Threat CC.AX.CCC-nS.6.1.3

URI: CC.AX.CCC-nS.6.1.3

Package: ProcessComms

< prev | next >

Description: Client Client unable to use 2-factor authentication to access service Service: if service Service requires clients to authenticate using a second factor (e.g. a one time key or out of band key exchange), but this is not available to Client then access will be impossible.

Threat Type: Primary Threat

Matching Pattern:

CC.AX.CCC-nS.6.1.3
MP-CCC-nS

Finds a Client that is not sharing or forwarding credentials, with access to a Service that does not use a separate authenticator, the ClientChannel between them, the Client and Service hosts and optionally the Client user and Service manager.

        (empty)

CSG-ClientOneTimeKeyAccess

Access to a service Service requires a one time key, generated using a one time key device which itself requires a password entered by the user Human, who then types the one time key into their client application Client.

CSG-ClientOutOfBandKeyAccess

Access to a service Service requires the user Human to supply a password, and then enter a key which is sent to them via a separate channel into their client application Client.