{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Cryptography & Key Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-04","description":"Data being processed in memory or active sessions is protected against unauthorized access and exposure through techniques commensurate with risk, including process isolation, memory protections, masking of sensitive fields on display, and confidential-computing or equivalent enclave technologies for high-sensitivity workloads. Access to data in use is limited to the processing identity, and residual data is cleared from memory and temporary storage after use.","details":{"control_category":"technical","control_type":"preventive","domain":"Cryptography & Key Management","guidance":[],"members":[{"control_id":"PR.DS-10","coverage":"full","framework":"nist-csf-2","relationship":"equal"}],"statement":"Data being processed in memory or active sessions is protected against unauthorized access and exposure through techniques commensurate with risk, including process isolation, memory protections, masking of sensitive fields on display, and confidential-computing or equivalent enclave technologies for high-sensitivity workloads. Access to data in use is limited to the processing identity, and residual data is cleared from memory and temporary storage after use.","title":"Protect data in use from unauthorized access","unified_id":"UC-CRYPTO-04"},"id":"uc:UC-CRYPTO-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CRYPTO-04","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"UC-CRYPTO-04 — Protect data in use from unauthorized access","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02a2cd1428ce68a4467abdf2f81162e14ebabd1058d9a2e92df66bcbee47831a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","targetId":"uc:UC-CRYPTO-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24ab90dfdd49b75d1555acb1f931c03d52bb21b9f2275da9f651b386627e56ce","properties":{},"sourceDetailPath":"/data/v1/records/wf-c33-0d69c278.json","sourceId":"wf:C33","targetDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","targetId":"uc:UC-CRYPTO-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d7ed4cf34f1e7b868f597d323b1b8bd111160279bd908e186ab865856d550f4","properties":{"rationale":"protecting data in use (memory/session encryption, enclaves) extends cryptographic coverage to active data, closing the residual exposure that at-rest/in-transit encryption leaves open","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","sourceId":"uc:UC-CRYPTO-04","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64636910b275e35be75bc6717dd97f4eebe76c4402e63289b791d8ecb53084c8","properties":{"rationale":"session/memory protection reduces exposure of data held in active communication sessions","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","sourceId":"uc:UC-CRYPTO-04","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b6fb2f7672985d2036e3de2f76507ef1bd9c15152269cdc496e9b5a2146402da","properties":{"control_id":"PR.DS-10","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","sourceId":"uc:UC-CRYPTO-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-10-0ec91e33.json","targetId":"ctrl:nist-csf-2:PR.DS-10","type":"maps_to"}],"schemaVersion":1}
