Does NIST Cybersecurity Framework require Access Control?

Yes — 1 provision

Access Control (PR.AA)

Implements: Access Control active Effective: Feb 26, 2024
"CSF 2.0 consolidated identity and access management into a single **PR.AA** subcategory, clarifying that authentication and authorization are inseparable."

Requirements

RequirementDetails
Identity managementManage identities and credentials for authorized users
Access enforcementEnforce access permissions based on policies
Sources: NIST CSF 2.0
View Framework View Requirement Coverage matrix