Control statement
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Discussion
Non-organizational users include system users other than organizational users explicitly covered by [IA-2](#ia-2) . Non-organizational users are uniquely identified and authenticated for accesses other than those explicitly identified and documented in [AC-14](#ac-14) . Identification and authentication of non-organizational users accessing federal systems may be required to protect federal, proprietary, or privacy-related information (with exceptions noted for national security systems). Organizations consider many factors—including security, privacy, scalability, and practicality—when balancing the need to ensure ease of use for access to federal information and systems with the need to protect and adequately mitigate risk.
From control text to operational evidence
Use Identification and Authentication (Non-organizational Users) as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity proofing, authentication strength, credential lifecycle, and trusted identity assertions.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- identity-proofing records
- authenticator issuance and revocation logs
- MFA and federation configuration
- credential inventory and rotation evidence
Common failure patterns
- strong authentication applied only to interactive users
- service credentials without ownership or rotation
- weak recovery paths that bypass MFA
- federated trust not reviewed after partner changes
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
non-organizational users or processes acting on behalf of non-organizational users are uniquely identified and authenticated.
Examine
- Identification and authentication policy
- system security plan
- privacy plan
- procedures addressing user identification and authentication
- system design documentation
- system configuration settings and associated documentation
- system audit records
- list of system accounts
- other relevant documents or records
Interview
- Organizational personnel with system operations responsibilities
- organizational personnel with information security and privacy responsibilities
- system/network administrators
- organizational personnel with account management responsibilities
Test
- Mechanisms supporting and/or implementing identification and authentication capabilities
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
IA-8(1) — Acceptance of PIV Credentials from Other Agencies
Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
Official discussion
Acceptance of Personal Identity Verification (PIV) credentials from other federal agencies applies to both logical and physical access control systems. PIV credentials are those credentials issued by federal agencies that conform to FIPS Publication 201 and supporting guidelines. The adequacy and reliability of PIV card issuers are addressed and authorized using [SP 800-79-2](#10963761-58fc-4b20-b3d6-b44a54daba03).
Assessment objectives and methods
- IA-08(01)[01]Personal Identity Verification-compliant credentials from other federal agencies are accepted;
- IA-08(01)[02]Personal Identity Verification-compliant credentials from other federal agencies are electronically verified.
Examine
- Identification and authentication policy
- system security plan
- procedures addressing user identification and authentication
- system design documentation
- system configuration settings and associated documentation
- system audit records
- PIV verification records
- evidence of PIV credentials
- PIV credential authorizations
- other relevant documents or records
Interview
- Organizational personnel with system operations responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- organizational personnel with account management responsibilities
Test
- Mechanisms supporting and/or implementing identification and authentication capabilities
- mechanisms that accept and verify PIV credentials
Related controls
IA-8(2) — Acceptance of External Authenticators
- (a)Accept only external authenticators that are NIST-compliant; and
- (b)Document and maintain a list of accepted external authenticators.
Official discussion
Acceptance of only NIST-compliant external authenticators applies to organizational systems that are accessible to the public (e.g., public-facing websites). External authenticators are issued by nonfederal government entities and are compliant with [SP 800-63B](#e59c5a7c-8b1f-49ca-8de0-6ee0882180ce) . Approved external authenticators meet or exceed the minimum Federal Government-wide technical, security, privacy, and organizational maturity requirements. Meeting or exceeding Federal requirements allows Federal Government relying parties to trust external authenticators in connection with an authentication transaction at a specified authenticator assurance level.
Assessment objectives and methods
- IA-08(02)(a)only external authenticators that are NIST-compliant are accepted;
- IA-08(02)(b)
- IA-08(02)(b)[01]a list of accepted external authenticators is documented;
- IA-08(02)(b)[02]a list of accepted external authenticators is maintained.
Examine
- Identification and authentication policy
- system security plan
- procedures addressing user identification and authentication
- system design documentation
- system configuration settings and associated documentation
- system audit records
- list of third-party credentialing products, components, or services procured and implemented by organization
- third-party credential verification records
- evidence of third-party credentials
- third-party credential authorizations
- other relevant documents or records
Interview
- Organizational personnel with system operations responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- organizational personnel with account management responsibilities
Test
- Mechanisms supporting and/or implementing identification and authentication capabilities
- mechanisms that accept external credentials
IA-8(3) — Use of FICAM-approved Products
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
IA-8(4) — Use of Defined Profiles
Conform to the following profiles for identity management [Organization-defined: identity management profiles].
Official discussion
Organizations define profiles for identity management based on open identity management standards. To ensure that open identity management standards are viable, robust, reliable, sustainable, and interoperable as documented, the Federal Government assesses and scopes the standards and technology implementations against applicable laws, executive orders, directives, policies, regulations, standards, and guidelines.
Organization-defined parameters (1)
Assessment objectives and methods
there is conformance with [Organization-defined: identity management profiles] for identity management.
Examine
- Identification and authentication policy
- system security plan
- system design documentation
- system configuration settings and associated documentation
- system audit records
- other relevant documents or records
Interview
- Organizational personnel with system operations responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- organizational personnel with account management responsibilities
Test
- Mechanisms supporting and/or implementing identification and authentication capabilities
- mechanisms supporting and/or implementing conformance with profiles
IA-8(5) — Acceptance of PIV-I Credentials
Accept and verify federated or PKI credentials that meet [Organization-defined: policy].
Official discussion
Acceptance of PIV-I credentials can be implemented by PIV, PIV-I, and other commercial or external identity providers. The acceptance and verification of PIV-I-compliant credentials apply to both logical and physical access control systems. The acceptance and verification of PIV-I credentials address nonfederal issuers of identity cards that desire to interoperate with United States Government PIV systems and that can be trusted by Federal Government-relying parties. The X.509 certificate policy for the Federal Bridge Certification Authority (FBCA) addresses PIV-I requirements. The PIV-I card is commensurate with the PIV credentials as defined in cited references. PIV-I credentials are the credentials issued by a PIV-I provider whose PIV-I certificate policy maps to the Federal Bridge PIV-I Certificate Policy. A PIV-I provider is cross-certified with the FBCA (directly or through another PKI bridge) with policies that have been mapped and approved as meeting the requirements of the PIV-I policies defined in the FBCA certificate policy.
Organization-defined parameters (1)
Assessment objectives and methods
- IA-08(05)[01]federated or PKI credentials that meet [Organization-defined: policy] are accepted;
- IA-08(05)[02]federated or PKI credentials that meet [Organization-defined: policy] are verified.
Examine
- Identification and authentication policy
- system security plan
- procedures addressing user identification and authentication
- system design documentation
- system configuration settings and associated documentation
- system audit records
- PIV-I verification records
- evidence of PIV-I credentials
- PIV-I credential authorizations
- other relevant documents or records
Interview
- Organizational personnel with system operations responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- organizational personnel with account management responsibilities
Test
- Mechanisms supporting and/or implementing identification and authentication capabilities
- mechanisms that accept and verify PIV-I credentials
IA-8(6) — Disassociability
Implement the following measures to disassociate user attributes or identifier assertion relationships among individuals, credential service providers, and relying parties: [Organization-defined: measures].
Official discussion
Federated identity solutions can create increased privacy risks due to the tracking and profiling of individuals. Using identifier mapping tables or cryptographic techniques to blind credential service providers and relying parties from each other or to make identity attributes less visible to transmitting parties can reduce these privacy risks.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: measures] to disassociate user attributes or identifier assertion relationships among individuals, credential service providers, and relying parties are implemented.
Examine
- Identification and authentication policy
- system security plan
- privacy plan
- procedures addressing user identification and authentication
- system design documentation
- system configuration settings and associated documentation
- system audit records
- other relevant documents or records
Interview
- Organizational personnel with system operations responsibilities
- organizational personnel with information security and privacy responsibilities
- system/network administrators
- system developers
- organizational personnel with account management responsibilities
Test
- Mechanisms supporting and/or implementing identification and authentication capabilities
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.