NIST800-IA-2(5) IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication
NIST800-IA-2(5) in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for NIST800-IA-2(5) yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: IA - Identification and Authentication), in our words, not a statement of the standard and not binding on an assessor.
- the identification and authentication policy
- the authenticator-management records
- the periodic review output