Skip to content

One-Time Password

What is One-Time Password?

A password that is valid for only a single login session or transaction, generated dynamically to provide an additional layer of authentication security.

Information Security

Each of these is named in at least one of the same controls as one-time password. The number is how many controls name both.

What the standards actually require on one-time password

Requirements naming one-time password across 4 standards, quoted from the control text.

Challenges may use out-of-band, one-time-password, knowledge or biometric methods provided by the issuer/ACS; the method should provide adequate assurance commensurate with the transaction risk and applicable regulation.

EMV3DS-14 · Challenge authentication methods
MITRE D3FEND1 control

Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load...

MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot · MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot

Implement AAL3 authentication per NIST SP 800-63B Section 4.3. AAL3 requires (a) Multi-Factor Cryptographic Hardware authenticator OR Single-Factor Cryptographic Hardware combined with a memorised secret OR Multi-Factor One-Time Password Device combined with a...

NISTSP63-6 · AAL3 Authentication: Hardware Cryptographic, Verifier Impersonation Resistance, Phishing Resistance

Questions people ask about one-time password

What is One-Time Password?
A password that is valid for only a single login session or transaction, generated dynamically to provide an additional layer of authentication security.
Why is One-Time Password important for compliance?
One-Time Password is a key concept in Information Security. Understanding one-time password helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address One-Time Password?
One-Time Password appears in the requirement text of EMV 3‑D Secure (3DS) - Payment Authentication Protocol, ITU-T X.805 - Security Architecture for End-to-End Communications, MITRE D3FEND, NIST SP 800-63 Digital Identity Guidelines. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about One-Time Password?
Explore our compliance framework pages to see how one-time password applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how One-Time Password applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.