All frameworks
nist-80053-rev5version Rev. 5

NIST SP 800-53 Rev. 5

Official source

1,196 controls.

ReferenceFamilyTitle
IA-13(3)Identification and AuthenticationToken Management
IA-2Identification and AuthenticationIdentification and Authentication (Organizational Users)
IA-2(1)Identification and AuthenticationMulti-factor Authentication to Privileged Accounts
IA-2(10)Identification and AuthenticationSingle Sign-on
IA-2(11)Identification and AuthenticationRemote Access — Separate Device
IA-2(12)Identification and AuthenticationAcceptance of PIV Credentials
IA-2(13)Identification and AuthenticationOut-of-band Authentication
IA-2(2)Identification and AuthenticationMulti-factor Authentication to Non-privileged Accounts
IA-2(3)Identification and AuthenticationLocal Access to Privileged Accounts
IA-2(4)Identification and AuthenticationLocal Access to Non-privileged Accounts
IA-2(5)Identification and AuthenticationIndividual Authentication with Group Authentication
IA-2(6)Identification and AuthenticationAccess to Accounts —separate Device
IA-2(7)Identification and AuthenticationNetwork Access to Non-privileged Accounts — Separate Device
IA-2(8)Identification and AuthenticationAccess to Accounts — Replay Resistant
IA-2(9)Identification and AuthenticationNetwork Access to Non-privileged Accounts — Replay Resistant
IA-3Identification and AuthenticationDevice Identification and Authentication
IA-3(1)Identification and AuthenticationCryptographic Bidirectional Authentication
IA-3(2)Identification and AuthenticationCryptographic Bidirectional Network Authentication
IA-3(3)Identification and AuthenticationDynamic Address Allocation
IA-3(4)Identification and AuthenticationDevice Attestation
IA-4Identification and AuthenticationIdentifier Management
IA-4(1)Identification and AuthenticationProhibit Account Identifiers as Public Identifiers
IA-4(2)Identification and AuthenticationSupervisor Authorization
IA-4(3)Identification and AuthenticationMultiple Forms of Certification
IA-4(4)Identification and AuthenticationIdentify User Status
IA-4(5)Identification and AuthenticationDynamic Management
IA-4(6)Identification and AuthenticationCross-organization Management
IA-4(7)Identification and AuthenticationIn-person Registration
IA-4(8)Identification and AuthenticationPairwise Pseudonymous Identifiers
IA-4(9)Identification and AuthenticationAttribute Maintenance and Protection
IA-5Identification and AuthenticationAuthenticator Management
IA-5(1)Identification and AuthenticationPassword-based Authentication
IA-5(10)Identification and AuthenticationDynamic Credential Binding
IA-5(11)Identification and AuthenticationHardware Token-based Authentication
IA-5(12)Identification and AuthenticationBiometric Authentication Performance
IA-5(13)Identification and AuthenticationExpiration of Cached Authenticators
IA-5(14)Identification and AuthenticationManaging Content of PKI Trust Stores
IA-5(15)Identification and AuthenticationGSA-approved Products and Services
IA-5(16)Identification and AuthenticationIn-person or Trusted External Party Authenticator Issuance
IA-5(17)Identification and AuthenticationPresentation Attack Detection for Biometric Authenticators
IA-5(18)Identification and AuthenticationPassword Managers
IA-5(2)Identification and AuthenticationPublic Key-based Authentication
IA-5(3)Identification and AuthenticationIn-person or Trusted External Party Registration
IA-5(4)Identification and AuthenticationAutomated Support for Password Strength Determination
IA-5(5)Identification and AuthenticationChange Authenticators Prior to Delivery
IA-5(6)Identification and AuthenticationProtection of Authenticators
IA-5(7)Identification and AuthenticationNo Embedded Unencrypted Static Authenticators
IA-5(8)Identification and AuthenticationMultiple System Accounts
IA-5(9)Identification and AuthenticationFederated Credential Management
IA-6Identification and AuthenticationAuthentication Feedback

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.