Identity Provider
What is Identity Provider?
A service that creates, maintains, and manages identity information and provides authentication services to applications in a federated or SSO environment.
Terms that appear alongside identity provider
Each of these is named in at least one of the same controls as identity provider. The number is how many controls name both.
- threat intelligence 3 shared controls
- nist 3 shared controls
- audit 3 shared controls
- authorization 2 shared controls
- key management 2 shared controls
- tls 2 shared controls
- policy 2 shared controls
- authentication 2 shared controls
Frameworks that govern identity provider
What the standards actually require on identity provider
Requirements naming identity provider across 6 standards, quoted from the control text.
Federate workforce access to AWS through a single corporate identity provider via IAM Identity Center or SAML so that user lifecycle, MFA and access reviews are centrally governed.
SEC02-BP04 · Rely on a centralized identity provider →Identity Providers and Authorization Servers. Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance...
NIST800-IA-13 · Identity Providers and Authorization Servers. Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance with [organization-defined] using →Security Layer 2 Services per X.805 Clause 7.2: The Services Security Layer is concerned with security of network services that service providers offer to their customers - encompasses the protection of the basic network connectivity services + supplementary v...
X805-Layer2-Services-Security-Frame-Relay-ATM-IP-VoIP-QoS-Toll-Free-IM-VPN-AAA-DNS · ITU-T X.805 Security Layer 2 - Services Security + Frame Relay + ATM + IP + VoIP + QoS + Toll-Free + Instant Messaging + VPN + AAA Authentication-Authorization-Accounting + DNS + IMS + 5G + Cellular Mobile Voice + SMS →Select and apply appropriate ATT&CK matrix for target environment. ATT&CK FOR ENTERPRISE primary matrix covers Windows + macOS + Linux + Office Suite + IaaS + SaaS + Identity Provider + Network platforms.
MITRE-ATTACK-Matrices-Enterprise-Mobile-ICS-Cloud-AWS-Azure-Google-Office-365-Container-Platform-Specific · MITRE ATT&CK Matrices + Enterprise + Mobile + ICS + Cloud + AWS + Azure + Google + Office 365 + Container →ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Info...
ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities · ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities →Disclose and operate authentication and authorization features per MDS2 PAUT + NAUT + AUTH sections. Person Authentication (PAUT) including user identification + password complexity + MFA support + biometric authentication + smart-card support + LDAP/Active Di...
MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT · MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management →Questions people ask about identity provider
What is Identity Provider?
Why is Identity Provider important for compliance?
Which compliance frameworks address Identity Provider?
Where can I learn more about Identity Provider?
See how Identity Provider applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.