SEARCH RESULTS


NIST SP 800-175b Guideline for Using Cryptographic Standards in the Federal Government     3.1 3.1.13 3.1.17 3.1.19 3.13 3.13.10 3.13.11 3.13.15 3.13.16 3.13.8 3.5 3.5.10 3.8 3.8.6 Access Control Identification and Authentication Media Protection System and Communications Protection

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-175Br1.pdf

This NIST Special Publication is one part in a series of documents intended to provide guidance to the Federal Government for using cryptography to protect its sensitive, but unclassified digitized information during transmission and while in storage.

Open Web Application Security Project (OWASP) – Testing for Account Enumeration and Guessable User Account     3.5.2 3.5.7 3.5.8 3.5.9 csc4.2 Identification and Authentication

https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/03-Identity_Management_Testing/04-Testing_for_Account_Enumeration_and_Guessable_User_Account

The scope of this test is to verify if it is possible to collect a set of valid usernames by interacting with the authentication mechanism of the application.