NIST 800-63-4 introduces a Digital Identity Risk Management (DIRM) framework and explicitly prioritizes stronger authentication protocols that are resistant to phishing attacks. Furthermore, it redefines assurance levels from point-in-time verification towards continuous evaluation of threats, service impacts, and user populations.
This move also disfavored email OTP and reduced SMS-based authentication methods, and cemented FIDO2 passkeys as the gold standard of authentication.
...
28 views
0 likes