# SP-051 Tokenised Asset Security Architecture

Status: draft. Release 26.03. Modified 2026-03-10. Licence: CC BY-SA 4.0.

Scope: Security architecture for institutional tokenised asset platforms covering custody architecture (HSM, MPC, threshold signatures), smart contract security lifecycle, oracle and price feed integrity, on-chain/off-chain security boundaries, DeFi protocol integration risks, cross-chain bridge security, and regulatory compliance across MiCA, FCA, SEC, and Basel Committee frameworks. Addresses the OWASP Smart Contract Top...
Use when: Financial institutions building tokenised bond, equity, or fund platforms for institutional investors. Asset managers launching tokenised money market funds or structured products (following BlackRock BUIDL, Franklin Templeton BENJI precedent).
Not when: Organisations using blockchain solely for internal record-keeping or provenance tracking where no financial assets are at risk -- the custody and key management controls are disproportionate.

## Controls (36, NIST SP 800-53 ids)
- Critical (14): SC-12, SC-13, SC-07, SC-28, AC-03, AC-06, AU-02, SA-11, CM-03, IR-04, RA-03, SI-10, CA-08, CA-07
- Important (12): SC-08, AC-04, CM-08, IR-06, IR-01, CP-09, PE-03, PS-06, AC-05, IA-04, AU-03, SR-03
- Standard (10): CM-07, CM-02, CM-04, SA-04, SA-15, PM-09, PM-25, PT-02, CP-02, MA-04

## What each critical control mitigates (14)
- SC-12 Cryptographic Key Establishment and Management: T-DLT-001, T-DLT-010
- SC-13 Cryptographic Protection: none of the threats below
- SC-07 Boundary Protection: T-DLT-003, T-DLT-004
- SC-28 Protection of Information at Rest: none of the threats below
- AC-03 Access Enforcement: T-DLT-005, T-DLT-008
- AC-06 Least Privilege: T-DLT-009
- AU-02 Event Logging: T-DLT-001, T-DLT-007, T-DLT-009
- SA-11 Developer Testing and Evaluation: T-DLT-002
- CM-03 Configuration Change Control: T-DLT-005, T-DLT-009
- IR-04 Incident Handling: T-DLT-004, T-DLT-010
- RA-03 Risk Assessment: T-DLT-004
- SI-10 Information Input Validation: T-DLT-002, T-DLT-003
- CA-08 Penetration Testing: T-DLT-002
- CA-07 Continuous Monitoring: T-DLT-003, T-DLT-004, T-DLT-007, T-DLT-010

## Threats and the controls that mitigate them (10)
- T-DLT-001 undefined: SC-12, SR-03, AC-05, AU-02
- T-DLT-002 undefined: SA-11, SI-10, CA-08
- T-DLT-003 undefined: SI-10, CA-07, SC-07
- T-DLT-004 undefined: SC-07, IR-04, CA-07, RA-03
- T-DLT-005 undefined: AC-03, CM-03, AC-05
- T-DLT-006 undefined: SC-08, AC-04
- T-DLT-007 undefined: AU-02, CM-08, CA-07, AC-04
- T-DLT-008 undefined: AC-03, AC-04, IA-04
- T-DLT-009 undefined: CM-03, AC-06, PS-06, AU-02
- T-DLT-010 undefined: SC-12, SR-03, IR-04, CA-07, PE-03

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-051/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-051/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 54 KB: /api/v1/patterns/SP-051
- Page for people: /patterns/sp-051/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-026 PCI Full Environment; SP-029 Zero Trust Architecture; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-042 Third Party Risk Management; SP-047 Secure Agentic AI Frameworks

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
