Identity Terrain
The identity plane as ground: planes, credentials, assurance, assertions, authorization integrity
The organization shall identify on the terrain overlay every authoritative identity plane, the policy decision and enforcement points it operates, and the trust relationships between planes.
PurposeTo make identity positional, so that the plane controlling movement everywhere else is itself defensible ground rather than an assumed service.Activities10 · Metrics4Identities shall be proofed to a level commensurate with the access they confer, and bound to credentials whose strength matches that level.
PurposeTo ensure the credential is as strong as the access behind it, so that proofing and authentication assurance are matched rather than assumed.Activities10 · Metrics4Users, services and devices shall be authenticated at an assurance level commensurate with the terrain being accessed, and the assurance achieved shall be recorded with the authorization decision.
PurposeTo ensure authentication strength varies with what is being reached, and that the level achieved is available to the decision that relies on it.Activities10 · Metrics4Identity assertions, tokens and session material shall be protected against interception, replay and forgery, and their validity shall be bounded in time and scope.
PurposeTo prevent a valid authentication from becoming a durable, portable credential in an adversary's hands.Activities10 · Metrics4Authorization policy shall be enforced at a decision point that every access path consults, and changes to that policy shall be controlled, logged and reviewable.
PurposeTo ensure the policy that governs movement is actually consulted and cannot be altered without trace.Activities10 · Metrics4