id: "IA-05(09)" title: "Federated Credential Management" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-05.09" priority: "P1" implementation_level: "organization" parent: "IA-05" enhancement: True


Statement

Use the following external organizations to federate credentials: {{ insert: param, ia-05.09_odp }}.

Guidance

Federation provides organizations with the capability to authenticate individuals and devices when conducting cross-organization activities involving the processing, storage, or transmission of information. Using a specific list of approved external organizations for authentication helps to ensure that those organizations are vetted and trusted.

Assessment Objective

{{ insert: param, ia-05.09_odp }} are used to federate credentials.

Identification and authentication policy

procedures addressing authenticator management

procedures addressing account management

system security plan

security agreements

other relevant documents or records

Organizational personnel with authenticator management responsibilities

organizational personnel with information security responsibilities

system/network administrators

Mechanisms supporting and/or implementing safeguards for authenticator management