Single Sign-On (SSO)
What is Single Sign-On (SSO)?
An authentication scheme that allows a user to log in with a single set of credentials to access multiple, independent software systems. SSO improves user experience while centralising authentication control.
Terms that appear alongside single sign-on (sso)
Each of these is named in at least one of the same controls as single sign-on (sso). The number is how many controls name both.
- single sign on 5 shared controls
- oauth 4 shared controls
- saml 4 shared controls
- authentication 4 shared controls
- zero trust 3 shared controls
- role based access control 3 shared controls
- privileged access management pam 3 shared controls
- multi factor authentication 3 shared controls
Frameworks that govern single sign-on (sso)
What the standards actually require on single sign-on (sso)
Requirements naming single sign-on (sso) across 6 standards, quoted from the control text.
Use single sign-on so users authenticate once to reach applications and data across cloud and on-premises environments rather than maintaining separate credentials per application.
ASBv3-IM-5 · Use single sign-on (SSO) for application access →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Identity and Access Management (IAM) is a critical control area per FSA Cybersecurity Guidelines + intersects with FISC Security Guidelines + Japan Banking Customer Authentication Standards + APPI access control.
JP-FSA-CYB-Identity-Access-Management-Privileged-Access-MFA-Zero-Trust-Just-In-Time-Banking-Customer-Authentication · Japan FSA Cybersecurity Identity and Access Management + Privileged Access + MFA + Zero Trust + Just-In-Time + Banking Customer Authentication + Risk-Based Authentication + Out-of-Band + Biometric + FIDO2 + Internet Banking Security →Implement Asset Management + Identity and Access Management + Cryptography per MTCS SS 584. Asset Management (ISO 27001 Annex A.8 alignment) - asset inventory (hardware + software + data + virtual + container + serverless) + asset classification + asset owners...
MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe · MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe →Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with IdP (Azure AD + Okta + Auth0 + Ping + ForgeRock + AWS IAM Identity Center) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign...
NISTSP144-5 · Identity and Access in Cloud, Federation, and Privileged Access →Questions people ask about single sign-on (sso)
What is Single Sign-On (SSO)?
Why is Single Sign-On (SSO) important for compliance?
Which compliance frameworks address Single Sign-On (SSO)?
Where can I learn more about Single Sign-On (SSO)?
See how Single Sign-On (SSO) applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.