NIST 800-171 · Identification and Authentication

Requirement 3.5.2

SPRS weight
SPRS weight: 5
POA&M eligibility
Not POA&M-eligible
Assessment objectives
3 assessment objectives

Official requirement text

Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.5.2[a]the identity of each user is authenticated or verified as a prerequisite to system access.
  2. 3.5.2[b]the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access.
  3. 3.5.2[c]the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.