Essential Cybersecurity Controls (ECC – 2 : 2024) 2-15-3 Requirement:
- The cybersecurity requirements for external web applications must include at least the following:
- Use of web application firewall.
- Adoption of the multi-tier architecture principle.
- Use of secure protocols (e.g., HTTPS).
- Clarification of the secure usage policy for users.
- User authentication based on defined number and factors of authentication, as a result of impact assessment of authentication failure and bypass for users' access.
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you