NIST 800-53 IA-13 Mappings

Identity providers, both internal and external to the organization, manage the user, device, and NPE authenticators and issue statements, often called identity assertions, attesting to identities of other systems or systems components. Authorization servers create and issue access tokens to identified and authenticated users and devices that can be used to gain access to system or information resources. For example, single sign-on (SSO) provides identity provider and authorization server functions. Authenticator management (to include credential management) is covered by IA-05.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
IA-13 Identity Providers and Authorization Servers mitigates T1078 Valid Accounts
IA-13 Identity Providers and Authorization Servers mitigates T1078.002 Domain Accounts
IA-13 Identity Providers and Authorization Servers mitigates T1078.004 Cloud Accounts
IA-13 Identity Providers and Authorization Servers mitigates T1111 Multi-Factor Authentication Interception
IA-13 Identity Providers and Authorization Servers mitigates T1134 Access Token Manipulation
IA-13 Identity Providers and Authorization Servers mitigates T1134.001 Token Impersonation/Theft
IA-13 Identity Providers and Authorization Servers mitigates T1134.003 Make and Impersonate Token
IA-13 Identity Providers and Authorization Servers mitigates T1134.005 SID-History Injection
IA-13 Identity Providers and Authorization Servers mitigates T1528 Steal Application Access Token
IA-13 Identity Providers and Authorization Servers mitigates T1556 Modify Authentication Process
IA-13 Identity Providers and Authorization Servers mitigates T1556.006 Multi-Factor Authentication
IA-13 Identity Providers and Authorization Servers mitigates T1556.007 Hybrid Identity
IA-13 Identity Providers and Authorization Servers mitigates T1556.009 Conditional Access Policies
IA-13 Identity Providers and Authorization Servers mitigates T1606 Forge Web Credentials
IA-13 Identity Providers and Authorization Servers mitigates T1606.002 SAML Tokens
IA-13 Identity Providers and Authorization Servers mitigates T1621 Multi-Factor Authentication Request Generation
IA-13 Identity Providers and Authorization Servers mitigates T1649 Steal or Forge Authentication Certificates