R126. Set a password regeneration mechanism

This document contains the details of the security requirements related to the definition and management of access credentials in the organization. This requirement establishes the importance of defining a mechanism to securely regenerate user passwords.


The system must provide a secure mechanism to regenerate a user’s password.


Passwords are identity assertion elements that can be easily lost or forgotten. Systems should have a secure mechanism that allows users to generate a new password when they have lost their previous one. Alternatively, passwords can be leaked as a result of a user’s actions or a breach in the system. Thus, there should also exist a secure mechanism that allows users to change their passwords when they require it. Furthermore, none of these mechanisms should send a recovery secret in plain text nor should they reveal the current password.


