Pages
Policy Config — TLS Floor

Source: c65 policy-definitions.md P11 — level-select shape

‹ Policy Catalog

TLS Floor

Connections below the TLS baseline are refused. Carries NIST SP 800-52 single-handedly; encryption-in-transit evidence for HIPAA, GDPR, and SOC 2.

Data Protection
high
P11
SatisfiesATLASCSF 2.0800-52ISO 27001SOC 2HIPAAGDPR
Underlying control— show
egress: weak_tls = trueedit as custom control →

Minimum TLS version

Ordered weakest → strongest; click a level to set the floor.

Everything below TLS 1.2 raises a finding — 2 current destinations below the floor.

Exceptions

Scoped carve-outs with a reason and an expiry — accepted risk, on the record.

ScopeValueReasonExpires
destinationlegacy-erp.internal:8443Vendor appliance stuck on TLS 1.1 — upgrade contract signed2026-12-31

Remediation shown on findings: Upgrade the destination's TLS, or block the connection.

Qpoint Brand Style Guide