HTTPS Communication with External Facing Services
V12.2.1
Verify that TLS is used for all connectivity between a client and external facing, HTTP-based services, and does not fall back to insecure or unencrypted communications.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 102, 117, 157, 21, 217, 220, 31, 39, 473, 593, 594, 620, 65, 89, 94
V12.2.2
Verify that external facing services use publicly trusted TLS certificates.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 102, 117, 157, 21, 217, 220, 39, 473, 594, 620, 65, 89, 94
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.