{"data":{"id":"IA-07","name":"Cryptographic Module Authentication","family":"IA","family_name":"Identification and Authentication","withdrawn":false,"description":"Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.","supplemental_guidance":"Authentication mechanisms may be required within a cryptographic module to authenticate an operator accessing the module and to verify that the operator is authorized to assume the requested role and perform services within that role.","enhancements":[],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"IA-07","name":"Cryptographic Module Authentication","description":"Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.","discussion":"Authentication mechanisms may be required within a cryptographic module to authenticate an operator accessing the module and to verify that the operator is authorized to assume the requested role and perform services within that role.","related_controls":["AC-03","IA-05","SA-04","SC-12","SC-13"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["5.17"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-01","PR.AA-03"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.12","RGS.2.3","SecNumCloud.11.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(63)"],"gdpr":["Art.32(1)(a)","Rec.83"],"dora":["Art.9(3)"],"bio2":["5.17"],"rbi_csf":["ITGRCA.16"],"fisc":["FISC.T4"],"lgpd_bcb":[],"hkma_tme1":["TME1.8.3","TME1.9.1"],"mlps_2":[],"dnb_good_practice":["DNB.18.3"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-6"],"qatar_nia":["AC"],"sama_csf":["3.1","3.4"],"uae_ia":["T9"],"bom_ctrm":["3.3"],"cbe_csf":["CTO-3"],"bot_cyber":["Ch2.2"],"ffiec_is":["II.C.15","II.C.19"],"hipaa_sr":["§164.312(d)"],"cmmc_2":["IA"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["C"],"fips_140":["FIPS 140-3 §7.4"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FCS","CC Part 2 — FIA"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.200(a)(1)"],"fda_cyber":["SA-1"],"hitrust_csf":["10.c"],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.7"],"owasp_masvs_v2":["MASVS-AUTH-2"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.61","SCO60.66"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication ensures firmware update processes use FIPS-validated signature verification, preventing adversaries from installing corrupted firmware that fails cryptographic integrity checks."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication enforces FIPS-validated Secure Boot verification, ensuring that only cryptographically-signed boot components load during the pre-OS boot sequence."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication validates code signing through FIPS-compliant algorithms, ensuring adversaries cannot subvert trust controls by exploiting weak or non-validated cryptographic verification."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication validates system image integrity using FIPS-compliant hash verification, preventing adversaries from loading modified firmware that fails validated cryptographic checks."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication validates hardware component identity through FIPS-compliant attestation, detecting supply chain compromises where adversaries substitute or tamper with hardware components."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"FIPS-validated cryptographic modules authenticate system firmware updates, preventing adversaries from installing unauthorized firmware by requiring valid cryptographic signatures verified through certified algorithms."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication enforces Secure Boot with FIPS-validated verification, preventing bootkit installation by requiring cryptographically-signed boot loaders and early-launch anti-malware components."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication on network device boot processes validates ROMMON integrity using FIPS-compliant algorithms, detecting unauthorized firmware modifications at the ROM Monitor level."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication validates the integrity of network boot images received via TFTP, preventing adversaries from loading compromised OS images through man-in-the-middle attacks on boot traffic."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication ensures code signing policy enforcement uses FIPS-validated algorithms, preventing adversaries from weakening signature requirements through cryptographic downgrade attacks."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication validates system image patches through FIPS-compliant signature verification, preventing adversaries from applying unauthorized modifications to running network device firmware."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cryptographic module authentication prevents system image downgrades by enforcing FIPS-validated version comparison and signature verification, blocking adversaries from reverting to vulnerable firmware versions."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.AA-01, PR.AA-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-005","SP-022","SP-024","SP-050"]}}