We recently went through a third party review of our systems where the consultants have reported a finding that we have TLSv1.0 enabled. In the report they are referring to this NIST document which recommends (Page 28):
If the server supports government-only applications, it shall not be configured to support TLS version 1.0. If the server supports citizen or business facing applications, it may be configured to support TLS version 1.0.
We are not the government but for the sake of a security I decided to run the online SSL Analyzer and check if there are any issues. It did not show any red flags. My question is, Do we really need to disable TLS 1.0 altogether.
We are dealing with Admin portal of a web application which does not contain any kind of payment features so PCI-DSS is not a requirement for us.