Multifactor Authentication for E-Commerce

Download the Practice Guide

The NCCoE recently released the final version of NIST Cybersecurity Practice Guide SP 1800-17, Multifactor Authentication for E-Commerce. Use the buttons below to view this publication in its entirety or scroll down for links to a specific section.

Download PDF » Open Web Version »

Current Status

The NCCoE released a final version of NIST Special Publication (SP) 1800-17 Multifactor Authentication for E-Commerce on July 30, 2019.

For ease of use, the guide is available in volumes:

  • SP 1800-17A: Executive Summary (PDF) (web page
  • SP 1800-17B: Approach, Architecture, and Security Characteristics (PDF) (web page
  • SP 1800-17C: How-To Guides (PDF) (web page

Or download the complete guide (PDF) (web page).

Read the two-page fact sheet for a brief overview of this project.

If you have questions or suggestions, please email us at consumer-nccoe@nist.gov. To get the latest information about retail sector projects, sign up for our email alerts.

Summary

Smart chip credit cards and terminals work together to protect in-store payments. These in-store security advances were introduced in 2015, and have pushed malicious actors who possess stolen credit card data to perform payment card fraud online. Because online retailers cannot utilize all of the benefits of improved credit card technology, they should consider implementing stronger authentication to reduce the risk of electronic commerce (e-commerce) fraud.

In collaboration with stakeholders in the retail sector, the NCCoE published a practice guide that explores risk-based scenarios to trigger the use of multifactor authentication (MFA) to help reduce fraudulent online purchases. In the project’s example implementations, if certain risk elements (contextual data related to the transaction) are exceeded that could indicate an increased likelihood of fraudulent activity during the online shopping session, the purchaser will be prompted to present another distinct authentication factor—something the purchaser has—in addition to the username and password.

The NCCoE’s practice guide to Multifactor Authentication for E-Commerce can help your organization:

  • reduce online fraudulent purchases, including those resulting from the use of credential stuffing to take over accounts
  • show customers that the organization is committed to its security
  • protect your e-commerce systems
    • provide greater situational awareness
    • avoid system-administrator-account takeover through phishing
  • implement the example solutions by using our step-by-step guide

Questions? Comments? Reach us at consumer-nccoe@nist.gov.

Collaborating Vendors

Organizations participating in this project submitted their capabilities in response to an open call in the Federal Register for all sources of relevant security capabilities from academia and industry (vendors and integrators). The following respondents with relevant capabilities or product components (identified as “Technology Partners/Collaborators” herein) signed a Cooperative Research and Development Agreement to collaborate with NIST in a consortium to build this example solution.

RSA logo
Splunk logo
StrongKey logo
TokenOne logo
Yubico logo