IA-8 Identification and authentication of non-organizational users
Requires non-organizational users, and processes acting on their behalf, to be uniquely identified and authenticated so that external party activity on the system is attributable in the same way as internal activity.
4
artefacts
1
held by a system
2
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Federation or external identity provider configuration and trust agreements · Identity provider / directory
periodic reviewEvidence produced at each review
- Evidence of unique accounts rather than shared partner logins · Identity provider / directory
- Access review evidence for external identities · Identity provider / directory
governing documentDocuments that govern the control
- Identity register covering external users such as customers, partners and vendors · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- One shared login issued per partner organization, so individual actions cannot be attributed
- External accounts persist after the commercial relationship ends
- Federated trust accepted without agreeing the assurance level behind it
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetIA-7 Cryptographic module authentication · IA-9 Service Identification and Authentication. Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications