Authentication Documentation
V6.1.1
Verify that application documentation defines how controls such as rate limiting, anti-automation, and adaptive response, are used to defend against attacks such as credential stuffing and password brute force. The documentation must make clear how these controls are configured and prevent malicious account lockout.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 114, 115, 116, 151, 2, 49, 50, 70
V6.1.2
Verify that a list of context-specific words is documented in order to prevent their use in passwords. The list could include permutations of organization names, product names, system identifiers, project codenames, department or role names, and similar.
Required for Level 2 and 3
Related CAPEC™ Requirements
V6.1.3
Verify that, if the application includes multiple authentication pathways, these are all documented together with the security controls and authentication strength which must be consistently enforced across them.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 113, 114, 115, 151, 179, 50
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.