Authentication Factor Lifecycle and Recovery

V6.4.1

Verify that system generated initial passwords or activation codes are securely randomly generated, follow the existing password policy, and expire after a short period of time or after they are initially used. These initial secrets must not be permitted to become the long term password.

Required for Level 1, 2 and 3

CAPEC™ (3.9): 151, 49, 633

V6.4.2

Verify that password hints or knowledge-based authentication (so-called "secret questions") are not present.

Required for Level 1, 2 and 3

CAPEC™ (3.9): 114, 115, 151, 16, 49, 560, 70

V6.4.3

Verify that a secure process for resetting a forgotten password is implemented, that does not bypass any enabled multi-factor authentication mechanisms.

Required for Level 2 and 3

CAPEC™ (3.9): 114, 115, 151, 49, 50

V6.4.4

Verify that if a multi-factor authentication factor is lost, evidence of identity proofing is performed at the same level as during enrollment.

Required for Level 2 and 3

CAPEC™ (3.9): 114, 115, 151, 50

V6.4.5

Verify that renewal instructions for authentication mechanisms which expire are sent with enough time to be carried out before the old authentication mechanism expires, configuring automated reminders if necessary.

Required for Level 3

CAPEC™ (3.9): 518, 519, 603, 607

V6.4.6

Verify that administrative users can initiate the password reset process for the user, but that this does not allow them to change or choose the user's password. This prevents a situation where they know the user's password.

Required for Level 3

CAPEC™ (3.9): 416, 50, 518, 519, 548, 603, 607

Disclaimer

Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.

Github logo View source on GitHub

OWASP Cornucopia

OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use. OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 4.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.

© 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.