unified
UC-GOV-36 — Maintain communications security and cryptography policies
Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-36
- title
- Maintain communications security and cryptography policies
- statement
- Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SC-1
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21h
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21j
- coverage
- partial
- delta
- actual deployment of MFA and secured emergency communication systems
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-GOV-36 — Maintain communications security and cryptography policies
- Policy Lifecycle Management oversees UC-GOV-36 — Maintain communications security and cryptography policies
- UC-GOV-36 — Maintain communications security and cryptography policies mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Establishing communications-security and cryptography policies (encryption, MFA expectations) remedies missing policy for this domain.
- UC-GOV-36 — Maintain communications security and cryptography policies maps_to NIS2-Art21h — Policies on the use of cryptography and encryption
- framework
- nis2
- control_id
- NIS2-Art21h
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-36 — Maintain communications security and cryptography policies maps_to SC-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- SC-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-36 — Maintain communications security and cryptography policies maps_to NIS2-Art21j — Use of multi-factor authentication, secured communications and emergency communication systems
- framework
- nis2
- control_id
- NIS2-Art21j
- coverage
- partial
- delta
- actual deployment of MFA and secured emergency communication systems
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Policy Suite Review operates UC-GOV-36 — Maintain communications security and cryptography policies