id: "IA-02(10)" title: "Single Sign-on" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-02.10" priority: "P1" implementation_level: "system" parent: "IA-02" enhancement: True


Statement

Provide a single sign-on capability for {{ insert: param, ia-02.10_odp }}.

Guidance

Single sign-on enables users to log in once and gain access to multiple system resources. Organizations consider the operational efficiencies provided by single sign-on capabilities with the risk introduced by allowing access to multiple systems via a single authentication event. Single sign-on can present opportunities to improve system security, for example by providing the ability to add multi-factor authentication for applications and systems (existing and new) that may not be able to natively support multi-factor authentication.

Assessment Objective

a single sign-on capability is provided for {{ insert: param, ia-02.10_odp }}.

Identification and authentication policy

system security plan

procedures addressing single sign-on capability for system accounts and services

procedures addressing identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

list of system accounts and services requiring single sign-on capability

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with account management responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms supporting and/or implementing identification and authentication capabilities

mechanisms supporting and/or implementing single sign-on capability for system accounts and services