STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Application Security and Development Security Technical Implementation Guide

V-222559

CAT II (Medium)

The application must accept Federal Identity, Credential, and Access Management (FICAM)-approved third-party credentials.

Rule ID

SV-222559r1015708_rule

STIG

Application Security and Development Security Technical Implementation Guide

Version

V6R4

CCIs

CCI-004083CCI-002011

Discussion

FICAM establishes a federated identity framework for the federal government. FICAM provides government-wide services for common Identity, Credential and Access Management (ICAM) requirements. The FICAM Trust Framework Solutions (TFS) is the federated identity framework for the U.S. federal government. The TFS is a process by which Industry Trust Frameworks (The codification of requirements for credentials and their issuance, privacy and security requirements, as well as auditing qualifications and processes) are evaluated and assessed for potential use by the government. A Trust Framework that is comparable to federal standards is adopted through this process, which allows federal government Relying Parties (Federal Government websites or RP's) to trust Credential Service Providers (a.k.a. Identity Providers) that have been assessed under that particular trust framework. This allows federal government relying parties to trust such credentials at their approved assurance levels. This requirement only applies to applications that are intended to be accessible to nonfederal government agencies and other partners through FICAM. Third-party credentials are those credentials issued by nonfederal government entities approved by the FICAM TFS initiative.

Check Content

Review the application documentation and interview the application administrator to identify application access methods.

If the application is not PKI-enabled due to the hosted data being publicly releasable, this check is Not Applicable.

If the application is only deployed to SIPRNet, this requirement is Not Applicable.

If the application is not intended to be available to federal government partners this requirement is Not Applicable.

Ask the application administrator to demonstrate how the application is configured to allow the use of third-party credentials, verify the third-party credentials are FICAM approved.

If the application does not accept FICAM-approved credentials when accepting third-party credentials, this is a finding.

Fix Text

Configure applications intended to be accessible to nonfederal government agencies to use FICAM-approved third-party credentials.