Pages
Policy Config — TLS Floor
Source: c65 policy-definitions.md P11 — level-select shape
‹ Policy Catalog
TLS Floor
Connections below the TLS baseline are refused. Carries NIST SP 800-52 single-handedly; encryption-in-transit evidence for HIPAA, GDPR, and SOC 2.
Data Protection
high
P11Satisfies
ATLAS
CSF 2.0
800-52
ISO 27001
SOC 2
HIPAA
GDPR
Underlying control— show
egress: weak_tls = trueedit as custom control →Minimum TLS version
Ordered weakest → strongest; click a level to set the floor.
Everything below TLS 1.2 raises a finding — 2 current destinations below the floor.
Exceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| destination | legacy-erp.internal:8443 | Vendor appliance stuck on TLS 1.1 — upgrade contract signed | 2026-12-31 | |
Remediation shown on findings: Upgrade the destination's TLS, or block the connection.