V12.1.1: Verify that only the latest recommended versions of the TLS protocol are enabled, such as TLS 1.2 and TLS 1.3. The latest version of the TLS protocol must be the preferred option.
ASVS Maturity
V12.1.2
V12.1.2: Verify that only recommended cipher suites are enabled, with the strongest cipher suites set as preferred. L3 applications must only support cipher suites which provide forward secrecy.
ASVS Maturity
V12.1.3
V12.1.3: Verify that the application validates that mTLS client certificates are trusted before using the certificate identity for authentication or authorization.
ASVS Maturity
V12.1.4
V12.1.4: Verify that proper certification revocation, such as Online Certificate Status Protocol (OCSP) Stapling, is enabled and configured.
ASVS Maturity
V12.1.5
V12.1.5: Verify that Encrypted Client Hello (ECH) is enabled in the application's TLS settings to prevent exposure of sensitive metadata, such as the Server Name Indication (SNI), during TLS handshake processes.