Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: IA-FAMILY: IDENTIFICATION AND AUTHENTICATION

IA-9 SERVICE IDENTIFICATION AND AUTHENTICATION

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

ia-9

service identification and authentication

 

assessment objective:

Determine if the organization:

ia-9[1]  

defines information system services to be identified and authenticated using security safeguards;

ia-9[2]  

defines security safeguards to be used to identify and authenticate organization-defined information system services; and

ia-9[3]  

identifies and authenticates organization-defined information system services using organization-defined security safeguards.

potential assessment methods and objects:

Examine: [SELECT FROM: Identification and authentication policy; procedures addressing service identification and authentication; security plan; information system design documentation; security safeguards used to identify and authenticate information system services; information system configuration settings and associated documentation; information system audit records; other relevant documents or records].

Interview: [select from: Organizational personnel with information system operations responsibilities; organizational personnel with information security responsibilities; system/network administrators; system developers; organizational personnel with identification and authentication responsibilities].

Test: [select from: Security safeguards implementing service identification and authentication capability].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056