id: "SC-23" title: "Session Authenticity" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-23" priority: "P1" implementation_level: "system" enhancements: - sc-23.1 - sc-23.2 - sc-23.3 - sc-23.4 - sc-23.5


Statement

Protect the authenticity of communications sessions.

Guidance

Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of communications sessions in the ongoing identities of other parties and the validity of transmitted information. Authenticity protection includes protecting against "man-in-the-middle" attacks, session hijacking, and the insertion of false information into sessions.

Assessment Objective

the authenticity of communication sessions is protected.

System and communications protection policy

procedures addressing session authenticity

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

Mechanisms supporting and/or implementing session authenticity