Authentication Factor Lifecycle and Recovery
V6.4.1
Verify that system generated initial passwords or activation codes are securely randomly generated, follow the existing password policy, and expire after a short period of time or after they are initially used. These initial secrets must not be permitted to become the long term password.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
V6.4.2
Verify that password hints or knowledge-based authentication (so-called "secret questions") are not present.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 114, 115, 151, 16, 49, 560, 70
V6.4.3
Verify that a secure process for resetting a forgotten password is implemented, that does not bypass any enabled multi-factor authentication mechanisms.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 114, 115, 151, 49, 50
V6.4.4
Verify that if a multi-factor authentication factor is lost, evidence of identity proofing is performed at the same level as during enrollment.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 114, 115, 151, 50
V6.4.5
Verify that renewal instructions for authentication mechanisms which expire are sent with enough time to be carried out before the old authentication mechanism expires, configuring automated reminders if necessary.
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 518, 519, 603, 607
V6.4.6
Verify that administrative users can initiate the password reset process for the user, but that this does not allow them to change or choose the user's password. This prevents a situation where they know the user's password.
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 416, 50, 518, 519, 548, 603, 607
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.