Identities and credentials for authorized users, services, and hardware are managed by the organization
NIST Cybersecurity Framework (CSF) 2.0 2.0
PR.AA
Identity Management, Authentication, and Access Control
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
| Citation | PR.AA |
|---|---|
| Clé de plateforme | arcate:compliance:requirements/nist-csf/2.0/PR.AA |
| Emplacement dans la source | row 91 of sheet 'CSF 2.0' |
| Publié par | NIST |
Exigences filles
Identities are proofed and bound to credentials based on the context of interactions
Users, services, and hardware are authenticated
Identity assertions are protected, conveyed, and verified
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Physical access to assets is managed, monitored, and enforced commensurate with risk