|IA-9 (1) Information Exchange || |
The organization ensures that service providers receive, validate, and transmit identification and authentication information.
|IA-9 (2) Transmission Of Decisions || |
For distributed architectures (e.g., service-oriented architectures), the decisions regarding the validation of identification and authentication claims may be made by services separate from the services acting on those decisions. In such situations, it is necessary to provide the identification and authentication decisions (as opposed to the actual identifiers and authenticators) to the services that need to act on those decisions.
The organization ensures that identification and authentication decisions are transmitted between Assignment: organization-defined services consistent with organizational policies.