Skip to main content

πŸ’Ό IA-1 Policy and Procedures (L)(M)(H)

  • Contextual name: πŸ’Ό IA-1 Policy and Procedures (L)(M)(H)
  • ID: /frameworks/fedramp-high-security-controls/ia/01
  • Located in: πŸ’Ό Identification and Authentication

Description​

a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:

  1. [Selection (one-or-more): organization-level; mission/business process-level; system-level] identification and authentication policy that:

    (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

    (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and

  2. Procedures to facilitate the implementation of the identification and authentication policy and the associated identification and authentication controls;

b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the identification and authentication policy and procedures; and

c. Review and update the current identification and authentication:

  1. Policy [FedRAMP Assignment: at least every 3 years] and following [Assignment: organization-defined events]; and

  2. Procedures [FedRAMP Assignment: at least annually] and following [FedRAMP Assignment: significant changes].

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/ia/01
  • Internal
    • ID: dec-c-4561d464

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό IA-1 Policy and Procedures

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό IA-1 Policy and Procedures (L)(M)(H)
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό IA-1 Policy and Procedures (L)(M)(H)

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags