Skip to main content

πŸ’Ό PR.AA-01: Identities and credentials for authorized users, services, and hardware are managed by the organization

Description​

  1. Initiate requests for new access or additional access for employees, contractors, and others, and track, review, and fulfill the requests, with permission from system or data owners when needed
  2. Issue, manage, and revoke cryptographic certificates and identity tokens, cryptographic keys (i.e., key management), and other credentials
  3. Select a unique identifier for each device from immutable hardware characteristics or an identifier securely provisioned to the device
  4. Physically label authorized hardware with an identifier for inventory and servicing purposes

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/pr-ac/01
    • /frameworks/nist-sp-800-53-r5/ac/01
    • /frameworks/nist-sp-800-53-r5/ac/02
    • /frameworks/nist-sp-800-53-r5/ac/14
    • /frameworks/nist-sp-800-53-r5/ia/01
    • /frameworks/nist-sp-800-53-r5/ia/02
    • /frameworks/nist-sp-800-53-r5/ia/03
    • /frameworks/nist-sp-800-53-r5/ia/04
    • /frameworks/nist-sp-800-53-r5/ia/05
    • /frameworks/nist-sp-800-53-r5/ia/06
    • /frameworks/nist-sp-800-53-r5/ia/07
    • /frameworks/nist-sp-800-53-r5/ia/08
    • /frameworks/nist-sp-800-53-r5/ia/09
    • /frameworks/nist-sp-800-53-r5/ia/10
    • /frameworks/nist-sp-800-53-r5/ia/11

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes1922
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AC-1 Policy and Procedures
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AC-2 Account Management131730
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό AC-14 Permitted Actions Without Identification or Authentication1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-1 Policy and Procedures
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-2 Identification and Authentication (organizational Users)132
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-3 Device Identification and Authentication4
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-4 Identifier Management9
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-5 Authenticator Management184
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-6 Authentication Feedback
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-7 Cryptographic Module Authentication
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-8 Identification and Authentication (non-organizational Users)6
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-9 Service Identification and Authentication2
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-10 Adaptive Authentication
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-11 Re-authentication

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (23)​

PolicyLogic CountFlags
πŸ“ AWS Account IAM Access Analyzer is not enabled for all regions 🟒1🟒 x6
πŸ“ AWS Account IAM Password Policy Number of passwords to remember is not set to 24 🟒1🟒 x6
πŸ“ AWS Account Root User credentials were used is the last 30 days πŸ”΄πŸŸ’1πŸ”΄ x1, 🟒 x6
πŸ“ AWS EC2 Instance IAM role is not attached 🟒1🟒 x6
πŸ“ AWS IAM Policy allows full administrative privileges 🟒1🟒 x6
πŸ“ AWS IAM Server Certificate is expired 🟒1🟒 x6
πŸ“ AWS IAM User Access Keys are not rotated every 90 days or less 🟒1🟒 x6
πŸ“ AWS IAM User has inline or directly attached policies 🟒1🟠 x1, 🟒 x5
πŸ“ AWS IAM User has more than one active access key 🟒1🟒 x6
πŸ“ AWS IAM User MFA is not enabled for all users with console password 🟒1🟒 x6
πŸ“ AWS IAM User with console and programmatic access set during the initial creation 🟒🟒 x3
πŸ“ AWS IAM User with credentials unused for 45 days or more is not disabled 🟒1🟒 x6
πŸ“ AWS KMS Symmetric CMK Rotation is not enabled 🟒1🟒 x6
πŸ“ AWS S3 Bucket MFA Delete is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ Azure App Service Authentication is disabled and Basic Authentication is enabled 🟒1🟒 x6
πŸ“ Azure App Service Basic Authentication is enabled 🟒🟒 x3
πŸ“ Azure App Service is not registered with Microsoft Entra ID 🟒1🟒 x6
πŸ“ Azure Key Vault Soft Delete and Purge Protection functions are not enabled 🟒1🟒 x6
πŸ“ Azure Non-RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure Non-RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Keys without expiration date 🟒1🟒 x6
πŸ“ Azure RBAC Key Vault stores Secrets without expiration date 🟒1🟒 x6
πŸ“ Consumer Google Accounts are used 🟒🟒 x3