Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication confirms that each party to a communication (for example a person, device, service or application) really is who it claims to be, and gives assurance that no party is impersonating another or replaying an earlier exchange without authorization. (1) Authentication Categories per X.805 + X.800 + X.811 framework: (a) Peer Entity Authentication - mutual + unilateral + verifying communicating parties; (b) Data Origin Authentication - verifying source of received data; (c) Authentication of the User + Device + Service + Application + Process. (2) Authentication Factors per NIST SP 800-63: (a) Something you know - password + PIN + passphrase; (b) Something you have - smart card + token + hardware key + mobile device; (c) Something you are - biometric (fingerprint + face + iris + voice + behavioural); (d) Somewhere you are - geolocation + IP + device fingerprint; (e) Something you do - behavioural biometrics + typing pattern. Multi-Factor Authentication (MFA) combines 2+ factors from different categories. (3) Strong Authentication Mechanisms: (a) Public Key Infrastructure (PKI) + X.509 Certificates; (b) Kerberos (TGT + service tickets); (c) FIDO2 + WebAuthn + Passkeys; (d) OAuth 2.0 + OpenID Connect + JWT tokens; (e) SAML 2.0 SSO; (f) Time-Based One-Time Password (TOTP) + RFC 6238; (g) HMAC-Based OTP (HOTP) + RFC 4226; (h) Out-of-Band + push notification + SMS (deprecated by NIST); (i) Biometric authentication (FIDO biometrics + Apple Face ID + Touch ID + Windows Hello); (j) Hardware tokens (YubiKey + RSA SecurID + Google Titan); (k) Smart cards + PIV + CAC + national eID. (4) Authentication per Security Layer: (a) Infrastructure - device authentication + 802.1X + MACsec mutual auth + physical port authentication + IPSec IKEv2 mutual; (b) Services - service-level auth + IMS AKA + 5G AKA + Diameter authentication + RADIUS + TACACS+; (c) Applications - application user auth + email + web + directory + file transfer + IM. (5) Authentication per Security Plane: (a) Management - administrator authentication + multi-factor mandatory + privileged access; (b) Control - signalling node authentication + BGP MD5/RPKI + OSPF MD5/HMAC + IS-IS MD5 + IKE; (c) End-User - subscriber + user authentication + SIM + EAP-SIM/AKA + WPA2-Enterprise EAP-TLS. (6) Threats Mitigated per X.805 Table 1: (a) Corruption (Y) - prevents unauthorized changes by impostors; (b) Disclosure (Y) - prevents impostor obtaining information; (c) Interruption (Y) - prevents impostor service disruption. (7) Standards: (a) ISO/IEC 27001 A.9.2 + A.9.4 (2013) / A.5.16 + A.8.5 (2022); (b) NIST SP 800-53 IA family; (c) NIST SP 800-63A/B/C Digital Identity; (d) ITU-T X.509 PKI; (e) ITU-T X.811 Authentication Framework; (f) 3GPP TS 33.501 5G Auth + 33.220 GBA; (g) IETF RFC 4226/6238 OTP + RFC 8252 OAuth Native Apps + RFC 6749 OAuth 2.0; (h) FIDO Alliance specifications; (i) ICAO Doc 9303 Machine Readable Travel Documents; (j) GSMA Mobile Connect; (k) eIDAS Regulation (EU); (l) ENISA Trust Services and eIDAS. (8) Modern Evolution: (a) Passwordless authentication via FIDO2/WebAuthn/Passkeys; (b) Continuous Authentication via behavioural biometrics; (c) Risk-Based Authentication (RBA) with context; (d) Decentralised Identity (DID) + Verifiable Credentials (VCs); (e) Self-Sovereign Identity (SSI); (f) Zero Trust Identity verification continuous; (g) Adaptive MFA; (h) Workload Identity (SPIFFE/SPIRE); (i) Post-Quantum Cryptography (PQC) for authentication keys. Coordinates with ITU-T X.509 PKI + X.811 Authentication Framework + X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Corruption/Disclosure/Interruption + Security Dimension 1 Access Control + ISO/IEC 27001 + NIST SP 800-53 + NIST SP 800-63 + FIDO Alliance + 3GPP 5G AKA + GSMA Mobile Connect + IETF OAuth + eIDAS. ITU-T X.805 Security Dimension 2 Authentication applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 119 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.