NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
IA-12(4)In-person Validation and Verification  •   •STRIDE-LM
(5)Address Confirmation ••  ••STRIDE-LM
(6)Accept Externally-proofed Identities       STRIDE-LM
IA-13Identity Providers and Authorization Servers       STRIDE-LM
(2)Verification of Identity Assertions and Access Tokens       STRIDE-LM
(3)Token Management       STRIDE-LM
MA-4(4)Authentication and Separation of Maintenance Sessions       STRIDE-LM
PE-2(2)Two Forms of Identification       STRIDE-LM
PS-4Personnel Termination••• •••STRIDE-LM
SA-4(10)Use of Approved PIV Products••• •••STRIDE-LM
SC-11Trusted Path       STRIDE-LM
SC-12(3)Asymmetric Keys       STRIDE-LM
SC-16(2)Anti-spoofing Mechanisms       STRIDE-LM
SC-17Public Key Infrastructure Certificates ••  ••STRIDE-LM
SC-20Secure Name/Address Resolution Service (Authoritative Source)••• •••STRIDE-LM
(2)Data Origin and Integrity       STRIDE-LM
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)••• •••STRIDE-LM
SC-22Architecture and Provisioning for Name/Address Resolution Service••• •••STRIDE-LM
SC-23Session Authenticity ••  ••STRIDE-LM
(1)Invalidate Session Identifiers at Logout       STRIDE-LM
(3)Unique System-generated Session Identifiers       STRIDE-LM
(5)Allowed Certificate Authorities       STRIDE-LM
SR-4(1)Identity       STRIDE-LM
(3)Validate as Genuine and Not Altered       STRIDE-LM
SR-11Component Authenticity••• •••STRIDE-LM
(3)Anti-counterfeit Scanning       STRIDE-LM