NIST SP 800-63-4
Authentication and Authenticator Types

NIST SP 800-63-4 3: Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

Implement authentication per NIST SP 800-63-4 Volume B (Authentication and Authenticator Lifecycle). Approve authenticator types per Section 4 covering (a) memorised secrets (Section 4.1), (b) look-up secrets (Section 4.2), (c) out-of-band devices (Section 4.3 with restrictions on SMS), (d) single-factor and multi-factor OTP devices (Section 4.4 + 4.5), (e) cryptographic software and hardware (Section 4.6 + 4.7 + 4.8 + 4.9), (f) syncable authenticators (NEW in Rev 4 per Section 4.10 covering FIDO2 passkeys that synchronise across user devices via cloud + provider attestation + cryptographic guarantees). Multi-Factor Authentication required at AAL2 per Section 5.2 + AAL3 per Section 5.3. Phishing-resistance per Section 4.13 specifies phishing-resistant authenticators (multi-factor cryptographic hardware + FIDO2 + smart card + PIV) and is REQUIRED at AAL3 + RECOMMENDED at AAL2 for high-risk transactions per OMB M-22-09.

What else in your programme already covers this

This control maps to 168 controls across 75 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 13485 · 5 controls

BSI IT-Grundschutz · 4 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

ISO 27043 · 4 controls

ISO 27799 · 4 controls

ISO/SAE 21434 · 4 controls

  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

OWASP Top 10:2025 · 4 controls

API 1164 · 3 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

IEC 62443 · 3 controls

ISO 27019 · 3 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 1800-32 · 3 controls

  • 3.10 Encrypt Sensitive Data in Transit
  • 3.7 Establish and Maintain a Data Classification Scheme
  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

South Korea ISMS-P · 3 controls

ISO 19011 · 2 controls

  • 6.4 Logging and Monitoring
  • 6.5 Preparing and Distributing Audit Report

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27011:2024 · 2 controls

  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

NIST SP 800-190 · 2 controls

OWASP ASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)

ISO 20000-1 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

ITIL 4 · 1 control

  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal

OWASP MASVS · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 168 it maps to, and the evidence behind each claim, over MCP and REST.