UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

DODD 8520.03

Identity Authentication for Information Systems

active, Most Current
Organization: DODD
Publication Date: 19 May 2023
Status: active
Page Count: 46
scope:

Purpose:

In accordance with the authority in DoD Directive 5144.02, this issuance:

• Establishes policy, assigns responsibilities, and provides procedures for authenticating person and non-person entities (NPEs) to DoD information systems, including credential management.

• Establishes policy and prescribes procedures for establishing credentials and performing identity authentication of all entities accessing DoD information systems that authenticate themselves to DoD or external entities in accordance with DoD Instruction (DoDI) 8500.01.

• Establishes sensitivity levels to align with risk management requirements as specified in DoDI 8510.01, and establishes credential strengths to better align with identity proofing, credential management, and authentication requirements as specified in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3.

• Implements use of hardware public key infrastructure (PKI) certificates such as the personal identity verification (PIV) authentication public key certificate, as defined in the NIST Federal Information Processing Standard (FIPS) 201-2, on the DoD common access card (CAC), as the preferred authenticator for person entities to use when accessing DoD information systems on unclassified networks.

• Provides guidance on using authenticators including hardware and software PKI based, username and password, multi-factor authentication (MFA), and assertions.

Document History

DODD 8520.03
May 19, 2023
Identity Authentication for Information Systems
Purpose: In accordance with the authority in DoD Directive 5144.02, this issuance: • Establishes policy, assigns responsibilities, and provides procedures for authenticating person and non-person...
July 27, 2017
Identity Authentication for Information Systems
PURPOSE. In accordance with the authority in DoD Directive (DoDD) 5144.1 (Reference (a)), this Instruction: a. Implements policy in DoD Instruction (DoDI) 8500.01 (Reference (b)), assigns...
May 13, 2011
Identity Authentication for Information Systems
A description is not available for this item.

References

Advertisement