Belgium CyberFundamentals
Belgium CyberFundamentals: Protect

Belgium CyberFundamentals BE-CF-01: Account management and provisioning

Account management and provisioning. Implements CyFun PR.AC-1: identities and credentials for authorised devices, users and processes are issued, managed, verified, revoked and audited.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 20 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • AWWA-2.1 User Access Management
  • AWWA-2.3 Account Management
  • AWWA-2.4 Physical Access Controls

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • 62351-8 Role-based access control (RBAC)
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Belgium CyberFundamentals: Protect

Query this from an agent

The graph holds this control, the 20 it maps to, and the evidence behind each claim, over MCP and REST.