官术网_书友最值得收藏!

Identification and authentication policy

The identification and authentication policy defines the organization's rules for information system identifiers that are provisioned and managed, as well as the mechanisms allowed for positive authentication of provisioned information system identifiers.

What the identification and authentication policy should address:

  • Identifying information system users, processes acting on behalf of users, or devices
  • Authenticating (or verifying) the identities of those users, processes, or devices as a prerequisite to allowing access to organizational information systems
  • Using multifactor authentication for local and network access to information systems
  • Employing replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts
  • Preventing reuse of identifiers for a defined period
  • Disabling identifiers after a defined period of inactivity
  • Enforcing a minimum password complexity and change of characters when new passwords are created
  • Prohibiting password reuse for a specified number of generations
  • Allowing temporary password use for system logons with an immediate change to a permanent password
  • Storing and transmitting only encrypted representation of passwords
  • Obscuring feedback of authentication information
主站蜘蛛池模板: 永胜县| 哈巴河县| 吉安县| 高雄市| 烟台市| 桑植县| 山东| 嘉兴市| 方城县| 钦州市| 万盛区| 鄄城县| 苍山县| 通河县| 阜康市| 崇左市| 平湖市| 渭源县| 军事| 桃园市| 贵港市| 武强县| 会东县| 鹰潭市| 阿图什市| 临武县| 泉州市| 怀来县| 河池市| 房产| 郸城县| 阿图什市| 双流县| 冷水江市| 东乌珠穆沁旗| 苗栗市| 武城县| 高要市| 会泽县| 伊吾县| 健康|