@@ -1286,7 +1286,7 @@ These requirements apply to the product, regardless of the product's use case an
* integration of an external Identity Management System into the product, or
* a dedicated Identity Management module built into the product.
***AAC_AUTH-2** The product shall not implement a design where default credentials or keys are used to identify subjects.
***AAC_AUTH-3**Product shall use multi-factor authentication to confirm the identity of a natural user appropriate to the intended and reasonably foreseeable use.
***AAC_AUTH-3**The product shall use multi‑factor authentication to authenticate system users.
***AAC_AUTH-4** Product shall limit a natural user's authorisation validity of a session via a configurable setting that shall be initially limited by factory default of one day.
***AAC_AUTH-5** The authorisation model shall enforce separation of privileges appropriate to the intended and reasonably foreseeable use of the product.
***AAC_AUTH-6** All access to privileged interfaces, control functions, and sensitive operations shall be subject to strong authentication of subjects, services, or integrated components.