Rule ID
SV-288149r1252655_rule
Version
V1R0.1
In the context of authentication, an assertion is a verifiable statement from an Identity Provider (IdP) to a Relying Party (RP) that contains information about an end-user, including their authentication status and other relevant details. An assertion is essentially a message or document that the IdP (like a website or service that handles logins) sends to the RP (the application or service the user is trying to access) to confirm that a user has been authenticated. Assertions typically include information about: - User identity: The user's name, email, or other identifying attributes. - Authentication status: Whether the user has successfully logged in and the method used (e.g., password, multifactor authentication [MFA]). - Time of authentication: When the user was authenticated. - Attributes: Other relevant user data, like roles, permissions, or department affiliations.
Review the application documentation and deployed configuration to determine whether the application issues assertions in accordance with organization-defined identification and authentication policy. If the application does not issue assertions in accordance with organization-defined identification and authentication policy, this is a finding.
Configure the application to issue assertions in accordance with organization-defined identification and authentication policy.