id: "IA-08(06)" title: "Disassociability" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-08.06" priority: "P1" implementation_level: "organization" parent: "IA-08" enhancement: True
Statement
Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers, and relying parties: {{ insert: param, ia-08.06_odp }}.
Guidance
Federated identity solutions can create increased privacy risks due to the tracking and profiling of individuals. Using identifier mapping tables or cryptographic techniques to blind credential service providers and relying parties from each other or to make identity attributes less visible to transmitting parties can reduce these privacy risks.
Assessment Objective
{{ insert: param, ia-08.06_odp }} to disassociate user attributes or identifier assertion relationships among individuals, credential service providers, and relying parties are implemented.
Identification and authentication policy
system security plan
privacy plan
procedures addressing user identification and authentication
system design documentation
system configuration settings and associated documentation
system audit records
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with information security and privacy responsibilities
system/network administrators
system developers
organizational personnel with account management responsibilities
Mechanisms supporting and/or implementing identification and authentication capabilities