Single Sign-On
What is Single Sign-On?
An authentication scheme that allows users to access multiple applications and services with one set of login credentials, improving user experience and security.
Terms that appear alongside single sign-on
Each of these is named in at least one of the same controls as single sign-on. The number is how many controls name both.
- single sign on sso 5 shared controls
- oauth 4 shared controls
- saml 4 shared controls
- nist 4 shared controls
- authentication 4 shared controls
- zero trust 3 shared controls
- role based access control 3 shared controls
- privileged access management pam 3 shared controls
Frameworks that govern single sign-on
What the standards actually require on single sign-on
Requirements naming single sign-on across 6 standards, quoted from the control text.
Use single sign-on so users authenticate once to reach applications and data across cloud and on-premises environments rather than maintaining separate credentials per application.
ASBv3-IM-5 · Use single sign-on (SSO) for application access →Federation and single sign-on. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Identity & Access in Cloud.
NIST190-09 · Federation and single sign-on →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control.
JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication · Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security →Implement Asset Management + Identity and Access Management + Cryptography per MTCS SS 584. Asset Management (ISO 27001 Annex A.8 alignment) - asset inventory (hardware + software + data + virtual + container + serverless) + asset classification + asset owners...
MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe · MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe →Questions people ask about single sign-on
What is Single Sign-On?
Why is Single Sign-On important for compliance?
Which compliance frameworks address Single Sign-On?
Where can I learn more about Single Sign-On?
See how Single Sign-On applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.