IA-04 Identifier Management

Identification and Authentication

Low Moderate High

Description

The organization manages user identifiers by: (i) uniquely identifying each user; (ii) verifying the identity of each user; (iii) receiving authorization to issue a user identifier from an appropriate organization official; (iv) issuing the user identifier to the intended party; (v) disabling the user identifier after [Assignment: organization-defined time period] of inactivity; and (vi) archiving user identifiers.\n

Supplemental Guidance

Identifier management is not applicable to shared information system accounts (e.g., guest and anonymous accounts). FIPS 201 and Special Publications 800-73, 800- 76, and 800-78 specify a personal identity verification (PIV) credential for use in the unique identification and authentication of federal employees and contractors.\n

Changes from Rev 4

Removed control step to disable the identifier and associated parameter

Enhancements

(0) None.\n

Compliance Mappings

ISO 27002:2022

5.16

CIS Controls v8

12.55.66.6

NIST CSF 2.0

PR.AAPR.AA-03PR.AA-04PR.AA-05

SOC 2 TSC

CC6.1CC6.1-POF3CC6.1-POF4CC6.6CC6.6-POF2CC6.6-POF3

ISO 17799 (legacy)

11.2.311.5.2

COBIT 4.1 (legacy)

DS5.3DS5.4