Security Questionnaire Mapper
Data protection and encryption ยท question family

Encryption in transit: the clause the question tests

Whether data is protected on the wire, on which paths and with which protocol versions.

How the customer usually asks it

example

"Is all data encrypted in transit using TLS 1.2 or higher?"

Read this question

Anchor clauses

5 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20228.24 Use of cryptography
CSA Cloud Controls Matrix v4.0.1CEK-03 Data Encryption
NIST Cybersecurity Framework 2.0PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
PCI DSS v4.0.14.2.1 Strong cryptography and security protocols are implemented
HIPAA Security Rule (45 CFR 164)164.312(e)(1) Transmission Security (Standard)

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The protocol versions and cipher settings in use on every external and internal path that carries the customer's data, and the certificate management record.

The clauses, with what an assessor asks for

ISO 27001 8.24 Use of cryptography

Define and implement rules for effective use of cryptography and key management.

Evidence an assessor expects: Encryption policy; Key management procedures; Algorithm inventory; Key usage records
Where answers usually fall short: Missing documented key lifecycle; Use of outdated or weak algorithms
Source: ISO/IEC 27001:2022
CSA CCM CEK-03 Data Encryption

What it asks for, in one line (the standard's own text is not quoted here):

Apply cryptographic protection to stored data and to data moving across networks, using libraries that hold certification against an approved standard.

Evidence an assessor expects: Configuration evidence showing encryption enabled at rest and in transit per system; The certification of the cryptographic libraries or modules in use, such as a validation certificate; Inventory of data stores and transport paths with their encryption status; Exceptions where encryption is not applied and the risk acceptance behind them
Where answers usually fall short: Encryption at rest claimed from a provider default without verification per data store; Uncertified or self-built cryptographic implementations in use
Source: CSA Cloud Controls Matrix v4.0.1
NIST CSF PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected

The confidentiality, integrity, and availability of data-in-transit are protected.

Evidence an assessor expects: TLS configuration standards and scan results; VPN and zero trust network access policy; Email transport encryption configuration; API security policy with mutual authentication; Network traffic encryption audit
Where answers usually fall short: Weak ciphers still permitted for legacy clients; Internal traffic unencrypted
Source: NIST Cybersecurity Framework 2.0
PCI DSS 4.2.1 Strong cryptography and security protocols are implemented

What it asks for, in one line (the standard's own text is not quoted here):

Strong cryptography and security protocols are implemented as follows to safeguard PAN during transmission over open, public networks:; Only trusted keys and certificates are accepted.; Certificates used to safeguard PAN during transmission

Evidence an assessor expects: Documented policies and procedures defining trusted keys and certificates, and the protocol and cipher suites accepted; System configurations for each PAN transmission endpoint showing the strong cryptography and protocols implemented; Evidence of certificate validity checking, including expiry and revocation status, at the point of transmission; Captured transmission samples or scan output confirming PAN is not sent in the clear on any open public network path; Inventory of trusted keys and certificates in use for safeguarding PAN
Where answers usually fall short: Revocation checking disabled or failing open, so a revoked certificate is still accepted; Strong configuration on the primary endpoint while legacy, failover or administrative endpoints accept weak protocols
Source: PCI DSS v4.0.1
HIPAA 164.312(e)(1) Transmission Security (Standard)

Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network. NIST recommends encrypted transport, secure email, and validated VPN.

Evidence an assessor expects: Transport encryption standard; TLS configuration scans; Secure email gateway records; VPN configuration evidence
Where answers usually fall short: Legacy TLS versions enabled; FTP and SMTP used in clear
Source: HIPAA Security Rule (45 CFR 164)

Other families in data protection and encryption