PR.AA: Identity Management, Authentication, And Access Control
Category is new to this version of the framework and incorporates the following item from the previous version: PR.AC: Identity Management, Authentication and Access Control.
Description
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
Framework Subcategories
PR.AA-01: Identities and credentials for authorized users, services, and hardware are managed by the organization
[csf.tools Note: Subcategories do not have detailed descriptions.]
PR.AA-02: Identities are proofed and bound to credentials based on the context of interactions
[csf.tools Note: Subcategories do not have detailed descriptions.]
PR.AA-03: Users, services, and hardware are authenticated
[csf.tools Note: Subcategories do not have detailed descriptions.]
PR.AA-04: Identity assertions are protected, conveyed, and verified
[csf.tools Note: Subcategories do not have detailed descriptions.]
PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
[csf.tools Note: Subcategories do not have detailed descriptions.]
PR.AA-06: Physical access to assets is managed, monitored, and enforced commensurate with risk
[csf.tools Note: Subcategories do not have detailed descriptions.]