Verify system generated initial passwords or activation codes SHOULD be securely randomly generated, SHOULD be at least 6 characters long, and MAY contain letters and numbers, and expire after a short period of time. These initial secrets must not be permitted to become the long term password.
Level 1 required: True
Level 2 required: True
Level 3 required: True
CWE: 330
Verify that enrollment and use of user-provided authentication devices are supported, such as a U2F or FIDO tokens.
Level 1 required: False
Level 2 required: True
Level 3 required: True
CWE: 308
Verify that renewal instructions are sent with sufficient time to renew time bound authenticators.
Level 1 required: False
Level 2 required: True
Level 3 required: True
CWE: 287
Credit via OWASP ASVS. For more information visit The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v3.0 license.
Loading comments 0%