Skip to content

IA-1: Policy and Procedures

An OSCAL Control

    • personnel or roles

      personnel or roles to whom the identification and authentication policy is to be disseminated are defined;

    • personnel or roles

      personnel or roles to whom the identification and authentication procedures are to be disseminated is/are defined;

    • official

      an official to manage the identification and authentication policy and procedures is defined;

    • frequency

      the frequency at which the current identification and authentication policy is reviewed and updated is defined;

    • events

      events that would require the current identification and authentication policy to be reviewed and updated are defined;

    • frequency

      the frequency at which the current identification and authentication procedures are reviewed and updated is defined;

    • events

      events that would require identification and authentication procedures to be reviewed and updated are defined;