Cryptographic Bidirectional Authentication
Bidirectional authentication provides stronger protection to validate the identity of other devices for connections that are of greater risk. This requirement enhances SP 800-171 requirement 03.05.02.
NIST SP 800-172 Enhanced CUI Protection Center
Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.
CUI requirement family
Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.
Family catalog
Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.
Bidirectional authentication provides stronger protection to validate the identity of other devices for connections that are of greater risk. This requirement enhances SP 800-171 requirement 03.05.02.
A potential risk of using password managers is that adversaries can target the collection of passwords generated by the password manager. Therefore, the passwords require strong protection, including encrypting the passwords. This requirement enhances SP 800-171 requirement 03.05.07.
Device attestation refers to the identification and authentication of a device based on its configuration and known operating state. Device attestation can be determined via a cryptographic hash of the device. If device attestation is the means of identification and authentication, then it is important that patches and updates to the device are handled via a configuration management process such that the patches and
In addition to applications, other forms of static storage include access scripts and function keys. Organizations exercise caution when determining whether embedded or stored authenticators are encrypted or unencrypted. If authenticators are used in the manner stored, then those representations are considered unencrypted authenticators. This requirement enhances SP 800-171 requirement 03.05.07.
Cached authenticators are used to authenticate to a local machine when the network is not available. If cached authentication information is out of date, the validity of the authentication information may be questionable. This requirement enhances SP 800-171 requirement 03.05.07.
Identity proofing is the process of collecting, validating, and verifying user identity information to establish credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Resolving user identities ensure each user identity belongs to a unique individual. Organizations may be subject to laws, Executive Orders, directives,
Identity providers (both internal and external to the organization) manage user, device, and non-person entity authenticators and issue statements (often called identity assertions) that attest to the identities of other systems or system components. Authorization servers create and issue access tokens to identified and authenticated users and devices that can be used to gain access to organizational systems or infor
Try a shorter term or clear a filter.