STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← IA-13 (02) — Identification and Authentication

CCI-005157

Definition

The private keys used to sign assertions and tokens are protected commensurate with the impact of the system and information resources that can be accessed.

Parent Control

IA-13 (02)Identification and AuthenticationIdentification and Authentication

Linked STIG Checks (2)

V-274840CAT IIThe API must protect the private keys used to sign assertions and tokens.Application Programming Interface (API) Security Requirements GuideV-278410CAT IINGINX must generate, manage, and protect from disclosure and misuse the cryptographic keys that protect access tokens.F5 NGINX Security Technical Implementation Guide