FIDO Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: A FIDO authenticator vendor wants to claim FIPS 140-2 compliance. Which component of the authenticator must be validated?
- The USB interface firmware
- The cryptographic module performing key operations (Correct answer)
- The attestation certificate chain
- The CTAP2 protocol stack
Correct answer: The cryptographic module performing key operations
FIPS 140-2 validation applies specifically to the cryptographic module that performs key generation, signing, and other cryptographic operations.
Question 2: Under the Americans with Disabilities Act (ADA), what obligation do relying parties have when deploying FIDO authentication?
- Deploy only biometric authenticators for simplicity
- Offer accessible alternatives for users who cannot use physical authenticators (Correct answer)
- Exempt disabled users from MFA requirements entirely
- Use only voice-based FIDO authentication
Correct answer: Offer accessible alternatives for users who cannot use physical authenticators
ADA compliance requires relying parties to provide reasonable accommodations, including accessible authentication alternatives for users who cannot operate standard FIDO devices.
Question 3: Which regulatory framework specifically addresses strong customer authentication (SCA) for online payments in Europe and is compatible with FIDO2?
- MiFID II
- PSD2 (Correct answer)
- Basel III
- DORA
Correct answer: PSD2
PSD2's Strong Customer Authentication (SCA) requirements mandate two-factor authentication for online payments, which FIDO2 authenticators can satisfy.
Question 4: A FIDO relying party in the financial sector is subject to FFIEC guidance. What does FFIEC guidance say about authentication risk assessments?
- Risk assessments are optional for banks under $1B in assets
- Institutions must perform periodic risk assessments to evaluate authentication adequacy (Correct answer)
- FFIEC mandates FIDO specifically for all transactions
- Risk assessments only apply to mobile banking applications
Correct answer: Institutions must perform periodic risk assessments to evaluate authentication adequacy
FFIEC guidance requires financial institutions to conduct periodic risk assessments of their authentication controls to ensure they remain adequate against evolving threats.
Question 5: The Cybersecurity Maturity Model Certification (CMMC) for US defense contractors requires MFA for which scenario?
- Access to publicly available contractor websites
- Remote access and access to CUI (Controlled Unclassified Information) (Correct answer)
- Internal cafeteria ordering systems
- Contractor personal email accounts
Correct answer: Remote access and access to CUI (Controlled Unclassified Information)
CMMC Level 2 and above requires MFA for remote access and for accessing systems containing Controlled Unclassified Information (CUI).
Question 6: Under SOC 2 Type II audits, how is a FIDO-based MFA deployment typically evaluated?
- Auditors verify the FIDO Alliance logo on devices
- Auditors test the design and operating effectiveness of authentication controls over time (Correct answer)
- SOC 2 explicitly excludes authentication from its scope
- Auditors only check that passwords are at least 12 characters
Correct answer: Auditors test the design and operating effectiveness of authentication controls over time
SOC 2 Type II audits evaluate both the design and operating effectiveness of security controls, including MFA, over an extended observation period.
Question 7: Which international standard provides a framework for information security management that organizations use to demonstrate FIDO deployment governance?
- ISO 9001
- ISO/IEC 27001 (Correct answer)
- ISO 14001
- ISO 31000
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS) and provides the governance framework within which FIDO deployments are managed.
A FIDO authenticator vendor wants to claim FIPS 140-2 compliance.
Which component of the authenticator must be validated?