NIST 800-171 v2

110 security requirements available

3.5.3Derived Requirement

Identification and Authentication

Security Requirement

Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.[24] [25].

Discussion

Multifactor authentication requires the use of two or more different factors to authenticate. The factors are defined as something you know (e.g., password, personal identification number [PIN]); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). Multifactor authentication solutions that feature physical authenticators include hardware authenticators providing time-based or challenge-response authenticators and smart cards. In addition to authenticating users at the system level (i.e., at logon), organizations may also employ authentication mechanisms at the application level, when necessary, to provide increased information security. Access to organizational systems is defined as local access or network access. Local access is any access to organizational systems by users (or processes acting on behalf of users) where such access is obtained by direct connections without the use of networks. Network access is access to systems by users (or processes acting on behalf of users) where such access is obtained through network connections (i.e., nonlocal accesses). Remote access is a type of network access that involves communication through external networks. The use of encrypted virtual private networks for connections between organization-controlled and non-organization controlled endpoints may be treated as internal networks with regard to protecting the confidentiality of information. [SP 800-63-3] provides guidance on digital identities. [24] Multifactor authentication requires two or more different factors to achieve authentication. The factors include: something you know (e.g., password/PIN); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). The requirement for multifactor authentication should not be interpreted as requiring federal Personal Identity Verification (PIV) card or Department of Defense Common Access Card (CAC)-like solutions. A variety of multifactor solutions (including those with replay resistance) using tokens and biometrics are commercially available. Such solutions may employ hard tokens (e.g., smartcards, key fobs, or dongles) or soft tokens to store user credentials. [25] Local access is any access to a system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network. Network access is any access to a system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet).

Framework
NIST SP 800-171 Rev 2
Family
Identification and Authentication
Requirement Type
derived

Related Frameworks

6 paths across 2 frameworks
NIST 800-533 mappings
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI3 mappings
CCI-000765
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000766
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000767
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

348 STIGs reach this control through 33 CCIs via 800-53 control IA-2. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

9 STIGs
Show 1 more STIG in this category →

Operating System — Server

44 STIGs
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-1715 of 448 findings match
Amazon Linux 2023 Security Technical Implementation Guide
V1R32026-02-2713 of 187 findings match
Show 36 more STIGs in this category →
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-067 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-167 of 283 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-195 of 103 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-135 of 375 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-192 of 216 findings match

Operating System — Mainframe

109 STIGs
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-0922 of 230 findings match
IBM z/OS TSS Security Technical Implementation Guide
92025-06-2422 of 231 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-0918 of 222 findings match
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-0917 of 225 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-1011 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-0511 of 193 findings match
Show 101 more STIGs in this category →
CA IDMS Security Technical Implementation Guide
V2R12024-09-131 of 74 findings match

Operating System — Mobile

36 STIGs
Show 28 more STIGs in this category →

Network Device

57 STIGs
Application Layer Gateway Security Requirements Guide
V2R32025-09-157 of 160 findings match
Network Device Management Security Requirements Guide
V5R32025-02-116 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-106 of 105 findings match
Show 49 more STIGs in this category →
AAA Services Security Requirements Guide
V2R22024-12-044 of 77 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-223 of 41 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-193 of 119 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-112 of 53 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-072 of 32 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-111 of 26 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-081 of 47 findings match

Database

21 STIGs
Database Security Requirements Guide
V4R52026-02-264 of 142 findings match
Database Security Requirements Guide
42024-12-044 of 142 findings match
Show 13 more STIGs in this category →

Web / Application Server

20 STIGs
Application Server Security Requirements Guide
V4R42025-09-109 of 137 findings match
Application Server Security Requirements Guide
42025-02-119 of 128 findings match
Show 12 more STIGs in this category →
Web Server Security Requirements Guide
V4R42025-09-103 of 126 findings match
Web Server Security Requirements Guide
42025-02-123 of 124 findings match

Virtualization / Container

19 STIGs
Container Platform Security Requirements Guide
V2R42025-09-1015 of 188 findings match
Container Platform Security Requirements Guide
22025-05-1515 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-0612 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-1012 of 198 findings match
Show 11 more STIGs in this category →

Cloud / Identity Service

5 STIGs

Endpoint Security Management

22 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-1210 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-0410 of 125 findings match
Show 14 more STIGs in this category →
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-144 of 98 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-042 of 55 findings match
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-202 of 34 findings match
BlackBerry UEM Security Technical Implementation Guide
V2R12020-12-041 of 16 findings match

Productivity Application

4 STIGs

Uncategorized

2 STIGs