NIST 800-53 r5 · Controls catalogue · Family IA
IA-8Identification and Authentication (Non-organizational Users)
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (22)
- T1053 Scheduled Task/Job Execution, Persistence, Privilege Escalation
- T1053.007 Container Orchestration Job Execution, Persistence, Privilege Escalation
- T1059 Command and Scripting Interpreter Execution
- T1059.001 PowerShell Execution
- T1059.008 Network Device CLI Execution
- T1087.004 Cloud Account Discovery
- T1190 Exploit Public-Facing Application Initial Access
- T1210 Exploitation of Remote Services Lateral Movement
- T1213 Data from Information Repositories Collection
- T1213.001 Confluence Collection
- T1213.002 Sharepoint Collection
- T1213.004 Customer Relationship Management Software Collection
- T1213.005 Messaging Applications Collection
- T1528 Steal Application Access Token Credential Access
- T1530 Data from Cloud Storage Collection
- T1537 Transfer Data to Cloud Account Exfiltration
- T1538 Cloud Service Dashboard Discovery
- T1542 Pre-OS Boot Stealth, Persistence
- T1542.001 System Firmware Stealth, Persistence
- T1542.003 Bootkit Stealth, Persistence
- T1542.005 TFTP Boot Stealth, Persistence
- T1547.006 Kernel Modules and Extensions Persistence, Privilege Escalation
Weaknesses this control addresses (6)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-287 | Improper Authentication | 5,200+ | Mandates unique identification and authentication of non-organizational users, directly mitigating improper authentication. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Requires authentication for non-organizational users, preventing access to critical functions without proper identification and authentication. |
CWE-290 | Authentication Bypass by Spoofing | 700+ | Unique identification of non-organizational users reduces the feasibility of authentication bypass by spoofing. |
CWE-288 | Authentication Bypass Using an Alternate Path or Channel | 600+ | Enforces authentication for non-organizational users, making it harder to bypass via alternate paths or channels. |
CWE-302 | Authentication Bypass by Assumed-Immutable Data | 42 | Proper authentication for non-organizational users counters bypasses relying on assumed-immutable data. |
CWE-304 | Missing Critical Step in Authentication | 39 | Ensures the authentication process is followed for non-organizational users, avoiding missing critical steps. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-51567 KEV UPD | 10.0 | 10.0 | 0.8652 | good |
CVE-2025-32433 KEV UPD | 10.0 | 10.0 | 0.9859 | good |
CVE-2025-34028 KEV UPD | 10.0 | 10.0 | 0.9766 | good |
CVE-2024-5910 KEV UPD | 9.9 | 9.8 | 0.9178 | good |
CVE-2024-47575 KEV UPD | 9.9 | 9.8 | 0.9495 | good |
CVE-2024-0012 KEV UPD | 9.9 | 9.8 | 0.9970 | good |
CVE-2024-11680 KEV UPD | 9.9 | 9.8 | 0.9156 | good |
CVE-2025-31161 KEV UPD | 9.9 | 9.8 | 0.9995 | good |
CVE-2025-3248 KEV UPD | 9.9 | 9.8 | 1.0000 | good |
CVE-2025-61757 KEV UPD | 9.9 | 9.8 | 0.8831 | good |
CVE-2026-24423 KEV UPD | 9.9 | 9.8 | 0.8769 | good |
CVE-2026-33017 KEV UPD | 9.9 | 9.8 | 0.9618 | good |
CVE-2026-39987 KEV UPD | 9.9 | 9.8 | 0.9658 | good |
CVE-2026-41940 KEV | 9.9 | 9.8 | 0.9811 | good |
CVE-2026-20253 KEV UPD | 9.9 | 9.8 | 0.9694 | good |
CVE-2026-35273 KEV | 9.9 | 9.8 | 0.9547 | good |
CVE-2026-72529 KEV | 9.9 | 9.8 | 0.0078 | good |
CVE-2024-46506 UPD | 9.7 | 10.0 | 0.6204 | good |
CVE-2025-0108 KEV UPD | 9.5 | 9.1 | 0.9846 | good |
CVE-2025-58434 UPD | 9.3 | 9.8 | 0.4989 | good |
CVE-2025-4008 KEV UPD | 9.2 | 8.8 | 0.9326 | good |
CVE-2025-52665 UPD | 9.2 | 10.0 | 0.4097 | good |
CVE-2026-23744 UPD | 9.2 | 9.8 | 0.4503 | good |
CVE-2026-33032 UPD | 9.1 | 9.8 | 0.3848 | good |
CVE-2026-26190 | 9.0 | 9.8 | 0.3691 | good |