NIST 800-53 REV 5 • IDENTIFICATION AND AUTHENTICATION
IA-5(16) — In-person or Trusted External Party Authenticator Issuance
Require that the issuance of {{ insert: param, ia-05.16_odp.01 }} be conducted {{ insert: param, ia-05.16_odp.02 }} before {{ insert: param, ia-05.16_odp.03 }} with authorization by {{ insert: param, ia-05.16_odp.04 }}.
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
Supplemental Guidance
Issuing authenticators in person or by a trusted external party enhances and reinforces the trustworthiness of the identity proofing process.
Practitioner Notes
This enhancement requires in-person or trusted external party involvement when issuing authenticators — someone trusted must physically verify the recipient's identity.
Example 1: Require new employees to receive their initial password and MFA token in person from the IT help desk after the HR department confirms their identity.
Example 2: For remote employees, use a bonded courier service to deliver hardware tokens and initial credentials, with signature verification upon delivery.