Commit 3fd58feb authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Slight clarification to AUT-1 risk factor

parent ee9e12f4
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -585,7 +585,7 @@ Description: Affects likelihood of threats involving authentication.
Rationale: An improper account management and authentication implementation can directly impact with a successful breach

* **[AUT-0]** User employs a third party identity and authentication provider
* **[AUT-1]** Identity and authentication are managed by the user through a centralised identity system
* **[AUT-1]** Identity and authentication are managed through a user-owned and managed centralised identity system
* **[AUT-2]** Each system utilised by the user involves its own set of account information and secrets

### C.2.4 RF-DAT: Sensitivity of data