Obscure Feedback
Practice statement
Obscure feedback of authentication information.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.5.11.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(1)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
authentication information is obscured during the authentication process.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
IA.L2-3.5.11Obscure Feedback
Obscure feedback of authentication information.
[a]
authentication information is obscured during the authentication process.
Masked entry on every surface, including kiosks, scanners, and the mirrored conference display
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses the single Obscure Feedback objective across the authentication surfaces enumerated below.
Surfaces in scope. Workstation and kiosk logon, virtual desktop sign-in, internal web applications, the mobile apps that can open CUI, and network-device consoles. Each was walked physically, not assumed.
Configuration. Password fields mask input and the endpoint baseline disables the password reveal button, so a user cannot un-mask on a shared screen. Shared kiosks do not display the last signed-in username. SSH and serial consoles do not echo typed passwords. Authentication failure messages are generic — they do not reveal which factor or which half of the credential failed.
Shared spaces. Presenters authenticate before mirroring starts, and screen mirroring is disconnected before any re-authentication prompt. Kiosk displays carry privacy filters and are angled away from the aisle. Push-approval prompts are approved on the phone, so no code is displayed on the shared wall.
Maintenance. Quarterly walk-through against a checklist covering each surface above, done by someone who did not configure it. New application intake includes a masked-input check before the app is allowed to authenticate against the IdP.
Accepted gap. One shop-floor HMI briefly shows the last character typed on its touch keyboard and the vendor cannot disable that behavior. The panel is inside a badge-controlled cell, faces away from the walkway, and its account has no access to CUI shares. Exception reviewed annually.
What the evidence looks like
- Endpoint baseline settings disabling the password reveal button and last-username display
- Internal UI standard requiring masked credential input and generic failure text
- Completed quarterly walk-through checklist with reviewer and date
- Photograph or layout note showing kiosk placement and privacy filters
- Exception register entry for the HMI touch keyboard
Environment
Shop floor with shared kiosks and handheld scanners; a conference room that mirrors laptop screens to a wall display during customer visits.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.