NIST Special Publication 800-171 Revision 2

Date Published: January 28th, 2021

Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3

Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)

Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here

3.5.10 Store and transmit only cryptographically-protected passwords.

Control Family: Identification and Authentication

Control Type: Derived

SPRS Value: 5

SPRS Supplemental Guidance:

Encrypted representations of passwords include, for example, encrypted versions of passwords and one-way cryptographic hashes of passwords

CMMC Level(s): IA.L2-3.5.10

Top Ten Failed Requirement: No

DIBCAC HIGH Failure Rate (OTS):

67th of 110

Referenced in:

DFARS 252.204-7012

Derived From: NIST SP 800-53r4

  • IA-5(1)

NIST Supplemental Guidance:

[NIST CRYPTO]

NIST SP 800-171r2 Control 3.5.10 → MITRE ATT&CK 14.1

NIST SP 800-171r2 Control 3.5.10 → MITRE ATT&CK 14.1

Mapping note: MITRE ATT&CK 14.1 techniques are derived through the NIST SP 800-53 Rev. 4 controls mapped to each NIST SP 800-171 Rev. 2 requirement.

Summary

  • Total mappings: 68
  • Families: 1
  • Outer ring: Technique ID + name
  • MITRE ATT&CK version: 14.1

Family counts

  • Authenticator Management: 68 techniques

Usage notes

  • Click a family or technique to zoom in.
  • Click the center to zoom back out.
  • Hover to view technique details.

Discussion:

Cryptographically-protected passwords use salted one-way cryptographic hashes of passwords. See [NIST CRYPTO].

Determining Statements (NIST SP 800-171Ar2)

3.5.10[a] passwords are cryptographically protected in storage.
3.5.10[b] passwords are cryptographically protected in transit.

Assessors are instructed to-

Examine: [SELECT FROM: Identification and authentication policy; password policy; procedures addressing authenticator management; system security plan; system configuration settings and associated documentation; system design documentation; password configurations and associated documentation; other relevant documents or records].

Interview: [SELECT FROM: Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators; system developers].

Test: [SELECT FROM: Mechanisms supporting or implementing password-based authenticator management capability].

FURTHER DISCUSSION

All passwords must be cryptographically protected using a one-way function for storage and transmission. This type of protection changes passwords into another form, or a hashed password. A one-way transformation makes it theoretically impossible to turn the hashed password back into the original password, but inadequate complexity (IA.L2-3.5.7) may still facilitate offline cracking of hashes.

Example

You are responsible for managing passwords for your organization. You protect all passwords with a one-way transformation, or hashing, before storing them. Passwords are never transmitted across a network unencrypted [a,b].

Potential Assessment Considerations

  • Are passwords prevented from being stored in reversible encryption form in any company systems [a]?

  • Are passwords stored as one-way hashes constructed from passwords [a]?

ISO/IEC 27001:2013

No direct mapping

NIST SP 800-171r2 Control 3.5.10 → MITRE ATT&CK
MITRE ATT&CK v14.1

NIST SP 800-171r2 Control 3.5.10 → MITRE ATT&CK

Total Mappings

68
technique references

Families

1
Authenticator Management

Control

3.5.10
IA.L2-3.5.10

Authenticator Management 68 techniques

  • T1003OS Credential Dumping
  • T1003.001LSASS Memory
  • T1003.002Security Account Manager
  • T1003.003NTDS
  • T1003.004LSA Secrets
  • T1003.005Cached Domain Credentials
  • T1003.006DCSync
  • T1003.007Proc Filesystem
  • T1003.008/etc/passwd and /etc/shadow
  • T1021Remote Services
  • T1021.001Remote Desktop Protocol
  • T1021.004SSH
  • T1040Network Sniffing
  • T1072Software Deployment Tools
  • T1078Valid Accounts
  • T1078.002Domain Accounts
  • T1078.004Cloud Accounts
  • T1098.001Additional Cloud Credentials
  • T1098.002Exchange Email Delegate Permissions
  • T1098.003Add Office 365 Global Administrator Role
  • T1098.004SSH Authorized Keys
  • T1110Brute Force
  • T1110.001Password Guessing
  • T1110.002Password Cracking
  • T1110.003Password Spraying
  • T1110.004Credential Stuffing
  • T1111Two-Factor Authentication Interception
  • T1114Email Collection
  • T1114.002Remote Email Collection
  • T1133External Remote Services
  • T1136Create Account
  • T1136.001Local Account
  • T1136.002Domain Account
  • T1136.003Cloud Account
  • T1528Steal Application Access Token
  • T1530Data from Cloud Storage Object
  • T1539Steal Web Session Cookie
  • T1550.003Pass the Ticket
  • T1552Unsecured Credentials
  • T1552.001Credentials In Files
  • T1552.002Credentials in Registry
  • T1552.004Private Keys
  • T1552.006Group Policy Preferences
  • T1555Credentials from Password Stores
  • T1555.001Keychain
  • T1555.002Securityd Memory
  • T1555.004Windows Credential Manager
  • T1555.005Password Managers
  • T1556Modify Authentication Process
  • T1556.001Domain Controller Authentication
  • T1556.003Pluggable Authentication Modules
  • T1556.004Network Device Authentication
  • T1556.005Reversible Encryption
  • T1558Steal or Forge Kerberos Tickets
  • T1558.001Golden Ticket
  • T1558.002Silver Ticket
  • T1558.003Kerberoasting
  • T1558.004AS-REP Roasting
  • T1559Inter-Process Communication
  • T1559.001Component Object Model
  • T1563.001SSH Hijacking
  • T1599Network Boundary Bridging
  • T1599.001Network Address Translation Traversal
  • T1601Modify System Image
  • T1601.001Patch System Image
  • T1601.002Downgrade System Image
  • T1621Multi-Factor Authentication Request Generation
  • T1649Steal or Forge Authentication Certificates