id: "IA-05(07)" title: "No Embedded Unencrypted Static Authenticators" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-05.07" priority: "P1" implementation_level: "organization" parent: "IA-05" enhancement: True
Statement
Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.
Guidance
In addition to applications, other forms of static storage include access scripts and function keys. Organizations exercise caution when determining whether embedded or stored authenticators are in encrypted or unencrypted form. If authenticators are used in the manner stored, then those representations are considered unencrypted authenticators.
Assessment Objective
unencrypted static authenticators are not embedded in applications or other forms of static storage.
Identification and authentication policy
system security plan
procedures addressing authenticator management
system design documentation
system configuration settings and associated documentation
logical access scripts
application code reviews for detecting unencrypted static authenticators
other relevant documents or records
Organizational personnel with authenticator management responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
Mechanisms supporting and/or implementing authenticator management capability
mechanisms implementing authentication in applications