IA-05.17 ยท Presentation Attack Detection for Biometric Authenticators

Control Description

Employ presentation attack detection mechanisms for biometric-based authentication.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
system
Enhancement
Control Statement
The control requirements

Employ presentation attack detection mechanisms for biometric-based authentication.

Supplemental Guidance

Biometric characteristics do not constitute secrets. Such characteristics can be obtained by online web accesses, taking a picture of someone with a camera phone to obtain facial images with or without their knowledge, lifting from objects that someone has touched (e.g., a latent fingerprint), or capturing a high-resolution image (e.g., an iris pattern). Presentation attack detection technologies including liveness detection, can mitigate the risk of these types of attacks by making it difficult to produce artifacts intended to defeat the biometric sensor.

Related NIST Controls
Other NIST 800-53 controls related to this one