# IA-05 Authenticator Management

NIST SP 800-53 control. Family: IA Identification and Authentication. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Manage system authenticators by: a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator; b. Establishing initial authenticator content for any authenticators issued by the organization; c. Ensuring that authenticators have sufficient strength of mechanism for their intended use; d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators; e. Changing default authenticators prior to first use; f. Changing or refreshing authenticators [Assignment: organization-defined time period by authenticator type] or when [Assignment: organization-defined events] occur; g. Protecting authenticator content from unauthorized disclosure and modification; h. Requiring individuals to take, and having devices implement, specific controls to protect authenticators; and i. Changing authenticators for group or role accounts when membership to those accounts changes.
Guidance: Authenticators include passwords, cryptographic devices, biometrics, certificates, one-time password devices, and ID badges. Device authenticators include certificates and passwords. Initial authenticator content is the actual content of the authenticator (e.g., the initial password). In contrast, the requirements for authenticator content contain specific criteria or characteristics (e.g., minimum password length). Developers may deliver system components with factory default authentication credentials (i.e., passwords) to allow for initial installation and configuration. Default authentication credentials are often well known, easily discoverable, and present a significant risk. The requirement to protect individual authenticators may be implemented via control PL-04 or PS-06 for authenticators in the possession of individuals and by controls AC-03, AC-06, and SC-28 for authenticators stored in organizational systems, including passwords stored in hashed or encrypted formats or files containing encrypted or hashed passwords accessible with administrator privileges. Systems support authenticator management by organization-defined settings and restrictions for various authenticator characteristics (e.g., minimum password length, validation time window for time synchronous one-time tokens, and number of allowed rejections during the verification stage of biometric authentication). Actions can be taken to safeguard individual authenticators, including maintaining possession of authenticators, not sharing authenticators with others, and immediately reporting lost, stolen, or compromised authenticators. Authenticator management includes issuing and revoking authenticators for temporary access when no longer needed.

## Enhancements (15)
- IA-05(01) Password-based Authentication. Baselines: low, moderate, high
- IA-05(02) Public Key-based Authentication. Baselines: moderate, high
- IA-05(05) Change Authenticators Prior to Delivery
- IA-05(06) Protection of Authenticators. Baselines: moderate, high
- IA-05(07) No Embedded Unencrypted Static Authenticators
- IA-05(08) Multiple System Accounts
- IA-05(09) Federated Credential Management
- IA-05(10) Dynamic Credential Binding
- IA-05(12) Biometric Authentication Performance
- IA-05(13) Expiration of Cached Authenticators
- IA-05(14) Managing Content of PKI Trust Stores
- IA-05(15) GSA-approved Products and Services
- IA-05(16) In-person or Trusted External Party Authenticator Issuance
- IA-05(17) Presentation Attack Detection for Biometric Authenticators
- IA-05(18) Password Managers
Withdrawn by NIST: IA-05(03) (now in IA-12(04)); IA-05(04) (now in IA-05(01)); IA-05(11) (now in IA-02(01) and IA-02(02)).
Each enhancement's statement: /api/v1/controls/IA-05?fields=enhancements

## Patterns that use it (20)
- Critical (9): SP-022 Board of Directors Room; SP-028 Secure DevOps Pipeline Pattern; SP-029 Zero Trust Architecture; SP-030 API Security; SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-037 Privileged User Management; SP-052 Decentralised Identity & Verifiable Credentials (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (9): SP-011 Cloud Computing Pattern; SP-012 Secure Software Development Lifecycle; SP-015 Secure Remote Working; SP-027 Secure LLM Usage; SP-034 Cyber Resilience; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-044 SaaS Identity Lifecycle Management; SP-047 Secure Agentic AI Frameworks; SP-050 Mobile Security Architecture (draft)
- Standard (2): SP-031 Security Monitoring and Response; SP-039 Client-Side Encryption and Data Privacy

## Clauses by framework (79 frameworks)
- iso_27001_2022: A.5.16, A.5.17, A.8.5. OSA's own, not in NIST's crosswalk: A.8.5
- iso_27002_2022: 5.16, 5.17, 8.5
- cobit_2019: DSS05
- pci_dss_v4: 2.2.1, 2.2.2, 8.2, 8.3, 8.3.6, 8.3.9, 8.6
- nist_csf_2: PR.AA-01, PR.AA-02, PR.AA-03, PR.AA-04. OSA's own, not in NIST's crosswalk: PR.AA-02, PR.AA-04
- cis_controls_v8: CIS 4.7, CIS 5, CIS 5.2, CIS 14.3
- soc2_tsc: CC6.1
- finos_ccc: CCC-C11
- iec_62443: 3-3 SR 1.1, 3-3 SR 1.5, 3-3 SR 1.7
- asd_e8: E8-5 ML3, E8-7
- mas_trm: 9
- bsi_grundschutz: ORP.4
- anssi: Hygiene.10, Hygiene.12, RGS.2.2, SecNumCloud.10.5
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.B.d(60), IV.C(61)
- gdpr: Art.32(1)(a), Art.32(1)(b)
- dora: Art.9(3), Art.9(4)(c), Art.9(4)(d)
- bio2: 5.16, 5.17, 8.5
- rbi_csf: Annex1.8, Annex1.9, ITGRCA.19
- fisc: FISC.T2, FISC.T10
- lgpd_bcb: BCB.Art.3, BCB.OpenFinance, BCB.PIX, LGPD.Art.46
- hkma_tme1: TME1.8.2, TME1.8.3, TME1.10.4
- mlps_2: 8.1.4.1, 8.1.10.7
- dnb_good_practice: DNB.17.1, DNB.17.2
- cra: CRA.I.2d
- swift_cscf: SWIFT.4.1, SWIFT.4.2, SWIFT.5.2, SWIFT.5.4
- cbb_tm: TM-6
- cbuae: CR-4
- nca_ecc: 2-2
- qatar_nia: AC
- sama_csf: 3.1
- uae_ia: T9
- bog_cisd: CISD-IX, CISD-VIII
- bom_ctrm: 3.3
- cbe_csf: CTO-1, CTO-5
- cbn_csf: Part3.2
- popia: s19
- sa_js2: JS2-7.1, JS2-8.1
- bot_cyber: Ch2.2
- cpmi_pfmi: CG.PR, PFMI.P17
- eba_ict: 3.4.2, 3.8(b)
- ecb_croe: CROE.2.3.1
- ffiec_is: II.C.7(b), II.C.15, II.C.15(a)
- hipaa_sr: §164.308(a)(4)(ii)(C), §164.308(a)(5)(ii)(D), §164.312(d)
- iosco_cyber: PROT-1
- nydfs_500: 500.7, 500.12
- sebi_cscrf: PR.AA
- cmmc_2: AC, IA
- nerc_cip: CIP-007-6
- nrc_73_54: RG5.71-A-AC
- tsa_psd: SD-2 Sec B
- ieee_1686: 5.1, 5.7
- doe_c2m2: ACCESS
- api_1164: Sec 6
- awia: AWWA Sec 3
- iaea_nss: Sec 5.2
- fips_140: FIPS 140-3 §7.4, FIPS 140-3 §7.9
- pci_hsm: 9
- common_criteria: CC Part 2 — FIA
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.10(d), §11.100(a), §11.100(b), §11.200(a)(1), §11.200(a)(1)(ii), §11.200(a)(2), §11.300(a), §11.300(b), §11.300(c), §11.300(e)
- fda_cyber: SA-1
- hitrust_csf: 01.a, 01.c
- iso_27799: 9.3, 9.4
- lloyds_ms: MS8.3
- naic_ds: 4-access, 4B
- nhs_dspt: NDG-4.1, NDG-4.2, NDG-4.3
- pra_ss1_23: P-IT.1
- solvency_ii: EIOPA-ICT-4.4
- owasp_masvs_v2: MASVS-AUTH-1, MASVS-AUTH-2, MASVS-NETWORK-2
- csa_ccm_v4: IAM-02, IAM-06, IAM-14, IAM-15
- csa_aicm: IAM-02, IAM-06, IAM-14, IAM-15
- ccss_v9: 1.04.1, 1.04.2, 1.06.2
- mica: Art.40(1), Art.55(1), Art.63(1), Art.67(1), Art.76(1)
- basel_sco60: SCO60.61, SCO60.62, SCO60.66
- bssc: GSP-11, KMS-06, KMS-07, KMS-08, NOS-05, NOS-08
- sec_custody_digital: SEC-CD-02, SEC-CD-03, SEC-CD-05, SEC-CD-06, SEC-CD-07, SEC-CD-16
- dpdpa: Rules.6(1)(b)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/IA-05
- Clauses only: /api/v1/controls/IA-05?fields=mappings
- Page for people: /controls/ia-05/
