NIST SP 800-53 Rev. 5 · Identification and Authentication
IA-5(1) — Authenticator Management | Password-Based Authentication
Credentials past required rotation. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
A password or key still in use long past the date it should have been replaced
Applications and automated systems sign in using long-lived keys rather than passwords typed by a person. These are created once, pasted into a configuration file, and forgotten. They frequently outlast the project, the vendor, and the employee who created them, and a key that leaks stays useful to whoever finds it for as long as it remains valid.
Why this check earns its place. Nobody receives a reminder that an application key is ageing. There is no login prompt to nag anyone, so the only way to find them is to go looking.
- What it reads
- The organization's own inventory of application keys and when each was created.
- What it reports
- Keys older than the organization's own replacement interval, and keys about to stop working without warning.
See related public disclosures on the Signals page →
The requirement
The organization must enforce authenticator lifetime restrictions and require authenticators to be changed or refreshed at an organization-defined frequency.
NIST SP 800-53 Rev. 5 — IA-5(1) (Authenticator Management | Password-Based Authentication).
NIST requires a defined refresh frequency without setting it. The 90-day rotation interval below, and any exemption for credentials managed by an automated rotation service, are local decisions.
What a check finds
Active credential older than the rotation interval, or approaching hard expiry.
Choose your platform
CISA performance goals
- 3.C — Create unique credentials (partial)
What a result does not prove
Credential age alone does not indicate compromise. It indicates that the organization's own rotation requirement has not been evidenced for this credential.