IA-8(100)—Identification And Authentication (Non-Organizational Users)
PBMM (P2)
Secret (P2)
Technical
>Control Description
In accordance with the TBS Standard on Identity and Credential Assurance (including Appendix B and C) [Reference 60], the organization determines the required identity and credential assurance levels and selects appropriate controls using the standardized assurance levels specified in Appendix B, and implements the minimum requirements for establishing an identity assurance level specified in Appendix C.
>Supplemental Guidance
The TBS Standard on Identity and Credential Assurance [Reference 60] establishes requirements for organizations to adopt a common methodology for assessing their identity and credential risks and selecting appropriate controls or arrangements to mitigate those risks using a standardized assurance level framework. The standard is supported by the TBS Guideline on Defining Authentication Requirements [Reference 61] and the TBS Guideline on Identity Assurance [Reference 62]. These guidelines are intended to be used in conjunction with CSE ITSB-31: User Authentication for IT Systems [Reference 18].
Ask AI
Configure your API key to use AI features.