IA-2(12): Acceptance of PIV Credentials
Control Family:
Threats Addressed:
Baselines:
- Low
- Moderate
- High
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- IA-2(12): Acceptance Of Piv Credentials
Control Statement
Accept and electronically verify Personal Identity Verification-compliant credentials.
Supplemental Guidance
Acceptance of Personal Identity Verification (PIV)-compliant credentials applies to organizations implementing logical access control and physical access control systems. PIV-compliant credentials are those credentials issued by federal agencies that conform to FIPS Publication 201 and supporting guidance documents. The adequacy and reliability of PIV card issuers are authorized using SP 800-79-2 . Acceptance of PIV-compliant credentials includes derived PIV credentials, the use of which is addressed in SP 800-166 . The DOD Common Access Card (CAC) is an example of a PIV credential.
OT Discussion
The acceptance of PIV credentials is only required for federal organizations, as defined by OMB Memorandum M-19-17 [OMB-M1917]. Nonfederal organizations should refer to IA-2 (1) (2) for guidance on multi-factor authentication credentials. Furthermore, many OT systems do not have the ability to accept PIV credentials and will require compensating controls.