| IA-13(3) | Identification and Authentication | Token Management |
| IA-2 | Identification and Authentication | Identification and Authentication (Organizational Users) |
| IA-2(1) | Identification and Authentication | Multi-factor Authentication to Privileged Accounts |
| IA-2(10) | Identification and Authentication | Single Sign-on |
| IA-2(11) | Identification and Authentication | Remote Access — Separate Device |
| IA-2(12) | Identification and Authentication | Acceptance of PIV Credentials |
| IA-2(13) | Identification and Authentication | Out-of-band Authentication |
| IA-2(2) | Identification and Authentication | Multi-factor Authentication to Non-privileged Accounts |
| IA-2(3) | Identification and Authentication | Local Access to Privileged Accounts |
| IA-2(4) | Identification and Authentication | Local Access to Non-privileged Accounts |
| IA-2(5) | Identification and Authentication | Individual Authentication with Group Authentication |
| IA-2(6) | Identification and Authentication | Access to Accounts —separate Device |
| IA-2(7) | Identification and Authentication | Network Access to Non-privileged Accounts — Separate Device |
| IA-2(8) | Identification and Authentication | Access to Accounts — Replay Resistant |
| IA-2(9) | Identification and Authentication | Network Access to Non-privileged Accounts — Replay Resistant |
| IA-3 | Identification and Authentication | Device Identification and Authentication |
| IA-3(1) | Identification and Authentication | Cryptographic Bidirectional Authentication |
| IA-3(2) | Identification and Authentication | Cryptographic Bidirectional Network Authentication |
| IA-3(3) | Identification and Authentication | Dynamic Address Allocation |
| IA-3(4) | Identification and Authentication | Device Attestation |
| IA-4 | Identification and Authentication | Identifier Management |
| IA-4(1) | Identification and Authentication | Prohibit Account Identifiers as Public Identifiers |
| IA-4(2) | Identification and Authentication | Supervisor Authorization |
| IA-4(3) | Identification and Authentication | Multiple Forms of Certification |
| IA-4(4) | Identification and Authentication | Identify User Status |
| IA-4(5) | Identification and Authentication | Dynamic Management |
| IA-4(6) | Identification and Authentication | Cross-organization Management |
| IA-4(7) | Identification and Authentication | In-person Registration |
| IA-4(8) | Identification and Authentication | Pairwise Pseudonymous Identifiers |
| IA-4(9) | Identification and Authentication | Attribute Maintenance and Protection |
| IA-5 | Identification and Authentication | Authenticator Management |
| IA-5(1) | Identification and Authentication | Password-based Authentication |
| IA-5(10) | Identification and Authentication | Dynamic Credential Binding |
| IA-5(11) | Identification and Authentication | Hardware Token-based Authentication |
| IA-5(12) | Identification and Authentication | Biometric Authentication Performance |
| IA-5(13) | Identification and Authentication | Expiration of Cached Authenticators |
| IA-5(14) | Identification and Authentication | Managing Content of PKI Trust Stores |
| IA-5(15) | Identification and Authentication | GSA-approved Products and Services |
| IA-5(16) | Identification and Authentication | In-person or Trusted External Party Authenticator Issuance |
| IA-5(17) | Identification and Authentication | Presentation Attack Detection for Biometric Authenticators |
| IA-5(18) | Identification and Authentication | Password Managers |
| IA-5(2) | Identification and Authentication | Public Key-based Authentication |
| IA-5(3) | Identification and Authentication | In-person or Trusted External Party Registration |
| IA-5(4) | Identification and Authentication | Automated Support for Password Strength Determination |
| IA-5(5) | Identification and Authentication | Change Authenticators Prior to Delivery |
| IA-5(6) | Identification and Authentication | Protection of Authenticators |
| IA-5(7) | Identification and Authentication | No Embedded Unencrypted Static Authenticators |
| IA-5(8) | Identification and Authentication | Multiple System Accounts |
| IA-5(9) | Identification and Authentication | Federated Credential Management |
| IA-6 | Identification and Authentication | Authentication Feedback |