Enclave
What is Enclave?
A network segment with specific security requirements that is separated from other segments through access controls and monitoring.
Frameworks that govern enclave
What the standards actually require on enclave
Requirements naming enclave across 6 standards, quoted from the control text.
Places a gateway PEP at the boundary of a resource enclave (a group of resources), suitable for legacy applications or on-premises data centers that cannot protect resources individually.
SP800-207-DEP-ENCLAVE · Enclave-Based Deployment →Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...
X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records →Per OWASP MASVS v2 MASVS-CRYPTO: correct use of cryptography in mobile apps. Requirements include (a) use industry-vetted cryptographic primitives + libraries + parameter choices appropriate to risk + (b) avoid weak + deprecated algorithms + custom cryptograph...
OWASPMASVS-2 · MASVS-CRYPTO: Cryptography Usage →Limit damage from perimeter breaches by segmenting networks into logical enclaves and restricting host-to-host communication paths so a compromised system cannot reach other enclaves.
CISA-ICS-7S-4 · Build a Defendable Environment →TEEs (e.g. Intel SGX, ARM TrustZone, AMD SEV) provide a hardware-protected enclave where confidential computation can run with attestation and integrity guarantees, supporting confidential cloud workloads and processing of regulated data.
ENISA-DPE-4.3 · Trusted execution environments (TEEs) →Apply Section 7 encryption and key management in cloud including: data at rest (provider-managed encryption + customer-managed encryption keys CMEK + Bring Your Own Key BYOK + Hold Your Own Key HYOK) + data in transit (TLS 1.3 + IPsec + mTLS) + data in use (co...
NISTSP144-4 · Encryption, Key Management, and BYOK →Questions people ask about enclave
What is Enclave?
Why is Enclave important for compliance?
Which compliance frameworks address Enclave?
Where can I learn more about Enclave?
See how Enclave applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.