Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
System and Communications Protection · Enhancement
SC-12(3) · Asymmetric Keys
View parent controlControl statement and discussion
NIST control statement
Produce, control, and distribute asymmetric cryptographic keys using [Selection (one): NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user’s private key; certificates issued in accordance with organization-defined requirements].
Discussion
[SP 800-56A](#20957dbb-6a1e-40a2-b38a-66f67d33ac2e), [SP 800-56B](#0d083d8a-5cc6-46f1-8d79-3081d42bcb75) , and [SP 800-56C](#eef62b16-c796-4554-955c-505824135b8a) provide guidance on cryptographic key establishment schemes and key derivation methods. [SP 800-57-1](#110e26af-4765-49e1-8740-6750f83fcda1), [SP 800-57-2](#e7942589-e267-4a5a-a3d9-f39a7aae81f0) , and [SP 800-57-3](#8306620b-1920-4d73-8b21-12008528595f) provide guidance on cryptographic key management.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-12(6) · Physical Control of Keys
View parent controlControl statement and discussion
NIST control statement
Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.
Discussion
For organizations that use external service providers (e.g., cloud service or data center providers), physical control of cryptographic keys provides additional assurance that information stored by such external providers is not subject to unauthorized disclosure or modification.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-13 · Cryptographic Protection
Control statement and discussion
NIST control statement
a. Determine the [Assignment: cryptographic uses] ; and
b. Implement the following types of cryptography required for each specified cryptographic use: [Assignment: types of cryptography].
Discussion
Cryptography can be employed to support a variety of security solutions, including the protection of classified information and controlled unclassified information, the provision and implementation of digital signatures, and the enforcement of information separation when authorized individuals have the necessary clearances but lack the necessary formal access approvals. Cryptography can also be used to support random number and hash generation. Generally applicable cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography. For example, organizations that need to protect classified information may specify the use of NSA-approved cryptography. Organizations that need to provision and implement digital signatures may specify the use of FIPS-validated cryptography. Cryptography is implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · SC-13 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · SC-13 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Base control
SC-15 · Collaborative Computing Devices and Applications
Control statement and discussion
NIST control statement
a. Prohibit remote activation of collaborative computing devices and applications with the following exceptions: [Assignment: exceptions where remote activation is to be allowed] ; and
b. Provide an explicit indication of use to users physically present at the devices.
Discussion
Collaborative computing devices and applications include remote meeting devices and applications, networked white boards, cameras, and microphones. The explicit indication of use includes signals to users when collaborative computing devices and applications are activated.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-15 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-15(1) · Physical or Logical Disconnect
View parent controlControl statement and discussion
NIST control statement
Provide [Selection (one-or-more): physical; logical] disconnect of collaborative computing devices in a manner that supports ease of use.
Discussion
Failing to disconnect from collaborative computing devices can result in subsequent compromises of organizational information. Providing easy methods to disconnect from such devices after a collaborative computing session ensures that participants carry out the disconnect activity without having to go through complex and tedious procedures. Disconnect from collaborative computing devices can be manual or automatic.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-15(3) · Disabling and Removal in Secure Work Areas
View parent controlControl statement and discussion
NIST control statement
Disable or remove collaborative computing devices and applications from [Assignment: systems or system components] in [Assignment: secure work areas].
Discussion
Failing to disable or remove collaborative computing devices and applications from systems or system components can result in compromises of information, including eavesdropping on conversations. A Sensitive Compartmented Information Facility (SCIF) is an example of a secure work area.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-15(4) · Explicitly Indicate Current Participants
View parent controlControl statement and discussion
NIST control statement
Provide an explicit indication of current participants in [Assignment: online meetings and teleconferences].
Discussion
Explicitly indicating current participants prevents unauthorized individuals from participating in collaborative computing sessions without the explicit knowledge of other participants.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-16 · Transmission of Security and Privacy Attributes
Control statement and discussion
NIST control statement
Associate [Assignment: organization-defined security and privacy attributes] with information exchanged between systems and between system components.
Discussion
Security and privacy attributes can be explicitly or implicitly associated with the information contained in organizational systems or system components. Attributes are abstractions that represent the basic properties or characteristics of an entity with respect to protecting information or the management of personally identifiable information. Attributes are typically associated with internal data structures, including records, buffers, and files within the system. Security and privacy attributes are used to implement access control and information flow control policies; reflect special dissemination, management, or distribution instructions, including permitted uses of personally identifiable information; or support other aspects of the information security and privacy policies. Privacy attributes may be used independently or in conjunction with security attributes.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-16(1) · Integrity Verification
View parent controlControl statement and discussion
NIST control statement
Verify the integrity of transmitted security and privacy attributes.
Discussion
Part of verifying the integrity of transmitted information is ensuring that security and privacy attributes that are associated with such information have not been modified in an unauthorized manner. Unauthorized modification of security or privacy attributes can result in a loss of integrity for transmitted information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-16(2) · Anti-spoofing Mechanisms
View parent controlControl statement and discussion
NIST control statement
Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.
Discussion
Some attack vectors operate by altering the security attributes of an information system to intentionally and maliciously implement an insufficient level of security within the system. The alteration of attributes leads organizations to believe that a greater number of security functions are in place and operational than have actually been implemented.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-16(3) · Cryptographic Binding
View parent controlControl statement and discussion
NIST control statement
Implement [Assignment: mechanisms or techniques] to bind security and privacy attributes to transmitted information.
Discussion
Cryptographic mechanisms and techniques can provide strong security and privacy attribute binding to transmitted information to help ensure the integrity of such information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-17 · Public Key Infrastructure Certificates
Control statement and discussion
NIST control statement
a. Issue public key certificates under an [Assignment: certificate policy] or obtain public key certificates from an approved service provider; and
b. Include only approved trust anchors in trust stores or certificate stores managed by the organization.
Discussion
Public key infrastructure (PKI) certificates are certificates with visibility external to organizational systems and certificates related to the internal operations of systems, such as application-specific time services. In cryptographic systems with a hierarchical structure, a trust anchor is an authoritative source (i.e., a certificate authority) for which trust is assumed and not derived. A root certificate for a PKI system is an example of a trust anchor. A trust store or certificate store maintains a list of trusted root certificates.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-17 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Base control
SC-18 · Mobile Code
Control statement and discussion
NIST control statement
a. Define acceptable and unacceptable mobile code and mobile code technologies; and
b. Authorize, monitor, and control the use of mobile code within the system.
Discussion
Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-18 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-18(1) · Identify Unacceptable Code and Take Corrective Actions
View parent controlControl statement and discussion
NIST control statement
Identify [Assignment: unacceptable mobile code] and take [Assignment: corrective actions].
Discussion
Corrective actions when unacceptable mobile code is detected include blocking, quarantine, or alerting administrators. Blocking includes preventing the transmission of word processing files with embedded macros when such macros have been determined to be unacceptable mobile code.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-18(2) · Acquisition, Development, and Use
View parent controlControl statement and discussion
NIST control statement
Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [Assignment: mobile code requirements].
Discussion
None.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-18(3) · Prevent Downloading and Execution
View parent controlControl statement and discussion
NIST control statement
Prevent the download and execution of [Assignment: unacceptable mobile code].
Discussion
None.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-18(4) · Prevent Automatic Execution
View parent controlControl statement and discussion
NIST control statement
Prevent the automatic execution of mobile code in [Assignment: software applications] and enforce [Assignment: actions] prior to executing the code.
Discussion
Actions enforced before executing mobile code include prompting users prior to opening email attachments or clicking on web links. Preventing the automatic execution of mobile code includes disabling auto-execute features on system components that employ portable storage devices, such as compact discs, digital versatile discs, and universal serial bus devices.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-18(5) · Allow Execution Only in Confined Environments
View parent controlControl statement and discussion
NIST control statement
Allow execution of permitted mobile code only in confined virtual machine environments.
Discussion
Permitting the execution of mobile code only in confined virtual machine environments helps prevent the introduction of malicious code into other systems and system components.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-20 · Secure Name/Address Resolution Service (Authoritative Source)
Control statement and discussion
NIST control statement
a. Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and
b. Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.
Discussion
Providing authoritative source information enables external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for the host/service name to network address resolution information obtained through the service. Systems that provide name and address resolution services include domain name system (DNS) servers. Additional artifacts include DNS Security Extensions (DNSSEC) digital signatures and cryptographic keys. Authoritative data includes DNS resource records. The means for indicating the security status of child zones include the use of delegation signer resource records in the DNS. Systems that use technologies other than the DNS to map between host and service names and network addresses provide other means to assure the authenticity and integrity of response data.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-20 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-20(2) · Data Origin and Integrity
View parent controlControl statement and discussion
NIST control statement
Provide data origin and integrity protection artifacts for internal name/address resolution queries.
Discussion
None.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-21 · Secure Name/Address Resolution Service (Recursive or Caching Resolver)
Control statement and discussion
NIST control statement
Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.
Discussion
Each client of name resolution services either performs this validation on its own or has authenticated channels to trusted validation providers. Systems that provide name and address resolution services for local clients include recursive resolving or caching domain name system (DNS) servers. DNS client resolvers either perform validation of DNSSEC signatures, or clients use authenticated channels to recursive resolvers that perform such validations. Systems that use technologies other than the DNS to map between host and service names and network addresses provide some other means to enable clients to verify the authenticity and integrity of response data.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · SC-21 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · SC-21 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Base control
SC-22 · Architecture and Provisioning for Name/Address Resolution Service
Control statement and discussion
NIST control statement
Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.
Discussion
Systems that provide name and address resolution services include domain name system (DNS) servers. To eliminate single points of failure in systems and enhance redundancy, organizations employ at least two authoritative domain name system servers—one configured as the primary server and the other configured as the secondary server. Additionally, organizations typically deploy the servers in two geographically separated network subnetworks (i.e., not located in the same physical facility). For role separation, DNS servers with internal roles only process name and address resolution requests from within organizations (i.e., from internal clients). DNS servers with external roles only process name and address resolution information requests from clients external to organizations (i.e., on external networks, including the Internet). Organizations specify clients that can access authoritative DNS servers in certain roles (e.g., by address ranges and explicit lists).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-22 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Base control
SC-23 · Session Authenticity
Control statement and discussion
NIST control statement
Protect the authenticity of communications sessions.
Discussion
Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of communications sessions in the ongoing identities of other parties and the validity of transmitted information. Authenticity protection includes protecting against "man-in-the-middle" attacks, session hijacking, and the insertion of false information into sessions.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-23 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-23(1) · Invalidate Session Identifiers at Logout
View parent controlControl statement and discussion
NIST control statement
Invalidate session identifiers upon user logout or other session termination.
Discussion
Invalidating session identifiers at logout curtails the ability of adversaries to capture and continue to employ previously valid session IDs.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-23(3) · Unique System-generated Session Identifiers
View parent controlControl statement and discussion
NIST control statement
Generate a unique session identifier for each session with [Assignment: randomness requirements] and recognize only session identifiers that are system-generated.
Discussion
Generating unique session identifiers curtails the ability of adversaries to reuse previously valid session IDs. Employing the concept of randomness in the generation of unique session identifiers protects against brute-force attacks to determine future session identifiers.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.