Identification and Authentication
Identify users, processes, and devices before authorizing access.
Identification and authentication is the family that contains multi-factor authentication. It covers unique identities for users and devices, how authenticators are issued and protected, password rules, and replay resistance. Two of its requirements are Level 1 practices.
- 3.5.1 Give every user, process, and device an identity
- 3.5.2 Prove those identities
- 3.5.3 Require multi-factor authentication
- 3.5.4 Use replay-resistant authentication
- 3.5.5 Do not recycle identifiers
- 3.5.6 Disable dormant accounts
- 3.5.7 Set password rules
- 3.5.8 Block password reuse
- 3.5.9 Force a change after a temporary password
- 3.5.10 Never store or send passwords in the clear
- 3.5.11 Hide password entry