Skip to main content

Controls Overview

60 controls: 36 verified, 24 to-do | 42 platform, 18 operator

Technical Controls (Platform-Provided)

IDTitleStatusOwnerCSF Function
SID-ACCESS-01Multi-Tenant Isolationverifiedplatformprotect
SID-ACCESS-02Rate Limiting and Brute-Force Protectionverifiedplatformprotect
SID-ACCESS-03User Consent Before Credential Disclosureverifiedplatformprotect
SID-ACCESS-04SPOCP Policy-Based Query Authorizationverifiedplatformprotect
SID-AUDIT-01Structured Security Event Loggingverifiedplatformdetect
SID-AUTH-01FIDO2/WebAuthn Passwordless Authenticationverifiedplatformprotect
SID-AUTH-02JWT Bearer Token Session Managementverifiedplatformprotect
SID-AUTH-03OIDC Gate for External Identity Providersverifiedplatformprotect
SID-AUTH-04WebSocket JWT Handshake Authenticationverifiedplatformprotect
SID-CRYPTO-01PKCS#11 HSM Key Protectionverifiedplatformprotect
SID-CRYPTO-02PRF Extension Key Derivationverifiedplatformprotect
SID-CRYPTO-03AES-256-GCM Encrypted Keystoreverifiedplatformprotect
SID-CRYPTO-04COSE Sign1 and mDOC Cryptographyverifiedplatformprotect
SID-CRYPTO-05Secure Random Number Generationverifiedplatformprotect
SID-DATA-01SD-JWT Selective Disclosureverifiedplatformprotect
SID-DATA-02mDOC Element-Level Selective Disclosureverifiedplatformprotect
SID-DATA-03Credential Revocation via Token Status Listverifiedplatformprotect
SID-DATA-04VCTM Schema Validationverifiedplatformprotect
SID-DATA-05Gate/Remove Dead VC/VP Storage Pathsverifiedplatformprotect
SID-DATA-06PII Field Encryption for User Recordsto_doplatformprotect
SID-HARD-01Error Message Sanitizationverifiedplatformprotect
SID-HARD-02Input Validation and Injection Preventionverifiedplatformprotect
SID-HARD-03Network Segmentation (Separate Server Ports)verifiedplatformprotect
SID-HARD-04Secure Registration Enforcementverifiedplatformprotect
SID-HARD-05Browser Security Controlsverifiedplatformprotect
SID-KEY-01WSCA WebSocket Key Signing Delegationverifiedplatformprotect
SID-KEY-02IACA Certificate Managementverifiedplatformprotect
SID-KEY-03FIDO WSCD via Sign Extension (previewSign)to_doplatformprotect
SID-PRIV-01Minimal Disclosure Enforcementverifiedplatformprotect
SID-PRIV-02VP Nonce Binding (Anti-Replay)verifiedplatformprotect
SID-PRIV-03Right-to-Erasure Bulk Deletion APIto_doplatformprotect
SID-TRANS-01TLS 1.2+ Minimum with Configurable Versionverifiedplatformprotect
SID-TRANS-02OpenID4VCI Credential Issuance Protocolverifiedplatformprotect
SID-TRANS-03OpenID4VP Credential Presentation Protocolverifiedplatformprotect
SID-TRANS-04SSRF-Protected HTTP Clientverifiedplatformprotect
SID-TRUST-01AuthZEN PDP Trust Evaluation Serviceverifiedplatformidentify
SID-TRUST-02Multi-Registry Trust Framework Supportverifiedplatformidentify
SID-TRUST-03Issuer and Verifier Trust Gatingverifiedplatformprotect
SID-TRUST-04Trust Decision Caching with Circuit Breakerverifiedplatformprotect

Organizational Controls (Operator-Required)

IDTitleStatusOwnerCSF Function
SID-ORG-01Information Security Policyto_dooperatorgovern
SID-ORG-02Roles, Responsibilities, and Segregation of Dutiesto_dooperatorgovern
SID-ORG-03Risk Management Frameworkto_dooperatoridentify
SID-ORG-04Supplier and Third-Party Securityto_dooperatorgovern
SID-ORG-05Legal, Regulatory, and Contractual Complianceto_dooperatorgovern
SID-ORG-06Wallet Service Practice Statementto_dooperatorgovern
SID-ORG-07Terms of Service and Privacy Policyto_dooperatorgovern
SID-OPS-01Incident Response and Managementto_dooperatorrespond
SID-OPS-02Business Continuity and ICT Readinessto_dooperatorrecover
SID-OPS-03Backup and Recoveryto_dooperatorrecover
SID-OPS-04Vulnerability Managementto_doplatformdetect
SID-OPS-05Change Managementto_doplatformgovern
SID-OPS-06Monitoring and Alertingto_dooperatordetect
SID-OPS-07Fraud Managementto_dooperatordetect
SID-OPS-08Secure Development Lifecycleto_doplatformprotect
SID-PPL-01Personnel Screening and Onboardingto_dooperatorprotect
SID-PPL-02Security Awareness, Education, and Trainingto_dooperatorprotect
SID-PPL-03Confidentiality and Non-Disclosure Agreementsto_dooperatorprotect
SID-PPL-04Information Security Event Reportingto_dooperatordetect
SID-PHY-01Data Center Physical Securityto_dooperatorprotect
SID-PHY-02Equipment and Media Securityto_dooperatorprotect