Picto thématique

Rule n° 18 - The website offers a mechanism to prevent account or identity theft.

The number of attempts of account theft or identity theft on the web is considerable. To avoid this, Web services can put in place mechanisms to verify that it is indeed you, and it's good that you want to make your online operations. Several mechanisms can be set up depending on the criticality of the content and services concerned. For example, if you hear of two-factor authentication, it is no a double early delivery of mail, but a verification of your identity with a phone number.

#Personal information #Development #Privacy

Goal

  • Strengthen user safety and confidence by preventing the risk of identity theft.
  • Limit the costs of processing impersonations for the user and the online service.
  • Strengthen users' confidence in the use of their data.

Implementation

Set up a double-factor verification system or other strong verification, and not a simple identification method using username and password

Control

When logging in to private areas, check for the presence of a two-factor verification mechanism or other strong verification.

By Opquast - Read the license


Discover Opquast training and certification

The objective of these rules and the Opquast community mission is ‘making the web better’ for your customers and for everyone! Opquast rules cover the key major areas of risk that can negatively affect website users such as privacy, ecodesign, accessibility and security.

Opquast training has already allowed over 19,000 web professionals to have their skills certified. Train your teams, contact us

We offer a 1 hour free discovery module.