Skip to main content

Controls Overview

82 security controls across the platform.

Technical Controls

Platform-Provided

IDTitleOwnerCSF Function
SID-ACCESS-01Multi-Tenant Isolationplatformprotect
SID-ACCESS-02Rate Limiting and Brute-Force Protectionplatformprotect
SID-ACCESS-03User Consent Before Credential Disclosureplatformprotect
SID-ACCESS-04SPOCP Policy-Based Query Authorizationplatformprotect
SID-ARCH-01Platform Architecture Non-Applicability Registerplatformidentify
SID-AUDIT-01Structured Security Event Loggingplatformdetect
SID-AUDIT-02Privacy-Preserving Audit Event Taxonomyplatformdetect
SID-AUTH-01FIDO2/WebAuthn Passwordless Authenticationplatformprotect
SID-AUTH-02JWT Bearer Token Session Managementplatformprotect
SID-AUTH-03OIDC Gate for External Identity Providersplatformprotect
SID-AUTH-04WebSocket JWT Handshake Authenticationplatformprotect
SID-AUTH-05Wallet Unlock, Lockout, and PIN Securityplatformprotect
SID-AUTH-06Wallet Lifecycle Managementplatformprotect
SID-CRYPTO-01PKCS#11 HSM Key Protectionplatformprotect
SID-CRYPTO-02PRF Extension Key Derivationplatformprotect
SID-CRYPTO-03AES-256-GCM Encrypted Keystoreplatformprotect
SID-CRYPTO-04COSE Sign1 and mDOC Cryptographyplatformprotect
SID-CRYPTO-05Secure Random Number Generationplatformprotect
SID-DATA-01SD-JWT Selective Disclosureplatformprotect
SID-DATA-02mDOC Element-Level Selective Disclosureplatformprotect
SID-DATA-03Credential Revocation via Token Status Listplatformprotect
SID-DATA-04VCTM Schema Validationplatformprotect
SID-DATA-06PII Field Encryption for User Recordsplatformprotect
SID-DATA-07Credential Re-issuance and Lifecycle Managementplatformprotect
SID-DATA-08Server-Side Data Cache Protectionplatformprotect
SID-DATA-09Runtime Memory Protectionplatformprotect
SID-DATA-10Wallet Backup Securityplatformprotect
SID-HARD-01Error Message Sanitizationplatformprotect
SID-HARD-02Input Validation and Injection Preventionplatformprotect
SID-HARD-03Network Segmentation (Separate Server Ports)platformprotect
SID-HARD-04Secure Registration Enforcementplatformprotect
SID-HARD-05Browser Security Controlsplatformprotect
SID-HARD-06Wallet Attestation and Environment Integrityplatformidentify
SID-HARD-07Resource Upload Constraintsplatformprotect
SID-HARD-08Sensitive Data UI Protectionplatformprotect
SID-HARD-09Application Resilience and Anti-Tamperingplatformprotect
SID-KEY-01WSCA WebSocket Key Signing Delegationplatformprotect
SID-KEY-02IACA Certificate Managementplatformprotect
SID-KEY-03WSCD Client Library with rawSign APIplatformprotect
SID-KEY-04R2PS Remote WSCD SCAL2 Complianceplatformprotect
SID-PRIV-01Minimal Disclosure Enforcementplatformprotect
SID-PRIV-02VP Nonce Binding (Anti-Replay)platformprotect
SID-PRIV-03Right-to-Erasure Bulk Deletion APIplatformprotect
SID-PRIV-04Pseudonymous Authenticationplatformprotect
SID-TRANS-01TLS 1.2+ Minimum with Configurable Versionplatformprotect
SID-TRANS-02OpenID4VCI Credential Issuance Protocolplatformprotect
SID-TRANS-03OpenID4VP Credential Presentation Protocolplatformprotect
SID-TRANS-04SSRF-Protected HTTP Clientplatformprotect
SID-TRUST-01AuthZEN PDP Trust Evaluation Serviceplatformidentify
SID-TRUST-02Multi-Registry Trust Framework Supportplatformidentify
SID-TRUST-03Issuer and Verifier Trust Gatingplatformprotect
SID-TRUST-04Trust Decision Caching with Circuit Breakerplatformprotect
SID-TRUST-05Relying Party Registration and Over-Request Detectionplatformprotect

Operator-Required

IDTitleOwnerCSF Function
SID-ARCH-02Operator-Scope Compliance Obligationsoperatorgovern
SID-TRANS-05Operator TLS Deployment Enforcementoperatorprotect

Organizational Controls

Platform-Provided

IDTitleOwnerCSF Function
SID-OPS-04Vulnerability Managementplatformdetect
SID-OPS-05Secure Configuration Managementplatformgovern
SID-OPS-08Secure Development Lifecycleplatformprotect
SID-OPS-09Platform Security Documentationplatformidentify

Operator-Required

IDTitleOwnerCSF Function
SID-OPS-01Incident Response and Managementoperatorrespond
SID-OPS-02Business Continuity and ICT Readinessoperatorrecover
SID-OPS-03Backup and Recoveryoperatorrecover
SID-OPS-06Monitoring and Alertingoperatordetect
SID-OPS-07Fraud Managementoperatordetect
SID-OPS-10Encryption-at-Rest and Secrets Managementoperatorprotect
SID-OPS-11Data Leakage Prevention — Infrastructure Controlsoperatorprotect
SID-OPS-12Deployment Environment Separationoperatorprotect
SID-OPS-13Operator Security Documentationoperatoridentify
SID-ORG-01Information Security Policyoperatorgovern
SID-ORG-02Roles, Responsibilities, and Segregation of Dutiesoperatorgovern
SID-ORG-03Risk Management Frameworkoperatoridentify
SID-ORG-04Supplier and Third-Party Securityoperatorgovern
SID-ORG-05Legal, Regulatory, and Contractual Complianceoperatorgovern
SID-ORG-06Wallet Service Practice Statementoperatorgovern
SID-ORG-07Terms of Service and Privacy Policyoperatorgovern
SID-ORG-08Information Classification and Labellingoperatoridentify
SID-PHY-01Data Center Physical Securityoperatorprotect
SID-PHY-02Equipment and Media Securityoperatorprotect
SID-PPL-01Personnel Screening and Onboardingoperatorprotect
SID-PPL-02Security Awareness, Education, and Trainingoperatorprotect
SID-PPL-03Confidentiality and Non-Disclosure Agreementsoperatorprotect
SID-PPL-04Information Security Event Reportingoperatordetect