Requirements / Identification and Authentication (IA)
IA.L2-3.5.11
Obscure Feedback
Official Source Material
Obscure feedback of authentication information.
Determine if:
- [a] authentication information is obscured during the authentication process.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Every mainstream sign-in screen already obscures input. Your work is inventory, not engineering.
Masked password fields on the operating system, in browsers, on network gear consoles, and in your single sign-on portal satisfy objective [a] out of the box. Collect a screenshot per system type and pair the set with one policy sentence stating that authentication feedback is obscured.
The reveal-password control and brief character display do not fail you.
The assessment guide accepts displaying feedback for a very limited time before fully obscuring it, which is what mobile keyboards and the reveal control do. Cover the residue with a procedure line telling users not to reveal passwords within view of others, because a procedure reaches the applications no setting can.
Do not build controls to disable what vendors ship enabled.
Disabling the reveal button through policy is available if you want it, but it is not needed to meet [a], and it trades a compliance nothing for extra lockouts. Spend the effort on requirements with objectives still unmet.