Identification and Authentication Policy
DU-1-POL-717-002 · owner: infosec · QMS clause: 07.01.07
Confidential Business Information (CBI) — do not distribute. This document contains proprietary information of DroneUp, LLC. It is intended solely for the information and use of parties operating on behalf of DroneUp, LLC and its affiliates. Such proprietary information may not be used, reproduced, or disclosed to any other parties for any other purpose without express written permission. The information contained in this document is effective as of the revision date in the document control record.
Revision history
| Version | Date | Description | Updated by |
| 1 | 2026-06-24 | Initial publication. Separated this content from Access Control. | Irina Prozhoha |
1. Purpose
This policy establishes DroneUp’s organization-level framework for identification and authentication. It defines the principles, roles, and enforceable requirements governing how users, devices, and systems are uniquely identified, securely authenticated, and re-authenticated before being granted access to DroneUp data, information, and systems. This policy mandates unique identification of organizational and non-organizational users, device and system identification, multi-factor authentication, replay-resistant authentication, identifier management, authenticator management, password verification, and obscured authentication feedback, and delegates implementation specifics to subordinate subpolicies and procedures.
2. Scope
This Identification and Authentication Policy [DU-1-POL-717-002] operates under the authority of the Information Security Program Policy [DU-1-POL-521-001], which governs DroneUp’s Information Compliance Program. This policy establishes requirements for the identification and authentication of users, devices, and systems across DroneUp operations. The following subordinate documents operationalize the specific requirements of this policy:
- Authenticator Management Subpolicy [DU-2-SUB-717-009]
- Multi-Factor Authentication (MFA) Subpolicy [DU-2-SUB-717-007]
- Password Requirements Subpolicy [DU-2-SUB-717-006]
- Identity Management Profiles Subpolicy [DU-2-SUB-717-008]
- Secrets Management Subpolicy [DU-2-SUB-713-002]
- Unsuccessful Logon Attempts Procedure [DU-3-SUB-717-007]
- Identifier Management Procedure [DU-2-PRO-717-019]
- Account Management Procedure [DU-2-PRO-717-001]
- Multi Factor Authentication (MFA) Procedure [DU-2-PRO-717-017]
- User Identification and Authentication Procedure [DU-2-PRO-717-023]
- Replay-Resistant Authentication Procedure [DU-2-PRO-717-018]
- Password Management Procedure [DU-2-PRO-717-020]
Who this applies to: all DroneUp employees, contractors, and consultants, and all information systems, data, and operations that create, receive, process, store, or transmit information on behalf of DroneUp or entrusted to DroneUp by clients, partners, or the U.S. Government.
What this covers: all DroneUp information systems, networks, cloud services, products, and business operations, regardless of geographic location or hosting model, including all systems and services that handle Controlled Unclassified Information (CUI) under DroneUp’s federal contracting activities.
Review and update this policy at least annually and upon Significant Change, in accordance with the document control record. Non-compliance may result in disciplinary action up to and including termination, as defined in Section 12. Direct questions to the Information Security team through designated support channels.
Compliance and control framework alignment
This policy is designed to address the NIST SP 800-171 Rev. 3 Identification and Authentication control family (03.05). Controls 03.05.06, 03.05.08, 03.05.09, and 03.05.10 are withdrawn in Rev. 3 and are not addressed by this policy. This policy also supports compliance with 32 CFR Part 2002 governing the CUI Program by ensuring that access to systems processing CUI is preceded by unique identification and secure authentication of users, devices, and processes. The specific requirements addressed are recorded in the control mapping for this document rather than in the section headings.
3. User Identification and Authentication
Information Systems Personnel must:
- Uniquely identify and authenticate all organizational users and associate that unique identification with processes acting on behalf of those users, where each user’s identifier is generated automatically by the HR-driven provisioning integration according to the User Identification and Authentication Procedure [DU-2-PRO-717-023]; Information Systems Personnel create identifiers manually only as a documented fallback when the automated integration is unavailable.
- Require users to re-authenticate after session termination conditions defined in the Access Control Policy [DU-1-POL-717-001], including the defined period of inactivity, a change of authenticators or roles, and when executing privileged functions, as documented in the User Identification and Authentication Procedure [DU-2-PRO-717-023].
- Uniquely identify and authenticate non-organizational users and processes acting on behalf of non-organizational users, sponsored through the Account Management Procedure [DU-2-PRO-717-001], using identity management profiles defined in the Identity Management Profiles Subpolicy [DU-2-SUB-717-008].
4. Device Identification and Authentication
Information Systems Personnel must:
- Uniquely identify and authenticate devices and types of devices before establishing local, remote, or network connections, in accordance with the Identifier Management Procedure [DU-2-PRO-717-019]; DroneUp Delivery UAS are authenticated by per-device certificates over an encrypted tunnel.
5. Multi-Factor Authentication
Information Systems Personnel must:
- Implement multi-factor authentication for access to privileged and non-privileged accounts, as defined in the Multi Factor Authentication (MFA) Procedure [DU-2-PRO-717-017].
6. Replay Resistant Authentication
Information Systems Personnel must:
- Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts through the centrally managed identity provider configuration defined in the Replay-Resistant Authentication Procedure [DU-2-PRO-717-018].
7. Identifier Management
Information Systems Personnel must:
- Manage system identifiers by receiving authorization from the designated Access Manager before assigning an identifier; selecting unique identifiers; assigning identifiers to the intended individual, group, role, service, or device; preventing identifier reuse for the period defined in the Identifier Management Procedure [DU-2-PRO-717-019]; and incorporating an individual’s status (such as contractor) per the Identifier Management Procedure [DU-2-PRO-717-019].
8. Password Management
Information Systems Personnel must:
- Maintain the organizational compromised-password verification mechanism by governing its configuration through the identity provider; verify annually that the identity provider’s compromised-password detection feature is active and current; and trigger an immediate out-of-cycle verification following any confirmed or suspected organizational password compromise, in accordance with the Password Management Procedure [DU-2-PRO-717-020] and the Event Response Plan [DU-3-WI-940-002].
- Verify that passwords are not found on the identity provider’s list of commonly used, expected, or compromised passwords at the time users create or update passwords, as configured in the identity provider and defined in the Password Management Procedure [DU-2-PRO-717-020].
- Configure and maintain all systems to transmit passwords only over cryptographically protected channels, in accordance with the Secrets Management Subpolicy [DU-2-SUB-713-002].
- Configure and maintain all systems to store passwords only in cryptographically protected form, in accordance with the Secrets Management Subpolicy [DU-2-SUB-713-002].
- Enforce the organization-defined password composition and complexity rules for all accounts on systems that process, store, or transmit CUI, as defined in the Password Management Procedure [DU-2-PRO-717-020].
All Personnel must:
- Select a new password upon first use after account recovery, as enforced by the identity provider self-service reset flow defined in the Password Management Procedure [DU-2-PRO-717-020].
- Store and transmit passwords only through DroneUp-approved systems and tools, in accordance with the Secrets Management Subpolicy [DU-2-SUB-713-002].
9. Authentication Feedback
The Accountable Security Authority must:
- Verify that all DroneUp systems obscure authentication information — including masking passwords at entry — during the authentication process, and document verification findings during security assessments conducted in accordance with the Authentication Feedback Procedure [DU-2-PRO-717-021].
10. Authenticator Management
Information Systems Personnel must:
- Manage system authenticators across their full lifecycle — including initial issuance and identity verification, default authenticator change upon first use, enforcement of strength requirements, secure distribution, revocation upon separation or compromise, periodic refresh, and protection from unauthorized disclosure or use — as defined in the Authenticator Management Procedure [DU-2-PRO-717-022].
11. Exceptions
Exceptions to this policy are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].
12. Enforcement and Sanctions
Enforcement and sanctions are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].
Document control
| Document number | DU-1-POL-717-002 |
| Title | Identification and Authentication Policy |
| Classification | CBI |
| Owner | VP of Operations |
| Approval authority | Accountable Security Authority |
| Exec approval (verified) | John Vernon (CEO) · 2026-06-19 14:32 UTC · PR #2 |
| Effective date | 2026-06-24 |
| Revision | 1 |
| Review cycle | Annual; and upon Significant Change |
| Parent document | DU-1-POL-521-001 |
| Reviewed by | E. Bremer (2026-06-18) D. Gonzalez (2026-06-18) |