Identity Federation
What is Identity Federation?
A system of trust between identity providers and service providers that allows users to authenticate once and access multiple systems across different organisations. Federation protocols include SAML, OAuth, and OpenID Connect.
Terms that appear alongside identity federation
Each of these is named in at least one of the same controls as identity federation. The number is how many controls name both.
- authorisation 3 shared controls
- authentication 3 shared controls
- just in time access 2 shared controls
- multi factor authentication 2 shared controls
- iso 27001 2 shared controls
- governance 2 shared controls
- access management 2 shared controls
- nist 2 shared controls
Frameworks that govern identity federation
What the standards actually require on identity federation
Requirements naming identity federation across 6 standards, quoted from the control text.
Provide enterprise identity federation and standardized user credentialing across DoD components.
DODZT-1.5 · Identity Federation and User Credentialing →Migrate identity federation, smart card credentials, and authentication tokens to CNSA 2.0 supported algorithms in coordination with relying parties.
QRMIG-12 · Identity Federation and Smart Cards →Replace long-lived IAM access keys with short-lived credentials issued via IAM roles, IAM Identity Center, STS or workload identity federation.
SEC02-BP02 · Use temporary credentials →Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control.
JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication · Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security →Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles.
KNCF-Protect-Access-Control-IAM-Privileged-MFA-Zero-Trust-Identity-Lifecycle-IAG-PAM · Kuwait NCF Protect + Access Control + IAM + Privileged + MFA + Zero Trust + Identity Lifecycle →Lloyds MS11.10 Third Party and Outsourcing Cyber Risk - comprehensive third-party risk management programme + PRA SS2/21 Outsourcing and Third Party Risk Management requirements + due diligence at onboarding + cyber security questionnaire (SIG + CAIQ + custom)...
LLOYDS-MS11-Third-Party-Outsourcing-Cyber-Risk-Cloud-Security-Data-Protection-Classification-MS11-10-14-11 · Lloyds MS11 Third Party + Cloud + Data Protection + Classification + MS11.10-14-11 →Questions people ask about identity federation
What is Identity Federation?
Why is Identity Federation important for compliance?
Which compliance frameworks address Identity Federation?
Where can I learn more about Identity Federation?
See how Identity Federation applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.