Certificate Pinning
What is Certificate Pinning?
A security technique that associates a host with its expected public key or certificate, preventing man-in-the-middle attacks by rejecting certificates that do not match the pinned values.
Terms that appear alongside certificate pinning
Each of these is named in at least one of the same controls as certificate pinning. The number is how many controls name both.
- tls 4 shared controls
- integrity 3 shared controls
- cipher 2 shared controls
- encryption 2 shared controls
- oauth 2 shared controls
- compliance 2 shared controls
- audit 2 shared controls
- cybersecurity 2 shared controls
Frameworks that govern certificate pinning
What the standards actually require on certificate pinning
Requirements naming certificate pinning across 4 standards, quoted from the control text.
GLI-33 geolocation + mobile + internet wagering security. GEOLOCATION VERIFICATION: in regulated jurisdictions (US states + provinces) wager acceptance must be CONTINUOUSLY GEO-VERIFIED to ensure player is physically within authorized boundary;
GLI33-Geolocation-Mobile-Internet-Wagering · GLI-33 Geolocation Verification, Mobile and Internet Wagering Security, Session Management →GS1 DATA SECURITY + INTEGRITY in supply chain data exchange. KEY PRINCIPLES: (1) DATA INTEGRITY - master data + EPCIS events + GDSN exchanges must be ACCURATE + COMPLETE + TIMELY + reflect true state of supply chain;
GS1-DataSecurity-Integrity-AccessControl · GS1 Data Security and Integrity in Exchange, Access Control and Tamper Evidence →HL7 FHIR Transport Security. TRANSPORT LAYER SECURITY (TLS) - all FHIR APIs MUST use TLS 1.2+ for production + TLS 1.3 recommended; certificate validation + trust chain + certificate pinning where appropriate + HSTS + secure session establishment + cipher suit...
HL7-FHIR-Transport-TLS-Communication · HL7 FHIR Transport Security - TLS 1.2+, Communication Security, Time Keeping, Server CapabilityStatement →Per OWASP MASVS v2 MASVS-NETWORK: secure network communication for mobile apps. Requirements include (a) use TLS 1.2 or later with strong cipher suites for all sensitive network communications + (b) implement certificate pinning where appropriate + with secure...
OWASPMASVS-4 · MASVS-NETWORK: Network Communication →Questions people ask about certificate pinning
What is Certificate Pinning?
Why is Certificate Pinning important for compliance?
Which compliance frameworks address Certificate Pinning?
Where can I learn more about Certificate Pinning?
See how Certificate Pinning applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.