NIST SP 800-144
Identity and Access

NIST SP 800-144 5: Identity and Access in Cloud, Federation, and Privileged Access

Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with IdP (Azure AD + Okta + Auth0 + Ping + ForgeRock + AWS IAM Identity Center) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign-On (SSO) + risk-based authentication. Implement privileged access (PAM + JIT access + bastion hosts + session recording + just-enough-access JEA) + secrets management (Vault + Secrets Manager + Key Vault) + service accounts + managed identities + RBAC + ABAC + policy-as-code (OPA + Sentinel + Cloud Custodian).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.