PlumbTrackLive demoGRC Risk System

← internal audit

Audit — IA-5 — Authenticator Management

Framework: NIST SP 800-53 Rev.5 IA-5 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the enforced authenticator/password configuration (Group Policy or IdP password policy) to confirm minimum length, composition/complexity, and password-history reuse restrictions meet organizational policy and NIST SP 800-63B (CIS Control 5.2).
Test Provision a test account and confirm the user is forced to change the initial or temporary authenticator at first logon before any other access is granted (IA-5(1)).
Examine Examine build/hardening standards and a sample of deployed systems, devices, and applications to confirm vendor default passwords are changed before or upon installation (IA-5(1); CIS Control 4.7).
Examine Examine authenticator storage and transport configuration to confirm passwords are stored salted-and-hashed (not plaintext or reversibly encrypted) and are only transmitted over encrypted channels (IA-5(1)(c)/(d)).
Examine Examine the configured minimum and maximum authenticator lifetimes (e.g., password maximum age, certificate validity/expiration) and confirm expired authenticators are refreshed or revoked and cannot continue to be used.
Interview Interview help-desk and IAM personnel on the identity-proofing steps performed before issuing, distributing, or resetting an authenticator (including lost-token or lost-credential replacement) to confirm the requester's identity is verified first.
Examine Examine PKI/certificate management records (where certificate-based authenticators are used) to confirm certificates are issued by an approved CA, mapped to authorized users, and revoked promptly upon personnel termination or role change (IA-5(2)).