NIST 800-53 r5 · Controls catalogue · Family IA
IA-12Identity Proofing
Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; Resolve user identities to a unique individual; and Collect, validate, and verify identity evidence.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (4)
- T1078 Valid Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.002 Domain Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.003 Local Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.004 Cloud Accounts Stealth, Persistence, Privilege Escalation, Initial Access
Weaknesses this control addresses (2)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-287 | Improper Authentication | 5,200+ | Identity proofing requires collecting, validating, and verifying evidence to resolve claims to unique individuals, directly preventing insufficient proof of identity during account establishment. |
CWE-290 | Authentication Bypass by Spoofing | 700+ | Requiring verifiable identity evidence at appropriate assurance levels makes it substantially harder for attackers to successfully spoof or impersonate users to obtain accounts. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2023-7028 KEV UPD | 9.9 | 10.0 | 0.9465 | good |
CVE-2025-40554 | 9.5 | 9.8 | 0.5731 | good |
CVE-2026-55040 KEV UPD | 9.5 | 9.1 | 0.0549 | good |
CVE-2025-40552 UPD | 9.3 | 9.8 | 0.4973 | good |
CVE-2025-6216 UPD | 9.0 | 9.8 | 0.3513 | good |
CVE-2025-47646 UPD | 8.7 | 9.8 | 0.2565 | good |
CVE-2023-49340 UPD | 7.5 | 9.8 | 0.0086 | good |
CVE-2024-8878 UPD | 7.5 | 9.8 | 0.0126 | good |
CVE-2025-30411 UPD | 7.5 | 10.0 | 0.0069 | good |
CVE-2025-30412 UPD | 7.5 | 10.0 | 0.0062 | good |
CVE-2024-48428 UPD | 7.4 | 9.8 | 0.0076 | good |
CVE-2024-11103 UPD | 7.4 | 9.8 | 0.0075 | good |
CVE-2024-53552 UPD | 7.4 | 9.8 | 0.0082 | good |
CVE-2024-11350 UPD | 7.4 | 9.8 | 0.0070 | good |
CVE-2025-1387 UPD | 7.4 | 9.8 | 0.0057 | good |
CVE-2024-54092 UPD | 7.4 | 9.8 | 0.0074 | good |
CVE-2025-10127 UPD | 7.4 | 9.8 | 0.0063 | good |
CVE-2025-12870 | 7.4 | 9.8 | 0.0062 | good |
CVE-2025-12871 | 7.4 | 9.8 | 0.0058 | good |
CVE-2025-64113 UPD | 7.4 | 9.8 | 0.0060 | good |
CVE-2023-53894 UPD | 7.4 | 9.8 | 0.0063 | good |
CVE-2022-50910 UPD | 7.4 | 9.8 | 0.0068 | good |
CVE-2025-4320 UPD | 7.4 | 10.0 | 0.0047 | good |
CVE-2026-28268 | 7.4 | 9.8 | 0.0067 | good |
CVE-2026-11551 | 7.4 | 9.8 | 0.0063 | good |