36 MAC Pt. 1, R. 8.1
Identification and Authentication Management
Cite as 36 Miss. Admin. Code Pt. 1, R. 8.1
Identification and Authentication Management
A. Each agency must identify system users, processes acting on behalf of users, and
devices. Typically, individual identifiers are the usernames associated with the system
accounts assigned to those individuals. Additionally, common device identifiers can
include: media access control (MAC), Internet protocol (IP) addresses, device-unique
token identifiers.
B. Each agency must establish and follow an authentication process, preferably
automated, for granting access to enterprise assets upon new hire, rights grant, or role
change of a user.
1. All access to enterprise assets must be authenticated and adhere to guidance
that follows; and
2. All granting of account access (assignment of privileges) must follow a strict
and defined process (i.e. using account request forms and approvals thereof by
the appropriate personnel). This process is preferably automated (such as the
use of Privileged Access Management (PAM) systems) but can also be
manual.
C. Each agency must use multifactor authentication (MFA) for local (console or other
direct access) and network access (any access that occurs over a network of any type)
to privileged accounts and for network access to non-privileged accounts. For
network access, this includes such protocols as RDP, SSH, and VDI. Multifactor
authentication requires the use of two or more different factors to authenticate. The
factors are defined as something you know (e.g., password, personal identification
number [PIN]); something you have (e.g., cryptographic identification device, token);
or something you are (e.g., biometric).
1. Require MFA for all administrative access accounts, where supported, on all
enterprise assets, whether managed on-site or through a third-party provider.
2. Require all externally exposed agency or third-party applications (such as
Box, 365, etc.) to enforce MFA, where supported. Enforcing MFA through a
directory service or single sign on (SSO) provider is a satisfactory
implementation of this requirement. This includes public access to state
licensure sites.
3. Where MFA authentication is not supported (such as local administrator, root,
or service accounts), accounts must use passwords that contain at least
fourteen (14) characters and are unique to that system. The passwords should
be changed when the account is believed to have been breached or otherwise
compromised in any way.
D. Each agency must implement replay-resistant authentication mechanisms for network
access to privileged and non-privileged accounts.
1. Authentication processes resist replay attacks if it is impractical to
successfully authenticate by recording or replaying previous authentication
messages. For example, Windows systems not in a domain rely on NTLM and
NTLMv2 authentication. These protocols are vulnerable to replay attacks.
Join workstations to a domain to ensure Kerberos is used as an authentication
protocol (which is not vulnerable to replay attacks). As an alternative, use a
one-time password authentication mechanism (such as an RSA token) for
logging into systems.
E. Each agency must prevent reuse of identifiers for an agency-defined period. For
example, when a user leaves an agency, the username assigned to that user should not
be re-used for a specified period (such as 6 months).
F. Each agency must disable identifiers after an agency-defined period of inactivity
(such as 45 days).
G. Each agency must enforce minimum password requirements for all non-administrator
accounts. At minimum, the guidelines must adhere to the detailed guidance in NIST
800-63B section 5.1, 5.1.1.1, 5.1.1.2 and the additional requirements below.
1. Passwords must be unique per unique account. If one username/account is
used across multiple assets, it must employ a unique password on each.
2. Passwords must contain at least 8 characters for accounts using MFA and 14
characters for accounts not using MFA.
3. Passwords must not be disclosed to anyone except in emergency
circumstances or when there is an overriding operational necessity.
4. Usernames must be unique per user. Further, “group” or shared accounts
should not be utilized.
5. Default passwords must adhere to the requirements of this section and must be
changed upon initial authentication by the user. During account creation or
password resets, unique passwords should be set for each account as opposed
to using a common, default password for multiple users.
6. Passwords must be required on all user accounts.
7. Each agency must prohibit automated/scripted password input.
H. Each agency must use industry-standard encryption standards to encrypt passwords
when stored or in transit. At a minimum, encryption shall meet or exceed AES 128-
bit and TLS 1.3.