id: "IA-13(02)" title: "Verification of Identity Assertions and Access Tokens" family: "IA" family_name: "Identification and Authentication" sort_id: "ia-13.02" priority: "P1" implementation_level: "system" parent: "IA-13" enhancement: True


Statement

The source and integrity of identity assertions and access tokens are verified before granting access to system and information resources.

Guidance

This includes verification of digital signatures protecting identity assertions and access tokens, as well as included metadata. Metadata includes information about the access request such as information unique to user, system or information resource being accessed, or the transaction itself such as time. Protected system and information resources could include connected networks, applications, and APIs.

Assessment Objective: the source of identity assertions is verified before granting access to system and information resources;

Assessment Objective: the source of access tokens is verified before granting access to system and information resources;

Assessment Objective: the integrity of identity assertions is verified before granting access to system and information resources;

Assessment Objective: the integrity of access tokens is verified before granting access to system and information resources

Identification and authentication policy;

system security plan; system design documentation;

system configuration settings and associated documentation;

other relevant documents or records

Organizational personnel with system operations responsibilities;

organizational personnel with information security responsibilities;

system/ network administrators;

organizational personnel with account management responsibilities;

system developers

Identity provider mechanisms supporting and/or implementing identification and authentication capabilities and access rights