Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-171 CUI Protection Center

03.05 — Identification and Authentication

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

8Active requirements
4Withdrawn records
8Parameters
36Assessment objectives

CUI requirement family

Identification and Authentication

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

8 active4 withdrawnRevision 3
IA

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.05.01Active

User Identification and Authentication

System users include individuals (or system processes acting on behalf of individuals) who are authorized to access a system. Typically, individual identifiers are the usernames associated with the system accounts assigned to those individuals. Since system processes execute on behalf of groups and roles, organizations may require the unique identification of individuals in group accounts or the accountability of ind

03.05.02Active

Device Identification and Authentication

Devices that require unique device-to-device identification and authentication are defined by type, device, or a combination of type and device. Organization-defined device types include devices that are not owned by the organization. Systems use shared known information (e.g., Media Access Control .MAC, Transmission Control Protocol/Internet Protocol .TCP/IP addresses) for device identification or organizational aut

03.05.03Active

Multi-Factor Authentication

This requirement applies to user accounts. Multi-factor authentication requires the use of two or more different factors to achieve authentication. The authentication factors are defined as follows: something you know (e.g., a personal identification number .PIN), something you have (e.g., a physical authenticator, such as a cryptographic private key), or something you are (e.g., a biometric). Multi-factor authentica

03.05.04Active

Replay-Resistant Authentication

Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges, such as time synchronous or challenge-response one-time authenticators.

03.05.05Active

Identifier Management

Identifiers are provided for users, processes acting on behalf of users, and devices. Prohibiting the reuse of identifiers prevents the assignment of previously used individual, group, role, service, or device identifiers to different individuals, groups, roles, services, or devices. Characteristics that identify the status of individuals include contractors, foreign nationals, and non-organizational users. Identifyi

03.05.06Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.05.06; use the recorded replacement relationships.

03.05.07Active

Password Management

Password-based authentication applies to passwords used in single-factor or multi-factor authentication. Long passwords or passphrases are preferable to shorter passwords. Enforced composition rules provide marginal security benefits while decreasing usability. However, organizations may choose to establish and enforce certain rules for password generation (e.g., minimum character length) under certain circumstances.

03.05.08Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.05.08; use the recorded replacement relationships.

03.05.09Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.05.09; use the recorded replacement relationships.

03.05.10Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.05.10; use the recorded replacement relationships.

03.05.11Active

Authentication Feedback

Authentication feedback does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For example, for desktop or notebook systems with relatively large monitors, the threat may be significant (commonly referred to as shoulder surfing). For mobile devices with small displays, this threat may be less significant and is balanced against the increased likelihood of input

03.05.12Active

Authenticator Management

Authenticators include passwords, cryptographic devices, biometrics, certificates, one-time password devices, and ID badges. The initial authenticator content is the actual content of the authenticator (e.g., the initial password). In contrast, requirements for authenticator content contain specific characteristics. Authenticator management is supported by organization-defined settings and restrictions for various au