Back to catalog
IAC-10.10IACIdentification & Authentication
Expiration of Cached Authenticators
Description
Automated mechanisms exist to prohibit the use of cached authenticators after organization-defined time period.
Cross-Mappings
102 paths across 3 frameworks
Cross-Mappings
NIST 800-531 mapping
IA-5(13)
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI2 mappings
CCI-002006
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002007
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG69 mappings
SV-104247r1_ruleSymantec ProxySG must prohibit the use of cached authenticators after 300 seconds at a minimum.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R3 · disa_xccdf · related
SV-202115r961521_ruleThe network device must prohibit the use of cached authenticators after an organization-defined time period.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V5R3 · disa_xccdf · related
SV-203733r958828_ruleThe operating system must prohibit the use of cached authenticators after one day.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-204804r961521_ruleThe application server must prohibit the use of cached authenticators after an organization-defined time period.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205000r831377_ruleThe ALG must prohibit the use of cached authenticators after an organization-defined time period.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-205573r961521_ruleThe Mainframe Product must prohibit the use of cached authenticators after one hour.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-206601r961521_ruleThe DBMS must prohibit the use of cached authenticators after an organization-defined time period.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-207486r958828_ruleThe VMM must prohibit the use of cached authenticators after one day.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-215205r958828_ruleIf LDAP authentication is required, AIX must setup LDAP client to refresh user and group caches less than a day.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-217166r958828_ruleIf Network Security Services (NSS) is being used by the SUSE operating system it must prohibit the use of cached authentications after one day.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
+59 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer