PR.AA-03: Users, services, and hardware are authenticated
Threats Addressed:
Subcategory is new to this version of the framework and incorporates the following items from the previous version: PR.AC-3: Remote access is managed, PR.AC-7: Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks).
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
Ex1: Require multifactor authentication
Ex2: Enforce policies for the minimum strength of passwords, PINs, and similar authenticators
Ex3: Periodically reauthenticate users, services, and hardware based on risk (e.g., in zero trust architectures)
Ex4: Ensure that authorized personnel can access accounts essential for protecting safety under emergency conditions
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
AC-7: Unsuccessful Logon Attempts
Enforce a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period] ; and Automatically [Assignment (one or more): lock the account or node for [Assignment: organization-defined time period] , lock the account or node until released by an administrator, delay next logon prompt per [Assignment: organization-defined…
AC-12: Session Termination
Automatically terminate a user session after [Assignment: organization-defined conditions or trigger events].
IA-2: Identification and Authentication (Organizational Users)
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
IA-3: Device Identification and Authentication
Uniquely identify and authenticate [Assignment: organization-defined devices and/or types of devices] before establishing a [Assignment (one or more): local, remote, network] connection.
IA-5: Authenticator Management
Manage system authenticators by: Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator; Establishing initial authenticator content for any authenticators issued by the organization; Ensuring that authenticators have sufficient strength of mechanism for their intended use; Establishing and implementing administrative procedures for initial…
IA-7: Cryptographic Module Authentication
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.
IA-8: Identification and Authentication (Non-organizational Users)
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
IA-9: Service Identification and Authentication
Uniquely identify and authenticate [Assignment: organization-defined system services and applications] before establishing communications with devices, users, or other services or applications.
IA-10: Adaptive Authentication
Require individuals accessing the system to employ [Assignment: organization-defined supplemental authentication techniques or mechanisms] under specific [Assignment: organization-defined circumstances or situations].
IA-11: Re-authentication
Require users to re-authenticate when [Assignment: organization-defined circumstances or situations].
NIST SP 800-171 Revision 3.0
03.01.11: Session Termination
Terminate a user session automatically after [Assignment: organization-defined conditions or trigger events requiring session disconnect].
03.05.01: User Identification and Authentication
Uniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users. Re-authenticate users when [Assignment: organization-defined circumstances or situations requiring re-authentication].
03.05.02: Device Identification and Authentication
Uniquely identify and authenticate [Assignment: organization-defined devices or types of devices] before establishing a system connection.
03.05.03: Multi-Factor Authentication
Implement multi-factor authentication for access to privileged and non-privileged accounts.
03.05.04: Replay-Resistant Authentication
Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.
03.05.07: Password Management
Maintain a list of commonly-used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords. Transmit passwords only over cryptographically protected channels.…
03.05.12: Authenticator Management
Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution. Establish initial authenticator content for any authenticators issued by the organization. Establish and implement administrative procedures for initial authenticator distribution; for lost, compromised, or damaged authenticators; and for revoking authenticators. Change default authenticators at…
Cloud Controls Matrix v4.0
DCS-08: Equipment Identification
Use equipment identification as a method for connection authentication.
IAM-01: Identity and Access Management Policy and Procedures
Establish, document, approve, communicate, implement, apply, evaluate and maintain policies and procedures for identity and access management. Review and update the policies and procedures at least annually.
IAM-02: Strong Password Policy and Procedures
Establish, document, approve, communicate, implement, apply, evaluate and maintain strong password policies and procedures. Review and update the policies and procedures at least annually.
IAM-14: Strong Authentication
Define, implement and evaluate processes, procedures and technical measures for authenticating access to systems, application and data assets, including multifactor authentication for at least privileged user and sensitive data access. Adopt digital certificates or alternatives which achieve an equivalent level of security for system identities.
IAM-16: Authorization Mechanisms
Define, implement and evaluate processes, procedures and technical measures to verify access to data and system functions is authorized.
IVS-03: Network Security
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating controls.
UEM-05: Endpoint Management
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-06: Automatic Lock Screen
Configure all relevant interactive-use endpoints to require an automatic lock screen.
UEM-14: Third-Party Endpoint Security Posture
Define, implement and evaluate processes, procedures and technical and/or contractual measures to maintain proper security of third-party endpoints with access to organizational assets.