Skip to content

Enclave

What is Enclave?

A network segment with specific security requirements that is separated from other segments through access controls and monitoring.

Information Security

What the standards actually require on enclave

Requirements naming enclave across 6 standards, quoted from the control text.

Places a gateway PEP at the boundary of a resource enclave (a group of resources), suitable for legacy applications or on-premises data centers that cannot protect resources individually.

SP800-207-DEP-ENCLAVE · Enclave-Based Deployment

Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...

X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records
OWASP MASVS2 controls

Per OWASP MASVS v2 MASVS-CRYPTO: correct use of cryptography in mobile apps. Requirements include (a) use industry-vetted cryptographic primitives + libraries + parameter choices appropriate to risk + (b) avoid weak + deprecated algorithms + custom cryptograph...

OWASPMASVS-2 · MASVS-CRYPTO: Cryptography Usage

Limit damage from perimeter breaches by segmenting networks into logical enclaves and restricting host-to-host communication paths so a compromised system cannot reach other enclaves.

CISA-ICS-7S-4 · Build a Defendable Environment

TEEs (e.g. Intel SGX, ARM TrustZone, AMD SEV) provide a hardware-protected enclave where confidential computation can run with attestation and integrity guarantees, supporting confidential cloud workloads and processing of regulated data.

ENISA-DPE-4.3 · Trusted execution environments (TEEs)

Apply Section 7 encryption and key management in cloud including: data at rest (provider-managed encryption + customer-managed encryption keys CMEK + Bring Your Own Key BYOK + Hold Your Own Key HYOK) + data in transit (TLS 1.3 + IPsec + mTLS) + data in use (co...

NISTSP144-4 · Encryption, Key Management, and BYOK

Questions people ask about enclave

What is Enclave?
A network segment with specific security requirements that is separated from other segments through access controls and monitoring.
Why is Enclave important for compliance?
Enclave is a key concept in Information Security. Understanding enclave helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Enclave?
Enclave appears in the requirement text of NIST SP 800-207, ITU-T X.805 - Security Architecture for End-to-End Communications, OWASP MASVS, CISA Industrial Control Systems (ICS) Security Guidance, ENISA Data Protection Engineering - From Theory to Practice. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Enclave?
Explore our compliance framework pages to see how enclave applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Enclave applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.