Authentication Requirements



Definitions

A authentication requirement is any access control requirement that specifies a required amount of the security quality subfactor authentication.

Objectives

The typical objectives of authentication requirement are to:

Measurements

Authentication requirements are typically specified in terms of the following measurements:

Examples

General Examples

The following are typical examples of authentication requirements:

The following are typical examples of authentication constraints:

The preceding examples are written as absolutes and are therefore theoretically not feasible because no system is 100% effective against security attacks. To make the requirement more feasible and testable, a minimum success threshold can be added as follows:

Specific Examples

The following are examples of authentication requirements from the Global Personal Marketplace (GPM) system, a global Web-based marketplace bringing together private individuals and small companies to buy and sell all manner of items:

Guidelines

The following guidelines have been found to be useful when producing authentication requirements: