Risk-Based Authentication
What is Risk-Based Authentication?
An adaptive authentication approach that adjusts security requirements based on the assessed risk level of a login attempt, considering factors like location and device.
Terms that appear alongside risk-based authentication
Each of these is named in at least one of the same controls as risk-based authentication. The number is how many controls name both.
- authentication 9 shared controls
- access control 4 shared controls
- oauth 3 shared controls
- multi factor authentication 3 shared controls
- saml 3 shared controls
- nist 3 shared controls
- digital identity 2 shared controls
- zero trust 2 shared controls
Frameworks that govern risk-based authentication
What the standards actually require on risk-based authentication
Requirements naming risk-based authentication across 6 standards, quoted from the control text.
The DS and ACS use the rich transaction, device and contextual data carried by 3DS to assess the risk of a transaction and decide frictionless vs challenge, supporting issuer fraud strategies while limiting friction.
EMV3DS-18 · Risk-based authentication →Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control.
JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication · Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security →Per PSD2 RTS Articles 10-18: SCA exemptions. Requirements include (a) implement Low-Value Exemption for amounts up to EUR 30 cumulative EUR 100 + (b) implement Trusted Beneficiary Exemption for whitelisted payees + (c) implement Recurring Transaction Exemption...
PSDTWO-2 · SCA Exemptions and Risk-Based Authentication →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →RBI AA Audit + Logging + Authentication establishes the assurance layer for the AA ecosystem. (1) IT System Audit: per RBI Cyber Security Framework + RBI IT Guidelines for NBFC-AA - bi-annual or annual independent IT system audit by qualified auditors (CISA +...
RBI-AA-Audit-Logging-IT-System-Audit-Consent-Lifecycle-Authentication · RBI AA Audit + Logging - IT System Audit + Consent Lifecycle Logging + Customer Authentication + Bi-Annual Audit + RBI Inspection + Sahamati Compliance Reporting →Questions people ask about risk-based authentication
What is Risk-Based Authentication?
Why is Risk-Based Authentication important for compliance?
Which compliance frameworks address Risk-Based Authentication?
Where can I learn more about Risk-Based Authentication?
See how Risk-Based Authentication applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.