<?xml version="1.0"?>

<rss version="2.0">


<channel>
<title>Home - All Categories - FedRAMP  - Identification and Authentication &amp;#40;IA&amp;#41;  </title>
<link>http://www.compliancewiki.org/category/fedramp/identification-and-authentication-ia/14/</link>
<description>This RSS Feed contains Articles of Category in the knowledge base. You can click on the title to view its content. Powered by PHPKB (https://www.phpkb.com)</description>
<item>
										<guid>http://www.compliancewiki.org/article/cryptographic-module-authentication-ia-7-711.html</guid>
										<title>Cryptographic Module Authentication IA-7</title>
										<link>http://www.compliancewiki.org/article/cryptographic-module-authentication-ia-7-711.html</link>
										<description><![CDATA[Overview:The information system implements mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/authenticator-feedback-ia-6-710.html</guid>
										<title>Authenticator Feedback IA-6</title>
										<link>http://www.compliancewiki.org/article/authenticator-feedback-ia-6-710.html</link>
										<description><![CDATA[Overview:The information system obscures feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals. Supplemental Guidance:The feedback from...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/no-embedded-unencrypted-static-authenticators-ia-5-7-708.html</guid>
										<title>No Embedded Unencrypted Static Authenticators IA-5&#40;7&#41;</title>
										<link>http://www.compliancewiki.org/article/no-embedded-unencrypted-static-authenticators-ia-5-7-708.html</link>
										<description><![CDATA[Overview:The organization ensures that unencrypted static authenticators are not embedded in applications or access scripts or stored on function keys. Supplemental Guidance:Organizations exercise caution in determining whether embedded or stored...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/network-access-to-privileged-accounts-replay-resistant-ia-2-8-696.html</guid>
										<title>Network Access to Privileged Accounts Replay Resistant IA-2&#40;8&#41;</title>
										<link>http://www.compliancewiki.org/article/network-access-to-privileged-accounts-replay-resistant-ia-2-8-696.html</link>
										<description><![CDATA[Overview:The information system implements replay-resistant authentication mechanisms for network access to privileged accounts. Supplemental Guidance:Authentication processes resist replay attacks if it is impractical to achieve successful...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/device-identification-and-authentication-ia-3-699.html</guid>
										<title>Device Identification and Authentication IA-3</title>
										<link>http://www.compliancewiki.org/article/device-identification-and-authentication-ia-3-699.html</link>
										<description><![CDATA[Overview:The information system uniquely identifies and authenticates [Assignment: organization- defined specific and/or types of devices] before establishing a [Selection (one or more): local; remote; network] connection. Supplemental Guidance...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/acceptance-of-piv-credentials-from-other-agencies-ia-8-1-713.html</guid>
										<title>Acceptance of PIV Credentials from Other Agencies IA-8&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/acceptance-of-piv-credentials-from-other-agencies-ia-8-1-713.html</link>
										<description><![CDATA[Overview:The information system accepts and electronically verifies Personal Identity Verification (PIV) credentials from other federal agencies. Supplemental Guidance:This control enhancement applies to logical access control systems (LACS) and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hardware-token-based-authentication-ia-5-11-709.html</guid>
										<title>Hardware Token-Based Authentication IA-5&#40;11&#41;</title>
										<link>http://www.compliancewiki.org/article/hardware-token-based-authentication-ia-5-11-709.html</link>
										<description><![CDATA[Overview:The information system, for hardware token-based authentication, employs mechanisms that satisfy [Assignment: organization-defined token quality requirements]. Supplemental Guidance:Hardware token-based authentication typically refers to the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-identification-and-authorization-policy-and-procedures-ia-1-690.html</guid>
										<title>FedRAMP - Identification and Authorization Policy and Procedures IA-1</title>
										<link>http://www.compliancewiki.org/article/fedramp-identification-and-authorization-policy-and-procedures-ia-1-690.html</link>
										<description><![CDATA[Overview:The organization:a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:1. An identification and authentication policy that addresses purpose, scope, roles, responsibilities, management commitment,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/organizational-users-group-authentication-ia-2-5-695.html</guid>
										<title>Organizational Users Group Authentication IA-2&#40;5&#41;</title>
										<link>http://www.compliancewiki.org/article/organizational-users-group-authentication-ia-2-5-695.html</link>
										<description><![CDATA[Overview:The organization requires individuals to be authenticated with an individual authenticator when a group authenticator is employed. Supplemental Guidance:Requiring individuals to use individual authenticators as a second level of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/identifier-management-ia-4-700.html</guid>
										<title>Identifier Management IA-4</title>
										<link>http://www.compliancewiki.org/article/identifier-management-ia-4-700.html</link>
										<description><![CDATA[Overview:The organization manages information system identifiers by:a. Receiving authorization from [Assignment: organization-defined personnel or roles] to assign an individual, group, role, or device identifier;b. Selecting an identifier that...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/protection-of-authenticators-ia-5-6-707.html</guid>
										<title>Protection of Authenticators IA-5&#40;6&#41;</title>
										<link>http://www.compliancewiki.org/article/protection-of-authenticators-ia-5-6-707.html</link>
										<description><![CDATA[Overview:The organization protects authenticators commensurate with the security category of the information to which use of the authenticator permits access. Supplemental Guidance:For information systems containing multiple security categories of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/automated-support-for-password-strength-determination-ia-5-4-706.html</guid>
										<title>Automated Support for Password Strength Determination IA-5&#40;4&#41;</title>
										<link>http://www.compliancewiki.org/article/automated-support-for-password-strength-determination-ia-5-4-706.html</link>
										<description><![CDATA[Overview:The organization employs automated tools to determine if password authenticators are sufficiently strong to satisfy [Assignment: organization-defined requirements]. Supplemental Guidance:This control enhancement focuses on the creation of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/acceptance-of-third-party-credentials-ia-8-2-714.html</guid>
										<title>Acceptance of Third-Party Credentials IA-8&#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/acceptance-of-third-party-credentials-ia-8-2-714.html</link>
										<description><![CDATA[Overview:The information system accepts only FICAM-approved third-party credentials. Supplemental Guidance:This control enhancement typically applies to organizational information systems that are accessible to the general public, for example, public...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/authenticator-management-ia-5-702.html</guid>
										<title>Authenticator Management IA-5</title>
										<link>http://www.compliancewiki.org/article/authenticator-management-ia-5-702.html</link>
										<description><![CDATA[Overview:The organization manages information system authenticators by:a. Verifying, as part of the initial authenticator distribution, the identity of the individual, group, role, or device receiving the authenticator;b. Establishing initial...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/network-access-to-privileged-accounts-ia-2-1-692.html</guid>
										<title>Network Access to Privileged Accounts IA-2&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/network-access-to-privileged-accounts-ia-2-1-692.html</link>
										<description><![CDATA[Overview:The information system implements multifactor authentication for network access to privileged accounts. Supplemental Guidance: Related control: AC-6. Action Items:1) Implement MFA for network access to privileged accounts Â  Related...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/password-based-authentication-ia-5-1-703.html</guid>
										<title>Password-Based Authentication IA-5&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/password-based-authentication-ia-5-1-703.html</link>
										<description><![CDATA[Overview:The information system, for password-based authentication:(a) Enforces minimum password complexity of [Assignment: organization-defined requirements for case sensitivity, number of characters, mix of upper-case letters, lower-case letters,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/acceptance-of-piv-credentials-ia-2-12-698.html</guid>
										<title>Acceptance of PIV Credentials IA-2&#40;12&#41;</title>
										<link>http://www.compliancewiki.org/article/acceptance-of-piv-credentials-ia-2-12-698.html</link>
										<description><![CDATA[Overview:The information system accepts and electronically verifies Personal Identity Verification (PIV) credentials. Supplemental Guidance:This control enhancement applies to organizations implementing logical access control systems (LACS) and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/pki-based-authentication-ia-5-2-704.html</guid>
										<title>PKI-Based Authentication IA-5&#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/pki-based-authentication-ia-5-2-704.html</link>
										<description><![CDATA[Overview:The information system, for PKI-based authentication:(a) Validates certifications by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information;(b) Enforces authorized access...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/incident-response-testing-ir-3-719.html</guid>
										<title>Incident Response Testing IR-3</title>
										<link>http://www.compliancewiki.org/article/incident-response-testing-ir-3-719.html</link>
										<description><![CDATA[Overview:The organization tests the incident response capability for the information system [Assignment: organization-defined frequency] using [Assignment: organization-defined tests] to determine the incident response effectiveness and documents the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/identification-and-authorization-non-organizational-users-ia-8-712.html</guid>
										<title>Identification and Authorization Non-Organizational Users IA-8</title>
										<link>http://www.compliancewiki.org/article/identification-and-authorization-non-organizational-users-ia-8-712.html</link>
										<description><![CDATA[Overview:The information system uniquely identifies and authenticates non-organizational users (or processes acting on behalf of non-organizational users). Supplemental Guidance:Non-organizational users include information system users other than...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/identify-user-status-ia-4-4-701.html</guid>
										<title>Identify User Status IA-4&#40;4&#41;</title>
										<link>http://www.compliancewiki.org/article/identify-user-status-ia-4-4-701.html</link>
										<description><![CDATA[Overview:The organization manages individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]. Supplemental Guidance:Characteristics identifying the status of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/local-access-to-privileged-accounts-ia-2-3-694.html</guid>
										<title>Local Access to Privileged Accounts IA-2&#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/local-access-to-privileged-accounts-ia-2-3-694.html</link>
										<description><![CDATA[Overview:The information system implements multifactor authentication for local access to privileged accounts. Supplemental Guidance: Related control: AC-6. Action Items:1) Implement MFA for local access to privileged accounts Â  Related Documents:1)...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/use-of-ficam-approved-products-ia-8-3-715.html</guid>
										<title>Use of FICAM-Approved Products IA-8&#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/use-of-ficam-approved-products-ia-8-3-715.html</link>
										<description><![CDATA[Overview:The organization employs only FICAM-approved information system components in [Assignment: organization-defined information systems] to accept third-party credentials. Supplemental Guidance:This control enhancement typically applies to...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/use-of-ficam-issue-profiles-ia-8-4-716.html</guid>
										<title>Use of FICAM-Issue Profiles IA-8&#40;4&#41;</title>
										<link>http://www.compliancewiki.org/article/use-of-ficam-issue-profiles-ia-8-4-716.html</link>
										<description><![CDATA[Overview:The information system conforms to FICAM-issued profiles. Supplemental Guidance:This control enhancement addresses open identity management standards. To ensure that these standards are viable, robust, reliable, sustainable (e.g., available...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/remote-access-separate-device-ia-2-11-697.html</guid>
										<title>Remote Access Separate Device IA-2&#40;11&#41;</title>
										<link>http://www.compliancewiki.org/article/remote-access-separate-device-ia-2-11-697.html</link>
										<description><![CDATA[Overview:The information system implements multifactor authentication for remote access to privileged and non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access and the device meets ...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/network-access-to-non-privileged-accounts-ia-2-2-693.html</guid>
										<title>Network Access to Non-Privileged Accounts IA-2&#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/network-access-to-non-privileged-accounts-ia-2-2-693.html</link>
										<description><![CDATA[Overview:The information system implements multifactor authentication for network access to non- privileged accounts. Action Items:1) Implement MFA for network access to non-privileged accounts Â  Related Documents:1) Identity and Access Management...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/in-person-and-trusted-third-party-registration-ia-5-3-705.html</guid>
										<title>In-Person and Trusted Third-Party Registration IA-5&#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/in-person-and-trusted-third-party-registration-ia-5-3-705.html</link>
										<description><![CDATA[Overview:The organization requires that the registration process to receive [Assignment: organization- defined types of and/or specific authenticators] be conducted [Selection: in person; by a trusted third party] before [Assignment: organization...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/organizational-users-ia-2-691.html</guid>
										<title>Organizational Users IA-2</title>
										<link>http://www.compliancewiki.org/article/organizational-users-ia-2-691.html</link>
										<description><![CDATA[Overview:The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users). Supplemental Guidance:Organizational users include employees or individuals that organizations deem to...]]></description>

									</item>

</channel>

</rss>