id: "IA-11" title: "Re-authentication" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-11" priority: "P1" implementation_level: "system"
Statement
Require users to re-authenticate when {{ insert: param, ia-11_odp }}.
Guidance
In addition to the re-authentication requirements associated with device locks, organizations may require re-authentication of individuals in certain situations, including when roles, authenticators or credentials change, when security categories of systems change, when the execution of privileged functions occurs, after a fixed time period, or periodically.
Assessment Objective
users are required to re-authenticate when {{ insert: param, ia-11_odp }}.
Identification and authentication policy
procedures addressing user and device re-authentication
system security plan
system design documentation
system configuration settings and associated documentation
list of circumstances or situations requiring re-authentication
system audit records
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
organizational personnel with identification and authentication responsibilities
Mechanisms supporting and/or implementing identification and authentication capabilities