OWASP Top 10:2025
Cryptography

OWASP Top 10:2025 OWASPTOP10-2: A02:2025 Cryptographic Failures and Secret Management

Address OWASP Top 10 A02 Cryptographic Failures per OWASP Top 10:2025. Cryptographic Failures occur when sensitive data is not appropriately protected by cryptography enabling data exposure including weak + deprecated algorithms + improper parameter choices + key management failures + clear-text transmission + clear-text storage + side-channel attacks + and improper certificate validation. Mitigations include (a) classify data + apply appropriate cryptographic protection per classification + (b) use industry-vetted algorithms + key sizes + libraries + (c) implement key management lifecycle including generation + storage + rotation + revocation + (d) protect data at rest + in transit + in use appropriate to risk + (e) implement secrets management using dedicated secret store + rotation + no hard-coded secrets + (f) maintain crypto-agility for algorithm migration.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.