Defenses Against Session Abuse
V7.5.1
Verify that the application requires full re-authentication before allowing modifications to sensitive account attributes which may affect authentication such as email address, phone number, MFA configuration, or other information used in account recovery.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 114, 115, 151, 21, 50
V7.5.2
Verify that users are able to view and (having authenticated again with at least one factor) terminate any or all currently active sessions.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 151, 195, 21, 31, 464, 465, 510, 543, 593, 98
V7.5.3
Verify that the application requires further authentication with at least one factor or secondary verification before performing highly sensitive transactions or operations.
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 114, 115, 151, 21, 49, 50
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.