# IA-06 Authentication Feedback

NIST SP 800-53 control. Family: IA Identification and Authentication. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.
Guidance: Authentication feedback from systems does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For some types of systems, such as desktops or notebooks with relatively large monitors, the threat (referred to as shoulder surfing) may be significant. For other types of systems, such as mobile devices with small displays, the threat may be less significant and is balanced against the increased likelihood of typographic input errors due to small keyboards. Thus, the means for obscuring authentication feedback is selected accordingly. Obscuring authentication feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a very limited time before obscuring it.

## Patterns that use it (4)
- Standard (4): SP-001 Client Module; SP-002 Server Module; SP-032 Modern Authentication; SP-033 Passkey Authentication

## Clauses by framework (39 frameworks)
- iso_27001_2022: A.5.17, A.8.5. OSA's own, not in NIST's crosswalk: A.5.17
- iso_27002_2022: 5.17
- cobit_2019: DSS05
- nist_csf_2: PR.AA-01
- mas_trm: 9
- bsi_grundschutz: ORP.4
- anssi: Hygiene.10, SecNumCloud.10.5
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59)
- gdpr: Art.32(1)(b)
- dora: Art.9(4)(c)
- bio2: 5.17
- rbi_csf: Annex1.8
- fisc: FISC.T2
- hkma_tme1: TME1.8.3
- mlps_2: 8.1.4.1
- cra: CRA.I.2d
- cbb_tm: TM-6
- cbuae: CR-4
- nca_ecc: 2-2
- qatar_nia: AC
- sama_csf: 3.1
- uae_ia: T9
- bog_cisd: CISD-VIII
- bom_ctrm: 3.3
- cbe_csf: CTO-1
- cbn_csf: Part3.2
- sa_js2: JS2-7.1, JS2-8.1
- bot_cyber: Ch2.2
- eba_ict: 3.4.2
- ffiec_is: II.C.15
- hipaa_sr: §164.308(a)(5)(ii)(D), §164.312(d)
- iosco_cyber: PROT-1
- sebi_cscrf: PR.AA
- cmmc_2: IA
- common_criteria: CC Part 2 — FIA
- fda_21_cfr_11: §11.200(a)(1), §11.300(d)
- fda_cyber: SA-1
- hitrust_csf: 01.c
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/IA-06
- Clauses only: /api/v1/controls/IA-06?fields=mappings
- Page for people: /controls/ia-06/
