SecFrame Explorer
controls.intelligence
SearchPricing
AI lookups:3/3left
3/3
Sign in
FrameworksNIST 800-171Identification and Authentication
// Level 3 · Controls

Identification and Authentication

Identify users and authenticate identities.

3.5.1High

Identification

Identify system users, processes acting on behalf of users, and devices.

3.5.2High

Authentication

Authenticate the identities of users, processes, or devices as a prerequisite to allowing access.

3.5.3Critical

Multifactor Authentication

Use multifactor authentication for access to privileged accounts and for network access to non-privileged accounts.

3.5.4High

Replay-Resistant Authentication

Employ replay-resistant authentication mechanisms.

3.5.5Low

Identifier Reuse

Prevent reuse of identifiers for a defined period.

3.5.6Medium

Identifier Inactivity

Disable identifiers after a defined period of inactivity.

3.5.7Medium

Password Complexity

Enforce a minimum password complexity and change of characters when new passwords are created.

3.5.8Low

Password Reuse

Prohibit password reuse for a specified number of generations.

3.5.9Low

Temporary Passwords

Allow temporary password use for system logons with an immediate change to a permanent password.

3.5.10High

Cryptographic Password Storage

Store and transmit only cryptographically protected passwords.

3.5.11Low

Authenticator Feedback Obscuring

Obscure feedback of authentication information.

// SecFrame Explorer — security frameworks, decoded
TermsPricingRefundsPrivacy·Powered by arnav.au