be sufficiently randomised
using a random function.
3.
Passwords must not
be
relatable in an obvious manner
to public information such as
MAC address or Wi-Fi SSID.
The developer shall also provide 5
instances of randomised passwords that
are generated using the aforementioned
password randomisation mechanism to
CCC.
5.1-3:
Authentication
mechanisms
used
to
authenticate users against
a device shall use best
practice
cryptography,
appropriate
to
the
properties
of
the
technology, risk and usage.
M
M
M
M
Please note that there are many
mechanisms used for performing
authentication, and passwords are not
the only mechanism for authenticating a
user to a device. If other authentication
mechanisms are used, please provide
details.
Supporting evidence shall list all
authentication
mechanisms
(e.g.
passwords, tokens, smart cards, digital
signatures, biometrics, etc.) available for
the various device login-interfaces (e.g.
device configuration portal, companion
mobile application, etc.), and describe
how each of the mechanisms are
adequately secured to address the risk
CLS Publication #2 | Page 23 of 49