NIST SP 800-53 Rev. 5 · Identification and Authentication

IA-5(1) — Authenticator Management | Password-Based Authentication

Credentials past required rotation. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.

Why this matters

A password or key still in use long past the date it should have been replaced

Applications and automated systems sign in using long-lived keys rather than passwords typed by a person. These are created once, pasted into a configuration file, and forgotten. They frequently outlast the project, the vendor, and the employee who created them, and a key that leaks stays useful to whoever finds it for as long as it remains valid.

Why this check earns its place. Nobody receives a reminder that an application key is ageing. There is no login prompt to nag anyone, so the only way to find them is to go looking.

What it reads
The organization's own inventory of application keys and when each was created.
What it reports
Keys older than the organization's own replacement interval, and keys about to stop working without warning.

See related public disclosures on the Signals page →

The requirement

The organization must enforce authenticator lifetime restrictions and require authenticators to be changed or refreshed at an organization-defined frequency.

NIST SP 800-53 Rev. 5 — IA-5(1) (Authenticator Management | Password-Based Authentication).

NIST requires a defined refresh frequency without setting it. The 90-day rotation interval below, and any exemption for credentials managed by an automated rotation service, are local decisions.

What a check finds

Active credential older than the rotation interval, or approaching hard expiry.

Choose your platform

CISA performance goals

  • 3.C — Create unique credentials (partial)

Full coverage map →

What a result does not prove

Credential age alone does not indicate compromise. It indicates that the organization's own rotation requirement has not been evidenced for this credential.