Manage authenticator lifecycle per NIST SP 800-63-4 Volume B Chapter 6. Binding per Section 6.1: bind authenticator to verified subscriber identity. Authenticator recovery per Section 6.2: post-loss recovery via re-proofing OR strong alternative evidence + alternative authenticator + risk-based controls. Authenticator replacement per Section 6.3. Authenticator expiration per Section 6.4 covering cryptographic key lifetime + biometric template freshness + memorised secret rotation policy (note: Rev 4 retains the no-arbitrary-rotation guidance but allows rotation on suspected compromise). Authenticator suspension per Section 6.5: temporary suspension on suspected compromise + clear unsuspend procedure. Authenticator revocation per Section 6.6: terminal revocation on confirmed compromise + clear binding-replacement workflow. Lifecycle event records per Section 6.7. Subscriber notification of binding changes per Section 6.8. Strong account recovery without weak fallback mechanisms (no security questions + no static PINs as sole factor).
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 72 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.