Open Banking Security
mTLS + Signing + Keys

Open Banking Security OPENBANK-3: Mutual TLS, Token Binding, Request Signing (JWS), Key Management

Implement mutual TLS + token binding + JWS signing + key management per FAPI 2.0 + national scheme requirements. mTLS for Client Authentication and Token Binding must (a) use certificate-based mutual authentication between AS + Client + (b) bind tokens to client certificate via OAuth 2.0 Mutual TLS Client Authentication and Certificate Bound Access Tokens (RFC 8705), (c) maintain certificate lifecycle including provisioning + renewal + revocation + with directory integration. Request signing with JSON Web Signatures must (a) sign requests per JAR (JWT-Secured Authorization Request) + JARM (JWT Authorization Response Mode) + Pushed Authorization Request, (b) maintain JWKS endpoint + signing key rotation. Key Management for Signing and Encryption must (a) maintain dedicated signing + encryption keys per FAPI 2.0 + national scheme + (b) use HSM where appropriate + (c) implement key rotation + revocation + (d) align with broader cryptographic key management programme. Token Lifetime and Refresh Token Hygiene must (a) maintain short-lived access tokens + (b) implement refresh token rotation + binding + revocation + (c) align with FAPI 2.0 + scheme-specific lifetime requirements.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 181 controls across 59 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)

NIST SP 800-53 Rev 5 · 6 controls

  • AWWA-3.1 Network Segmentation
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.1 Malware Protection
  • AWWA-4.3 Configuration Management
  • FFIEC-06 Network security and segmentation
  • FFIEC-07 Endpoint protection and detection
  • FFIEC-08 Application security controls
  • FFIEC-09 Encryption and key management
  • FFIEC-10 Secure configuration standards

FedRAMP Rev 5 · 5 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 27043:2015 · 5 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-27 Network security management

ISO/SAE 21434 · 5 controls

  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-27 Network security management

BSI IT-Grundschutz · 4 controls

  • BSI-08 Cryptographic protection of data
  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

NIST SP 800-190 · 4 controls

API 1164 · 3 controls

  • API1164-13 Business Continuity and Recovery
  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems
  • CJIS-7 Configuration Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

IEC 62443 · 3 controls

  • IEC62443-13 Network security monitoring
  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27011:2024 · 3 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation
  • 27011-8.3 Cryptography and key management

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-13 Network security monitoring
  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems

ISO/IEC 27400:2022 · 3 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-6.3 Secure Update Mechanism
  • 27400-6.4 Default Configuration Security

NIST SP 1800-32 · 3 controls

  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DSS.3 Secure Development Practices
  • IM8-SEC.3 Network Security

South Korea ISMS-P · 3 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-01 System Hardening and Patch Management
  • ISMSP-SYS-02 Encryption Implementation

APPI · 2 controls

  • APPI-A31 Provision of Personally Referable Information
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 2 controls

  • CAT-D3-1 Preventative controls
  • CAT-D3-3 Corrective controls
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption

ISO/IEC 27010:2015 · 2 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-13.1 Communications Security
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • CA-ITSG33-SC-01 Security Control Catalogue

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • 62351-9 Cyber security key management
  • ISO-26262-8-7 Configuration management
  • ISO28001-PS-01 Facility Security
  • ISO20000-10 Configuration management
  • 29115-7.4 Level of Assurance 4 (LoA4)

ITIL 4 · 1 control

  • ITIL4-10 Configuration management
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 181 it maps to, and the evidence behind each claim, over MCP and REST.