Identification and Authentication
NIST SP 800-53 Rev 5 Identification and Authentication controls.
Policy and Procedures
Develop, document, and disseminate to [parameter]:
Identification and Authentication (Organizational Users)
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Device Identification and Authentication
Uniquely identify and authenticate [parameter] before establishing a [parameter] connection.
Identifier Management
Manage system identifiers by:
Authenticator Management
Manage system authenticators by:
Authentication Feedback
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.
Cryptographic Module Authentication
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.
Identification and Authentication (Non-organizational Users)
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Service Identification and Authentication
Uniquely identify and authenticate [parameter] before establishing communications with devices, users, or other services or applications.
Adaptive Authentication
Require individuals accessing the system to employ [parameter] under specific [parameter].
Re-authentication
Require users to re-authenticate when [parameter].
Identity Proofing
Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines;
Identity Providers and Authorization Servers
Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance with [parameter] using [parameter].