Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-8Transmission Confidentiality and Integrity

Protect the {{ insert: param, sc-08_odp }} of transmitted information.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (1)

ATT&CK techniques this control mitigates (19)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-319Cleartext Transmission of Sensitive Information1,042The control explicitly requires confidentiality protection for transmitted information, preventing cleartext exposure of sensitive data.
CWE-300Channel Accessible by Non-Endpoint53Confidentiality and integrity protections on the transmission channel directly reduce the ability of non-endpoint actors to access or tamper with the data.
CWE-614Sensitive Cookie in HTTPS Session Without 'Secure' Attribute52Enforcing confidentiality on transmitted sensitive cookies requires the Secure attribute, preventing exposure on insecure channels.
CWE-924Improper Enforcement of Message Integrity During Transmission in a Communication Channel36The control directly mandates integrity protection for transmitted information, addressing failures to enforce message integrity in transit.
CWE-523Unprotected Transport of Credentials20Requiring protected transport for credentials directly mitigates unprotected credential transmission over networks.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2022-33655.19.80.5260good
CVE-2025-342712.09.80.0106good
CVE-2025-28592.09.80.0034good
CVE-2025-632102.09.80.0014good
CVE-2025-139262.09.80.0009good
CVE-2026-423631.99.30.0003good
CVE-2026-71611.99.30.0004good
CVE-2024-15091.89.10.0009good
CVE-2026-240601.89.10.0002good
CVE-2025-05561.88.80.0015good
CVE-2025-686371.89.10.0006good
CVE-2025-214501.89.10.0020good
CVE-2024-475191.78.30.0008good
CVE-2025-101741.78.30.0002good
CVE-2025-21901.68.10.0015good
CVE-2024-365531.68.10.0009good
CVE-2025-232061.68.10.0007good
CVE-2024-138721.67.50.0138good
CVE-2026-307921.68.10.0007good
CVE-2025-677521.68.10.0001good
CVE-2026-321051.57.70.0004good
CVE-2025-10601.57.50.0016good
CVE-2025-28611.57.50.0017good
CVE-2025-264731.57.50.0022good
CVE-2021-417191.57.50.0031good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-9