Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Refresh ISO 27001 Multisession Control Statement. #1610

Closed
cmlh opened this issue Apr 8, 2023 · 8 comments
Closed

Refresh ISO 27001 Multisession Control Statement. #1610

cmlh opened this issue Apr 8, 2023 · 8 comments
Labels
1) Discussion ongoing Issue is opened and assigned but no clear proposal yet V3 _5.0 - draft This should be discussed once a 5.0 draft has been prepared.

Comments

@cmlh
Copy link
Contributor

cmlh commented Apr 8, 2023

"1.6 Compliance" of MVSP mandates * Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18.

The parent of all MVSP issues is #1151.

V3.7 Defenses Against Session Management Exploits states "Previously, based on ISO 27002 requirements, the ASVS has required blocking multiple simultaneous sessions. Blocking simultaneous sessions is no longer appropriate, ...".

ISO 27002 was updated during 2022 and therefore this statement in ASVS should reflect the latest release of ISO 27002.

I don't know if this is reflect in the latest ISO 27002 or not as I don't have it at hand at the moment.

This issue should also reconsidered when undertaking QA of each future release of ASVS.

@cmlh
Copy link
Contributor Author

cmlh commented Apr 10, 2023

I can't locate the associated control within ISO 27002:2022 and the commit was made by @vanderaj.

@tghosth
Copy link
Collaborator

tghosth commented Jun 15, 2023

So I think that given we no longer mandate this anyway, I am not super worried about an updated reference.

In general, I think figuring out how to comply with other regulation is not really in scope for ASVS and certainly not a key goal for 5.0.

@tghosth
Copy link
Collaborator

tghosth commented Jun 15, 2023

In 5.0, I am expecting we will need to trim down this text as much as possible anyway.

@tghosth tghosth closed this as not planned Won't fix, can't repro, duplicate, stale Jun 15, 2023
@tghosth
Copy link
Collaborator

tghosth commented Jun 15, 2023

Closing as I don't think we will take action on this

@cmlh
Copy link
Contributor Author

cmlh commented Jun 16, 2023

Closing as I don't think we will take action on this

Can @tghosth provide the context of this decision as it can fixed with a Pull Request?

@tghosth
Copy link
Collaborator

tghosth commented Jun 19, 2023

Highly likely that this sentence will be removed in 5.0 anyway

cmlh added a commit to cmlh/ASVS that referenced this issue Jun 26, 2023
Remove Unknown ISO 27001 Multisession Control
@tghosth
Copy link
Collaborator

tghosth commented Jul 11, 2023

I am reopening this and marking it to be considered when we create the actual 5.0 draft.

@tghosth tghosth reopened this Jul 11, 2023
@tghosth tghosth added 1) Discussion ongoing Issue is opened and assigned but no clear proposal yet _5.0 - draft This should be discussed once a 5.0 draft has been prepared. labels Jul 11, 2023
@elarlang elarlang added the V3 label Oct 16, 2024
@ryarmst
Copy link
Collaborator

ryarmst commented Oct 21, 2024

@cmlh Related discussion: #2101

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
1) Discussion ongoing Issue is opened and assigned but no clear proposal yet V3 _5.0 - draft This should be discussed once a 5.0 draft has been prepared.
Projects
None yet
Development

No branches or pull requests

4 participants