Compliance Node Overview
MITRE ATT&CK Mobile T1521 covers adversary use of TLS, symmetric, or asymmetric encrypted channels for mobile command-and-control communication. Pegasus, Predator, FinSpy, BRATA Android banker, and most modern mobile commercial spyware use encrypted C2 to evade network inspection. Compliance obligations include NIST SP 800-53 SC-7 (Boundary Protection), SI-4 (System Monitoring), NIST SP 800-124 Rev 2, ISO 27001 A.8.20, A.8.21, A.8.16, NIS2 Article 21(2)(b), PCI MPoC for mobile payment, and HIPAA Security Rule mobile transmission security.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1521/
SHA-256 integrity: ad1d2c11b16966951923b68d12ec4bbcbb5317818b28d060ab337915c180df19
Primary Citations — 8 traced to source
- MITRE ATT&CK Mobile Technique T1521: Encrypted Channel (https://attack.mitre.org/techniques/T1521/)
- NIST SP 800-124 Rev 2: Guidelines for Managing the Security of Mobile Devices in the Enterprise
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access