{"data":{"id":"IA-12","name":"Identity Proofing","family":"IA","family_name":"Identification and Authentication","withdrawn":false,"description":"a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines;\nb. Resolve user identities to a unique individual; and\nc. Collect, validate, and verify identity evidence.","supplemental_guidance":"Identity proofing is the process of collecting, validating, and verifying a user’s identity information for the purposes of establishing credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Standards and guidelines specifying identity assurance levels for identity proofing include [SP 800-63-3] and [SP 800-63A]. Organizations may be subject to laws, executive orders, directives, regulations, or policies that address the collection of identity evidence. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.","enhancements":[{"id":"IA-12(01)","name":"Supervisor Authorization","statement":"Require that the registration process to receive an account for logical access includes supervisor or sponsor authorization.","baselines":[]},{"id":"IA-12(02)","name":"Identity Evidence","statement":"Require evidence of individual identification be presented to the registration authority.","baselines":["moderate","high"]},{"id":"IA-12(03)","name":"Identity Evidence Validation and Verification","statement":"Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification].","baselines":["moderate","high"]},{"id":"IA-12(04)","name":"In-person Validation and Verification","statement":"Require that the validation and verification of identity evidence be conducted in person before a designated registration authority.","baselines":["high"]},{"id":"IA-12(05)","name":"Address Confirmation","statement":"Require that a [Selection (one): registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.","baselines":["moderate","high"]},{"id":"IA-12(06)","name":"Accept Externally-proofed Identities","statement":"Accept externally-proofed identities at [Assignment: organization-defined identity assurance level].","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IA-12","name":"Identity Proofing","description":"a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines;\nb. Resolve user identities to a unique individual; and\nc. Collect, validate, and verify identity evidence.","discussion":"Identity proofing is the process of collecting, validating, and verifying a user’s identity information for the purposes of establishing credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Standards and guidelines specifying identity assurance levels for identity proofing include [SP 800-63-3] and [SP 800-63A]. Organizations may be subject to laws, executive orders, directives, regulations, or policies that address the collection of identity evidence. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.","related_controls":["AC-05","IA-01","IA-02","IA-03","IA-04","IA-05","IA-06","IA-08","IA-13"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":true,"changes_from_rev4":"New control in Rev 5."}},"compliance_mappings":{"iso_27001_2022":["A.5.16"],"iso_27002_2022":["5.16"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-01","PR.AA-02"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":["Art.9(4)(d)"],"bio2":["5.16"],"rbi_csf":["Annex1.9"],"fisc":["FISC.T2"],"lgpd_bcb":[],"hkma_tme1":["TME1.8.3"],"mlps_2":[],"dnb_good_practice":["DNB.17.1"],"cra":["CRA.I.2d"],"swift_cscf":[],"cbb_tm":["TM-6"],"cbuae":["CR-4"],"nca_ecc":["2-2"],"qatar_nia":["AC"],"sama_csf":["3.1"],"uae_ia":["T9"],"bog_cisd":["CISD-IX"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-1"],"cbn_csf":["Part3.2"],"sa_js2":["JS2-7.1"],"bot_cyber":["Ch2.2"],"cpmi_pfmi":["CG.PR"],"eba_ict":["3.4.2"],"ecb_croe":["CROE.2.3.1"],"ffiec_is":["II.C.7(b)","II.C.15"],"hipaa_sr":["§164.312(d)"],"iosco_cyber":["PROT-1"],"sebi_cscrf":["PR.AA"],"cmmc_2":["IA"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["ACCESS"],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FIA"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.100(b)","§11.200(a)(3)"],"fda_cyber":["SA-1"],"hitrust_csf":[],"iso_27799":["9.3"],"lloyds_ms":["BP2.1","MS8.3"],"naic_ds":[],"nhs_dspt":["NDG-4.3"],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.4"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":["1.03.5","1.04.4"],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":["Act.9(1)","Rules.10","Rules.11"]},"attack_techniques":[{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identity proofing that verifies user identities before account provisioning prevents adversary acquisition of valid accounts by ensuring account creation requires verified real-world identity backed by validated evidence."},{"id":"T1078.002","name":"Domain Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identity proofing for domain account issuance—including government ID verification and organizational affiliation confirmation—prevents adversaries from obtaining legitimate domain credentials through identity fraud."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identity proofing requirements for local account provisioning ensure that local credentials are only issued to verified individuals, preventing adversary social engineering of account creation processes."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Identity proofing for cloud account provisioning—including multi-factor identity verification and organizational validation—prevents adversaries from fraudulently obtaining cloud credentials through identity impersonation."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: baselines LMH to -MH; Rev 5 baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-029","SP-032","SP-033","SP-044","SP-050","SP-052"]}}