NIST 800-53 IA-2

User Identification and Authentication

Return to master list of NIST 800-53 controls.


Automated Inspection items for NIST SP 800-53 IA-2 assessment.

Automated Inspection items are efficient enough that they can usually be part of a CA-7 Continuous Monitoring program on a daily (or in some cases hourly) basis, simultaneously meeting the requirements of RA-5 Vulnerability Scanning. While NIST 800-53 allows Continuous Monitoring results to be used for CA-2 Security Assessments and CA-4 Security Certification, a separate run using the same automated Inspection items in combination with more laborious items for CA-2 and CA-4 adds no significant burden.

Depending on FIPS 199 impact level and whether the Industrial Control Systems (ICS/SCADA) subset of 800-53 is chosen,  LJK/Security™ starter templates provide automated Inspection items as follows:

NIST SP 800-53 R2 IA-2
Description  Automated Tests
A non-plaintext password authentication mechanism is installed.
(VMS,ACMEORLGI,NOTJUST)
No Username shall have a null primary password.
(UAF,PWDNULL,PRIMAXPRIV)
(UAF,PWDNULL,PRIPROHIB)
(UAF,PWDNULL,PRIREQUIRE)
There is no Default Incoming DECnet account.
(DECNET,DEFINCACC,PROHIBITED)
(DECNET,DEFINCACC,REQUIRED)
There is no Default Outgoing DECnet account. (This control is not available under DECnet-Plus.)
(DECNET,DEFOUTACC,PROHIBITED)
(DECNET,DEFOUTACC,REQUIRED)
There is no Default Privileged DECnet account.
(DECNET,DEFPRVACC,PROHIBITED)
(DECNET,DEFPRVACC,REQUIRED)
NIST SP 800-53 R2 IA-2(1)
Description  Automated Tests
A non-plaintext password authentication mechanism is installed.
(VMS,ACMEORLGI,NOTJUST)
No unauthorized authentication software is installed.
(VMS,ACMEORLGI,NOMORETHAN)
Required authentication software is installed.
(VMS,ACMEORLGI,MUSTHAVE)
NIST SP 800-53 R2 IA-2(2)
Description  Automated Tests
A non-plaintext password authentication mechanism is installed.
(VMS,ACMEORLGI,NOTJUST)
No unauthorized authentication software is installed.
(VMS,ACMEORLGI,NOMORETHAN)
Required authentication software is installed.
(VMS,ACMEORLGI,MUSTHAVE)
NIST SP 800-53 R2 IA-2(3)
Description  Automated Tests
A non-plaintext password authentication mechanism is installed.
(VMS,ACMEORLGI,NOTJUST)
No unauthorized authentication software is installed.
(VMS,ACMEORLGI,NOMORETHAN)
Required authentication software is installed.
(VMS,ACMEORLGI,MUSTHAVE)

Manual Inspection items for NIST SP 800-53 IA-2 assessment.

Manual Inspection items are useful mainly for CA-2 Security Assessments and CA-4 Security Certification. For most environments they are too laborious to include in CA-7 Continuous Monitoring.

Depending on FIPS 199 impact level and whether the Industrial Control Systems (ICS/SCADA) subset of 800-53 is chosen,  LJK/Security™ starter templates provide Manual Inspection items in the following groups:

Determination Statement Number Group Names
NIST SP 800-53 R2 IA-2(1)
POLICY
SECURITY
SYSTEM
NIST SP 800-53 R2 IA-2(2)
POLICY
SECURITY
NIST SP 800-53 R2 IA-2(3)
POLICY
SECURITY

Manual Invasive Testing items for NIST SP 800-53 IA-2 assessment.

Manual Invasive Testing items are useful mainly for CA-2 Security Assessments and CA-4 Security Certification. For most environments they are too laborious to include in CA-7 Continuous Monitoring. The level of effort required and the degree of invasiveness are so high (in most cases making up for lack of Common Criteria evaluation) that arrangement as a Common Control is almost always a requirement for execution.

Depending on FIPS 199 impact level and whether the Industrial Control Systems (ICS/SCADA) subset of 800-53 is chosen,  LJK/Security™ starter templates provide Manual Invasive Testing items in the following groups:

Determination Statement Number Group Names
NIST SP 800-53 R2 IA-2
TEST_ADD_ACME

Descriptions above apply to  LJK/Security™ Version 3.0.

The notation NIST SP 800-53 above refers in particular to NIST Special Publication 800-53 Revision 2.

Those NIST Special Publications specify security standards in support of FISMA for US Federal Government civil activities.

Return to master list of NIST 800-53 controls.


Valid HTML 4.01! Viewable with Any Browser