askmeidentity · Compliance crosswalk · 2026-05-22
Compliance crosswalk — IAM controls
Printable crosswalk that maps IAM controls across the 5 frameworks every regulated enterprise touches. Maps to the longer interactive crosswalk page.
Authentication
| NIST 800-53 | IA-2, IA-5, IA-8 | Identification & Authentication |
| SOC 2 | CC6.1, CC6.6, CC6.7 | Logical & Physical Access |
| HIPAA | § 164.312(a)(2)(i), (d) | Unique user ID + person/entity auth |
| FFIEC | II.C.7, II.C.8 | Authentication & layered security |
| FedRAMP | IA-2, IA-5 (control inheritance from NIST) |
Access control + least privilege
| NIST 800-53 | AC-2, AC-3, AC-6, AC-17 |
| SOC 2 | CC6.1, CC6.2, CC6.3 |
| HIPAA | § 164.308(a)(3)(ii)(A), (B) |
| FFIEC | II.C.13, II.C.14 |
| FedRAMP | AC-2(1)-(13), AC-3, AC-6(7)-(9) |
Audit logging + monitoring
| NIST 800-53 | AU-2, AU-3, AU-6, AU-9 |
| SOC 2 | CC7.1, CC7.2 |
| HIPAA | § 164.308(a)(1)(ii)(D), § 164.312(b) |
| FFIEC | II.C.15 |
| FedRAMP | AU family (continuous monitoring) |
Account management (lifecycle)
| NIST 800-53 | AC-2, AC-2(1)-(13) |
| SOC 2 | CC6.2, CC6.3 |
| HIPAA | § 164.308(a)(3), § 164.308(a)(4) |
| FFIEC | II.C.13 (provisioning + termination) |
| FedRAMP | AC-2 enhancements per impact level |
Privileged access
| NIST 800-53 | AC-5, AC-6, AU-9(4) |
| SOC 2 | CC6.1, CC6.7 |
| HIPAA | § 164.308(a)(3)(ii)(A) (workforce clearance) |
| FFIEC | II.C.14 (privileged accounts) |
| FedRAMP | AC-6(1)-(10) + AU-9(4) |
Risk-based / continuous authentication
| NIST 800-53 | IA-2(1)-(12) |
| SOC 2 | CC6.6 |
| HIPAA | (no direct equivalent; addressed via § 164.308 risk analysis) |
| FFIEC | 2021 Authentication & Access Guidance Update |
| FedRAMP | IA-2(11)-(12) per impact level |
Identity proofing + verification
| NIST 800-63 | IAL2 / IAL3 (separate publication) |
| SOC 2 | (no direct control; satisfied via design) |
| HIPAA | § 164.308(a)(4)(ii)(B) workforce clearance |
| FFIEC | CIP (Customer Identification Program) for banks |
| FedRAMP | IA-12 (Identity Proofing) |