SekitCrosswalk
Start free trial
NIST CSF 2.0 · derived mapping target

PR.AA-01Identities and credentials managed

Manage the identities and credentials of your users, services, and devices throughout their lifecycle, so access is always tied to a known, current account.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

ISO/IEC 27001:2022 · Annex A controls counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

MFA enrollment evidence
The proof that a second verification step (beyond the password) is required to access important systems.
Password policy and manager
The company's password rules (length, complexity, expiry) and whether a password manager is used, plus how they are technically enforced.
Joiner-mover-leaver procedure
The process the company follows when someone joins, changes role, or leaves: how access and devices are granted and removed.
From the Sekit evidence catalog

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves PR.AA-01?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk
  1. In Claude or ChatGPT, add a custom connector and paste this URL.
  2. Sign in with your email to finish. Free, read-only, no organization required.