NIST SP 800-63-4
Authenticator Lifecycle Management

NIST SP 800-63-4 NISTSP63R4-4: Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation

Manage authenticator lifecycle per NIST SP 800-63-4 Volume B Chapter 6. Binding per Section 6.1: bind authenticator to verified subscriber identity. Authenticator recovery per Section 6.2: post-loss recovery via re-proofing OR strong alternative evidence + alternative authenticator + risk-based controls. Authenticator replacement per Section 6.3. Authenticator expiration per Section 6.4 covering cryptographic key lifetime + biometric template freshness + memorised secret rotation policy (note: Rev 4 retains the no-arbitrary-rotation guidance but allows rotation on suspected compromise). Authenticator suspension per Section 6.5: temporary suspension on suspected compromise + clear unsuspend procedure. Authenticator revocation per Section 6.6: terminal revocation on confirmed compromise + clear binding-replacement workflow. Lifecycle event records per Section 6.7. Subscriber notification of binding changes per Section 6.8. Strong account recovery without weak fallback mechanisms (no security questions + no static PINs as sole factor).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 72 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 1800-32 · 3 controls

South Korea ISMS-P · 3 controls

  • ISMSP-AC-02 User Account Management
  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-12 User access management and provisioning
  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 2 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-23 Backup and recovery procedures

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 2 controls

  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

  • OWASPMASVS-3 MASVS-AUTH: Authentication and Authorization
  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • 4.4.8 Business Continuity and Recovery

BSI IT-Grundschutz · 1 control

  • BSI-01 Account management and provisioning
  • DIQ-1 Data Integration and Interoperability
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO/IEC 27010:2015 · 1 control

  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.