NIST CSF 2.0 · derived mapping target
PR.AA-03Users and devices authenticated
Require users, services, and devices to prove their identity before access, using strong methods such as multi-factor authentication where the risk warrants it.
Mapping at a glance
PR.AA-03Users and devices authenticatedNIST CSF 2.0
RCF-0067Least privilege / RBACIdentity & Access Management · PolicyRCF-0068Least privilege / RBACIdentity & Access Management · ProcessRCF-0069Least privilege / RBACIdentity & Access Management · TechnicalRCF-0070Privileged access managementIdentity & Access Management · PolicyRCF-0071Privileged access managementIdentity & Access Management · Process
PR.AA-03 is covered by 21 Sekit CSF controls. +16 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0067Least privilege / RBAC · PolicyRCF-0068Least privilege / RBAC · ProcessRCF-0069Least privilege / RBAC · TechnicalRCF-0070Privileged access management · PolicyRCF-0071Privileged access management · ProcessRCF-0072Privileged access management · TechnicalRCF-0085Access reviews (recertification) · PolicyRCF-0086Access reviews (recertification) · ProcessRCF-0087Access reviews (recertification) · TechnicalRCF-0166Local admin control · PolicyRCF-0167Local admin control · ProcessRCF-0168Local admin control · TechnicalRCF-0184Zero Trust network access · PolicyRCF-0185Zero Trust network access · ProcessRCF-0186Zero Trust network access · TechnicalRCF-0334Cloud IAM · PolicyRCF-0335Cloud IAM · ProcessRCF-0336Cloud IAM · TechnicalRCF-0349Multi-tenancy controls · PolicyRCF-0350Multi-tenancy controls · ProcessRCF-0351Multi-tenancy controls · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
MFA enrollment evidence
The proof that a second verification step (beyond the password) is required to access important systems.
Password policy and manager
The company's password rules (length, complexity, expiry) and whether a password manager is used, plus how they are technically enforced.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves PR.AA-03?”
Also via MCP, free with account