Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.AA-01 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-01: Identities and credentials for authorized users, services, and hardware are managed by the organization Identities and credentials for authorized users, services, and hardware are managed by the organization
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 264 controls across 100 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 2.2.2 2.2.2 Vendor default accounts managed 7.2.5.1 7.2.5.1 Application and system account access reviewed periodically 8.2.1 8.2.1 Unique ID assigned to every user 8.2.2 8.2.2 Shared and generic IDs only by exception 8.2.4 8.2.4 User ID lifecycle changes authorized 8.2.6 8.2.6 Inactive accounts removed within 90 days 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned 8.3.5 8.3.5 Initial and reset passwords unique and changed 8.3.6 8.3.6 Password minimum length 12 and complexity 9.2.3 9.2.3 Physical protection of network hardware and lines 9.2.4 9.2.4 Locking of consoles in sensitive areas 7.2.4 7.2.4 User accounts and privileges reviewed every six months 7.2.5 7.2.5 Application and system accounts least privilege 7.3.1 7.3.1 Need-to-know access control system covers all components 8.6.1 8.6.1 Interactive use of system accounts controlled 8.6.3 8.6.3 System account passwords protected against misuse AC-2 Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(3) Disable Accounts IA-2 Identification and Authentication (Organizational Users) IA-3 Device Identification and Authentication IA-4 Identifier Management IA-4(4) Identifier Management | Identify User Status (IA-4(4)) IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-8 Identification and Authentication (Non-Organizational Users) PS-4 Personnel Termination AC-2 Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(3) Disable Accounts IA-2 Identification and Authentication (Organizational Users) IA-3 Device Identification and Authentication IA-4 Identifier Management IA-4(4) Identifier Management | Identify User Status (IA-4(4)) IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-8 Identification and Authentication (Non-Organizational Users) PS-4 Personnel Termination CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-15.7 Securely Decommission Service Providers CIS-4.7 Manage Default Accounts on Enterprise Assets and Software CIS-5.1 Establish and Maintain an Inventory of Accounts CIS-5.2 Use Unique Passwords CIS-5.3 Disable Dormant Accounts CIS-5.5 Establish and Maintain an Inventory of Service Accounts CIS-5.6 Centralize Account Management CIS-6.1 Establish an Access Granting Process CIS-6.2 Establish an Access Revoking Process 5.16 Identity management 5.17 Authentication information 5.18 Access rights 6.5 Responsibilities after termination or change of employment 8.2 Privileged access rights 8.5 Secure authentication 6.4 Human resource security 6.4.3 Termination and change of employment 6.6 Access control 6.6.2 User access management 6.6.3 User responsibilities 6.6.4 System and application access control ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules ANSSI-HYG-11 Protect Passwords Stored on Systems ASBv3-IM-5 Use single sign-on (SSO) for application access ASBv3-IM-8 Restrict the exposure of credential and secrets IM-1 Use centralized identity and authentication system IM-3 Manage application identities securely and automatically PA-3 Manage lifecycle of identities and entitlements C5-IDM-01 Policy for user accounts and access rights C5-IDM-02 Granting and change of user accounts and access rights C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins C5-IDM-08 Confidentiality of authentication information C5-PSS-07 Confidentiality of Authentication Information 5.15 Access control 5.16 Identity management 5.17 Authentication information 6.7 Remote working 8.5 Secure authentication ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-21 Disable local administrator accounts (Excellent) ASD37-23 Protect authentication credentials (Excellent) ISM-0407 Secure record of user access authorisations ISM-0414 Unique identification of system users ISM-1685 Managing break glass and service account credentials ACCESS-1 Establish and Maintain Identities ACCESS-2 Control Logical and Physical Access ARCH-3 Implement Data Security 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties CE-AC.1 User Account Approval Process CE-AC.3 Remove or Disable Accounts When No Longer Required CE-SC.5 Password-Based Authentication Quality OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.4 Certificate Management MYHR-REG-11 Ensuring required information is given to the System Operator MYHR-SEC-2 Access controls and user account management ITSG33-AC Access Control (AC) ITSG33-IA Identification and Authentication (IA) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) AMLCTF-35 Identity Verification Standard AWWA-2.2 Authentication Mechanisms AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AESCSF-IAM-1 Identity management BSI-03 Multi-factor authentication requirements BE-CF-01 Account management and provisioning CNCF-RT-ACCESS Runtime Access (Identity, Authentication, Authorization) CA-SB327-1798.91.04b Authentication Outside a Local Area Network (Password Safe Harbor) CSL-Art34 CII Operator Security Obligations - Art. 34 PIPL-Art51 Security Measures and Management System DSO-3 Data Access Management ENISA-DPE-5.3 Privacy-enhancing access control and authorisation (ABC, ZKP) FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) ISO27799-12 Unique user identification and authentication 23837-1.7.3 Authentication and classical post-processing ISO27043-13 Authentication and password management 27400-6.1 Secure Device Design ISO21434-13 Authentication and password management Art.21.2.i Human resources security, access control policies and asset management PR.AC-1 PR.AC-1: Identities and credentials are managed for authorized devices and users PR.AC-1 PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PTESPHASE-2 Intelligence Gathering (OSINT) RCEPEC-1 Online Personal Information Protection (12.13) SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-1 Build Integrity - Source, Build, Provenance SSAE18-CC6.2 CC6.2 - New User Registration and Authorization CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification ISMSP-AC-03 Authentication Mechanisms TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-NET-02 Access Control and Authentication CPSC-CS.2 Authentication and Access Controls CYB-2 Account Security Measures WCAGREC-3 Principle 3: Understandable Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 264 it maps to, and the evidence behind each claim, over MCP and REST.