[Withdrawn: Incorporated into SC-4.]
[Withdrawn: Incorporated into SC-4.]
Only allow the use of [Assignment: organization-defined certificate authorities] for verification of the establishment of protected sessions.
Fail to a [Assignment: organization-defined known system state] for the following failures on the indicated components while preserving [Assignment: organization-defined system state information] in failure: [Assignment: list of organization-defined types of system failures on organization-defined system components].
Employ minimal functionality and information storage on the following system components: [Assignment: organization-defined system components].
Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks.
[Withdrawn: Incorporated into SC-42.]
Include within organizational systems the following platform independent applications: [Assignment: organization-defined platform-independent applications].
Protect the [Selection (one or more): confidentiality; integrity] of the following information at rest: [Assignment: organization-defined information at rest].
Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on [Assignment: organization-defined system components or media]: [Assignment: organization-defined information].
Remove the following information from online storage and store offline in a secure location: [Assignment: organization-defined information].