id: "IA-03(01)" title: "Cryptographic Bidirectional Authentication" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-03.01" priority: "P1" implementation_level: "system" parent: "IA-03" enhancement: True


Statement

Authenticate {{ insert: param, ia-03.01_odp.01 }} before establishing {{ insert: param, ia-03.01_odp.02 }} connection using bidirectional authentication that is cryptographically based.

Guidance

A local connection is a connection with a device that communicates without the use of a network. A network connection is a connection with a device that communicates through a network. A remote connection is a connection with a device that communicates through an external network. Bidirectional authentication provides stronger protection to validate the identity of other devices for connections that are of greater risk.

Assessment Objective

{{ insert: param, ia-03.01_odp.01 }} are authenticated before establishing {{ insert: param, ia-03.01_odp.02 }} connection using bidirectional authentication that is cryptographically based.

Identification and authentication policy

system security plan

procedures addressing device identification and authentication

system design documentation

list of devices requiring unique identification and authentication

device connection reports

system configuration settings and associated documentation

other relevant documents or records

Organizational personnel with operational responsibilities for device identification and authentication

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms supporting and/or implementing device authentication capability

cryptographically based bidirectional authentication mechanisms