Commit 1860a0a3 authored by Santeri Toikka's avatar Santeri Toikka
Browse files

Added applicability to AC_AUTH-2

Closes #670
parent 631cecad
Loading
Loading
Loading
Loading
+1 −0
Original line number Diff line number Diff line
@@ -1467,6 +1467,7 @@ These requirements apply to the product, regardless of the product's use case an
  2. integration of an external Identity Management System into the product, or
  3. a dedicated Identity Management module built into the product.
* **AAC_AUTH-2** The product shall not allow for default credentials or keys to be used to identify subjects.
  * This requirement does not apply to tailor-made products, where product user requests changes as per CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (b).
* **AAC_AUTH-3** The product shall use multi‑factor authentication to authenticate system users.
* **AAC_AUTH-4** The product shall limit a system user’s session validity duration via a configurable setting that shall initially be limited to a default of, at maximum, one day.
* **AAC_AUTH-5** The authorization model shall enforce separation of privileges appropriate to the use case.