{"data":{"id":"IA-06","name":"Authentication Feedback","family":"IA","family_name":"Identification and Authentication","withdrawn":false,"description":"Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.","supplemental_guidance":"Authentication feedback from systems does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For some types of systems, such as desktops or notebooks with relatively large monitors, the threat (referred to as shoulder surfing) may be significant. For other types of systems, such as mobile devices with small displays, the threat may be less significant and is balanced against the increased likelihood of typographic input errors due to small keyboards. Thus, the means for obscuring authentication feedback is selected accordingly. Obscuring authentication feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a very limited time before obscuring it.","enhancements":[],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IA-06","name":"Authentication Feedback","description":"Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.","discussion":"Authentication feedback from systems does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For some types of systems, such as desktops or notebooks with relatively large monitors, the threat (referred to as shoulder surfing) may be significant. For other types of systems, such as mobile devices with small displays, the threat may be less significant and is balanced against the increased likelihood of typographic input errors due to small keyboards. Thus, the means for obscuring authentication feedback is selected accordingly. Obscuring authentication feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a very limited time before obscuring it.","related_controls":["AC-03"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.17","A.8.5"],"iso_27002_2022":["5.17"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-01"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.10","SecNumCloud.10.5"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(4)(c)"],"bio2":["5.17"],"rbi_csf":["Annex1.8"],"fisc":["FISC.T2"],"lgpd_bcb":[],"hkma_tme1":["TME1.8.3"],"mlps_2":["8.1.4.1"],"dnb_good_practice":[],"cra":["CRA.I.2d"],"swift_cscf":[],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-VIII"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1"],"cbn_csf":["Part3.2"],"sa_js2":["JS2-7.1","JS2-8.1"],"bot_cyber":["Ch2.2"],"eba_ict":["3.4.2"],"ffiec_is":["II.C.15"],"hipaa_sr":["§164.308(a)(5)(ii)(D)","§164.312(d)"],"iosco_cyber":["PROT-1"],"sebi_cscrf":["PR.AA"],"cmmc_2":["IA"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FIA"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.200(a)(1)","§11.300(d)"],"fda_cyber":["SA-1"],"hitrust_csf":["01.c"],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Obscuring authentication feedback when accessing cloud storage prevents shoulder-surfing or screen capture attacks from revealing credentials that adversaries could use to access cloud-hosted data."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Obscuring authentication credentials during session establishment for remote services prevents adversaries from capturing authentication material through visual observation or screen recording during login."},{"id":"T1578","name":"Modify Cloud Compute Infrastructure","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Obscuring authentication feedback for cloud management consoles prevents adversaries from observing credentials used to access cloud compute infrastructure through visual surveillance techniques."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Masking password entry during RDP authentication prevents adversaries from capturing credentials through shoulder surfing, screen recording, or keylogger correlation with visible character counts."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Obscuring VNC authentication feedback prevents adversaries from determining credential length or composition through visual observation of the authentication dialog."},{"id":"T1578.001","name":"Create Snapshot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Masking authentication credentials when accessing cloud snapshot management interfaces prevents adversaries from observing cloud credentials used for infrastructure operations."},{"id":"T1578.002","name":"Create Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Obscuring authentication feedback during cloud instance creation workflows prevents adversaries from capturing cloud management credentials through observation or recording."},{"id":"T1578.003","name":"Delete Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Masking authentication credentials when accessing cloud instance deletion interfaces prevents unauthorized individuals from observing credentials during infrastructure management operations."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.5 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.AA-01 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-032","SP-033"]}}