Skip to main content

πŸ’Ό PR.AA-02: Identities are proofed and bound to credentials based on the context of interactions

Description​

  1. Verify a person's claimed identity at enrollment time using government-issued identity credentials (e.g., passport, visa, driver's license)
  2. Issue a different credential for each person (i.e., no credential sharing)

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/pr-ac/06
    • /frameworks/nist-sp-800-53-r5/ia/12

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.AC-6: Identities are proofed and bound to credentials and asserted in interactions48
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-12 Identity Proofing6

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (8)​

PolicyLogic CountFlags
πŸ“ AWS Account IAM Password Policy Number of passwords to remember is not set to 24 🟒1🟒 x6
πŸ“ AWS EC2 Instance IAM role is not attached 🟒1🟒 x6
πŸ“ AWS IAM User has inline or directly attached policies 🟒1🟠 x1, 🟒 x5
πŸ“ AWS IAM User with console and programmatic access set during the initial creation 🟒🟒 x3
πŸ“ AWS S3 Bucket MFA Delete is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ Azure App Service Authentication is disabled and Basic Authentication is enabled 🟒1🟒 x6
πŸ“ Azure App Service Basic Authentication is enabled 🟒🟒 x3
πŸ“ Consumer Google Accounts are used 🟒🟒 x3