{"data":{"id":"IA-04","name":"Identifier Management","family":"IA","family_name":"Identification and Authentication","withdrawn":false,"description":"Manage system identifiers by:\na. Receiving authorization from [Assignment: organization-defined personnel or roles] to assign an individual, group, role, service, or device identifier;\nb. Selecting an identifier that identifies an individual, group, role, service, or device;\nc. Assigning the identifier to the intended individual, group, role, service, or device; and\nd. Preventing reuse of identifiers for [Assignment: organization-defined time period].","supplemental_guidance":"Common device identifiers include Media Access Control (MAC) addresses, Internet Protocol (IP) addresses, or device-unique token identifiers. The management of individual identifiers is not applicable to shared system accounts. Typically, individual identifiers are the usernames of the system accounts assigned to those individuals. In such instances, the account management activities of AC-02 use account names provided by IA-04. Identifier management also addresses individual identifiers not necessarily associated with system accounts. Preventing the reuse of identifiers implies preventing the assignment of previously used individual, group, role, service, or device identifiers to different individuals, groups, roles, services, or devices.","enhancements":[{"id":"IA-04(01)","name":"Prohibit Account Identifiers as Public Identifiers","statement":"Prohibit the use of system account identifiers that are the same as public identifiers for individual accounts.","baselines":[]},{"id":"IA-04(02)","name":"Supervisor Authorization","withdrawn":true,"incorporated_into":["IA-12(01)"]},{"id":"IA-04(03)","name":"Multiple Forms of Certification","withdrawn":true,"incorporated_into":["IA-12(02)"]},{"id":"IA-04(04)","name":"Identify User Status","statement":"Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status].","baselines":["moderate","high"]},{"id":"IA-04(05)","name":"Dynamic Management","statement":"Manage individual identifiers dynamically in accordance with [Assignment: organization-defined dynamic identifier policy].","baselines":[]},{"id":"IA-04(06)","name":"Cross-organization Management","statement":"Coordinate with the following external organizations for cross-organization management of identifiers: [Assignment: organization-defined external organizations].","baselines":[]},{"id":"IA-04(07)","name":"In-person Registration","withdrawn":true,"incorporated_into":["IA-12(04)"]},{"id":"IA-04(08)","name":"Pairwise Pseudonymous Identifiers","statement":"Generate pairwise pseudonymous identifiers.","baselines":[]},{"id":"IA-04(09)","name":"Attribute Maintenance and Protection","statement":"Maintain the attributes for each uniquely identified individual, device, or service in [Assignment: organization-defined protected central storage].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IA-04","name":"Identifier Management","description":"Manage system identifiers by:\na. Receiving authorization from [Assignment: organization-defined personnel or roles] to assign an individual, group, role, service, or device identifier;\nb. Selecting an identifier that identifies an individual, group, role, service, or device;\nc. Assigning the identifier to the intended individual, group, role, service, or device; and\nd. Preventing reuse of identifiers for [Assignment: organization-defined time period].","discussion":"Common device identifiers include Media Access Control (MAC) addresses, Internet Protocol (IP) addresses, or device-unique token identifiers. The management of individual identifiers is not applicable to shared system accounts. Typically, individual identifiers are the usernames of the system accounts assigned to those individuals. In such instances, the account management activities of AC-02 use account names provided by IA-04. Identifier management also addresses individual identifiers not necessarily associated with system accounts. Preventing the reuse of identifiers implies preventing the assignment of previously used individual, group, role, service, or device identifiers to different individuals, groups, roles, services, or devices.","related_controls":["AC-05","IA-02","IA-03","IA-05","IA-08","IA-09","IA-12","MA-04","PE-02","PE-03","PE-04","PL-04","PM-12","PS-03","PS-04","PS-05","SC-37"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Removed control step to disable the identifier and associated parameter"}},"compliance_mappings":{"iso_27001_2022":["A.5.16"],"iso_27002_2022":["5.16"],"cobit_2019":["DSS05"],"pci_dss_v4":["8.2"],"nist_csf_2":["PR.AA-01","PR.AA-02"],"cis_controls_v8":["CIS 5","CIS 5.5","CIS 6.6"],"soc2_tsc":["CC6.1","CC6.1-POF3","CC6.1-POF4","CC6.6","CC6.6-POF2","CC6.6-POF3"],"finos_ccc":["CCC-C11"],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.6","Hygiene.7","Hygiene.11","Hygiene.32","SecNumCloud.10.2"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.B.d(60)"],"gdpr":["Art.5(1)(f)","Art.32(1)(b)"],"dora":["Art.9(4)(c)","Art.9(4)(d)"],"bio2":["5.16"],"rbi_csf":["Annex1.8","ITGRCA.19"],"fisc":["FISC.T2"],"lgpd_bcb":[],"hkma_tme1":["TME1.8.1"],"mlps_2":["8.1.4.1"],"dnb_good_practice":["DNB.17.1","DNB.17.2"],"cra":["CRA.I.2d"],"swift_cscf":[],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-VIII"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1"],"cbn_csf":["Part3.2"],"popia":["s19"],"sa_js2":["JS2-7.1"],"bot_cyber":["Ch2.2"],"cpmi_pfmi":["CG.PR"],"eba_ict":["3.4.2"],"ecb_croe":["CROE.2.3.1"],"ffiec_is":["II.C.7(b)","II.C.15"],"hipaa_sr":["§164.308(a)(3)(ii)(C)","§164.308(a)(4)(ii)(C)","§164.308(a)(5)(ii)(D)","§164.312(a)(2)(i)","§164.312(d)"],"iosco_cyber":["PROT-1"],"nydfs_500":["500.7"],"sebi_cscrf":["PR.AA"],"cmmc_2":["AC","IA"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["ACCESS"],"api_1164":[],"awia":[],"iaea_nss":["Sec 5.2"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FIA"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.10(d)","§11.100(a)","§11.100(b)","§11.200(a)(2)","§11.300(a)","§11.300(c)"],"fda_cyber":["SA-1"],"hitrust_csf":["01.a","02.c"],"iso_27799":["7.3","9.3"],"lloyds_ms":["MS8.3"],"naic_ds":["4-access","4B"],"nhs_dspt":["NDG-4.1","NDG-4.2"],"pra_ss1_23":["P-IT.1"],"solvency_ii":["EIOPA-ICT-4.4"],"owasp_masvs_v2":[],"csa_ccm_v4":["IAM-03","IAM-06","IAM-13"],"csa_aicm":["IAM-03","IAM-06","IAM-13"],"ccss_v9":[],"mica":["Art.63(2)"],"basel_sco60":["SCO60.62"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management—including unique identification and timely disabling of inactive accounts—reduces the credential-dumping attack surface by ensuring that dormant or orphaned identifiers do not provide additional exploitable credential material."},{"id":"T1053","name":"Scheduled Task/Job","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identifier management with authorization controls ensures that scheduled tasks and jobs can only be created by properly identified and authorized users, preventing adversaries from scheduling persistent tasks under orphaned or shared identifiers."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Unique identifier management combined with timely deactivation of inactive accounts reduces the brute-force attack surface by eliminating dormant accounts that adversaries could target without triggering active-user alerting."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures that access to information repositories is tied to verified, individual identifiers, enabling accurate access controls and audit trails that detect unauthorized data collection."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures that application access tokens are bound to verified identities, enabling detection of token theft when tokens are used from systems or locations inconsistent with their assigned identifiers."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures cloud storage access is restricted to verified, authorized identifiers, preventing data collection through orphaned cloud accounts or shared credentials."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Identifier management with timely deactivation prevents transfer of data to cloud accounts using orphaned or unauthorized identifiers, ensuring only verified users can establish cross-account data-transfer connections."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures that system process creation and modification requires properly authorized identifiers, preventing adversaries from establishing persistent services using shared or orphaned account credentials."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier lifecycle management reduces unsecured credential exposure by ensuring that disused identifiers and their associated credentials are archived or revoked, not left accessible for adversary exploitation."},{"id":"T1562","name":"Impair Defenses","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures that modifications to security controls require authenticated, authorized identifiers, preventing adversaries from impairing defenses using anonymous or shared accounts."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management enables detection of remote session hijacking by tying sessions to unique identifiers, making it anomalous when a session is accessed from a different identity context."},{"id":"T1578","name":"Modify Cloud Compute Infrastructure","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures cloud compute modifications require verified identifiers, preventing adversaries from creating, modifying, or deleting cloud instances using orphaned or unauthorized cloud account credentials."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management restricts access to network device configuration by requiring verified identifiers for management-protocol access, preventing unauthorized configuration extraction."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Identifier management with timely account deactivation reduces cached domain credentials available for extraction by ensuring that dormant accounts do not accumulate stale cached logon material on workstations."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management restricts directory replication rights to verified domain controller identifiers, making DCSync attacks detectable when replication requests originate from non-DC identifiers."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures RDP access requires properly verified individual identifiers, preventing unauthorized remote desktop sessions through shared, default, or orphaned account credentials."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management restricts VNC access to verified identifiers, preventing adversaries from using shared or orphaned VNC credentials to establish unauthorized graphical remote control."},{"id":"T1053.002","name":"At","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures 'at' job creation requires authorized identifiers, preventing adversaries from scheduling persistent tasks through anonymous or orphaned batch-scheduling accounts."},{"id":"T1053.005","name":"Scheduled Task","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures scheduled task creation requires verified identifiers, enabling detection when tasks are created under orphaned or unauthorized account credentials."},{"id":"T1098.007","name":"Additional Local or Domain Groups","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identifier management prevents unauthorized group membership changes by ensuring group modifications require verified administrator identifiers, detecting adversary attempts to add themselves to privileged groups."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Unique identifier management with inactive-account disabling reduces password-guessing targets by eliminating dormant accounts from the authentication-attempt surface."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier lifecycle management reduces password-cracking value by ensuring that credentials associated with disabled identifiers cannot be used for authentication even if hashes are cracked offline."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Identifier management with unique-user identification makes password-spraying detectable by enabling per-account failed-authentication tracking that identifies systematic credential-testing patterns."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management reduces credential-stuffing effectiveness by ensuring that identifiers are unique to the organization, limiting the applicability of leaked credentials from external breaches."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures Confluence access is tied to verified identifiers, enabling detection of unauthorized data collection through access-pattern analysis against individual account baselines."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures SharePoint access requires verified identifiers, enabling access auditing and detection of anomalous document-library access patterns."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures CRM access requires verified identifiers, preventing unauthorized access to customer data through shared, default, or orphaned account credentials."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures messaging application access requires verified identifiers, enabling detection of unauthorized message access through per-user activity baselines."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures that kernel module installation requires verified administrative identifiers, preventing adversaries from loading rootkits or malicious extensions under unauthorized credentials."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management supports application-access-token validation by ensuring tokens are bound to verified identifiers, enabling detection when tokens are used outside their assigned identity context."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Identifier management with proper cloud identity controls restricts metadata API credential access to verified instance identifiers, preventing unauthorized credential harvesting from cloud environments."},{"id":"T1578.001","name":"Create Snapshot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures cloud snapshot creation requires verified identifiers, preventing adversaries from exfiltrating data by creating unauthorized snapshots of production volumes."},{"id":"T1578.002","name":"Create Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures cloud instance creation requires verified identifiers, preventing adversaries from spinning up unauthorized compute resources for cryptomining or pivot operations."},{"id":"T1578.003","name":"Delete Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures cloud instance deletion requires verified identifiers, preventing adversaries from destroying organizational resources through unauthorized teardown operations."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Identifier management ensures SNMP access requires authenticated identifiers (SNMPv3), preventing unauthorized MIB queries through community-string-based access that lacks individual accountability."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Proper identifier management ensures network device management requires verified individual identifiers, preventing unauthorized configuration extraction through shared or default management credentials."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-019","SP-021","SP-022","SP-028","SP-029","SP-030","SP-032","SP-033","SP-037","SP-044","SP-047","SP-051","SP-052"]}}