NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users)
NIST800-IA-2 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
IA-2 Identification and Authentication (Organizational Users). Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC6.1 CC6.1 Logical access security over protected information assets (reviewed pair)
- SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) (closest match)
- SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials (closest match)
- SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties (closest match)
- SOC2-P5.1 P5.1 Data subject access (closest match)
HIPAA Security Rule
- 164.312(a)(1) Access Control (Standard) (closest match)
- 164.312(a)(2)(i) Unique User Identification (Required) (closest match)
- 164.312(d) Person or Entity Authentication (Standard) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: IA - Identification and Authentication), in our words, not a statement of the standard and not binding on an assessor.
- the identification and authentication policy
- the authenticator-management records
- the periodic review output