STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

IA-8

Identification and AuthenticationRev 5system

Identification and Authentication (Non-Organizational Users)

Baselines:LowModerateHigh

Control Statement

Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.

Supplemental Guidance

Non-organizational users include system users other than organizational users explicitly covered by [IA-2](#ia-2) . Non-organizational users are uniquely identified and authenticated for accesses other than those explicitly identified and documented in [AC-14](#ac-14) . Identification and authentication of non-organizational users accessing federal systems may be required to protect federal, proprietary, or privacy-related information (with exceptions noted for national security systems). Organizations consider many factors—including security, privacy, scalability, and practicality—when balancing the need to ensure ease of use for access to federal information and systems with the need to protect and adequately mitigate risk.

Related Controls (16)

AC-2AC-6AC-14AC-17AC-18AU-6IA-2IA-4IA-5IA-10IA-11IA-13MA-4RA-3SA-4SC-8

CCI Identifiers (1)

CCI-000804Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.

Linked STIG Checks (89)

Across 80 STIGs. Click to expand.