id: "IA-02(05)" title: "Individual Authentication with Group Authentication" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-02.05" priority: "P1" implementation_level: "system" parent: "IA-02" enhancement: True
Statement
When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.
Guidance
Individual authentication prior to shared group authentication mitigates the risk of using group accounts or authenticators.
Assessment Objective
users are required to be individually authenticated before granting access to the shared accounts or resources when shared accounts or authenticators are employed.
Identification and authentication policy
system security plan
procedures addressing user identification and authentication
system design documentation
system configuration settings and associated documentation
system audit records
list of system accounts
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with account management responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
Mechanisms supporting and/or implementing an authentication capability for group accounts