Control Packs · IDN-005 · v1.0.0

Account Identity and Session Boundary

Establish who a request is from where the work happens, decide how long a session lasts and how it ends, and make sure one account's identifier cannot be substituted for another's.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Ensure the identity behind a request is established at the point the work is performed, that the account identifier is never taken from client-supplied input without a check, and that a session has a confirmed lifetime and a way to be ended.

  • The system never firmly establishes who is askingA request is trusted because it carries a session, without the holder, scope, or age of that session being checked where the work happens. Sessions never end, credentials are stored recoverably, and one account's identifier can be substituted for another in a request.
Versioned applicability rule
{
  "any": [
    {
      "characteristic": "SENSITIVE_DATA",
      "equals": true
    },
    {
      "characteristic": "MULTI_TENANT",
      "equals": true
    },
    {
      "characteristic": "PRIVILEGED_ACTION",
      "equals": true
    }
  ]
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Which parts of the system require a signed-in account, and what may be reached without one?Naming the boundary is what makes it checkable. Anything not named tends to end up reachable by default.IDN-005-Q1 · scope
  • How long should a signed-in session stay valid, and what ends it early?A session that never expires is a credential with no end date. The right answer depends on who uses the system and from where, so it cannot be chosen for you.IDN-005-Q2 · choice

Requirements for the coding agent

  • IDN-005-R1Establish the acting account server-side at the point the work is performed, and never take the account or tenant identifier from client-supplied input without verifying it against the established session. Deny by default for anything outside the confirmed unauthenticated surface.
  • IDN-005-R2Implement the confirmed session lifetime and end conditions, store credentials and tokens in a non-recoverable or protected form, and provide a way to invalidate one account's sessions without affecting others.

Tests and evidence to retain

  • IDENTITY_SUBSTITUTION_TESTCall each protected operation while substituting another account's or tenant's identifier in the request, and confirm the substituted value is refused rather than honoured.
  • SESSION_LIFETIME_TESTExercise an expired session, an invalidated session, and the confirmed end condition, and confirm access stops and the lifecycle event is recorded.
  • configuration_or_policy
  • implementation_location
  • test_result
  • telemetry_definition

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • IA-2 · Identification and Authentication (Organizational Users)NIST_SP_800_53_5_2_0 · partially addressesEstablishing the acting account server-side addresses identification for these operations; it does not cover the full control family.
  • IA-5 · Authenticator ManagementNIST_SP_800_53_5_2_0 · partially addressesHolding credentials in a non-recoverable form and providing invalidation addresses part of authenticator management; it is not a complete programme.
  • AC-12 · Session TerminationNIST_SP_800_53_5_2_0 · partially addressesA confirmed session lifetime and end condition is session termination for this system; it does not establish organization-wide session policy.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review