Skip to main content

V1.2 — Authentication Architecture

Authentication Architecture: 4 L3 requirement(s). V1.2.1: Verify the use of unique or special low-privilege operating system accounts for all application components, services, an... V1.2.2: Verify that communications between application components, including APIs, middleware and data layers, are authenticated... V1.2.3: Verify that the application uses a single vetted authentication mechanism that is known to be secure, can be extended to... ... and 1 more.

PropertyValue
SectionV1.2
Ownerplatform

Mapped Controls

ControlTitle
SID-AUTH-01FIDO2/WebAuthn Passwordless Authentication
SID-AUTH-02JWT Bearer Token Session Management
SID-AUTH-03OIDC Gate for External Identity Providers
SID-AUTH-04WebSocket JWT Handshake Authentication

Source: OWASP Application Security Verification Standard 4.0.3