03.05: Identification and Authentication

Controls

03.05.01: User Identification and Authentication

Uniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users. Re-authenticate users when [Assignment: organization-defined circumstances or situations requiring re-authentication].

03.05.05: Identifier Management

Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier. Select and assign an identifier that identifies an individual, group, role, service, or device. Prevent the reuse of identifiers for [Assignment: organization-defined time period]. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual…

03.05.07: Password Management

Maintain a list of commonly-used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords. Transmit passwords only over cryptographically protected channels.…

03.05.12: Authenticator Management

Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution. Establish initial authenticator content for any authenticators issued by the organization. Establish and implement administrative procedures for initial authenticator distribution; for lost, compromised, or damaged authenticators; and for revoking authenticators. Change default authenticators at…