Skip to content

Commit 63e2483

Browse files
authored
Update c7-secure-digital-identities.md (for real now)
1 parent fdd2d8c commit 63e2483

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

docs/the-top-10/c7-secure-digital-identities.md

+3-1
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,9 @@ The [NIST Special Publication 800-63B: Digital Identity Guidelines (Authenticati
1313

1414
NIST 800-63b describes three levels of authentication assurance called Authentication Assurance Level (AAL):
1515

16-
#### Level 1 : Passwords: The first level, AAL level 1 is reserved for lower-risk applications that do not contain PII or other private data. At AAL level 1 only single-factor authentication is required, typically through the use of a password (something you know). The security of passwords (or credentials in general) is of utmost importance, this includes both secure storage (using a key-derivation function and such) as well as corresponding processes, e.g. having a secure password-reset flow.
16+
#### Level 1 : Passwords:
17+
18+
The first level, AAL level 1 is reserved for lower-risk applications that do not contain PII or other private data. At AAL level 1 only single-factor authentication is required, typically through the use of a password (something you know). The security of passwords (or credentials in general) is of utmost importance, this includes both secure storage (using a key-derivation function and such) as well as corresponding processes, e.g. having a secure password-reset flow.
1719

1820
#### Level 2 : Multi-Factor Authentication
1921

0 commit comments

Comments
 (0)