65827 UPD | 6.7 | 9.1 | 0.0026 | good |
CVE-2026-24060 | 6.7 | 9.1 | 0.0020 | good |
CVE-2024-30209 UPD | 6.6 | 9.6 | 0.0027 | good |
CVE-2025-57800 UPD | 6.6 | 8.8 | 0.0046 | good |
CVE-2024-50634 | 6.5 | 8.8 | 0.0044 | good |