IA-4(1)—Prohibit Account Identifiers As Public Identifiers
>Control Description
Prohibit the use of system account identifiers that are the same as public identifiers for individual accounts.
>Supplemental Guidance
Prohibiting account identifiers as public identifiers applies to any publicly disclosed account identifier used for communication such as, electronic mail and instant messaging. Prohibiting the use of systems account identifiers that are the same as some public identifier, such as the individual identifier section of an electronic mail address, makes it more difficult for adversaries to guess user identifiers. Prohibiting account identifiers as public identifiers without the implementation of other supporting controls only complicates guessing of identifiers.
Additional protections are required for authenticators and credentials to protect the account.
>Related Controls
>Assessment Interview Topics
Questions assessors commonly ask
Process & Governance:
- •What formal policies and procedures govern the implementation of IA-4(1) (Prohibit Account Identifiers As Public Identifiers)?
- •Who are the designated roles responsible for implementing, maintaining, and monitoring IA-4(1)?
- •How frequently is the IA-4(1) policy reviewed and updated, and what triggers policy changes?
- •What governance structure ensures IA-4(1) requirements are consistently applied across all systems?
Technical Implementation:
- •Describe the specific technical mechanisms or controls used to enforce IA-4(1) requirements.
- •What automated tools, systems, or technologies are deployed to implement IA-4(1)?
- •How is IA-4(1) integrated into your system architecture and overall security posture?
- •What configuration settings, parameters, or technical specifications enforce IA-4(1) requirements?
Evidence & Documentation:
- •What documentation demonstrates the complete implementation of IA-4(1)?
- •What audit logs, records, reports, or monitoring data validate IA-4(1) compliance?
- •Can you provide evidence of periodic reviews, assessments, or testing of IA-4(1) effectiveness?
- •What artifacts would you present during a FedRAMP assessment to demonstrate IA-4(1) compliance?
Ask AI
Configure your API key to use AI features.