{"data":{"id":"IA-09","name":"Service Identification and Authentication","family":"IA","family_name":"Identification and Authentication","withdrawn":false,"description":"Uniquely identify and authenticate [Assignment: organization-defined system services and applications] before establishing communications with devices, users, or other services or applications.","supplemental_guidance":"Services that may require identification and authentication include web applications using digital certificates or services or applications that query a database. Identification and authentication methods for system services and applications include information or code signing, provenance graphs, and electronic signatures that indicate the sources of services. Decisions regarding the validity of identification and authentication claims can be made by services separate from the services acting on those decisions. This can occur in distributed system architectures. In such situations, the identification and authentication decisions (instead of actual identifiers and authentication data) are provided to the services that need to act on those decisions.","enhancements":[{"id":"IA-09(01)","name":"Information Exchange","withdrawn":true,"incorporated_into":["IA-09"]},{"id":"IA-09(02)","name":"Transmission of Decisions","withdrawn":true,"incorporated_into":["IA-09"]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"IA-09","name":"Service Identification and Authentication","description":"Uniquely identify and authenticate [Assignment: organization-defined system services and applications] before establishing communications with devices, users, or other services or applications.","discussion":"Services that may require identification and authentication include web applications using digital certificates or services or applications that query a database. Identification and authentication methods for system services and applications include information or code signing, provenance graphs, and electronic signatures that indicate the sources of services. Decisions regarding the validity of identification and authentication claims can be made by services separate from the services acting on those decisions. This can occur in distributed system architectures. In such situations, the identification and authentication decisions (instead of actual identifiers and authentication data) are provided to the services that need to act on those decisions.","related_controls":["IA-03","IA-04","IA-05","IA-13","SC-08"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-01","PR.AA-03"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":["3-3 SR 1.2"],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.11"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":["TME1.9.3"],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbuae":["CR-4"],"nca_ecc":["5-1"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1"],"bot_cyber":["Ch2.2"],"hipaa_sr":["§164.312(d)"],"cmmc_2":["IA"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":["Order 2222"],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FIA"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.10(h)"],"fda_cyber":["SA-1"],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1036","name":"Masquerading","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Service identification and authentication using digital certificates and verified service identities detect adversary masquerading by validating that services are who they claim to be, preventing impersonation of legitimate services."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authenticating services before establishing communications ensures that scripting interpreters and command execution environments are invoked only by verified, authorized services rather than adversary-controlled processes."},{"id":"T1525","name":"Implant Internal Image","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Requiring authentication of container images and deployment services before establishing trust prevents adversaries from implanting malicious code in internal images through unverified deployment pipelines."},{"id":"T1546","name":"Event Triggered Execution","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Service identification and authentication for event-triggered execution mechanisms ensures that only verified, authorized services can register event consumers, preventing adversary persistence through unauthorized event triggers."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Strong service authentication using digital certificates and trusted third-party verification directly counters trust subversion by ensuring services must cryptographically prove their identity before being trusted."},{"id":"T1554","name":"Compromise Host Software Binary","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Authenticating software binaries and services before establishing communication channels detects compromised host software by validating that executables match their expected cryptographic identities."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Service identification and authentication for email services—validating sender identity through DKIM, SPF, and DMARC—detects phishing attempts where adversaries impersonate legitimate services or organizations."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Authenticating services that request information from users enables detection of phishing-for-information attempts where adversaries impersonate legitimate services to elicit sensitive data."},{"id":"T1036.001","name":"Invalid Code Signature","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Service authentication through valid digital certificates detects binaries with invalid code signatures by requiring cryptographic identity verification before services establish trusted communications."},{"id":"T1036.005","name":"Match Legitimate Name or Location","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Service identification and authentication detect adversaries matching legitimate service names or locations by requiring services to prove identity through cryptographic mechanisms rather than relying solely on naming conventions."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Authenticating PowerShell remoting endpoints through Kerberos or certificate-based verification prevents adversaries from executing malicious PowerShell commands through impersonated service endpoints."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Service authentication for Apple Remote Management ensures AppleScript execution requests originate from verified management services, preventing adversary command execution through impersonated macOS management interfaces."},{"id":"T1213.003","name":"Code Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Authenticating code repository services before granting access ensures that repository access requests come from verified applications, preventing adversary data collection through impersonated repository interfaces."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Service identification that verifies dynamic library authenticity before loading prevents adversaries from adding unauthorized LC_LOAD_DYLIB entries that load malicious libraries through unverified library services."},{"id":"T1546.013","name":"PowerShell Profile","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Authenticating PowerShell profile execution contexts ensures that profile modifications originate from verified management services, detecting adversary-planted malicious profile content in unauthorized contexts."},{"id":"T1553.004","name":"Install Root Certificate","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Service identification through certificate chain validation detects rogue root certificate installations by verifying that certificate authorities are authenticated members of the trusted certificate hierarchy."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Service authentication for security telemetry pipelines ensures that event indicator sources are verified, preventing adversaries from injecting false data or blocking legitimate indicators through impersonated services."},{"id":"T1562.009","name":"Safe Mode Boot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Authenticating boot services ensures that safe mode boot requests originate from verified system components, detecting adversary attempts to force safe mode through unauthorized boot service manipulation."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Service identification that authenticates email sender identity through DKIM signatures and SPF validation detects spearphishing attachments from adversaries impersonating legitimate email services."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Authenticating web services referenced in email links through certificate validation and domain verification detects spearphishing links that direct users to adversary-controlled impersonation sites."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Service authentication for email systems detects spearphishing attachment delivery from adversaries impersonating legitimate services during reconnaissance by validating sender service identity."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Authenticating web services referenced in reconnaissance phishing links through certificate and domain verification detects adversary impersonation sites designed to harvest information."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: nist_csf_2 PR.AA-01 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-030","SP-032","SP-044","SP-046"]}}