Stop Counting Factors... Start Describing Authentication Events

Stop Counting Factors... Start Describing Authentication Events

Source: YouTube · FIDO Alliance · published Feb 7, 2025 · 31:55

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

Pamela Dingle and Dean Saaks propose replacing the outdated practice of counting authentication factors with a framework of seven credential management properties to more precisely describe authentication security 0:42.

Key Takeaways:
• Traditional factor-based thinking creates an "illusion of diversity" since multiple factors often share the same credential boundary and unlock mechanism 0:42
• The proposed framework defines seven property classes: boundary, recovery, containment/unlock, reuse, enrollment, provider provenance, and compliance 0:49
• The speakers invite the identity community to help standardize this vocabulary through IETF, OpenID Foundation, or FIDO Alliance 0:52

Moving from factor counting to property-based descriptions could enable more precise security standards that better protect users authenticating online.

Sources:

  • 0:42 Speaker credentials framing the standards discussion
  • 0:49 Interoperability patterns as foundation for new framework
  • 0:52 Standards body collaboration context
  • 0:09 Session introduction and speaker setup

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

uh I'm Pam Dingle I am uh one of your friendly neighborhood program committee members and I'm introducing myself and my colleague Dean saaks good morning good morning uh so we are going to do questions in the app if you're online um but I have to check them myself so oh you got me oh Megan's here awesome all right so we can just listen to Megan and Life's good all right let's go oh wow my mic is hot very that's all we need to know as are these lights as usual all right so Pam why you introduce yourself and then we'll get we'll get rolling here all right perfect uh so my name is Pamela Dingle I am the director of identity standards at Microsoft so I work with a team of Highly amazing individuals who go out to different standards bodies and try to make interoperability patterns that can work…