id: "SC-23" title: "Session Authenticity" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-23" priority: "P1" implementation_level: "system" enhancements: - sc-23.1 - sc-23.2 - sc-23.3 - sc-23.4 - sc-23.5
Statement
Protect the authenticity of communications sessions.
Guidance
Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of communications sessions in the ongoing identities of other parties and the validity of transmitted information. Authenticity protection includes protecting against "man-in-the-middle" attacks, session hijacking, and the insertion of false information into sessions.
Assessment Objective
the authenticity of communication sessions is protected.
System and communications protection policy
procedures addressing session authenticity
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
Mechanisms supporting and/or implementing session authenticity