NIST Special Publication 800-53 Revision 4
IDNameBaselinesPriorityThreats
LowModerateHigh
AC-4(17)Domain Authentication   
  • P1
STRIDE-LM
AC-7Unsuccessful Logon Attempts•••
  • P2
STRIDE-LM
AC-9(1)Unsuccessful Logons   
  • P0
STRIDE-LM
(2)Successful / Unsuccessful Logons   
  • P0
STRIDE-LM
AC-17Remote Access•••
  • P1
STRIDE-LM
AC-18(1)Authentication And Encryption ••
  • P1
STRIDE-LM
AU-10(2)Validate Binding Of Information Producer Identity   
  • P2
STRIDE-LM
IA-1Identification And Authentication Policy And Procedures•••
  • P1
STRIDE-LM
IA-2Identification And Authentication (Organizational Users)•••
  • P1
STRIDE-LM
(1)Network Access To Privileged Accounts•••
  • P1
STRIDE-LM
(2)Network Access To Non-Privileged Accounts ••
  • P1
STRIDE-LM
(3)Local Access To Privileged Accounts ••
  • P1
STRIDE-LM
(5)Group Authentication   
  • P1
STRIDE-LM
(8)Network Access To Privileged Accounts - Replay Resistant ••
  • P1
STRIDE-LM
(9)Network Access To Non-Privileged Accounts - Replay Resistant  •
  • P1
STRIDE-LM
(12)Acceptance Of Piv Credentials•••
  • P1
STRIDE-LM
(13)Out-Of-Band Authentication   
  • P1
STRIDE-LM
IA-3Device Identification And Authentication ••
  • P1
STRIDE-LM
(1)Cryptographic Bidirectional Authentication   
  • P1
STRIDE-LM
(4)Device Attestation   
  • P1
STRIDE-LM
IA-4Identifier Management•••
  • P1
STRIDE-LM
(1)Prohibit Account Identifiers As Public Identifiers   
  • P1
STRIDE-LM
(3)Multiple Forms Of Certification   
  • P1
STRIDE-LM
(7)In-Person Registration   
  • P1
STRIDE-LM
IA-5Authenticator Management•••
  • P1
STRIDE-LM
(1)Password-Based Authentication•••
  • P1
STRIDE-LM
(2)Pki-Based Authentication ••
  • P1
STRIDE-LM
(3)In-Person Or Trusted Third-Party Registration ••
  • P1
STRIDE-LM
(5)Change Authenticators Prior To Delivery   
  • P1
STRIDE-LM
(6)Protection Of Authenticators   
  • P1
STRIDE-LM
(9)Cross-Organization Credential Management   
  • P1
STRIDE-LM
(10)Dynamic Credential Association   
  • P1
STRIDE-LM
(11)Hardware Token-Based Authentication•••
  • P1
STRIDE-LM
(12)Biometric-Based Authentication   
  • P1
STRIDE-LM
(13)Expiration Of Cached Authenticators   
  • P1
STRIDE-LM
(14)Managing Content Of Pki Trust Stores   
  • P1
STRIDE-LM
(15)Ficam-Approved Products And Services   
  • P1
STRIDE-LM
IA-7Cryptographic Module Authentication•••
  • P1
STRIDE-LM
IA-8Identification And Authentication (Non-Organizational Users)•••
  • P1
STRIDE-LM
(1)Acceptance Of Piv Credentials From Other Agencies•••
  • P1
STRIDE-LM
(2)Acceptance Of Third-Party Credentials•••
  • P1
STRIDE-LM
(3)Use Of Ficam-Approved Products•••
  • P1
STRIDE-LM
(4)Use Of Ficam-Issued Profiles•••
  • P1
STRIDE-LM
(5)Acceptance Of Piv-I Credentials   
  • P1
STRIDE-LM
IA-9Service Identification And Authentication   
  • P0
STRIDE-LM
(1)Information Exchange   
  • P0
STRIDE-LM
IA-10Adaptive Identification And Authentication   
  • P0
STRIDE-LM
IA-11Re-Authentication   
  • P0
STRIDE-LM
MA-4Nonlocal Maintenance•••
  • P2
STRIDE-LM
PE-2(2)Two Forms Of Identification   
  • P1
STRIDE-LM