Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

IA-12 — Identity Proofing

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

6Enhancements
0Parameters
2Baseline memberships
3Assessment methods

IA — Identification and Authentication · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

  1. a.Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines;
  2. b.Resolve user identities to a unique individual; and
  3. c.Collect, validate, and verify identity evidence.
Official NIST discussion

Discussion

Identity proofing is the process of collecting, validating, and verifying a user’s identity information for the purposes of establishing credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Standards and guidelines specifying identity assurance levels for identity proofing include [SP 800-63-3](#737513fa-6758-403f-831d-5ddab5e23cb3) and [SP 800-63A](#9099ed2c-922a-493d-bcb4-d896192243ff) . Organizations may be subject to laws, executive orders, directives, regulations, or policies that address the collection of identity evidence. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Identity Proofing as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity proofing, authentication strength, credential lifecycle, and trusted identity assertions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • identity-proofing records
  • authenticator issuance and revocation logs
  • MFA and federation configuration
  • credential inventory and rotation evidence

Common failure patterns

  • strong authentication applied only to interactive users
  • service credentials without ownership or rotation
  • weak recovery paths that bypass MFA
  • federated trust not reviewed after partner changes

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. IA-12a.users who require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines are identity proofed;
  2. IA-12b.user identities are resolved to a unique individual;
  3. IA-12c.
    1. IA-12c.[01]identity evidence is collected;
    2. IA-12c.[02]identity evidence is validated;
    3. IA-12c.[03]identity evidence is verified.

Examine

  • Identification and authentication policy
  • procedures addressing identity proofing
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with system operations responsibilities
  • organizational personnel with information security and privacy responsibilities
  • legal counsel
  • system/network administrators
  • system developers
  • organizational personnel with identification and authentication responsibilities

Test

  • Mechanisms supporting and/or implementing identification and authentication capabilities
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-172 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

IA-12(1) — Supervisor Authorization

Require that the registration process to receive an account for logical access includes supervisor or sponsor authorization.

Official discussion

Including supervisor or sponsor authorization as part of the registration process provides an additional level of scrutiny to ensure that the user’s management chain is aware of the account, the account is essential to carry out organizational missions and functions, and the user’s privileges are appropriate for the anticipated responsibilities and authorities within the organization.

Assessment objectives and methods

the registration process to receive an account for logical access includes supervisor or sponsor authorization.

Examine

  • Identification and authentication policy
  • procedures addressing identity proofing
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system operations responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • organizational personnel with identification and authentication responsibilities

Test

  • Mechanisms supporting and/or implementing identification and authentication capabilities
Official NIST control enhancement

IA-12(2) — Identity Evidence

ModerateHigh

Require evidence of individual identification be presented to the registration authority.

Official discussion

Identity evidence, such as documentary evidence or a combination of documents and biometrics, reduces the likelihood of individuals using fraudulent identification to establish an identity or at least increases the work factor of potential adversaries. The forms of acceptable evidence are consistent with the risks to the systems, roles, and privileges associated with the user’s account.

Assessment objectives and methods

evidence of individual identification is presented to the registration authority.

Examine

  • Identification and authentication policy
  • procedures addressing identity proofing
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system operations responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • organizational personnel with identification and authentication responsibilities

Test

  • Mechanisms supporting and/or implementing identification and authentication capabilities
Official NIST control enhancement

IA-12(3) — Identity Evidence Validation and Verification

ModerateHigh

Require that the presented identity evidence be validated and verified through [Organization-defined: methods of validation and verification].

Official discussion

Validation and verification of identity evidence increases the assurance that accounts and identifiers are being established for the correct user and authenticators are being bound to that user. Validation refers to the process of confirming that the evidence is genuine and authentic, and the data contained in the evidence is correct, current, and related to an individual. Verification confirms and establishes a linkage between the claimed identity and the actual existence of the user presenting the evidence. Acceptable methods for validating and verifying identity evidence are consistent with the risks to the systems, roles, and privileges associated with the users account.

Organization-defined parameters (1)
methods of validation and verificationmethods of validation and verification of identity evidence are defined;
Assessment objectives and methods

the presented identity evidence is validated and verified through [Organization-defined: methods of validation and verification].

Examine

  • Identification and authentication policy
  • procedures addressing identity proofing
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system operations responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • organizational personnel with identification and authentication responsibilities

Test

  • Mechanisms supporting and/or implementing identification and authentication capabilities
Official NIST control enhancement

IA-12(4) — In-person Validation and Verification

High

Require that the validation and verification of identity evidence be conducted in person before a designated registration authority.

Official discussion

In-person proofing reduces the likelihood of fraudulent credentials being issued because it requires the physical presence of individuals, the presentation of physical identity documents, and actual face-to-face interactions with designated registration authorities.

Assessment objectives and methods

the validation and verification of identity evidence is conducted in person before a designated registration authority.

Examine

  • Identification and authentication policy
  • procedures addressing identity proofing
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system operations responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • organizational personnel with identification and authentication responsibilities

Test

  • Mechanisms supporting and/or implementing identification and authentication capabilities
Official NIST control enhancement

IA-12(5) — Address Confirmation

ModerateHigh

Require that a [Organization-defined: ia-12.05_odp] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.

Official discussion

To make it more difficult for adversaries to pose as legitimate users during the identity proofing process, organizations can use out-of-band methods to ensure that the individual associated with an address of record is the same individual that participated in the registration. Confirmation can take the form of a temporary enrollment code or a notice of proofing. The delivery address for these artifacts is obtained from records and not self-asserted by the user. The address can include a physical or digital address. A home address is an example of a physical address. Email addresses and telephone numbers are examples of digital addresses.

Organization-defined parameters (1)
ia-12.05_odp
Assessment objectives and methods

a [Organization-defined: ia-12.05_odp] is delivered through an out-of-band channel to verify the user’s address (physical or digital) of record.

Examine

  • Identification and authentication policy
  • procedures addressing identity proofing
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system operations responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • organizational personnel with identification and authentication responsibilities

Test

  • Mechanisms supporting and/or implementing identification and authentication capabilities
Related controls
Official NIST control enhancement

IA-12(6) — Accept Externally-proofed Identities

Accept externally-proofed identities at [Organization-defined: identity assurance level].

Official discussion

To limit unnecessary re-proofing of identities, particularly of non-PIV users, organizations accept proofing conducted at a commensurate level of assurance by other agencies or organizations. Proofing is consistent with organizational security policy and the identity assurance level appropriate for the system, application, or information accessed. Accepting externally-proofed identities is a fundamental component of managing federated identities across agencies and organizations.

Organization-defined parameters (1)
identity assurance levelan identity assurance level for accepting externally proofed identities is defined;
Assessment objectives and methods

externally proofed identities are accepted [Organization-defined: identity assurance level].

Examine

  • Identification and authentication policy
  • procedures addressing identity proofing
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with system operations responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • organizational personnel with identification and authentication responsibilities

Test

  • Mechanisms supporting and/or implementing identification and authentication capabilities
Related controls
Source record

Authoritative sources