| IAC-01 | Identification & Authentication Policy | 10 — Critical | Govern | 36 |
| IAC-02 | Identity & Access Management (IAM) | 10 — Critical | Govern | 129 |
| IAC-03 | Authenticate, Authorize and Audit (AAA) | 9 — Critical | Protect | 72 |
| IAC-03.1 | Replay-Resistant Authentication | 9 — Critical | Protect | 41 |
| IAC-03.2 | Retain Access Records | 3 — Low | Protect | 9 |
| IAC-03.3 | Identity Providers (IdP) & Authorization Servers | 7 — High | Identify | 2 |
| IAC-04 | User Provisioning & De-Provisioning | 10 — Critical | Protect | 58 |
| IAC-04.1 | Change of Roles & Duties | 10 — Critical | Protect | 32 |
| IAC-04.2 | Termination of Employment | 10 — Critical | Protect | 60 |
| IAC-05 | Identity Proofing (Identity Verification) | 10 — Critical | Protect | 33 |
| IAC-05.1 | In-Person or Trusted Third-Party Registration | 9 — Critical | Protect | 10 |
| IAC-05.2 | Identity Evidence | 5 — Medium | Protect | 15 |
| IAC-05.3 | Identity Evidence Validation & Verification | 5 — Medium | Protect | 14 |
| IAC-05.4 | In-Person Validation & Verification | 5 — Medium | Protect | 8 |
| IAC-05.5 | Address Confirmation | 1 — Low | Protect | 11 |
| IAC-06 | Role-Based Access Control (RBAC) | 9 — Critical | Protect | 96 |
| IAC-07 | Attribute-Based Access Control (ABAC) | 5 — Medium | Identify | 20 |
| IAC-07.1 | Real-Time Access Decisions | 3 — Low | Protect | 1 |
| IAC-07.2 | Access Profile Rules | 5 — Medium | Protect | 1 |
| IAC-08 | Account Management | 10 — Critical | Protect | 83 |
| IAC-08.1 | Automated System Account Management (Directory Services) | 5 — Medium | Protect | 49 |
| IAC-08.2 | Authorized Accounts | 9 — Critical | Protect | 2 |
| IAC-08.3 | User & Service Account Inventories | 10 — Critical | Identify | 10 |
| IAC-08.4 | Disable Inactive Accounts | 10 — Critical | Protect | 45 |
| IAC-08.5 | Account Disabling for High Risk Individuals | 10 — Critical | Protect | 20 |
| IAC-08.6 | Automated Audit Actions | 5 — Medium | Protect | 18 |
| IAC-08.7 | Account Separation Between Infrastructure Environments | 7 — High | Protect | 2 |
| IAC-08.8 | Multiple System Accounts | 5 — Medium | Protect | 7 |
| IAC-09 | Management Approval For New or Changed Accounts | 10 — Critical | Detect | 30 |
| IAC-09.1 | Management Approval For Privileged Accounts | 10 — Critical | Protect | 38 |
| IAC-10 | Privileged Account Management (PAM) | 10 — Critical | Protect | 60 |
| IAC-10.1 | Privileged Account Inventories | 10 — Critical | Protect | 25 |
| IAC-10.2 | Privileged Account Separation | 4 — Medium | Protect | 3 |
| IAC-10.3 | Dedicated Privileged Account | 7 — High | Protect | 4 |
| IAC-10.4 | Privileged Command Execution | 5 — Medium | Protect | 2 |
| IAC-10.5 | Manual Override | 3 — Low | Protect | 2 |
| IAC-11 | Emergency Accounts | 5 — Medium | Respond | 8 |
| IAC-11.1 | Removal of Temporary / Emergency Accounts | 9 — Critical | Protect | 22 |
| IAC-12 | Periodic Review of Individual & Service Account Privileges | 10 — Critical | Detect | 62 |
| IAC-12.1 | System Account Reviews | 10 — Critical | Protect | 13 |
| IAC-13 | User Identity (ID) Management | 9 — Critical | Protect | 36 |
| IAC-13.1 | Standardized Identifier Management (User Names) | 9 — Critical | Protect | 63 |
| IAC-13.2 | Employment Status Identification | 7 — High | Protect | 20 |
| IAC-13.3 | Citizenship Identification | 3 — Low | Identify | 2 |
| IAC-13.4 | Dynamic Management | 5 — Medium | Protect | 4 |
| IAC-13.5 | Cross-Organization Management | 5 — Medium | Protect | 10 |
| IAC-13.6 | Privileged Account Identifiers | 9 — Critical | Protect | 12 |
| IAC-13.7 | Pairwise Pseudonymous Identifiers (PPID) | 1 — Low | Protect | 5 |
| IAC-14 | Authenticator Management | 10 — Critical | Protect | 84 |
| IAC-14.1 | Events Requiring Authenticator Change | 9 — Critical | Protect | 4 |
| IAC-14.2 | Protection of Authenticators | 10 — Critical | Protect | 49 |
| IAC-14.3 | No Embedded Unencrypted Static Authenticators | 10 — Critical | Protect | 27 |
| IAC-14.4 | Default Authenticators | 10 — Critical | Protect | 77 |
| IAC-14.5 | Expiration of Cached Authenticators | 5 — Medium | Protect | 10 |
| IAC-15 | Password-Based Authentication | 9 — Critical | Protect | 77 |
| IAC-15.1 | Automated Support For Password Strength | 5 — Medium | Protect | 38 |
| IAC-15.2 | Password Managers | 8 — High | Protect | 21 |
| IAC-16 | Passkeys | 8 — High | Protect | 2 |
| IAC-17 | Biometric Authentication | 5 — Medium | Protect | 6 |
| IAC-18 | PKI-Based Authentication | 9 — Critical | Protect | 32 |
| IAC-19 | Hardware Token-Based Authentication | 9 — Critical | Protect | 29 |
| IAC-20 | Authenticator Feedback | 6 — Medium | Protect | 38 |
| IAC-21 | Restrictions on Shared Groups / Accounts | 10 — Critical | Protect | 36 |
| IAC-21.1 | Group Authentication | 7 — High | Protect | 21 |
| IAC-22 | User Responsibilities for Account Management | 10 — Critical | Protect | 26 |
| IAC-23 | Credential Sharing | 10 — Critical | Protect | 16 |
| IAC-24 | Reference Monitor | 1 — Low | Protect | 3 |
| IAC-25 | Access Enforcement | 10 — Critical | Protect | 76 |
| IAC-25.1 | Access To Sensitive / Regulated Data | 10 — Critical | Protect | 21 |
| IAC-25.2 | Database Access | 10 — Critical | Protect | 10 |
| IAC-26 | Use of Privileged Utility Programs | 9 — Critical | Protect | 14 |
| IAC-27 | Dedicated Administrative Machines | 8 — High | Protect | 12 |
| IAC-28 | Dual Authorization for Privileged Commands | 5 — Medium | Protect | 9 |
| IAC-29 | Revocation of Access Authorizations | 9 — Critical | Protect | 16 |
| IAC-30 | Least Privilege | 10 — Critical | Protect | 103 |
| IAC-30.1 | Prohibit Non-Privileged Users from Executing Privileged Functions | 9 — Critical | Protect | 31 |
| IAC-30.2 | Authorize Access to Security Functions | 9 — Critical | Protect | 21 |
| IAC-30.3 | Non-Privileged Access for Non-Security Functions | 9 — Critical | Protect | 34 |
| IAC-30.4 | Auditing Use of Privileged Functions | 9 — Critical | Detect | 30 |
| IAC-30.5 | Network Access to Privileged Commands | 5 — Medium | Protect | 8 |
| IAC-30.6 | Privilege Levels for Code Execution | 5 — Medium | Protect | 8 |
| IAC-31 | Permitted Actions Without Identification or Authorization | 8 — High | Protect | 26 |
| IAC-32 | Identification & Authentication for Organizational Users | 9 — Critical | Protect | 83 |
| IAC-32.1 | Out-of-Band Authentication (OOBA) | 5 — Medium | Protect | 4 |
| IAC-32.2 | Acceptance of PIV Credentials | 2 — Low | Protect | 19 |
| IAC-33 | Identification & Authentication for Non-Organizational Users | 9 — Critical | Protect | 53 |
| IAC-33.1 | Acceptance of Third-Party Credentials | 2 — Low | Protect | 19 |
| IAC-33.2 | Acceptance of External Authenticators | 4 — Medium | Protect | 2 |
| IAC-33.3 | Disassociability | 2 — Low | Protect | 2 |
| IAC-33.4 | Acceptance of PIV Credentials from Other Organizations | 2 — Low | Protect | 16 |
| IAC-33.5 | Use of FICAM-Issued Profiles | 2 — Low | Protect | 16 |
| IAC-34 | Identification & Authentication for Devices | 9 — Critical | Protect | 60 |
| IAC-34.1 | Device Attestation | 5 — Medium | Protect | 5 |
| IAC-34.2 | Device Authorization Enforcement | 5 — Medium | Protect | 2 |
| IAC-35 | Access Control For Mobile Devices | 9 — Critical | Protect | 46 |
| IAC-36 | Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS) | 9 — Critical | Protect | 30 |
| IAC-36.1 | Sharing Identification & Authentication Information | 5 — Medium | Protect | 6 |
| IAC-36.2 | Privileged Access by Non-Organizational Users | 9 — Critical | Protect | 11 |
| IAC-37 | Multi-Factor Authentication (MFA) | 9 — Critical | Protect | 95 |
| IAC-37.1 | Replay-Resistant Multi-Factor Authentication (MFA) | 8 — High | Protect | 8 |
| IAC-37.2 | Phishing-Resistant Multi-Factor Authentication (MFA) | 9 — Critical | Protect | 11 |
| IAC-37.3 | Out-of-Band (OOB) Multi-Factor Authentication (MFA) | 5 — Medium | Protect | 37 |
| IAC-37.4 | Alternative Multi-Factor Authentication (MFA) | 5 — Medium | Protect | 1 |
| IAC-37.5 | Multi-Factor Authentication (MFA) For Network Access to Privileged Accounts | 9 — Critical | Protect | 59 |
| IAC-37.6 | Multi-Factor Authentication (MFA) For Network Access to Non-Privileged Accounts | 7 — High | Protect | 46 |
| IAC-37.7 | Multi-Factor Authentication (MFA) For Local Access to Privileged Accounts | 5 — Medium | Protect | 51 |
| IAC-38 | Cryptographic Module Authentication | 8 — High | Protect | 27 |
| IAC-39 | Hardware Security Modules (HSM) | 3 — Low | Protect | 5 |
| IAC-40 | Single Sign-On (SSO) Transparent Authentication | 5 — Medium | Protect | 5 |
| IAC-41 | Adaptive Identification & Authentication | 5 — Medium | Protect | 9 |
| IAC-42 | Continuous Authentication | 2 — Low | Protect | 4 |
| IAC-43 | Re-Authentication | 8 — High | Protect | 31 |
| IAC-44 | Mutual Authentication (MA) | 2 — Low | Protect | 2 |
| IAC-45 | Federated Credential Management | 4 — Medium | Protect | 10 |
| IAC-46 | Invalidate Session Identifiers at Logout | 5 — Medium | Protect | 7 |
| IAC-47 | Unique System-Generated Session Identifiers | 3 — Low | Protect | 7 |
| IAC-48 | Software Defined Storage (SDS) Data Access Control | 3 — Low | Protect | 1 |
| IAC-49 | Sensitive / Regulated Data Access Enforcement | 7 — High | Protect | 14 |
| IAC-49.1 | Sensitive / Regulated Data Actions | 7 — High | Protect | 5 |
| IAC-50 | Compliance As Code (CAC) Identity Governance | 7 — High | Identify | 0 |
| IAC-51 | Compliance As Code (CAC) Least Privileges | 8 — High | Protect | 0 |
| IAC-52 | Compliance As Code (CAC) Credential Lifecycle Management | 7 — High | Protect | 0 |
| IAC-53 | Compliance As Code (CAC) Credentials Management | 8 — High | Protect | 0 |