Skip to content

Data in Transit

What is Data in Transit?

Data that is actively moving from one location to another, such as across the internet or through a private network. Protecting data in transit typically requires encryption protocols such as TLS/SSL.

Information Security

Each of these is named in at least one of the same controls as data in transit. The number is how many controls name both.

What the standards actually require on data in transit

Requirements naming data in transit across 6 standards, quoted from the control text.

Encrypt sensitive data in transit. Example implementations include TLS and OpenSSH.

3.10 · Encrypt Sensitive Data in Transit

Enforce TLS 1.2 or higher for all data in transit and disable legacy protocols across Azure services.

DP-3 · Encrypt sensitive data in transit

Encrypt sensitive data in transit. Example implementations can include: Transport Layer Security (TLS) and Open Secure Shell (OpenSSH).

CIS-3.10 · Encrypt Sensitive Data in Transit
CMMC 2.01 control

Apply cryptographic protection to prevent unauthorized disclosure of CUI during transmission, unless alternative physical safeguards protect it instead.

SC.L2-3.13.8 · Data in Transit

Sensitive data is encrypted in transit using current TLS versions with strong cipher suites and certificate validation.

IS-IV.F.2 · Data in Transit Encryption
ISO 270431 control

Encryption of data in transit. Control from ISO 27043 framework, domain: ISO 27043: Cryptography.

ISO27043-18 · Encryption of data in transit

Questions people ask about data in transit

What is Data in Transit?
Data that is actively moving from one location to another, such as across the internet or through a private network. Protecting data in transit typically requires encryption protocols such as TLS/SSL.
Why is Data in Transit important for compliance?
Data in Transit is a key concept in Information Security. Understanding data in transit helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data in Transit?
Data in Transit appears in the requirement text of NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements, Azure Security Benchmark, CIS Controls v8, CMMC 2.0, FFIEC IT Examination Handbook. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data in Transit?
Explore our compliance framework pages to see how data in transit applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data in Transit applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.