NIST Digital Identity and Authentication

NobleKrypton avatar
NobleKrypton
·
·
Download

Start Quiz

Study Flashcards

6 Questions

What is digital identity according to NIST SP 800-63-3?

A unique representation of a subject engaged in an online transaction

What is the primary goal of digital user authentication?

To authenticate the identities of users, processes, or devices

What is required for local and network access to privileged accounts?

Multifactor authentication

What should be done with identifiers after a defined period of inactivity?

Disable them

What should be prohibited for a specified number of generations?

Password reuse

What should be done with authentication information?

Obscure feedback of it

Study Notes

Digital Identity

  • A unique representation of a subject engaged in an online transaction.

Digital Authentication

  • The process of determining the validity of one or more authenticators used to claim a digital identity.

Basic Security Requirements

  • Identify information system users, processes acting on behalf of users, or devices.
  • Authenticate (or verify) the identities of those users, processes, or devices as a prerequisite to allowing access to organizational information systems.

Derived Security Requirements

  • Use multifactor authentication for:
    • Local and network access to privileged accounts.
    • Network access to non-privileged accounts.
  • Employ replay-resistant authentication mechanisms for:
    • Network access to privileged accounts.
    • Network access to non-privileged accounts.
  • Prevent reuse of identifiers for a defined period.
  • Disable identifiers after a defined period of inactivity.
  • Enforce minimum password complexity and change of characters when new passwords are created.
  • Prohibit password reuse for a specified number of generations.
  • Allow temporary password use for system logons with an immediate change to a permanent password.
  • Store and transmit only cryptographically-protected passwords.
  • Obscure feedback of authentication information.

Learn about digital identities, authentication processes, and security requirements as per NIST SP 800-63-3 guidelines.

Make Your Own Quizzes and Flashcards

Convert your notes into interactive study material.

Get started for free

More Quizzes Like This

Use Quizgecko on...
Browser
Browser