id: "IA-02(10)" title: "Single Sign-on" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-02.10" priority: "P1" implementation_level: "system" parent: "IA-02" enhancement: True
Statement
Provide a single sign-on capability for {{ insert: param, ia-02.10_odp }}.
Guidance
Single sign-on enables users to log in once and gain access to multiple system resources. Organizations consider the operational efficiencies provided by single sign-on capabilities with the risk introduced by allowing access to multiple systems via a single authentication event. Single sign-on can present opportunities to improve system security, for example by providing the ability to add multi-factor authentication for applications and systems (existing and new) that may not be able to natively support multi-factor authentication.
Assessment Objective
a single sign-on capability is provided for {{ insert: param, ia-02.10_odp }}.
Identification and authentication policy
system security plan
procedures addressing single sign-on capability for system accounts and services
procedures addressing identification and authentication
system design documentation
system configuration settings and associated documentation
system audit records
list of system accounts and services requiring single sign-on capability
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with account management responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
Mechanisms supporting and/or implementing identification and authentication capabilities
mechanisms supporting and/or implementing single sign-on capability for system accounts and services