Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.AA-02 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-02: Identities are proofed and bound to credentials based on the context of interactions Identities are proofed and bound to credentials based on the context of interactions. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 141 controls across 78 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-IA-10 IA-10 Adaptive Authentication NIST800-IA-12 IA-12 Identity Proofing NIST800-IA-13 IA-13 Identity Providers and Authorization Servers NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users) NIST800-IA-4 IA-4 Identifier Management NIST800-IA-7 IA-7 Cryptographic Module Authentication NIST800-IA-8 IA-8 Identification and Authentication (Non-organizational Users) SP800-53-IA Identification and Authentication Family IA-12 Identity Proofing (IA-12) IA-12(2) Identity Proofing | Identity Evidence (IA-12(2)) IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3)) IA-5 Authenticator Management IA-8 Identification and Authentication (Non-Organizational Users) IA-12 Identity Proofing (IA-12) IA-12(2) Identity Proofing | Identity Evidence (IA-12(2)) IA-12(3) Identity Proofing | Identity Evidence Validation and Verification (IA-12(3)) IA-5 Authenticator Management IA-8 Identification and Authentication (Non-Organizational Users) ISM-1593 Identity verification before issuing credentials ISM-1594 Secure delivery of new credentials ISM-1595 Changing credentials on first use 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.4 Certificate Management ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) MYHR-REG-11 Ensuring required information is given to the System Operator MYHR-REG-2 Healthcare recipient registration and identity verification FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 5.16 Identity management 8.5 Secure authentication 5.16 Identity management 8.5 Secure authentication BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) AMLCTF-35 Identity Verification Standard SEC02-BP04 Rely on a centralized identity provider AWWA-2.2 Authentication Mechanisms IM-4 Authenticate server and services BSI-03 Multi-factor authentication requirements BE-CF-06 Identity proofing and verification C5-IDM-02 Granting and change of user accounts and access rights CIS-6.1 Establish an Access Granting Process DSO-3 Data Access Management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) ISO27799-12 Unique user identification and authentication 23837-1.7.3 Authentication and classical post-processing ISO27043-13 Authentication and password management 27400-6.1 Secure Device Design ISO21434-13 Authentication and password management Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications PR.AC-6 PR.AC-6: Identities are proofed and bound to credentials and asserted in interactions NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition 161R1-IA-2 Identification and Authentication (Organizational Users) NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working 8.3.3 8.3.3 Identity verified before factor changes PTESPHASE-2 Intelligence Gathering (OSINT) RCEPEC-1 Online Personal Information Protection (12.13) SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-1 Build Integrity - Source, Build, Provenance SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SSAE18-CC6.2 CC6.2 - New User Registration and Authorization CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification ISMSP-AC-03 Authentication Mechanisms TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-NET-02 Access Control and Authentication CPSC-CS.2 Authentication and Access Controls CYB-2 Account Security Measures WCAGREC-3 Principle 3: Understandable Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 141 it maps to, and the evidence behind each claim, over MCP and REST.