CYB-07 · Cyber security
TLS configuration must achieve a minimum A rating on the SSL Labs Server Test or equivalent. This covers: TLS version (1.2 minimum, 1.3 preferred), cipher suite strength, certificate chain validity, and OCSP stapling.
Trigger
SSL certificate grades below A, or using deprecated TLS 1.0/1.1 protocols, or weak cipher suites, or certificate issued to wrong domain
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Run SSL Labs test. Disable TLS 1.0 and 1.1. Enable TLS 1.3. Remove deprecated cipher suites. Enable OCSP stapling. Use a certificate from a trusted CA.
Evidence required
Automated assessment
Verified by the Provantis cyber scanner. Machine checks performed: