IA
Identification and Authentication
Verifies the identities of users, processes, and devices before granting access to organizational systems.
Family stats
Controls
11
Objectives
25
L1
2
L2 only
9
11 controls in this family
All
Level 1
Level 2 only
3.5.1
Identify system users, processes acting on behalf of users, and devices.
L1
›
3.5.10
Store and transmit only cryptographically-protected passwords.
L2
›
3.5.11
Obscure feedback of authentication information.
L2
›
3.5.2
Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to...
L1
›
3.5.3
Use multifactor authentication for local and network access to privileged accounts and for network...
L2
›
3.5.4
Employ replay-resistant authentication mechanisms for network access to privileged and...
L2
›
3.5.5
Prevent reuse of identifiers for a defined period.
L2
›
3.5.6
Disable identifiers after a defined period of inactivity.
L2
›
3.5.7
Enforce a minimum password complexity and change of characters when new passwords are created.
L2
›
3.5.8
Prohibit password reuse for a specified number of generations.
L2
›
3.5.9
Allow temporary password use for system logons with an immediate change to a permanent password
L2
›
Begin the conversation
Your contract eligibility is on a clock. Let’s get to work.
A 30-minute scoping call with a senior consultant. No pitch. We listen, scope honestly, and tell you what we’d do — including whether we are the right fit.
Request a scoping call →