36 MAC Pt. 1, R. 8.1

Identification and Authentication Management

Year: 2026Length: 712 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 8.1

Identification and Authentication Management A. Each agency must identify system users, processes acting on behalf of users, and devices. Typically, individual identifiers are the usernames associated with the system accounts assigned to those individuals. Additionally, common device identifiers can include: media access control (MAC), Internet protocol (IP) addresses, device-unique token identifiers. B. Each agency must establish and follow an authentication process, preferably automated, for granting access to enterprise assets upon new hire, rights grant, or role change of a user. 1. All access to enterprise assets must be authenticated and adhere to guidance that follows; and 2. All granting of account access (assignment of privileges) must follow a strict and defined process (i.e. using account request forms and approvals thereof by the appropriate personnel). This process is preferably automated (such as the use of Privileged Access Management (PAM) systems) but can also be manual. C. Each agency must use multifactor authentication (MFA) for local (console or other direct access) and network access (any access that occurs over a network of any type) to privileged accounts and for network access to non-privileged accounts. For network access, this includes such protocols as RDP, SSH, and VDI. Multifactor authentication requires the use of two or more different factors to authenticate. The factors are defined as something you know (e.g., password, personal identification number [PIN]); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). 1. Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a third-party provider. 2. Require all externally exposed agency or third-party applications (such as Box, 365, etc.) to enforce MFA, where supported. Enforcing MFA through a directory service or single sign on (SSO) provider is a satisfactory implementation of this requirement. This includes public access to state licensure sites. 3. Where MFA authentication is not supported (such as local administrator, root, or service accounts), accounts must use passwords that contain at least fourteen (14) characters and are unique to that system. The passwords should be changed when the account is believed to have been breached or otherwise compromised in any way. D. Each agency must implement replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. 1. Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. For example, Windows systems not in a domain rely on NTLM and NTLMv2 authentication. These protocols are vulnerable to replay attacks. Join workstations to a domain to ensure Kerberos is used as an authentication protocol (which is not vulnerable to replay attacks). As an alternative, use a one-time password authentication mechanism (such as an RSA token) for logging into systems. E. Each agency must prevent reuse of identifiers for an agency-defined period. For example, when a user leaves an agency, the username assigned to that user should not be re-used for a specified period (such as 6 months). F. Each agency must disable identifiers after an agency-defined period of inactivity (such as 45 days). G. Each agency must enforce minimum password requirements for all non-administrator accounts. At minimum, the guidelines must adhere to the detailed guidance in NIST 800-63B section 5.1, 5.1.1.1, 5.1.1.2 and the additional requirements below. 1. Passwords must be unique per unique account. If one username/account is used across multiple assets, it must employ a unique password on each. 2. Passwords must contain at least 8 characters for accounts using MFA and 14 characters for accounts not using MFA. 3. Passwords must not be disclosed to anyone except in emergency circumstances or when there is an overriding operational necessity. 4. Usernames must be unique per user. Further, “group” or shared accounts should not be utilized. 5. Default passwords must adhere to the requirements of this section and must be changed upon initial authentication by the user. During account creation or password resets, unique passwords should be set for each account as opposed to using a common, default password for multiple users. 6. Passwords must be required on all user accounts. 7. Each agency must prohibit automated/scripted password input. H. Each agency must use industry-standard encryption standards to encrypt passwords when stored or in transit. At a minimum, encryption shall meet or exceed AES 128- bit and TLS 1.3.
36 MAC Pt. 1, R. 8.1: Identification and Authentication Management | Justis AI