Authentication - CSP Mechanism for Authenticator Revocation or Suspension Upon Theft or Loss, v1.0

Credential Service Providers must be able to revoke or suspend authenticators in cases where the authenticator may have been stolen or lost.

Assessment Step

1
Authenticator Suspension (AuthenticatorSuspension)
Does the CSP have a capability to immediately revoke or suspend an authenticator when needed?
Artifact
A1
Provide evidence (e.g. policies, processes, screenshots) that the CSP is able to revoke or suspend an authenticator immediately upon notice by a subscriber that their authenticator may be lost or stolen.

Conformance Criteria (1)

C1
The CSP SHALL provide a mechanism to revoke or suspend the authenticator immediately upon notification from subscriber that loss or theft of the authenticator is suspected.
Citation
NIST SP 800-63B
Section 5.2.1