Authentication
What is Authentication?
The process of verifying the identity of a user, device, or system. Common methods include passwords, biometrics, tokens, and multi-factor authentication (MFA).
Related terms
Frameworks that govern authentication
What the standards actually require on authentication
Requirements naming authentication across 6 standards, quoted from the control text.
Multi-factor authentication is used to authenticate unprivileged users of systems.
ISM-0974 · Multi-factor authentication is used to authenticate unprivileged users of systems. →Strong cryptography is used to render all authentication factors unreadable during transmission and storage on all system components
8.3.2 · Strong cryptography is used to render all authentication factors unreadable during transmission and storage on all system components →Factors that determine the required level of authentication assurance in a given context
29115-6.1 · Authentication context →Uniquely identify and authenticate non-organizational users (e.g., federal customers).
IA-8 · Identification and Authentication (Non-Organizational Users) →Decoupled authentication allows the ACS to authenticate the cardholder out-of-band, separately from the purchase session (e.g. via the issuer's banking app), with the result returned when complete.
EMV3DS-13 · Decoupled authentication →Uniquely identify and authenticate non-organizational users (e.g., federal customers).
IA-8 · Identification and Authentication (Non-Organizational Users) →Questions people ask about authentication
What is Authentication?
Why is Authentication important for compliance?
What concepts are related to Authentication?
Which compliance frameworks address Authentication?
Where can I learn more about Authentication?
See how Authentication applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.