Contributions
Implementation examples
Every example is tied to a specific control and, ideally, to the individual assessment objectives it claims to satisfy. Verdicts and reasoning are attached to each one.
2 examples referencing SSH
Both ends prove who they are: validated TLS for people, mutual TLS and pinned keys for machines
AO coverage. Addresses the single Communications Authenticity objective for the session types in scope: user-to-application, application-to-application, and administrative. User-to-application.…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet- SC.L2-3.13.9[a] [b] [c]
Inactivity windows defined per connection type: 15 minutes for admin sessions, 12 hours for VPN
AO coverage. Addresses all three Connections Termination objectives: defining the inactivity period, terminating at end of session, and terminating after the defined inactivity period. Defined…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet