← Controls / IA

IA-05 Authenticator Management

Identification and Authentication

Low Moderate High

Description

Manage system authenticators by: a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator; b. Establishing initial authenticator content for any authenticators issued by the organization; c. Ensuring that authenticators have sufficient strength of mechanism for their intended use; d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators; e. Changing default authenticators prior to first use; f. Changing or refreshing authenticators [Assignment: organization-defined time period by authenticator type] or when [Assignment: organization-defined events] occur; g. Protecting authenticator content from unauthorized disclosure and modification; h. Requiring individuals to take, and having devices implement, specific controls to protect authenticators; and i. Changing authenticators for group or role accounts when membership to those accounts changes.

Supplemental Guidance

Authenticators include passwords, cryptographic devices, biometrics, certificates, one-time password devices, and ID badges. Device authenticators include certificates and passwords. Initial authenticator content is the actual content of the authenticator (e.g., the initial password). In contrast, the requirements for authenticator content contain specific criteria or characteristics (e.g., minimum password length). Developers may deliver system components with factory default authentication credentials (i.e., passwords) to allow for initial installation and configuration. Default authentication credentials are often well known, easily discoverable, and present a significant risk. The requirement to protect individual authenticators may be implemented via control PL-04 or PS-06 for authenticators in the possession of individuals and by controls AC-03, AC-06, and SC-28 for authenticators stored in organizational systems, including passwords stored in hashed or encrypted formats or files containing encrypted or hashed passwords accessible with administrator privileges. Systems support authenticator management by organization-defined settings and restrictions for various authenticator characteristics (e.g., minimum password length, validation time window for time synchronous one-time tokens, and number of allowed rejections during the verification stage of biometric authentication). Actions can be taken to safeguard individual authenticators, including maintaining possession of authenticators, not sharing authenticators with others, and immediately reporting lost, stolen, or compromised authenticators. Authenticator management includes issuing and revoking authenticators for temporary access when no longer needed.

Changes from Rev 4

Removes requirement to change default content of authenticators prior to information system installation New parameter requires specifying events that require changing or refreshing authenticators Changes 'security safeguards' to 'controls' Discussion includes new examples

Enhancements (15)

What NIST adds to this control. Select one to read its statement.

IA-05(01) Password-based Authentication LowModerateHigh

For password-based authentication: a. Maintain a list of commonly-used, expected, or compromised passwords and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised directly or indirectly; b. Verify, when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5(1)(a); c. Transmit passwords only over cryptographically-protected channels; d. Store passwords using an approved salted key derivation function, preferably using a keyed hash; e. Require immediate selection of a new password upon account recovery; f. Allow user selection of long passwords and passphrases, including spaces and all printable characters; g. Employ automated tools to assist the user in selecting strong password authenticators; and h. Enforce the following composition and complexity rules: [Assignment: organization-defined composition and complexity rules].

IA-05(02) Public Key-based Authentication ModerateHigh

a. For public key-based authentication: 1. Enforce authorized access to the corresponding private key; and 2. Map the authenticated identity to the account of the individual or group; and b. When public key infrastructure (PKI) is used: 1. Validate certificates by constructing and verifying a certification path to an accepted trust anchor, including checking certificate status information; and 2. Implement a local cache of revocation data to support path discovery and validation.

IA-05(05) Change Authenticators Prior to Delivery

Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and installation.

IA-05(06) Protection of Authenticators ModerateHigh

Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.

IA-05(07) No Embedded Unencrypted Static Authenticators

Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.

IA-05(08) Multiple System Accounts

Implement [Assignment: organization-defined security controls] to manage the risk of compromise due to individuals having accounts on multiple systems.

IA-05(09) Federated Credential Management

Use the following external organizations to federate credentials: [Assignment: organization-defined external organizations].

IA-05(10) Dynamic Credential Binding

Bind identities and authenticators dynamically using the following rules: [Assignment: organization-defined binding rules].

IA-05(12) Biometric Authentication Performance

For biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [Assignment: organization-defined biometric quality requirements].

IA-05(13) Expiration of Cached Authenticators

Prohibit the use of cached authenticators after [Assignment: organization-defined time period].

IA-05(14) Managing Content of PKI Trust Stores

For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, including networks, operating systems, browsers, and applications.

IA-05(15) GSA-approved Products and Services

Use only General Services Administration-approved products and services for identity, credential, and access management.

IA-05(16) In-person or Trusted External Party Authenticator Issuance

Require that the issuance of [Assignment: organization-defined types of and/or specific authenticators] be conducted [Selection (one): in person; by a trusted external party] before [Assignment: organization-defined registration authority] with authorization by [Assignment: organization-defined personnel or roles].

IA-05(17) Presentation Attack Detection for Biometric Authenticators

Employ presentation attack detection mechanisms for biometric-based authentication.

IA-05(18) Password Managers

a. Employ [Assignment: organization-defined password managers] to generate and manage passwords; and b. Protect the passwords using [Assignment: organization-defined controls].

Withdrawn by NIST:

  • IA-05(03) In-person or Trusted External Party Registration, now in IA-12(04)
  • IA-05(04) Automated Support for Password Strength Determination, now in IA-05(01)
  • IA-05(11) Hardware Token-based Authentication, now in IA-02(01) and IA-02(02)

MITRE ATT&CK Techniques (72)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 4 Execution 1 Persistence 19 Privilege Escalation 8 Defense Evasion 15 Credential Access 43 Discovery 1 Lateral Movement 8 Collection 3
Show all 72 techniques grouped by tactic

Credential Access

Compliance Mappings

ISO 27001:2022

A.5.16A.5.17A.8.5

ISO 27002:2022

5.165.178.5

COBIT 2019

DSS05

CIS Controls v8

CIS 4.7CIS 5CIS 5.2CIS 14.3

NIST CSF 2.0

PR.AA-01PR.AA-02PR.AA-03PR.AA-04

SOC 2 TSC

CC6.1

PCI DSS v4.0.1

2.2.12.2.28.28.38.3.68.3.98.6

CSA CCM v4

IAM-02IAM-06IAM-14IAM-15

CSA AICM v1

IAM-02IAM-06IAM-14IAM-15

FINOS CCC

CCC-C11

IEC 62443

3-3 SR 1.13-3 SR 1.53-3 SR 1.7

MAS TRM

9

ASD Essential Eight

E8-5 ML3E8-7

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.10Hygiene.12RGS.2.2SecNumCloud.10.5

FINMA Circular 2023/1

IV.B.d(59)IV.B.d(60)IV.C(61)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(a)Art.32(1)(b)

EU DORA

Art.9(3)Art.9(4)(c)Art.9(4)(d)

BIO2

5.165.178.5

RBI CSF

Annex1.8Annex1.9ITGRCA.19

FISC Security Guidelines

FISC.T2FISC.T10

LGPD + BCB 4893

BCB.Art.3BCB.OpenFinanceBCB.PIXLGPD.Art.46

HKMA TM-E-1

TME1.8.2TME1.8.3TME1.10.4

MLPS 2.0

8.1.4.18.1.10.7

DNB Good Practice

DNB.17.1DNB.17.2

EU CRA

CRA.I.2d

SWIFT CSCF

SWIFT.4.1SWIFT.4.2SWIFT.5.2SWIFT.5.4

SAMA CSF

3.1

NCA ECC

2-2

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CTO-1CTO-5

SA JS2

JS2-7.1JS2-8.1

CBN CSF

Part3.2

BoG CISD

CISD-IXCISD-VIII

POPIA

s19

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

CPMI-IOSCO PFMI

CG.PRPFMI.P17

FFIEC IS

II.C.7(b)II.C.15II.C.15(a)

NYDFS 500

500.7500.12

HIPAA Security Rule

§164.308(a)(4)(ii)(C)§164.308(a)(5)(ii)(D)§164.312(d)

ECB CROE

CROE.2.3.1

EBA ICT Guidelines

3.4.23.8(b)

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2

CMMC 2.0

ACIA

NERC CIP

CIP-007-6

10 CFR 73.54

RG5.71-A-AC

TSA Pipeline SD

SD-2 Sec B

IEEE 1686-2022

5.15.7

DOE C2M2 v2.1

ACCESS

API 1164

Sec 6

AWIA

AWWA Sec 3

IAEA NSS 17-T

Sec 5.2

FIPS 140-3

FIPS 140-3 §7.4FIPS 140-3 §7.9

PCI HSM

9

Common Criteria

CC Part 2 — FIA

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.4

Lloyd's Minimum Standards

MS8.3

NAIC Insurance Data Security

4-access4B

PRA SS1/23

P-IT.1

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.a01.c

FDA 21 CFR Part 11

§11.10(d)§11.100(a)§11.100(b)§11.200(a)(1)§11.200(a)(1)(ii)§11.200(a)(2)§11.300(a)§11.300(b)§11.300(c)§11.300(e)

FDA Cybersecurity Guidance

SA-1

ISO 27799

9.39.4

NHS DSPT

NDG-4.1NDG-4.2NDG-4.3

OWASP MASVS v2.1

MASVS-AUTH-1MASVS-AUTH-2MASVS-NETWORK-2

CCSS v9.0

1.04.11.04.21.06.2

MiCA

Art.40(1)Art.55(1)Art.63(1)Art.67(1)Art.76(1)

Basel SCO60

SCO60.61SCO60.62SCO60.66

BSSC Standards

GSP-11KMS-06KMS-07KMS-08NOS-05NOS-08

SEC Custody (Digital Assets)

SEC-CD-02SEC-CD-03SEC-CD-05SEC-CD-06SEC-CD-07SEC-CD-16

India DPDPA

Rules.6(1)(b)

ISO 17799 (legacy)

11.5.211.5.3

COBIT 4.1 (legacy)

None.