EvidenceSheet

IA-8 Identification and authentication of non-organizational users

Requires non-organizational users, and processes acting on their behalf, to be uniquely identified and authenticated so that external party activity on the system is attributable in the same way as internal activity.

4
artefacts
1
held by a system
2
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Federation or external identity provider configuration and trust agreements · Identity provider / directory

periodic reviewEvidence produced at each review

  • Evidence of unique accounts rather than shared partner logins · Identity provider / directory
  • Access review evidence for external identities · Identity provider / directory

governing documentDocuments that govern the control

  • Identity register covering external users such as customers, partners and vendors · Policy repository / GRC workspace

First move

Start with the 1 of 4 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

IA-7 Cryptographic module authentication · IA-9 Service Identification and Authentication. Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications