id: "IA-08(02)" title: "Acceptance of External Authenticators" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-08.02" priority: "P1" implementation_level: "system" parent: "IA-08" enhancement: True
Accept only external authenticators that are NIST-compliant; and
Document and maintain a list of accepted external authenticators.
Guidance
Acceptance of only NIST-compliant external authenticators applies to organizational systems that are accessible to the public (e.g., public-facing websites). External authenticators are issued by nonfederal government entities and are compliant with SP 800-63B . Approved external authenticators meet or exceed the minimum Federal Government-wide technical, security, privacy, and organizational maturity requirements. Meeting or exceeding Federal requirements allows Federal Government relying parties to trust external authenticators in connection with an authentication transaction at a specified authenticator assurance level.
Assessment Objective: only external authenticators that are NIST-compliant are accepted;
Assessment Objective: a list of accepted external authenticators is documented;
Assessment Objective: a list of accepted external authenticators is maintained.
Identification and authentication policy
system security plan
procedures addressing user identification and authentication
system design documentation
system configuration settings and associated documentation
system audit records
list of third-party credentialing products, components, or services procured and implemented by organization
third-party credential verification records
evidence of third-party credentials
third-party credential authorizations
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
organizational personnel with account management responsibilities
Mechanisms supporting and/or implementing identification and authentication capabilities
mechanisms that accept external credentials