id: "IA-08" title: "Identification and Authentication (Non-organizational Users)" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-08" priority: "P1" implementation_level: "system" enhancements: - ia-8.1 - ia-8.2 - ia-8.3 - ia-8.4 - ia-8.5 - ia-8.6


Statement

Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.

Guidance

Non-organizational users include system users other than organizational users explicitly covered by IA-2 . Non-organizational users are uniquely identified and authenticated for accesses other than those explicitly identified and documented in AC-14 . Identification and authentication of non-organizational users accessing federal systems may be required to protect federal, proprietary, or privacy-related information (with exceptions noted for national security systems). Organizations consider many factors—including security, privacy, scalability, and practicality—when balancing the need to ensure ease of use for access to federal information and systems with the need to protect and adequately mitigate risk.

Assessment Objective

non-organizational users or processes acting on behalf of non-organizational users are uniquely identified and authenticated.

Identification and authentication policy

system security plan

privacy plan

procedures addressing user identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

list of system accounts

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

organizational personnel with account management responsibilities

Mechanisms supporting and/or implementing identification and authentication capabilities