NIST 800-53 r5 · Controls catalogue · Family IA
IA-4Identifier Management
Manage system identifiers by: Receiving authorization from {{ insert: param, ia-04_odp.01 }} to assign an individual, group, role, service, or device identifier; Selecting an identifier that identifies an individual, group, role, service, or device; Assigning the identifier to the intended individual, group, role, service, or device; and Preventing reuse of identifiers for {{ insert: param, ia-04_odp.02 }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (36)
- T1003 OS Credential Dumping Credential Access
- T1003.005 Cached Domain Credentials Credential Access
- T1003.006 DCSync Credential Access
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.005 VNC Lateral Movement
- T1053 Scheduled Task/Job Execution, Persistence, Privilege Escalation
- T1053.002 At Execution, Persistence, Privilege Escalation
- T1053.005 Scheduled Task Execution, Persistence, Privilege Escalation
- T1098.007 Additional Local or Domain Groups Persistence, Privilege Escalation
- T1110 Brute Force Credential Access
- T1110.001 Password Guessing Credential Access
- T1110.002 Password Cracking Credential Access
- T1110.003 Password Spraying Credential Access
- T1110.004 Credential Stuffing Credential Access
- T1213 Data from Information Repositories Collection
- T1213.001 Confluence Collection
- T1213.002 Sharepoint Collection
- T1213.004 Customer Relationship Management Software Collection
- T1213.005 Messaging Applications Collection
- T1528 Steal Application Access Token Credential Access
- T1530 Data from Cloud Storage Collection
- T1537 Transfer Data to Cloud Account Exfiltration
- T1543 Create or Modify System Process Persistence, Privilege Escalation
- T1547.006 Kernel Modules and Extensions Persistence, Privilege Escalation
- T1550.001 Application Access Token Lateral Movement
- T1552 Unsecured Credentials Credential Access
- T1552.005 Cloud Instance Metadata API Credential Access
- T1563 Remote Service Session Hijacking Lateral Movement
- T1578 Modify Cloud Compute Infrastructure Defense Impairment
- T1578.001 Create Snapshot Defense Impairment
- T1578.002 Create Cloud Instance Defense Impairment
- T1578.003 Delete Cloud Instance Defense Impairment
- T1602 Data from Configuration Repository Collection
- T1602.001 SNMP (MIB Dump) Collection
- T1602.002 Network Device Configuration Dump Collection
- T1685 Disable or Modify Tools Defense Impairment
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Requires explicit authorization before any identifier can be assigned, preventing missing authorization. |
CWE-284 | Improper Access Control | 6,900+ | Ensures identifiers are properly authorized and assigned, supporting effective access control. |
CWE-287 | Improper Authentication | 5,200+ | Provides unique, authorized identifiers that are foundational to preventing authentication weaknesses. |
CWE-863 | Incorrect Authorization | 3,900+ | Enforces correct authorization checks during the identifier assignment process. |
CWE-285 | Improper Authorization | 1,500+ | Mandates authorization for identifier assignment, reducing risks of improper authorization. |
CWE-286 | Incorrect User Management | 32 | Directly implements correct management of identifiers for individuals, groups, roles, services, and devices. |
CWE-642 | External Control of Critical State Data | 18 | Requires authorization and prevents reuse, mitigating external control of critical identifier state data. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-13609 UPD | 5.9 | 8.2 | 0.0044 | good |
CVE-2026-71327 | 5.5 | 7.6 | 0.0036 | good |
CVE-2026-57024 | 4.3 | 5.3 | 0.0025 | good |
CVE-2024-41146 UPD | 3.7 | 4.6 | 0.0031 | good |
CVE-2026-5794 | 3.5 | 4.9 | 0.0026 | good |
CVE-2024-56511 UPD | 9.2 | 9.8 | 0.4446 | good |
CVE-2023-26689 UPD | 7.4 | 9.8 | 0.0062 | good |
CVE-2025-13613 UPD | 7.3 | 9.8 | 0.0048 | good |
CVE-2026-24058 UPD | 7.3 | 9.8 | 0.0054 | good |
CVE-2026-8457 UPD | 7.3 | 9.8 | 0.0040 | good |
CVE-2025-64725 | 7.2 | 9.8 | 0.0035 | good |
CVE-2026-9701 | 7.2 | 9.8 | 0.0028 | good |
CVE-2025-7972 UPD | 6.9 | 9.1 | 0.0050 | good |
CVE-2025-29266 UPD | 6.7 | 9.6 | 0.0041 | good |
CVE-2026-35638 | 6.4 | 8.8 | 0.0029 | good |
CVE-2026-50627 UPD | 6.4 | 9.1 | 0.0044 | good |
CVE-2024-48853 UPD | 6.3 | 9.0 | 0.0037 | good |
CVE-2024-55634 UPD | 6.1 | 8.1 | 0.0041 | good |
CVE-2025-59048 UPD | 6.0 | 8.1 | 0.0025 | good |
CVE-2026-56428 | 6.0 | 8.1 | 0.0028 | good |
CVE-2024-11283 UPD | 5.8 | 7.5 | 0.0042 | good |
CVE-2025-41248 UPD | 5.8 | 7.5 | 0.0043 | good |
CVE-2026-10842 | 5.8 | 7.5 | 0.0031 | good |
CVE-2022-35503 UPD | 5.7 | 7.5 | 0.0054 | good |
CVE-2024-28020 UPD | 5.6 | 8.0 | 0.0037 | good |