Article 97 mandates Strong Customer Authentication (SCA) by PSPs when the payer (a) accesses its payment account online; (b) initiates an electronic payment transaction; (c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses. SCA is defined in Article 4(30) as an authentication based on the use of two or more elements categorised as: knowledge (something only the user knows, e.g. password / PIN / answer to a secret question - not username / email which are identifiers); possession (something only the user possesses, e.g. token + smart card + phone running an authentication app); inherence (something the user is, e.g. fingerprint + face + voice biometric); the elements must be independent so that the breach of one does not compromise the reliability of the others. For electronic remote payment transactions (Article 97(2)) SCA must include elements which dynamically link the transaction to a specific amount + specific payee (dynamic linking). PSPs must apply adequate security measures to protect the confidentiality + integrity of the PSUs personalised security credentials (Article 97(3)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.