id: "IA-12(06)" title: "Accept Externally-proofed Identities" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-12.06" priority: "P1" implementation_level: "organization" parent: "IA-12" enhancement: True
Statement
Accept externally-proofed identities at {{ insert: param, ia-12.06_odp }}.
Guidance
To limit unnecessary re-proofing of identities, particularly of non-PIV users, organizations accept proofing conducted at a commensurate level of assurance by other agencies or organizations. Proofing is consistent with organizational security policy and the identity assurance level appropriate for the system, application, or information accessed. Accepting externally-proofed identities is a fundamental component of managing federated identities across agencies and organizations.
Assessment Objective
externally proofed identities are accepted {{ insert: param, ia-12.06_odp }}.
Identification and authentication policy
procedures addressing identity proofing
system security plan
other relevant documents or records
Organizational personnel with system operations responsibilities
organizational personnel with information security responsibilities
system/network administrators
system developers
organizational personnel with identification and authentication responsibilities
Mechanisms supporting and/or implementing identification and authentication capabilities