Identities and credentials for authorized users, services, and hardware are managed by the organization
Parent: PR.AA
Description
No description available.
Mapped SPARTA techniques
3 techniques
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records DE-0005 against IA-2 Identification and Authentication (Organizational Users), and CSF 2.0's own crosswalk names that control as an informative reference for PR.AA-01. Through SPARTA: SPARTA's catalog maps DE-0005 to countermeasure CM0035 Protect Authenticators, and that countermeasure's own CSF references include PR.AA-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records EX-0011 against IA-2 Identification and Authentication (Organizational Users), and CSF 2.0's own crosswalk names that control as an informative reference for PR.AA-01. Through SPARTA: SPARTA's catalog maps EX-0011 to countermeasure CM0035 Protect Authenticators, and that countermeasure's own CSF references include PR.AA-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records IA-0001.02 against IA-5 Authenticator Management, and CSF 2.0's own crosswalk names that control as an informative reference for PR.AA-01. Through SPARTA: SPARTA's catalog maps IA-0001.02 to countermeasure CM0001 Protect Sensitive Information, and that countermeasure's own CSF references include PR.AA-01. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Crosswalks to 11 in NIST SP 800-53 Rev. 5
- AC-1Policy and Procedures
- AC-2Account Management
- IA-1Policy and Procedures
- IA-2Identification and Authentication (Organizational Users)
- IA-3Device Identification and Authentication
- IA-4Identifier Management
- IA-5Authenticator Management
- IA-6Authentication Feedback
- IA-7Cryptographic Module Authentication
- IA-8Identification and Authentication (Non-organizational Users)
- IA-9Service Identification and Authentication
Cite as SafeMode Space, csf-2-0 PR.AA-01.