SAML
What is SAML?
Security Assertion Markup Language, an XML-based standard for exchanging authentication and authorization data between identity providers and service providers.
Terms that appear alongside saml
Each of these is named in at least one of the same controls as saml. The number is how many controls name both.
- authentication 8 shared controls
- oauth 7 shared controls
- access control 7 shared controls
- multi factor authentication 6 shared controls
- nist 6 shared controls
- multi factor authentication mfa 6 shared controls
- zero trust 5 shared controls
- role based access control 5 shared controls
Frameworks that govern saml
What the standards actually require on saml
Requirements naming saml across 6 standards, quoted from the control text.
Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →Federate workforce access to AWS through a single corporate identity provider via IAM Identity Center or SAML so that user lifecycle, MFA and access reviews are centrally governed.
SEC02-BP04 · Rely on a centralized identity provider →HL7 FHIR Authentication. SMART APP LAUNCH IMPLEMENTATION GUIDE v2.2.0 - foundational FHIR-based OAuth 2.0 / OAuth 2.1 + OpenID Connect framework + standardised app authorization.
HL7-FHIR-Auth-SMART-OAuth-OIDC-Backend · HL7 FHIR Authentication - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services + Token Lifetime →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control.
JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication · Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security →Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles.
KNCF-Protect-Access-Control-IAM-Privileged-MFA-Zero-Trust-Identity-Lifecycle-IAG-PAM · Kuwait NCF Protect + Access Control + IAM + Privileged + MFA + Zero Trust + Identity Lifecycle →Questions people ask about saml
What is SAML?
Why is SAML important for compliance?
Which compliance frameworks address SAML?
Where can I learn more about SAML?
See how SAML applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.