{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-03","description":"Provide trusted, mutually authenticated communication paths for security-relevant interactions, and protect the authenticity and integrity of communication sessions to prevent hijacking, insertion, and replay. Terminate network connections at the end of a session or after a defined period of inactivity, and use separate out-of-band channels for delivering sensitive items such as credentials and keys.","details":{"control_category":"technical","control_type":"preventive","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"SC-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-23","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-37","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Provide trusted, mutually authenticated communication paths for security-relevant interactions, and protect the authenticity and integrity of communication sessions to prevent hijacking, insertion, and replay. Terminate network connections at the end of a session or after a defined period of inactivity, and use separate out-of-band channels for delivering sensitive items such as credentials and keys.","title":"Provide trusted channels and control session lifecycle","unified_id":"UC-NET-03"},"id":"uc:UC-NET-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-03","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-NET-03 — Provide trusted channels and control session lifecycle","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01144b49309d686dda87005af303cb45294f11ef813ebde7d588e64322fb6246","properties":{"rationale":"Terminating connections after inactivity addresses unattended-session/no-logout exposure; primary auth strength owned elsewhere.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:07177a3f7e3ffe9985d0f4ae8a1eedec15864128e7c1b49ef7bf99b801d7d586","properties":{},"sourceDetailPath":"/data/v1/records/wf-c49-5eff4769.json","sourceId":"wf:C49","targetDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","targetId":"uc:UC-NET-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e4930031c4e98fa0337179a0ed2f2875f81c6d640db01e0ba749bffe03ae534","properties":{"control_id":"SC-23","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-23-77326ab3.json","targetId":"ctrl:nist-800-53:SC-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:307aaa3ff6067b1987301898f2760743c0a955ddcf88d86094502fc3c7fb86d6","properties":{"rationale":"Trusted, mutually authenticated communication paths plus session-integrity protection prevent man-in-the-middle interception and insertion.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3df2bd66c760ef78fab8316f9b69e16cbf9ddcfc66e1467a4de904a126aab525","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","targetId":"uc:UC-NET-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a26f064f6fdca3ab5a9a4b3649202a67d4c520e37219c67a9d8c557b488e46b","properties":{"rationale":"Out-of-band delivery of credentials/keys plus mutually authenticated trusted paths prevent credential capture and spoofing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/risk-crypto-cleartext-credential-transfer-b88065a1.json","targetId":"risk:crypto-cleartext-credential-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f6e51d66c8d0b2a96b0b134c44e84ebfbb8c8098c96ef577c6324572401336b","properties":{"control_id":"SC-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-10-01b0320e.json","targetId":"ctrl:nist-800-53:SC-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:508d48e43e853b5f261e6cc67e51ce2a82956879a49ddd2a6cdb9d7248b971fe","properties":{"control_id":"SC-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-11-971f92bc.json","targetId":"ctrl:nist-800-53:SC-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:837d75050ef7daf3f5cdeab8b49e77ac136232fece5402441b5dd9eff67b47f5","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","targetId":"uc:UC-NET-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a3b0a06f9c8d8eb02d152c15cf1dde5e8425eab7f8340834aaacacb6a83ed489","properties":{"control_id":"SC-37","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-37-370be823.json","targetId":"ctrl:nist-800-53:SC-37","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc8ea202106a924ddb3a875e605bb3d30f1dadb05a4863351a30bc2825213f92","properties":{"rationale":"Protecting session authenticity/integrity against hijacking, insertion, and replay and terminating idle sessions is the operative session-hijacking defense.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/risk-net-session-hijacking-434ddd0c.json","targetId":"risk:net-session-hijacking","type":"mitigates"}],"schemaVersion":1}
