id: "IA-08" title: "Identification and Authentication (Non-organizational Users)" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-08" priority: "P1" implementation_level: "system" enhancements: - ia-8.1 - ia-8.2 - ia-8.3 - ia-8.4 - ia-8.5 - ia-8.6
Statement
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Guidance
Non-organizational users include system users other than organizational users explicitly covered by IA-2 . Non-organizational users are uniquely identified and authenticated for accesses other than those explicitly identified and documented in AC-14 . Identification and authentication of non-organizational users accessing federal systems may be required to protect federal, proprietary, or privacy-related information (with exceptions noted for national security systems). Organizations consider many factors—including security, privacy, scalability, and practicality—when balancing the need to ensure ease of use for access to federal information and systems with the need to protect and adequately mitigate risk.
Assessment Objective
non-organizational users or processes acting on behalf of non-organizational users are uniquely identified and authenticated.
Identification and authentication policy
system security plan
privacy plan
procedures addressing user identification and authentication
system design documentation
system configuration settings and associated documentation
system audit records
list of system accounts
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with information security and privacy responsibilities
system/network administrators
organizational personnel with account management responsibilities
Mechanisms supporting and/or implementing identification and authentication capabilities