Identity Proofing

LOW ✓ MODERATE ✓ HIGH
6 Enhancements 1 Overlay 9 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Identity proofing is the process of collecting, validating, and verifying a user’s identity information for the purposes of establishing credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Standards and guidelines specifying identity assurance levels for identity proofing include SP 800-63-3 and SP 800-63A . Organizations may be subject to laws, executive orders, directives, regulations, or policies that address the collection of identity evidence. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

Enhancements NIST SOURCE

IA-12(1) Supervisor Authorization LOW MODERATE HIGH

Require that the registration process to receive an account for logical access includes supervisor or sponsor authorization.

Discussion

Including supervisor or sponsor authorization as part of the registration process provides an additional level of scrutiny to ensure that the user’s management chain is aware of the account, the account is essential to carry out organizational missions and functions, and the user’s privileges are appropriate for the anticipated responsibilities and authorities within the organization.

Open full page for IA-12(1) →
IA-12(2) Identity Evidence LOW ✓ MODERATE ✓ HIGH

Require evidence of individual identification be presented to the registration authority.

Discussion

Identity evidence, such as documentary evidence or a combination of documents and biometrics, reduces the likelihood of individuals using fraudulent identification to establish an identity or at least increases the work factor of potential adversaries. The forms of acceptable evidence are consistent with the risks to the systems, roles, and privileges associated with the user’s account.

Open full page for IA-12(2) →
IA-12(3) Identity Evidence Validation and Verification LOW ✓ MODERATE ✓ HIGH

Require that the presented identity evidence be validated and verified through [methods of validation and verification].

Discussion

Validation and verification of identity evidence increases the assurance that accounts and identifiers are being established for the correct user and authenticators are being bound to that user. Validation refers to the process of confirming that the evidence is genuine and authentic, and the data contained in the evidence is correct, current, and related to an individual. Verification confirms and establishes a linkage between the claimed identity and the actual existence of the user presenting the evidence. Acceptable methods for validating and verifying identity evidence are consistent with the risks to the systems, roles, and privileges associated with the users account.

Open full page for IA-12(3) →
IA-12(4) In-person Validation and Verification LOW MODERATE ✓ HIGH

Require that the validation and verification of identity evidence be conducted in person before a designated registration authority.

Discussion

In-person proofing reduces the likelihood of fraudulent credentials being issued because it requires the physical presence of individuals, the presentation of physical identity documents, and actual face-to-face interactions with designated registration authorities.

Open full page for IA-12(4) →
IA-12(5) Address Confirmation LOW ✓ MODERATE ✓ HIGH

Require that a [one of: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.

Discussion

To make it more difficult for adversaries to pose as legitimate users during the identity proofing process, organizations can use out-of-band methods to ensure that the individual associated with an address of record is the same individual that participated in the registration. Confirmation can take the form of a temporary enrollment code or a notice of proofing. The delivery address for these artifacts is obtained from records and not self-asserted by the user. The address can include a physical or digital address. A home address is an example of a physical address. Email addresses and telephone numbers are examples of digital addresses.

Open full page for IA-12(5) →
IA-12(6) Accept Externally-proofed Identities LOW MODERATE HIGH

Accept externally-proofed identities at [identity assurance level].

Discussion

To limit unnecessary re-proofing of identities, particularly of non-PIV users, organizations accept proofing conducted at a commensurate level of assurance by other agencies or organizations. Proofing is consistent with organizational security policy and the identity assurance level appropriate for the system, application, or information accessed. Accepting externally-proofed identities is a fundamental component of managing federated identities across agencies and organizations.

Open full page for IA-12(6) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for IA-12 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. users who require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines are identity proofed;
  2. user identities are resolved to a unique individual;
  3. identity evidence is collected;
  4. identity evidence is validated;
  5. identity evidence is verified.

Examine

[SELECT FROM: Identification and authentication policy; procedures addressing identity proofing; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with system operations responsibilities; organizational personnel with information security and privacy responsibilities; legal counsel; system/network administrators; system developers; organizational personnel with identification and authentication responsibilities].

Test

[SELECT FROM: Mechanisms supporting and/or implementing identification and authentication capabilities].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Not applicable at this tier.

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (2) (3) (5)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (2) (3) (4) (5)
  • Added: (1)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for IA-12. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Identification and authentication policy
  • system security plan
  • privacy plan

Testing

  • Mechanisms supporting and/or implementing identification and authentication capabilities

Other Records

  • procedures addressing identity proofing
  • other relevant documents or records