Skip to main content

WIN-8.4.4-01 — Implement OWASP ASVS level 3

If a wallet instance is a web application, it shall implement all applicable controls of the OWASP ASVS at level 3.

PropertyValue
Section8.4.4 WebApp
Ownerplatform

Mapped Controls

ControlTitle
SID-HARD-01Error Message Sanitization
SID-HARD-02Input Validation and Injection Prevention
SID-HARD-05Browser Security Controls
SID-AUTH-01FIDO2/WebAuthn Passwordless Authentication
SID-CRYPTO-03AES-256-GCM Encrypted Keystore
SID-HARD-08Sensitive Data UI Protection
SID-HARD-09Application Resilience and Anti-Tampering

Source: ENISA – Security Requirements for European Digital Identity Wallets v0.5