Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.AA-03 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-03: Users, services, and hardware are authenticated Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 123 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-18(1) Authentication and Encryption AC-7 Unsuccessful Logon Attempts IA-11 Re-Authentication IA-2 Identification and Authentication (Organizational Users) IA-2(12) Acceptance of PIV Credentials IA-2(2) MFA to Non-Privileged Accounts IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6)) IA-3 Device Identification and Authentication IA-5(1) Password-Based Authentication IA-5(2) Public Key-Based Authentication IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) MA-4 Nonlocal Maintenance AC-18(1) Authentication and Encryption AC-7 Unsuccessful Logon Attempts IA-11 Re-Authentication IA-2 Identification and Authentication (Organizational Users) IA-2(12) Acceptance of PIV Credentials IA-2(2) MFA to Non-Privileged Accounts IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6)) IA-3 Device Identification and Authentication IA-5(1) Password-Based Authentication IA-5(2) Public Key-Based Authentication IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) MA-4 Nonlocal Maintenance NIST800-AC-7 AC-7 Unsuccessful Logon Attempts NIST800-IA-1 IA-1 Policy and Procedures NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users) NIST800-IA-3 IA-3 Device Identification and Authentication NIST800-IA-7 IA-7 Cryptographic Module Authentication NIST800-IA-8 IA-8 Identification and Authentication (Non-organizational Users) NIST800-IA-9 IA-9 Service Identification and Authentication NIST800-MA-4 MA-4 Nonlocal Maintenance SP800-53-IA Identification and Authentication Family CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-13.5 Manage Access Control for Remote Assets CIS-5.2 Use Unique Passwords CIS-6.3 Require MFA for Externally-Exposed Applications CIS-6.4 Require MFA for Remote Network Access CIS-6.5 Require MFA for Administrative Access 8.3.1 8.3.1 Access authenticated with at least one factor 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes 8.4.1 8.4.1 MFA for non-console administrative CDE access 8.4.2 8.4.2 MFA for all non-console CDE access 8.4.3 8.4.3 MFA for remote access that could reach CDE 8.5.1 8.5.1 MFA system resistant to replay and bypass 8.6.1 8.6.1 Interactive use of system accounts controlled ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services ANSSI-HYG-13 Prefer Strong Authentication Where Possible ANSSI-HYG-20 Secure Wi-Fi Access Networks and Separate Usage ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working ISM-0622 IT equipment authentication via gateways ISM-0974 Multi-factor authentication for unprivileged users ISM-1173 Multi-factor authentication for privileged users ISM-1546 Authenticating users before access 5.16 Identity management 5.17 Authentication information 6.7 Remote working 8.5 Secure authentication 03.01.08 Unsuccessful Logon Attempts 03.05.01 User Identification and Authentication 03.05.02 Device Identification and Authentication 03.05.03 Multi-Factor Authentication SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal CE-AC.2 Authenticate Users Before Granting Access CE-AC.7 MFA for Administrative Accounts CE-SC.4 Authenticate Users Before Access CE-SC.6 Multi-Factor Authentication for Cloud Services E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1 E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2 E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3 ASBv3-IM-5 Use single sign-on (SSO) for application access IM-4 Authenticate server and services IM-6 Use strong authentication controls 5.16 Identity management 5.17 Authentication information 8.5 Secure authentication BE-CF-03 Multi-factor authentication requirements BE-CF-11 Session management controls 6.6 Access control 6.6.4 System and application access control PR.AC-3 PR.AC-3: Remote access is managed PR.AC-7 PR.AC-7: Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals' security and privacy risks and other organizational risks) 161R1-IA-3 Device Identification and Authentication 161R1-IA-9 Service Identification and Authentication 3.5.1e Identification of Systems, Components, and Devices 3.5.3e Prohibit Connection of Unknown or Unverified System Components ASD37-20 Multi-factor authentication (Essential) AWWA-2.2 Authentication Mechanisms AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment MYHR-REG-2 Healthcare recipient registration and identity verification AESCSF-IAM-3 Multi-factor authentication Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications PR.AC-3 PR.AC-3: Remote access is managed Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 123 it maps to, and the evidence behind each claim, over MCP and REST.