MARS-E
Access Control and Identity Authentication - MARS-E v2.0

MARS-E MARS-E-Access-Control-Identity-Authentication-NIST-800-63-Identity-Assurance-Levels-MFA-AC-IA-Families: MARS-E Access Control + Identity + Authentication + NIST 800-63 + MFA + AC + IA Families

Implement NIST 800-53 AC Access Control family + IA Identification and Authentication family per MARS-E v2.0 catalog. NIST 800-63-3 Identity Assurance Level 2 (IAL2) + Authenticator Assurance Level 2 (AAL2) + Federation Assurance Level 2 (FAL2) for Exchange consumer authentication + IAL3 + AAL3 for administrative access. Identity proofing via Experian + LexisNexis + manual document review + biometric verification. Multi-Factor Authentication (MFA) mandatory for all administrative access + remote access + privileged operations. Role-Based Access Control (RBAC) with separation of duties (Eligibility Adjudicator + System Administrator + Privacy Officer + Security Officer). Least privilege enforcement. Account management lifecycle (provisioning + recertification + deprovisioning) with quarterly recertification. Privileged Access Management (PAM) with session recording for privileged users. Remote access via approved VPN + bastion host + jump server. Trust relationships with CMS Federal Data Services Hub + IRS + SSA + Department of Homeland Security + VLP (Verify Lawful Presence) coordinated through HHS Trust Framework.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 132 controls across 63 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27799:2025 · 5 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-07 Workforce security and clearance procedures
  • ISO27799-08 Information access management
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-17 Facility access controls

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 4 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.4 Physical Access Controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO/IEC 27010:2015 · 3 controls

  • 27010-7.1 Information Classification for Sharing
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats

OWASP Top 10:2025 · 3 controls

South Korea ISMS-P · 3 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-AC-04 Network Access Control
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)
  • ISO28001-PI-01 Personnel Security Screening
  • ISO28001-PS-01 Facility Security

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management

OWASP ASVS · 2 controls

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • AMLCTF-35 Identity Verification Standard

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • ACQS-7-3 Worker Screening

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-3 Personnel Security

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • ISO20000-15 Access management for services

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ITIL 4 · 1 control

  • ITIL4-15 Access management for services

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 132 it maps to, and the evidence behind each claim, over MCP and REST.