NIST IR 8523 offers practical guidance to help law-enforcement and justice agencies secure Criminal Justice Information (CJI) with multi-factor authentication (MFA). It explains why moving beyond passwords is critical, then lays out core design principles: reusing authenticators, offering multiple factor types, and minimizing shared secrets. The report also compares MFA options—local agency, state-level, VPN-integrated, or federated architectures—showing how each balances security, usability, and cost. Recommendations stress phishing-resistant authenticators, single sign-on, and phased rollouts to make adoption smoother and more effective.
Format: |
|
Topics: | |
Website: | Visit Publisher Website |
Publisher: | U.S. Department of Commerce |
Published: | September 1, 2025 |
License: | Public Domain |