id: "IA-05(07)" title: "No Embedded Unencrypted Static Authenticators" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-05.07" priority: "P1" implementation_level: "organization" parent: "IA-05" enhancement: True


Statement

Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.

Guidance

In addition to applications, other forms of static storage include access scripts and function keys. Organizations exercise caution when determining whether embedded or stored authenticators are in encrypted or unencrypted form. If authenticators are used in the manner stored, then those representations are considered unencrypted authenticators.

Assessment Objective

unencrypted static authenticators are not embedded in applications or other forms of static storage.

Identification and authentication policy

system security plan

procedures addressing authenticator management

system design documentation

system configuration settings and associated documentation

logical access scripts

application code reviews for detecting unencrypted static authenticators

other relevant documents or records

Organizational personnel with authenticator management responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms supporting and/or implementing authenticator management capability

mechanisms implementing authentication in applications