NIST Special Publication 800-171 Revision 2
Date Published: January 28th, 2021
Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3
Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)
Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here
3.5.3 Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
Control Family: Identification and Authentication
Control Type: Derived
SPRS Value: 3/5
SPRS Supplemental Guidance:
Subtract 5 points if MFA not
implemented.
Subtract 3 points if implemented for
remote and privileged users,
but not the general user.
CMMC Level(s): IA.L2-3.5.3
DIBCAC HIGH Failure Rate (OTS):
2nd of 110
Referenced in:
DFARS 252.204-7012
Derived From: NIST SP 800-53r4
IA-2(1)
IA-2(2)
IA-2(3)
NIST Supplemental Guidance:
[SP 800-63-3]
NIST SP 800-171r2 Control 3.5.3 → MITRE ATT&CK 14.1
Summary
- Total mappings: 166
- Families: 1
- Outer ring: Technique ID + name
- MITRE ATT&CK version: 14.1
Family counts
- Identification and Authentication (Organizational Users): 166 techniques
Usage notes
- Click a family or technique to zoom in.
- Click the center to zoom back out.
- Hover to view technique details.
Discussion:
Multifactor authentication requires the use of two or more different factors to authenticate. The factors are defined as something you know (e.g., password, personal identification number [PIN]); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). Multifactor authentication solutions that feature physical authenticators include hardware authenticators providing time-based or challenge-response authenticators and smart cards. In addition to authenticating users at the system level (i.e., at logon), organizations may also employ authentication mechanisms at the application level, when necessary, to provide increased information security.
Access to organizational systems is defined as local access or network access. Local access is any access to organizational systems by users (or processes acting on behalf of users) where such access is obtained by direct connections without the use of networks. Network access is access to systems by users (or processes acting on behalf of users) where such access is obtained through network connections (i.e., nonlocal accesses). Remote access is a type of network access that involves communication through external networks. The use of encrypted virtual private networks for connections between organization-controlled and non-organization controlled endpoints may be treated as internal networks with regard to protecting the confidentiality of information.
[SP 800-63-3] provides guidance on digital identities.
Determining Statements (NIST SP 800-171Ar2)
3.5.3[a] privileged accounts are identified.
3.5.3[b] multifactor authentication is implemented for local access to privileged
accounts.
3.5.3[c] multifactor authentication is implemented for network access to privileged
accounts.
3.5.3[d] multifactor authentication is implemented for network access to non-privileged
accounts.
Assessors are instructed to-
Examine: [SELECT FROM: Identification and authentication policy; procedures addressing user identification and authentication; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; list of system accounts; other relevant documents or records].
Interview: [SELECT FROM: Personnel with system operations responsibilities; personnel with account management responsibilities; personnel with information security responsibilities; system or network administrators; system developers].
Test: [SELECT FROM: Mechanisms supporting or implementing multifactor authentication capability].
FURTHER DISCUSSION
Implement a combination of two or more factors of authentication to verify privileged account holders’ identity regardless of how the user is accessing the account. Implement a combination of two or more factors for non-privileged users accessing the system over a network.
The implementation of multi-factor authentication will depend on the environment and business needs. Although two-factor authentication directly on the computer is most common, there are situations (e.g., multi-factor identification for a mission system that cannot be altered) where additional technical or physical solutions can provide security. If a mobile device is used to access a system or application containing CUI, multi-factor authentication is required.
This requirement, IA.L2-3.5.3, requires multifactor authentication for network access to non-privileged accounts and complements five other requirements dealing with remote access (AC.L2-3.1.12, AC.L2-3.1.14, AC.L2-3.1.13, AC.L2-3.1.15, and MA.L2-3.7.5:
AC.L2-3.1.12 requires the control of remote access sessions.
AC.L2-3.1.14 limits remote access to specific access control points.
AC.L2-3.1.13 requires the use of cryptographic mechanisms when enabling remote sessions.
AC.L2-3.1.15 requires authorization for privileged commands executed during a remote.
Finally, MA.L2-3.7.5 requires the addition of multifactor authentication for remote maintenance sessions.
This requirement, IA.L2-3.5.3, also enhances IA.L2-3.5.2, which is a requirement for a less rigorous form of user authentication.
Example
You decide to implement multifactor authentication (MFA) to improve security of your network. Your first step is enabling MFA on VPN access to your internal network [c,d]. When users initiate remote access, they will be prompted for the additional authentication factor. Because you also use a cloud-based email solution, you require MFA for access to that resource as well [c,d]. Finally, you enable MFA for both local and network logins for the system administrator accounts used to patch and manage servers [a,b,c].
Potential Assessment Considerations
Does the system uniquely identify and authenticate users, including privileged accounts [b,c,d]?
ISO/IEC 27001:2013
No direct mapping
NIST SP 800-171r2 Control 3.5.3 → MITRE ATT&CK
Total Mappings
Families
Control
Identification and Authentication (Organizational Users) 166 techniques
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.003NTDS
- T1003.004LSA Secrets
- T1003.005Cached Domain Credentials
- T1003.006DCSync
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.002SMB/Windows Admin Shares
- T1021.003Distributed Component Object Model
- T1021.004SSH
- T1021.005VNC
- T1021.006Windows Remote Management
- T1036.007Double File Extension
- T1040Network Sniffing
- T1047Windows Management Instrumentation
- T1053Scheduled Task/Job
- T1053.002At (Windows)
- T1053.003Cron
- T1053.005Scheduled Task
- T1053.006Systemd Timers
- T1053.007Container Orchestration Job
- T1055Process Injection
- T1055.008Ptrace System Calls
- T1056.003Web Portal Capture
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.008Network Device CLI
- T1072Software Deployment Tools
- T1078Valid Accounts
- T1078.002Domain Accounts
- T1078.003Local Accounts
- T1078.004Cloud Accounts
- T1087.004Cloud Account
- T1098Account Manipulation
- T1098.001Additional Cloud Credentials
- T1098.002Exchange Email Delegate Permissions
- T1098.003Add Office 365 Global Administrator Role
- T1098.004SSH Authorized Keys
- T1110Brute Force
- T1110.001Password Guessing
- T1110.002Password Cracking
- T1110.003Password Spraying
- T1110.004Credential Stuffing
- T1111Two-Factor Authentication Interception
- T1114Email Collection
- T1114.002Remote Email Collection
- T1133External Remote Services
- T1134Access Token Manipulation
- T1134.001Token Impersonation/Theft
- T1134.002Create Process with Token
- T1134.003Make and Impersonate Token
- T1136Create Account
- T1136.001Local Account
- T1136.002Domain Account
- T1136.003Cloud Account
- T1185Browser Session Hijacking
- T1190Exploit Public-Facing Application
- T1197BITS Jobs
- T1210Exploitation of Remote Services
- T1213Data from Information Repositories
- T1213.001Confluence
- T1213.002Sharepoint
- T1213.003Code Repositories
- T1218Signed Binary Proxy Execution
- T1218.007Msiexec
- T1222File and Directory Permissions Modification
- T1222.001Windows File and Directory Permissions Modification
- T1222.002Linux and Mac File and Directory Permissions Modification
- T1484Domain Policy Modification
- T1489Service Stop
- T1495Firmware Corruption
- T1505Server Software Component
- T1505.001SQL Stored Procedures
- T1505.002Transport Agent
- T1505.004IIS Components
- T1525Implant Internal Image
- T1528Steal Application Access Token
- T1530Data from Cloud Storage Object
- T1537Transfer Data to Cloud Account
- T1538Cloud Service Dashboard
- T1539Steal Web Session Cookie
- T1542Pre-OS Boot
- T1542.001System Firmware
- T1542.003Bootkit
- T1542.005TFTP Boot
- T1543Create or Modify System Process
- T1543.001Launch Agent
- T1543.002Systemd Service
- T1543.003Windows Service
- T1543.004Launch Daemon
- T1546.003Windows Management Instrumentation Event Subscription
- T1547.004Winlogon Helper DLL
- T1547.006Kernel Modules and Extensions
- T1547.009Shortcut Modification
- T1547.012Print Processors
- T1547.013XDG Autostart Entries
- T1548Abuse Elevation Control Mechanism
- T1548.002Bypass User Account Control
- T1548.003Sudo and Sudo Caching
- T1550Use Alternate Authentication Material
- T1550.001Application Access Token
- T1550.002Pass the Hash
- T1550.003Pass the Ticket
- T1552Unsecured Credentials
- T1552.001Credentials In Files
- T1552.002Credentials in Registry
- T1552.004Private Keys
- T1552.006Group Policy Preferences
- T1552.007Container API
- T1553Subvert Trust Controls
- T1553.006Code Signing Policy Modification
- T1555.005Password Managers
- T1556Modify Authentication Process
- T1556.001Domain Controller Authentication
- T1556.003Pluggable Authentication Modules
- T1556.004Network Device Authentication
- T1556.006Multi-Factor Authentication
- T1556.007Hybrid Identity
- T1558Steal or Forge Kerberos Tickets
- T1558.001Golden Ticket
- T1558.002Silver Ticket
- T1558.003Kerberoasting
- T1558.004AS-REP Roasting
- T1559Inter-Process Communication
- T1559.001Component Object Model
- T1562Impair Defenses
- T1562.001Disable or Modify Tools
- T1562.002Disable Windows Event Logging
- T1562.004Disable or Modify System Firewall
- T1562.006Indicator Blocking
- T1562.007Disable or Modify Cloud Firewall
- T1562.008Disable Cloud Logs
- T1562.009Safe Mode Boot
- T1563Remote Service Session Hijacking
- T1563.001SSH Hijacking
- T1563.002RDP Hijacking
- T1569System Services
- T1569.001Launchctl
- T1569.002Service Execution
- T1574Hijack Execution Flow
- T1574.005Executable Installer File Permissions Weakness
- T1574.010Services File Permissions Weakness
- T1574.012COR_PROFILER
- T1578Modify Cloud Compute Infrastructure
- T1578.001Create Snapshot
- T1578.002Create Cloud Instance
- T1578.003Delete Cloud Instance
- T1580Cloud Infrastructure Discovery
- T1585.003Cloud Accounts
- T1586.003Cloud Accounts
- T1599Network Boundary Bridging
- T1599.001Network Address Translation Traversal
- T1601Modify System Image
- T1601.001Patch System Image
- T1601.002Downgrade System Image
- T1610Deploy Container
- T1611Escape to Host
- T1613Container and Resource Discovery
- T1619Cloud Storage Object Discovery
- T1621Multi-Factor Authentication Request Generation
- T1648Serverless Execution
- T1649Steal or Forge Authentication Certificates
Frameworks & Controls
3.5: Identification and Authentication
3.5.1 Identify system users, processes acting on behalf of users, and devices.
3.5.6 Disable identifiers after a defined period of inactivity.
3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created.
3.5.8 Prohibit password reuse for a specified number of generations.
3.5.10 Store and transmit only cryptographically-protected passwords.