NIST 800-171 v2

110 security requirements available

3.5.11Derived Requirement

Identification and Authentication

Security Requirement

Obscure feedback of authentication information

Discussion

The feedback from systems does not provide any information that would allow unauthorized individuals to compromise authentication mechanisms. For some types of systems or system components, for example, desktop or notebook computers with relatively large monitors, the threat (often referred to as shoulder surfing) may be significant. For other types of systems or components, for example, mobile devices with small displays, this threat may be less significant, and is balanced against the increased likelihood of typographic input errors due to the small keyboards. Therefore, the means for obscuring the authenticator feedback is selected accordingly. Obscuring authenticator feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a very limited time before fully obscuring it.

Framework
NIST SP 800-171 Rev 2
Family
Identification and Authentication
Requirement Type
derived

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
IA-6
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000206
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

41 STIGs reach this control through 1 CCI via 800-53 control IA-6. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

4 STIGs

Operating System — Server

2 STIGs

Operating System — Mainframe

4 STIGs
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-093 of 225 findings match
Mainframe Product Security Requirements Guide
32024-12-051 of 193 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match

Network Device

2 STIGs
Network Device Management Security Requirements Guide
V5R32025-02-111 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-101 of 105 findings match

Database

17 STIGs
Database Security Requirements Guide
42024-12-041 of 142 findings match
Database Security Requirements Guide
V4R52026-02-261 of 142 findings match
Show 9 more STIGs in this category →

Web / Application Server

4 STIGs

Virtualization / Container

4 STIGs
Container Platform Security Requirements Guide
22025-05-151 of 187 findings match
Container Platform Security Requirements Guide
V2R42025-09-101 of 188 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-061 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-101 of 198 findings match

Endpoint Security Management

4 STIGs
Central Log Server Security Requirements Guide
32024-12-041 of 125 findings match
Central Log Server Security Requirements Guide
V3R42026-02-121 of 127 findings match