Out-Of-Band Authentication
Objective
Prevent wire fraud via voice deepfake.
Control / requirement
Independent channel verification + policy enforcement.
Business impact
Voice deepfake attacks have successfully authorized wire transfers of $25M+ (2024 multinational deepfake fraud case). Single-channel authentication is no longer sufficient.
Validation approach
Test ID: D7-CTL-H03-VTS-001 Test Type: Manual Test Design: Financial requests >$10,000, credential resets, vendor payment changes require independent channel verification Execution Steps: 1. Initiate test financial request >$10k 2. Attempt single-channel approval 3. Verify OOB requirement enforced 4. Check policy compliance Pass Criteria: single_channel_approval_blocked = True; independent_verification_required = True; policy_compliance_audited = True Independent Verification: Auditor tests OOB enforcement.
Expected evidence
Not separately specified in the available source.
Mapping and source
Not separately specified in the available source.
Implementation guidance
Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.
Assessment considerations
- Confirm scope and applicability.
- Inspect control design and responsible ownership.
- Test representative operation and adverse conditions where appropriate.
- Evaluate evidence provenance, completeness and contradictory evidence.
- Record limitations and notably absent outcomes.