id: "IA-02(08)" title: "Access to Accounts — Replay Resistant" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-02.08" priority: "P1" implementation_level: "system" parent: "IA-02" enhancement: True
Statement
Implement replay-resistant authentication mechanisms for access to {{ insert: param, ia-02.08_odp }}.
Guidance
Authentication processes resist replay attacks if it is impractical to achieve successful authentications by replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges such as time synchronous or cryptographic authenticators.
Assessment Objective
replay-resistant authentication mechanisms for access to {{ insert: param, ia-02.08_odp }} are implemented.
Identification and authentication policy
system security plan
procedures addressing user identification and authentication
system design documentation
system configuration settings and associated documentation
system audit records
list of privileged system accounts
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with account management responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
Mechanisms supporting and/or implementing identification and authentication capabilities
Mechanisms supporting and/or implementing replay-resistant authentication mechanisms