V7.5.1: Verify that the application requires full re-authentication before allowing modifications to sensitive account attributes which may affect authentication such as email address, phone number, MFA configuration, or other information used in account recovery.
ASVS Maturity
V7.5.2
V7.5.2: Verify that users are able to view and (having authenticated again with at least one factor) terminate any or all currently active sessions.
ASVS Maturity
V7.5.3
V7.5.3: Verify that the application requires further authentication with at least one factor or secondary verification before performing highly sensitive transactions or operations.