AU-10(1): Association Of Identities

Parent Control:

AU-10: Non-Repudiation

CSF v1.1 References:

Threats Addressed:

Baselines:

(Not part of any baseline)

Next Version:

Control Statement

The information system:

  1. Binds the identity of the information producer with the information to [Assignment: organization-defined strength of binding]; and
  2. Provides the means for authorized individuals to determine the identity of the producer of the information.

Supplemental Guidance

This control enhancement supports audit requirements that provide organizational personnel with the means to identify who produced specific information in the event of an information transfer. Organizations determine and approve the strength of the binding between the information producer and the information based on the security category of the information and relevant risk factors.