Term · 28. International Regulations
Step-Up Authentication
Definition
Pattern requiring additional authentication factors when an authenticated user attempts an action of elevated sensitivity — wire transfer, password change, admin operation, sensitive data export. The base session uses one factor (e.g., password); the sensitive action triggers MFA challenge. Improves UX by avoiding MFA at every login while maintaining strong control on high-impact actions.
- Synonyms
-
- Step-up auth
- Application
- Regulatory: GDPR — EU 2016/679 · NIST SP 800-63 (Digital Identity Guidelines) · PCI DSS v4.0.1 Req. 7-8
- Standards & regulations
-
- GDPR
- NIST
- PCI
- Sources
-
- GDPR — Regulation (EU) 2016/679 (EUR-Lex) primary source
Related terms
-
HITRUST CSF (Common Security Framework) (HITRUST)
Healthcare-focused certifiable framework consolidating HIPAA, HITECH, NIST, ISO 27001, PCI DSS, GDPR, and 40+ other auth …
-
Multi-factor Authentication (MFA)
Authentication requiring two or more independent factors from different categories: knowledge (password), possession (ph …
-
Password Policy
Rules governing password creation, complexity, length, lifetime, and reuse. NIST SP 800-63B (current guidance) — minimum …
-
Audit
Independent examination of identity controls, processes, and records to verify compliance with policy and regulatory req …
-
Audit Trail
Chronological record of identity events — authentication, authorization decisions, provisioning actions, configuration c …
-
Automated Data Classification
Machine learning-driven discovery and classification of sensitive data across structured and unstructured stores — ident …