NIST SP 800-53 Rev 5 HIGH
IA: Identification and Authentication – NIST SP 800-53 Revision 5.1 HIGH

NIST SP 800-53 Rev 5 HIGH IA-5(1): IA-5(1) Authenticator Management | Password-based Authentication

For password-based authentication: (a) Maintain a list of commonly-used, expected, or compromised passwords and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised directly or indirectly; (b) Verify, when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5(1)(a); (c) Transmit passwords only over cryptographically-protected channels; (d) Store passwords using an approved salted key derivation function, preferably using a keyed hash; (e) Require immediate selection of a new password upon account recovery; (f) Allow user selection of long passwords and passphrases, including spaces and all printable characters; (g) Employ automated tools to assist the user in selecting strong password authenticators; and (h) Enforce the following composition and complexity rules: [Assignment: organization-defined composition and complexity rules].

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 3 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 1 control

  • IA-5(1) Password-Based Authentication

FedRAMP Moderate · 1 control

  • IA-5(1) Password-Based Authentication
  • NIST800-IA-5(1) IA-5(1) Authenticator Management | Password-based Authentication

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IA: Identification and Authentication – NIST SP 800-53 Revision 5.1 HIGH

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.