id: "SA-04(10)" title: "Use of Approved PIV Products" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.10" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True
Statement
Employ only information technology products on the FIPS 201-approved products list for Personal Identity Verification (PIV) capability implemented within organizational systems.
Guidance
Products on the FIPS 201-approved products list meet NIST requirements for Personal Identity Verification (PIV) of Federal Employees and Contractors. PIV cards are used for multi-factor authentication in systems and organizations.
Assessment Objective
only information technology products on the FIPS 201-approved products list for the Personal Identity Verification (PIV) capability implemented within organizational systems are employed.
Supply chain risk management plan
system and services acquisition policy
procedures addressing the integration of security requirements, descriptions, and criteria into the acquisition process
solicitation documentation
acquisition documentation
acquisition contracts for the system, system component, or system service
service level agreements
FIPS 201 approved products list
system security plan
other relevant documents or records
Organizational personnel with acquisition/contracting responsibilities
organizational personnel with the responsibility for determining system security requirements
organizational personnel with the responsibility for ensuring that only FIPS 201- approved products are implemented
organizational personnel with information security responsibilities
Organizational processes for selecting and employing FIPS 201-approved products