Skip to main content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Comments Requested - Draft of NIST SP1800-17, Multifactor Authentication for E-Commerce

According to a recent independent analysis, e-commerce fraud increased by 30 percent in 2017, compared to 2016, as malicious actors shift from using stolen credit card data in stores at the checkout counter to using stolen credit card data for fraudulent online shopping. Because online retailers cannot utilize all of the benefits of improved credit card technology, they should consider implementing stronger authentication to reduce the risk of e-commerce fraud.

In collaboration with stakeholders in the retail sector, the National Cybersecurity Center of Excellence (NCCoE) is publishing a draft practice guide that explores risk-based scenarios that use multifactor authentication (MFA) to help reduce fraudulent online purchases. In the project’s example implementations, if certain risk elements (contextual data related to the transaction) are exceeded that could indicate an increased likelihood of fraudulent activity during the online shopping session, the purchaser will be prompted to present another distinct authentication factor—something the purchaser has—in addition to the username and password.

The NCCoE’s practice guide, Draft Special Publication 1800-17Multifactor Authentication for E-Commerce, can help organizations reduce online fraudulent purchases, show customers that the organization is committed to its security, help avoid system-administrator-account takeover through phishing, and assist organizations to implement the example solutions by using the step-by-step guide.

Comments are due by October 22, 2018.  Email Comments to: %20consumer-nccoe [at] nist.gov?Subject=Comments%20Requested:%20Draft%20of%20NIST%20SP%201800-17,%20Multifactor%20Authentication%20for%20E-Commerce">consumer-nccoe [at] nist.gov

Released August 23, 2018, Updated August 27, 2018