MARS-E
Access Control and Identity Authentication - MARS-E v2.0

MARS-E MARS-E-Access-Control-Identity-Authentication-NIST-800-63-Identity-Assurance-Levels-MFA-AC-IA-Families: MARS-E Access Control + Identity + Authentication + NIST 800-63 + MFA + AC + IA Families

Implement NIST 800-53 AC Access Control family + IA Identification and Authentication family per MARS-E v2.0 catalog. NIST 800-63-3 Identity Assurance Level 2 (IAL2) + Authenticator Assurance Level 2 (AAL2) + Federation Assurance Level 2 (FAL2) for Exchange consumer authentication + IAL3 + AAL3 for administrative access. Identity proofing via Experian + LexisNexis + manual document review + biometric verification. Multi-Factor Authentication (MFA) mandatory for all administrative access + remote access + privileged operations. Role-Based Access Control (RBAC) with separation of duties (Eligibility Adjudicator + System Administrator + Privacy Officer + Security Officer). Least privilege enforcement. Account management lifecycle (provisioning + recertification + deprovisioning) with quarterly recertification. Privileged Access Management (PAM) with session recording for privileged users. Remote access via approved VPN + bastion host + jump server. Trust relationships with CMS Federal Data Services Hub + IRS + SSA + Department of Homeland Security + VLP (Verify Lawful Presence) coordinated through HHS Trust Framework.

What else in your programme already covers this

This control maps to 144 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 13485 · 6 controls

ISO 27799 · 5 controls

ISO 27043 · 4 controls

ISO/SAE 21434 · 4 controls

  • 3.10 Encrypt Sensitive Data in Transit
  • 3.7 Establish and Maintain a Data Classification Scheme
  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data
  • 3.9 Encrypt Data on Removable Media

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27010:2015 · 3 controls

OWASP Top 10:2025 · 3 controls

South Korea ISMS-P · 3 controls

  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report

ISO 19011 · 2 controls

  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report

ISO/IEC 27011:2024 · 2 controls

  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management

OWASP ASVS · 2 controls

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)

ISO 20000-1 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

ITIL 4 · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 144 it maps to, and the evidence behind each claim, over MCP and REST.