id: "IA-02(08)" title: "Access to Accounts — Replay Resistant" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-02.08" priority: "P1" implementation_level: "system" parent: "IA-02" enhancement: True


Statement

Implement replay-resistant authentication mechanisms for access to {{ insert: param, ia-02.08_odp }}.

Guidance

Authentication processes resist replay attacks if it is impractical to achieve successful authentications by replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges such as time synchronous or cryptographic authenticators.

Assessment Objective

replay-resistant authentication mechanisms for access to {{ insert: param, ia-02.08_odp }} are implemented.

Identification and authentication policy

system security plan

procedures addressing user identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

list of privileged system accounts

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with account management responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms supporting and/or implementing identification and authentication capabilities

Mechanisms supporting and/or implementing replay-resistant authentication mechanisms