HomeControl Library › 3.5.1
3.5 Identification & Authentication5 ptsAlso Level 1

3.5.1 — Uniquely identify users, processes, and devices

Identify system users, processes acting on behalf of users, and devices.

Every user, service, and device has its own unique identity.

What it actually means

You can't hold anyone accountable, or authenticate them, if you can't tell them apart. Every person, service account, and device that touches CUI needs a unique identifier — no shared logins. Devices are uniquely identified through enrollment (MDM); users and services through your identity provider.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library