Skip to content
ControlVerdict
IA.L2-3.5.11CMMC Level 2Level 2

Obscure Feedback

Practice statement

Obscure feedback of authentication information.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.5.11.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(1)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    authentication information is obscured during the authentication process.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    IA.L2-3.5.11Obscure Feedback
    Obscure feedback of authentication information.
    • [a]

      authentication information is obscured during the authentication process.

    Masked entry on every surface, including kiosks, scanners, and the mirrored conference display

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses the single Obscure Feedback objective across the authentication surfaces enumerated below.

    Surfaces in scope. Workstation and kiosk logon, virtual desktop sign-in, internal web applications, the mobile apps that can open CUI, and network-device consoles. Each was walked physically, not assumed.

    Configuration. Password fields mask input and the endpoint baseline disables the password reveal button, so a user cannot un-mask on a shared screen. Shared kiosks do not display the last signed-in username. SSH and serial consoles do not echo typed passwords. Authentication failure messages are generic — they do not reveal which factor or which half of the credential failed.

    Shared spaces. Presenters authenticate before mirroring starts, and screen mirroring is disconnected before any re-authentication prompt. Kiosk displays carry privacy filters and are angled away from the aisle. Push-approval prompts are approved on the phone, so no code is displayed on the shared wall.

    Maintenance. Quarterly walk-through against a checklist covering each surface above, done by someone who did not configure it. New application intake includes a masked-input check before the app is allowed to authenticate against the IdP.

    Accepted gap. One shop-floor HMI briefly shows the last character typed on its touch keyboard and the vendor cannot disable that behavior. The panel is inside a badge-controlled cell, faces away from the walkway, and its account has no access to CUI shares. Exception reviewed annually.

    What the evidence looks like

    • Endpoint baseline settings disabling the password reveal button and last-username display
    • Internal UI standard requiring masked credential input and generic failure text
    • Completed quarterly walk-through checklist with reviewer and date
    • Photograph or layout note showing kiosk placement and privacy filters
    • Exception register entry for the HMI touch keyboard

    Environment

    Shop floor with shared kiosks and handheld scanners; a conference room that mirrors laptop screens to a wall display during customer visits.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.