IA-8(4): Use Of Ficam-Issued Profiles

CSF v1.1 References:

Threats Addressed:


  • Low
  • Moderate
  • High

Next Version:

Control Statement

The information system conforms to FICAM-issued profiles.

Supplemental Guidance

This control enhancement addresses open identity management standards. To ensure that these standards are viable, robust, reliable, sustainable (e.g., available in commercial information technology products), and interoperable as documented, the United States Government assesses and scopes identity management standards and technology implementations against applicable federal legislation, directives, policies, and requirements. The result is FICAM-issued implementation profiles of approved protocols (e.g., FICAM authentication protocols such as SAML 2.0 and OpenID 2.0, as well as other protocols such as the FICAM Backend Attribute Exchange).