Skip to main content

WUH-8.3.1-Sec-02 — No operation before app-level authentication

After the initial setup of application-level authentication, no operation shall be possible on the wallet unit before application-level authentication. In particular, WSCA/WSCD authentication shall not be possible before being authenticated with application-level authentication.

PropertyValue
Section8.3.1 Auth
Ownerplatform

Mapped Controls

ControlTitle
SID-AUTH-01FIDO2/WebAuthn Passwordless Authentication
SID-AUTH-02JWT Bearer Token Session Management
SID-ACCESS-02Rate Limiting and Brute-Force Protection
SID-AUTH-05Wallet Unlock, Lockout, and PIN Security

Source: ENISA – Security Requirements for European Digital Identity Wallets v0.5