← Back to Baseline

MB-R104

HUMAN VERIFICATION REQUIRED ASVS 6.1.1 Anti-automation policy is documented

MB-C13 Application Behavior & Human Assurance Medium

Application documentation defines how controls such as rate limiting, anti-automation, and adaptive response, are used to defend against attacks such as credential stuffing and password brute force. The documentation must make clear how these controls are configured and prevent malicious account lockout.