NIST 800-171 v2

110 security requirements available

3.5.2Basic Requirement

Identification and Authentication

Security Requirement

Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.

Discussion

Individual authenticators include the following: passwords, key cards, cryptographic devices, and one-time password devices. Initial authenticator content is the actual content of the authenticator, for example, the initial password. In contrast, the requirements about authenticator content include the minimum password length. Developers ship system components with factory default authentication credentials to allow for initial installation and configuration. Default authentication credentials are often well known, easily discoverable, and present a significant security risk. Systems support authenticator management by organization-defined settings and restrictions for various authenticator characteristics including minimum password length, validation time window for time synchronous one-time tokens, and number of allowed rejections during the verification stage of biometric authentication. Authenticator management includes issuing and revoking, when no longer needed, authenticators for temporary access such as that required for remote maintenance. Device authenticators include certificates and passwords. [SP 800-63-3] provides guidance on digital identities.

Framework
NIST SP 800-171 Rev 2
Family
Identification and Authentication
Requirement Type
basic

Related Frameworks

96 paths across 2 frameworks
NIST 800-533 mappings
IA-2
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
IA-3
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
IA-5
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI31 mappings
CCI-000176
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000179
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000180
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000181
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000182
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000183
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000184
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000764
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000777
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000778
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001544
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001610
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001958
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001980
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001981
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001982
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001983
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001984
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001985
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001986
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001987
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001988
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001989
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001990
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002042
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002365
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002366
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004053
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004054
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004055
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004056
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

461 STIGs reach this control through 149 CCIs via 800-53 controls IA-2, IA-3, IA-5. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

9 STIGs
Show 1 more STIG in this category →

Operating System — Server

49 STIGs
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-1751 of 448 findings match
Show 41 more STIGs in this category →
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-0632 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-1632 of 283 findings match
Amazon Linux 2023 Security Technical Implementation Guide
V1R32026-02-2731 of 187 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-1330 of 375 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-1920 of 103 findings match
Solaris 11 SPARC Security Technical Implementation Guide
V3R52026-02-1912 of 217 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-1912 of 216 findings match

Operating System — Mainframe

110 STIGs
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-0934 of 230 findings match
IBM z/OS TSS Security Technical Implementation Guide
92025-06-2434 of 231 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-1033 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-0533 of 193 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-0932 of 225 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-0929 of 222 findings match
Show 102 more STIGs in this category →
CA IDMS Security Technical Implementation Guide
V2R12024-09-133 of 74 findings match

Operating System — Mobile

36 STIGs
Show 28 more STIGs in this category →

Network Device

121 STIGs
AAA Services Security Requirements Guide
V2R22024-12-0427 of 77 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-1923 of 119 findings match
Domain Name System (DNS) Security Requirements Guide
42024-07-0223 of 118 findings match
Network Device Management Security Requirements Guide
V5R32025-02-1122 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-1022 of 105 findings match
Show 113 more STIGs in this category →
Riverbed NetIM OS Security Technical Implementation Guide
V1R12025-10-0213 of 154 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-1512 of 160 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-1111 of 53 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-0810 of 47 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-229 of 41 findings match
BIND 9.x Security Technical Implementation Guide
V3R22026-02-257 of 73 findings match
BIND 9.x Security Technical Implementation Guide
22024-02-157 of 70 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-077 of 32 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-115 of 26 findings match
Cisco ISE NAC Security Technical Implementation Guide
V2R32025-12-105 of 30 findings match
RUCKUS ICX NDM Security Technical Implementation Guide
V1R12025-05-283 of 25 findings match
Layer 2 Switch Security Requirements Guide
V3R42026-02-122 of 36 findings match
Layer 2 Switch Security Requirements Guide
32025-03-052 of 28 findings match
Router Security Requirements Guide
V5R22025-09-102 of 123 findings match
Router Security Requirements Guide
52024-05-282 of 108 findings match
SEL-2740S L2S Security Technical Implementation Guide
V1R12019-05-062 of 13 findings match
SEL-2740S NDM Security Technical Implementation Guide
V1R12019-05-061 of 13 findings match

Database

25 STIGs
Database Security Requirements Guide
V4R52026-02-2619 of 142 findings match
Database Security Requirements Guide
42024-12-0419 of 142 findings match
Show 17 more STIGs in this category →

Web / Application Server

31 STIGs
Application Server Security Requirements Guide
V4R42025-09-1017 of 137 findings match
Application Server Security Requirements Guide
42025-02-1117 of 128 findings match
Web Server Security Requirements Guide
V4R42025-09-1016 of 126 findings match
Web Server Security Requirements Guide
42025-02-1216 of 124 findings match
Show 23 more STIGs in this category →

Virtualization / Container

30 STIGs
Container Platform Security Requirements Guide
V2R42025-09-1037 of 188 findings match
Container Platform Security Requirements Guide
22025-05-1537 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-0634 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-1034 of 198 findings match
Show 22 more STIGs in this category →
Kubernetes Security Technical Implementation Guide
V2R62026-02-122 of 92 findings match

Cloud / Identity Service

6 STIGs

Endpoint Security Management

27 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-1231 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-0431 of 125 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-0410 of 55 findings match
Show 19 more STIGs in this category →
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-147 of 98 findings match
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-206 of 34 findings match
BlackBerry UEM Security Technical Implementation Guide
V2R12020-12-041 of 16 findings match

Productivity Application

13 STIGs

Uncategorized

4 STIGs