Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-222559 | APSC-DV-001900 | SV-222559r985967_rule | Medium |
Description |
---|
FICAM establishes a federated identity framework for the federal government. FICAM provides government-wide services for common Identity, Credential and Access Management (ICAM) requirements. The FICAM Trust Framework Solutions (TFS) is the federated identity framework for the U.S. federal government. The TFS is a process by which Industry Trust Frameworks (The codification of requirements for credentials and their issuance, privacy and security requirements, as well as auditing qualifications and processes) are evaluated and assessed for potential use by the government. A Trust Framework that is comparable to federal standards is adopted through this process, which allows federal government Relying Parties (Federal Government websites or RP's) to trust Credential Service Providers (a.k.a. Identity Providers) that have been assessed under that particular trust framework. This allows federal government relying parties to trust such credentials at their approved assurance levels. This requirement only applies to applications that are intended to be accessible to nonfederal government agencies and other partners through FICAM. Third-party credentials are those credentials issued by nonfederal government entities approved by the FICAM TFS initiative. |
STIG | Date |
---|---|
Application Security and Development Security Technical Implementation Guide | 2024-06-05 |
Check Text ( C-24229r985965_chk ) |
---|
Review the application documentation and interview the application administrator to identify application access methods. If the application is not PKI-enabled due to the hosted data being publicly releasable, this check is Not Applicable. If the application is only deployed to SIPRNet, this requirement is Not Applicable. If the application is not intended to be available to federal government partners this requirement is Not Applicable. Ask the application administrator to demonstrate how the application is configured to allow the use of third-party credentials, verify the third-party credentials are FICAM approved. If the application does not accept FICAM-approved credentials when accepting third-party credentials, this is a finding. |
Fix Text (F-24218r985966_fix) |
---|
Configure applications intended to be accessible to nonfederal government agencies to use FICAM-approved third-party credentials. |