← Controls / IA

IA-04 Identifier Management

Identification and Authentication

Low Moderate High

Description

Manage system identifiers by: a. Receiving authorization from [Assignment: organization-defined personnel or roles] to assign an individual, group, role, service, or device identifier; b. Selecting an identifier that identifies an individual, group, role, service, or device; c. Assigning the identifier to the intended individual, group, role, service, or device; and d. Preventing reuse of identifiers for [Assignment: organization-defined time period].

Supplemental Guidance

Common device identifiers include Media Access Control (MAC) addresses, Internet Protocol (IP) addresses, or device-unique token identifiers. The management of individual identifiers is not applicable to shared system accounts. Typically, individual identifiers are the usernames of the system accounts assigned to those individuals. In such instances, the account management activities of AC-02 use account names provided by IA-04. Identifier management also addresses individual identifiers not necessarily associated with system accounts. Preventing the reuse of identifiers implies preventing the assignment of previously used individual, group, role, service, or device identifiers to different individuals, groups, roles, services, or devices.

Changes from Rev 4

Removed control step to disable the identifier and associated parameter

Enhancements (6)

What NIST adds to this control. Select one to read its statement.

IA-04(01) Prohibit Account Identifiers as Public Identifiers

Prohibit the use of system account identifiers that are the same as public identifiers for individual accounts.

IA-04(04) Identify User Status ModerateHigh

Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status].

IA-04(05) Dynamic Management

Manage individual identifiers dynamically in accordance with [Assignment: organization-defined dynamic identifier policy].

IA-04(06) Cross-organization Management

Coordinate with the following external organizations for cross-organization management of identifiers: [Assignment: organization-defined external organizations].

IA-04(08) Pairwise Pseudonymous Identifiers

Generate pairwise pseudonymous identifiers.

IA-04(09) Attribute Maintenance and Protection

Maintain the attributes for each uniquely identified individual, device, or service in [Assignment: organization-defined protected central storage].

Withdrawn by NIST:

  • IA-04(02) Supervisor Authorization, now in IA-12(01)
  • IA-04(03) Multiple Forms of Certification, now in IA-12(02)
  • IA-04(07) In-person Registration, now in IA-12(04)

MITRE ATT&CK Techniques (36)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Execution 3 Persistence 6 Privilege Escalation 6 Defense Evasion 6 Credential Access 11 Lateral Movement 4 Collection 9 Exfiltration 1
Show all 36 techniques grouped by tactic

Compliance Mappings

ISO 27001:2022

A.5.16

ISO 27002:2022

5.16

COBIT 2019

DSS05

CIS Controls v8

CIS 5CIS 5.5CIS 6.6

NIST CSF 2.0

PR.AA-01PR.AA-02

SOC 2 TSC

CC6.1CC6.1-POF3CC6.1-POF4CC6.6CC6.6-POF2CC6.6-POF3

PCI DSS v4.0.1

8.2

CSA CCM v4

IAM-03IAM-06IAM-13

CSA AICM v1

IAM-03IAM-06IAM-13

FINOS CCC

CCC-C11

MAS TRM

9

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.6Hygiene.7Hygiene.11Hygiene.32SecNumCloud.10.2

FINMA Circular 2023/1

IV.B.d(59)IV.B.d(60)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(b)

EU DORA

Art.9(4)(c)Art.9(4)(d)

BIO2

5.16

RBI CSF

Annex1.8ITGRCA.19

FISC Security Guidelines

FISC.T2

HKMA TM-E-1

TME1.8.1

MLPS 2.0

8.1.4.1

DNB Good Practice

DNB.17.1DNB.17.2

EU CRA

CRA.I.2d

SAMA CSF

3.1

NCA ECC

2-2

UAE IA

T9

CBB TM

TM-6

Qatar NIA

AC

CBUAE

CR-4

CBE CSF

CTO-1

SA JS2

JS2-7.1

CBN CSF

Part3.2

BoG CISD

CISD-VIII

POPIA

s19

BoM CTRM

3.3

IOSCO Cyber Resilience

PROT-1

CPMI-IOSCO PFMI

CG.PR

FFIEC IS

II.C.7(b)II.C.15

NYDFS 500

500.7

HIPAA Security Rule

§164.308(a)(3)(ii)(C)§164.308(a)(4)(ii)(C)§164.308(a)(5)(ii)(D)§164.312(a)(2)(i)§164.312(d)

ECB CROE

CROE.2.3.1

EBA ICT Guidelines

3.4.2

SEBI CSCRF

PR.AA

BOT Cyber Resilience

Ch2.2

CMMC 2.0

ACIA

DOE C2M2 v2.1

ACCESS

IAEA NSS 17-T

Sec 5.2

Common Criteria

CC Part 2 — FIA

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.4

Lloyd's Minimum Standards

MS8.3

NAIC Insurance Data Security

4-access4B

PRA SS1/23

P-IT.1

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.a02.c

FDA 21 CFR Part 11

§11.10(d)§11.100(a)§11.100(b)§11.200(a)(2)§11.300(a)§11.300(c)

FDA Cybersecurity Guidance

SA-1

ISO 27799

7.39.3

NHS DSPT

NDG-4.1NDG-4.2

MiCA

Art.63(2)

Basel SCO60

SCO60.62

ISO 17799 (legacy)

11.2.311.5.2

COBIT 4.1 (legacy)

DS5.3DS5.4