1Overview
SC.L2-3.13.8 protects CUI as it moves across the network. It requires that cryptographic mechanisms be implemented to prevent unauthorized disclosure of CUI during transmission, unless the CUI is otherwise protected by alternative physical safeguards. It is a three-point requirement that cannot be deferred on a plan of action.
CUI in transit crosses network paths where it can be intercepted, and once intercepted, unencrypted CUI is disclosed. This control requires protecting CUI during transmission, and it offers two acceptable means: cryptographic mechanisms, encrypting the data in transit, or alternative physical safeguards, such as a protected distribution system, where the physical path itself prevents interception. The organization identifies which mechanisms and safeguards it will use and then implements one or the other to protect transmitted CUI. The three assessment objectives cover identifying the cryptographic mechanisms, identifying any alternative physical safeguards, and implementing protection during transmission.
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
The requirement is to prevent unauthorized disclosure of CUI during transmission through cryptographic mechanisms, with alternative physical safeguards as an accepted substitute. The assessment objectives split this into identifying the cryptographic mechanisms intended for this purpose, identifying any alternative physical safeguards, and implementing either the cryptographic mechanisms or the physical safeguards to protect CUI in transit. In most environments this means encrypting CUI whenever it crosses the network.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.13.8 into three objectives: identify cryptographic mechanisms, identify alternative physical safeguards, and implement one to protect CUI in transit.
Cryptographic mechanisms intended to prevent unauthorized disclosure of CUI during transmission are identified. The encryption to use is chosen.
Alternative physical safeguards intended to prevent unauthorized disclosure of CUI during transmission are identified. Any physical alternative is chosen.
Either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. Protection is actually applied.
The three objectives are identifying the two means and implementing one. The common failure is at objective [c], where CUI is transmitted over paths that are not consistently encrypted. The assessor looks for the mechanisms identified and protection actually implemented for CUI in transit.
3Failure Patterns
The failures are about CUI transmitted without protection.
Unencrypted transmission paths
CUI sent over paths that are not encrypted can be intercepted and disclosed. Implementing encryption on those paths protects it.
Encryption on some paths only
Protecting CUI on some transmission paths while leaving others in the clear leaves gaps. Protection has to cover the CUI in transit.
Mechanisms not identified
Without identifying the cryptographic mechanisms or physical safeguards to use, implementation is ad hoc. Identification is the basis for consistent protection.
4Ownership
This is an IT and network-owned technical control.
| Role | Responsibility for this control |
|---|---|
| IT and network | Implements encryption on CUI transmission paths. Owns the encryption configuration. |
| Security or compliance lead | Identifies the mechanisms and confirms CUI in transit is protected. |
| Program lead | Documents the transmission protection in the system security plan. |
5Tooling
The control is delivered by encryption of CUI in transit, or physical safeguards where used.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | TLS, VPN, encrypted protocols | Identified cryptographic mechanisms for transit. |
| [b] | Protected distribution system | Identified physical alternative where used. |
| [c] | Encryption implemented on transmission paths | CUI protected in transit. |
The caveat is that protection has to cover the paths CUI actually travels, and the cryptography should meet the FIPS-validation requirement that accompanies this control. Encryption on some paths but not others, or non-validated cryptography, leaves exposure. The assessor examines identification and implementation, so all three objectives have to hold.
6Evidence
The satisfied version of 3.13.8 shows CUI protected in transit.
| Evidence | What it demonstrates |
|---|---|
| Identified mechanisms and safeguards | Objectives [a], [b]. The means chosen. |
| Encryption configuration | Objective [c]. CUI protected in transit. |
The evidence should show identified cryptographic mechanisms or physical safeguards and their implementation on CUI transmission paths. The identified mechanisms together with the encryption configuration are the clearest demonstration, and because this control cannot sit on a plan of action, the protection has to be real at the time of assessment.
CUI in transit is exposed unless it is protected
Data crossing the network can be intercepted, so this three-point control asks that CUI be protected in transit by encryption or physical safeguards. Implementing that protection on the paths CUI travels is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.8. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.8[a] through 3.13.8[c]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SC.L2-3.13.8 among the three-point derived security requirements. ecfr.gov