💼 IA-5(1) Authenticator Management | Password-based Authentication
- ID: /frameworks/nist-sp-800-53-r5/ia/05/01
Description
For password-based authentication:
(a) Maintain a list of commonly-used, expected, or compromised passwords and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised directly or indirectly;
(b) Verify, when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5(1)(a);
(c) Transmit passwords only over cryptographically-protected channels;
(d) Store passwords using an approved salted key derivation function, preferably using a keyed hash;
(e) Require immediate selection of a new password upon account recovery;
(f) Allow user selection of long passwords and passphrases, including spaces and all printable characters;
(g) Employ automated tools to assist the user in selecting strong password authenticators; and
(h) Enforce the following composition and complexity rules: [Assignment: organization-defined composition and complexity rules].
Similar
- Sections
- /frameworks/aws-fsbp-v1.0.0/api-gateway/02
- /frameworks/aws-fsbp-v1.0.0/cloudfront/03
- /frameworks/aws-fsbp-v1.0.0/cloudfront/07
- /frameworks/aws-fsbp-v1.0.0/cloudfront/08
- /frameworks/aws-fsbp-v1.0.0/cloudfront/10
- /frameworks/aws-fsbp-v1.0.0/elasticache/05
- /frameworks/aws-fsbp-v1.0.0/elb/01
- /frameworks/aws-fsbp-v1.0.0/elb/02
- /frameworks/aws-fsbp-v1.0.0/elb/03
- /frameworks/aws-fsbp-v1.0.0/elb/08
- /frameworks/aws-fsbp-v1.0.0/elb/17
- /frameworks/aws-fsbp-v1.0.0/es/08
- /frameworks/aws-fsbp-v1.0.0/iam/07
- /frameworks/aws-fsbp-v1.0.0/opensearch/08
- /frameworks/aws-fsbp-v1.0.0/s3/05
 
- Internal
Similar Sections (Take Policies From)
Similar Sections (Give Policies To)
Sub Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance | 
|---|
Policies (8)