03.05.11: Authentication Feedback
Control Family:
CSF v2.0 References:
Previous Version:
- NIST Special Publication 800-171 Revision 2:
- 3.5.11: Obscure feedback of authentication information
Requirements
- Obscure feedback of authentication information during the authentication process.
Discussion
Authentication feedback does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For example, for desktop or notebook systems with relatively large monitors, the threat may be significant (commonly referred to as shoulder surfing). For mobile devices with small displays, this threat may be less significant and is balanced against the increased likelihood of input errors due to small keyboards. Therefore, the means of obscuring authenticator feedback is selected accordingly. Obscuring feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a limited time before fully obscuring it.