πΌ IA-5(1) Authenticator Management | Password-based Authentication
- Contextual name: πΌ IA-5(1) Authenticator Management | Password-based Authentication
- ID:
/frameworks/nist-sp-800-53-r5/ia/05/01
- Located in: πΌ IA-5 Authenticator Management
Descriptionβ
For password-based authentication:
(a) Maintain a list of commonly-used, expected, or compromised passwords and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised directly or indirectly;
(b) Verify, when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5(1)(a);
(c) Transmit passwords only over cryptographically-protected channels;
(d) Store passwords using an approved salted key derivation function, preferably using a keyed hash;
(e) Require immediate selection of a new password upon account recovery;
(f) Allow user selection of long passwords and passphrases, including spaces and all printable characters;
(g) Employ automated tools to assist the user in selecting strong password authenticators; and
(h) Enforce the following composition and complexity rules: [Assignment: organization-defined composition and complexity rules].
Similarβ
- Sections
/frameworks/aws-fsbp-v1.0.0/api-gateway/02
/frameworks/aws-fsbp-v1.0.0/cloudfront/03
/frameworks/aws-fsbp-v1.0.0/cloudfront/07
/frameworks/aws-fsbp-v1.0.0/cloudfront/08
/frameworks/aws-fsbp-v1.0.0/cloudfront/10
/frameworks/aws-fsbp-v1.0.0/elasticache/05
/frameworks/aws-fsbp-v1.0.0/elb/01
/frameworks/aws-fsbp-v1.0.0/elb/02
/frameworks/aws-fsbp-v1.0.0/elb/03
/frameworks/aws-fsbp-v1.0.0/elb/08
/frameworks/aws-fsbp-v1.0.0/elb/17
/frameworks/aws-fsbp-v1.0.0/es/08
/frameworks/aws-fsbp-v1.0.0/iam/07
/frameworks/aws-fsbp-v1.0.0/opensearch/08
/frameworks/aws-fsbp-v1.0.0/s3/05
- Internal
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (4)β