id: "IA-08(05)" title: "Acceptance of PIV-I Credentials" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-08.05" priority: "P1" implementation_level: "system" parent: "IA-08" enhancement: True


Statement

Accept and verify federated or PKI credentials that meet {{ insert: param, ia-08.05_odp }}.

Guidance

Acceptance of PIV-I credentials can be implemented by PIV, PIV-I, and other commercial or external identity providers. The acceptance and verification of PIV-I-compliant credentials apply to both logical and physical access control systems. The acceptance and verification of PIV-I credentials address nonfederal issuers of identity cards that desire to interoperate with United States Government PIV systems and that can be trusted by Federal Government-relying parties. The X.509 certificate policy for the Federal Bridge Certification Authority (FBCA) addresses PIV-I requirements. The PIV-I card is commensurate with the PIV credentials as defined in cited references. PIV-I credentials are the credentials issued by a PIV-I provider whose PIV-I certificate policy maps to the Federal Bridge PIV-I Certificate Policy. A PIV-I provider is cross-certified with the FBCA (directly or through another PKI bridge) with policies that have been mapped and approved as meeting the requirements of the PIV-I policies defined in the FBCA certificate policy.

Assessment Objective: federated or PKI credentials that meet {{ insert: param, ia-08.05_odp }} are accepted;

Assessment Objective: federated or PKI credentials that meet {{ insert: param, ia-08.05_odp }} are verified.

Identification and authentication policy

system security plan

procedures addressing user identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

PIV-I verification records

evidence of PIV-I credentials

PIV-I credential authorizations

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

organizational personnel with account management responsibilities

Mechanisms supporting and/or implementing identification and authentication capabilities

mechanisms that accept and verify PIV-I credentials