| SC-13(1) | System and Communications Protection | FIPS-validated Cryptography |
| SC-13(2) | System and Communications Protection | NSA-approved Cryptography |
| SC-13(3) | System and Communications Protection | Individuals Without Formal Access Approvals |
| SC-13(4) | System and Communications Protection | Digital Signatures |
| SC-14 | System and Communications Protection | Public Access Protections |
| SC-15 | System and Communications Protection | Collaborative Computing Devices and Applications |
| SC-15(1) | System and Communications Protection | Physical or Logical Disconnect |
| SC-15(2) | System and Communications Protection | Blocking Inbound and Outbound Communications Traffic |
| SC-15(3) | System and Communications Protection | Disabling and Removal in Secure Work Areas |
| SC-15(4) | System and Communications Protection | Explicitly Indicate Current Participants |
| SC-16 | System and Communications Protection | Transmission of Security and Privacy Attributes |
| SC-16(1) | System and Communications Protection | Integrity Verification |
| SC-16(2) | System and Communications Protection | Anti-spoofing Mechanisms |
| SC-16(3) | System and Communications Protection | Cryptographic Binding |
| SC-17 | System and Communications Protection | Public Key Infrastructure Certificates |
| SC-18 | System and Communications Protection | Mobile Code |
| SC-18(1) | System and Communications Protection | Identify Unacceptable Code and Take Corrective Actions |
| SC-18(2) | System and Communications Protection | Acquisition, Development, and Use |
| SC-18(3) | System and Communications Protection | Prevent Downloading and Execution |
| SC-18(4) | System and Communications Protection | Prevent Automatic Execution |
| SC-18(5) | System and Communications Protection | Allow Execution Only in Confined Environments |
| SC-19 | System and Communications Protection | Voice Over Internet Protocol |
| SC-2 | System and Communications Protection | Separation of System and User Functionality |
| SC-2(1) | System and Communications Protection | Interfaces for Non-privileged Users |
| SC-2(2) | System and Communications Protection | Disassociability |
| SC-20 | System and Communications Protection | Secure Name/Address Resolution Service (Authoritative Source) |
| SC-20(1) | System and Communications Protection | Child Subspaces |
| SC-20(2) | System and Communications Protection | Data Origin and Integrity |
| SC-21 | System and Communications Protection | Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| SC-21(1) | System and Communications Protection | Data Origin and Integrity |
| SC-22 | System and Communications Protection | Architecture and Provisioning for Name/Address Resolution Service |
| SC-23 | System and Communications Protection | Session Authenticity |
| SC-23(1) | System and Communications Protection | Invalidate Session Identifiers at Logout |
| SC-23(2) | System and Communications Protection | User-initiated Logouts and Message Displays |
| SC-23(3) | System and Communications Protection | Unique System-generated Session Identifiers |
| SC-23(4) | System and Communications Protection | Unique Session Identifiers with Randomization |
| SC-23(5) | System and Communications Protection | Allowed Certificate Authorities |
| SC-24 | System and Communications Protection | Fail in Known State |
| SC-25 | System and Communications Protection | Thin Nodes |
| SC-26 | System and Communications Protection | Decoys |
| SC-26(1) | System and Communications Protection | Detection of Malicious Code |
| SC-27 | System and Communications Protection | Platform-independent Applications |
| SC-28 | System and Communications Protection | Protection of Information at Rest |
| SC-28(1) | System and Communications Protection | Cryptographic Protection |
| SC-28(2) | System and Communications Protection | Offline Storage |
| SC-28(3) | System and Communications Protection | Cryptographic Keys |
| SC-29 | System and Communications Protection | Heterogeneity |
| SC-29(1) | System and Communications Protection | Virtualization Techniques |
| SC-3 | System and Communications Protection | Security Function Isolation |
| SC-3(1) | System and Communications Protection | Hardware Separation |