Federated Re-authentication
V7.6.1
Verify that session lifetime and termination between Relying Parties (RPs) and Identity Providers (IdPs) behave as documented, requiring re-authentication as necessary such as when the maximum time between IdP authentication events is reached.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 195, 21, 31, 464, 465, 510, 543, 593, 98
V7.6.2
Verify that creation of a session requires either the user's consent or an explicit action, preventing the creation of new application sessions without user interaction.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 416
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.