PR.AA-03
Users, services, and hardware are authenticated
Implementation examples
- Ex1: Require multifactor authentication
- Ex2: Enforce policies for the minimum strength of passwords, PINs, and similar authenticators
- Ex3: Periodically reauthenticate users, services, and hardware based on risk (e.g., in zero trust architectures)
- Ex4: Ensure that authorized personnel can access accounts essential for protecting safety under emergency conditions
Mapped NIST 800-53 r5 controls (10)
Mapped CWE weaknesses (4)
Hover any chip for the human-reviewed coverage assessment in each direction. ← = the CWE covers this subcategory; → = this subcategory covers the CWE. F / M / P = full, mostly, partial.
All informative references (80)
- CCMv4.0: DCS-08
- CCMv4.0: IAM-01
- CCMv4.0: IAM-02
- CCMv4.0: IAM-14
- CCMv4.0: IAM-16
- CCMv4.0: IVS-03
- CCMv4.0: UEM-05
- CCMv4.0: UEM-06
- CCMv4.0: UEM-14
- CRI Profile v2.0: PR.AA-03
- CRI Profile v2.0: PR.AA-03.01
- CRI Profile v2.0: PR.AA-03.02
- CRI Profile v2.0: PR.AA-03.03
- CSF v1.1: PR.AC-3
- CSF v1.1: PR.AC-7
- ISO/IEC 27001:2022: Mandatory Clause: None
- ISO/IEC 27001:2022: Annex A Controls: 5.15
- ISO/IEC 27001:2022: Annex A Controls: 5.16
- ISO/IEC 27001:2022: Annex A Controls: 5.17
- ISO/IEC 27001:2022: Annex A Controls: 5.18
- ISO/IEC 27001:2022: Annex A Controls: 8.5
- NICE Framework: DD-WRL-001
- NICE Framework: IO-WRL-002
- NICE Framework: IO-WRL-003
- NICE Framework: IO-WRL-005
- NICE Framework: OG-WRL-013
- NICE Framework: OG-WRL-014
- NICE Framework: PD-WRL-004
- OWASP Top 10 LLM Applications: LLM06-2025
- OWASP Top 10 LLM Applications: LLM10-2025
- PCI DSS: 8.3.1
- PCI DSS: 8.3.6
- PCI DSS: 8.3.7
- PCI DSS: 8.3.8
- PCI DSS: 8.3.9
- PCI DSS: 8.2.8
- PCI DSS: 9.2.4
- PCI DSS: 2.2.2
- PCI DSS: 2.3.1
- PCI DSS: 3.5.1.3
- PCI DSS: 8.3.10
- PCI DSS: 8.3.10.1
- SCF: IAC-01.2
- SCF: IAC-02
- SCF: IAC-03
- SCF: IAC-04
- SCF: IAC-05
- SDOS: SDOS-AD-01
- SDOS: SDOS-IA-01
- SP 800-171 Rev 3: 03.01.11
- SP 800-171 Rev 3: 03.05.01
- SP 800-171 Rev 3: 03.05.02
- SP 800-171 Rev 3: 03.05.03
- SP 800-171 Rev 3: 03.05.04
- SP 800-171 Rev 3: 03.05.07
- SP 800-171 Rev 3: 03.05.12
- SP 800-53 Rev 5.1.1: AC-07
- SP 800-53 Rev 5.1.1: AC-12
- SP 800-53 Rev 5.1.1: IA-02
- SP 800-53 Rev 5.1.1: IA-03
- SP 800-53 Rev 5.1.1: IA-05
- SP 800-53 Rev 5.1.1: IA-07
- SP 800-53 Rev 5.1.1: IA-08
- SP 800-53 Rev 5.1.1: IA-09
- SP 800-53 Rev 5.1.1: IA-10
- SP 800-53 Rev 5.1.1: IA-11
- SP 800-53 Rev 5.2.0: AC-07
- SP 800-53 Rev 5.2.0: AC-12
- SP 800-53 Rev 5.2.0: IA-02
- SP 800-53 Rev 5.2.0: IA-03
- SP 800-53 Rev 5.2.0: IA-05
- SP 800-53 Rev 5.2.0: IA-07
- SP 800-53 Rev 5.2.0: IA-08
- SP 800-53 Rev 5.2.0: IA-09
- SP 800-53 Rev 5.2.0: IA-10
- SP 800-53 Rev 5.2.0: IA-11
- SP 800-81r3: 3.1
- SP 800-81r3: 3.3.2
- SP 800-81r3: 3.4.2
- SSDF: PO.5.2
Source: NIST Cybersecurity Framework 2.0 · CSF 2.0 → 800-53 mappings sourced from NIST Cybersecurity & Privacy Reference Tool (CPRT) · US government work — attribution requested per NIST Open License Terms. Direct CSF→CWE/CVE cross-references will be added in a Phase B LLM-authored mapping pass (not yet rendered).