Skip to content
Skillv1.0.0

PR.AA-02_praa-02

Identities are proofed and bound to credentials based on the context of interactions

by CyberStrikeus(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from CyberStrikeus/CyberStrike (.cyberstrike/skill/NIST/CSF_v2.0/PR_protect/PR.AA-02_praa-02/SKILL.md). Install upstream with npx skills add CyberStrikeus/CyberStrike --skill PR.AA-02_praa-02. Copyright stays with the author.

PR.AA-02 PR.AA-02

Subcategory of: Identity Management, Authentication, and Access Control (PR.AA)

High-Level Description

Function: PROTECT (PR) Framework: NIST Cybersecurity Framework v2.0

Identities are proofed and bound to credentials based on the context of interactions

What to Check

  • Verify PR.AA-02 PR.AA-02 outcome is achieved
  • Review documentation and evidence for PR.AA-02
  • Assess organizational maturity for PROTECT function
  • Map to SP 800-53 controls that satisfy PR.AA-02

How to Test

Step 1: Identify Current Profile

Determine the organization's current and target CSF profile tier for PR.AA-02.

Step 2: Assess Outcome Achievement

# Review organizational policies and procedures
# Check for evidence that PR.AA-02 outcome is met
# Interview stakeholders responsible for PROTECT

Step 3: Map to Technical Controls

Identify which SP 800-53 controls implement this CSF outcome and verify their operating effectiveness.

Tools

Tool Purpose Usage
cloud-audit-mcp Assess cloud security posture cloud_audit_* tools
Manual Review Policy and procedure review Interviews and documentation

Remediation Guide

Achieve the PR.AA-02 PR.AA-02 outcome:

Identities are proofed and bound to credentials based on the context of interactions

Risk Assessment

Finding Severity Impact
PR.AA-02 PR.AA-02 outcome not achieved High PROTECT Function Gap

CWE Categories

CWE ID Title
CWE-284 Improper Access Control

References

Checklist

  • Current profile tier assessed
  • Target profile tier defined
  • Gap analysis completed
  • SP 800-53 control mapping verified
  • Implementation roadmap exists

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/cyberstrikeus-cyberstrike-pr-aa-02-praa-02/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

cyberstrikeus-cyberstrike-pr-aa-02-praa-02.ocm.jsonjson
{
  "ocm": "1",
  "id": "cyberstrikeus-cyberstrike-pr-aa-02-praa-02",
  "kind": "skill",
  "name": "PR.AA-02_praa-02",
  "description": "Identities are proofed and bound to credentials based on the context of interactions",
  "publisher": "CyberStrikeus",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "general"
    ],
    "tags": [
      "skill-md",
      "nist",
      "csf",
      "v2-0",
      "pr-aa-02",
      "pr",
      "subcategory",
      "github"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Identities are proofed and bound to credentials based on the context of interactions"
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "github",
      "repository": "https://github.com/CyberStrikeus/CyberStrike",
      "path": ".cyberstrike/skill/NIST/CSF_v2.0/PR_protect/PR.AA-02_praa-02/SKILL.md",
      "ref": "df28ccd3dc6d6c02391169121ee2dcdf4a6a132b",
      "url": "https://github.com/CyberStrikeus/CyberStrike/blob/df28ccd3dc6d6c02391169121ee2dcdf4a6a132b/.cyberstrike/skill/NIST/CSF_v2.0/PR_protect/PR.AA-02_praa-02/SKILL.md",
      "key": "CyberStrikeus/CyberStrike/.cyberstrike/skill/NIST/CSF_v2.0/PR_protect/PR.AA-02_praa-02/SKILL.md"
    }
  },
  "instructions": "# PR.AA-02 PR.AA-02\n\n> **Subcategory of:** Identity Management, Authentication, and Access Control (PR.AA)\n\n## High-Level Description\n\n**Function:** PROTECT (PR)\n**Framework:** NIST Cybersecurity Framework v2.0\n\nIdentities are proofed and bound to credentials based on the context of interactions\n\n## What to Check\n\n- [ ] Verify PR.AA-02 PR.AA-02 outcome is achieved\n- [ ] Review documentation and evidence for PR.AA-02\n- [ ] Assess organizational maturity for PROTECT function\n- [ ] Map to SP 800-53 controls that satisfy PR.AA-02\n\n## How to Test\n\n### Step 1: Identify Current Profile\n\nDetermine the",
  "cost": {
    "context_tokens": 584
  }
}

Fetch it by URL: GET /api/v1/registry/cyberstrikeus-cyberstrike-pr-aa-02-praa-02/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.