unified

UC-ACCESS-08 — Manage and protect authenticators across their lifecycle

Authenticators (passwords, tokens, keys, certificates) are issued through a verified process, with vendor defaults changed before use and minimum strength requirements enforced. Authentication information is protected in storage (salted hashing or encryption) and in transmission, masked during entry, and never embedded in code or scripts. Authenticators are revoked on compromise or separation and rotated at defined intervals or events.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
preventive
category
technical

Details

unified_id
UC-ACCESS-08
title
Manage and protect authenticators across their lifecycle
statement
Authenticators (passwords, tokens, keys, certificates) are issued through a verified process, with vendor defaults changed before use and minimum strength requirements enforced. Authentication information is protected in storage (salted hashing or encryption) and in transmission, masked during entry, and never embedded in code or scripts. Authenticators are revoked on compromise or separation and rotated at defined intervals or events.
domain
Access Control & Identity Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    IA-5
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    IA-6
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.5.17
    coverage
    partial
    delta
    advising personnel on proper handling and protection of authentication information
    relationship
    intersects_with
guidance
  • source
    nist-ai-agent-identity
    sourceTitle
    NIST NCCoE: Software and AI Agent Identity and Authorization
    propositionId
    NIST-AGI-02
    propositionTitle
    Agent authentication and credential lifecycle
    sourcePages
    Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines

Source

No record-specific source URL is provided.

Connections