NIST 800-53 r5 · Controls catalogue · Family IA
IA-9Service Identification and Authentication
Uniquely identify and authenticate {{ insert: param, ia-09_odp }} before establishing communications with devices, users, or other services or applications.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (22)
- T1036 Masquerading Stealth
- T1036.001 Invalid Code Signature Stealth
- T1036.005 Match Legitimate Resource Name or Location Stealth
- T1059 Command and Scripting Interpreter Execution
- T1059.001 PowerShell Execution
- T1059.002 AppleScript Execution
- T1213.003 Code Repositories Collection
- T1525 Implant Internal Image Persistence
- T1546 Event Triggered Execution Privilege Escalation, Persistence
- T1546.006 LC_LOAD_DYLIB Addition Privilege Escalation, Persistence
- T1546.013 PowerShell Profile Privilege Escalation, Persistence
- T1553 Subvert Trust Controls Defense Impairment
- T1553.004 Install Root Certificate Defense Impairment
- T1554 Compromise Host Software Binary Persistence
- T1566 Phishing Initial Access
- T1566.001 Spearphishing Attachment Initial Access
- T1566.002 Spearphishing Link Initial Access
- T1598 Phishing for Information Reconnaissance
- T1598.002 Spearphishing Attachment Reconnaissance
- T1598.003 Spearphishing Link Reconnaissance
- T1685 Disable or Modify Tools Defense Impairment
- T1688 Safe Mode Boot Defense Impairment
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-287 | Improper Authentication | 5,200+ | Requires unique identification and authentication of services before any communications, directly mitigating improper authentication. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Mandates authentication prior to establishing communications with services, preventing missing authentication for this critical function. |
CWE-346 | Origin Validation Error | 700+ | Requires unique identification of the service before communications, addressing failures to validate the origin of the interaction. |
CWE-290 | Authentication Bypass by Spoofing | 700+ | Unique identification and authentication of services before communications makes spoofing of service identities substantially harder. |
CWE-940 | Improper Verification of Source of a Communication Channel | 56 | Enforces verification of the source of a communication channel by requiring identification and authentication of services first. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-10576 UPD | 7.0 | 9.4 | 0.0016 | good |
CVE-2026-33173 | 4.4 | 5.3 | 0.0039 | good |
CVE-2024-51567 KEV UPD | 10.0 | 10.0 | 0.8652 | good |
CVE-2025-32433 KEV UPD | 10.0 | 10.0 | 0.9859 | good |
CVE-2025-34028 KEV UPD | 10.0 | 10.0 | 0.9766 | good |
CVE-2024-5910 KEV UPD | 9.9 | 9.8 | 0.9178 | good |
CVE-2024-47575 KEV UPD | 9.9 | 9.8 | 0.9495 | good |
CVE-2024-0012 KEV UPD | 9.9 | 9.8 | 0.9970 | good |
CVE-2024-11680 KEV UPD | 9.9 | 9.8 | 0.9156 | good |
CVE-2025-3248 KEV UPD | 9.9 | 9.8 | 1.0000 | good |
CVE-2025-61757 KEV UPD | 9.9 | 9.8 | 0.8831 | good |
CVE-2026-24423 KEV UPD | 9.9 | 9.8 | 0.8769 | good |
CVE-2026-33017 KEV UPD | 9.9 | 9.8 | 0.9618 | good |
CVE-2026-39987 KEV UPD | 9.9 | 9.8 | 0.9658 | good |
CVE-2026-41940 KEV | 9.9 | 9.8 | 0.9811 | good |
CVE-2026-20253 KEV UPD | 9.9 | 9.8 | 0.9694 | good |
CVE-2026-35273 KEV | 9.9 | 9.8 | 0.9547 | good |
CVE-2026-72529 KEV | 9.9 | 9.8 | 0.0078 | good |
CVE-2024-46506 UPD | 9.7 | 10.0 | 0.6204 | good |
CVE-2025-0108 KEV UPD | 9.5 | 9.1 | 0.9846 | good |
CVE-2025-58434 UPD | 9.3 | 9.8 | 0.4989 | good |
CVE-2025-4008 KEV UPD | 9.2 | 8.8 | 0.9326 | good |
CVE-2025-52665 UPD | 9.2 | 10.0 | 0.4097 | good |
CVE-2026-23744 UPD | 9.2 | 9.8 | 0.4503 | good |
CVE-2026-33032 UPD | 9.1 | 9.8 | 0.3848 | good |