// ITSP.10.171 · FAMILY 05 · 8 REQUIREMENTS
Identification and authentication
Last verified: 2026-10-05
// REQUIREMENTS
| Identifier | Requirement | Level 1 |
|---|---|---|
| 03.05.01 | User identification, authentication, and re-authentication | Level 1 |
| 03.05.02 | Device identification and authentication | Level 1 |
| 03.05.03 | Multi-factor authentication | Level 1 |
| 03.05.04 | Replay-resistant authentication | |
| 03.05.05 | Identifier management | |
| 03.05.07 | Password management | |
| 03.05.11 | Authentication feedback | |
| 03.05.12 | Authenticator management |
// INTENT
Know who is on the system before it does anything.
// WHAT A FIRST ASSESSMENT FINDS
MFA on the VPN maybe, absent on email, absent on the domain, absent on the cloud tenant's admin plane.
// THE WORK
MFA on every path to Specified Information and on every privileged account, unique IDs, a written password policy that matches the one applied, and replay-resistant mechanisms. At Level 2 none of this is negotiable, and it shouldn't be at your company regardless of the program.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.