Replay Attack
What is Replay Attack?
A network attack in which a valid data transmission is maliciously repeated or delayed. The attacker intercepts data and retransmits it at a later time to gain unauthorised access or duplicate a transaction.
Frameworks that govern replay attack
What the standards actually require on replay attack
Requirements naming replay attack across 5 standards, quoted from the control text.
MFA systems are implemented as follows: • The MFA system is not susceptible to replay attacks. • MFA systems cannot be bypassed by any users, including administrative users unless specifically documented, and authorized by
8.5.1 · MFA systems are implemented as follows: • The MFA system is not susceptible to replay attacks. • MFA systems cannot be bypassed by any users, including administrative users unless specifically documented, and authorized by →HL7 FHIR Transport Security. TRANSPORT LAYER SECURITY (TLS) - all FHIR APIs MUST use TLS 1.2+ for production + TLS 1.3 recommended; certificate validation + trust chain + certificate pinning where appropriate + HSTS + secure session establishment + cipher suit...
HL7-FHIR-Transport-TLS-Communication · HL7 FHIR Transport Security - TLS 1.2+, Communication Security, Time Keeping, Server CapabilityStatement →Threats during the authentication event including replay attacks, man-in-the-middle, and session hijacking
29115-9.4 · Authentication mechanism threats →Address OWASP Top 10 A07 Identification and Authentication Failures per OWASP Top 10:2025. Identification and Authentication Failures arise from weak password + session management + credential storage + recovery + reuse attacks + credential stuffing + session...
OWASPTOP10-7 · A07:2025 Identification and Authentication Failures →Presentations are typically short-lived and must include temporal validity constraints to prevent replay attacks.
VP-3 · Presentation Validity →Questions people ask about replay attack
What is Replay Attack?
Why is Replay Attack important for compliance?
Which compliance frameworks address Replay Attack?
Where can I learn more about Replay Attack?
See how Replay Attack applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.