Skip to main content
IAC

Identification & Authentication

123 controls

Implement secure, compliant and resilient Identity and Access Management (IAM) capabilities that enforce least privilege across human users, devices, service accounts and other Non-Person Entities (NPEs).

SCF # Control Name Weight NIST CSF Frameworks
IAC-01 Identification & Authentication Policy 10 — Critical Govern 36
IAC-02 Identity & Access Management (IAM) 10 — Critical Govern 129
IAC-03 Authenticate, Authorize and Audit (AAA) 9 — Critical Protect 72
IAC-03.1 Replay-Resistant Authentication 9 — Critical Protect 41
IAC-03.2 Retain Access Records 3 — Low Protect 9
IAC-03.3 Identity Providers (IdP) & Authorization Servers 7 — High Identify 2
IAC-04 User Provisioning & De-Provisioning 10 — Critical Protect 58
IAC-04.1 Change of Roles & Duties 10 — Critical Protect 32
IAC-04.2 Termination of Employment 10 — Critical Protect 60
IAC-05 Identity Proofing (Identity Verification) 10 — Critical Protect 33
IAC-05.1 In-Person or Trusted Third-Party Registration 9 — Critical Protect 10
IAC-05.2 Identity Evidence 5 — Medium Protect 15
IAC-05.3 Identity Evidence Validation & Verification 5 — Medium Protect 14
IAC-05.4 In-Person Validation & Verification 5 — Medium Protect 8
IAC-05.5 Address Confirmation 1 — Low Protect 11
IAC-06 Role-Based Access Control (RBAC) 9 — Critical Protect 96
IAC-07 Attribute-Based Access Control (ABAC) 5 — Medium Identify 20
IAC-07.1 Real-Time Access Decisions 3 — Low Protect 1
IAC-07.2 Access Profile Rules 5 — Medium Protect 1
IAC-08 Account Management 10 — Critical Protect 83
IAC-08.1 Automated System Account Management (Directory Services) 5 — Medium Protect 49
IAC-08.2 Authorized Accounts 9 — Critical Protect 2
IAC-08.3 User & Service Account Inventories 10 — Critical Identify 10
IAC-08.4 Disable Inactive Accounts 10 — Critical Protect 45
IAC-08.5 Account Disabling for High Risk Individuals 10 — Critical Protect 20
IAC-08.6 Automated Audit Actions 5 — Medium Protect 18
IAC-08.7 Account Separation Between Infrastructure Environments 7 — High Protect 2
IAC-08.8 Multiple System Accounts 5 — Medium Protect 7
IAC-09 Management Approval For New or Changed Accounts 10 — Critical Detect 30
IAC-09.1 Management Approval For Privileged Accounts 10 — Critical Protect 38
IAC-10 Privileged Account Management (PAM) 10 — Critical Protect 60
IAC-10.1 Privileged Account Inventories 10 — Critical Protect 25
IAC-10.2 Privileged Account Separation 4 — Medium Protect 3
IAC-10.3 Dedicated Privileged Account 7 — High Protect 4
IAC-10.4 Privileged Command Execution 5 — Medium Protect 2
IAC-10.5 Manual Override 3 — Low Protect 2
IAC-11 Emergency Accounts 5 — Medium Respond 8
IAC-11.1 Removal of Temporary / Emergency Accounts 9 — Critical Protect 22
IAC-12 Periodic Review of Individual & Service Account Privileges 10 — Critical Detect 62
IAC-12.1 System Account Reviews 10 — Critical Protect 13
IAC-13 User Identity (ID) Management 9 — Critical Protect 36
IAC-13.1 Standardized Identifier Management (User Names) 9 — Critical Protect 63
IAC-13.2 Employment Status Identification 7 — High Protect 20
IAC-13.3 Citizenship Identification 3 — Low Identify 2
IAC-13.4 Dynamic Management 5 — Medium Protect 4
IAC-13.5 Cross-Organization Management 5 — Medium Protect 10
IAC-13.6 Privileged Account Identifiers 9 — Critical Protect 12
IAC-13.7 Pairwise Pseudonymous Identifiers (PPID) 1 — Low Protect 5
IAC-14 Authenticator Management 10 — Critical Protect 84
IAC-14.1 Events Requiring Authenticator Change 9 — Critical Protect 4
IAC-14.2 Protection of Authenticators 10 — Critical Protect 49
IAC-14.3 No Embedded Unencrypted Static Authenticators 10 — Critical Protect 27
IAC-14.4 Default Authenticators 10 — Critical Protect 77
IAC-14.5 Expiration of Cached Authenticators 5 — Medium Protect 10
IAC-15 Password-Based Authentication 9 — Critical Protect 77
IAC-15.1 Automated Support For Password Strength 5 — Medium Protect 38
IAC-15.2 Password Managers 8 — High Protect 21
IAC-16 Passkeys 8 — High Protect 2
IAC-17 Biometric Authentication 5 — Medium Protect 6
IAC-18 PKI-Based Authentication 9 — Critical Protect 32
IAC-19 Hardware Token-Based Authentication 9 — Critical Protect 29
IAC-20 Authenticator Feedback 6 — Medium Protect 38
IAC-21 Restrictions on Shared Groups / Accounts 10 — Critical Protect 36
IAC-21.1 Group Authentication 7 — High Protect 21
IAC-22 User Responsibilities for Account Management 10 — Critical Protect 26
IAC-23 Credential Sharing 10 — Critical Protect 16
IAC-24 Reference Monitor 1 — Low Protect 3
IAC-25 Access Enforcement 10 — Critical Protect 76
IAC-25.1 Access To Sensitive / Regulated Data 10 — Critical Protect 21
IAC-25.2 Database Access 10 — Critical Protect 10
IAC-26 Use of Privileged Utility Programs 9 — Critical Protect 14
IAC-27 Dedicated Administrative Machines 8 — High Protect 12
IAC-28 Dual Authorization for Privileged Commands 5 — Medium Protect 9
IAC-29 Revocation of Access Authorizations 9 — Critical Protect 16
IAC-30 Least Privilege 10 — Critical Protect 103
IAC-30.1 Prohibit Non-Privileged Users from Executing Privileged Functions 9 — Critical Protect 31
IAC-30.2 Authorize Access to Security Functions 9 — Critical Protect 21
IAC-30.3 Non-Privileged Access for Non-Security Functions 9 — Critical Protect 34
IAC-30.4 Auditing Use of Privileged Functions 9 — Critical Detect 30
IAC-30.5 Network Access to Privileged Commands 5 — Medium Protect 8
IAC-30.6 Privilege Levels for Code Execution 5 — Medium Protect 8
IAC-31 Permitted Actions Without Identification or Authorization 8 — High Protect 26
IAC-32 Identification & Authentication for Organizational Users 9 — Critical Protect 83
IAC-32.1 Out-of-Band Authentication (OOBA) 5 — Medium Protect 4
IAC-32.2 Acceptance of PIV Credentials 2 — Low Protect 19
IAC-33 Identification & Authentication for Non-Organizational Users 9 — Critical Protect 53
IAC-33.1 Acceptance of Third-Party Credentials 2 — Low Protect 19
IAC-33.2 Acceptance of External Authenticators 4 — Medium Protect 2
IAC-33.3 Disassociability 2 — Low Protect 2
IAC-33.4 Acceptance of PIV Credentials from Other Organizations 2 — Low Protect 16
IAC-33.5 Use of FICAM-Issued Profiles 2 — Low Protect 16
IAC-34 Identification & Authentication for Devices 9 — Critical Protect 60
IAC-34.1 Device Attestation 5 — Medium Protect 5
IAC-34.2 Device Authorization Enforcement 5 — Medium Protect 2
IAC-35 Access Control For Mobile Devices 9 — Critical Protect 46
IAC-36 Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS) 9 — Critical Protect 30
IAC-36.1 Sharing Identification & Authentication Information 5 — Medium Protect 6
IAC-36.2 Privileged Access by Non-Organizational Users 9 — Critical Protect 11
IAC-37 Multi-Factor Authentication (MFA) 9 — Critical Protect 95
IAC-37.1 Replay-Resistant Multi-Factor Authentication (MFA) 8 — High Protect 8
IAC-37.2 Phishing-Resistant Multi-Factor Authentication (MFA) 9 — Critical Protect 11
IAC-37.3 Out-of-Band (OOB) Multi-Factor Authentication (MFA) 5 — Medium Protect 37
IAC-37.4 Alternative Multi-Factor Authentication (MFA) 5 — Medium Protect 1
IAC-37.5 Multi-Factor Authentication (MFA) For Network Access to Privileged Accounts 9 — Critical Protect 59
IAC-37.6 Multi-Factor Authentication (MFA) For Network Access to Non-Privileged Accounts 7 — High Protect 46
IAC-37.7 Multi-Factor Authentication (MFA) For Local Access to Privileged Accounts 5 — Medium Protect 51
IAC-38 Cryptographic Module Authentication 8 — High Protect 27
IAC-39 Hardware Security Modules (HSM) 3 — Low Protect 5
IAC-40 Single Sign-On (SSO) Transparent Authentication 5 — Medium Protect 5
IAC-41 Adaptive Identification & Authentication 5 — Medium Protect 9
IAC-42 Continuous Authentication 2 — Low Protect 4
IAC-43 Re-Authentication 8 — High Protect 31
IAC-44 Mutual Authentication (MA) 2 — Low Protect 2
IAC-45 Federated Credential Management 4 — Medium Protect 10
IAC-46 Invalidate Session Identifiers at Logout 5 — Medium Protect 7
IAC-47 Unique System-Generated Session Identifiers 3 — Low Protect 7
IAC-48 Software Defined Storage (SDS) Data Access Control 3 — Low Protect 1
IAC-49 Sensitive / Regulated Data Access Enforcement 7 — High Protect 14
IAC-49.1 Sensitive / Regulated Data Actions 7 — High Protect 5
IAC-50 Compliance As Code (CAC) Identity Governance 7 — High Identify 0
IAC-51 Compliance As Code (CAC) Least Privileges 8 — High Protect 0
IAC-52 Compliance As Code (CAC) Credential Lifecycle Management 7 — High Protect 0
IAC-53 Compliance As Code (CAC) Credentials Management 8 — High Protect 0

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.