Authentication - Use of Out-of-Band Device, v1.0

An out-of-band authenticator is a physical device that is uniquely addressable and can communicate securely with the verifier over a distinct communications channel. There are many ways to use such a device in authentication and doing so must adhere to rules found within NIST 800-63-3B: 5.1.3

Assessment Steps (2)

1
Out of Band Authenticators (OutofBandAuthenticators)
Does the out-of-band authenticator meet the criteria specified in NIST 800-63-3B: Section 5.1.3.1.
Artifact
A1
Provide evidence (e.g. policies, risk assessment documentation) that the use of out-of-band authenticator devices adheres to requirements.
2
Out of Band Verifiers (OutofBandVerifiers)
Does the out-of-band verifier meet the criteria specified in NIST 800-63-3B: Section 5.1.3.2.
Artifact
A1
Provide evidence (e.g. policies, risk assessment documentation) that the out-of-band verifiers adheres to requirements.

Conformance Criteria (2)

C1
CSPs using out of band authenticators MUST adhere to requirements in NIST 800-63-3B: Section 5.1.3.1.
Citation
NIST SP 800-63B
Section 5.1.3.1
C2
CSPs using out of band verifiers must adhere to requirements in NIST 800-63-3B: Section 5.1.3.2.
Citation
NIST SP 800-63B
Section 5.1.3.2