
ia-4(2) |
identifier management | supervisor authorization |
|
assessment objective: Determine if the organization requires that the registration process to receive an individual identifier includes supervisor authorization. |
potential assessment methods and objects: Examine: [select from: Identification and authentication policy; procedures addressing identifier management; procedures addressing account management; information system design documentation; information system configuration settings and associated documentation; information system audit records; other relevant documents or records]. Interview: [select from: Organizational personnel with identifier management responsibilities; supervisors responsible for authorizing identifier registration; organizational personnel with information security responsibilities; system/network administrators]. Test: [select from: Automated mechanisms supporting and/or implementing identifier management]. |