Skip to content

Authentication

What is Authentication?

The process of verifying the identity of a user, device, or system. Common methods include passwords, biometrics, tokens, and multi-factor authentication (MFA).

Information Security

What the standards actually require on authentication

Requirements naming authentication across 6 standards, quoted from the control text.

Multi-factor authentication is used to authenticate unprivileged users of systems.

ISM-0974 · Multi-factor authentication is used to authenticate unprivileged users of systems.
PCI DSS 4.018 controls

Strong cryptography is used to render all authentication factors unreadable during transmission and storage on all system components

8.3.2 · Strong cryptography is used to render all authentication factors unreadable during transmission and storage on all system components

Factors that determine the required level of authentication assurance in a given context

29115-6.1 · Authentication context
FedRAMP High16 controls

Uniquely identify and authenticate non-organizational users (e.g., federal customers).

IA-8 · Identification and Authentication (Non-Organizational Users)

Decoupled authentication allows the ACS to authenticate the cardholder out-of-band, separately from the purchase session (e.g. via the issuer's banking app), with the result returned when complete.

EMV3DS-13 · Decoupled authentication
FedRAMP Moderate15 controls

Uniquely identify and authenticate non-organizational users (e.g., federal customers).

IA-8 · Identification and Authentication (Non-Organizational Users)

Questions people ask about authentication

What is Authentication?
The process of verifying the identity of a user, device, or system. Common methods include passwords, biometrics, tokens, and multi-factor authentication (MFA).
Why is Authentication important for compliance?
Authentication is a key concept in Information Security. Understanding authentication helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Authentication?
Key concepts related to Authentication include MFA (Multi-Factor Authentication), Authorisation. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Authentication?
Authentication appears in the requirement text of Australian Information Security Manual, PCI DSS 4.0, ISO/IEC 29115:2023 - Entity Authentication Assurance Framework, FedRAMP High, EMV 3‑D Secure (3DS) - Payment Authentication Protocol. Across these standards we have identified 125 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Authentication?
Explore our compliance framework pages to see how authentication applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Authentication applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.