id: "IA-13(02)" title: "Verification of Identity Assertions and Access Tokens" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-13.02" priority: "P1" implementation_level: "system" parent: "IA-13" enhancement: True
Statement
The source and integrity of identity assertions and access tokens are verified before granting access to system and information resources.
Guidance
This includes verification of digital signatures protecting identity assertions and access tokens, as well as included metadata. Metadata includes information about the access request such as information unique to user, system or information resource being accessed, or the transaction itself such as time. Protected system and information resources could include connected networks, applications, and APIs.
Assessment Objective: the source of identity assertions is verified before granting access to system and information resources;
Assessment Objective: the source of access tokens is verified before granting access to system and information resources;
Assessment Objective: the integrity of identity assertions is verified before granting access to system and information resources;
Assessment Objective: the integrity of access tokens is verified before granting access to system and information resources
Identification and authentication policy;
system security plan; system design documentation;
system configuration settings and associated documentation;
other relevant documents or records
Organizational personnel with system operations responsibilities;
organizational personnel with information security responsibilities;
system/ network administrators;
organizational personnel with account management responsibilities;
system developers
Identity provider mechanisms supporting and/or implementing identification and authentication capabilities and access rights