FedRAMP High
IA - Identification and Authentication

FedRAMP High IA-5(1): Password-Based Authentication

Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 35 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 5 controls

  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 8.3.5 8.3.5 Initial and reset passwords unique and changed
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis

CMMC 2.0 · 4 controls

UK Cyber Essentials · 3 controls

  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.7 Educate Users on Strong Passwords
  • CE-SC.9 Device Unlocking Credentials and Brute-Force Protection

C5 (Germany) · 2 controls

  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-07 Confidentiality of Authentication Information

ISO 27002:2022 · 2 controls

  • 5.17 Authentication information
  • 8.5 Secure authentication

SOC 2 · 2 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules

CIS Controls v8 · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.17 Authentication information

ISO 27701:2019 · 1 control

  • 6.6.4 System and application access control

NIST SP 800-172 · 1 control

  • IA-5(1) IA-5(1) Authenticator Management | Password-based Authentication
  • IA-5(1) IA-5(1) Authenticator Management | Password-based Authentication
  • IA-5(1) IA-5(1) Authenticator Management | Password-based Authentication

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IA - Identification and Authentication

You are reading one control. How much of FedRAMP High have you already done?

FedRAMP High IA-5(1) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.

Query this from an agent

The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.