graphgrc

SCF - IAC-03 - Identification & Authentication for Non-Organizational Users

Mechanisms exist to uniquely identify and centrally Authenticate, Authorize and Audit (AAA) third-party users and processes that provide services to the organization.

Mapped framework controls

ISO 27002

NIST 800-53

SOC 2

Control questions

Does the organization uniquely identify and centrally Authenticate, Authorize and Audit (AAA) third-party users and processes that provide services to the organization?