CCI-005168
CCI-005168 Definition
| Status | |
| Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
Determine if:- assertions are time-restricted in accordance with IA-13(03)_ODP policy; and- access tokens are time-restricted in accordance with IA-13(03)_ODP policy;
Validation Procedures
Examine: [SELECT FROM: Identification and authentication policy; access control policy; procedures for assertion and token management; system design documentation; system configuration settings and associated documentation; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system operations responsibilities; organizational personnel with information security responsibilities; system/ network administrators; organizational personnel with account management responsibilities; system developers]. Test: [SELECT FROM: Mechanisms and software supporting and/or implementing token generation].