NIST SP 800-171 & CMMC 2.0 3.5.1 Requirement:
Identify information system users, processes acting on behalf of users, or devices.
NIST SP 800-171 & CMMC 2.0 3.5.1 Requirement Explanation:
User accounts and systems need to be given unique identifiers The ability to identify a user or system is a critical part of authentication. It also allows you to trace events and incidents to a user or system.
Example NIST SP 800-171 & CMMC 2.0 3.5.1 Implementation:
Assign unique & unambiguous usernames to your user accounts. An example is to assign the user name of jdoe to an account belonging to an employee named John Doe. This allows you to identify the account owner. Assign unique identifiers to your systems such as workstations and servers. An example is naming a computer using its model & serial number (e.g. Model#_Serial#)
NIST SP 800-171 & CMMC 2.0 3.5.1 Scenario(s):
- Scenario 1:
Alice, a system administrator is reviewing user account names in active directory. She notices a few usernames that do not uniquely identify the user of the account. One example is an account named "EpicDeveloper85". The account name does not indicate the person using the account. After further investigation, Alice discovers the person behind the account and renames it to reflect their first and last name.
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you