Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-15-1

Cybersecurity Requirements For External Web Applications Must Be Defined, Documented And Approved.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-15-2

The Cybersecurity Requirements For External Web Applications Must Be Implemented.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-15-3

  1. The cybersecurity requirements for external web applications must include at least the following:
    1. Use of web application firewall.
    2. Adoption of the multi-tier architecture principle.
    3. Use of secure protocols (e.g., HTTPS).
    4. Clarification of the secure usage policy for users.
    5. User authentication based on defined number and factors of authentication, as a result of impact assessment of authentication failure and bypass for users' access.

Essential Cybersecurity Controls (ECC – 2 : 2024) - 2-15-4

The Cybersecurity Requirements For External Web Applications Must Be Reviewed Periodically