Trusted Communications Channels
LOW MODERATE HIGHRequirements NIST SOURCE
Implement the security design principle of trusted communications channels in [systems or system components].
Discussion (NIST Supplemental Guidance)
The principle of trusted communication channels states that when composing a system where there is a potential threat to communications between components (i.e., the interconnections between components), each communication channel is trustworthy to a level commensurate with the security dependencies it supports (i.e., how much it is trusted by other components to perform its security functions). Trusted communication channels are achieved by a combination of restricting access to the communication channel (to ensure an acceptable match in the trustworthiness of the endpoints involved in the communication) and employing end-to-end protections for the data transmitted over the communication channel (to protect against interception and modification and to further increase the assurance of proper end-to-end communication).
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SA-8(18) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- systems or system components that implement the security design principle of trusted communications channels are defined;
- <SA-08(18)_ODP systems or system components> implement the security design principle of trusted communications channels.
Examine
[SELECT FROM: System and services acquisition policy; procedures addressing the security design principle of trusted communications channels used in the specification, design, development, implementation, and modification of the system; system design documentation; security and privacy requirements and specifications for the system; system security and privacy architecture; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with the responsibility for determining system security and privacy requirements; organizational personnel with system specification, design, development, implementation, and modification responsibilities; system developers; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for applying the security design principle of trusted communications channels in system specification, design, development, implementation, and modification; mechanisms supporting the application of the security design principle of trusted communications channels in system specification, design, development, implementation, and modification].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SA-8(18). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and services acquisition policy
- system security plan
Configuration
- system design documentation
- system security and privacy architecture
Testing
- Organizational processes for applying the security design principle of trusted communications channels in system specification, design, development, implementation, and modification
- mechanisms supporting the application of the security design principle of trusted communications channels in system specification, design, development, implementation, and modification
Other Records
- procedures addressing the security design principle of trusted communications channels used in the specification, design, development, implementation, and modification of the system
- security and privacy requirements and specifications for the system
- other relevant documents or records