NIST 800-53 r5 · Controls catalogue · Family IA
IA-2Identification and Authentication (Organizational Users)
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Last updated: 21 August 2026 14:15 UTC
Implementations targeting this control (2)
- azure-mcsb-im-06-mfa Subscription owners have multi-factor authentication enabled Microsoft.Authorization/roleAssignments partial protect enforce
- gcp-cis-iam-mfa-enforcement Owner principals have MFA / 2-step verification cloudidentity.googleapis.com/User partial protect enforce
ATT&CK techniques this control mitigates (171)
- T1003 OS Credential Dumping Credential Access
- T1003.001 LSASS Memory Credential Access
- T1003.002 Security Account Manager Credential Access
- T1003.003 NTDS Credential Access
- T1003.004 LSA Secrets Credential Access
- T1003.005 Cached Domain Credentials Credential Access
- T1003.006 DCSync Credential Access
- T1003.007 Proc Filesystem Credential Access
- T1003.008 /etc/passwd and /etc/shadow Credential Access
- T1021 Remote Services Lateral Movement
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.002 SMB/Windows Admin Shares Lateral Movement
- T1021.003 Distributed Component Object Model Lateral Movement
- T1021.004 SSH Lateral Movement
- T1021.005 VNC Lateral Movement
- T1021.006 Windows Remote Management Lateral Movement
- T1021.007 Cloud Services Lateral Movement
- T1021.008 Direct Cloud VM Connections Lateral Movement
- T1036.007 Double File Extension Stealth
- T1036.010 Masquerade Account Name Stealth
- T1040 Network Sniffing Credential Access, Discovery
- T1047 Windows Management Instrumentation Execution
- T1053 Scheduled Task/Job Execution, Persistence, Privilege Escalation
- T1053.002 At Execution, Persistence, Privilege Escalation
- T1053.003 Cron Execution, Persistence, Privilege Escalation
- T1053.005 Scheduled Task Execution, Persistence, Privilege Escalation
- T1053.006 Systemd Timers Execution, Persistence, Privilege Escalation
- T1053.007 Container Orchestration Job Execution, Persistence, Privilege Escalation
- T1055 Process Injection Stealth, Privilege Escalation
- T1055.008 Ptrace System Calls Stealth, Privilege Escalation
- T1056.003 Web Portal Capture Collection, Credential Access
- T1059 Command and Scripting Interpreter Execution
- T1059.001 PowerShell Execution
- T1059.008 Network Device CLI Execution
- T1059.009 Cloud API Execution
- T1072 Software Deployment Tools Execution, Lateral Movement
- T1078 Valid Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.002 Domain Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.003 Local Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.004 Cloud Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1087.004 Cloud Account Discovery
- T1098 Account Manipulation Persistence, Privilege Escalation
- T1098.001 Additional Cloud Credentials Persistence, Privilege Escalation
- T1098.002 Additional Email Delegate Permissions Persistence, Privilege Escalation
- T1098.003 Additional Cloud Roles Persistence, Privilege Escalation
- T1098.004 SSH Authorized Keys Persistence, Privilege Escalation
- T1098.007 Additional Local or Domain Groups Persistence, Privilege Escalation
- T1110 Brute Force Credential Access
- T1110.001 Password Guessing Credential Access
- T1110.002 Password Cracking Credential Access
Weaknesses this control addresses (4)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-287 | Improper Authentication | 5,200+ | Requires unique identification and authentication of organizational users, directly preventing improper authentication. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Mandates authentication for organizational users and their associated processes, eliminating missing authentication for critical functions. |
CWE-1392 | Use of Default Credentials | 100+ | Unique identification requirement prevents use of default or shared credentials by organizational users. |
CWE-1390 | Weak Authentication | 88 | Enforces authentication for users, reducing the viability of weak authentication mechanisms. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-51567 KEV UPD | 10.0 | 10.0 | 0.8652 | good |
CVE-2025-32433 KEV UPD | 10.0 | 10.0 | 0.9859 | good |
CVE-2025-34028 KEV UPD | 10.0 | 10.0 | 0.9766 | good |
CVE-2025-32975 KEV UPD | 10.0 | 10.0 | 0.0242 | good |
CVE-2026-20127 KEV UPD | 10.0 | 10.0 | 0.8824 | good |
CVE-2026-20182 KEV UPD | 10.0 | 10.0 | 0.9152 | good |
CVE-2024-21410 KEV UPD | 9.9 | 9.8 | 0.1266 | good |
CVE-2023-38096 UPD | 9.9 | 9.8 | 0.8155 | good |
CVE-2024-4358 KEV UPD | 9.9 | 9.8 | 0.9748 | good |
CVE-2024-5910 KEV UPD | 9.9 | 9.8 | 0.9178 | good |
CVE-2024-7593 KEV UPD | 9.9 | 9.8 | 0.9999 | good |
CVE-2024-47575 KEV UPD | 9.9 | 9.8 | 0.9495 | good |
CVE-2024-0012 KEV UPD | 9.9 | 9.8 | 0.9970 | good |
CVE-2024-11680 KEV UPD | 9.9 | 9.8 | 0.9156 | good |
CVE-2024-53704 KEV UPD | 9.9 | 9.8 | 0.9513 | good |
CVE-2025-1044 UPD | 9.9 | 9.8 | 0.7530 | good |
CVE-2024-54085 KEV UPD | 9.9 | 9.8 | 0.6083 | good |
CVE-2025-31161 KEV UPD | 9.9 | 9.8 | 0.9995 | good |
CVE-2025-3248 KEV UPD | 9.9 | 9.8 | 1.0000 | good |
CVE-2025-61882 KEV UPD | 9.9 | 9.8 | 0.9972 | good |
CVE-2025-61757 KEV UPD | 9.9 | 9.8 | 0.8831 | good |
CVE-2026-24423 KEV UPD | 9.9 | 9.8 | 0.8769 | good |
CVE-2026-33017 KEV UPD | 9.9 | 9.8 | 0.9618 | good |
CVE-2026-39987 KEV UPD | 9.9 | 9.8 | 0.9658 | good |
CVE-2026-41940 KEV | 9.9 | 9.8 | 0.9811 | good |