Skip to Content

NIST 800-171 - Identifier Reuse (3.5.5)

Overview:
Prevent reuse of identifiers for a defined period.


Action Items:
3.5.5[a]
Determine if: a period within which identifiers cannot be reused is defined.


3.5.5[b]
Determine if: reuse of identifiers is prevented within the defined period.


POTENTIAL ASSESSMENT METHODS AND OBJECTS


1
Examine: Identification and authentication policy; procedures addressing identifier management; procedures addressing account management; system security plan; system design documentation; system configuration settings and associated documentation; list of system accounts; list of identifiers generated from physical access control devices; other relevant documents or records].


2
Interview: Personnel with identifier management responsibilities; personnel with information security responsibilities; system or network administrators; system developers].


3
Test: Mechanisms supporting or implementing identifier management].


Related Documents (document name and content will vary by organization):
1) Identification and authentication policy
2) procedures addressing identifier management
3) procedures addressing account management
4) system security plan
5) system design documentation
6) system configuration settings and associated documentation
7) list of system accounts
8) list of identifiers generated from physical access control devices
9) other relevant documents or records


Additional Guidance:
Identifiers are provided for users, processes acting on behalf of users, or devices (3.5.1). Preventing reuse of identifiers implies preventing the assignment of previously used individual, group, role, or device identifiers to different individuals, groups, roles, or devices.