PlumbTrackLive demoGRC Risk System

← control library

Re-authentication IA-11

Identification and Authentication · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds IA-11 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Identification and Authentication family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

IA-11 (Re-authentication) is about making a user prove who they are again at the right moments — not only once at login. When something sensitive happens, or after a stretch of idle time, the session should ask for credentials again instead of trusting the old login forever. It is a technical Identification and Authentication control in the Low baseline that carries up into Moderate and High.

What good looks like

Framework mapping

How to move it toward Implemented