IA-2

Identification and Authentication (Organizational Users)

Identification and Authentication

The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).

High PriorityAI-Relevant Control

Purpose

Ensure that users are properly identified and authenticated before accessing system resources.

AI Relevance

Critical for authenticating users accessing AI systems, APIs, and sensitive AI resources to prevent unauthorized access.

Implementation Guidance

Implement strong authentication mechanisms, multi-factor authentication, and secure identity management systems.

Assessment

Test authentication mechanisms, verify identity proofing, review authentication logs, and validate authentication controls.

Requirements

  • 1Uniquely identify organizational users
  • 2Authenticate organizational users
  • 3Uniquely identify processes acting on behalf of organizational users
  • 4Authenticate processes acting on behalf of organizational users
  • 5Use multifactor authentication for local access to privileged accounts
  • 6Use multifactor authentication for network access to privileged accounts
  • 7Use multifactor authentication for remote access to privileged accounts
  • 8Use multifactor authentication for local access to non-privileged accounts
  • 9Use multifactor authentication for network access to non-privileged accounts
  • 10Use multifactor authentication for remote access to non-privileged accounts

Framework Context

NIST 800-53 Rev 5

Security and Privacy Controls for Federal Information Systems

Official Documentation →

NIST AI RMF

AI Risk Management Framework

AI RMF Documentation →

OWASP AISVS

AI Security Verification Standard

AISVS Documentation →