OWASP ASVS
V6 Cryptography at Rest

OWASP ASVS OWASPASVS-6: Stored Cryptography (V6)

Per OWASP ASVS V6: implement secure stored cryptography. Requirements include (a) classify data + apply appropriate cryptographic protection per classification + (b) use industry-vetted algorithms + key sizes + modes + libraries (AES-GCM + ChaCha20-Poly1305 + Argon2 + similar approved choices) + (c) implement key management lifecycle including generation + storage + rotation + revocation + destruction + (d) use HSM or cloud key management service for high-assurance scenarios + (e) protect cryptographic material in memory + during processing + (f) maintain crypto-agility to migrate algorithms when broken + (g) audit cryptographic operations.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.