San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

IA-5 Authenticator Management

Identification and Authentication family. 101 Control Correlation Identifiers map to this control, and 113 STIG rules implement those CCIs.

15CAT I (high)
98CAT II (medium)
0CAT III (low)
101CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to IA-5
Red Hat Enterprise Linux 9V227
Red Hat Enterprise Linux 8V221
Microsoft Windows Server 2019V318
Microsoft Windows Server 2022V218
Microsoft Windows 10V314
Microsoft Windows 11V212
KubernetesV22
Google Chrome Current WindowsV21

Control Correlation Identifiers mapped to IA-5

CCIDefinitionRev
CCI-000176Manage system authenticators by establishing initial authenticator content for authenticators issued by the organization.5, 4
CCI-000179The organization manages information system authenticators by establishing minimum lifetime restrictions for authenticators.4
CCI-000180The organization manages information system authenticators by establishing maximum lifetime restrictions for authenticators.4
CCI-000181The organization manages information system authenticators by establishing reuse conditions for authenticators.4
CCI-000182Manage system authenticators by changing or refreshing authenticators in accordance with the organization-defined time period by authenticator type or when organization-defined events occur.5, 4
CCI-000183Manage system authenticators by protecting authenticator content from unauthorized disclosure.5, 4
CCI-000184Manage system authenticators by requiring individuals to take, and having devices implement, specific security controls to protect authenticators.5, 4
CCI-000185For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.5, 4
CCI-000186For public key-based authentication, enforce authorized access to the corresponding private key.5, 4
CCI-000187For public key-based authentication, map the authenticated identity to the account of the individual or group.5, 4
CCI-000192The information system enforces password complexity by the minimum number of upper case characters used.4
CCI-000193The information system enforces password complexity by the minimum number of lower case characters used.4
CCI-000194The information system enforces password complexity by the minimum number of numeric characters used.4
CCI-000195The information system, for password-based authentication, when new passwords are created, enforces that at least an organization-defined number of characters are changed.4
CCI-000196The information system, for password-based authentication, stores only cryptographically-protected passwords.4
CCI-000197For password-based authentication, transmit passwords only over cryptographically-protected channels.5, 4
CCI-000198The information system enforces minimum password lifetime restrictions.4
CCI-000199The information system enforces maximum password lifetime restrictions.4
CCI-000200The information system prohibits password reuse for the organization-defined number of generations.4
CCI-000201Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.5, 4
CCI-000202The organization ensures unencrypted static authenticators are not embedded in access scripts.4
CCI-000203The organization ensures unencrypted static authenticators are not stored on function keys.4
CCI-000204Defines the security controls required to manage the risk of compromise due to individuals having accounts on multiple systems.5, 4
CCI-000205The information system enforces minimum password length.4
CCI-001544Manage system authenticators by ensuring that authenticators have sufficient strength of mechanism for their intended use.5, 4
CCI-001610Defines the time-period (by authenticator type) for changing/refreshing authenticators.5, 4
CCI-001611The organization defines the minimum number of special characters for password complexity enforcement.4
CCI-001612The organization defines the minimum number of upper case characters for password complexity enforcement.4
CCI-001613The organization defines the minimum number of lower case characters for password complexity enforcement.4
CCI-001614The organization defines the minimum number of numeric characters for password complexity enforcement.4
CCI-001615The organization defines the minimum number of characters that are changed when new passwords are created.4
CCI-001616The organization defines minimum password lifetime restrictions.4
CCI-001617The organization defines maximum password lifetime restrictions.4
CCI-001618The organization defines the number of generations for which password reuse is prohibited.4
CCI-001619The information system enforces password complexity by the minimum number of special characters used.4
CCI-001621Implement organization-defined security controls to manage the risk of compromise due to individuals having accounts on multiple systems.5, 4
CCI-001980Manage system authenticators by verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator.5, 4
CCI-001981Manage system authenticators by establishing administrative procedures for initial authenticator distribution.5, 4
CCI-001982The organization manages information system authenticators by establishing administrative procedures for lost/compromised authenticators.4
CCI-001983The organization manages information system authenticators by establishing administrative procedures for damaged authenticators.4
CCI-001984Manage system authenticators by establishing administrative procedures for revoking authenticators.5, 4
CCI-001985Manage system authenticators by implementing administrative procedures for initial authenticator distribution.5, 4
CCI-001986The organization manages information system authenticators by implementing administrative procedures for lost/compromised authenticators.4
CCI-001987The organization manages information system authenticators by implementing administrative procedures for damaged authenticators.4
CCI-001988Manage system authenticators by implementing administrative procedures for revoking authenticators.5, 4
CCI-001989The organization manages information system authenticators by changing default content of authenticators prior to information system installation.4
CCI-001990Manage system authenticators by changing authenticators for group or role accounts when membership to those accounts changes.5, 4
CCI-001991The information system, for PKI-based authentication, implements a local cache of revocation data to support path discovery and validation in case of inability to access revocation information via the network.4
CCI-001992The organization defines the personnel or roles responsible for authorizing the organization's registration authority accountable for the authenticator registration process.4
CCI-001993The organization defines the registration authority accountable for the authenticator registration process.4
CCI-001994The organization defines the types of and/or specific authenticators that are subject to the authenticator registration process.4
CCI-001995The organization requires that the registration process, to receive organization-defined types of and/or specific authenticators, be conducted in person, or by a trusted third-party, before an organization-defined registration authority with authorization by organization-defined personnel or roles.4
CCI-001996The organization defines the requirements required by the automated tools to determine if password authenticators are sufficiently strong.4
CCI-001997The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy organization-defined requirements.4
CCI-001998Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and installation.5, 4
CCI-001999The organization defines the external organizations to be coordinated with for cross-organization management of credentials.4
CCI-002000The organization coordinates with organization-defined external organizations for cross-organization management of credentials.4
CCI-002001Bind identities and authenticators dynamically using organization-defined binding rules.5, 4
CCI-002002The organization defines the token quality requirements to be employed by the information system mechanisms for token-based authentication.4
CCI-002003The information system, for token-based authentication, employs mechanisms that satisfy organization-defined token quality requirements.4
CCI-002004Defines the biometric quality requirements to be employed by the mechanisms for biometric-based authentication.5, 4
CCI-002005For biometric-based authentication, employ mechanisms that satisfy organization-defined biometric quality requirements.5, 4
CCI-002006Defines the time period after which the use of cached authenticators is prohibited.5, 4
CCI-002007Prohibit the use of cached authenticators after an organization-defined time period.5, 4
CCI-002008For PKI-based authentication, employs an organization-wide methodology for managing the content of PKI trust stores installed across all platforms including networks, operating systems, browsers, and applications.5, 4
CCI-002041The information system allows the use of a temporary password for system logons with an immediate change to a permanent password.4
CCI-002042Manage system authenticators by protecting authenticator content from unauthorized modification.5, 4
CCI-002043The organization uses only FICAM-approved path discovery and validation products and services.4
CCI-002365The organization manages information system authenticators by requiring individuals to take specific security safeguards to protect authenticators.4
CCI-002366The organization manages information system authenticators by having devices implement specific security safeguards to protect authenticators.4
CCI-002367The organization ensures unencrypted static authenticators are not embedded in applications.4
CCI-004053Manage system authenticators by establishing administrative procedures for lost/compromised or damaged authenticators.5
CCI-004054Manage system authenticators by implementing administrative procedures for lost/compromised or damaged authenticators.5
CCI-004055Manage system authenticators by changing default authenticators prior to first use.5
CCI-004056Defines the events for when to change or refresh authenticators.5
CCI-004057Defines the frequency for updating commonly used, expected, or compromised passwords, when they are suspected of being compromised directly or indirectly.5
CCI-004058For password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.5
CCI-004059For password-based authentication, update the list of passwords on an organization-defined frequency.5
CCI-004060For password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.5
CCI-004061For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).5
CCI-004062For password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.5
CCI-004063For password-based authentication, require immediate selection of a new password upon account recovery.5
CCI-004064For password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.5
CCI-004065For password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.5
CCI-004066For password-based authentication, enforce organization-defined composition and complexity rules.5
CCI-004067Defines the composition and complexity rules to be enforced.5
CCI-004068For public key-based authentication, implement a local cache of revocation data to support path discovery and validation.5
CCI-004069Ensure that the unencrypted static authenticators are not embedded in applications or other forms of static storage.5
CCI-004070Use organization-defined external organizations to federate credentials.5
CCI-004071Defines the external organizations used to federate credentials.5
CCI-004072Defines the binding rules for binding identities and authenticators.5
CCI-004073Use only General Services Administration-approved and validated products and services for identity, credential, and access management.5
CCI-004074Require that the issuance of organization-defined types of and/or specific authenticators be conducted in person or by a trusted external party before the organization-defined registration authority with authorization by organization-defined personnel or roles.5
CCI-004075Defines types of and/or specific authenticators to be conducted in person or by a trusted external party before the organization-defined registration authority.5
CCI-004076Defines the registration authority who conducts the issuance of organization-defined types of and/or specific authenticators.5
CCI-004077Defines the personnel or roles who authorize the issuance of organization-defined types of and/or specific authenticators.5
CCI-004078Employ presentation attack detection mechanisms for biometric-based authentication.5
CCI-004079Employ organization-defined password managers to generate and manage passwords.5
CCI-004080Defines the password managers employed to generate and manage passwords.5
CCI-004081Protect the passwords using organization-defined controls.5
CCI-004082Defines the controls for protecting the passwords.5

STIG rules that implement IA-5

RuleSTIG IDSeverityRequirement
V-205645WN19-DC-000280mediumWindows Server 2019 domain controllers must have a PKI server certificate.
V-205646WN19-DC-000290highWindows Server 2019 domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA).
V-205647WN19-DC-000300highWindows Server 2019 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).
V-205648WN19-PK-000010mediumWindows Server 2019 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.
V-205649WN19-PK-000020mediumWindows Server 2019 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.
V-205650WN19-PK-000030mediumWindows Server 2019 must have the US DoD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.
V-205651WN19-SO-000350mediumWindows Server 2019 users must be required to enter a password to access private keys stored on the computer.
V-205652WN19-AC-000080mediumWindows Server 2019 must have the built-in Windows password complexity policy enabled.
V-205653WN19-AC-000090highWindows Server 2019 reversible password encryption must be disabled.
V-205654WN19-SO-000300highWindows Server 2019 must be configured to prevent the storage of the LAN Manager hash of passwords.
V-205655WN19-SO-000180mediumWindows Server 2019 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers.
V-205656WN19-AC-000060mediumWindows Server 2019 minimum password age must be configured to at least one day.
V-205657WN19-00-000020mediumWindows Server 2019 passwords for the built-in Administrator account must be changed at least every 60 days.
V-205658WN19-00-000210mediumWindows Server 2019 passwords must be configured to expire.
V-205659WN19-AC-000050mediumWindows Server 2019 maximum password age must be configured to 60 days or less.
V-205660WN19-AC-000040mediumWindows Server 2019 password history must be configured to 24 passwords remembered.
V-205661WN19-00-000050mediumWindows Server 2019 manually managed application account passwords must be at least 14 characters in length.
V-205662WN19-AC-000070mediumWindows Server 2019 minimum password length must be configured to 14 characters.
V-220716WN10-00-000090mediumAccounts must be configured to require password expiration.
V-220742WN10-AC-000020mediumThe password history must be configured to 24 passwords remembered.
V-220743WN10-AC-000025mediumThe maximum password age must be configured to 60 days or less.
V-220744WN10-AC-000030mediumThe minimum password age must be configured to at least 1 day.
V-220745WN10-AC-000035mediumPasswords must, at a minimum, be 14 characters.
V-220746WN10-AC-000040mediumThe built-in Microsoft password complexity filter must be enabled.
V-220747WN10-AC-000045highReversible password encryption must be disabled.
V-220903WN10-PK-000005mediumThe DoD Root CA certificates must be installed in the Trusted Root Store.
V-220904WN10-PK-000010mediumThe External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.
V-220905WN10-PK-000015mediumThe DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
V-220906WN10-PK-000020mediumThe US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
V-220926WN10-SO-000110mediumUnencrypted passwords must not be sent to third-party SMB Servers.
V-220937WN10-SO-000195highThe system must be configured to prevent the storage of the LAN Manager hash of passwords.
V-220952WN10-SO-000280mediumPasswords for enabled local Administrator accounts must be changed at least every 60 days.
V-221579DTBC-0037mediumOnline revocation checks must be performed.
V-230229RHEL-08-010090mediumRHEL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
V-230230RHEL-08-010100mediumRHEL 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.
V-230231RHEL-08-010110mediumRHEL 8 must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.
V-230232RHEL-08-010120mediumRHEL 8 must employ FIPS 140-2 approved cryptographic hashing algorithms for all stored passwords.
V-230233RHEL-08-010130mediumThe RHEL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.
V-230355RHEL-08-020090mediumRHEL 8 must map the authenticated identity to the user or group account for PKI-based authentication.
V-230357RHEL-08-020110mediumRHEL 8 must enforce password complexity by requiring that at least one uppercase character be used.
V-230358RHEL-08-020120mediumRHEL 8 must enforce password complexity by requiring that at least one lower-case character be used.
V-230359RHEL-08-020130mediumRHEL 8 must enforce password complexity by requiring that at least one numeric character be used.
V-230360RHEL-08-020140mediumRHEL 8 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
V-230361RHEL-08-020150mediumRHEL 8 must require the maximum number of repeating characters be limited to three when passwords are changed.
V-230362RHEL-08-020160mediumRHEL 8 must require the change of at least four character classes when passwords are changed.
V-230363RHEL-08-020170mediumRHEL 8 must require the change of at least 8 characters when passwords are changed.
V-230364RHEL-08-020180mediumRHEL 8 passwords must have a 24 hours/1 day minimum password lifetime restriction in /etc/shadow.
V-230365RHEL-08-020190mediumRHEL 8 passwords for new users or password changes must have a 24 hours/1 day minimum password lifetime restriction in /etc/login.defs.
V-230366RHEL-08-020200mediumRHEL 8 user account passwords must have a 60-day maximum password lifetime restriction.
V-230367RHEL-08-020210mediumRHEL 8 user account passwords must be configured so that existing passwords are restricted to a 60-day maximum lifetime.
V-230369RHEL-08-020230mediumRHEL 8 passwords must have a minimum of 15 characters.
V-230370RHEL-08-020231mediumRHEL 8 passwords for new users must have a minimum of 15 characters.
V-230375RHEL-08-020280mediumAll RHEL 8 passwords must contain at least one special character.
V-230376RHEL-08-020290mediumRHEL 8 must prohibit the use of cached authentications after one day.
V-242415CNTR-K8-001160highSecrets in Kubernetes must not be stored as environment variables.
V-253273WN11-00-000090mediumAccounts must be configured to require password expiration.
V-253300WN11-AC-000020mediumThe password history must be configured to 24 passwords remembered.
V-253301WN11-AC-000025mediumThe maximum password age must be configured to 60 days or less.
V-253302WN11-AC-000030mediumThe minimum password age must be configured to at least 1 day.
V-253303WN11-AC-000035mediumPasswords must, at a minimum, be 14 characters.
V-253304WN11-AC-000040mediumThe built-in Microsoft password complexity filter must be enabled.
V-253305WN11-AC-000045highReversible password encryption must be disabled.
V-253427WN11-PK-000005mediumThe DoD Root CA certificates must be installed in the Trusted Root Store.
V-253428WN11-PK-000010mediumThe External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.
V-253450WN11-SO-000110mediumUnencrypted passwords must not be sent to third-party SMB Servers.
V-253461WN11-SO-000195highThe system must be configured to prevent the storage of the LAN Manager hash of passwords.
V-253476WN11-SO-000280mediumPasswords for enabled local Administrator accounts must be changed at least every 60 days.
V-254239WN22-00-000020mediumWindows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days.
V-254242WN22-00-000050mediumWindows Server 2022 manually managed application account passwords must be at least 14 characters in length.
V-254258WN22-00-000210mediumWindows Server 2022 passwords must be configured to expire.
V-254288WN22-AC-000040mediumWindows Server 2022 password history must be configured to 24 passwords remembered.
V-254289WN22-AC-000050mediumWindows Server 2022 maximum password age must be configured to 60 days or less.
V-254290WN22-AC-000060mediumWindows Server 2022 minimum password age must be configured to at least one day.
V-254291WN22-AC-000070mediumWindows Server 2022 minimum password length must be configured to 14 characters.
V-254292WN22-AC-000080mediumWindows Server 2022 must have the built-in Windows password complexity policy enabled.
V-254293WN22-AC-000090highWindows Server 2022 reversible password encryption must be disabled.
V-254412WN22-DC-000280mediumWindows Server 2022 domain controllers must have a PKI server certificate.
V-254413WN22-DC-000290highWindows Server 2022 domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA).
V-254414WN22-DC-000300highWindows Server 2022 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA).
V-254442WN22-PK-000010mediumWindows Server 2022 must have the DoD Root Certificate Authority (CA) certificates installed in the Trusted Root Store.
V-254443WN22-PK-000020mediumWindows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.
V-254444WN22-PK-000030mediumWindows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.
V-254462WN22-SO-000180mediumWindows Server 2022 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers.
V-254474WN22-SO-000300highWindows Server 2022 must be configured to prevent the storage of the LAN Manager hash of passwords.
V-254479WN22-SO-000350mediumWindows Server 2022 users must be required to enter a password to access private keys stored on the computer.
V-257826RHEL-09-215015highRHEL 9 must not have a File Transfer Protocol (FTP) server package installed.
V-258041RHEL-09-411010mediumRHEL 9 user account passwords for new users or password changes must have a 60-day maximum password lifetime restriction in /etc/login.defs.
V-258042RHEL-09-411015mediumRHEL 9 user account passwords must have a 60-day maximum password lifetime restriction.
V-258091RHEL-09-611010mediumRHEL 9 must ensure the password complexity module in the system-auth file is configured for three retries or less.
V-258097RHEL-09-611040mediumRHEL 9 must ensure the password complexity module is enabled in the password-auth file.
V-258099RHEL-09-611050mediumRHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.
V-258100RHEL-09-611055mediumRHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.
V-258101RHEL-09-611060mediumRHEL 9 must enforce password complexity rules for the root account.
V-258102RHEL-09-611065mediumRHEL 9 must enforce password complexity by requiring that at least one lowercase character be used.
V-258103RHEL-09-611070mediumRHEL 9 must enforce password complexity by requiring that at least one numeric character be used.
V-258104RHEL-09-611075mediumRHEL 9 passwords for new users or password changes must have a 24 hours minimum password lifetime restriction in /etc/login.defs.
V-258105RHEL-09-611080mediumRHEL 9 passwords must have a 24 hours minimum password lifetime restriction in /etc/shadow.
V-258107RHEL-09-611090mediumRHEL 9 passwords must be created with a minimum of 15 characters.
V-258109RHEL-09-611100mediumRHEL 9 must enforce password complexity by requiring that at least one special character be used.
V-258111RHEL-09-611110mediumRHEL 9 must enforce password complexity by requiring that at least one uppercase character be used.
V-258112RHEL-09-611115mediumRHEL 9 must require the change of at least eight characters when passwords are changed.
V-258113RHEL-09-611120mediumRHEL 9 must require the maximum number of repeating characters of the same character class be limited to four when passwords are changed.
V-258114RHEL-09-611125mediumRHEL 9 must require the maximum number of repeating characters be limited to three when passwords are changed.
V-258115RHEL-09-611130mediumRHEL 9 must require the change of at least four character classes when passwords are changed.
V-258116RHEL-09-611135mediumRHEL 9 must be configured so that user and group account administration utilities are configured to store only encrypted representations of passwords.
V-258117RHEL-09-611140mediumRHEL 9 must be configured to use the shadow file to store only encrypted representations of passwords.
V-258127RHEL-09-611190mediumRHEL 9, for PKI-based authentication, must enforce authorized access to the corresponding private key.
V-258131RHEL-09-631010mediumRHEL 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
V-258132RHEL-09-631015mediumRHEL 9 must map the authenticated identity to the user or group account for PKI-based authentication.
V-258133RHEL-09-631020mediumRHEL 9 must prohibit the use of cached authenticators after one day.
V-258231RHEL-09-671015mediumRHEL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords.
V-258233RHEL-09-671025mediumRHEL 9 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-3 approved cryptographic hashing algorithm for system authentication.
V-274883CNTR-K8-001161highSensitive information must be stored using Kubernetes Secrets or an external Secret store provider.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/IA-5. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.