Docy Child

INFRA-1 TLS Certificates and Endpoints

Estimated reading: 2 minutes 513 views

What is this control about?

Transport Layer Security (TLS) certificates are essential to securing internet connections and transactions through data encryption. Not having a plan to manage certificates can lead to system outages and security breaches, which can result in exposure of confidential data to attackers.

Available tools in the marketplace

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below, because we haven’t personally used them.

 TLS Certificates and EndPoint Tools
DigiCert
Pingdom
Keychest

Available templates

TrustCloud has a curated list of templates internally or externally sourced to help you get started. Click on the link for a downloadable version:

  • N/A – no templates recommendation

Control implementation

Note: This control is 100% automated by TrustCloud. Connect your system to enjoy the benefit of automation

For a manual implementation: 

Install a TLS solution to track all your TLS server certificates:

  • Validity period
  • Signed algorithm
  • DN and SAN content

Implement a process to renew your TLS certificate once it expires

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action

  • Provide the latest SSL scan of your browser showing adequate TLS certificates

Evidence example

From the suggested action above, an example is provided below.

  1. Provide the latest SSL (Secure Sockets Layer) scan of your browser showing adequate TLS (Transport Layer Security) certificates.
    Use Qualys SSL to run a scan on test on your server and browser.

 

INFRA 1 screenshot1

Join the conversation

ON THIS PAGE
SUBSCRIBE
FlightSchool
SHARE THIS ARTICLE
Twitter Facebook LinkedIn

❤️  Joyfully crafted by a 100% distributed team.