Authentication Protocol
What is Authentication Protocol?
A set of rules governing the exchange of information for verifying the identity of a user, device, or system in a communication.
Frameworks that govern authentication protocol
What the standards actually require on authentication protocol
Requirements naming authentication protocol across 3 standards, quoted from the control text.
Use authentication protocols resistant to relevant threats including replay, eavesdropping, and man in the middle.
ISO29115-7.1 · Authentication Protocol Requirements →When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.
ISM-1919 · When multi-factor authentication is used to authenticate users or customers to online serv →Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a...
NISTSP63-6 · AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance →Questions people ask about authentication protocol
What is Authentication Protocol?
Why is Authentication Protocol important for compliance?
Which compliance frameworks address Authentication Protocol?
Where can I learn more about Authentication Protocol?
See how Authentication Protocol applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.