Frameworks / FIDO2 / WebAuthn / FIDO2-Phishing-Resistance FIDO2 / WebAuthn
FIDO2/WebAuthn: Relying Party Implementation, Phishing Resistance and Security
FIDO2 / WebAuthn FIDO2-Phishing-Resistance: Phishing Resistance, Channel Binding, Anti-Replay and Privacy FIDO2 PHISHING RESISTANCE properties + the channel binding + anti-replay + privacy mechanisms. PHISHING RESISTANCE: WebAuthn ceremonies bind the authentication to the ORIGIN (cryptographically verified by the client + RP server); a phishing site at evil.example.com cannot complete a WebAuthn assertion for legitimate.example.com - the browser + authenticator refuse the binding. NIST SP 800-63B Section 5.2.5 + the 2024 OMB M-22-09 + ZTA strategy mandate phishing-resistant authentication for high-impact federal systems + recommend FIDO2 + PIV/CAC. CHANNEL BINDING (legacy via Token Binding RFC 8471/8472, now deprecated) bound the assertion to the TLS channel preventing relay; the current model relies on origin binding + clientDataJSON inclusion in the signed authenticatorData + clientDataHash. ANTI-REPLAY: challenge-based per ceremony + signature counter (signCount monotonic) + anti-replay timestamping (RP issues + tracks challenge nonces with TTL + binds to client + session). CLONE DETECTION: signCount monotonic; lower-than-stored counter indicates a cloned authenticator + the credential MUST be revoked or step-up triggered. PRIVACY: AAGUID + attestation are anonymised (per-batch); discoverable credentials use opaque user-handle not user-identifying; cross-site tracking is prevented by per-RP-ID credential scoping (no global identifier); enterprise attestation is the explicit privacy-degraded exception for managed deployments.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 245 controls across 133 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing ISO27043-13 Authentication and password management ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) ISO21434-13 Authentication and password management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-19 Certificate management OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management ASD37-17 TLS encryption between email servers (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) AWWA-2.2 Authentication Mechanisms AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity ISO27799-02 ePHI encryption at rest and in transit ISO27799-12 Unique user identification and authentication ISO27799-16 Transmission security and encryption PQC-5 Cryptographic Inventory and PQC Migration Roadmap PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response QRCM-1.2 Quantum-Vulnerable Identification QRCM-3.1 Hybrid Solution Deployment (2025-2030) QRCM-4.2 TLS 1.3 Adoption OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-7 A07:2025 Identification and Authentication Failures BSI-03 Multi-factor authentication requirements BSI-08 Cryptographic protection of data CJIS-8 Media Protection CJIS-9 System and Communications Protection FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment GhCSA-Service-Provider-Licensing-Professional Cybersecurity Service Provider Licensing and Professional Accreditation 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-2 Information Security Program (ISP) - Section 4 NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP123-3 Authentication, Access Control, and Account Management NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NDPA-1 Applicability, Scope, and Carve-Outs NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-7 Cross-Border Data Transfers and International Cooperation ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-6 Security Misconfiguration and Secure API Design OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts PTESPHASE-2 Intelligence Gathering (OSINT) PTESPHASE-3 Threat Modeling CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication ISMSP-AC-03 Authentication Mechanisms ISMSP-SYS-02 Encryption Implementation AMLCTF-35 Identity Verification Standard APPI-A34 Request for Correction, Addition or Deletion DSO-3 Data Access Management LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation MT-CDPA-Universal-Opt-Out-Mechanism-1-January-2025-GPC-Global-Privacy-Control-Mandatory-Recognition Montana CDPA Universal Opt-Out Mechanism + 1 January 2025 + GPC + Global Privacy Control + Mandatory Recognition NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NHPA-6 Reasonable Data Security and Breach Response NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-3 API Security Standards, mTLS, and Encryption OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-2 SCA Exemptions and Risk-Based Authentication NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training AUPRV-4 APP 10-11 Quality, Security of Personal Information NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing RCEPEC-1 Online Personal Information Protection (12.13) EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice SA-PDPL-13 Encryption of personal data IM8-CLD.2 Cloud Security Controls TEFCAREC-1 Common Agreement Conformance and Onboarding TSAPIPE-2 OT/IT Network Segmentation and Access Control TURKEYKVKK-2 Information Notice and Data Subject Rights CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VIETNAMPDP-2 Consent and Notice Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in FIDO2/WebAuthn: Relying Party Implementation, Phishing Resistance and Security Query this from an agent The graph holds this control, the 245 it maps to, and the evidence behind each claim, over MCP and REST.