id: "IA-11" title: "Re-authentication" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-11" priority: "P1" implementation_level: "system"


Statement

Require users to re-authenticate when {{ insert: param, ia-11_odp }}.

Guidance

In addition to the re-authentication requirements associated with device locks, organizations may require re-authentication of individuals in certain situations, including when roles, authenticators or credentials change, when security categories of systems change, when the execution of privileged functions occurs, after a fixed time period, or periodically.

Assessment Objective

users are required to re-authenticate when {{ insert: param, ia-11_odp }}.

Identification and authentication policy

procedures addressing user and device re-authentication

system security plan

system design documentation

system configuration settings and associated documentation

list of circumstances or situations requiring re-authentication

system audit records

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

organizational personnel with identification and authentication responsibilities

Mechanisms supporting and/or implementing identification and authentication capabilities