id: "IA-12(06)" title: "Accept Externally-proofed Identities" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-12.06" priority: "P1" implementation_level: "organization" parent: "IA-12" enhancement: True


Statement

Accept externally-proofed identities at {{ insert: param, ia-12.06_odp }}.

Guidance

To limit unnecessary re-proofing of identities, particularly of non-PIV users, organizations accept proofing conducted at a commensurate level of assurance by other agencies or organizations. Proofing is consistent with organizational security policy and the identity assurance level appropriate for the system, application, or information accessed. Accepting externally-proofed identities is a fundamental component of managing federated identities across agencies and organizations.

Assessment Objective

externally proofed identities are accepted {{ insert: param, ia-12.06_odp }}.

Identification and authentication policy

procedures addressing identity proofing

system security plan

other relevant documents or records

Organizational personnel with system operations responsibilities

organizational personnel with information security responsibilities

system/network administrators

system developers

organizational personnel with identification and authentication responsibilities

Mechanisms supporting and/or implementing identification and authentication capabilities