Authentication Risk Assessment Form
Use this form to assess authentication risks, identify control gaps, and capture follow-up actions.
Authentication Context
Application/System Name
*
Environment
*
Production
Staging
Development
Other
Authentication Method(s) in Use
*
Password
MFA
SSO
Passkeys
OTP
Biometric
Magic Link
Other
Number of User Accounts in Scope
Business Owner or Team Responsible
Risk Assessment
Authentication Risk Level
*
Low
1
2
3
4
High
5
1 is Low, 5 is High
Top Authentication Threats Observed
*
Brute Force
Credential Stuffing
Phishing
Weak Passwords
Session Hijacking
Account Takeover
Privilege Misuse
Other
Control Coverage / Effectiveness
*
1
2
3
4
5
Security Controls Status
*
Rows
Implemented
Partial
Not Implemented
Not Applicable
MFA enforced
1
2
3
4
Password policy exists
5
6
7
8
Lockout / rate limiting enabled
9
10
11
12
Session timeout configured
13
14
15
16
Suspicious login monitoring enabled
17
18
19
20
Recovery flow reviewed
21
22
23
24
Review and Follow-Up
Primary remediation actions needed
*
Target completion date
*
 -
Month
 -
Day
Year
Date
Reviewer name or role
*
Submit Assessment
Should be Empty: