← Controls / IA

IA-06 Authentication Feedback

Identification and Authentication

Low Moderate High

Description

Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.

Supplemental Guidance

Authentication feedback from systems does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For some types of systems, such as desktops or notebooks with relatively large monitors, the threat (referred to as shoulder surfing) may be significant. For other types of systems, such as mobile devices with small displays, the threat may be less significant and is balanced against the increased likelihood of typographic input errors due to small keyboards. Thus, the means for obscuring authentication feedback is selected accordingly. Obscuring authentication feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a very limited time before obscuring it.

Patterns that use this control (4)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.17A.8.5

ISO 27002:2022

5.17

COBIT 2019

DSS05

NIST CSF 2.0

PR.AA-01

MAS TRM

9

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.10SecNumCloud.10.5

FINMA Circular 2023/1

IV.B.d(59)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(b)

EU DORA

Art.9(4)(c)

BIO2

5.17

RBI CSF

Annex1.8

FISC Security Guidelines

FISC.T2

HKMA TM-E-1

TME1.8.3

MLPS 2.0

8.1.4.1

EU CRA

CRA.I.2d

SAMA CSF

3.1

NCA ECC

2-2

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CTO-1

SA JS2

JS2-7.1JS2-8.1

CBN CSF

Part3.2

BoG CISD

CISD-VIII

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

FFIEC IS

II.C.15

HIPAA Security Rule

§164.308(a)(5)(ii)(D)§164.312(d)

EBA ICT Guidelines

3.4.2

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2

CMMC 2.0

IA

Common Criteria

CC Part 2 — FIA

HITRUST CSF v11

01.c

FDA 21 CFR Part 11

§11.200(a)(1)§11.300(d)

FDA Cybersecurity Guidance

SA-1

ISO 17799 (legacy)

11.5.1

COBIT 4.1 (legacy)

None.