NIST 800-171 v2
110 security requirements available
Identification and Authentication
Security Requirement
Obscure feedback of authentication information
Discussion
The feedback from systems does not provide any information that would allow unauthorized individuals to compromise authentication mechanisms. For some types of systems or system components, for example, desktop or notebook computers with relatively large monitors, the threat (often referred to as shoulder surfing) may be significant. For other types of systems or components, for example, mobile devices with small displays, this threat may be less significant, and is balanced against the increased likelihood of typographic input errors due to the small keyboards. Therefore, the means for obscuring the authenticator feedback is selected accordingly. Obscuring authenticator feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a very limited time before fully obscuring it.
- Framework
- NIST SP 800-171 Rev 2
- Family
- Identification and Authentication
- Requirement Type
- derived
Related Frameworks
2 paths across 2 frameworks
Related Frameworks
NIST 800-531 mapping
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
Related STIGs
41 STIGs reach this control through 1 CCI via 800-53 control IA-6. Expand a row to see the responsible NICE and O*NET roles.