id: "IA-05(13)" title: "Expiration of Cached Authenticators" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-05.13" priority: "P1" implementation_level: "system" parent: "IA-05" enhancement: True


Statement

Prohibit the use of cached authenticators after {{ insert: param, ia-05.13_odp }}.

Guidance

Cached authenticators are used to authenticate to the local machine when the network is not available. If cached authentication information is out of date, the validity of the authentication information may be questionable.

Assessment Objective

the use of cached authenticators is prohibited after {{ insert: param, ia-05.13_odp }}.

Identification and authentication policy

procedures addressing authenticator management

system security plan

system design documentation

system configuration settings and associated documentation

system audit records

other relevant documents or records

Organizational personnel with authenticator management responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms supporting and/or implementing authenticator management capability