03.05.01: User Identification and Authentication

Control Familly: Identification and Authentication

SPRS: N/A

Top Ten Failed Requirement: N/A

Supporting Publications:

  • SP 800-63-3 [27]

Referenced in: N/A

Control Type: N/A

CPCSC Level 2: 03.05.01

CMMC Level(s): N/A

Derived From: NIST SP 800-53r5

  • IA-02

  • IA-11

a. Uniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users.

b. Re-authenticate users when [Assignment: organization-defined circumstances or situations requiring re-authentication].

Discussion:

System users include individuals (or system processes acting on behalf of individuals) who are authorized to access a system. Typically, individual identifiers are the usernames associated with the system accounts assigned to those individuals. Since system processes execute on behalf of groups and roles, organizations may require the unique identification of individuals in group accounts or the accountability of individual activity. The unique identification and authentication of users apply to all system accesses. Organizations use passwords, physical authenticators, biometrics, or some combination thereof to authenticate user identities. Organizations may reauthenticate individuals in certain situations, including when roles, authenticators, or credentials change; when the execution of privileged functions occurs; after a fixed time period; or periodically.

Assessment Methods and Objectives

Examine [SELECT FROM: identification and authentication policy and procedures; list of circumstances or situations requiring re-authentication; system design documentation; system configuration settings; system audit records; list of system accounts; system security plan; other relevant documents or records]

Interview [SELECT FROM: personnel with identification and authentication responsibilities; personnel with system operations responsibilities; personnel with account management responsibilities; system developers; personnel with information security responsibilities; system administrators]

Test [SELECT FROM: processes for uniquely identifying and authenticating users; mechanisms for supporting or implementing identification and authentication capabilities]

NIST SP 800-171A r3 Determining Statements Determine if:

A.03.05.01.ODP[01]: circumstances or situations that require re-authentication are defined.

A.03.05.01.a[01]: system users are uniquely identified. A

.03.05.01.a[02]: system users are authenticated.

A.03.05.01.a[03]: processes acting on behalf of users are associated with uniquely identified and authenticated system users.

A.03.05.01.b: users are reauthenticated when <A.03.05.01.ODP[01]: circumstances or situations>.