manage.get.gov/docs/compliance/dist/system-security-plans/ato/ia-12.5.md
Logan McDonald 1d3dfdb8d5
Add compliance documentation to source control (#116)
* add initial setup of compliance-trestle
2022-09-14 08:46:43 -04:00

1.4 KiB
Raw Blame History

implementation-status control-origination
c-not-implemented
c-inherited-cloud-gov
c-inherited-cisa
c-common-control
c-system-specific-control

ia-12.5 - [catalog] Address Confirmation

Control Statement

Require that a No value found be delivered through an out-of-band channel to verify the users address (physical or digital) of record.

Control guidance

To make it more difficult for adversaries to pose as legitimate users during the identity proofing process, organizations can use out-of-band methods to ensure that the individual associated with an address of record is the same individual that participated in the registration. Confirmation can take the form of a temporary enrollment code or a notice of proofing. The delivery address for these artifacts is obtained from records and not self-asserted by the user. The address can include a physical or digital address. A home address is an example of a physical address. Email addresses and telephone numbers are examples of digital addresses.

Control assessment-objective

a No value found is delivered through an out-of-band channel to verify the users address (physical or digital) of record.


What is the solution and how is it implemented?

Add control implementation description here for control ia-12.5