
A.14.1.3: Protecting Application Services Transactions
Ensure that information involved in application service transactions is protected to prevent incomplete transmission, mis-routing, unauthorized message alteration, unauthorized disclosure, and unauthorized message duplication or replay.

A.13.2.1: Information Transfer Policies and Procedures
Implement policies and procedures for secure transfer of information, both within the organization and with external entities.

A.10.1.1: Policy on the Use of Cryptographic Controls
Develop and implement a policy on the use of cryptographic controls.