CCI-005159
CCI-005159 Definition
| Status | |
| Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
​Determine if:-- assertions are issued in accordance with[IA-13(03)_ODP; identification and authentication policy is defined]; and- access tokens are issued in accordance with [IA-13(03)_ODP; identification and authentication policy is defined].
Validation Procedures
Examine: [SELECT FROM: Identification and authentication policy; access control policy; procedures for assertion and token management; system design documentation; system configuration settings and associated documentation; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system operations responsibilities; organizational personnel with information security responsibilities; system/ network administrators; organizational personnel with account management responsibilities; system developers]. Test: [SELECT FROM: Mechanisms and software supporting and/or implementing token generation].