Frameworks / NIST SP 800-190 / NIST190-07 NIST SP 800-190
NIST SP 800-190: Identity & Access in Cloud
NIST SP 800-190 NIST190-07: Multi-factor authentication for cloud Multi-factor authentication for cloud. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Identity & Access in Cloud.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 95 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.4 Certificate Management ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security AMLCTF-35 Identity Verification Standard AWWA-2.2 Authentication Mechanisms BSI-03 Multi-factor authentication requirements DSO-3 Data Access Management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) ISO27799-12 Unique user identification and authentication 23837-1.7.3 Authentication and classical post-processing ISO27043-13 Authentication and password management 27400-6.1 Secure Device Design ISO21434-13 Authentication and password management NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PTESPHASE-2 Intelligence Gathering (OSINT) RCEPEC-1 Online Personal Information Protection (12.13) SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-1 Build Integrity - Source, Build, Provenance SSAE18-CC6.2 CC6.2 - New User Registration and Authorization CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification ISMSP-AC-03 Authentication Mechanisms TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-NET-02 Access Control and Authentication CPSC-CS.2 Authentication and Access Controls CYB-2 Account Security Measures WCAGREC-3 Principle 3: Understandable Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Identity & Access in Cloud Query this from an agent The graph holds this control, the 95 it maps to, and the evidence behind each claim, over MCP and REST.