NIST Special Publication 800-171 Revision 2
Date Published: January 28th, 2021
Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3
Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)
Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here
3.5.2 Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.
Control Family: Identification and Authentication
Control Type: Basic
SPRS Value: 5
SPRS Supplemental Guidance: N/A
CMMC Level(s):
IA.L1-b.1.vi
IA.L2-3.5.2
Top Ten Failed Requirement: No
DIBCAC HIGH Failure Rate (OTS):
73rd of 110
Referenced in:
DFARS 252.204-7012
Derived From: NIST SP 800-53r4
IA-2
IA-3
IA-5
NIST Supplemental Guidance:
N/A
NIST SP 800-171r2 Control 3.5.2 → MITRE ATT&CK 14.1
Summary
- Total mappings: 242
- Families: 3
- Outer ring: Technique ID + name
- MITRE ATT&CK version: 14.1
Family counts
- Identification and Authentication (Organizational Users): 166 techniques
- Device Identification and Authentication: 8 techniques
- Authenticator Management: 68 techniques
Usage notes
- Click a family or technique to zoom in.
- Click the center to zoom back out.
- Hover to view technique details.
Discussion:
Individual authenticators include the following: passwords, key cards, cryptographic devices, and one-time password devices. Initial authenticator content is the actual content of the authenticator, for example, the initial password. In contrast, the requirements about authenticator content include the minimum password length. Developers ship system components with factory default authentication credentials to allow for initial installation and configuration. Default authentication credentials are often well known, easily discoverable, and present a significant security risk.
Systems support authenticator management by organization-defined settings and restrictions for various authenticator characteristics including minimum password length, validation time window for time synchronous one-time tokens, and number of allowed rejections during the verification stage of biometric authentication. Authenticator management includes issuing and revoking, when no longer needed, authenticators for temporary access such as that required for remote maintenance. Device authenticators include certificates and passwords.
[SP 800-63-3] provides guidance on digital identities.
Determining Statements (NIST SP 800-171Ar2)
3.5.2[a] the identity of each user is authenticated or verified as a prerequisite to system
access.
3.5.2[b] the identity of each process acting on behalf of a user is authenticated or
verified as a prerequisite to system access.
3.5.2[c] the identity of each device accessing or connecting to the system is
authenticated or verified as a prerequisite to system access.
Assessors are instructed to-
Examine: [SELECT FROM: Identification and authentication policy; system security plan; procedures addressing authenticator management; procedures addressing user identification and authentication; system design documentation; list of system authenticator types; system configuration settings and associated documentation; change control records associated with managing system authenticators; system audit logs and records; other relevant documents or records].
Interview: [SELECT FROM: Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators].
Test: [SELECT FROM: Mechanisms supporting or implementing authenticator management capability].
FURTHER DISCUSSION
Before a person or device is given system access, verify that the user or device is who or what it claims to be. This verification is called authentication. The most common way to verify identity is using a username and a hard-to-guess password. Some devices ship with default usernames and passwords. Some devices ship with a default username (e.g., admin) and password. A default username and password must be immediately changed to something unique. Default passwords may be well known to the public, easily found in a search, or easy to guess, allowing an unauthorized person to access the system.
Example 1
You are in charge of purchasing. You know that some laptops come with a default username and password. You notify IT that all default passwords should be reset prior to laptop use [a]. You ask IT to explain the importance of resetting default passwords and convey how easily they are discovered using internet searches during next week’s cybersecurity awareness training.
Example 2
Your company decides to use cloud services for email and other capabilities. Upon reviewing this requirement, you realize every user or device that connects to the cloud service must be authenticated. As a result, you work with your cloud service provider to ensure that only properly authenticated users and devices are allowed to connect to the system [a,c].
Potential Assessment Considerations
Are unique authenticators used to verify user identities (e.g., passwords) [a]?
An example of a process acting on behalf of users could be a script that logs in as a person or service account [b]. Can the OSA show that it maintains a record of all of those service accounts for use when reviewing log data or responding to an incident?
Are user credentials authenticated in system processes (e.g., credentials binding, certificates, tokens) [b]?
Are device identifiers used in authentication processes (e.g., MAC address, nonanonymous computer name, certificates) [c]?
ISO/IEC 27001:2013
A.9.2.1 User registration and de-registration
A.9.2.1 User registration and de-registration
A.9.2.4 Management of secret authentication information of users
A.9.3.1 Use of secret authentication information
A.9.4.3 Password management system
NIST SP 800-171r2 Control 3.5.2 → MITRE ATT&CK
Total Mappings
Families
Control
Authenticator Management 68 techniques
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.003NTDS
- T1003.004LSA Secrets
- T1003.005Cached Domain Credentials
- T1003.006DCSync
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.004SSH
- T1040Network Sniffing
- T1072Software Deployment Tools
- T1078Valid Accounts
- T1078.002Domain Accounts
- T1078.004Cloud Accounts
- T1098.001Additional Cloud Credentials
- T1098.002Exchange Email Delegate Permissions
- T1098.003Add Office 365 Global Administrator Role
- T1098.004SSH Authorized Keys
- T1110Brute Force
- T1110.001Password Guessing
- T1110.002Password Cracking
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1111Two-Factor Authentication Interception
- T1114Email Collection
- T1114.002Remote Email Collection
- T1133External Remote Services
- T1136Create Account
- T1136.001Local Account
- T1136.002Domain Account
- T1136.003Cloud Account
- T1528Steal Application Access Token
- T1530Data from Cloud Storage Object
- T1539Steal Web Session Cookie
- T1550.003Pass the Ticket
- T1552Unsecured Credentials
- T1552.001Credentials In Files
- T1552.002Credentials in Registry
- T1552.004Private Keys
- T1552.006Group Policy Preferences
- T1555Credentials from Password Stores
- T1555.001Keychain
- T1555.002Securityd Memory
- T1555.004Windows Credential Manager
- T1555.005Password Managers
- T1556Modify Authentication Process
- T1556.001Domain Controller Authentication
- T1556.003Pluggable Authentication Modules
- T1556.004Network Device Authentication
- T1556.005Reversible Encryption
- T1558Steal or Forge Kerberos Tickets
- T1558.001Golden Ticket
- T1558.002Silver Ticket
- T1558.003Kerberoasting
- T1558.004AS-REP Roasting
- T1559Inter-Process Communication
- T1559.001Component Object Model
- T1563.001SSH Hijacking
- T1599Network Boundary Bridging
- T1599.001Network Address Translation Traversal
- T1601Modify System Image
- T1601.001Patch System Image
- T1601.002Downgrade System Image
- T1621Multi-Factor Authentication Request Generation
- T1649Steal or Forge Authentication Certificates
Device Identification and Authentication 8 techniques
- T1530Data from Cloud Storage Object
- T1537Transfer Data to Cloud Account
- T1552Unsecured Credentials
- T1552.005Cloud Instance Metadata API
- T1602Data from Configuration Repository
- T1602.001SNMP (MIB Dump)
- T1602.002Network Device Configuration Dump
- T1621Multi-Factor Authentication Request Generation
Identification and Authentication (Organizational Users) 166 techniques
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.003NTDS
- T1003.004LSA Secrets
- T1003.005Cached Domain Credentials
- T1003.006DCSync
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.002SMB/Windows Admin Shares
- T1021.003Distributed Component Object Model
- T1021.004SSH
- T1021.005VNC
- T1021.006Windows Remote Management
- T1036.007Double File Extension
- T1040Network Sniffing
- T1047Windows Management Instrumentation
- T1053Scheduled Task/Job
- T1053.002At (Windows)
- T1053.003Cron
- T1053.005Scheduled Task
- T1053.006Systemd Timers
- T1053.007Container Orchestration Job
- T1055Process Injection
- T1055.008Ptrace System Calls
- T1056.003Web Portal Capture
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.008Network Device CLI
- T1072Software Deployment Tools
- T1078Valid Accounts
- T1078.002Domain Accounts
- T1078.003Local Accounts
- T1078.004Cloud Accounts
- T1087.004Cloud Account
- T1098Account Manipulation
- T1098.001Additional Cloud Credentials
- T1098.002Exchange Email Delegate Permissions
- T1098.003Add Office 365 Global Administrator Role
- T1098.004SSH Authorized Keys
- T1110Brute Force
- T1110.001Password Guessing
- T1110.002Password Cracking
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1111Two-Factor Authentication Interception
- T1114Email Collection
- T1114.002Remote Email Collection
- T1133External Remote Services
- T1134Access Token Manipulation
- T1134.001Token Impersonation/Theft
- T1134.002Create Process with Token
- T1134.003Make and Impersonate Token
- T1136Create Account
- T1136.001Local Account
- T1136.002Domain Account
- T1136.003Cloud Account
- T1185Browser Session Hijacking
- T1190Exploit Public-Facing Application
- T1197BITS Jobs
- T1210Exploitation of Remote Services
- T1213Data from Information Repositories
- T1213.001Confluence
- T1213.002Sharepoint
- T1213.003Code Repositories
- T1218Signed Binary Proxy Execution
- T1218.007Msiexec
- T1222File and Directory Permissions Modification
- T1222.001Windows File and Directory Permissions Modification
- T1222.002Linux and Mac File and Directory Permissions Modification
- T1484Domain Policy Modification
- T1489Service Stop
- T1495Firmware Corruption
- T1505Server Software Component
- T1505.001SQL Stored Procedures
- T1505.002Transport Agent
- T1505.004IIS Components
- T1525Implant Internal Image
- T1528Steal Application Access Token
- T1530Data from Cloud Storage Object
- T1537Transfer Data to Cloud Account
- T1538Cloud Service Dashboard
- T1539Steal Web Session Cookie
- T1542Pre-OS Boot
- T1542.001System Firmware
- T1542.003Bootkit
- T1542.005TFTP Boot
- T1543Create or Modify System Process
- T1543.001Launch Agent
- T1543.002Systemd Service
- T1543.003Windows Service
- T1543.004Launch Daemon
- T1546.003Windows Management Instrumentation Event Subscription
- T1547.004Winlogon Helper DLL
- T1547.006Kernel Modules and Extensions
- T1547.009Shortcut Modification
- T1547.012Print Processors
- T1547.013XDG Autostart Entries
- T1548Abuse Elevation Control Mechanism
- T1548.002Bypass User Account Control
- T1548.003Sudo and Sudo Caching
- T1550Use Alternate Authentication Material
- T1550.001Application Access Token
- T1550.002Pass the Hash
- T1550.003Pass the Ticket
- T1552Unsecured Credentials
- T1552.001Credentials In Files
- T1552.002Credentials in Registry
- T1552.004Private Keys
- T1552.006Group Policy Preferences
- T1552.007Container API
- T1553Subvert Trust Controls
- T1553.006Code Signing Policy Modification
- T1555.005Password Managers
- T1556Modify Authentication Process
- T1556.001Domain Controller Authentication
- T1556.003Pluggable Authentication Modules
- T1556.004Network Device Authentication
- T1556.006Multi-Factor Authentication
- T1556.007Hybrid Identity
- T1558Steal or Forge Kerberos Tickets
- T1558.001Golden Ticket
- T1558.002Silver Ticket
- T1558.003Kerberoasting
- T1558.004AS-REP Roasting
- T1559Inter-Process Communication
- T1559.001Component Object Model
- T1562Impair Defenses
- T1562.001Disable or Modify Tools
- T1562.002Disable Windows Event Logging
- T1562.004Disable or Modify System Firewall
- T1562.006Indicator Blocking
- T1562.007Disable or Modify Cloud Firewall
- T1562.008Disable Cloud Logs
- T1562.009Safe Mode Boot
- T1563Remote Service Session Hijacking
- T1563.001SSH Hijacking
- T1563.002RDP Hijacking
- T1569System Services
- T1569.001Launchctl
- T1569.002Service Execution
- T1574Hijack Execution Flow
- T1574.005Executable Installer File Permissions Weakness
- T1574.010Services File Permissions Weakness
- T1574.012COR_PROFILER
- T1578Modify Cloud Compute Infrastructure
- T1578.001Create Snapshot
- T1578.002Create Cloud Instance
- T1578.003Delete Cloud Instance
- T1580Cloud Infrastructure Discovery
- T1585.003Cloud Accounts
- T1586.003Cloud Accounts
- T1599Network Boundary Bridging
- T1599.001Network Address Translation Traversal
- T1601Modify System Image
- T1601.001Patch System Image
- T1601.002Downgrade System Image
- T1610Deploy Container
- T1611Escape to Host
- T1613Container and Resource Discovery
- T1619Cloud Storage Object Discovery
- T1621Multi-Factor Authentication Request Generation
- T1648Serverless Execution
- T1649Steal or Forge Authentication Certificates
Frameworks & Controls
3.5: Identification and Authentication
3.5.1 Identify system users, processes acting on behalf of users, and devices.
3.5.6 Disable identifiers after a defined period of inactivity.
3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created.
3.5.8 Prohibit password reuse for a specified number of generations.
3.5.10 Store and transmit only cryptographically-protected passwords.