Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Access Control · Base control
AC-5 · Separation of Duties
Control statement and discussion
NIST control statement
a. Identify and document [Assignment: duties of individuals] ; and
b. Define system access authorizations to support separation of duties.
Discussion
Separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion. Separation of duties includes dividing mission or business functions and support functions among different individuals or roles, conducting system support functions with different individuals, and ensuring that security personnel who administer access control functions do not also administer audit functions. Because separation of duty violations can span systems and application domains, organizations consider the entirety of systems and system components when developing policy on separation of duties. Separation of duties is enforced through the account management activities in [AC-2](#ac-2) , access control mechanisms in [AC-3](#ac-3) , and identity management activities in [IA-2](#ia-2), [IA-4](#ia-4) , and [IA-12](#ia-12).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-5 — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Base control
IA-2 · Identification and Authentication (Organizational Users)
Control statement and discussion
NIST control statement
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Discussion
Organizations can satisfy the identification and authentication requirements by complying with the requirements in [HSPD 12](#f16e438e-7114-4144-bfe2-2dfcad8cb2d0) . Organizational users include employees or individuals who organizations consider to have an equivalent status to employees (e.g., contractors and guest researchers). Unique identification and authentication of users applies to all accesses other than those that are explicitly identified in [AC-14](#ac-14) and that occur through the authorized use of group authenticators without individual authentication. Since processes execute on behalf of groups and roles, organizations may require unique identification of individuals in group accounts or for detailed accountability of individual activity.
Organizations employ passwords, physical authenticators, or biometrics to authenticate user identities or, in the case of multi-factor authentication, some combination thereof. Access to organizational systems is defined as either local access or network access. Local access is any access to organizational systems by users or processes acting on behalf of users, where access is obtained through direct connections without the use of networks. Network access is access to organizational systems by users (or processes acting on behalf of users) where access is obtained through network connections (i.e., nonlocal accesses). Remote access is a type of network access that involves communication through external networks. Internal networks include local area networks and wide area networks.
The use of encrypted virtual private networks for network connections between organization-controlled endpoints and non-organization-controlled endpoints may be treated as internal networks with respect to protecting the confidentiality and integrity of information traversing the network. Identification and authentication requirements for non-organizational users are described in [IA-8](#ia-8).
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · IA-2 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · IA-2 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IA-2 — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(1) · Multi-factor Authentication to Privileged Accounts
View parent controlControl statement and discussion
NIST control statement
Implement multi-factor authentication for access to privileged accounts.
Discussion
Multi-factor authentication requires the use of two or more different factors to achieve authentication. The authentication factors are defined as follows: something you know (e.g., a personal identification number [PIN]), something you have (e.g., a physical authenticator such as a cryptographic private key), or something you are (e.g., a biometric). Multi-factor authentication solutions that feature physical authenticators include hardware authenticators that provide time-based or challenge-response outputs and smart cards such as the U.S. Government Personal Identity Verification (PIV) card or the Department of Defense (DoD) Common Access Card (CAC). In addition to authenticating users at the system level (i.e., at logon), organizations may employ authentication mechanisms at the application level, at their discretion, to provide increased security. Regardless of the type of access (i.e., local, network, remote), privileged accounts are authenticated using multi-factor options appropriate for the level of risk. Organizations can add additional security measures, such as additional or more rigorous authentication mechanisms, for specific types of access.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · IA-2 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · IA-2 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IA-2 (1) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(2) · Multi-factor Authentication to Non-privileged Accounts
View parent controlControl statement and discussion
NIST control statement
Implement multi-factor authentication for access to non-privileged accounts.
Discussion
Multi-factor authentication requires the use of two or more different factors to achieve authentication. The authentication factors are defined as follows: something you know (e.g., a personal identification number [PIN]), something you have (e.g., a physical authenticator such as a cryptographic private key), or something you are (e.g., a biometric). Multi-factor authentication solutions that feature physical authenticators include hardware authenticators that provide time-based or challenge-response outputs and smart cards such as the U.S. Government Personal Identity Verification card or the DoD Common Access Card. In addition to authenticating users at the system level, organizations may also employ authentication mechanisms at the application level, at their discretion, to provide increased information security. Regardless of the type of access (i.e., local, network, remote), non-privileged accounts are authenticated using multi-factor options appropriate for the level of risk. Organizations can provide additional security measures, such as additional or more rigorous authentication mechanisms, for specific types of access.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (2) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement · Withdrawn
IA-2(3) · Local Access to Privileged Accounts
View parent controlControl statement and discussion
NIST control statement
Withdrawn in this source release; review the official source for disposition.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement · Withdrawn
IA-2(4) · Local Access to Non-privileged Accounts
View parent controlControl statement and discussion
NIST control statement
Withdrawn in this source release; review the official source for disposition.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-2(5) · Individual Authentication with Group Authentication
View parent controlControl statement and discussion
NIST control statement
When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.
Discussion
Individual authentication prior to shared group authentication mitigates the risk of using group accounts or authenticators.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (5) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement
IA-2(6) · Access to Accounts —separate Device
View parent controlControl statement and discussion
NIST control statement
Implement multi-factor authentication for [Selection (one-or-more): local; network; remote] access to [Selection (one-or-more): privileged accounts; non-privileged accounts] such that:
(a) One of the factors is provided by a device separate from the system gaining access; and
(b) The device meets [Assignment: strength of mechanism requirements].
Discussion
The purpose of requiring a device that is separate from the system to which the user is attempting to gain access for one of the factors during multi-factor authentication is to reduce the likelihood of compromising authenticators or credentials stored on the system. Adversaries may be able to compromise such authenticators or credentials and subsequently impersonate authorized users. Implementing one of the factors on a separate device (e.g., a hardware token), provides a greater strength of mechanism and an increased level of assurance in the authentication process.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (6) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement · Withdrawn
IA-2(7) · Network Access to Non-privileged Accounts — Separate Device
View parent controlControl statement and discussion
NIST control statement
Withdrawn in this source release; review the official source for disposition.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-2(8) · Access to Accounts — Replay Resistant
View parent controlControl statement and discussion
NIST control statement
Implement replay-resistant authentication mechanisms for access to [Selection (one-or-more): privileged accounts; non-privileged accounts].
Discussion
Authentication processes resist replay attacks if it is impractical to achieve successful authentications by replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges such as time synchronous or cryptographic authenticators.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · IA-2 (8) — Direct NIST identifier reference. GovRAMP source matrix
Identification and Authentication · Enhancement · Withdrawn
IA-2(9) · Network Access to Non-privileged Accounts — Replay Resistant
View parent controlControl statement and discussion
NIST control statement
Withdrawn in this source release; review the official source for disposition.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-2(10) · Single Sign-on
View parent controlControl statement and discussion
NIST control statement
Provide a single sign-on capability for [Assignment: system accounts and services].
Discussion
Single sign-on enables users to log in once and gain access to multiple system resources. Organizations consider the operational efficiencies provided by single sign-on capabilities with the risk introduced by allowing access to multiple systems via a single authentication event. Single sign-on can present opportunities to improve system security, for example by providing the ability to add multi-factor authentication for applications and systems (existing and new) that may not be able to natively support multi-factor authentication.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement · Withdrawn
IA-2(11) · Remote Access — Separate Device
View parent controlControl statement and discussion
NIST control statement
Withdrawn in this source release; review the official source for disposition.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-2(12) · Acceptance of PIV Credentials
View parent controlControl statement and discussion
NIST control statement
Accept and electronically verify Personal Identity Verification-compliant credentials.
Discussion
Acceptance of Personal Identity Verification (PIV)-compliant credentials applies to organizations implementing logical access control and physical access control systems. PIV-compliant credentials are those credentials issued by federal agencies that conform to FIPS Publication 201 and supporting guidance documents. The adequacy and reliability of PIV card issuers are authorized using [SP 800-79-2](#10963761-58fc-4b20-b3d6-b44a54daba03) . Acceptance of PIV-compliant credentials includes derived PIV credentials, the use of which is addressed in [SP 800-166](#e8552d48-cf41-40aa-8b06-f45f7fb4706c) . The DOD Common Access Card (CAC) is an example of a PIV credential.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-2(13) · Out-of-band Authentication
View parent controlControl statement and discussion
NIST control statement
Implement the following out-of-band authentication mechanisms under [Assignment: conditions]: [Assignment: out-of-band authentication].
Discussion
Out-of-band authentication refers to the use of two separate communication paths to identify and authenticate users or devices to an information system. The first path (i.e., the in-band path) is used to identify and authenticate users or devices and is generally the path through which information flows. The second path (i.e., the out-of-band path) is used to independently verify the authentication and/or requested action. For example, a user authenticates via a notebook computer to a remote server to which the user desires access and requests some action of the server via that communication path. Subsequently, the server contacts the user via the user’s cell phone to verify that the requested action originated from the user. The user may confirm the intended action to an individual on the telephone or provide an authentication code via the telephone. Out-of-band authentication can be used to mitigate actual or suspected "man-in the-middle" attacks. The conditions or criteria for activation include suspicious activities, new threat indicators, elevated threat levels, or the impact or classification level of information in requested transactions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Enhancement
IA-4(9) · Attribute Maintenance and Protection
View parent controlControl statement and discussion
NIST control statement
Maintain the attributes for each uniquely identified individual, device, or service in [Assignment: protected central storage].
Discussion
For each of the entities covered in [IA-2](#ia-2), [IA-3](#ia-3), [IA-8](#ia-8) , and [IA-9](#ia-9) , it is important to maintain the attributes for each authenticated entity on an ongoing basis in a central (protected) store.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Identification and Authentication · Base control
IA-8 · Identification and Authentication (Non-organizational Users)
Control statement and discussion
NIST control statement
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Discussion
Non-organizational users include system users other than organizational users explicitly covered by [IA-2](#ia-2) . Non-organizational users are uniquely identified and authenticated for accesses other than those explicitly identified and documented in [AC-14](#ac-14) . Identification and authentication of non-organizational users accessing federal systems may be required to protect federal, proprietary, or privacy-related information (with exceptions noted for national security systems). Organizations consider many factors—including security, privacy, scalability, and practicality—when balancing the need to ensure ease of use for access to federal information and systems with the need to protect and adequately mitigate risk.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · IA-8 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · IA-8 — Direct NIST identifier reference. GovRAMP source matrix
Maintenance · Base control
MA-4 · Nonlocal Maintenance
Control statement and discussion
NIST control statement
a. Approve and monitor nonlocal maintenance and diagnostic activities;
b. Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system;
c. Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions;
d. Maintain records for nonlocal maintenance and diagnostic activities; and
e. Terminate session and network connections when nonlocal maintenance is completed.
Discussion
Nonlocal maintenance and diagnostic activities are conducted by individuals who communicate through either an external or internal network. Local maintenance and diagnostic activities are carried out by individuals who are physically present at the system location and not communicating across a network connection. Authentication techniques used to establish nonlocal maintenance and diagnostic sessions reflect the network access requirements in [IA-2](#ia-2) . Strong authentication requires authenticators that are resistant to replay attacks and employ multi-factor authentication. Strong authenticators include PKI where certificates are stored on a token protected by a password, passphrase, or biometric. Enforcing requirements in [MA-4](#ma-4) is accomplished, in part, by other controls. [SP 800-63B](#e59c5a7c-8b1f-49ca-8de0-6ee0882180ce) provides additional guidance on strong authentication and authenticators.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · MA-4 — Direct NIST identifier reference. GovRAMP source matrix