id: "IA-02(12)" title: "Acceptance of PIV Credentials" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-02.12" priority: "P1" implementation_level: "system" parent: "IA-02" enhancement: True


Statement

Accept and electronically verify Personal Identity Verification-compliant credentials.

Guidance

Acceptance of Personal Identity Verification (PIV)-compliant credentials applies to organizations implementing logical access control and physical access control systems. PIV-compliant credentials are those credentials issued by federal agencies that conform to FIPS Publication 201 and supporting guidance documents. The adequacy and reliability of PIV card issuers are authorized using SP 800-79-2 . Acceptance of PIV-compliant credentials includes derived PIV credentials, the use of which is addressed in SP 800-166 . The DOD Common Access Card (CAC) is an example of a PIV credential.

Assessment Objective

Personal Identity Verification-compliant credentials are accepted and electronically verified.

Identification and authentication policy

system security plan

procedures addressing user identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

PIV verification records

evidence of PIV credentials

PIV credential authorizations

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with account management responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

Mechanisms supporting and/or implementing acceptance and verification of PIV credentials