unified
UC-CRYPTO-04 — Protect data in use from unauthorized access
Data being processed in memory or active sessions is protected against unauthorized access and exposure through techniques commensurate with risk, including process isolation, memory protections, masking of sensitive fields on display, and confidential-computing or equivalent enclave technologies for high-sensitivity workloads. Access to data in use is limited to the processing identity, and residual data is cleared from memory and temporary storage after use.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Cryptography & Key Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CRYPTO-04
- title
- Protect data in use from unauthorized access
- statement
- Data being processed in memory or active sessions is protected against unauthorized access and exposure through techniques commensurate with risk, including process isolation, memory protections, masking of sensitive fields on display, and confidential-computing or equivalent enclave technologies for high-sensitivity workloads. Access to data in use is limited to the processing identity, and residual data is cleared from memory and temporary storage after use.
- domain
- Cryptography & Key Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-csf-2
- control_id
- PR.DS-10
- coverage
- full
- relationship
- equal
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-CRYPTO-04 — Protect data in use from unauthorized access
- Data Encryption & In-Use Protection Operations operates UC-CRYPTO-04 — Protect data in use from unauthorized access
- UC-CRYPTO-04 — Protect data in use from unauthorized access mitigates Weak or absent encryption and key management
- strength
- primary
- rationale
- protecting data in use (memory/session encryption, enclaves) extends cryptographic coverage to active data, closing the residual exposure that at-rest/in-transit encryption leaves open
- UC-CRYPTO-04 — Protect data in use from unauthorized access mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- related
- rationale
- session/memory protection reduces exposure of data held in active communication sessions
- UC-CRYPTO-04 — Protect data in use from unauthorized access maps_to PR.DS-10 — Data Security: The confidentiality, integrity, and availability of data-in-use are protected
- framework
- nist-csf-2
- control_id
- PR.DS-10
- coverage
- full
- relationship
- equal
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.