Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Contingency Planning · Base control
CP-10 · System Recovery and Reconstitution
Control statement and discussion
NIST control statement
Provide for the recovery and reconstitution of the system to a known state within [Assignment: organization-defined time period consistent with recovery time and recovery point objectives] after a disruption, compromise, or failure.
Discussion
Recovery is executing contingency plan activities to restore organizational mission and business functions. Reconstitution takes place following recovery and includes activities for returning systems to fully operational states. Recovery and reconstitution operations reflect mission and business priorities; recovery point, recovery time, and reconstitution objectives; and organizational metrics consistent with contingency plan requirements. Reconstitution includes the deactivation of interim system capabilities that may have been needed during recovery operations. Reconstitution also includes assessments of fully restored system capabilities, reestablishment of continuous monitoring activities, system reauthorization (if required), and activities to prepare the system and organization for future disruptions, breaches, compromises, or failures. Recovery and reconstitution capabilities can include automated mechanisms and manual procedures. Organizations establish recovery time and recovery point objectives as part of contingency planning.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · CP-10 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CP-10 — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-10(2) · Transaction Recovery
View parent controlControl statement and discussion
NIST control statement
Implement transaction recovery for systems that are transaction-based.
Discussion
Transaction-based systems include database management systems and transaction processing systems. Mechanisms supporting transaction recovery include transaction rollback and transaction journaling.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CP-10 (2) — Direct NIST identifier reference. GovRAMP source matrix
Contingency Planning · Enhancement
CP-10(4) · Restore Within Time Period
View parent controlControl statement and discussion
NIST control statement
Provide the capability to restore system components within [Assignment: restoration time periods] from configuration-controlled and integrity-protected information representing a known, operational state for the components.
Discussion
Restoration of system components includes reimaging, which restores the components to known, operational states.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Enhancement
CP-10(6) · Component Protection
View parent controlControl statement and discussion
NIST control statement
Protect system components used for recovery and reconstitution.
Discussion
Protection of system recovery and reconstitution components (i.e., hardware, firmware, and software) includes physical and technical controls. Backup and restoration components used for recovery and reconstitution include router tables, compilers, and other system software.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Base control
CP-11 · Alternate Communications Protocols
Control statement and discussion
NIST control statement
Provide the capability to employ [Assignment: alternative communications protocols] in support of maintaining continuity of operations.
Discussion
Contingency plans and the contingency training or testing associated with those plans incorporate an alternate communications protocol capability as part of establishing resilience in organizational systems. Switching communications protocols may affect software applications and operational aspects of systems. Organizations assess the potential side effects of introducing alternate communications protocols prior to implementation.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Base control
CP-12 · Safe Mode
Control statement and discussion
NIST control statement
When [Assignment: conditions] are detected, enter a safe mode of operation with [Assignment: restrictions].
Discussion
For systems that support critical mission and business functions—including military operations, civilian space operations, nuclear power plant operations, and air traffic control operations (especially real-time operational environments)—organizations can identify certain conditions under which those systems revert to a predefined safe mode of operation. The safe mode of operation, which can be activated either automatically or manually, restricts the operations that systems can execute when those conditions are encountered. Restriction includes allowing only selected functions to execute that can be carried out under limited power or with reduced communications bandwidth.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Contingency Planning · Base control
CP-13 · Alternative Security Mechanisms
Control statement and discussion
NIST control statement
Employ [Assignment: alternative or supplemental security mechanisms] for satisfying [Assignment: security functions] when the primary means of implementing the security function is unavailable or compromised.
Discussion
Use of alternative security mechanisms supports system resiliency, contingency planning, and continuity of operations. To ensure mission and business continuity, organizations can implement alternative or supplemental security mechanisms. The mechanisms may be less effective than the primary mechanisms. However, having the capability to readily employ alternative or supplemental mechanisms enhances mission and business continuity that might otherwise be adversely impacted if operations had to be curtailed until the primary means of implementing the functions was restored. Given the cost and level of effort required to provide such alternative capabilities, the alternative or supplemental mechanisms are only applied to critical security capabilities provided by systems, system components, or system services. For example, an organization may issue one-time pads to senior executives, officials, and system administrators if multi-factor tokens—the standard means for achieving secure authentication— are compromised.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Base control
IA-1 · Policy and Procedures
Control statement and discussion
NIST control statement
a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
1. [Selection (one-or-more): organization-level; mission/business process-level; system-level] identification and authentication policy that:
(a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
(b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
2. Procedures to facilitate the implementation of the identification and authentication policy and the associated identification and authentication controls;
b. Designate an [Assignment: official] to manage the development, documentation, and dissemination of the identification and authentication policy and procedures; and
c. Review and update the current identification and authentication:
1. Policy [Assignment: frequency] and following [Assignment: events] ; and
2. Procedures [Assignment: frequency] and following [Assignment: events].
Discussion
Identification and authentication policy and procedures address the controls in the IA family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on the development of identification and authentication policy and procedures. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission- or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies that reflect the complex nature of organizations. Procedures can be established for security and privacy programs, for mission or business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to identification and authentication policy and procedures include assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-1 — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Base control
IA-2 · Identification and Authentication (Organizational Users)
Control statement and discussion
NIST control statement
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Discussion
Organizations can satisfy the identification and authentication requirements by complying with the requirements in [HSPD 12](#f16e438e-7114-4144-bfe2-2dfcad8cb2d0) . Organizational users include employees or individuals who organizations consider to have an equivalent status to employees (e.g., contractors and guest researchers). Unique identification and authentication of users applies to all accesses other than those that are explicitly identified in [AC-14](#ac-14) and that occur through the authorized use of group authenticators without individual authentication. Since processes execute on behalf of groups and roles, organizations may require unique identification of individuals in group accounts or for detailed accountability of individual activity.
Organizations employ passwords, physical authenticators, or biometrics to authenticate user identities or, in the case of multi-factor authentication, some combination thereof. Access to organizational systems is defined as either local access or network access. Local access is any access to organizational systems by users or processes acting on behalf of users, where access is obtained through direct connections without the use of networks. Network access is access to organizational systems by users (or processes acting on behalf of users) where access is obtained through network connections (i.e., nonlocal accesses). Remote access is a type of network access that involves communication through external networks. Internal networks include local area networks and wide area networks.
The use of encrypted virtual private networks for network connections between organization-controlled endpoints and non-organization-controlled endpoints may be treated as internal networks with respect to protecting the confidentiality and integrity of information traversing the network. Identification and authentication requirements for non-organizational users are described in [IA-8](#ia-8).
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · IA-2 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · IA-2 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IA-2 — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(1) · Multi-factor Authentication to Privileged Accounts
View parent controlControl statement and discussion
NIST control statement
Implement multi-factor authentication for access to privileged accounts.
Discussion
Multi-factor authentication requires the use of two or more different factors to achieve authentication. The authentication factors are defined as follows: something you know (e.g., a personal identification number [PIN]), something you have (e.g., a physical authenticator such as a cryptographic private key), or something you are (e.g., a biometric). Multi-factor authentication solutions that feature physical authenticators include hardware authenticators that provide time-based or challenge-response outputs and smart cards such as the U.S. Government Personal Identity Verification (PIV) card or the Department of Defense (DoD) Common Access Card (CAC). In addition to authenticating users at the system level (i.e., at logon), organizations may employ authentication mechanisms at the application level, at their discretion, to provide increased security. Regardless of the type of access (i.e., local, network, remote), privileged accounts are authenticated using multi-factor options appropriate for the level of risk. Organizations can add additional security measures, such as additional or more rigorous authentication mechanisms, for specific types of access.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · IA-2 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · IA-2 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IA-2 (1) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(2) · Multi-factor Authentication to Non-privileged Accounts
View parent controlControl statement and discussion
NIST control statement
Implement multi-factor authentication for access to non-privileged accounts.
Discussion
Multi-factor authentication requires the use of two or more different factors to achieve authentication. The authentication factors are defined as follows: something you know (e.g., a personal identification number [PIN]), something you have (e.g., a physical authenticator such as a cryptographic private key), or something you are (e.g., a biometric). Multi-factor authentication solutions that feature physical authenticators include hardware authenticators that provide time-based or challenge-response outputs and smart cards such as the U.S. Government Personal Identity Verification card or the DoD Common Access Card. In addition to authenticating users at the system level, organizations may also employ authentication mechanisms at the application level, at their discretion, to provide increased information security. Regardless of the type of access (i.e., local, network, remote), non-privileged accounts are authenticated using multi-factor options appropriate for the level of risk. Organizations can provide additional security measures, such as additional or more rigorous authentication mechanisms, for specific types of access.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (2) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(5) · Individual Authentication with Group Authentication
View parent controlControl statement and discussion
NIST control statement
When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.
Discussion
Individual authentication prior to shared group authentication mitigates the risk of using group accounts or authenticators.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (5) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(6) · Access to Accounts —separate Device
View parent controlControl statement and discussion
NIST control statement
Implement multi-factor authentication for [Selection (one-or-more): local; network; remote] access to [Selection (one-or-more): privileged accounts; non-privileged accounts] such that:
(a) One of the factors is provided by a device separate from the system gaining access; and
(b) The device meets [Assignment: strength of mechanism requirements].
Discussion
The purpose of requiring a device that is separate from the system to which the user is attempting to gain access for one of the factors during multi-factor authentication is to reduce the likelihood of compromising authenticators or credentials stored on the system. Adversaries may be able to compromise such authenticators or credentials and subsequently impersonate authorized users. Implementing one of the factors on a separate device (e.g., a hardware token), provides a greater strength of mechanism and an increased level of assurance in the authentication process.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (6) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(8) · Access to Accounts — Replay Resistant
View parent controlControl statement and discussion
NIST control statement
Implement replay-resistant authentication mechanisms for access to [Selection (one-or-more): privileged accounts; non-privileged accounts].
Discussion
Authentication processes resist replay attacks if it is impractical to achieve successful authentications by replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges such as time synchronous or cryptographic authenticators.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (8) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(10) · Single Sign-on
View parent controlControl statement and discussion
NIST control statement
Provide a single sign-on capability for [Assignment: system accounts and services].
Discussion
Single sign-on enables users to log in once and gain access to multiple system resources. Organizations consider the operational efficiencies provided by single sign-on capabilities with the risk introduced by allowing access to multiple systems via a single authentication event. Single sign-on can present opportunities to improve system security, for example by providing the ability to add multi-factor authentication for applications and systems (existing and new) that may not be able to natively support multi-factor authentication.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-2(12) · Acceptance of PIV Credentials
View parent controlControl statement and discussion
NIST control statement
Accept and electronically verify Personal Identity Verification-compliant credentials.
Discussion
Acceptance of Personal Identity Verification (PIV)-compliant credentials applies to organizations implementing logical access control and physical access control systems. PIV-compliant credentials are those credentials issued by federal agencies that conform to FIPS Publication 201 and supporting guidance documents. The adequacy and reliability of PIV card issuers are authorized using [SP 800-79-2](#10963761-58fc-4b20-b3d6-b44a54daba03) . Acceptance of PIV-compliant credentials includes derived PIV credentials, the use of which is addressed in [SP 800-166](#e8552d48-cf41-40aa-8b06-f45f7fb4706c) . The DOD Common Access Card (CAC) is an example of a PIV credential.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-2(13) · Out-of-band Authentication
View parent controlControl statement and discussion
NIST control statement
Implement the following out-of-band authentication mechanisms under [Assignment: conditions]: [Assignment: out-of-band authentication].
Discussion
Out-of-band authentication refers to the use of two separate communication paths to identify and authenticate users or devices to an information system. The first path (i.e., the in-band path) is used to identify and authenticate users or devices and is generally the path through which information flows. The second path (i.e., the out-of-band path) is used to independently verify the authentication and/or requested action. For example, a user authenticates via a notebook computer to a remote server to which the user desires access and requests some action of the server via that communication path. Subsequently, the server contacts the user via the user’s cell phone to verify that the requested action originated from the user. The user may confirm the intended action to an individual on the telephone or provide an authentication code via the telephone. Out-of-band authentication can be used to mitigate actual or suspected "man-in the-middle" attacks. The conditions or criteria for activation include suspicious activities, new threat indicators, elevated threat levels, or the impact or classification level of information in requested transactions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Base control
IA-3 · Device Identification and Authentication
Control statement and discussion
NIST control statement
Uniquely identify and authenticate [Assignment: devices and/or types of devices] before establishing a [Selection (one-or-more): local; remote; network] connection.
Discussion
Devices that require unique device-to-device identification and authentication are defined by type, device, or a combination of type and device. Organization-defined device types include devices that are not owned by the organization. Systems use shared known information (e.g., Media Access Control [MAC], Transmission Control Protocol/Internet Protocol [TCP/IP] addresses) for device identification or organizational authentication solutions (e.g., Institute of Electrical and Electronics Engineers (IEEE) 802.1x and Extensible Authentication Protocol [EAP], RADIUS server with EAP-Transport Layer Security [TLS] authentication, Kerberos) to identify and authenticate devices on local and wide area networks. Organizations determine the required strength of authentication mechanisms based on the security categories of systems and mission or business requirements. Because of the challenges of implementing device authentication on a large scale, organizations can restrict the application of the control to a limited number/type of devices based on mission or business needs.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-3 — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-3(1) · Cryptographic Bidirectional Authentication
View parent controlControl statement and discussion
NIST control statement
Authenticate [Assignment: devices and/or types of devices] before establishing [Selection (one-or-more): local; remote; network] connection using bidirectional authentication that is cryptographically based.
Discussion
A local connection is a connection with a device that communicates without the use of a network. A network connection is a connection with a device that communicates through a network. A remote connection is a connection with a device that communicates through an external network. Bidirectional authentication provides stronger protection to validate the identity of other devices for connections that are of greater risk.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-3(3) · Dynamic Address Allocation
View parent controlControl statement and discussion
NIST control statement
(a) Where addresses are allocated dynamically, standardize dynamic address allocation lease information and the lease duration assigned to devices in accordance with [Assignment: organization-defined lease information and lease duration] ; and
(b) Audit lease information when assigned to a device.
Discussion
The Dynamic Host Configuration Protocol (DHCP) is an example of a means by which clients can dynamically receive network address assignments.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-3(4) · Device Attestation
View parent controlControl statement and discussion
NIST control statement
Handle device identification and authentication based on attestation by [Assignment: configuration management process].
Discussion
Device attestation refers to the identification and authentication of a device based on its configuration and known operating state. Device attestation can be determined via a cryptographic hash of the device. If device attestation is the means of identification and authentication, then it is important that patches and updates to the device are handled via a configuration management process such that the patches and updates are done securely and do not disrupt identification and authentication to other devices.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Base control
IA-4 · Identifier Management
Control statement and discussion
NIST control statement
Manage system identifiers by:
a. Receiving authorization from [Assignment: personnel or roles] to assign an individual, group, role, service, or device identifier;
b. Selecting an identifier that identifies an individual, group, role, service, or device;
c. Assigning the identifier to the intended individual, group, role, service, or device; and
d. Preventing reuse of identifiers for [Assignment: time period].
Discussion
Common device identifiers include Media Access Control (MAC) addresses, Internet Protocol (IP) addresses, or device-unique token identifiers. The management of individual identifiers is not applicable to shared system accounts. Typically, individual identifiers are the usernames of the system accounts assigned to those individuals. In such instances, the account management activities of [AC-2](#ac-2) use account names provided by [IA-4](#ia-4) . Identifier management also addresses individual identifiers not necessarily associated with system accounts. Preventing the reuse of identifiers implies preventing the assignment of previously used individual, group, role, service, or device identifiers to different individuals, groups, roles, services, or devices.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · IA-4 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IA-4 — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-4(1) · Prohibit Account Identifiers as Public Identifiers
View parent controlControl statement and discussion
NIST control statement
Prohibit the use of system account identifiers that are the same as public identifiers for individual accounts.
Discussion
Prohibiting account identifiers as public identifiers applies to any publicly disclosed account identifier used for communication such as, electronic mail and instant messaging. Prohibiting the use of systems account identifiers that are the same as some public identifier, such as the individual identifier section of an electronic mail address, makes it more difficult for adversaries to guess user identifiers. Prohibiting account identifiers as public identifiers without the implementation of other supporting controls only complicates guessing of identifiers. Additional protections are required for authenticators and credentials to protect the account.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-4(4) · Identify User Status
View parent controlControl statement and discussion
NIST control statement
Manage individual identifiers by uniquely identifying each individual as [Assignment: characteristics].
Discussion
Characteristics that identify the status of individuals include contractors, foreign nationals, and non-organizational users. Identifying the status of individuals by these characteristics provides additional information about the people with whom organizational personnel are communicating. For example, it might be useful for a government employee to know that one of the individuals on an email message is a contractor.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · IA-4 (4) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IA-4 (4) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-4(5) · Dynamic Management
View parent controlControl statement and discussion
NIST control statement
Manage individual identifiers dynamically in accordance with [Assignment: dynamic identifier policy].
Discussion
In contrast to conventional approaches to identification that presume static accounts for preregistered users, many distributed systems establish identifiers at runtime for entities that were previously unknown. When identifiers are established at runtime for previously unknown entities, organizations can anticipate and provision for the dynamic establishment of identifiers. Pre-established trust relationships and mechanisms with appropriate authorities to validate credentials and related identifiers are essential.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.