Please enable JavaScript.
Coggle requires JavaScript to display documents.
Authenticator - Risk Based - Coggle Diagram
Authenticator - Risk Based
Secrets
L2
Moderate Risk
Commercial/RHO domains
ASP
Globals
Spheres
C2
AWS
Malvern
Administrative accounts
L3
High Risk
Federal domains
L1
Low Risk
NorthAmerica
MFA authenticators
L3
HIgh
RSA Security
IAL 3 + AAL3ish
L2
Moderate
Duo Security
OTP
Duo Push
Yubikeys
FIDO
IAL 2 + AAL2
Verifers
L1
Security Questions
N of N questions answered
MFA
Recovery Keys
Lookup Secrets
L2
Gap today
Capabilities/Actions
Reset authenticator
Secrets
L2
L1/2 Secret + MFA
L3
Admin assisted
L1
L1/2 Secret + MFA
L1 verifier???
Verfiers
L1
Secret
MFA
L1/L2 Secret + MFA
MFA authenticators
L2
L1/L2 Secret + MFA Verifier
L3
Admin assisted
Admin assisted
reset L1 verifier when no options exists
L2/3 secret reset/unlock
Guiding Principles
multiple authenticators of the same factor can't be used to perform reset functions
Possession of 1 factor shouldn't elevate to possessing another authenticator or factor
Verifiers used for a specific factor/authenticator type can't be used to reset another factor/authenticator type
Unique verifiers should be deployed for each authenticator type