3.5.4

  • Requirement

    Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.

  • Discussion

    Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges, such as time synchronous or challenge-response one-time authenticators.

More Info

  • Family

    Identification and Authentication
  • Related NIST 800-53 ID

    IA-02(08)
  • Reference Documents

    • N/A

NIST 800-171A r3 Assessment Guidance

CMMC Training

Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!