3.5.4: Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts
Control Family:
Control Type:
Derived
CSF v1.1 References:
Next Version:
- NIST SP 800-171 Revision 3.0:
- 03.05.04: Replay-Resistant Authentication
Discussion
Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges such as time synchronous or challenge-response one-time authenticators.
[SP 800-63-3] provides guidance on digital identities.