S/MIME
What is S/MIME?
Secure/Multipurpose Internet Mail Extensions, a standard for public key encryption and signing of email messages to ensure confidentiality, integrity, and authentication.
Terms that appear alongside s/mime
Each of these is named in at least one of the same controls as s/mime. The number is how many controls name both.
- fips 4 shared controls
- nist 4 shared controls
- tls 4 shared controls
- ipsec 3 shared controls
- post quantum cryptography 2 shared controls
- pki 2 shared controls
- audit trail 2 shared controls
- audit 2 shared controls
Frameworks that govern s/mime
What the standards actually require on s/mime
Requirements naming s/mime across 6 standards, quoted from the control text.
Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.
ISM-0490 · Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections. →Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...
X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records →Implement STANAG 4774/4778 label handling across email per RFC 8551 S/MIME + RFC 9580 OpenPGP profiles, documents per OOXML/ODF embedded metadata + PDF/X-3 embedded XML, file storage per NTFS/EXT4 extended attributes + cloud object storage tags.
STANAG-6 · Label Handling in Email, Documents, and Storage →Sections 9.1-9.2 of IRS Publication 1075 establish FTI-specific requirements that are NOT covered by NIST SP 800-53 but are specific to the IRS FTI protection regime.
IRSPub1075-Section91-92-FTI-Specific-Recordkeeping-Disclosure-Transmission-Restriction-MinSafeguards · IRS Publication 1075 Sections 9.1-9.2 + FTI-Specific Requirements + Recordkeeping + Disclosure Restrictions + Transmission Requirements + Minimum Protection Standards + Printing + Inventory + Destruction →Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for priv...
MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation · MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation →Deploy FIPS 140-3 validated cryptographic modules (NIST CMVP) supporting ML-KEM + ML-DSA + SLH-DSA. Test against NIST CAVP (Cryptographic Algorithm Validation Program) test vectors.
PQC-7 · FIPS Validated Modules, HSM Readiness, and Algorithm Validation →Questions people ask about s/mime
What is S/MIME?
Why is S/MIME important for compliance?
Which compliance frameworks address S/MIME?
Where can I learn more about S/MIME?
See how S/MIME applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.