NIST CSF 2.0 · derived mapping target
PR.AA-01Identities and credentials managed
Manage the identities and credentials of your users, services, and devices throughout their lifecycle, so access is always tied to a known, current account.
Mapping at a glance
PR.AA-01Identities and credentials managedNIST CSF 2.0
RCF-0061Identity lifecycleIdentity & Access Management · PolicyRCF-0062Identity lifecycleIdentity & Access Management · ProcessRCF-0063Identity lifecycleIdentity & Access Management · TechnicalRCF-0064Strong authentication (MFA)Identity & Access Management · PolicyRCF-0065Strong authentication (MFA)Identity & Access Management · Process
PR.AA-01 is covered by 21 Sekit CSF controls. +16 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0061Identity lifecycle · PolicyRCF-0062Identity lifecycle · ProcessRCF-0063Identity lifecycle · TechnicalRCF-0064Strong authentication (MFA) · PolicyRCF-0065Strong authentication (MFA) · ProcessRCF-0066Strong authentication (MFA) · TechnicalRCF-0073SSO & federation · PolicyRCF-0074SSO & federation · ProcessRCF-0075SSO & federation · TechnicalRCF-0076Password policy · PolicyRCF-0077Password policy · ProcessRCF-0078Password policy · TechnicalRCF-0079Session management · PolicyRCF-0080Session management · ProcessRCF-0081Session management · TechnicalRCF-0088JML (joiner-mover-leaver) · PolicyRCF-0089JML (joiner-mover-leaver) · ProcessRCF-0090JML (joiner-mover-leaver) · TechnicalRCF-0334Cloud IAM · PolicyRCF-0335Cloud IAM · ProcessRCF-0336Cloud IAM · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
MFA enrollment evidence
The proof that a second verification step (beyond the password) is required to access important systems.
Password policy and manager
The company's password rules (length, complexity, expiry) and whether a password manager is used, plus how they are technically enforced.
Joiner-mover-leaver procedure
The process the company follows when someone joins, changes role, or leaves: how access and devices are granted and removed.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves PR.AA-01?”
Also via MCP, free with account