Frameworks / ASD Strategies to Mitigate Cyber Security Incidents / ASD37-23 ASD Strategies to Mitigate Cyber Security Incidents
Limiting the Extent of Cyber Security Incidents
ASD Strategies to Mitigate Cyber Security Incidents ASD37-23: Protect authentication credentials (Excellent) Protect authentication credentials by removing them from memory when no longer needed. Use credential caching only when required. Centralise credential storage.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 168 controls across 98 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASBv3-DP-6 Use a secure key management process ASBv3-IM-2 Protect identity and authentication systems ASBv3-IM-8 Restrict the exposure of credential and secrets IM-1 Use centralized identity and authentication system NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts 8.6.3 8.6.3 System account passwords protected against misuse C5-IDM-08 Confidentiality of authentication information C5-IDM-09 Authentication mechanisms C5-PSS-07 Confidentiality of Authentication Information IA-5 Authenticator Management IA-5(6) Protection of Authenticators IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7)) IA-5 Authenticator Management IA-5(6) Protection of Authenticators IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7)) 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.4 Certificate Management CIS-5.6 Centralize Account Management CIS-6.7 Centralize Access Control FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 5.17 Authentication information 8.5 Secure authentication 5.17 Authentication information 8.5 Secure authentication BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security E8-ADMIN-ML3 Restrict Administrative Privileges (ML3) AMLCTF-35 Identity Verification Standard AWWA-2.2 Authentication Mechanisms BSI-03 Multi-factor authentication requirements BE-CF-03 Multi-factor authentication requirements DSO-3 Data Access Management Part11.300 Controls for identification codes and passwords (21 CFR §11.300) FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access ISO27799-12 Unique user identification and authentication 23837-1.7.3 Authentication and classical post-processing ISO27043-13 Authentication and password management 27400-6.1 Secure Device Design ISO21434-13 Authentication and password management MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPASVS-2 Authentication and Credential Storage (V2 + V2.4) DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PTESPHASE-2 Intelligence Gathering (OSINT) RCEPEC-1 Online Personal Information Protection (12.13) EHDSREG-6 Phased Application and Enforcement SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-1 Build Integrity - Source, Build, Provenance SOC2-CC6.1 CC6.1 Logical access security over protected information assets SSAE18-CC6.2 CC6.2 - New User Registration and Authorization CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification ISMSP-AC-03 Authentication Mechanisms TEFCAREC-1 Common Agreement Conformance and Onboarding TSAPIPE-2 OT/IT Network Segmentation and Access Control CE-SC.9 Device Unlocking Credentials and Brute-Force Protection UK-TSA-NET-02 Access Control and Authentication CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection WCAGREC-3 Principle 3: Understandable Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Limiting the Extent of Cyber Security Incidents You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done? ASD Strategies to Mitigate Cyber Security Incidents ASD37-23 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 168 it maps to, and the evidence behind each claim, over MCP and REST.