1Overview
IA.L2-3.5.5 prevents identifiers from being recycled too soon. It requires that the organization define a period during which identifiers cannot be reused and prevent reuse within it, so that a username or identifier once assigned to one person is not handed to another while the old association still matters. It is a one-point requirement and may be deferred on a plan of action.
When an identifier such as a username is reassigned to a new person too quickly, confusion follows: old audit records, permissions, or references now appear to belong to the new holder, and accountability blurs. This control asks the organization to set a period during which a retired identifier stays retired, and to prevent its reuse within that period, so the association between an identifier and a person remains clean. It keeps the identity records unambiguous as people come and go.
Prevent reuse of identifiers for a defined period.
The requirement has two parts: define the period and prevent reuse within it. The period is set by the organization to be long enough that the old association no longer causes confusion, and within it the identifier is not reassigned. This is usually a matter of directory practice and account records rather than a technical enforcement, but the period has to be defined and reuse actually prevented.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.5.5 into two objectives: define the period and prevent reuse within it.
A period within which identifiers cannot be reused is defined. The organization has set how long a retired identifier stays retired.
Reuse of identifiers is prevented within the defined period. Retired identifiers are not reassigned within the period.
The two objectives are the definition and the prevention. The common gap is at objective [a], where no period is defined, leaving reuse ungoverned. The assessor looks for a defined period and evidence that reuse is prevented within it.
3Failure Patterns
The failures are about undefined periods and quick reassignment.
No defined period
Without a defined reuse period, there is no rule governing reassignment, and objective [a] is unmet. Defining the period is the necessary first step.
Immediate reassignment
Reassigning an identifier to a new person soon after the old holder leaves lets the new person inherit old associations, confusing accountability. Preventing reuse within the defined period avoids this.
Period defined but not observed
A defined period that is not actually observed in practice leaves objective [b] unmet. The prevention has to be real, not just stated.
4Ownership
This is an IT-owned control, delivered through directory and account management practice.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Observes the defined reuse period and avoids reassigning identifiers within it. Owns the account records. |
| Security or compliance lead | Defines the reuse period and confirms reuse is prevented within it. |
| Program lead | Includes identifier reuse in account management practice and retains the evidence. |
5Tooling
The control is largely a matter of account management practice with a defined period.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Defined identifier reuse period | The period during which identifiers cannot be reassigned. |
| [b] | Account management practice, retained account records | Prevention of reassignment within the period. |
The caveat is that the control rests on practice more than technology, so the defined period has to be observed in account management. Retaining records of retired identifiers helps demonstrate that reuse is prevented within the period. The assessor examines the defined period and account practice, so both have to be evident.
6Evidence
The satisfied version of 3.5.5 shows a defined period and prevented reuse.
| Evidence | What it demonstrates |
|---|---|
| Defined reuse period | Objective [a]. The period during which identifiers cannot be reused. |
| Account management records | Objective [b]. Evidence identifiers are not reassigned within the period. |
The evidence should show a defined reuse period and account practice that prevents reassignment within it. The defined period paired with account records is the clearest demonstration of the control.
A retired username should stay retired long enough
Reassigning an identifier too soon carries an old holder's history into a new person's identity, and this control asks for a defined period during which reuse is prevented. Setting that period and observing it in account management is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.5.5. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.5.5[a] and 3.5.5[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov