AU-10(1): Association of Identities

Parent Control:

AU-10: Non-repudiation

Threats Addressed:


(Not part of any baseline)

Previous Version:

Control Statement

  1. Bind the identity of the information producer with the information to [Assignment: organization-defined strength of binding]; and
  2. Provide the means for authorized individuals to determine the identity of the producer of the information.

Supplemental Guidance

Binding identities to the information supports audit requirements that provide organizational personnel with the means to identify who produced specific information in the event of an information transfer. Organizations determine and approve the strength of attribute binding between the information producer and the information based on the security category of the information and other relevant risk factors.