Logo

CISOBot - Your AI CISO Assistant

IAC-04

Identification & Authentication for Devices

Weight: 9/10
Description

Mechanisms exist to uniquely identify and centrally Authenticate, Authorize and Audit (AAA) devices before establishing a connection using bidirectional authentication that is cryptographically- based and replay resistant.

Control Question

Does the organization uniquely identify and centrally Authenticate, Authorize and Audit (AAA) devices before establishing a connection using bidirectional authentication that is cryptographically- based and replay resistant?

Control Metadata
Domain:

Identification & Authentication

Validation Cadence:

Annual

Evidence Request List:

E-IAM-05 E-IAM-06

Have questions about this control?

Ask CISOBot for implementation guidance and best practices