FedRAMP Controls / AC

AC-17(2) Protection of Confidentiality and Integrity Using Encryption

Family AC
Baselines moderate
Mapped KSIs 3

Control statement

Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-IAM-05Least Privilege
_Persistently_ ensure that identity and access management employs measures to ensure each user or device can only access the resources they need.
Identity and Access Management
KSI-SVC-02Network Encryption
Encrypt or otherwise secure network traffic.
Service Configuration
KSI-SVC-06Secret Management
Automate management, protection, and regular rotation of digital keys, certificates, and other secrets.
Service Configuration