UK Open Banking Standard
Security Profile

UK Open Banking Standard OB-SEC.4: Certificate Management

Participants must use qualified certificates from the Open Banking Directory for mutual TLS authentication.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 207 controls across 86 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 5 controls

ISO 27043 · 4 controls

ISO/SAE 21434 · 4 controls

  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

ISO 13485 · 3 controls

ISO 27799 · 3 controls

BSI IT-Grundschutz · 2 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-08 Cryptographic protection of data
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27400:2022 · 2 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions

NIST SP 800-190 · 2 controls

  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 2 controls

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts

PTES · 2 controls

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • SIGSTORE-3 Sigstore for Containers and Artifacts (Cosign)

South Korea ISMS-P · 2 controls

  • VP-2 Holder Binding
  • W3CVCDM-4 Accessibility, Internationalization, Security

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 1 control

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Qatar DPL · 1 control

  • RCEPEC-1 Online Personal Information Protection (12.13)
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization

Saudi Arabia PDPL · 1 control

  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

WCAG 2.2 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security Profile

Query this from an agent

The graph holds this control, the 207 it maps to, and the evidence behind each claim, over MCP and REST.