10. Maintain Credential - Reset
When an employee or contractor forgets the shared secret associated with their credential, usually a password or PIN, they can request a reset. This prevents them from having to request a new credential.
Pre-condition: An employee has an active, agency-issued credential.
The individual forgets their password or PIN. They contact their credential manager for a reset. | |
The credential manager verifies the requestor’s identity. The verification method will vary by agency. |
|
The credential manager issues a reset. For example, this could be a temporary password or a security link to a web-based reset form. |
|
The individual resets their password or PIN. |
Post-condition: Shared secret is reset and the credential is again ready for use.
Click here for a consolidated image of this use case.