1Overview
IA.L2-3.5.11 closes the Identification and Authentication family with a small but important measure. It requires that the organization obscure the feedback of authentication information, so that as a user authenticates, the information they enter is not displayed in a way that others could see. It is a one-point requirement with a single assessment objective, and it may be deferred on a plan of action.
Authentication feedback is what the system shows while someone logs in, and if it reveals the credential, a password shown on screen, a token echoed in full, then anyone watching, in person or over the shoulder of a shared display, can capture it. This control requires that such feedback be obscured, most familiarly by masking a password with dots or asterisks as it is typed, so the credential is not exposed during entry. It is a modest control, but it closes a simple avenue of credential theft.
Obscure feedback of authentication information.
The requirement is that authentication information not be displayed openly as it is entered or processed. The everyday example is the masked password field, where characters appear as dots rather than the letters typed, but the principle extends to any point where a credential might otherwise be shown, such as error messages or logs that could echo it. The control is generally met by the default masking of modern login interfaces, with attention to any custom interface that might reveal credentials.
2The Assessment Objective
NIST SP 800-171A frames 3.5.11 as a single objective: obscure authentication feedback.
Authentication information is obscured during the authentication process. Credentials are not displayed openly during authentication.
The single objective is obscured authentication feedback. The common failure is a custom or legacy interface that displays a credential rather than masking it. The assessor looks for authentication information obscured throughout the process.
3Failure Patterns
The failures are about credentials shown openly during authentication.
Unmasked password fields
A login interface that shows the password as it is typed exposes it to anyone watching. Masking the field is the basic protection the control expects.
Credentials echoed in messages or logs
Error messages or logs that echo a password or token back reveal the credential outside the entry field. Obscuring feedback extends to any place a credential might otherwise appear.
Custom interfaces without masking
A custom application that does not mask authentication information leaves a gap even when standard logins are masked. Every authentication interface has to obscure the credential.
4Ownership
This is an IT-owned technical control, delivered through the authentication interfaces.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Ensures authentication information is masked across login interfaces, including custom ones. Owns the technical evidence. |
| Security or compliance lead | Confirms no interface displays or echoes credentials during authentication. |
| Program lead | Includes authentication interfaces in periodic review and retains the evidence. |
5Tooling
The control is delivered by masking in authentication interfaces.
| Objective | Tooling | What it provides |
|---|---|---|
| entry | Masked password fields | Credentials obscured as they are entered. |
| messages | Suppression of credentials in messages and logs | Credentials not echoed outside the entry field. |
| Coverage | Review of custom authentication interfaces | Masking applied across every authentication path. |
The caveat is that masking has to cover every authentication interface, including custom and legacy ones. Standard logins mask by default, so the control is met by confirming that no interface displays or echoes a credential. The assessor examines the authentication interfaces, so any unmasked path has to be corrected.
6Evidence
The satisfied version of 3.5.11 shows authentication information obscured throughout.
| Evidence | What it demonstrates |
|---|---|
| Login interface behavior | The objective. Authentication information masked during entry. |
| Interface review | The objective. No interface displays or echoes credentials. |
The evidence should show authentication information obscured across the login interfaces, with no path displaying a credential. The masked interfaces and a review confirming no exposure are the clearest demonstration of the control.
A credential on screen is a credential exposed
Authentication feedback that shows a password lets anyone nearby capture it, and this control asks for credentials to be obscured throughout the login. Confirming masking across every authentication interface, including custom ones, is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.11. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.5.11. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov