id: "IA-08(06)" title: "Disassociability" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-08.06" priority: "P1" implementation_level: "organization" parent: "IA-08" enhancement: True


Statement

Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers, and relying parties: {{ insert: param, ia-08.06_odp }}.

Guidance

Federated identity solutions can create increased privacy risks due to the tracking and profiling of individuals. Using identifier mapping tables or cryptographic techniques to blind credential service providers and relying parties from each other or to make identity attributes less visible to transmitting parties can reduce these privacy risks.

Assessment Objective

{{ insert: param, ia-08.06_odp }} to disassociate user attributes or identifier assertion relationships among individuals, credential service providers, and relying parties are implemented.

Identification and authentication policy

system security plan

privacy plan

procedures addressing user identification and authentication

system design documentation

system configuration settings and associated documentation

system audit records

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

system developers

organizational personnel with account management responsibilities

Mechanisms supporting and/or implementing identification and authentication capabilities