CMMCpedia Download

Requirements / Identification and Authentication (IA)

IA.L2-3.5.11

Obscure Feedback

Official Source Material

Obscure feedback of authentication information.

Determine if:

  1. [a] authentication information is obscured during the authentication process.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Every mainstream sign-in screen already obscures input. Your work is inventory, not engineering.

Masked password fields on the operating system, in browsers, on network gear consoles, and in your single sign-on portal satisfy objective [a] out of the box. Collect a screenshot per system type and pair the set with one policy sentence stating that authentication feedback is obscured.

The reveal-password control and brief character display do not fail you.

The assessment guide accepts displaying feedback for a very limited time before fully obscuring it, which is what mobile keyboards and the reveal control do. Cover the residue with a procedure line telling users not to reveal passwords within view of others, because a procedure reaches the applications no setting can.

Do not build controls to disable what vendors ship enabled.

Disabling the reveal button through policy is available if you want it, but it is not needed to meet [a], and it trades a compliance nothing for extra lockouts. Spend the effort on requirements with objectives still unmet.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.