Authentication - Use of Authenticator Types Without Verifier-Compromise Resistance Requirements, v1.0

Verifiers may have no compromise resistance requirements for some authenticator types.

Assessment Step

1
No Verifier Resistance (NoVerifierResistance)
Does the authentication verifier have no compromise resistance requirements? In some cases this is because the authenticator cannot be compromise resistant (such as TOTP where the verifier must have a copy of the shared secret to perform authentication).
Artifact
A1
Provide evidence (e.g. policies, operational details, processes) that the authentication verifier has no compromise resistance requirements?

Conformance Criteria (1)

C1
Chosen Authenticator types has no verifier resistance requirements.
Citation
NIST SP 800-63B
Section 5.2.7