id: "SC-23(05)" title: "Allowed Certificate Authorities" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-23.05" priority: "P1" implementation_level: "system" parent: "SC-23" enhancement: True


Statement

Only allow the use of {{ insert: param, sc-23.05_odp }} for verification of the establishment of protected sessions.

Guidance

Reliance on certificate authorities for the establishment of secure sessions includes the use of Transport Layer Security (TLS) certificates. These certificates, after verification by their respective certificate authorities, facilitate the establishment of protected sessions between web clients and web servers.

Assessment Objective

only the use of {{ insert: param, sc-23.05_odp }} for verification of the establishment of protected sessions is allowed.

System and communications protection policy

procedures addressing session authenticity

system design documentation

system configuration settings and associated documentation

list of certificate authorities allowed for verification of the establishment of protected sessions

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

Mechanisms supporting and/or implementing the management of certificate authorities