NIST SP 800-66 Rev 2
Technical

NIST SP 800-66 Rev 2 164.312(a)(2)(i): Unique User Identification (Required)

Assign a unique name or number for identifying and tracking user identity. NIST recommends no shared accounts and centralized identity store.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 45 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CMMC 2.0 · 4 controls

CIS Controls v8 · 3 controls

  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.6 Centralize Account Management

FedRAMP High · 3 controls

  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-4 Identifier Management

FedRAMP Moderate · 3 controls

  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-4 Identifier Management
  • SEC02-BP04 Rely on a centralized identity provider
  • SEC02-BP05 Audit and rotate credentials periodically
  • IM-1 Use centralized identity and authentication system
  • IM-3 Manage application identities securely and automatically

C5 (Germany) · 2 controls

ISO 27002:2022 · 2 controls

  • 5.16 Identity management
  • 5.17 Authentication information

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

PCI DSS 4.0 · 2 controls

  • 8.2.1 8.2.1 Unique ID assigned to every user
  • 8.2.2 8.2.2 Shared and generic IDs only by exception

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials

UK Cyber Essentials · 2 controls

  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-SC.4 Authenticate Users Before Access
  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ASD37-21 Disable local administrator accounts (Excellent)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • MYHR-REG-11 Ensuring required information is given to the System Operator

ISO 27001:2022 · 1 control

  • 5.16 Identity management

ISO 27701:2019 · 1 control

  • 6.6.2 User access management
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.