Skip to main content
Back to results
NIST 800-171 R-3.5.1

Identify Users, Processes, and Devices

Official citation: 3.5.1

Class: core · Severity: critical

Statement of the obligation — verify against source

3.5.1

What it means

Uniquely identify the users, the processes acting on their behalf, and the devices that access your systems. For people this is usually the user name tied to their account (individual identifiers don't apply to shared accounts, though you may still require unique IDs within group accounts for accountability). Devices can be identified by type, by device, or both — for example via MAC or IP addresses or unique token identifiers.

Educational reference only — not legal advice. Consult a qualified assessor or attorney for binding compliance determinations.