Frameworks / OWASP Top 10:2025 / OWASPTOP10-7 OWASP Top 10:2025
Authentication
OWASP Top 10:2025 OWASPTOP10-7: A07:2025 Identification and Authentication Failures Address OWASP Top 10 A07 Identification and Authentication Failures per OWASP Top 10:2025. Identification and Authentication Failures arise from weak password + session management + credential storage + recovery + reuse attacks + credential stuffing + session fixation + replay attacks. Mitigations include (a) implement strong password requirements aligned to NIST SP 800-63B including compromised password checking + (b) require multi-factor authentication for sensitive operations + privileged accounts + (c) implement secure password storage using adaptive hashing (Argon2 + bcrypt + PBKDF2 + scrypt) + (d) implement credential lifecycle management + (e) implement secure session management including cryptographically random tokens + secure cookies + appropriate timeout + (f) implement rate limiting + account lockout against brute force.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 61 controls across 46 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CWE-287 Improper Authentication CWE-306 Missing Authentication for Critical Function CWE-798 Use of Hard-coded Credentials 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) Part11.300 Controls for identification codes and passwords (21 CFR §11.300) FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access 23837-1.7.3 Authentication and classical post-processing 27400-6.1 Secure Device Design MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPAPI-2 Broken Authentication and Token Management OWASPASVS-2 Authentication and Credential Storage (V2 + V2.4) DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns RUSPD-2 Lawful Basis, Consent, Notice Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.