NIST SP 800-144
Identity and Access

NIST SP 800-144 NISTSP144-5: Identity and Access in Cloud, Federation, and Privileged Access

Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with an identity provider (IdP) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign-On (SSO) + risk-based authentication. Implement privileged access (PAM + JIT access + bastion hosts + session recording + just-enough-access JEA) + secrets management + service accounts + managed identities + RBAC + ABAC + policy-as-code.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 176 controls across 62 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-13 Right to object and request blocking
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

ISO 27799:2025 · 5 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-16 Transmission security and encryption

ISO/IEC 27043:2015 · 5 controls

  • ISO27043-08 Information classification and labeling
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 5 controls

  • ISO21434-08 Information classification and labeling
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.3 Cryptography and key management
  • 27011-8.6 Data protection and backup
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DAT.1 Data Classification
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

GDPR · 3 controls

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27400:2022 · 3 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

OWASP ASVS · 3 controls

OWASP MASVS · 3 controls

  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

BSI IT-Grundschutz · 2 controls

  • BSI-08 Cryptographic protection of data
  • BSI-15 Security categorization
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO/IEC 27010:2015 · 2 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-8.2 Membership Termination
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

API 1164 · 1 control

  • API1164-02 Risk Management Framework

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • AL-DPA-14 Direct Marketing
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • 60601-1.7.1 Equipment identification and marking
  • 62351-9 Cyber security key management

IEC 62443 · 1 control

  • IEC62443-02 System security categorization
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI

ISO/IEC 27019:2024 · 1 control

  • ISO27019-02 System security categorization
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • RUSPD-4 Special Categories, Biometric Data

South Korea ISMS-P · 1 control

  • ISMSP-SYS-02 Encryption Implementation

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • CPSC-CS.3 Data Protection for Safety Systems
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 176 it maps to, and the evidence behind each claim, over MCP and REST.