Verify that TLS is used for all client connectivity, and does not fall back to insecure or unencrypted communications. (C8)
Level 1 required: True
Level 2 required: True
Level 3 required: True
CWE: 319
Verify using up to date TLS testing tools that only strong cipher suites are enabled, with the strongest cipher suites set as preferred.
Level 1 required: True
Level 2 required: True
Level 3 required: True
CWE: 326
Verify that only the latest recommended versions of the TLS protocol are enabled, such as TLS 1.2 and TLS 1.3. The latest version of the TLS protocol should be the preferred option.
Level 1 required: True
Level 2 required: True
Level 3 required: True
CWE: 326
Credit via OWASP ASVS. For more information visit The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v3.0 license.
Loading comments 0%