IA-3(1): Cryptographic Bidirectional Authentication

CSF v1.1 References:

CSF v2.0 References:

PF v1.0 References:

Threats Addressed:

Baselines:

(Not part of any baseline)

Previous Version:

Control Statement

Authenticate [Assignment: organization-defined devices and/or types of devices] before establishing [Assignment (one or more): local, remote, network] connection using bidirectional authentication that is cryptographically based.

Supplemental Guidance

A local connection is a connection with a device that communicates without the use of a network. A network connection is a connection with a device that communicates through a network. A remote connection is a connection with a device that communicates through an external network. Bidirectional authentication provides stronger protection to validate the identity of other devices for connections that are of greater risk.

OT Discussion

For OT systems that include IIoT devices, these enhancements may be needed to protect device-to-device communication.