id: "IA-05(08)" title: "Multiple System Accounts" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-05.08" priority: "P1" implementation_level: "organization" parent: "IA-05" enhancement: True
Statement
Implement {{ insert: param, ia-05.08_odp }} to manage the risk of compromise due to individuals having accounts on multiple systems.
Guidance
When individuals have accounts on multiple systems and use the same authenticators such as passwords, there is the risk that a compromise of one account may lead to the compromise of other accounts. Alternative approaches include having different authenticators (passwords) on all systems, employing a single sign-on or federation mechanism, or using some form of one-time passwords on all systems. Organizations can also use rules of behavior (see PL-4 ) and access agreements (see PS-6 ) to mitigate the risk of multiple system accounts.
Assessment Objective
{{ insert: param, ia-05.08_odp }} are implemented to manage the risk of compromise due to individuals having accounts on multiple systems.
Identification and authentication policy
procedures addressing authenticator management
system security plan
list of individuals having accounts on multiple systems
list of security safeguards intended to manage risk of compromise due to individuals having accounts on multiple systems
other relevant documents or records
Organizational personnel with authenticator management responsibilities
organizational personnel with information security responsibilities
system/network administrators
Mechanisms supporting and/or implementing safeguards for authenticator management