id: "IA-08(02)" title: "Acceptance of External Authenticators" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-08.02" priority: "P1" implementation_level: "system" parent: "IA-08" enhancement: True


Accept only external authenticators that are NIST-compliant; and

Document and maintain a list of accepted external authenticators.

Guidance

Acceptance of only NIST-compliant external authenticators applies to organizational systems that are accessible to the public (e.g., public-facing websites). External authenticators are issued by nonfederal government entities and are compliant with SP 800-63B . Approved external authenticators meet or exceed the minimum Federal Government-wide technical, security, privacy, and organizational maturity requirements. Meeting or exceeding Federal requirements allows Federal Government relying parties to trust external authenticators in connection with an authentication transaction at a specified authenticator assurance level.

Assessment Objective: only external authenticators that are NIST-compliant are accepted;

Assessment Objective: a list of accepted external authenticators is documented;

Assessment Objective: a list of accepted external authenticators is maintained.

Identification and authentication policy

system security plan

procedures addressing user identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

list of third-party credentialing products, components, or services procured and implemented by organization

third-party credential verification records

evidence of third-party credentials

third-party credential authorizations

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

organizational personnel with account management responsibilities

Mechanisms supporting and/or implementing identification and authentication capabilities

mechanisms that accept external credentials