{"data":{"id":"IA-05","name":"Authenticator Management","family":"IA","family_name":"Identification and Authentication","withdrawn":false,"description":"Manage system authenticators by:\na. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator;\nb. Establishing initial authenticator content for any authenticators issued by the organization;\nc. Ensuring that authenticators have sufficient strength of mechanism for their intended use;\nd. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators;\ne. Changing default authenticators prior to first use;\nf. Changing or refreshing authenticators [Assignment: organization-defined time period by authenticator type] or when [Assignment: organization-defined events] occur;\ng. Protecting authenticator content from unauthorized disclosure and modification;\nh. Requiring individuals to take, and having devices implement, specific controls to protect authenticators; and\ni. Changing authenticators for group or role accounts when membership to those accounts changes.","supplemental_guidance":"Authenticators include passwords, cryptographic devices, biometrics, certificates, one-time password devices, and ID badges. Device authenticators include certificates and passwords. Initial authenticator content is the actual content of the authenticator (e.g., the initial password). In contrast, the requirements for authenticator content contain specific criteria or characteristics (e.g., minimum password length). Developers may deliver system components with factory default authentication credentials (i.e., passwords) to allow for initial installation and configuration. Default authentication credentials are often well known, easily discoverable, and present a significant risk. The requirement to protect individual authenticators may be implemented via control PL-04 or PS-06 for authenticators in the possession of individuals and by controls AC-03, AC-06, and SC-28 for authenticators stored in organizational systems, including passwords stored in hashed or encrypted formats or files containing encrypted or hashed passwords accessible with administrator privileges.\n\nSystems support authenticator management by organization-defined settings and restrictions for various authenticator characteristics (e.g., minimum password length, validation time window for time synchronous one-time tokens, and number of allowed rejections during the verification stage of biometric authentication). Actions can be taken to safeguard individual authenticators, including maintaining possession of authenticators, not sharing authenticators with others, and immediately reporting lost, stolen, or compromised authenticators. Authenticator management includes issuing and revoking authenticators for temporary access when no longer needed.","enhancements":[{"id":"IA-05(01)","name":"Password-based Authentication","statement":"For password-based authentication:\na. Maintain a list of commonly-used, expected, or compromised passwords and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised directly or indirectly;\nb. Verify, when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5(1)(a);\nc. Transmit passwords only over cryptographically-protected channels;\nd. Store passwords using an approved salted key derivation function, preferably using a keyed hash;\ne. Require immediate selection of a new password upon account recovery;\nf. Allow user selection of long passwords and passphrases, including spaces and all printable characters;\ng. Employ automated tools to assist the user in selecting strong password authenticators; and\nh. Enforce the following composition and complexity rules: [Assignment: organization-defined composition and complexity rules].","baselines":["low","moderate","high"]},{"id":"IA-05(02)","name":"Public Key-based Authentication","statement":"a. For public key-based authentication:\n1. Enforce authorized access to the corresponding private key; and\n2. Map the authenticated identity to the account of the individual or group; and\nb. When public key infrastructure (PKI) is used:\n1. Validate certificates by constructing and verifying a certification path to an accepted trust anchor, including checking certificate status information; and\n2. Implement a local cache of revocation data to support path discovery and validation.","baselines":["moderate","high"]},{"id":"IA-05(03)","name":"In-person or Trusted External Party Registration","withdrawn":true,"incorporated_into":["IA-12(04)"]},{"id":"IA-05(04)","name":"Automated Support for Password Strength Determination","withdrawn":true,"incorporated_into":["IA-05(01)"]},{"id":"IA-05(05)","name":"Change Authenticators Prior to Delivery","statement":"Require developers and installers of system components to provide unique authenticators or change default authenticators prior to delivery and installation.","baselines":[]},{"id":"IA-05(06)","name":"Protection of Authenticators","statement":"Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.","baselines":["moderate","high"]},{"id":"IA-05(07)","name":"No Embedded Unencrypted Static Authenticators","statement":"Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage.","baselines":[]},{"id":"IA-05(08)","name":"Multiple System Accounts","statement":"Implement [Assignment: organization-defined security controls] to manage the risk of compromise due to individuals having accounts on multiple systems.","baselines":[]},{"id":"IA-05(09)","name":"Federated Credential Management","statement":"Use the following external organizations to federate credentials: [Assignment: organization-defined external organizations].","baselines":[]},{"id":"IA-05(10)","name":"Dynamic Credential Binding","statement":"Bind identities and authenticators dynamically using the following rules: [Assignment: organization-defined binding rules].","baselines":[]},{"id":"IA-05(11)","name":"Hardware Token-based Authentication","withdrawn":true,"incorporated_into":["IA-02(01)","IA-02(02)"]},{"id":"IA-05(12)","name":"Biometric Authentication Performance","statement":"For biometric-based authentication, employ mechanisms that satisfy the following biometric quality requirements [Assignment: organization-defined biometric quality requirements].","baselines":[]},{"id":"IA-05(13)","name":"Expiration of Cached Authenticators","statement":"Prohibit the use of cached authenticators after [Assignment: organization-defined time period].","baselines":[]},{"id":"IA-05(14)","name":"Managing Content of PKI Trust Stores","statement":"For PKI-based authentication, employ an organization-wide methodology for managing the content of PKI trust stores installed across all platforms, including networks, operating systems, browsers, and applications.","baselines":[]},{"id":"IA-05(15)","name":"GSA-approved Products and Services","statement":"Use only General Services Administration-approved products and services for identity, credential, and access management.","baselines":[]},{"id":"IA-05(16)","name":"In-person or Trusted External Party Authenticator Issuance","statement":"Require that the issuance of [Assignment: organization-defined types of and/or specific authenticators] be conducted [Selection (one): in person; by a trusted external party] before [Assignment: organization-defined registration authority] with authorization by [Assignment: organization-defined personnel or roles].","baselines":[]},{"id":"IA-05(17)","name":"Presentation Attack Detection for Biometric Authenticators","statement":"Employ presentation attack detection mechanisms for biometric-based authentication.","baselines":[]},{"id":"IA-05(18)","name":"Password Managers","statement":"a. Employ [Assignment: organization-defined password managers] to generate and manage passwords; and\nb. Protect the passwords using [Assignment: organization-defined controls].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IA-05","name":"Authenticator Management","description":"Manage system authenticators by:\na. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, service, or device receiving the authenticator;\nb. Establishing initial authenticator content for any authenticators issued by the organization;\nc. Ensuring that authenticators have sufficient strength of mechanism for their intended use;\nd. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators;\ne. Changing default authenticators prior to first use;\nf. Changing or refreshing authenticators [Assignment: organization-defined time period by authenticator type] or when [Assignment: organization-defined events] occur;\ng. Protecting authenticator content from unauthorized disclosure and modification;\nh. Requiring individuals to take, and having devices implement, specific controls to protect authenticators; and\ni. Changing authenticators for group or role accounts when membership to those accounts changes.","discussion":"Authenticators include passwords, cryptographic devices, biometrics, certificates, one-time password devices, and ID badges. Device authenticators include certificates and passwords. Initial authenticator content is the actual content of the authenticator (e.g., the initial password). In contrast, the requirements for authenticator content contain specific criteria or characteristics (e.g., minimum password length). Developers may deliver system components with factory default authentication credentials (i.e., passwords) to allow for initial installation and configuration. Default authentication credentials are often well known, easily discoverable, and present a significant risk. The requirement to protect individual authenticators may be implemented via control PL-04 or PS-06 for authenticators in the possession of individuals and by controls AC-03, AC-06, and SC-28 for authenticators stored in organizational systems, including passwords stored in hashed or encrypted formats or files containing encrypted or hashed passwords accessible with administrator privileges.\n\nSystems support authenticator management by organization-defined settings and restrictions for various authenticator characteristics (e.g., minimum password length, validation time window for time synchronous one-time tokens, and number of allowed rejections during the verification stage of biometric authentication). Actions can be taken to safeguard individual authenticators, including maintaining possession of authenticators, not sharing authenticators with others, and immediately reporting lost, stolen, or compromised authenticators. Authenticator management includes issuing and revoking authenticators for temporary access when no longer needed.","related_controls":["AC-03","AC-06","CM-06","IA-02","IA-04","IA-07","IA-08","IA-09","MA-04","PE-02","PL-04","SC-12","SC-13"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Removes requirement to change default content of authenticators prior to information system installation New parameter requires specifying events that require changing or refreshing authenticators Changes 'security safeguards' to 'controls' Discussion includes new examples"}},"compliance_mappings":{"iso_27001_2022":["A.5.16","A.5.17","A.8.5"],"iso_27002_2022":["5.16","5.17","8.5"],"cobit_2019":["DSS05"],"pci_dss_v4":["2.2.1","2.2.2","8.2","8.3","8.3.6","8.3.9","8.6"],"nist_csf_2":["PR.AA-01","PR.AA-02","PR.AA-03","PR.AA-04"],"cis_controls_v8":["CIS 4.7","CIS 5","CIS 5.2","CIS 14.3"],"soc2_tsc":["CC6.1"],"finos_ccc":["CCC-C11"],"iso_42001_2023":[],"iec_62443":["3-3 SR 1.1","3-3 SR 1.5","3-3 SR 1.7"],"asd_e8":["E8-5 ML3","E8-7"],"nis2":[],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.10","Hygiene.12","RGS.2.2","SecNumCloud.10.5"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.B.d(60)","IV.C(61)"],"gdpr":["Art.32(1)(a)","Art.32(1)(b)"],"dora":["Art.9(3)","Art.9(4)(c)","Art.9(4)(d)"],"bio2":["5.16","5.17","8.5"],"rbi_csf":["Annex1.8","Annex1.9","ITGRCA.19"],"fisc":["FISC.T2","FISC.T10"],"lgpd_bcb":["BCB.Art.3","BCB.OpenFinance","BCB.PIX","LGPD.Art.46"],"hkma_tme1":["TME1.8.2","TME1.8.3","TME1.10.4"],"mlps_2":["8.1.4.1","8.1.10.7"],"dnb_good_practice":["DNB.17.1","DNB.17.2"],"cra":["CRA.I.2d"],"swift_cscf":["SWIFT.4.1","SWIFT.4.2","SWIFT.5.2","SWIFT.5.4"],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-IX","CISD-VIII"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1","CTO-5"],"cbn_csf":["Part3.2"],"popia":["s19"],"sa_js2":["JS2-7.1","JS2-8.1"],"bot_cyber":["Ch2.2"],"cpmi_pfmi":["CG.PR","PFMI.P17"],"eba_ict":["3.4.2","3.8(b)"],"ecb_croe":["CROE.2.3.1"],"ffiec_is":["II.C.7(b)","II.C.15","II.C.15(a)"],"hipaa_sr":["§164.308(a)(4)(ii)(C)","§164.308(a)(5)(ii)(D)","§164.312(d)"],"iosco_cyber":["PROT-1"],"nydfs_500":["500.7","500.12"],"sebi_cscrf":["PR.AA"],"cmmc_2":["AC","IA"],"nerc_cip":["CIP-007-6"],"nrc_73_54":["RG5.71-A-AC"],"tsa_psd":["SD-2 Sec B"],"ieee_1686":["5.1","5.7"],"ferc_cip":[],"doe_c2m2":["ACCESS"],"api_1164":["Sec 6"],"awia":["AWWA Sec 3"],"iaea_nss":["Sec 5.2"],"pci_pts":[],"fips_140":["FIPS 140-3 §7.4","FIPS 140-3 §7.9"],"cbest":[],"tiber_eu":[],"pci_hsm":["9"],"common_criteria":["CC Part 2 — FIA"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.10(d)","§11.100(a)","§11.100(b)","§11.200(a)(1)","§11.200(a)(1)(ii)","§11.200(a)(2)","§11.300(a)","§11.300(b)","§11.300(c)","§11.300(e)"],"fda_cyber":["SA-1"],"hitrust_csf":["01.a","01.c"],"iso_27799":["9.3","9.4"],"lloyds_ms":["MS8.3"],"naic_ds":["4-access","4B"],"nhs_dspt":["NDG-4.1","NDG-4.2","NDG-4.3"],"pra_ss1_23":["P-IT.1"],"solvency_ii":["EIOPA-ICT-4.4"],"owasp_masvs_v2":["MASVS-AUTH-1","MASVS-AUTH-2","MASVS-NETWORK-2"],"csa_ccm_v4":["IAM-02","IAM-06","IAM-14","IAM-15"],"csa_aicm":["IAM-02","IAM-06","IAM-14","IAM-15"],"ccss_v9":["1.04.1","1.04.2","1.06.2"],"mica":["Art.40(1)","Art.55(1)","Art.63(1)","Art.67(1)","Art.76(1)"],"basel_sco60":["SCO60.61","SCO60.62","SCO60.66"],"bssc":["GSP-11","KMS-06","KMS-07","KMS-08","NOS-05","NOS-08"],"sec_custody_digital":["SEC-CD-02","SEC-CD-03","SEC-CD-05","SEC-CD-06","SEC-CD-07","SEC-CD-16"],"dpdpa":["Rules.6(1)(b)"]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper authenticator management—including encrypted credential storage, regular rotation, and prohibition of reversible encryption—reduces the value of dumped credentials by ensuring they expire quickly and resist offline cracking."},{"id":"T1021","name":"Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Strong authenticator management requiring MFA for remote services, complex passwords, and certificate-based authentication raises the bar for adversary lateral movement by making credential reuse across remote services significantly harder."},{"id":"T1040","name":"Network Sniffing","tactics":["credential-access","discovery"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management that enforces encrypted authentication protocols and prohibits cleartext credential transmission reduces the value of network sniffing by ensuring captured traffic does not contain usable plaintext credentials."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication for software deployment tool access—including unique service credentials, regular rotation, and MFA—prevents adversaries from leveraging weak or shared deployment tool credentials for lateral execution."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Disciplined authenticator lifecycle management—including credential rotation, complexity enforcement, and revocation upon personnel changes—limits adversary exploitation of valid accounts by reducing the window of credential viability."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Password complexity requirements, minimum length enforcement, prohibited password lists, and account lockout policies directly counter brute force attacks by exponentially increasing the computational cost of password guessing."},{"id":"T1111","name":"Multi-Factor Authentication Interception","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Managing MFA authenticators with phishing-resistant methods such as FIDO2/WebAuthn, hardware tokens, and certificate-based authentication reduces vulnerability to MFA interception by eliminating interceptable one-time codes."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management enforcing strong, unique credentials for email access and requiring MFA for remote email protocols limits adversary email collection by preventing unauthorized mailbox access with stolen passwords."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Strong authenticator requirements for external remote services—including MFA, certificate-based authentication, and regular credential rotation—limit adversary exploitation of remote access gateways for initial access and persistence."},{"id":"T1136","name":"Create Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management policies that enforce strong initial credentials, prohibit default passwords, and require immediate rotation of provisioned credentials reduce the risk of adversary-created accounts with weak, predictable passwords."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Robust authenticator management that patches authentication infrastructure, enforces modern authentication protocols, and eliminates legacy authentication mechanisms reduces the attack surface for credential access exploitation."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Managing application access tokens with short lifetimes, scope restrictions, and regular rotation limits the impact of stolen tokens by ensuring compromised tokens expire before adversaries can fully exploit them."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management for cloud storage—including strong access keys, SAS token expiration, and service principal credential rotation—limits adversary access to cloud data by reducing the viability of compromised storage credentials."},{"id":"T1539","name":"Steal Web Session Cookie","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Session cookie management with secure attributes, short lifetimes, and binding to client characteristics reduces the utility of stolen web session cookies by ensuring they expire quickly and cannot be replayed from different contexts."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management that prohibits storing credentials in plaintext, enforces secrets management solutions, and audits credential storage practices directly reduces the availability of unsecured credentials for adversary discovery."},{"id":"T1555","name":"Credentials from Password Stores","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Managing authenticators with unique, complex passwords per service and enforcing password manager usage with strong master credentials reduces the impact of password store compromise by limiting credential reuse across systems."},{"id":"T1556","name":"Modify Authentication Process","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management that validates authentication process integrity, enforces signed authentication modules, and monitors for unauthorized changes to authentication configurations detects and prevents authentication process modification."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong Kerberos authenticator management—including long, random service account passwords, AES encryption enforcement, and regular keytab rotation—makes Kerberos ticket forging and cracking computationally infeasible."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management for network devices—including strong enable secrets, certificate-based management access, and regular credential rotation—prevents adversaries from accessing network devices to bridge security boundaries."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requirements for network device management—including MFA and certificate-based access—prevent unauthorized system image modifications by ensuring only properly authenticated administrators can alter firmware."},{"id":"T1621","name":"Multi-Factor Authentication Request Generation","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management implementing number-matching MFA, phishing-resistant authenticators, and MFA fatigue protections directly counters MFA prompt bombing by requiring user verification of authentication context before approval."},{"id":"T1649","name":"Steal or Forge Authentication Certificates","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Certificate lifecycle management—including short validity periods, certificate pinning, revocation checking, and HSM-backed private keys—limits adversary ability to steal or forge authentication certificates for unauthorized access."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Credential protection through Credential Guard, LSASS protections, and elimination of cleartext credential caching reduces the value of LSASS memory dumps by ensuring credentials stored in memory are encrypted or isolated."},{"id":"T1003.002","name":"Security Account Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing strong password hashing algorithms and eliminating LM hash storage in the SAM database reduces the effectiveness of SAM credential extraction by making offline hash cracking computationally expensive."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong domain password policies and regular credential rotation limit the impact of NTDS.dit extraction by ensuring that dumped Active Directory password hashes expire before adversaries can crack and use them."},{"id":"T1003.004","name":"LSA Secrets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management that avoids storing service credentials as LSA Secrets where possible and enforces managed service accounts reduces the credential material available for extraction from LSA secret storage."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Limiting the number of cached domain logons and enforcing strong password policies reduces the value of cached credential extraction by minimizing the number of cached hashes and increasing cracking difficulty."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong service account passwords and enforcement of AES Kerberos encryption make DCSync-extracted password hashes significantly more resistant to offline cracking, limiting the practical impact of directory replication attacks."},{"id":"T1003.007","name":"Proc Filesystem","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management ensuring applications do not store plaintext credentials in memory—combined with short-lived tokens and credential isolation—reduces credential material available for extraction via /proc filesystem reads."},{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing strong password hashing (SHA-512 with salt) in /etc/shadow and restricting file permissions limits the utility of /etc/passwd and /etc/shadow extraction by making offline hash cracking computationally prohibitive."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Requiring NLA (Network Level Authentication), strong passwords, and MFA for RDP access limits adversary lateral movement through Remote Desktop by ensuring stolen credentials alone are insufficient for remote logon."},{"id":"T1021.004","name":"SSH","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"SSH key management—including passphrase-protected keys, regular key rotation, and centralized authorized_keys governance—limits adversary SSH lateral movement by reducing the availability of exploitable SSH credentials."},{"id":"T1021.007","name":"Cloud Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management for cloud service access—including federated identity with MFA, conditional access, and regular token rotation—limits adversary lateral movement through cloud services using compromised credentials."},{"id":"T1021.008","name":"Direct Cloud VM Connections","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Strong authentication requirements for direct cloud VM access—including IAM-based authentication, serial console restrictions, and MFA—prevent adversary access to cloud instances through compromised cloud credentials."},{"id":"T1078.002","name":"Domain Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Domain credential management with password complexity, history enforcement, regular rotation, and MFA reduces the window of domain account exploitation by ensuring compromised passwords expire and cannot be easily reused."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Cloud credential management with federated identity, short-lived tokens, conditional access policies, and MFA significantly limits adversary exploitation of cloud accounts by adding multiple verification layers beyond passwords."},{"id":"T1098.001","name":"Additional Cloud Credentials","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management policies that audit and restrict credential creation in cloud IAM—including API key generation and OAuth token issuance—prevent adversary persistence through unauthorized additional cloud credentials."},{"id":"T1098.002","name":"Additional Email Delegate Permissions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Managing email delegations as part of authenticator governance—including regular review and approval workflows for mailbox permissions—prevents adversaries from silently adding email delegate permissions for persistent access."},{"id":"T1098.003","name":"Additional Cloud Roles","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Cloud role management policies that require approval workflows, enforce least privilege, and audit role assignments prevent adversary persistence and privilege escalation through unauthorized cloud role additions."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"SSH authorized_keys management—including centralized key governance, regular audits, and automated removal of orphaned keys—prevents adversary persistence through unauthorized SSH key installations on target systems."},{"id":"T1098.006","name":"Additional Container Cluster Roles","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Container cluster role management with RBAC auditing, role binding reviews, and principle of least privilege prevents adversaries from escalating privileges through unauthorized container cluster role assignments."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Password policies enforcing minimum length, complexity requirements, and account lockout after failed attempts directly counter password guessing by making successful guessing statistically improbable within lockout thresholds."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing strong, salted password hashing algorithms (bcrypt, scrypt, Argon2) and eliminating weak hash storage makes offline password cracking computationally prohibitive even when adversaries obtain hash databases."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Password policies prohibiting commonly used passwords, enforcing complexity, and implementing intelligent lockout mechanisms counter password spraying by ensuring that common passwords fail validation and trigger alerts."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Credential management policies requiring unique passwords per service and monitoring for breach correlation prevent credential stuffing by ensuring compromised credentials from external breaches are not reusable."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Strong authenticator management for remote email access—including application-specific passwords, MFA, and conditional access—prevents adversary remote email collection by raising authentication requirements beyond stolen passwords."},{"id":"T1136.001","name":"Local Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management policies that enforce strong initial passwords and integrate account creation with identity governance prevent adversary creation of local accounts with weak, easily exploitable credentials."},{"id":"T1136.002","name":"Domain Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Domain account provisioning policies that require identity verification, approval workflows, and strong initial authenticator assignment prevent adversary creation of domain accounts through unauthorized channels."},{"id":"T1136.003","name":"Cloud Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Cloud account provisioning with identity proofing, MFA enrollment requirements, and strong initial credential policies prevents adversary creation of cloud accounts that persist undetected."},{"id":"T1550.003","name":"Pass the Ticket","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Kerberos authenticator management with AES encryption, short ticket lifetimes, and PAC validation makes pass-the-ticket attacks less viable by limiting ticket reuse windows and enabling detection of forged tickets."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management that prohibits plaintext credential storage in files, enforces secrets management solutions, and scans for credential leakage directly eliminates the source material for credentials-in-files attacks."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Policies prohibiting credential storage in Windows registry keys and enforcing migration to managed credential stores eliminate the source of registry-stored credentials targeted by adversary credential harvesting."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Private key management enforcing passphrase protection, hardware security modules for key storage, and regular key rotation limits the utility of stolen private keys by adding layers of protection beyond file access."},{"id":"T1552.006","name":"Group Policy Preferences","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Eliminating Group Policy Preferences credentials through LAPS deployment and modern credential management removes the cpassword-based credential exposure that adversaries exploit in legacy GPP configurations."},{"id":"T1555.001","name":"Keychain","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Keychain management with strong master passwords, access control lists on keychain items, and hardware-backed credential storage on macOS limits adversary credential extraction from Apple Keychain stores."},{"id":"T1555.002","name":"Securityd Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management that minimizes credential caching in securityd memory and enforces hardware-backed credential isolation reduces the credential material available for extraction from macOS securityd process memory."},{"id":"T1555.004","name":"Windows Credential Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Credential Manager governance with regular credential audits, expiration policies, and migration to modern credential storage reduces the stored credential inventory available for extraction from Windows Credential Manager."},{"id":"T1555.005","name":"Password Managers","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Password manager management with strong master credentials, hardware-backed key storage, and zero-knowledge architecture limits the impact of password manager targeting by ensuring robust protection of the master credential vault."},{"id":"T1556.001","name":"Domain Controller Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management validating domain controller authentication DLL integrity, monitoring NTLM configuration, and enforcing Kerberos-only authentication detects and prevents skeleton key-style DC authentication modification."},{"id":"T1556.003","name":"Pluggable Authentication Modules","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"PAM authenticator management enforcing signed module validation, configuration file integrity monitoring, and restricted PAM directory access prevents adversary insertion of malicious pluggable authentication modules."},{"id":"T1556.004","name":"Network Device Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network device authenticator management enforcing TACACS+ with encrypted authentication, regular credential rotation, and configuration integrity monitoring prevents adversary modification of network device authentication."},{"id":"T1556.005","name":"Reversible Encryption","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management policies that prohibit reversible encryption storage, enforce modern password hashing, and audit for reversible encryption configurations eliminate the credential exposure that reversible encryption enables."},{"id":"T1556.009","name":"Conditional Access Policies","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Conditional access policy management with change auditing, approval workflows, and configuration monitoring prevents adversary weakening of authentication requirements through unauthorized policy modifications."},{"id":"T1558.001","name":"Golden Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Strong krbtgt account password management with regular rotation (at minimum every 180 days), long random passwords, and AES encryption enforcement makes golden ticket forgery detectable and limits the viability of forged TGTs."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Service account authenticator management with long, random passwords and AES Kerberos encryption makes silver ticket forging computationally infeasible by requiring adversaries to crack strong service account passwords."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Service account password management with 25+ character random passwords and enforced AES encryption makes Kerberoasting impractical by ensuring that extracted service ticket hashes resist offline cracking attempts."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ensuring all accounts require Kerberos pre-authentication and using strong encryption eliminates the AS-REP roasting attack vector by preventing adversaries from requesting encrypted data without proving identity."},{"id":"T1558.005","name":"Ccache Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Credential cache management with restricted file permissions on ccache files, short ticket lifetimes, and regular cache cleanup reduces the utility of stolen Kerberos ccache files for authentication reuse."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"SSH authenticator management enforcing key-based authentication, disabling agent forwarding by default, and requiring re-authentication for session resumption limits adversary ability to hijack established SSH sessions."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong authenticator requirements for network device management—including MFA and certificate-based access—prevent adversaries from accessing network devices to create unauthorized NAT rules that bridge security boundaries."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authenticator management requiring cryptographic authentication for firmware updates—including signed firmware enforcement and multi-factor administrative access—prevents unauthorized patching of network device system images."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong administrative authentication for network devices combined with firmware version enforcement and signed image requirements prevents adversary downgrade of system images to vulnerable versions."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.AA-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-011","SP-012","SP-015","SP-022","SP-027","SP-028","SP-029","SP-030","SP-031","SP-032","SP-033","SP-034","SP-037","SP-039","SP-040","SP-041","SP-044","SP-047","SP-050","SP-052","SP-054"]}}