Identification and Authentication - Level 2
CMMC IA.2.082 - Obscure Authentication Feedback
Requirement text: IA.2.082: Obscure feedback of authentication information. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 The feedback from systems does not provide any information that would allow unauthorized individuals to compromise ...
CMMC IA.2.081 - Encrypt Passwords
Requirement text: IA.2.081: Store and transmit only cryptographically-protected passwords. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Cryptographically-protected passwords use salted one-way cryptographic hashes of passwords. See NIST ...
CMMC IA.2.080 - Limit Use of Temporary Password
Requirement text: IA.2.080: Allow temporary password use for system logons with an immediate change to a permanent password. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Changing temporary passwords to permanent passwords immediately after system ...
CMMC IA.2.079 - Prohibit Password Reuse
Requirement text: IA.2.079: Prohibit password reuse for a specified number of generations. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Password lifetime restrictions do not apply to temporary passwords. CMMC CLARIFICATION Individuals may not ...
CMMC IA.2.078 - Enforce Password Complexity
Requirement text: IA.2.078: Enforce a minimum password complexity and change of characters when new passwords are created. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 This requirement applies to single-factor authentication of individuals using ...