Under active development Content is continuously updated and improved

IAM-21Credentials Validation

>Control Description

Organization systems utilize Federal Identity, Credential, and Access Management (FICAM) components and conform to FICAM-issued profiles; systems verify and accept the following external credentials: • personal Identity Verification (PIV) credentials from federal agencies, and • FICAM-approved credentials from non-federal third-parties

Theme

Technology

Type

Preventive

Policy/Standard

Access Management Procedure

>Implementation Guidance

1. Ensure that the organization uses Federal Identity, Credential, and Access Management (FICAM) components and conform to FICAM-issued profiles for Federal Systems. 2. Ensure that the organization accepts personal Identity Verification (PIV) credentials from federal agencies and FICAM-approved credentials from non-federal third-parties

>Testing Procedure

1. Inspect and validate whether the organization uses Federal Identity, Credential, and Access Management (FICAM) components and conform to FICAM-issued profiles for Federal Systems. 2. Validate that the organization accepts personal Identity Verification (PIV) credentials from federal agencies and FICAM-approved credentials from non-federal third-parties

>Audit Artifacts

E-IAM-27

Ask AI

Configure your API key to use AI features.