OWASP ASVS
V9 Communication

OWASP ASVS OWASPASVS-9: Communication Security (V9)

Per OWASP ASVS V9: implement secure communications. Requirements include (a) use TLS 1.2 or later with strong cipher suites + appropriate key sizes for all sensitive communications + (b) implement HSTS + appropriate certificate validation + pinning where applicable + (c) protect against TLS downgrade + man-in-the-middle attacks + (d) implement certificate lifecycle management including monitoring + rotation + revocation + (e) protect internal service-to-service communications equivalent to external communications + (f) implement mutual TLS where appropriate (high-assurance + service-to-service + zero trust) + (g) maintain crypto-agility for protocol + cipher migration.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.