id: "IA-02(05)" title: "Individual Authentication with Group Authentication" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-02.05" priority: "P1" implementation_level: "system" parent: "IA-02" enhancement: True


Statement

When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.

Guidance

Individual authentication prior to shared group authentication mitigates the risk of using group accounts or authenticators.

Assessment Objective

users are required to be individually authenticated before granting access to the shared accounts or resources when shared accounts or authenticators are employed.

Identification and authentication policy

system security plan

procedures addressing user identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

list of system accounts

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with account management responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms supporting and/or implementing an authentication capability for group accounts