Control Statement
Identities shall be proofed to a level commensurate with the access they confer, and bound to credentials whose strength matches that level.
Purpose. To ensure the credential is as strong as the access behind it, so that proofing and authentication assurance are matched rather than assumed.
Discussion
The failure this addresses is drift rather than misconfiguration. A person proofed at one level and issued a credential appropriate to it accumulates access over subsequent years, and nothing re-examines whether the original proofing still justifies the current entitlement. WF-2 catches this for privileged humans; this control generalises it to every identity including non-human ones, where the problem is worse because service identities are routinely issued long-lived secrets and then granted whatever access their consuming application later requires.
Goals and Metrics
A metric that cannot come out badly is not a metric. Each of these is capable of reporting that the control is not working.
- Percentage of identities whose credential strength matches conferred access
- Number of open strength-to-access mismatch findings
- Count of long-lived non-human secrets
- Median age of non-human secrets against the stated ceiling
Accountability
Exactly one role is accountable, and every other role carries at least Informed — no control in the published catalog leaves a role with zero relationship to it. That is a stated property of how these were authored, not a coincidence, and not a claim that every role's work is worth equal attention here.
| AO | CTI | SOC | HUNT | PLAT | ISSO |
|---|---|---|---|---|---|
| Authorizing Official / CISO: Accountable | Cyber Threat Intelligence cell: Informed | SOC / Defensive Operations: Consulted | Hunt team: Informed | Platform and product owners: Responsible | Governance / RMF / ISSO: Consulted |
AO Authorizing Official / CISOCTI Cyber Threat Intelligence cellSOC SOC / Defensive OperationsHUNT Hunt teamPLAT Platform and product ownersISSO Governance / RMF / ISSO
- AccountableAuthorizing Official / CISO
- InformedCyber Threat Intelligence cell
- ConsultedSOC / Defensive Operations
- InformedHunt team
- ResponsiblePlatform and product owners
- ConsultedGovernance / RMF / ISSO
Inputs and Outputs
Consumes
- ID-1 Identity Plane DefinitionIdentity planes the credentials are bound within
- WF-2 Privileged Human RegisterPrivileged human register, to match proofing to privilege
- KT-1 Decisive Point IdentificationDecisive points, which set the strength the credential must meet
- Outside the frameworkEntitlement data and identity proofing records
Produces
- ID-3 Authentication AssuranceCredential binding the achieved assurance level is computed from
- WF-5 Separation and Revocation TempoNon-human secret inventory that scopes revocation on separation
Activities
- L2Record the proofing level applied to each identity.
- L2Record the credential type bound to each identity.
- L2Raise a finding where credential strength is below the access conferred.
- L3Define the required proofing and credential strength per access tier, with provenance per
GA4. - L3Apply the requirement to non-human identities — service accounts, workload identities, API credentials — where binding is to an owning system and a named accountable human rather than to a person.
- L3Require phishing-resistant credentials for identities reaching decisive points, and record exceptions with expiry.
- L3Re-examine proofing adequacy when access changes, not only when the identity is created.
- L4Measure the gap between proofing level and access conferred across the population, and trend it.
- L4Measure the count and age of long-lived non-human secrets, since these are the credentials least likely to be rotated and most likely to be exfiltrated.
- L5Move non-human identities to short-lived, workload-attested credentials where the platform permits, retiring the long-lived secret class rather than managing it.
Measurement
Percentage of identities whose credential strength matches conferred access.
Count and median age of long-lived non-human secrets.
Evidence and Assessment
Proofing and credential record per identity; mismatch findings; non-human secret inventory with ages.
Examine the proofing standard and its provenance; test a sample of identities for credential strength against conferred access; test whether non-human identities are within scope in practice.
Related Guidance
- IA-5
- IA-12
- IA-9
- PR.AA-02
- PR.AA-01
Position in the Chain
Derived from the other controls’ own declarations, so the two directions cannot disagree.
Fed By
Nothing upstream — this control starts a chain.
Where This Control Is Used
Derived, in every case, from the declaration at the other end: the forms whose techniques name this control, the artifacts whose producing and consuming controls include it, the layers whose control lists name it, and the roles its own accountability chart puts to work. Nothing here is authored on this page, so the sheet cannot claim an edge the other end does not.
Forms of Maneuver It Assesses
- M3EnvelopmentMake identity, not network location, the decisive plane — surround the adversary with policy.3 of 20 techniques — M3.01, M3.06, M3.10
- M2Defense in DepthEnsure no single failure is decisive.1 of 18 techniques — M2.12
- M5AmbushTrade space for information and time, and impose cost.1 of 13 techniques — M5.03
Terrain It Is Named On
- T1IdentityBinds credential strength to the access it confers. This layer is where the mismatch between a weak credential and decisive-point access is actually visible.
Artifacts It Stands On
- consumesDecisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- consumesPrivileged human registerWhich individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
Roles It Puts to Work
- AccountableAuthorizing Official / CISOIntent, risk acceptance, and the scheme itself.
- ResponsiblePlatform and product ownersTheir own terrain. Obstacles get emplaced on their ground, so they site them.
- ConsultedSOC / Defensive OperationsManeuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
- ConsultedGovernance / RMF / ISSOTranslating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
- InformedCyber Threat Intelligence cellFrame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
- InformedHunt teamCounterattack. Works the hypotheses that Fuse raises.