Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.13.15Session authenticityITSP.10.171System and communications protection

Official Requirement

Protect the authenticity of communications sessions.

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

Communications sessions must be protected against session hijacking, man-in-the-middle attacks, and session replay. This means using secure protocols that verify both endpoints and protect session integrity throughout the communication.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Communications session authenticity protection

Implementation steps

  1. Enforce TLS 1.2+ on all communications and implement mutual certificate authentication for critical system-to-system connections
  2. Configure web applications with secure session management: signed session tokens, secure cookies, and anti-CSRF protections
  3. Implement IPsec or TLS for all internal communications carrying specified information
  4. Monitor for session anomalies (session fixation, replay attempts) through SIEM or application logging

Tools / systems

Evidence artifacts

Evidence frequency: Continuous enforcement; quarterly TLS and session configuration review