← Controls / IA

IA-02 Identification and Authentication (Organizational Users)

Identification and Authentication

Low Moderate High

Description

Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.

Supplemental Guidance

Organizations can satisfy the identification and authentication requirements by complying with the requirements in [HSPD 12]. Organizational users include employees or individuals who organizations consider to have an equivalent status to employees (e.g., contractors and guest researchers). Unique identification and authentication of users applies to all accesses other than those that are explicitly identified in AC-14 and that occur through the authorized use of group authenticators without individual authentication. Since processes execute on behalf of groups and roles, organizations may require unique identification of individuals in group accounts or for detailed accountability of individual activity. Organizations employ passwords, physical authenticators, or biometrics to authenticate user identities or, in the case of multi-factor authentication, some combination thereof. Access to organizational systems is defined as either local access or network access. Local access is any access to organizational systems by users or processes acting on behalf of users, where access is obtained through direct connections without the use of networks. Network access is access to organizational systems by users (or processes acting on behalf of users) where access is obtained through network connections (i.e., nonlocal accesses). Remote access is a type of network access that involves communication through external networks. Internal networks include local area networks and wide area networks. The use of encrypted virtual private networks for network connections between organization-controlled endpoints and non-organization-controlled endpoints may be treated as internal networks with respect to protecting the confidentiality and integrity of information traversing the network. Identification and authentication requirements for non-organizational users are described in IA-8.

Enhancements (8)

What NIST adds to this control. Select one to read its statement.

IA-02(01) Multi-factor Authentication to Privileged Accounts LowModerateHigh

Implement multi-factor authentication for access to privileged accounts.

IA-02(02) Multi-factor Authentication to Non-privileged Accounts LowModerateHigh

Implement multi-factor authentication for access to non-privileged accounts.

IA-02(05) Individual Authentication with Group Authentication High

When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.

IA-02(06) Access to Accounts —separate Device

Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that: a. One of the factors is provided by a device separate from the system gaining access; and b. The device meets [Assignment: organization-defined strength of mechanism requirements].

IA-02(08) Access to Accounts — Replay Resistant LowModerateHigh

Implement replay-resistant authentication mechanisms for access to [Selection (one or more): privileged accounts; non-privileged accounts].

IA-02(10) Single Sign-on

Provide a single sign-on capability for [Assignment: organization-defined system accounts and services].

IA-02(12) Acceptance of PIV Credentials LowModerateHigh

Accept and electronically verify Personal Identity Verification-compliant credentials.

IA-02(13) Out-of-band Authentication

Implement the following out-of-band authentication mechanisms under [Assignment: organization-defined conditions]: [Assignment: organization-defined out-of-band authentication].

Withdrawn by NIST:

  • IA-02(03) Local Access to Privileged Accounts, now in IA-02(01)
  • IA-02(04) Local Access to Non-privileged Accounts, now in IA-02(02)
  • IA-02(07) Network Access to Non-privileged Accounts — Separate Device, now in IA-02(06)
  • IA-02(09) Network Access to Non-privileged Accounts — Replay Resistant, now in IA-02(08)
  • IA-02(11) Remote Access — Separate Device, now in IA-02(06)

MITRE ATT&CK Techniques (173)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 6 Execution 20 Persistence 53 Privilege Escalation 43 Defense Evasion 59 Credential Access 42 Discovery 6 Lateral Movement 18 Collection 11 Exfiltration 1 Impact 2
Show all 173 techniques grouped by tactic

Persistence

T1053 T1078 T1098 T1133 T1136 T1197 T1505 T1525 T1542 T1543 T1556 T1574 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.007 T1136.001 T1136.002 T1136.003 T1505.002 T1505.004 T1542.001 T1542.003 T1542.005 T1543.001 T1543.002 T1543.003 T1543.004 T1543.005 T1546.003 T1547.004 T1547.006 T1547.009 T1547.012 T1547.013 T1556.001 T1556.003 T1556.004 T1556.006 T1556.007 T1556.009 T1574.005 T1574.010 T1574.012

Privilege Escalation

Defense Evasion

T1055 T1078 T1134 T1197 T1218 T1222 T1484 T1542 T1548 T1550 T1556 T1562 T1574 T1578 T1599 T1601 T1610 T1036.007 T1036.010 T1055.008 T1078.002 T1078.003 T1078.004 T1134.001 T1134.002 T1134.003 T1218.007 T1222.001 T1222.002 T1542.001 T1542.003 T1542.005 T1548.002 T1548.003 T1550.001 T1550.002 T1550.003 T1556.001 T1556.003 T1556.004 T1556.006 T1556.007 T1556.009 T1562.001 T1562.002 T1562.004 T1562.006 T1562.007 T1562.008 T1562.009 T1574.005 T1574.010 T1574.012 T1578.001 T1578.002 T1578.003 T1599.001 T1601.001 T1601.002

Credential Access

Compliance Mappings

ISO 27001:2022

A.5.16A.8.5

ISO 27002:2022

5.168.5

COBIT 2019

DSS05

CIS Controls v8

CIS 5CIS 5.6CIS 6.3CIS 6.4CIS 6.5CIS 12.5CIS 12.7

NIST CSF 2.0

PR.AA-01PR.AA-03PR.AA-04

SOC 2 TSC

CC6.1CC6.1-POF3CC6.1-POF4CC6.1-POF8

PCI DSS v4.0.1

8.18.38.48.5

CSA CCM v4

IAM-10IAM-13IAM-14IAM-15

CSA AICM v1

IAM-10IAM-13IAM-14IAM-15IAM-17

FINOS CCC

CCC-C03CCC-C11

IEC 62443

3-3 SR 1.1

NIS2 Directive

Art. 21(2)(j)

MAS TRM

914

ASD Essential Eight

E8-7E8-7 ML1E8-7 ML2E8-7 ML3

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.10Hygiene.11Hygiene.12RGS.2.2SecNumCloud.10.5

FINMA Circular 2023/1

IV.B.d(59)IV.B.d(60)IV.C(61)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(b)Art.32(1)(d)

EU DORA

Art.9(4)(c)Art.9(4)(d)

BIO2

5.168.5

RBI CSF

Annex1.8Annex1.9ITGRCA.19

FISC Security Guidelines

FISC.T2FISC.T10FISC.T11

LGPD + BCB 4893

BCB.Art.3BCB.OpenFinanceBCB.PIXLGPD.Art.46

HKMA TM-E-1

TME1.8.2TME1.8.3TME1.8.5TME1.10.2TME1.10.4

MLPS 2.0

8.1.4.18.2

DNB Good Practice

DNB.17.1

EU CRA

CRA.I.2d

SWIFT CSCF

SWIFT.1.2SWIFT.4.2

SAMA CSF

3.1

NCA ECC

2-25-1

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CTO-1CTO-5

SA JS2

JS2-7.1JS2-8.1

CBN CSF

Part3.2Part5.2

BoG CISD

CISD-IXCISD-VIII

POPIA

s19

BoM CTRM

3.33.13

IOSCO Cyber Resilience

PROT-1

CPMI-IOSCO PFMI

CG.PRPFMI.P17

FFIEC IS

II.C.7(b)II.C.15II.C.15(a)II.C.15(b)II.C.15(c)II.C.16

NYDFS 500

500.7500.12

HIPAA Security Rule

§164.310(a)(2)(iii)§164.312(a)(2)(i)§164.312(d)

ECB CROE

CROE.2.3.1

EBA ICT Guidelines

3.4.23.8(b)

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2Ch8.2Ch9.1

CMMC 2.0

ACIA

NERC CIP

CIP-005-7

10 CFR 73.54

RG5.71-A-AC

TSA Pipeline SD

SD-2 Sec B

IEEE 1686-2022

5.1

FERC CIP Orders

Order 850

DOE C2M2 v2.1

ACCESS

API 1164

Sec 6

AWIA

AWWA Sec 3

IAEA NSS 17-T

Sec 5.2

PCI PTS v6

C

FIPS 140-3

FIPS 140-3 §7.4

Common Criteria

CC Part 2 — FIA

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.4

Lloyd's Minimum Standards

MS8.3

NAIC Insurance Data Security

4-access4B

PRA SS1/23

P-IT.1

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.a01.c

FDA 21 CFR Part 11

§11.10(d)§11.100(a)§11.200(a)(1)§11.200(a)(1)(ii)§11.200(a)(2)§11.200(a)(3)

FDA Cybersecurity Guidance

SA-1

ISO 27799

9.39.4H.5

NHS DSPT

NDG-4.1NDG-4.3

OWASP MASVS v2.1

MASVS-AUTH-1MASVS-AUTH-2MASVS-AUTH-3

CCSS v9.0

1.03.51.04.11.04.31.05.11.05.3

MiCA

Art.40(1)Art.55(1)Art.63(1)Art.67(1)Art.72(1)Art.76(1)

Basel SCO60

SCO60.62SCO60.66SCO60.71

BSSC Standards

GSP-11KMS-06NOS-05

SEC Custody (Digital Assets)

SEC-CD-03SEC-CD-05SEC-CD-16

India DPDPA

Act.8(5)Rules.6(1)(b)Rules.Sch1.B.7

ISO 17799 (legacy)

11.2.311.4.211.5.2

COBIT 4.1 (legacy)

AI2.4DS5.3