NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
AC-4(17)Domain Authentication       STRIDE-LM
AC-7Unsuccessful Logon Attempts••• •••STRIDE-LM
(3)Biometric Attempt Limiting       STRIDE-LM
(4)Use of Alternate Authentication Factor       STRIDE-LM
AC-9(2)Successful and Unsuccessful Logons       STRIDE-LM
AC-17Remote Access••• •••STRIDE-LM
(10)Authenticate Remote Commands     ••STRIDE-LM
AC-18(1)Authentication and Encryption ••  ••STRIDE-LM
AC-24(2)No User or Process Identity       STRIDE-LM
AT-2(3)Social Engineering and Mining ••  ••STRIDE-LM
AU-10(2)Validate Binding of Information Producer Identity       STRIDE-LM
(4)Validate Binding of Information Reviewer Identity       STRIDE-LM
CM-14Signed Components       STRIDE-LM
IA-2Identification and Authentication (Organizational Users)••• •••STRIDE-LM
(1)Multi-factor Authentication to Privileged Accounts••• •••STRIDE-LM
(2)Multi-factor Authentication to Non-privileged Accounts••• •••STRIDE-LM
(5)Individual Authentication with Group Authentication  •   •STRIDE-LM
(6)Access to Accounts - Separate Device       STRIDE-LM
(8)Access to Accounts - Replay Resistant••• •••STRIDE-LM
(12)Acceptance of PIV Credentials••• •••STRIDE-LM
(13)Out-of-band Authentication       STRIDE-LM
IA-3Device Identification and Authentication •• •••STRIDE-LM
(1)Cryptographic Bidirectional Authentication       STRIDE-LM
(4)Device Attestation       STRIDE-LM
IA-4Identifier Management••• •••STRIDE-LM
IA-5Authenticator Management••• •••STRIDE-LM
(1)Password-based Authentication••• •••STRIDE-LM
(2)Public Key-based Authentication ••  ••STRIDE-LM
(5)Change Authenticators Prior to Delivery       STRIDE-LM
(6)Protection of Authenticators ••  ••STRIDE-LM
(7)No Embedded Unencrypted Static Authenticators       STRIDE-LM
(9)Federated Credential Management       STRIDE-LM
(10)Dynamic Credential Binding       STRIDE-LM
(12)Biometric Authentication Performance       STRIDE-LM
(13)Expiration of Cached Authenticators       STRIDE-LM
(14)Managing Content of PKI Trust Stores       STRIDE-LM
(16)In-person or Trusted External Party Authenticator Issuance       STRIDE-LM
(17)Presentation Attack Detection for Biometric Authenticators       STRIDE-LM
(18)Password Managers       STRIDE-LM
IA-7Cryptographic Module Authentication••• •••STRIDE-LM
IA-8Identification and Authentication (Non-organizational Users)••• •••STRIDE-LM
(1)Acceptance of PIV Credentials from Other Agencies••• •••STRIDE-LM
(2)Acceptance of External Authenticators••• •••STRIDE-LM
(5)Acceptance of PIV-I Credentials       STRIDE-LM
IA-9Service Identification and Authentication       STRIDE-LM
IA-10Adaptive Authentication       STRIDE-LM
IA-11Re-authentication••• •••STRIDE-LM
IA-12Identity Proofing ••  ••STRIDE-LM
(2)Identity Evidence ••  ••STRIDE-LM
(3)Identity Evidence Validation and Verification ••  ••STRIDE-LM