last sync: 2024-Nov-25 18:54:24 UTC

Identify status of individual users | Regulatory Compliance - Operational

Azure BuiltIn Policy definition

Source Azure Portal
Display name Identify status of individual users
Id ca748dfe-3e28-1d18-4221-89aea30aa0a5
Version 1.1.0
Details on versioning
Versioning Versions supported for Versioning: 1
1.1.0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description CMA_C1316 - Identify status of individual users
Additional metadata Name/Id: CMA_C1316 / CMA_C1316
Category: Operational
Title: Identify status of individual users
Ownership: Customer
Description: The customer is responsible for identifying the status (e.g., contractor, foreign national) of individual users with unique identifiers.
Requirements: The customer is responsible for implementing this recommendation.
Mode All
Type BuiltIn
Preview False
Deprecated False
Effect Default
Manual
Allowed
Manual, Disabled
RBAC role(s) none
Rule aliases none
Rule resource types IF (1)
Microsoft.Resources/subscriptions
Compliance
The following 6 compliance controls are associated with this Policy definition 'Identify status of individual users' (ca748dfe-3e28-1d18-4221-89aea30aa0a5)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
FedRAMP_High_R4 IA-4(4) FedRAMP_High_R4_IA-4(4) FedRAMP High IA-4 (4) Identification And Authentication Identify User Status Shared n/a The organization manages individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]. Supplemental Guidance: Characteristics identifying the status of individuals include, for example, contractors and foreign nationals. Identifying the status of individuals by specific characteristics provides additional information about the people with whom organizational personnel are communicating. For example, it might be useful for a government employee to know that one of the individuals on an email message is a contractor. Related control: AT-2. link 1
FedRAMP_Moderate_R4 IA-4(4) FedRAMP_Moderate_R4_IA-4(4) FedRAMP Moderate IA-4 (4) Identification And Authentication Identify User Status Shared n/a The organization manages individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]. Supplemental Guidance: Characteristics identifying the status of individuals include, for example, contractors and foreign nationals. Identifying the status of individuals by specific characteristics provides additional information about the people with whom organizational personnel are communicating. For example, it might be useful for a government employee to know that one of the individuals on an email message is a contractor. Related control: AT-2. link 1
hipaa 11109.01q1Organizational.57-01.q hipaa-11109.01q1Organizational.57-01.q 11109.01q1Organizational.57-01.q 11 Access Control 11109.01q1Organizational.57-01.q 01.05 Operating System Access Control Shared n/a The organization ensures that redundant user IDs are not issued to other users and that all users are uniquely identified and authenticated for both local and remote access to information systems. 7
hipaa 1167.01e2System.1-01.e hipaa-1167.01e2System.1-01.e 1167.01e2System.1-01.e 11 Access Control 1167.01e2System.1-01.e 01.02 Authorized Access to Information Systems Shared n/a The organization maintains a documented list of authorized users of information assets. 2
NIST_SP_800-53_R4 IA-4(4) NIST_SP_800-53_R4_IA-4(4) NIST SP 800-53 Rev. 4 IA-4 (4) Identification And Authentication Identify User Status Shared n/a The organization manages individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]. Supplemental Guidance: Characteristics identifying the status of individuals include, for example, contractors and foreign nationals. Identifying the status of individuals by specific characteristics provides additional information about the people with whom organizational personnel are communicating. For example, it might be useful for a government employee to know that one of the individuals on an email message is a contractor. Related control: AT-2. link 1
NIST_SP_800-53_R5 IA-4(4) NIST_SP_800-53_R5_IA-4(4) NIST SP 800-53 Rev. 5 IA-4 (4) Identification and Authentication Identify User Status Shared n/a Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]. link 1
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
FedRAMP High d5264498-16f4-418a-b659-fa7ef418175f Regulatory Compliance GA BuiltIn
FedRAMP Moderate e95f5a9f-57ad-4d03-bb0b-b1d16db93693 Regulatory Compliance GA BuiltIn
HITRUST/HIPAA a169a624-5599-4385-a696-c8d643089fab Regulatory Compliance GA BuiltIn
NIST SP 800-53 Rev. 4 cf25b9c1-bd23-4eb6-bd2c-f4f3ac644a5f Regulatory Compliance GA BuiltIn
NIST SP 800-53 Rev. 5 179d1daa-458f-4e47-8086-2a68d0d6c38f Regulatory Compliance GA BuiltIn
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-09-27 16:35:32 change Minor (1.0.0 > 1.1.0)
2022-09-19 17:41:40 add ca748dfe-3e28-1d18-4221-89aea30aa0a5
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC