compliance controls are associated with this Policy definition 'Accept only FICAM-approved third-party credentials' (2d2ca910-7957-23ee-2945-33f401606efc)
Control Domain |
Control |
Name |
MetadataId |
Category |
Title |
Owner |
Requirements |
Description |
Info |
Policy# |
FedRAMP_High_R4 |
IA-8(2) |
FedRAMP_High_R4_IA-8(2) |
FedRAMP High IA-8 (2) |
Identification And Authentication |
Acceptance Of Third-Party Credentials |
Shared |
n/a |
The information system accepts only FICAM-approved third-party credentials.
Supplemental Guidance: This control enhancement typically applies to organizational information systems that are accessible to the general public, for example, public-facing websites. Third-party credentials are those credentials issued by nonfederal government entities approved by the Federal Identity, Credential, and Access Management (FICAM) Trust Framework Solutions initiative. Approved third-party credentials meet or exceed the set of minimum federal government-wide technical, security, privacy, and organizational maturity requirements. This allows federal government relying parties to trust such credentials at their approved assurance levels. Related control: AU-2. |
link |
1 |
FedRAMP_Moderate_R4 |
IA-8(2) |
FedRAMP_Moderate_R4_IA-8(2) |
FedRAMP Moderate IA-8 (2) |
Identification And Authentication |
Acceptance Of Third-Party Credentials |
Shared |
n/a |
The information system accepts only FICAM-approved third-party credentials.
Supplemental Guidance: This control enhancement typically applies to organizational information systems that are accessible to the general public, for example, public-facing websites. Third-party credentials are those credentials issued by nonfederal government entities approved by the Federal Identity, Credential, and Access Management (FICAM) Trust Framework Solutions initiative. Approved third-party credentials meet or exceed the set of minimum federal government-wide technical, security, privacy, and organizational maturity requirements. This allows federal government relying parties to trust such credentials at their approved assurance levels. Related control: AU-2. |
link |
1 |
hipaa |
1122.01q1System.1-01.q |
hipaa-1122.01q1System.1-01.q |
1122.01q1System.1-01.q |
11 Access Control |
1122.01q1System.1-01.q 01.05 Operating System Access Control |
Shared |
n/a |
Unique IDs that can be used to trace activities to the responsible individual are required for all types of organizational and non-organizational users. |
|
7 |
hipaa |
1424.05j2Organizational.5-05.j |
hipaa-1424.05j2Organizational.5-05.j |
1424.05j2Organizational.5-05.j |
14 Third Party Assurance |
1424.05j2Organizational.5-05.j 05.02 External Parties |
Shared |
n/a |
The organization has a formal mechanism to authenticate the customer's identity prior to granting access to covered information. |
|
8 |
NIST_SP_800-53_R4 |
IA-8(2) |
NIST_SP_800-53_R4_IA-8(2) |
NIST SP 800-53 Rev. 4 IA-8 (2) |
Identification And Authentication |
Acceptance Of Third-Party Credentials |
Shared |
n/a |
The information system accepts only FICAM-approved third-party credentials.
Supplemental Guidance: This control enhancement typically applies to organizational information systems that are accessible to the general public, for example, public-facing websites. Third-party credentials are those credentials issued by nonfederal government entities approved by the Federal Identity, Credential, and Access Management (FICAM) Trust Framework Solutions initiative. Approved third-party credentials meet or exceed the set of minimum federal government-wide technical, security, privacy, and organizational maturity requirements. This allows federal government relying parties to trust such credentials at their approved assurance levels. Related control: AU-2. |
link |
1 |
NIST_SP_800-53_R5 |
IA-8(2) |
NIST_SP_800-53_R5_IA-8(2) |
NIST SP 800-53 Rev. 5 IA-8 (2) |
Identification and Authentication |
Acceptance of External Authenticators |
Shared |
n/a |
(a) Accept only external authenticators that are NIST-compliant; and
(b) Document and maintain a list of accepted external authenticators. |
link |
1 |