id: "IA-09" title: "Service Identification and Authentication" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-09" priority: "P1" implementation_level: "system" enhancements: - ia-9.1 - ia-9.2
Statement
Uniquely identify and authenticate {{ insert: param, ia-09_odp }} before establishing communications with devices, users, or other services or applications.
Guidance
Services that may require identification and authentication include web applications using digital certificates or services or applications that query a database. Identification and authentication methods for system services and applications include information or code signing, provenance graphs, and electronic signatures that indicate the sources of services. Decisions regarding the validity of identification and authentication claims can be made by services separate from the services acting on those decisions. This can occur in distributed system architectures. In such situations, the identification and authentication decisions (instead of actual identifiers and authentication data) are provided to the services that need to act on those decisions.
Assessment Objective
{{ insert: param, ia-09_odp }} are uniquely identified and authenticated before establishing communications with devices, users, or other services or applications.
Identification and authentication policy
procedures addressing service identification and authentication
system security plan
system design documentation
security safeguards used to identify and authenticate system services
system configuration settings and associated documentation
system audit records
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
organizational personnel with identification and authentication responsibilities
Security safeguards implementing service identification and authentication capabilities