Identification & Authentication
That users, processes, and devices are uniquely identified and proven before access — including multifactor authentication.
The 11 requirements, in plain language.
Identify system users, processes acting on behalf of users, and devices
Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems
Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts
Prevent reuse of identifiers for a defined period
Disable identifiers after a defined period of inactivity
Enforce a minimum password complexity and change of characters when new passwords are created
Prohibit password reuse for a specified number of generations
Allow temporary password use for system logons with an immediate change to a permanent password
Store and transmit only cryptographically-protected passwords
Obscure feedback of authentication information
One owner across the whole family — built, run, and proven.
Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.
See all fourteen families →Not sure which families your contract puts in scope?
A readiness check maps your environment to all 110 controls and tells you exactly where you stand.