STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← IA-13 (02) — Identification and Authentication

CCI-005157

Definition

The private keys used to sign assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.

Parent Control

IA-13 (02)Identification and AuthenticationIdentification and Authentication

Linked STIG Checks (4)

V-274840CAT IIThe API must protect the private keys used to sign assertions and tokens.Application Programming Interface (API) Security Requirements GuideV-283928CAT IFly Server must use an approved DoW enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users.AvePoint Fly Server Security Technical Implementation GuideV-278410CAT IINGINX must generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.F5 NGINX Security Technical Implementation GuideV-288147CAT IIThe application must protect the private keys used to sign assertions and tokens commensurate with the impact of the system and information resources that can be accessed.General Application (GAPP) Security Requirements Guide