NIST Cybersecurity Framework (CSF) 2.0 2.0

PR.AA

Identity Management, Authentication, and Access Control

Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access

Citation PR.AA
Clé de plateforme arcate:compliance:requirements/nist-csf/2.0/PR.AA
Emplacement dans la source row 91 of sheet 'CSF 2.0'
Publié par NIST

Exigences filles

PR.AA-01

Identities and credentials for authorized users, services, and hardware are managed by the organization

arcate:compliance:requirements/nist-csf/2.0/PR.AA-01

PR.AA-02

Identities are proofed and bound to credentials based on the context of interactions

arcate:compliance:requirements/nist-csf/2.0/PR.AA-02

PR.AA-03

Users, services, and hardware are authenticated

arcate:compliance:requirements/nist-csf/2.0/PR.AA-03

PR.AA-04

Identity assertions are protected, conveyed, and verified

arcate:compliance:requirements/nist-csf/2.0/PR.AA-04

PR.AA-05

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

arcate:compliance:requirements/nist-csf/2.0/PR.AA-05

PR.AA-06

Physical access to assets is managed, monitored, and enforced commensurate with risk

arcate:compliance:requirements/nist-csf/2.0/PR.AA-06