Check: APSC-DV-001900
Application Security and Development STIG:
APSC-DV-001900
(in versions v5 r3 through v4 r2)
Title
The application must accept FICAM-approved third-party credentials. (Cat II impact)
Discussion
FICAM establishes a federated identity framework for the Federal Government. FICAM provides Government-wide services for common Identity, Credential and Access Management (ICAM) requirements. The FICAM Trust Framework Solutions (TFS) is the federated identity framework for the U.S. federal government. The TFS is a process by which Industry Trust Frameworks (The codification of requirements for credentials and their issuance, privacy and security requirements, as well as auditing qualifications and processes) are evaluated and assessed for potential use by the Government. A Trust Framework that is comparable to federal standards is adopted through this process, which allows Federal Government Relying Parties (Federal Government web sites or RP's) to trust Credential Service Providers a.k.a. Identity Providers that have been assessed under that particular trust framework. This allows federal government relying parties to trust such credentials at their approved assurance levels. This requirement only applies to applications that are intended to be accessible to non-federal government agencies and other partners through FICAM. Third-party credentials are those credentials issued by non-federal government entities approved by the Federal Identity, Credential, and Access Management (FICAM) Trust Framework Solutions initiative.
Check Content
Review the application documentation and interview the application administrator to identify application access methods. If the application is not PK-enabled due to the hosted data being publicly releasable, this check is not applicable. If the application is only deployed to SIPRNet, this requirement is not applicable. If the application is not intended to be available to Federal government partners this requirement is not applicable. Ask the application administrator to demonstrate how the application is configured to allow the use of third-party credentials, verify the third-party credentials are FICAM approved. If the application does not accept FICAM approved credentials when accepting third-party credentials, this is a finding.
Fix Text
Configure applications intended to be accessible to non-federal government agencies to use FICAM-approved third-party credentials.
Additional Identifiers
Rule ID: SV-222559r879777_rule
Vulnerability ID: V-222559
Group Title: SRG-APP-000404
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002011 |
The information system accepts FICAM-approved third-party credentials. |
Controls
Number | Title |
---|---|
IA-8 (2) |
Acceptance Of Third-Party Credentials |