https://www.nist.gov/sites/default/files/documents
Post# of 82672
( Last Page Identity & Access Controls )
Also, Look into mapping of NIST 800 controls to PCI DSS controls
Front End - All Credit Card Co's/ POS/ Banks/ including Fed's
Back End - IBM & Unisys