IAM-21—Credentials Validation
>Control Description
Organization systems utilize Federal Identity, Credential, and Access Management (FICAM) components and conform to FICAM-issued profiles; systems verify and accept the following external credentials:
• personal Identity Verification (PIV) credentials from federal agencies, and
• FICAM-approved credentials from non-federal third-parties
Theme
Technology
Type
Preventive
Policy/Standard
Access Management Procedure>Implementation Guidance
1. Ensure that the organization uses Federal Identity, Credential, and Access Management (FICAM) components and conform to FICAM-issued profiles for Federal Systems. 2. Ensure that the organization accepts personal Identity Verification (PIV) credentials from federal agencies and FICAM-approved credentials from non-federal third-parties
>Testing Procedure
1. Inspect and validate whether the organization uses Federal Identity, Credential, and Access Management (FICAM) components and conform to FICAM-issued profiles for Federal Systems. 2. Validate that the organization accepts personal Identity Verification (PIV) credentials from federal agencies and FICAM-approved credentials from non-federal third-parties
>Audit Artifacts
E-IAM-27
Ask AI
Configure your API key to use AI features.