PIN Complexity Requirements, v1.0

Defines conformance and assessment criteria for verifying that an organization has established minimum PIN complexity requirements.
If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Steps (4)

1
PIN Minimum Length (PINMinimumLength)
Does the organization require a minimum length for PINs?
Artifacts
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A2
Provide the organization's minimum PIN length.
Parameter
Minimum Lengthrequired
NUMBER : Provide the minimum legth for PINs.
2
No Sequential Patterns In PINs (NoSequentialPatternsInPINs)
Does the organization prohibit sequential patterns (i.e., 123456) in PINs?
Artifacts
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A2
Identify whether the organization permits sequential patterns in PINs.
Parameter
No Sequential Patternsrequired
BOOLEAN : Select whether sequential patterns are prohibited in PINs. (True=Sequential patterns are NOT permitted.)
3
PINs Not Same As User ID (PINsNotSameAsUserID)
Does the organization prohibit PINs from being the same as the User ID?
Artifacts
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A2
Identify whether the organization prohibits PINs that are the same as Userids.
Parameter
PIN Same As User ID Prohibitedrequired
BOOLEAN : Select whether a PINs are prohibited from being the same as the User ID. (True=PINs must NOT be the same as the User ID)
4
No Repeating Digits In PINs (NoRepeatingDigitsInPINs)
Does the organization prohibit repeating digits (i.e., 112233) in PINs?
Artifacts
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A2
Identify whether the organization permits digits to repeat in PINs.
Parameter
Digits May Repeatrequired
BOOLEAN : Select whether repetition of digits in a PIN is prohibited. (True = Digits may NOT repeat)
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (4)

C1
When a PIN is utilized in conjunction with a certificate or a token (e.g. key fob with rolling numbers) for the purpose of advanced authentication, the PIN shall have a specified minimum length in digits.
Citation
CJIS-SP-V5-4
Section 5.6.2.1.2.
C3
When a PIN is utilized in conjunction with a certificate or a token (e.g. key fob with rolling numbers) for the purpose of advanced authentication, the PIN shall have no sequential patterns (i.e., 123456).
Citation
CJIS-SP-V5-4
Section 5.6.2.1.2.
C4
When a PIN is utilized in conjunction with a certificate or a token (e.g. key fob with rolling numbers) for the purpose of advanced authentication, the PIN shall not be the same as the User ID.
Citation
CJIS-SP-V5-4
Section 5.6.2.1.2.
C2
When a PIN is utilized in conjunction with a certificate or a token (e.g. key fob with rolling numbers) for the purpose of advanced authentication, the PIN shall have no repeating digits (i.e., 112233).
Citation
CJIS-SP-V5-4
Section 5.6.2.1.2.