Access Control and Identity Authentication - MARS-E v2.0
MARS-E MARS-E-Access-Control-Identity-Authentication-NIST-800-63-Identity-Assurance-Levels-MFA-AC-IA-Families: MARS-E Access Control + Identity + Authentication + NIST 800-63 + MFA + AC + IA Families
Implement NIST 800-53 AC Access Control family + IA Identification and Authentication family per MARS-E v2.0 catalog. NIST 800-63-3 Identity Assurance Level 2 (IAL2) + Authenticator Assurance Level 2 (AAL2) + Federation Assurance Level 2 (FAL2) for Exchange consumer authentication + IAL3 + AAL3 for administrative access. Identity proofing via Experian + LexisNexis + manual document review + biometric verification. Multi-Factor Authentication (MFA) mandatory for all administrative access + remote access + privileged operations. Role-Based Access Control (RBAC) with separation of duties (Eligibility Adjudicator + System Administrator + Privacy Officer + Security Officer). Least privilege enforcement. Account management lifecycle (provisioning + recertification + deprovisioning) with quarterly recertification. Privileged Access Management (PAM) with session recording for privileged users. Remote access via approved VPN + bastion host + jump server. Trust relationships with CMS Federal Data Services Hub + IRS + SSA + Department of Homeland Security + VLP (Verify Lawful Presence) coordinated through HHS Trust Framework.
What else in your programme already covers this
This control maps to 144 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.