IA-2(8): Network Access To Privileged Accounts – Replay Resistant
Control Family:
Threats Addressed:
Baselines:
- Moderate
- High
Next Version:
- NIST Special Publication 800-53 Revision 5:
- IA-2(8): Access to Accounts – Replay Resistant
Control Statement
The information system implements replay-resistant authentication mechanisms for network access to privileged accounts.
Supplemental Guidance
Authentication processes resist replay attacks if it is impractical to achieve successful authentications by replaying previous authentication messages. Replay-resistant techniques include, for example, protocols that use nonces or challenges such as Transport Layer Security (TLS) and time synchronous or challenge-response one-time authenticators.