Frameworks / OWASP Top 10:2025 / OWASPTOP10-2 OWASP Top 10:2025
Cryptography
OWASP Top 10:2025 OWASPTOP10-2: A02:2025 Cryptographic Failures and Secret Management Address OWASP Top 10 A02 Cryptographic Failures per OWASP Top 10:2025. Cryptographic Failures occur when sensitive data is not appropriately protected by cryptography enabling data exposure including weak + deprecated algorithms + improper parameter choices + key management failures + clear-text transmission + clear-text storage + side-channel attacks + and improper certificate validation. Mitigations include (a) classify data + apply appropriate cryptographic protection per classification + (b) use industry-vetted algorithms + key sizes + libraries + (c) implement key management lifecycle including generation + storage + rotation + revocation + (d) protect data at rest + in transit + in use appropriate to risk + (e) implement secrets management using dedicated secret store + rotation + no hard-coded secrets + (f) maintain crypto-agility for algorithm migration.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 155 controls across 90 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics GhCSA-Service-Provider-Licensing-Professional Cybersecurity Service Provider Licensing and Professional Accreditation 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication 27400-6.4 Default Configuration Security MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS PQC-5 Cryptographic Inventory and PQC Migration Roadmap PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OMANCS-5 Network, Endpoint, System Development, and Configuration Security Part11.30 Controls for open systems (21 CFR §11.30) Part11.300 Controls for identification codes and passwords (21 CFR §11.300) FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-2 Information Security Program (ISP) - Section 4 NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP123-3 Authentication, Access Control, and Account Management NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-4 IaaS Operational Recommendations and Workload Hardening NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NDPA-1 Applicability, Scope, and Carve-Outs NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-7 Cross-Border Data Transfers and International Cooperation ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-6 Security Misconfiguration and Secure API Design DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) GAMP5-Supplier-Operations-Change-Periodic Supplier Assessment, Operational Phase, Change Control and Periodic Review GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF 62351-9 Cyber security key management IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation MT-CDPA-Universal-Opt-Out-Mechanism-1-January-2025-GPC-Global-Privacy-Control-Mandatory-Recognition Montana CDPA Universal Opt-Out Mechanism + 1 January 2025 + GPC + Global Privacy Control + Mandatory Recognition AQAP2110-4 Configuration Management and Change Control STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NHPA-6 Reasonable Data Security and Breach Response NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-3 API Security Standards, mTLS, and Encryption OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs RUSPD-2 Lawful Basis, Consent, Notice Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 155 it maps to, and the evidence behind each claim, over MCP and REST.