NIST SP 800-53 Rev 5
IA - Identification and Authentication

NIST SP 800-53 Rev 5 NIST800-IA-5: IA-5 Authenticator Management

Manage system authenticators by: a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator; b. Establishing initial authenticator content for any authenticators issued by the organization; c. Ensuring that authenticators have sufficient strength of mechanism for their intended use; d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators; e. Changing default authenticators prior to first use; f. Changing or refreshing authenticators [Assignment: organization-defined time period by authenticator type] or when [Assignment: organization-defined events] occur; g. Protecting authenticator content from unauthorized disclosure and modification; h. Requiring individuals to take, and having devices implement, specific controls to protect authenticators; and i. Changing authenticators for group or role accounts when membership to those accounts changes.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 98 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 22 controls

  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 3.5.1.1 3.5.1.1 PAN hashes are keyed cryptographic hashes
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 3.6.1.2 3.6.1.2 Permitted storage forms for secret and private keys
  • 3.6.1.3 3.6.1.3 Cleartext key component access limited to minimum custodians
  • 3.7.3 3.7.3 Secure storage of cryptographic keys
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.3.10 8.3.10 Service provider customer password guidance
  • 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 8.3.3 8.3.3 Identity verified before factor changes
  • 8.3.5 8.3.5 Initial and reset passwords unique and changed
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts
  • 8.6.3 8.6.3 System account passwords protected against misuse

FedRAMP High · 7 controls

  • AC-18(1) Authentication and Encryption
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(2) Public Key-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7))

FedRAMP Moderate · 7 controls

  • AC-18(1) Authentication and Encryption
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(2) Public Key-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7))

CMMC 2.0 · 6 controls

  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-IM-8 Restrict the exposure of credential and secrets
  • DS-6 Enforce security of workload throughout DevOps lifecycle
  • IM-3 Manage application identities securely and automatically

CIS Controls v8 · 4 controls

  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.2 Use Unique Passwords
  • CIS-5.6 Centralize Account Management

UK Cyber Essentials · 4 controls

  • CE-AC.8 Passwordless Authentication
  • CE-SC.2 Change Default Passwords on Devices and Software
  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.8 Process for Compromised Passwords
  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services

C5 (Germany) · 3 controls

  • C5-IDM-08 Confidentiality of authentication information
  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-07 Confidentiality of Authentication Information

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

ACSC Essential Eight · 2 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • ASD37-21 Disable local administrator accounts (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)

ISO 27001:2022 · 2 controls

  • 5.17 Authentication information
  • 8.5 Secure authentication

ISO 27002:2022 · 2 controls

  • 5.17 Authentication information
  • 8.5 Secure authentication
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified

NIST SP 800-171 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • MALABO-Art7 Security of Electronic Transactions and Electronic Signatures
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

CMMC 2.0 Level 1 · 1 control

ETSI EN 303 645 · 1 control

  • EN303645-5.1 No universal default passwords

NIST SP 800-172 · 1 control

NIST SP 800-187 · 1 control

NIST SP 800-207 · 1 control

  • IA-5 IA-5 Authenticator Management
  • IA-5 IA-5 Authenticator Management
  • IA-5 IA-5 Authenticator Management

SOC 2 · 1 control

  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IA - Identification and Authentication

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-IA-5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 98 it maps to, and the evidence behind each claim, over MCP and REST.