PlumbTrackLive demoGRC Risk System

← control library

Identification and Authentication (Organizational Users) IA-2

Identification and Authentication · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds IA-2 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Identification and Authentication family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

IA-2 (Identification and Authentication) requires the system to uniquely identify and authenticate each organizational user - and the processes acting for them - before granting access. No shared logins. Rev 5 also requires multi-factor authentication (MFA) for access to privileged (IA-2(1)) and non-privileged (IA-2(2)) accounts across the Low, Moderate, and High baselines.

What good looks like

Framework mapping

How to move it toward Implemented