PlumbTrackLive demoGRC Risk System

← internal audit

Audit — IA-2 — Identification and Authentication (Organizational Users)

Framework: NIST SP 800-53 Rev.5 IA-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the account inventory and identity management policy to confirm every interactive user account maps to a single named individual, with no generic or shared logon accounts (e.g., 'admin', 'operator', a departmental mailbox) used for organizational user access (CIS Control 5.1/6.1).
Test Attempt to authenticate to a privileged account over the network with a valid password but a missing or invalid second factor, and confirm access is denied unless multi-factor authentication is satisfied (IA-2(1); CIS Control 6.5).
Examine Examine the identity provider or directory configuration (e.g., Entra ID, Okta, Active Directory) to confirm MFA is also enforced for non-privileged and remote/network access, not solely for administrators (IA-2(2); CIS Control 6.4).
Test Test the authentication exchange to confirm the mechanism is replay-resistant (e.g., Kerberos, PKI/smart card, TOTP or challenge-response tokens) rather than a static reusable secret sent over the wire (IA-2(8)).
Examine Examine authentication and session audit records to confirm the unique user identity is bound to the sessions and processes acting on that user's behalf, and that non-person/service accounts are clearly distinguished from human accounts.
Interview Interview system and identity administrators on how any emergency, break-glass, or exception shared credentials are provisioned, approved, monitored, and rotated, confirming such accounts are documented exceptions rather than routine access.
Examine Examine account-reconciliation evidence to confirm dormant, orphaned, or terminated-user identities are detected and disabled on a defined cadence so their credentials can no longer authenticate (CIS Control 5.3).