One-Time Password
What is One-Time Password?
A password that is valid for only a single login session or transaction, generated dynamically to provide an additional layer of authentication security.
Terms that appear alongside one-time password
Each of these is named in at least one of the same controls as one-time password. The number is how many controls name both.
- authentication 4 shared controls
- multi factor authentication 2 shared controls
- biometric authentication 2 shared controls
- nist 2 shared controls
Frameworks that govern one-time password
What the standards actually require on one-time password
Requirements naming one-time password across 4 standards, quoted from the control text.
Challenges may use out-of-band, one-time-password, knowledge or biometric methods provided by the issuer/ACS; the method should provide adequate assurance commensurate with the transaction risk and applicable regulation.
EMV3DS-14 · Challenge authentication methods →Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load...
MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot · MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot →Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a...
NISTSP63-6 · AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance →Questions people ask about one-time password
What is One-Time Password?
Why is One-Time Password important for compliance?
Which compliance frameworks address One-Time Password?
Where can I learn more about One-Time Password?
See how One-Time Password applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.