Skip to content

DIRA Additional Considerations #845

@idmken

Description

@idmken

The DIRA playbook should have a section on additional considerations which may not be specific to the DIRA process. For example:

  1. If the DIRA requires a phishing-resistant AAL2 but the recovery process is a phishable AAL2, that is a risk.
  2. If re-authentication at each attempt is not required, include a link to the NIST 800-63 table on re-authentication time frames

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions