NIST 800-171 · Identification and Authentication
Requirement 3.5.3
- SPRS weight
- SPRS weight: 5
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 4 assessment objectives
Official requirement text
Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.5.3[a]privileged accounts are identified.
- 3.5.3[b]multifactor authentication is implemented for local access to privileged accounts.
- 3.5.3[c]multifactor authentication is implemented for network access to privileged accounts.
- 3.5.3[d]multifactor authentication is implemented for network access to non-privileged accounts.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.