IA-12 Identity Proofing
Identification and Authentication
Description
a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a unique individual; and c. Collect, validate, and verify identity evidence.
Supplemental Guidance
Identity proofing is the process of collecting, validating, and verifying a user’s identity information for the purposes of establishing credentials for accessing a system. Identity proofing is intended to mitigate threats to the registration of users and the establishment of their accounts. Standards and guidelines specifying identity assurance levels for identity proofing include [SP 800-63-3] and [SP 800-63A]. Organizations may be subject to laws, executive orders, directives, regulations, or policies that address the collection of identity evidence. Organizational personnel consult with the senior agency official for privacy and legal counsel regarding such requirements.
Changes from Rev 4
New control in Rev 5.
Enhancements (6)
What NIST adds to this control. Select one to read its statement.
IA-12(01) Supervisor Authorization
Require that the registration process to receive an account for logical access includes supervisor or sponsor authorization.
IA-12(02) Identity Evidence ModerateHigh
Require evidence of individual identification be presented to the registration authority.
IA-12(03) Identity Evidence Validation and Verification ModerateHigh
Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification].
IA-12(04) In-person Validation and Verification High
Require that the validation and verification of identity evidence be conducted in person before a designated registration authority.
IA-12(05) Address Confirmation ModerateHigh
Require that a [Selection (one): registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record.
IA-12(06) Accept Externally-proofed Identities
Accept externally-proofed identities at [Assignment: organization-defined identity assurance level].
Patterns that use this control (6)
Grouped by the emphasis each pattern gives it.
MITRE ATT&CK Techniques (4)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.