官术网_书友最值得收藏!

Identification and authentication policy

The identification and authentication policy defines the organization's rules for information system identifiers that are provisioned and managed, as well as the mechanisms allowed for positive authentication of provisioned information system identifiers.

What the identification and authentication policy should address:

  • Identifying information system users, processes acting on behalf of users, or devices
  • Authenticating (or verifying) the identities of those users, processes, or devices as a prerequisite to allowing access to organizational information systems
  • Using multifactor authentication for local and network access to information systems
  • Employing replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts
  • Preventing reuse of identifiers for a defined period
  • Disabling identifiers after a defined period of inactivity
  • Enforcing a minimum password complexity and change of characters when new passwords are created
  • Prohibiting password reuse for a specified number of generations
  • Allowing temporary password use for system logons with an immediate change to a permanent password
  • Storing and transmitting only encrypted representation of passwords
  • Obscuring feedback of authentication information
主站蜘蛛池模板: 德安县| 元谋县| 阳谷县| 岱山县| 阿合奇县| 惠来县| 石景山区| 大邑县| 都安| 新昌县| 永寿县| 麻阳| 宝应县| 通海县| 西乌珠穆沁旗| 繁昌县| 漠河县| 天长市| 通山县| 增城市| 垦利县| 建瓯市| 麻城市| 栖霞市| 林西县| 绥芬河市| 刚察县| 紫阳县| 昭平县| 南安市| 循化| 苍南县| 溧水县| 绵竹市| 辉南县| 宁陕县| 阿鲁科尔沁旗| 江孜县| 云霄县| 嘉黎县| 德阳市|