HomeControl Library › 3.5.4
3.5 Identification & Authentication1 ptPOA&M-eligible

3.5.4 — Replay-resistant authentication

Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

Network logins can't be captured and replayed by an attacker.

What it actually means

Authentication over the network must resist replay attacks — where someone captures a login exchange and re-sends it. Modern protocols handle this for you: Kerberos, modern TLS-based authentication, and FIDO2 are replay-resistant. The work is usually confirming you're not relying on something legacy.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library