IA-2 Identification and Authentication (Organizational Users)
Identification and Authentication family. 33 Control Correlation Identifiers map to this control, and 39 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to IA-2 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 13 |
| Microsoft Windows Server 2019 | V3 | 8 |
| Microsoft Windows Server 2022 | V2 | 8 |
| Red Hat Enterprise Linux 8 | V2 | 6 |
| Microsoft Windows 10 | V3 | 2 |
| Microsoft Windows 11 | V2 | 2 |
Control Correlation Identifiers mapped to IA-2
| CCI | Definition | Rev |
|---|---|---|
| CCI-000764 | Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. | 5, 4 |
| CCI-000765 | Implement multifactor authentication for access to privileged accounts. | 5, 4 |
| CCI-000766 | Implement multifactor authentication for access to non-privileged accounts. | 5, 4 |
| CCI-000767 | The information system implements multifactor authentication for local access to privileged accounts. | 4 |
| CCI-000768 | The information system implements multifactor authentication for local access to non-privileged accounts. | 4 |
| CCI-000770 | The organization requires individuals to be authenticated with an individual authenticator when a group authenticator is employed. | 4 |
| CCI-001935 | The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access to privileged accounts. | 4 |
| CCI-001936 | The information system implements multifactor authentication for network access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access. | 4 |
| CCI-001937 | The device used in the information system implementation of multifactor authentication for network access to privileged accounts meets organization-defined strength of mechanism requirements. | 4 |
| CCI-001938 | The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access to non-privileged accounts. | 4 |
| CCI-001939 | The information system implements multifactor authentication for network access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access. | 4 |
| CCI-001940 | The device used in the information system implementation of multifactor authentication for network access to non-privileged accounts meets organization-defined strength of mechanism requirements. | 4 |
| CCI-001941 | Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts. | 5, 4 |
| CCI-001942 | The information system implements replay-resistant authentication mechanisms for network access to non-privileged accounts. | 4 |
| CCI-001943 | Defines the system accounts for which single sign-on capability will be provided. | 5, 4 |
| CCI-001944 | Defines the system services for which single sign-on capability will be provided. | 5, 4 |
| CCI-001945 | Provide a single sign-on capability for organization-defined system accounts. | 5, 4 |
| CCI-001946 | Provide a single sign-on capability for organization-defined system services. | 5, 4 |
| CCI-001947 | The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access and is to provide one factor of a multifactor authentication for remote access to privileged accounts. | 4 |
| CCI-001948 | The information system implements multifactor authentication for remote access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access. | 4 |
| CCI-001949 | The device used in the information system implementation of multifactor authentication for remote access to privileged accounts meets organization-defined strength of mechanism requirements. | 4 |
| CCI-001950 | The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access and is to provide one factor of a multifactor authentication for remote access to non-privileged accounts. | 4 |
| CCI-001951 | The information system implements multifactor authentication for remote access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access. | 4 |
| CCI-001952 | The device used in the information system implementation of multifactor authentication for remote access to non-privileged accounts meets organization-defined strength of mechanism requirements. | 4 |
| CCI-001953 | Accept Personal Identity Verification-compliant credentials. | 5, 4 |
| CCI-001954 | Electronically verify Personal Identity Verification-compliant credentials. | 5, 4 |
| CCI-001955 | Defines the out-of-band authentication to be implemented under organization-defined conditions. | 5, 4 |
| CCI-001956 | Defines the conditions for implementing organization-defined out-of-band authentication. | 5, 4 |
| CCI-001957 | Implement organization-defined out-of-band authentication mechanisms under organization-defined conditions. | 5, 4 |
| CCI-004045 | Require users to be individually authenticated before granting access to the shared accounts or resources. | 5 |
| CCI-004046 | Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access. | 5 |
| CCI-004047 | Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements. | 5 |
| CCI-004048 | Defines the strength of mechanism requirements for implementing multi-factor authentication. | 5 |
STIG rules that implement IA-2
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205699 | WN19-00-000070 | medium | Windows Server 2019 shared user accounts must not be permitted. |
| V-205700 | WN19-00-000200 | medium | Windows Server 2019 accounts must require passwords. |
| V-205701 | WN19-DC-000310 | medium | Windows Server 2019 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication. |
| V-205702 | WN19-DC-000020 | medium | Windows Server 2019 Kerberos user logon restrictions must be enforced. |
| V-205703 | WN19-DC-000030 | medium | Windows Server 2019 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less. |
| V-205704 | WN19-DC-000040 | medium | Windows Server 2019 Kerberos user ticket lifetime must be limited to 10 hours or less. |
| V-205705 | WN19-DC-000050 | medium | Windows Server 2019 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less. |
| V-205706 | WN19-DC-000060 | medium | Windows Server 2019 computer clock synchronization tolerance must be limited to five minutes or less. |
| V-220908 | WN10-SO-000005 | medium | The built-in administrator account must be disabled. |
| V-220946 | WN10-SO-000251 | medium | Windows 10 must use multifactor authentication for local and network access to privileged and nonprivileged accounts. |
| V-230273 | RHEL-08-010390 | medium | RHEL 8 must have the packages required for multifactor authentication installed. |
| V-230274 | RHEL-08-010400 | medium | RHEL 8 must implement certificate status checking for multifactor authentication. |
| V-230275 | RHEL-08-010410 | medium | RHEL 8 must accept Personal Identity Verification (PIV) credentials. |
| V-230296 | RHEL-08-010550 | medium | RHEL 8 must not permit direct logons to the root account using remote access via SSH. |
| V-230371 | RHEL-08-020240 | medium | RHEL 8 duplicate User IDs (UIDs) must not exist for interactive users. |
| V-230372 | RHEL-08-020250 | medium | RHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts. |
| V-253432 | WN11-SO-000005 | medium | The built-in administrator account must be disabled. |
| V-253470 | WN11-SO-000251 | medium | Windows 11 must use multifactor authentication for local and network access to privileged and nonprivileged accounts. |
| V-254244 | WN22-00-000070 | medium | Windows Server 2022 shared user accounts must not be permitted. |
| V-254257 | WN22-00-000200 | medium | Windows Server 2022 accounts must require passwords. |
| V-254386 | WN22-DC-000020 | medium | Windows Server 2022 Kerberos user logon restrictions must be enforced. |
| V-254387 | WN22-DC-000030 | medium | Windows Server 2022 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less. |
| V-254388 | WN22-DC-000040 | medium | Windows Server 2022 Kerberos user ticket lifetime must be limited to 10 hours or less. |
| V-254389 | WN22-DC-000050 | medium | Windows Server 2022 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less. |
| V-254390 | WN22-DC-000060 | medium | Windows Server 2022 computer clock synchronization tolerance must be limited to five minutes or less. |
| V-254415 | WN22-DC-000310 | medium | Windows Server 2022 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication. |
| V-257838 | RHEL-09-215075 | medium | RHEL 9 must have the openssl-pkcs11 package installed. |
| V-257983 | RHEL-09-255035 | medium | RHEL 9 SSHD must accept public key authentication. |
| V-257984 | RHEL-09-255040 | high | RHEL 9 SSHD must not allow blank passwords. |
| V-257985 | RHEL-09-255045 | medium | RHEL 9 must not permit direct logons to the root account using remote access via SSH. |
| V-258045 | RHEL-09-411030 | medium | RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users. |
| V-258048 | RHEL-09-411045 | medium | All RHEL 9 interactive users must have a primary group that exists. |
| V-258061 | RHEL-09-411110 | medium | RHEL 9 groups must have unique Group ID (GID). |
| V-258121 | RHEL-09-611160 | medium | RHEL 9 must use the common access card (CAC) smart card driver. |
| V-258122 | RHEL-09-611165 | medium | RHEL 9 must enable certificate based smart card authentication. |
| V-258123 | RHEL-09-611170 | medium | RHEL 9 must implement certificate status checking for multifactor authentication. |
| V-258124 | RHEL-09-611175 | medium | RHEL 9 must have the pcsc-lite package installed. |
| V-258125 | RHEL-09-611180 | medium | The pcscd service on RHEL 9 must be active. |
| V-258126 | RHEL-09-611185 | medium | RHEL 9 must have the opensc package installed. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/IA-2. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.