# IA-11 — Re-authentication

- **Control ID:** IA-11
- **Family:** [IA](/md/families/IA.md)
- **Baselines:** low, moderate, high
- **Enhancement of:** No content available.

## Description

Require users to re-authenticate when \[assignment\].

## Discussion

In addition to the re-authentication requirements associated with device locks, organizations may require re-authentication of individuals in certain situations, including when roles, authenticators or credentials change, when security categories of systems change, when the execution of privileged functions occurs, after a fixed time period, or periodically.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [PR.AA-01](/md/csf/PR.AA-01.md) — Identities and credentials for authorized users, services, and hardware are managed by the organization
- [PR.AA-03](/md/csf/PR.AA-03.md) — Users, services, and hardware are authenticated

## Related controls

- [AC-3](/md/controls/AC-3.md)
- [AC-11](/md/controls/AC-11.md)
- [IA-2](/md/controls/IA-2.md)
- [IA-3](/md/controls/IA-3.md)
- [IA-4](/md/controls/IA-4.md)
- [IA-8](/md/controls/IA-8.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
