id: "IA-05(09)" title: "Federated Credential Management" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-05.09" priority: "P1" implementation_level: "organization" parent: "IA-05" enhancement: True
Statement
Use the following external organizations to federate credentials: {{ insert: param, ia-05.09_odp }}.
Guidance
Federation provides organizations with the capability to authenticate individuals and devices when conducting cross-organization activities involving the processing, storage, or transmission of information. Using a specific list of approved external organizations for authentication helps to ensure that those organizations are vetted and trusted.
Assessment Objective
{{ insert: param, ia-05.09_odp }} are used to federate credentials.
Identification and authentication policy
procedures addressing authenticator management
procedures addressing account management
system security plan
security agreements
other relevant documents or records
Organizational personnel with authenticator management responsibilities
organizational personnel with information security responsibilities
system/network administrators
Mechanisms supporting and/or implementing safeguards for authenticator management