NIST Special Publication 800-171 Revision 2
IDName
3.1.1Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems)
3.1.8Limit unsuccessful logon attempts
3.1.17Protect wireless access using authentication and encryption
3.5.1Identify system users, processes acting on behalf of users, and devices
3.5.2Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems
3.5.3Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts
3.5.4Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts
3.5.7Enforce a minimum password complexity and change of characters when new passwords are created
3.5.10Store and transmit only cryptographically-protected passwords
3.7.5Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete
3.13.15Protect the authenticity of communications sessions