# IA-12 Identity Proofing

NIST SP 800-53 control. Family: IA Identification and Authentication. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a unique individual; and c. Collect, validate, and verify identity evidence.
Guidance: Identity proofing is the process of collecting, validating, and verifying a user’s identity information for the purposes of establishing credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Standards and guidelines specifying identity assurance levels for identity proofing include [SP 800-63-3] and [SP 800-63A]. Organizations may be subject to laws, executive orders, directives, regulations, or policies that address the collection of identity evidence. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.

## Enhancements (6)
- IA-12(01) Supervisor Authorization
- IA-12(02) Identity Evidence. Baselines: moderate, high
- IA-12(03) Identity Evidence Validation and Verification. Baselines: moderate, high
- IA-12(04) In-person Validation and Verification. Baselines: high
- IA-12(05) Address Confirmation. Baselines: moderate, high
- IA-12(06) Accept Externally-proofed Identities
Each enhancement's statement: /api/v1/controls/IA-12?fields=enhancements

## Patterns that use it (6)
- Critical (2): SP-033 Passkey Authentication; SP-052 Decentralised Identity & Verifiable Credentials (draft)
- Important (3): SP-029 Zero Trust Architecture; SP-032 Modern Authentication; SP-044 SaaS Identity Lifecycle Management
- Standard (1): SP-050 Mobile Security Architecture (draft)

## Clauses by framework (43 frameworks)
- iso_27001_2022: A.5.16. OSA's own, not in NIST's crosswalk: A.5.16
- iso_27002_2022: 5.16
- cobit_2019: DSS05
- nist_csf_2: PR.AA-01, PR.AA-02. OSA's own, not in NIST's crosswalk: PR.AA-01
- mas_trm: 9
- bsi_grundschutz: ORP.4
- dora: Art.9(4)(d)
- bio2: 5.16
- rbi_csf: Annex1.9
- fisc: FISC.T2
- hkma_tme1: TME1.8.3
- dnb_good_practice: DNB.17.1
- cra: CRA.I.2d
- cbb_tm: TM-6
- cbuae: CR-4
- nca_ecc: 2-2
- qatar_nia: AC
- sama_csf: 3.1
- uae_ia: T9
- bog_cisd: CISD-IX
- bom_ctrm: 3.3
- cbe_csf: CTO-1
- cbn_csf: Part3.2
- sa_js2: JS2-7.1
- bot_cyber: Ch2.2
- cpmi_pfmi: CG.PR
- eba_ict: 3.4.2
- ecb_croe: CROE.2.3.1
- ffiec_is: II.C.7(b), II.C.15
- hipaa_sr: §164.312(d)
- iosco_cyber: PROT-1
- sebi_cscrf: PR.AA
- cmmc_2: IA
- doe_c2m2: ACCESS
- common_criteria: CC Part 2 — FIA
- fda_21_cfr_11: §11.100(b), §11.200(a)(3)
- fda_cyber: SA-1
- iso_27799: 9.3
- lloyds_ms: BP2.1, MS8.3
- nhs_dspt: NDG-4.3
- solvency_ii: EIOPA-ICT-4.4
- ccss_v9: 1.03.5, 1.04.4
- dpdpa: Act.9(1), Rules.10, Rules.11
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/IA-12
- Clauses only: /api/v1/controls/IA-12?fields=mappings
- Page for people: /controls/ia-12/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
