IA-8: Identification And Authentication (Non-Organizational Users)
Control Family:
Threats Addressed:
Next Version:
- NIST Special Publication 800-53 Revision 5:
- IA-8: Identification and Authentication (non-organizational Users)
Control Statement
The information system uniquely identifies and authenticates non-organizational users (or processes acting on behalf of non-organizational users).
Supplemental Guidance
Non-organizational users include information system users other than organizational users explicitly covered by IA-2. These individuals are uniquely identified and authenticated for accesses other than those accesses explicitly identified and documented in AC-14. In accordance with the E-Authentication E-Government initiative, authentication of non-organizational users accessing federal information systems may be required to protect federal, proprietary, or privacy-related information (with exceptions noted for national security systems). Organizations use risk assessments to determine authentication needs and consider scalability, practicality, and security in balancing the need to ensure ease of use for access to federal information and information systems with the need to protect and adequately mitigate risk. IA-2 addresses identification and authentication requirements for access to information systems by organizational users.
Control Enhancements
IA-8(1): Acceptance Of Piv Credentials From Other Agencies
Baseline(s):
- Low
- Moderate
- High
The information system accepts and electronically verifies Personal Identity Verification (PIV) credentials from other federal agencies.
IA-8(2): Acceptance Of Third-Party Credentials
Baseline(s):
- Low
- Moderate
- High
The information system accepts only FICAM-approved third-party credentials.
IA-8(3): Use Of Ficam-Approved Products
Baseline(s):
- Low
- Moderate
- High
The organization employs only FICAM-approved information system components in [Assignment: organization-defined information systems] to accept third-party credentials.
IA-8(4): Use Of Ficam-Issued Profiles
Baseline(s):
- Low
- Moderate
- High
The information system conforms to FICAM-issued profiles.
IA-8(5): Acceptance Of Piv-I Credentials
Baseline(s):
The information system accepts and electronically verifies Personal Identity Verification-I (PIV-I) credentials.