03.05: Identification and Authentication
Controls
03.05.01: User Identification and Authentication
Uniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users. Re-authenticate users when [Assignment: organization-defined circumstances or situations requiring re-authentication].
03.05.02: Device Identification and Authentication
Uniquely identify and authenticate [Assignment: organization-defined devices or types of devices] before establishing a system connection.
03.05.03: Multi-Factor Authentication
Implement multi-factor authentication for access to privileged and non-privileged accounts.
03.05.04: Replay-Resistant Authentication
Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.
03.05.05: Identifier Management
Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier. Select and assign an identifier that identifies an individual, group, role, service, or device. Prevent the reuse of identifiers for [Assignment: organization-defined time period]. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual…
03.05.07: Password Management
Maintain a list of commonly-used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords. Transmit passwords only over cryptographically protected channels.…
03.05.11: Authentication Feedback
Obscure feedback of authentication information during the authentication process.
03.05.12: Authenticator Management
Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution. Establish initial authenticator content for any authenticators issued by the organization. Establish and implement administrative procedures for initial authenticator distribution; for lost, compromised, or damaged authenticators; and for revoking authenticators. Change default authenticators at…