<?xml version="1.0" ?>
<catalog xmlns="http://csrc.nist.gov/ns/oscal/1.0" uuid="11d5ade2-d32b-42c0-971e-3d72d49ad33d">
  <metadata>
    <title>NIST SP 800-63-4</title>
    <published>2026-09-30T13:10:04Z</published>
    <last-modified>2026-09-30T13:10:04Z</last-modified>
    <version>0.1</version>
    <oscal-version>1.2.2</oscal-version>
    <revisions>
      <revision>
        <title>63C</title>
        <version>63C</version>
      </revision>
      <revision>
        <title>63B</title>
        <version>63B</version>
      </revision>
      <revision>
        <title>63A</title>
        <version>63A</version>
      </revision>
      <revision>
        <title>63Base</title>
        <version>63Base</version>
      </revision>
    </revisions>
  </metadata>
  <group class="revision" id="revision-63Base">
    <title>63Base</title>
    <control id="DIRM-1">
      <title>Digital Identity Risk Management - RP Process Implementation</title>
      <prop name="label" class="index" value="3.0 #1"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM"/>
      <part id="DIRM-1_smt" name="statement">
        <p>Federal RPs SHALL implement the DIRM process for all online services.</p>
      </part>
      <part id="DIRM-1_obj" name="objective">
        <p>Determine if all online services of the Federal RP are identified and ensure the DIRM process is implemented for those online services.</p>
        <link href="#DIRM-1_smt" rel="assessment-for"/>
      </part>
      <part id="DIRM-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine DIRM policy to determine that it is intended to cover all organizational applications. If available, review the  list of online services to ensure all services are identified and that DIRM documentation for each online service exists.</p>
      </part>
      <part id="DIRM-1_gdn" name="guidance">
        <p>For relying parties, the intent of [the DIRM] process is to determine the assurance levels and any tailoring required to protect all online services and the applications, transactions, and systems that comprise or are impacted by those services. This directly contributes to the selection, development, and procurement of CSP services.</p>
      </part>
    </control>
    <control id="DIRM-2">
      <title>Digital Identity Risk Management - CSP/IdP Communication of Normative Deviations</title>
      <prop name="label" class="index" value="3.0 #2"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="DIRM"/>
      <part id="DIRM-2_smt" name="statement">
        <p>Whenever a service offering deviates from normative guidance, those deviations SHALL be clearly communicated to the RPs that utilize the service.</p>
      </part>
      <part id="DIRM-2_obj" name="objective">
        <p>Ensure that the CSP/IdP has a documented process for communicating when their services deviate from the established normative guidance of the applicable NIST SP 900-63 requirements.</p>
        <link href="#DIRM-2_smt" rel="assessment-for"/>
      </part>
      <part id="DIRM-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP/IdP policy for communicating deviations from normative guidance.</p>
      </part>
      <part id="DIRM-2_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview relying party customers to confirm they are familiar with the policy and process for communication and determine if the process is being used.</p>
      </part>
      <part id="DIRM-2_gdn" name="guidance">
        <p>For credential service providers and identity providers, the intent of [the DIRM] process is to design service offerings that meet the requirements of the defined assurance levels, continuously guard against compromises to the identity system, and meet the needs of RPs.</p>
      </part>
    </control>
    <control id="DIRM-3">
      <title>Digital Identity Risk Management - Documentation</title>
      <prop name="label" class="index" value="3.0 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM"/>
      <part id="DIRM-3_smt" name="statement">
        <p>At a minimum, organizations SHALL execute and document each step and complete and document the normative mandates and outcomes of each step, regardless of any organization-specific processes or tools used in the overall DIRM process.</p>
      </part>
      <part id="DIRM-3_obj" name="objective">
        <p>Determine that each step of the DIRM process is executed and documented.</p>
        <link href="#DIRM-3_smt" rel="assessment-for"/>
      </part>
      <part id="DIRM-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM process documentation to ensure the outcomes of each step are completed as applicable.</p>
      </part>
      <part id="DIRM-3_gdn" name="guidance">
        <p>This requirement is agnostic to any organization-specific processes or tools used in the overall DIRM process.(Ref. Sec. 3.0 #A)</p>
      </part>
    </control>
    <control id="DOS-1a">
      <title>Define Online Services - Mission and Business</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1a_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes the organizational mission and business objectives supported by the online service.</p>
      </part>
      <part id="DOS-1a_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the organizational mission and business objectives that are supported by the online service.</p>
        <link href="#DOS-1a_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes a description of its organizational mission and  business objectives.</p>
      </part>
      <part id="DOS-1a_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process.</p>
      </part>
    </control>
    <control id="DOS-1b">
      <title>Define Online Services - Dependencies</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1b_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes the mission and business partner dependencies associated with the online service.</p>
      </part>
      <part id="DOS-1b_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the mission and business partner dependencies associated with the online service.</p>
        <link href="#DOS-1b_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes its associated mission and business partner dependencies.</p>
      </part>
      <part id="DOS-1b_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process.</p>
      </part>
    </control>
    <control id="DOS-1c">
      <title>Define Online Services - Legal, Regulatory, Contractual</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1c_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes legal, regulatory, and contractual requirements, including privacy obligations that apply to the online service.</p>
      </part>
      <part id="DOS-1c_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the legal, regulatory, and contractual requirements, including obligations that apply to the online service.</p>
        <link href="#DOS-1c_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1c_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes its  legal, regulatory, and contractual requirements, including obligations that apply to the online service.</p>
      </part>
      <part id="DOS-1c_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process.</p>
      </part>
    </control>
    <control id="DOS-1d">
      <title>Define Online Services - Functionality and Data Processing</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1d_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes the functionality of the online service and the data that it is expected to process.</p>
      </part>
      <part id="DOS-1d_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the functionality of the online service and the data that it is expected to process.</p>
        <link href="#DOS-1d_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1d_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes its functionality and the data that it is expected to process.</p>
      </part>
      <part id="DOS-1d_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process.</p>
      </part>
    </control>
    <control id="DOS-1e">
      <title>Define Online Services - User Groups Transactions &amp; Access Privileges</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1e_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes user groups that need to have access to the online service as well as the types of online transactions and access privileges available to each user group.</p>
      </part>
      <part id="DOS-1e_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the user groups that need to have access to the online service.</p>
        <link href="#DOS-1e_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1e_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it identifies user groups and the  transaction types and access privileges associated with each group.</p>
      </part>
      <part id="DOS-1e_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process.</p>
        <p>The set of entities includes users of the online service, organizations, and populations served.</p>
        <p>It is crucial to differentiate between user groups and impacted entities.</p>
        <p>(a) User groups are users who are partitioned based on the specific functionality or access privileges offered to them (e.g., citizens checking tax status vs. tax preparers filing returns).</p>
        <p>(b) Impacted entities include everyone who could face negative consequences if the identity system fails. This group includes members of the user groups but also potentially those who never directly use the system.</p>
      </part>
    </control>
    <control id="DOS-1f">
      <title>Define Online Services - Impacted Entities and Business Processes</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1f_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes the set of entities (to include users of the online service, organizations, and populations served) that will be impacted by the online service and the broader business process of which it is a part.</p>
      </part>
      <part id="DOS-1f_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the set of entities that will be impacted by the online service and the broader business process of which it is a part.</p>
        <link href="#DOS-1f_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1f_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes  the set of entities that will be impacted by the online service and the broader business process of which it is a part.</p>
      </part>
      <part id="DOS-1f_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process. The set of entities includes users of the online service, organizations, and populations served.</p>
      </part>
    </control>
    <control id="DOS-1g">
      <title>Define Online Services - Previous Assessment Results and Technologies</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1g_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes the results of any preexisting DIRM assessments (as an input) and the current state of any preexisting identity technologies (i.e., proofing, authentication, or federation).</p>
      </part>
      <part id="DOS-1g_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the results of any preexisting DIRM assessments and the current state of any preexisting identity technologies.</p>
        <link href="#DOS-1g_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1g_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes the results of any preexisting DIRM assessments and/or a description of the current state of any preexisting identity technologies.</p>
      </part>
      <part id="DOS-1g_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process.</p>
      </part>
    </control>
    <control id="DOS-1h">
      <title>Define Online Services - Identity Evidence Availability</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1"/>
      <part id="DOS-1h_smt" name="statement">
        <p>RPs SHALL develop a description of the online service that includes the estimated availability of the types of identity evidence required for identity proofing across all user groups served.</p>
      </part>
      <part id="DOS-1h_obj" name="objective">
        <p>Determine if a description of the online service has been developed that includes the estimated availability of the types of identity evidence required for identity proofing across all user groups served.</p>
        <link href="#DOS-1h_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-1h_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes the estimated availability of the types of identity evidence required for identity proofing across all user groups served.</p>
      </part>
      <part id="DOS-1h_gdn" name="guidance">
        <p>The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process.</p>
      </part>
    </control>
    <control id="DOS-2">
      <title>Define Online Services - Impact Assessment Scope - Users and Organization</title>
      <prop name="label" class="index" value="3.1 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1, Impact assessment"/>
      <part id="DOS-2_smt" name="statement">
        <p>The scope of impact assessments SHALL include individuals who use the online service as well as the organization itself.</p>
      </part>
      <part id="DOS-2_obj" name="objective">
        <p>Determine if the scope of impact assessments includes impacts to individuals who use the online service and impacts to the organization.</p>
        <link href="#DOS-2_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure  the impact assessments address impacts to the  individuals who use the online service and impacts to the organization.</p>
      </part>
      <part id="DOS-2_gdn" name="guidance">
        <p>Note: "online application" is the same as "online service".</p>
      </part>
    </control>
    <control id="DOS-3">
      <title>Define Online Services - Impact Assessment Scope - Entities included in Mission and Business Needs</title>
      <prop name="label" class="index" value="3.1 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1, Impact assessment"/>
      <part id="DOS-3_smt" name="statement">
        <p>The scope of impact assessments for organizations SHALL identify other entities (e.g., mission partners, communities, and those identified in [SP800-30]) that need to be specifically included based on mission and business needs.</p>
      </part>
      <part id="DOS-3_obj" name="objective">
        <p>Determine if the scope of impact assessments for organizations identify other entities that need to be specifically included based on mission and business needs.</p>
        <link href="#DOS-3_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure the impact assessments address mission partners and other external organizations that may be impacted by the online service.</p>
      </part>
      <part id="DOS-3_gdn" name="guidance">
        <p>DOS-3 deals with user groups.</p>
      </part>
    </control>
    <control id="DOS-4">
      <title>Define Online Services - Impact Assessment Scope - Impacted Entities</title>
      <prop name="label" class="index" value="3.1 D"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM Step 1, Impact assessment"/>
      <part id="DOS-4_smt" name="statement">
        <p>At a minimum, organizations SHALL document all impacted entities (both internal and external to the organization) when conducting their impact assessments.</p>
      </part>
      <part id="DOS-4_obj" name="objective">
        <p>Determine if the scope of impact assessments for organizations identify all internal and external impacted entities.</p>
        <link href="#DOS-4_smt" rel="assessment-for"/>
      </part>
      <part id="DOS-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM documentation for each online service to ensure it includes a description of the scope of impact assessments for organizations that identifies all internal and external impacted entities.</p>
      </part>
      <part id="DOS-4_gdn" name="guidance">
        <p>DOS-4 deals with impacted entities.</p>
      </part>
    </control>
    <control id="CIA-1a">
      <title>Impact Assessment - Potential Harms for Impact Categories</title>
      <prop name="label" class="index" value="3.2 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM Step 2, Impact assessment"/>
      <part id="CIA-1a_smt" name="statement">
        <p>The impact assessment SHALL include a set of impact categories and the potential harms for each impact category.</p>
      </part>
      <part id="CIA-1a_obj" name="objective">
        <p>Determine that the impact assessment includes a set of impact categories and the potential harms for each impact category.</p>
        <link href="#CIA-1a_smt" rel="assessment-for"/>
      </part>
      <part id="CIA-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM impact assessment documentation to establish that the impact assessment includes a set of impact categories and the potential harms for each impact category.</p>
      </part>
    </control>
    <control id="CIA-1b">
      <title>Impact Assessment - Levels of Impact Identification</title>
      <prop name="label" class="index" value="3.2 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM Step 2, Impact assessment"/>
      <part id="CIA-1b_smt" name="statement">
        <p>The impact assessment SHALL include identifying the levels of impact.</p>
      </part>
      <part id="CIA-1b_obj" name="objective">
        <p>Determine that the impact assessment includes the levels of impact.</p>
        <link href="#CIA-1b_smt" rel="assessment-for"/>
      </part>
      <part id="CIA-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM impact assessment documentation to establish that the impact assessment includes the levels of impact.</p>
      </part>
    </control>
    <control id="CIA-1c">
      <title>Impact Assessment - Levels of Impact - User Groups</title>
      <prop name="label" class="index" value="3.2 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM Step 2, Impact assessment"/>
      <part id="CIA-1c_smt" name="statement">
        <p>The impact assessment SHALL include assessing the level of impact for each user group.</p>
      </part>
      <part id="CIA-1c_obj" name="objective">
        <p>Determine that the impact assessment includes an assessment of the level of impact for each user group.</p>
        <link href="#CIA-1c_smt" rel="assessment-for"/>
      </part>
      <part id="CIA-1c_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM impact assessment documentation to establish that the impact assessment includes an assessment for the level of impact for each user group.</p>
      </part>
    </control>
    <control id="CIA-2">
      <title>Impact Assessment - Levels of Impact - Transactions</title>
      <prop name="label" class="index" value="3.2 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="DIRM Step 2, Impact assessment"/>
      <part id="CIA-2_smt" name="statement">
        <p>The level of impact for each user group identified in Sec. 3.1 SHALL be considered separately based on the transactions available to that user group.</p>
      </part>
      <part id="CIA-2_obj" name="objective">
        <p>Determine if the levels of impact for each user group is considered separately based on the transactions available to that user group.</p>
        <link href="#CIA-2_smt" rel="assessment-for"/>
      </part>
      <part id="CIA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM impact assessment documentation to establish that the levels of impact for each user group is considered separately based on the transactions available to that user group.</p>
      </part>
    </control>
    <control id="IC-1">
      <title>Impact Categories</title>
      <prop name="label" class="index" value="3.2.1 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact categories, Potential harms"/>
      <part id="IC-1_smt" name="statement">
        <p>At a minimum, organizations SHALL include the following impact categories in their impact assessments:</p>
        <p>(a) Degradation of mission delivery.</p>
        <p>(b) Damage to trust, standing, or reputation.</p>
        <p>(c) Unauthorized access to information.</p>
        <p>(d) Financial loss or liability.</p>
        <p>(e) Loss of life or danger to human safety, human health, or environmental health.</p>
      </part>
      <part id="IC-1_obj" name="objective">
        <p>Determine if the impact categories in the impact assessments include degradation of mission delivery, damage to trust, standing, or reputation, unauthorized access to information, financial loss or liability, and loss of life or danger to human safety, human health, or environmental health.</p>
        <link href="#IC-1_smt" rel="assessment-for"/>
      </part>
      <part id="IC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM impact assessment documentation to establish that the impact categories include degradation of mission delivery, damage to trust, standing, or reputation, unauthorized access to information, financial loss or liability, and loss of life or danger to human safety, human health, or environmental health.</p>
      </part>
    </control>
    <control id="IC-2">
      <title>Impact Categories - Documentation and Application</title>
      <prop name="label" class="index" value="3.2.1 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact categories, Potential harms"/>
      <part id="IC-2_smt" name="statement">
        <p>Each impact category SHALL be documented and consistently applied when implementing the DIRM process across different online services offered by the organization.</p>
      </part>
      <part id="IC-2_obj" name="objective">
        <p>Determine if, for each online service offered by the organization, each impact category is documented and applied as part of the DIRM process.</p>
        <link href="#IC-2_smt" rel="assessment-for"/>
      </part>
      <part id="IC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM impact assessment documentation to establish that, for each online service, each impact category is documented and applied.</p>
      </part>
    </control>
    <control id="IC-3">
      <title>Impact Categories - Potential Harms</title>
      <prop name="label" class="index" value="3.2.1 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact categories, Potential harms"/>
      <part id="IC-3_smt" name="statement">
        <p>For each impact category, organizations SHALL consider potential harms for each of the impacted entities identified in Sec. 3.1</p>
      </part>
      <part id="IC-3_obj" name="objective">
        <p>Determine if potential harms are identified for each impact category and each of the impacted entities.</p>
        <link href="#IC-3_smt" rel="assessment-for"/>
      </part>
      <part id="IC-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the organization's DIRM impact assessment documentation to establish that potential harms are identified for each impact category and each of the impacted entities.</p>
      </part>
    </control>
    <control id="PIL-1">
      <title>Potential Impact Levels - Threshold Development, Examples, and Documentation</title>
      <prop name="label" class="index" value="3.2.2 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact levels"/>
      <part id="PIL-1_smt" name="statement">
        <p>To provide a more objective basis for impact level assignments, organizations SHOULD develop thresholds and examples for the impact levels for each impact category. Where this is done, particularly with specifically defined quantifiable values, these thresholds SHALL be documented and used consistently in the DIRM assessments across an organization to allow for a common understanding of risks.</p>
      </part>
      <part id="PIL-1_obj" name="objective">
        <p>PIL-1Obj1: Determine if thresholds and examples for the impact levels for each impact category have been developed. (0ptional) PIL-1Obj2: Determine if PIL-1Obj1 is documented and used consistently in the DIRM assessments. (conditional)</p>
        <link href="#PIL-1_smt" rel="assessment-for"/>
      </part>
      <part id="PIL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM impact assessment documentation to verify that they are documented, including any specifically defined quantifiable values, and look for evidence of consistent use in the DIRM assessments.</p>
      </part>
      <part id="PIL-1_gdn" name="guidance">
        <p>Assessment is required when: thresholds and examples for the impact levels were developed.</p>
      </part>
    </control>
    <control id="IA-1">
      <title>Impact Analysis - Impacts from Unauthorized Access</title>
      <prop name="label" class="index" value="3.2.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact analysis"/>
      <part id="IA-1_smt" name="statement">
        <p>The impact analysis SHALL consider the level of impact for each impact category for each type of impacted entity if an intruder obtains unauthorized access as a member of each user group.</p>
      </part>
      <part id="IA-1_obj" name="objective">
        <p>Determine if the impact analysis considers the level of impact resulting from unauthorized access, for each impact category for each type of impacted entity.</p>
        <link href="#IA-1_smt" rel="assessment-for"/>
      </part>
      <part id="IA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the  analysis of the organization's DIRM impact assessment to establish that it considers impacts from unauthorized access for each type of impacted entity,</p>
      </part>
    </control>
    <control id="IA-2">
      <title>Impact Analysis - User Groups</title>
      <prop name="label" class="index" value="3.2.3 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact analysis"/>
      <part id="IA-2_smt" name="statement">
        <p>The impact analysis SHALL be performed for each user group that has access to the online service.</p>
      </part>
      <part id="IA-2_obj" name="objective">
        <p>Determine if the impact analysis is performed for each user group that has access to the online service.</p>
        <link href="#IA-2_smt" rel="assessment-for"/>
      </part>
      <part id="IA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation for the impact analyses performed to determine that one exists for each user group that has access to the online service.</p>
      </part>
    </control>
    <control id="IA-3">
      <title>Impact Analysis - Output Documentation</title>
      <prop name="label" class="index" value="3.2.3 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact analysis"/>
      <part id="IA-3_smt" name="statement">
        <p>The output of this impact analysis is a set of impact levels for each user group that SHALL be documented for further analysis in accordance with Sec. 3.4.</p>
      </part>
      <part id="IA-3_obj" name="objective">
        <p>Determine if the output of the impact analysis includes a documented set of impact levels.</p>
        <link href="#IA-3_smt" rel="assessment-for"/>
      </part>
      <part id="IA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the output of the impact analysis to verify that it includes a documented set of impact levels.</p>
      </part>
    </control>
    <control id="CIL-1">
      <title>Combined Impact - Overall Impact Level and Application</title>
      <prop name="label" class="index" value="3.2.4 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact levels, User groups"/>
      <part id="CIL-1_smt" name="statement">
        <p>Organizations SHALL document the approach they use to combine their impact assessment into an overall impact level for each of their defined user groups and SHALL apply it consistently across all of its online services.</p>
      </part>
      <part id="CIL-1_obj" name="objective">
        <part id="CIL-1_obj-1" name="objective">
          <p>Determine if the approach used to combine the impact assessment into an overall impact level for each defined user group has been documented.</p>
          <link href="#CIL-1_smt" rel="assessment-for"/>
        </part>
        <part id="CIL-1_obj-2" name="objective">
          <p>Determine if the approach used to combine the impact assessment into an overall impact level for each defined user group is applied consistently across all online services.</p>
          <link href="#CIL-1_smt" rel="assessment-for"/>
        </part>
        <link href="#CIL-1_smt" rel="assessment-for"/>
      </part>
      <part id="CIL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM process documentation to ensure that the approach used to combine the impact assessment into an overall impact level for each defined user group has been documented.</p>
      </part>
      <part id="CIL-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the person/people responsible for implementing this approach to ensure they understand the approach and are implementing it consistently.</p>
      </part>
    </control>
    <control id="CIL-2">
      <title>Combined Impact Level - Impact Documentation</title>
      <prop name="label" class="index" value="3.2.4 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Impact levels, User groups"/>
      <part id="CIL-2_smt" name="statement">
        <p>At the conclusion of the combinatorial analysis, organizations SHALL document the impact for each user group.</p>
      </part>
      <part id="CIL-2_obj" name="objective">
        <p>Determine if the overall impact levels for each user group have been documented.</p>
        <link href="#CIL-2_smt" rel="assessment-for"/>
      </part>
      <part id="CIL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the completed combined impact assessments to ensure the approach and results for each user group have been documented.</p>
      </part>
    </control>
    <control id="AL-1">
      <title>Assurance Levels - xAL Need Determination</title>
      <prop name="label" class="index" value="3.3.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="IAL, AAL, FAL"/>
      <part id="AL-1_smt" name="statement">
        <p>The RP SHALL identify the types of assurance levels that apply to their online service from the following:</p>
        <p>(a) IAL: The robustness of the identity proofing process to determine the identity of an individual. The IAL is selected to mitigate risks that result from potential identity proofing failures.</p>
        <p>(b) AAL: The robustness of the authentication process itself and the binding between an authenticator and a specific individual's identifier. The AAL is selected to mitigate risks that result from potential authentication failures.</p>
        <p>(c) FAL: The robustness of the federation process used to communicate authentication and attribute information to an RP from an IdP. The FAL is selected to mitigate risks that result from potential federation failures.</p>
      </part>
      <part id="AL-1_obj" name="objective">
        <p>Determine if the online service needs an IAL, AAL, or FAL.</p>
        <link href="#AL-1_smt" rel="assessment-for"/>
      </part>
      <part id="AL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented needs of the identity service, the results of the DIRM documentation completed to date, and the IAL requirements from 800-63A, to determine if identity proofing is necessary.</p>
      </part>
      <part id="AL-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented needs of the identity service, the results of the DIRM documentation completed to date, and the IAL requirements from 800-63B, to determine if authentication is needed.</p>
      </part>
      <part id="AL-1_asm-examine-3" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented needs of the identity service, the results of the DIRM documentation completed to date, and the IAL requirements from 800-63C, to determine if federation is needed.</p>
      </part>
    </control>
    <control id="IALS-1">
      <title>Initial Assurance Level Selection - Process and Governance Documentation</title>
      <prop name="label" class="index" value="3.3.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Assurance levels"/>
      <part id="IALS-1_smt" name="statement">
        <p>Organizations SHALL develop and document a process and governance model for selecting initial assurance levels and controls based on the potential impacts of failures in the digital identity system.</p>
      </part>
      <part id="IALS-1_obj" name="objective">
        <p>Determine if the process and governance model for selecting initial assurance levels and controls has been developed based on the potential impacts of failures in the digital identity system and has been documented.</p>
        <link href="#IALS-1_smt" rel="assessment-for"/>
      </part>
      <part id="IALS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM documentation to verify that the process and governance model for selecting initial assurance levels and controls has been developed and documented.</p>
      </part>
      <part id="IALS-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the process and governance model documentation and identify the potential impacts of failures that the process and governance model were based on.</p>
      </part>
    </control>
    <control id="IIAL-1a">
      <title>Initial IAL - Decision Documentation</title>
      <prop name="label" class="index" value="3.3.3.1 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="IAL"/>
      <part id="IIAL-1a_smt" name="statement">
        <p>The organization SHALL document whether identity proofing is required for their application.</p>
      </part>
      <part id="IIAL-1a_obj" name="objective">
        <p>Determine if the question of whether identity proofing is required for the online service has been documented.</p>
        <link href="#IIAL-1a_smt" rel="assessment-for"/>
      </part>
      <part id="IIAL-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the online service documentation to verify that the results of the analysis to determine the need for identity proofing has been documented.</p>
      </part>
      <part id="IIAL-1a_gdn" name="guidance">
        <p>This documents the results of control AL-1.</p>
      </part>
    </control>
    <control id="IIAL-1b">
      <title>Initial IAL - Selection</title>
      <prop name="label" class="index" value="3.3.3.1 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="IAL"/>
      <part id="IIAL-1b_smt" name="statement">
        <p>If identity proofing is required for their application, the organization SHALL select an initial IAL for each user group based on the effective impact level determination from Sec. 3.2.4.</p>
      </part>
      <part id="IIAL-1b_obj" name="objective">
        <p>Determine if an initial IAL for each user group was determined and is based on the impact level determination (see  CIL requirements)</p>
        <link href="#IIAL-1b_smt" rel="assessment-for"/>
      </part>
      <part id="IIAL-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation to verify that the initial IAL has been determined for each user group and is based on the effective impact level determination (See CIL controls).</p>
      </part>
      <part id="IIAL-1b_gdn" name="guidance">
        <p>Assessment is required when: the online service requires identity proofing for their user groups. See AL-1. If identity proofing is required, see CIL controls for impact levels.</p>
      </part>
    </control>
    <control id="IAAL-1a">
      <title>Initial AAL - Decision Documentation</title>
      <prop name="label" class="index" value="3.3.3.2 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AAL"/>
      <part id="IAAL-1a_smt" name="statement">
        <p>The organization SHALL document whether authentication is required for their application.</p>
      </part>
      <part id="IAAL-1a_obj" name="objective">
        <p>Determine if the question of whether authentication is required for the online service has been documented.</p>
        <link href="#IAAL-1a_smt" rel="assessment-for"/>
      </part>
      <part id="IAAL-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the online service documentation to verify that the results of the analysis to determine the need for authentication has been documented.</p>
      </part>
      <part id="IAAL-1a_gdn" name="guidance">
        <p>This documents the results of requirement AL-1.</p>
      </part>
    </control>
    <control id="IAAL-1b">
      <title>Initial AAL - Selection</title>
      <prop name="label" class="index" value="3.3.3.2 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AAL"/>
      <part id="IAAL-1b_smt" name="statement">
        <p>If authentication is required for their application, the organization SHALL select an initial AAL for each user group based on the effective impact level determination from Sec. 3.2.4.</p>
      </part>
      <part id="IAAL-1b_obj" name="objective">
        <p>Determine if an initial AAL for each user group was determined and is based on the impact level determination (see  CIL requirements)</p>
        <link href="#IAAL-1b_smt" rel="assessment-for"/>
      </part>
      <part id="IAAL-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation to verify that the initial AAL has been determined for each user group and is based on the effective impact level determination (See CIL controls).</p>
      </part>
      <part id="IAAL-1b_gdn" name="guidance">
        <p>Assessment is required when: the online service requires authentication. See AL-1. If authentication is required, see CIL controls for impact levels.</p>
      </part>
    </control>
    <control id="IFAL-1a">
      <title>Initial FAL - Decision Documentation</title>
      <prop name="label" class="index" value="3.3.3.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="FAL"/>
      <part id="IFAL-1a_smt" name="statement">
        <p>The organization SHALL document whether federation is required for their application.</p>
      </part>
      <part id="IFAL-1a_obj" name="objective">
        <p>Determine if the question of whether federation is required for the online service has been documented.</p>
        <link href="#IFAL-1a_smt" rel="assessment-for"/>
      </part>
      <part id="IFAL-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the online service documentation to verify that the results of the analysis to determine the need for federation has been documented.</p>
      </part>
      <part id="IFAL-1a_gdn" name="guidance">
        <p>This documents the results of the FAL assessment in control AL-1. Assessment is required when: the organization will use federation.</p>
      </part>
    </control>
    <control id="IFAL-1b">
      <title>Initial FAL - Selection</title>
      <prop name="label" class="index" value="3.3.3.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="FAL"/>
      <part id="IFAL-1b_smt" name="statement">
        <p>If federation is required for their application, the organization SHALL select an initial FAL for each user group based on the effective impact level determination from  Sec. 3.2.4.</p>
      </part>
      <part id="IFAL-1b_obj" name="objective">
        <p>Determine if an initial FAL for each user group was determined and is based on the impact level determination (see  CIL requirements)</p>
        <link href="#IFAL-1b_smt" rel="assessment-for"/>
      </part>
      <part id="IFAL-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation to verify that the initial FAL has been determined for each user group and is based on the effective impact level determination (See CIL controls).</p>
      </part>
      <part id="IFAL-1b_gdn" name="guidance">
        <p>Assessment is required when: the online service requires federation. See AL-1. If federation will be used, see CIL controls for impact levels.</p>
      </part>
    </control>
    <control id="IFAL-2">
      <title>Initial FAL - FAL2 or FAL3 Assessment</title>
      <prop name="label" class="index" value="3.3.3.3 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="FAL"/>
      <part id="IFAL-2_smt" name="statement">
        <p>For online services that are assessed to be high impact, organizations SHALL conduct a further assessment to evaluate the risk of a compromised IdP to determine whether FAL2 or FAL3 is more appropriate for their use case.</p>
      </part>
      <part id="IFAL-2_obj" name="objective">
        <p>If the online service is "high impact," determine if further assessment has been done to evaluate the risk of a compromised IdP and if FAL2 or FAL3 is more appropriate.</p>
        <link href="#IFAL-2_smt" rel="assessment-for"/>
      </part>
      <part id="IFAL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation for additional assessments that evaluate if FAL2 or FAL3 is more appropriate.</p>
      </part>
      <part id="IFAL-2_gdn" name="guidance">
        <p>Dependent on the results from controls AL-1 and IFAL-1a. Assessment is required when: the online service is assessed to be "high-impact."</p>
      </part>
    </control>
    <control id="BC-1a">
      <title>Baseline Controls - IAL Controls</title>
      <prop name="label" class="index" value="3.3.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Baseline Controls"/>
      <part id="BC-1a_smt" name="statement">
        <p>Using the initial xALs selected in Sec. 3.3.3, the organization SHALL identify the applicable baseline controls for each user group for the Initial IAL and related technical and process controls from [SP800-63A].</p>
      </part>
      <part id="BC-1a_obj" name="objective">
        <p>Determine if the applicable baseline controls for the initial IAL and related technical and process controls have been identified for each user group in alignment with SP 800-63A.</p>
        <link href="#BC-1a_smt" rel="assessment-for"/>
      </part>
      <part id="BC-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the initial IAL baseline controls and related technical and process controls to determine that they are in alignment with SP 800-63A  for each  user group.</p>
      </part>
      <part id="BC-1a_gdn" name="guidance">
        <p>See IIAL controls.</p>
      </part>
    </control>
    <control id="BC-1b">
      <title>Baseline Controls - AAL Controls</title>
      <prop name="label" class="index" value="3.3.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Baseline Controls"/>
      <part id="BC-1b_smt" name="statement">
        <p>Using the initial xALs selected in Sec. 3.3.3, the organization SHALL identify the applicable baseline controls for each user group for the Initial AAL and related technical and process controls from [SP800-63B].</p>
      </part>
      <part id="BC-1b_obj" name="objective">
        <p>Determine if the applicable baseline controls for the initial AAL and related technical and process controls have been identified for each user group in alignment with SP 800-63B.</p>
        <link href="#BC-1b_smt" rel="assessment-for"/>
      </part>
      <part id="BC-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the initial AAL baseline controls and related technical and process controls to determine that they are in alignment with SP 800-63B for each  user group.</p>
      </part>
      <part id="BC-1b_gdn" name="guidance">
        <p>See IAAL controls.</p>
      </part>
    </control>
    <control id="BC-1c">
      <title>Baseline Controls - FAL Controls</title>
      <prop name="label" class="index" value="3.3.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Baseline Controls"/>
      <part id="BC-1c_smt" name="statement">
        <p>Using the initial xALs selected in Sec. 3.3.3, the organization SHALL identify the applicable baseline controls for each user group for the Initial FAL and related technical and process controls from [SP800-63C].</p>
      </part>
      <part id="BC-1c_obj" name="objective">
        <p>Determine if the applicable baseline controls for the initial FAL and related technical and process controls have been identified for each user group in alignment with SP 800-63C.</p>
        <link href="#BC-1c_smt" rel="assessment-for"/>
      </part>
      <part id="BC-1c_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the initial FAL baseline controls and related technical and process controls to determine that they are in alignment with SP 800-63C for each  user group</p>
      </part>
      <part id="BC-1c_gdn" name="guidance">
        <p>See IFAL controls.</p>
      </part>
    </control>
    <control id="TAL-1">
      <title>Tailor Assurance Levels - Mission Impacts</title>
      <prop name="label" class="index" value="3.4 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Tailoring"/>
      <part id="TAL-1_smt" name="statement">
        <p>Within the tailoring step, organizations SHALL focus on impacts to mission delivery due to the implementation of identity management controls.</p>
      </part>
      <part id="TAL-1_obj" name="objective">
        <p>Determine if the impacts to mission delivery are used as a focus for the tailoring step.</p>
        <link href="#TAL-1_smt" rel="assessment-for"/>
      </part>
      <part id="TAL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring documentation to ensure impacts to mission are used as a focus.</p>
      </part>
      <part id="TAL-1_gdn" name="guidance">
        <p>Impacts include the possibility of legitimate users who are unable to access desired online services or experience sufficient friction or frustration with the identity system (and technology selection) that they abandon attempts to access the online service.(Ref. Sec. 3.4 A)</p>
      </part>
    </control>
    <control id="TAL-2">
      <title>Tailor Assurance Levels - DIAS Review</title>
      <prop name="label" class="index" value="3.4 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Tailoring"/>
      <part id="TAL-2_smt" name="statement">
        <p>As a part of the tailoring process, organizations SHALL review the Digital Identity Acceptance Statements (DIAS) and practice statements from CSPs and IdPs that they use or intend to use.</p>
      </part>
      <part id="TAL-2_obj" name="objective">
        <p>Determine if the DIAS and practice statements from CSPs and IdPs have been reviewed as part of the tailoring process.</p>
        <link href="#TAL-2_smt" rel="assessment-for"/>
      </part>
      <part id="TAL-2_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the person/team responsible for completing the tailoring step to ensure they reviewed the DIAS and practice statements.</p>
      </part>
    </control>
    <control id="TAL-3">
      <title>Tailor Assurance Levels - Analysis</title>
      <prop name="label" class="index" value="3.4 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Tailoring"/>
      <part id="TAL-3_smt" name="statement">
        <p>Organizations SHALL also conduct their own analysis to ensure that their specific mission and the communities being served by the online service are given due consideration for tailoring purposes.</p>
      </part>
      <part id="TAL-3_obj" name="objective">
        <p>Determine if the tailoring process includes organizations' own analysis to ensure that their mission and communities served by the online services are given due consideration.</p>
        <link href="#TAL-3_smt" rel="assessment-for"/>
      </part>
      <part id="TAL-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring documentation to  ensure  analysis was done, and due consideration given, to the organization specific mission and the communities being served by the online service.</p>
      </part>
    </control>
    <control id="TAL-4">
      <title>Tailor Assurance Levels - Tailoring Process</title>
      <prop name="label" class="index" value="3.4 D"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Tailoring"/>
      <part id="TAL-4_smt" name="statement">
        <p>Organizations SHALL establish and document their xAL tailoring process.</p>
      </part>
      <part id="TAL-4_obj" name="objective">
        <p>(1) Determine if the xAL tailoring process has been documented.</p>
        <p>(2) Determine if the xAL tailoring process has been implemented.</p>
        <link href="#TAL-4_smt" rel="assessment-for"/>
      </part>
      <part id="TAL-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring process documentation for each xAL to verify its existence and completeness.</p>
      </part>
    </control>
    <control id="TAL-5">
      <title>Tailor Assurance Levels - Governance Approach</title>
      <prop name="label" class="index" value="3.4 E"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Tailoring"/>
      <part id="TAL-5_smt" name="statement">
        <p>At a minimum, [the tailoring] process SHALL follow a documented governance approach to allow for decision-making.</p>
      </part>
      <part id="TAL-5_obj" name="objective">
        <p>Determine if the tailoring process follows a documented governance approach that allows for decision-making.</p>
        <link href="#TAL-5_smt" rel="assessment-for"/>
      </part>
      <part id="TAL-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring process documentation for information on the governance approach that allows for decision-making.</p>
      </part>
    </control>
    <control id="TAL-6">
      <title>Tailor Assurance Levels - Document Decisions</title>
      <prop name="label" class="index" value="3.4 F"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Tailoring"/>
      <part id="TAL-6_smt" name="statement">
        <p>At a minimum, [the tailoring] process SHALL document all decisions in the tailoring process (see Sec. 3.4.4).</p>
      </part>
      <part id="TAL-6_obj" name="objective">
        <p>Determine if the tailoring process documents all decisions made during the tailoring process.</p>
        <link href="#TAL-6_smt" rel="assessment-for"/>
      </part>
      <part id="TAL-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring process documentation to determine that all decisions made during the tailoring process have been documented.</p>
      </part>
      <part id="TAL-6_gdn" name="guidance">
        <p>Examples of decisions include the assessed xALs, modified xALs, and supplemental and compensating controls in the Digital Identity Acceptance Statement</p>
      </part>
    </control>
    <control id="TAL-7">
      <title>Tailor Assurance Levels - Document Risk-Based Decisions</title>
      <prop name="label" class="index" value="3.4 G"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Tailoring"/>
      <part id="TAL-7_smt" name="statement">
        <p>At a minimum, the [tailoring] process SHALL justify and document all risk-based decisions or modifications to the initially assessed xALs in the Digital Identity Acceptance Statement (DIAS) (see Sec. 3.4.4).</p>
      </part>
      <part id="TAL-7_obj" name="objective">
        <p>Determine if the tailoring process justifies and documents all risk-based decisions or modifications to the initially selected xALs in the DIAS.</p>
        <link href="#TAL-7_smt" rel="assessment-for"/>
      </part>
      <part id="TAL-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring process documentation to ensure justifications are included in the documented risk-based decisions or modifications that apply to the initially selected xALs in the DIAS.</p>
      </part>
    </control>
    <control id="PCT-1">
      <title>Privacy, Customer Experience, Threat Resistance - Identify Impacts</title>
      <prop name="label" class="index" value="3.4.1 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Privacy, Customer Experience, Threat Resistance"/>
      <part id="PCT-1_smt" name="statement">
        <p>When progressing from the initial assurance level selection in [the Baseline Controls requirements] (Sec. 3.3.4) to the final xAL selection and implementation, organizations SHALL conduct detailed assessments of the controls defined for the initially selected xALs to identify potential impacts in the operational environment.</p>
      </part>
      <part id="PCT-1_obj" name="objective">
        <p>As part of the selection of the final xALs, determine if a detailed assessment of the initial xAL controls was conducted and identified potential impacts in the operational environment.</p>
        <link href="#PCT-1_smt" rel="assessment-for"/>
      </part>
      <part id="PCT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM documentation indicating the final xAL selection to ensure it includes  a detailed assessment of the initial xAL controls and identifies potential impacts in the operational environment.</p>
      </part>
      <part id="PCT-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the person(s) responsible for conducting the assessment of the initial xAL controls for how they identified the potential impacts in the operational environment.</p>
      </part>
    </control>
    <control id="PCT-2a">
      <title>Privacy, Customer Experience, Threat Resistance - Privacy Impact Assessment</title>
      <prop name="label" class="index" value="3.4.1 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Privacy"/>
      <part id="PCT-2a_smt" name="statement">
        <p>At a minimum, organizations SHALL assess the impacts and potential unintended consequences related to Privacy - Identify unintended consequences to the privacy of individuals who will be subject to the controls at an assessed xAL and of individuals affected by organizational or third-party practices related to the establishment, management, or federation of a digital identity. A privacy assessment SHOULD leverage an existing Privacy Threshold Analysis (PTA) or Privacy Impact Assessment (PIA) as inputs during the privacy assessment process.</p>
      </part>
      <part id="PCT-2a_obj" name="objective">
        <p>Determine if the organization assessed the impacts and potential unintended consequences related to privacy.</p>
        <link href="#PCT-2a_smt" rel="assessment-for"/>
      </part>
      <part id="PCT-2a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM documentation indicating the final xAL selection to ensure it includes an assessment of the impacts and potential unintended consequences related to privacy.</p>
      </part>
      <part id="PCT-2a_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the person(s) responsible for assessing the impacts and potential consequences related to privacy to determine if they leveraged a PTA or PIA as part of their process. (optional)</p>
      </part>
      <part id="PCT-2a_gdn" name="guidance">
        <p>As the goal of the privacy assessment is to identify privacy risks that arise from the initial assurance level selection, additional assessments and evaluations that are specific to the baseline controls for the assurance levels may be required for the underlying information system. Leveraging an existing PTA or PIA is recommended.</p>
      </part>
    </control>
    <control id="PCT-1b">
      <title>Privacy, Customer Experience, Threat Resistance - Customer Experience Impact Assessment</title>
      <prop name="label" class="index" value="3.4.1 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Customer Experience"/>
      <part id="PCT-1b_smt" name="statement">
        <p>At a minimum, organizations SHALL assess the impacts and potential unintended consequences related to Customer Experience - Determine whether implementation of the initial assurance levels may create substantial or unacceptable barriers to individuals seeking to access services. Customer experience assessments SHALL consider impacts that result from the identity management controls to ensure that they do not cause undue burdens, frustrations, or frictions for individuals and that there are pathways to provide service to users of all capabilities, resources, technology access, and economic statuses.</p>
      </part>
      <part id="PCT-1b_obj" name="objective">
        <p>Determine if the organization assessed the impacts and potential unintended consequences related to customer experience.</p>
        <link href="#PCT-1b_smt" rel="assessment-for"/>
      </part>
      <part id="PCT-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM documentation indicating the final xAL selection to ensure it includes an assessment of the impacts and potential unintended consequences related to customer experience, such as  undue burdens, frustrations, or frictions for individuals, as well as pathways to provide service to users of all capabilities, resources, technology access, and economic statuses.</p>
      </part>
      <part id="PCT-1b_gdn" name="guidance">
        <p>Determine whether implementation of the initial assurance levels may create substantial or unacceptable barriers to individuals seeking to access services.</p>
      </part>
    </control>
    <control id="PCT-1c">
      <title>Privacy, Customer Experience, Threat Resistance - Threat Resistance Impact Assessment</title>
      <prop name="label" class="index" value="3.4.1 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Threat Resistance"/>
      <part id="PCT-1c_smt" name="statement">
        <p>At a minimum, organizations SHALL assess the impacts and potential unintended consequences related to Threat Resistance - Determine whether the defined assurance level and related controls will address specific threats to the online service based on the operational environment, its threat actors, and known tactics, techniques, and procedures (TTPs). Threat assessments SHALL consider specific known and potential threats, threat actors, and TTPs within the implementation environment for the identity management functions.</p>
      </part>
      <part id="PCT-1c_obj" name="objective">
        <p>Determine if the organization assessed the impacts and potential unintended consequences related to threat resistance.</p>
        <link href="#PCT-1c_smt" rel="assessment-for"/>
      </part>
      <part id="PCT-1c_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM documentation indicating the final xAL selection to ensure there is an assessment of the impacts and potential unintended consequences related to threat resistance showing that the defined assurance level and related controls address: 1) specific threats to the online service based on the operation environment, 2) the threat actors of those specific threats and known  TTPs.</p>
      </part>
      <part id="PCT-1c_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the person(s) responsible for assessing the impacts and potential consequences related to privacy to determine if and how they considered specific known and potential threats, threat actors, and TTPs within the implementation environment for the identity management functions.</p>
      </part>
      <part id="PCT-1c_gdn" name="guidance">
        <p>For example, certain benefits programs may be more subject to familial threats or collusion. Based on their assessments, organizations MAY implement supplemental controls specific to the communities served by their online service. Conversely, organizations MAY tailor their assessed xAL down or modify their baseline controls if their threat assessment indicates that a reduced threat posture is appropriate based on their environment.</p>
      </part>
    </control>
    <control id="PCT-3">
      <title>Privacy, Customer Experience, Threat Resistance - Compensating and Supplemental Controls</title>
      <prop name="label" class="index" value="3.4.1 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Privacy, Customer Experience, Threat Resistance"/>
      <part id="PCT-3_smt" name="statement">
        <p>All assessments applied during the tailoring phase SHALL be extended to any compensating or supplemental controls, as defined in Sec. 3.4.2 and Sec. 3.4.3.</p>
      </part>
      <part id="PCT-3_obj" name="objective">
        <p>Determine if all assessments applied during the tailoring phase were extended to any identified compensating or supplemental controls.</p>
        <link href="#PCT-3_smt" rel="assessment-for"/>
      </part>
      <part id="PCT-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIRM documentation indicating the final xAL selection to ensure all assessments applied during the tailoring phase were extended to any compensating or supplemental controls identified in ICC-1 and ISC-1.</p>
      </part>
      <part id="PCT-3_gdn" name="guidance">
        <p>A compensating control is a management, operational, or technical control employed by an organization in lieu of a normative control (i.e., SHALL statements) in the defined xALs. (Ref. Sec. 3.4.2. A) The purpose of this requirement is to allow the RP to assess and determine the acceptability of the compensating controls for their use cases.(Ref. Sec. 3.4.2. C) Assessment is required when: compensating controls are implemented. Per section 3.4.2, "Organizations MAY choose to implement a compensating control if they are unable to implement a baseline control or when a risk assessment indicates that a compensating control sufficiently mitigates risk in alignment with organizational risk tolerance. This control MAY be a modification to the normative statements defined in these guidelines or MAY be applied elsewhere in an online service, digital transaction, or service life cycle."</p>
      </part>
    </control>
    <control id="PCT-4">
      <title>Privacy, Customer Experience, Threat Resistance - Cost-based Decision Documentation</title>
      <prop name="label" class="index" value="3.4.1 D"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Privacy, Customer Experience, Threat Resistance"/>
      <part id="PCT-4_smt" name="statement">
        <p>Any cost-based decisions that result in modifications to assessed xALs or baseline controls SHALL be documented in the Digital Identity Acceptance Statement (see Sec. 3.4.4).</p>
      </part>
      <part id="PCT-4_obj" name="objective">
        <p>Determine if cost-based decisions that result in modification to assessed xALs or baseline controls are documented in the Digital Identity Acceptance Statement (DIAS).</p>
        <link href="#PCT-4_smt" rel="assessment-for"/>
      </part>
      <part id="PCT-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIAS to ensure cost-based decisions that resulted in modification to the assessed xALs or baseline controls are documented.</p>
      </part>
    </control>
    <control id="ICC-1">
      <title>Identify Compensating Controls - Documentation</title>
      <prop name="label" class="index" value="3.4.2 B"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Compensating controls, Conditional"/>
      <part id="ICC-1_smt" name="statement">
        <p>Where compensating controls are implemented, organizations SHALL document the compensating control, the rationale for the deviation, comparability of the chosen alternative, and any resulting residual risks.</p>
      </part>
      <part id="ICC-1_obj" name="objective">
        <p>Determine if implemented compensating controls are documented, including the rationale for the deviation, comparability of the chosen alternative, and any resulting residual risks.</p>
        <link href="#ICC-1_smt" rel="assessment-for"/>
      </part>
      <part id="ICC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring documentation to ensure implemented compensating controls are fully documented, including the rationale for the deviation, comparability of the chosen alternative, and any resulting residual risks.</p>
      </part>
      <part id="ICC-1_gdn" name="guidance">
        <p>A compensating control is a management, operational, or technical control employed by an organization in lieu of a normative control (i.e., SHALL statements) in the defined xALs. (Ref. Sec. 3.4.2. A) The purpose of this requirement is to allow the RP to assess and determine the acceptability of the compensating controls for their use cases.(Ref. Sec. 3.4.2. C) Assessment is required when: compensating controls are implemented. Per section 3.4.2, "Organizations MAY choose to implement a compensating control if they are unable to implement a baseline control or when a risk assessment indicates that a compensating control sufficiently mitigates risk in alignment with organizational risk tolerance. This control MAY be a modification to the normative statements defined in these guidelines or MAY be applied elsewhere in an online service, digital transaction, or service life cycle."</p>
      </part>
    </control>
    <control id="ICC-2">
      <title>Identify Compensating Controls - Communication</title>
      <prop name="label" class="index" value="3.4.2 C"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="Compensating controls, Conditional"/>
      <part id="ICC-2_smt" name="statement">
        <p>CSPs and IdPs that implement compensating controls SHALL communicate this information to all potential RPs prior to integration.</p>
      </part>
      <part id="ICC-2_obj" name="objective">
        <p>Determine if CSPs and IdPs that implement compensating controls have communicated this information to all potential RPs prior to integration.</p>
        <link href="#ICC-2_smt" rel="assessment-for"/>
      </part>
      <part id="ICC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP/IdP communications with all RPs and potential RPs to ensure the information regarding the implementation of those compensating controls was done prior to their integration.</p>
      </part>
      <part id="ICC-2_gdn" name="guidance">
        <p>A compensating control is a management, operational, or technical control employed by an organization in lieu of a normative control (i.e., SHALL statements) in the defined xALs. (Ref. Sec. 3.4.2. A) The purpose of this requirement is to allow the RP to assess and determine the acceptability of the compensating controls for their use cases.(Ref. Sec. 3.4.2. C) Assessment is required when: compensating controls are implemented. Per section 3.4.2, "Organizations MAY choose to implement a compensating control if they are unable to implement a baseline control or when a risk assessment indicates that a compensating control sufficiently mitigates risk in alignment with organizational risk tolerance. This control MAY be a modification to the normative statements defined in these guidelines or MAY be applied elsewhere in an online service, digital transaction, or service life cycle."</p>
      </part>
    </control>
    <control id="ISC-1">
      <title>Identify Supplemental Controls - Impact Assessment</title>
      <prop name="label" class="index" value="3.4.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Supplemental controls"/>
      <part id="ISC-1_smt" name="statement">
        <p>Any supplemental controls SHALL be assessed for impacts based on the same factors used to tailor the organization's assurance level.</p>
      </part>
      <part id="ISC-1_obj" name="objective">
        <p>Determine if supplemental controls are assessed for impacts based on the same factors used to tailor the organization's assurance level.</p>
        <link href="#ISC-1_smt" rel="assessment-for"/>
      </part>
      <part id="ISC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring documentation to ensure any implemented supplemental controls have been assessed for impacts based on the same factors used to tailor the initial xALs. See TAL and PCT requirements.</p>
      </part>
      <part id="ISC-1_gdn" name="guidance">
        <p>Assessment is required when: supplemental controls are identified and implemented.</p>
      </part>
    </control>
    <control id="ISC-2">
      <title>Identify Supplemental Controls - Documentation</title>
      <prop name="label" class="index" value="3.4.3 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Supplemental controls"/>
      <part id="ISC-2_smt" name="statement">
        <p>Any supplemental controls SHALL be documented.</p>
      </part>
      <part id="ISC-2_obj" name="objective">
        <p>Determine if supplemental controls are documented.</p>
        <link href="#ISC-2_smt" rel="assessment-for"/>
      </part>
      <part id="ISC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the tailoring documentation to ensure implemented supplemental controls are fully documented.</p>
      </part>
      <part id="ISC-2_gdn" name="guidance">
        <p>Assessment is required when: supplemental controls are identified and implemented.</p>
      </part>
    </control>
    <control id="DIAS-1a">
      <title>Digital Identity Acceptance Statement - Documentation - Managed Online Services</title>
      <prop name="label" class="index" value="3.4.4 Aa"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-1a_smt" name="statement">
        <p>Organizations SHALL develop a Digital Identity Acceptance Statement (DIAS) to document the results of the DIRM process for each online service managed by the organization.</p>
      </part>
      <part id="DIAS-1a_obj" name="objective">
        <p>Determine if a DIAS was developed that documents the results of the DIRM process for each online service managed by the organization.</p>
        <link href="#DIAS-1a_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIAS to verify documentation of the DIRM process results for each online service managed by the organization.</p>
      </part>
      <part id="DIAS-1a_gdn" name="guidance">
        <p>See DIRM-1.</p>
      </part>
    </control>
    <control id="DIAS-1b">
      <title>Digital Identity Acceptance Statement - Documentation - External Online Services</title>
      <prop name="label" class="index" value="3.4.4 Ab"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-1b_smt" name="statement">
        <p>Organizations SHALL develop a Digital Identity Acceptance Statement (DIAS) to document the results of the DIRM process for each external online service used to support the mission of the organization.</p>
      </part>
      <part id="DIAS-1b_obj" name="objective">
        <p>Determine if a DIAS was developed that documents the results of the DIRM process for each external online service used to support the mission of the organization.</p>
        <link href="#DIAS-1b_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIAS to verify documentation of the DIRM process results for each external online service used to support the mission of the organization.</p>
      </part>
      <part id="DIAS-1b_gdn" name="guidance">
        <p>External online services include software-as-a-service offerings (e.g., social media platforms, email services, online marketing services). (Ref. Sec. 3.4.4.A) See DIRM-1</p>
      </part>
    </control>
    <control id="DIAS-2">
      <title>Digital Identity Acceptance Statement - Incorporating External DIAS Information</title>
      <prop name="label" class="index" value="3.4.4 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-2_smt" name="statement">
        <p>RPs who intend to use a particular CSP/IdP SHALL review the latter's DIAS and incorporate relevant information into the organization's DIAS for each online service.</p>
      </part>
      <part id="DIAS-2_obj" name="objective">
        <p>Determine if the RP reviewed the CSP/IdP's DIAS and incorporated relevant information into the RP's DIAS for each online service.</p>
        <link href="#DIAS-2_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine each RP online service's DIAS for relevant information from the DIAS of the CSP/IdP the RP intends to use.</p>
      </part>
      <part id="DIAS-2_gdn" name="guidance">
        <p>Assessment is required when: the CSP/IdP used by the RP has created a DIAS.</p>
      </part>
    </control>
    <control id="DIAS-3">
      <title>Digital Identity Acceptance Statement - Online Service DIAS contents</title>
      <prop name="label" class="index" value="3.4.4 C"/>
      <prop name="marking" class="target" value="RP, CSP/IdP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-3_smt" name="statement">
        <p>Organizations SHALL prepare a DIAS for their online service that includes, at a minimum:</p>
        <p>(a) Initial impact assessment results; initially assessed xALs.</p>
        <p>(b) Tailored xALs and rationale if the tailored xALs differs from the initially assessed xALs.</p>
        <p>(c) All compensating controls with their comparability or residual risks.</p>
        <p>(d) All supplemental controls.</p>
      </part>
      <part id="DIAS-3_obj" name="objective">
        <p>Determine if the organization's online service DIAS includes, at a minimum, initial impact assessment results, initially assessed xALs, tailored xALs and rationale if the tailored xALs differs from the initially assessed xALs,  all compensating controls with their comparability or residual risks, and all supplemental controls.</p>
        <link href="#DIAS-3_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine each DIAS to ensure it includes the initial impact assessment results, initially assessed xALs, tailored xALs and rationale if the tailored xALs differs from the initially assessed xALs,  all compensating controls with their comparability or residual risks, and all supplemental controls.</p>
      </part>
      <part id="DIAS-3_gdn" name="guidance">
        <p>Assessment is required for a CS{/IdP when: the CSP/IdP deviates from normative guidance and creates a DIAS.</p>
      </part>
    </control>
    <control id="DIAS-4">
      <title>Digital Identity Acceptance Statement - CSP DIAS Implementation</title>
      <prop name="label" class="index" value="3.4.4 D"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-4_smt" name="statement">
        <p>CSPs/IdPs SHALL implement the DIRM process and develop a DIAS for the services they offer if they deviate from the normative guidance in these guidelines, including when supplemental or compensating controls are added.</p>
      </part>
      <part id="DIAS-4_obj" name="objective">
        <p>For CSP/IdPs that deviate from normative guidance, determine if the CSP/IdP has implemented the DIRM process and developed a DIAS for the services they offer.</p>
        <link href="#DIAS-4_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation to ensure the DIRM process was implemented and a DIAS developed for their offered services.</p>
      </part>
      <part id="DIAS-4_gdn" name="guidance">
        <p>Assessment is required when: the CSP/IdP deviates from normative guidance, including when supplemental or compensating controls are added. To complete a DIRM of their offered assurance levels and controls, CSPs/IdPs MAY base their assessment on anticipated or representative digital identity services that they wish to support.</p>
      </part>
    </control>
    <control id="DIAS-5">
      <title>Digital Identity Acceptance Statement - CSP DIAS Elements</title>
      <prop name="label" class="index" value="3.4.4 E"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-5_smt" name="statement">
        <p>The DIAS prepared by a CSP SHALL include, at a minimum:</p>
        <p>(a) Claimed xAL, related controls, and rationale for any deviations from normative guidance;</p>
        <p>(b) All compensating controls with their comparability or residual risks; and</p>
        <p>(c) All supplemental controls.</p>
      </part>
      <part id="DIAS-5_obj" name="objective">
        <p>Determine if the CSP's DIAS  includes the claimed xAL, related controls, and rationale for any deviations from normative guidance, all compensating controls with their comparability or residual risks, and all supplemental controls.</p>
        <link href="#DIAS-5_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's DIAS to ensure it includes claimed xAL, related controls, and rationale for any deviations from normative guidance, all compensating controls with their comparability or residual risks, and all supplemental controls.</p>
      </part>
      <part id="DIAS-5_gdn" name="guidance">
        <p>Assessment is required when: the CSP/IdP has created a DIAS (see DIAS-4).</p>
      </part>
    </control>
    <control id="DIAS-6">
      <title>Digital Identity Acceptance Statement - Documentation of Relevant Inputs</title>
      <prop name="label" class="index" value="3.4.4 F"/>
      <prop name="marking" class="target" value="RP, CSP/IdP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-6_smt" name="statement">
        <p>The DIRM process for external online services used by the organization SHALL consider relevant inputs from the provider of the service and document the results in a DIAS.</p>
      </part>
      <part id="DIAS-6_obj" name="objective">
        <p>Determine if the DIRM process for external online services includes the results of  inputs from the provider of the service are documented in a DIAS.</p>
        <link href="#DIAS-6_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIAS containing the results of the DIRM process for external online services used by the organization includes and documents relevant inputs from the provider of the service.</p>
      </part>
      <part id="DIAS-6_gdn" name="guidance">
        <p>CSP's trying to meet this requirement should coordinate with the RP for the documentation.</p>
      </part>
    </control>
    <control id="DIAS-7">
      <title>Digital Identity Acceptance Statement - External Online Services DIAS</title>
      <prop name="label" class="index" value="3.4.4 G"/>
      <prop name="marking" class="target" value="RP, CSP/IdP"/>
      <prop name="marking" class="xal-level" value="Acceptance supplement"/>
      <part id="DIAS-7_smt" name="statement">
        <p>The DIAS prepared by the organization for external online services SHALL include, at a minimum:</p>
        <p>(a) Assessed xAL, related controls, and rationale for any deviations from normative guidance;</p>
        <p>(b) All compensating controls with their comparability or residual risks; and</p>
        <p>(c) All supplemental controls.</p>
      </part>
      <part id="DIAS-7_obj" name="objective">
        <p>Determine if the DIAS for external online services includes assessed xALs, related controls, and rationale for any deviations from normative guidance,  all compensating controls with their comparability or residual risks, and all supplemental controls.</p>
        <link href="#DIAS-7_smt" rel="assessment-for"/>
      </part>
      <part id="DIAS-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the DIAS prepared for each external online services to ensure they include assessed xALs, related controls, and rationale for any deviations from normative guidance,  all compensating controls with their comparability or residual risks, and all supplemental controls.</p>
      </part>
      <part id="DIAS-7_gdn" name="guidance">
        <p>Assessment is required when: the CSP/IdP created a DIAS (see DIAS-4)</p>
      </part>
    </control>
    <control id="CEI-1">
      <title>Continuously Evaluate and Improve - Implementation</title>
      <prop name="label" class="index" value="3.5 A"/>
      <prop name="marking" class="target" value="CSP/IdP, RP"/>
      <prop name="marking" class="xal-level" value="Continuous evaluation and improvement"/>
      <part id="CEI-1_smt" name="statement">
        <p>Organizations SHALL implement a continuous evaluation and improvement program that leverages input from end users who have interacted with the identity management system as well as performance metrics for the online service.</p>
      </part>
      <part id="CEI-1_obj" name="objective">
        <p>Determine if the organization has implemented a continuous evaluation and improvement program that leverages input from end users who have interacted with the identity management system and performance metrics for the online service.</p>
        <link href="#CEI-1_smt" rel="assessment-for"/>
      </part>
      <part id="CEI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation that describes the continuous evaluation and improvement program to ensure it leverages input from end users who have interacted with the identity management system.</p>
      </part>
      <part id="CEI-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation that describes the continuous evaluation and improvement program to ensure it leverages input from performance metrics for the online service.</p>
      </part>
      <part id="CEI-1_gdn" name="guidance">
        <p>The purpose of this control is to address the shifting environment in which they operate and more rapidly address service capability gaps.</p>
      </part>
    </control>
    <control id="CEI-2">
      <title>Continuously Evaluate and Improve - Documentation</title>
      <prop name="label" class="index" value="3.5 B"/>
      <prop name="marking" class="target" value="CSP/IdP, RP"/>
      <prop name="marking" class="xal-level" value="Continuous evaluation and improvement"/>
      <part id="CEI-2_smt" name="statement">
        <p>This program SHALL be documented, including the metrics that are collected, the sources of data required to enable performance evaluation, and the processes in place for taking timely actions based on the continuous improvement process.</p>
      </part>
      <part id="CEI-2_obj" name="objective">
        <p>Determine if the documentation includes:</p>
        <p>(a) the metrics that are collected,</p>
        <p>(b) the sources of data required to enable performance evaluation, and</p>
        <p>(c) the processes in place for taking timely actions based on the continuous improvement process.</p>
        <link href="#CEI-2_smt" rel="assessment-for"/>
      </part>
      <part id="CEI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the continuous evaluation and improvement program documentation to ensure it includes all collected metrics.</p>
      </part>
      <part id="CEI-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the continuous evaluation and improvement program documentation to ensure it includes the sources of data required to enable performance evaluation.</p>
      </part>
      <part id="CEI-2_asm-examine-3" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the continuous evaluation and improvement program documentation to ensure it includes the processes in place for taking timely actions based on the continuous improvement process.</p>
      </part>
    </control>
    <control id="CEI-3">
      <title>Continuously Evaluate and Improve - Monitoring</title>
      <prop name="label" class="index" value="3.5 C"/>
      <prop name="marking" class="target" value="CSP/IdP, RP"/>
      <prop name="marking" class="xal-level" value="Continuous evaluation and improvement"/>
      <part id="CEI-3_smt" name="statement">
        <p>Organizations SHALL monitor the evolving threat landscape.</p>
      </part>
      <part id="CEI-3_obj" name="objective">
        <p>Determine if the organization is monitoring the evolving threat landscape.</p>
        <link href="#CEI-3_smt" rel="assessment-for"/>
      </part>
      <part id="CEI-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the continuous evaluation and improvement program documentation to ensure it includes policies and procedures for monitoring the evolving threat landscape.</p>
      </part>
      <part id="CEI-3_gdn" name="guidance">
        <p>The purpose of monitoring the evolving threat landscape is to stay informed of the latest threats and fraud tactics.</p>
      </part>
    </control>
    <control id="CEI-4">
      <title>Continuously Evaluate and Improve - Assessing</title>
      <prop name="label" class="index" value="3.5 D"/>
      <prop name="marking" class="target" value="CSP/IdP, RP"/>
      <prop name="marking" class="xal-level" value="Continuous evaluation and improvement"/>
      <part id="CEI-4_smt" name="statement">
        <p>Organizations SHALL regularly assess the effectiveness of current security measures and fraud detection capabilities against the latest threats and fraud tactics.</p>
      </part>
      <part id="CEI-4_obj" name="objective">
        <p>Determine if the organization regularly assesses the effectiveness of current security measures and fraud detection capabilities against the latest threats and fraud tactics.</p>
        <link href="#CEI-4_smt" rel="assessment-for"/>
      </part>
      <part id="CEI-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the continuous evaluation and improvement program documentation (policy and logs) for evidence that the effectiveness of current security measures and fraud detection capabilities against the latest threats and fraud tactics is being assessed regularly.</p>
      </part>
    </control>
    <control id="EI-1">
      <title>Evaluation Inputs</title>
      <prop name="label" class="index" value="3.5.1 A"/>
      <prop name="marking" class="target" value="CSP/IdP, RP"/>
      <prop name="marking" class="xal-level" value="Continuous evaluation and improvement"/>
      <part id="EI-1_smt" name="statement">
        <p>At a minimum, evaluation inputs SHALL include:</p>
        <p>(a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate;</p>
        <p>(b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups);</p>
        <p>(c) Threat analysis, threat reporting, and threat intelligence feeds that are available;</p>
        <p>(d)  Fraud trends, fraud investigation results, and fraud metrics as available; and</p>
        <p>(e) The results of ongoing customer experience assessments and privacy assessments.</p>
      </part>
      <part id="EI-1_obj" name="objective">
        <p>Determine if the evaluation inputs include:</p>
        <p>(a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate;</p>
        <p>(b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups); (c)Threat analysis, threat reporting, and threat intelligence feeds that are available;</p>
        <p>(d) Fraud trends, fraud investigation results, and fraud metrics as available; and</p>
        <p>(e) The results of ongoing customer experience assessments and privacy assessments.</p>
        <link href="#EI-1_smt" rel="assessment-for"/>
      </part>
      <part id="EI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the continuous evaluation and improvement program documentation evaluation inputs to ensure they include:</p>
        <p>(a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate;</p>
        <p>(b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups);</p>
        <p>(c) Threat analysis, threat reporting, and threat intelligence feeds that are available; (d)Fraud trends, fraud investigation results, and fraud metrics as available; and</p>
        <p>(e) The results of ongoing customer experience assessments and privacy assessments.</p>
      </part>
      <part id="EI-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the continuous evaluation and improvement program to ensure it can use  all the following evaluation inputs:</p>
        <p>(a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate;</p>
        <p>(b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups);</p>
        <p>(c) Threat analysis, threat reporting, and threat intelligence feeds that are available;</p>
        <p>(d) Fraud trends, fraud investigation results, and fraud metrics as available; and</p>
        <p>(e) The results of ongoing customer experience assessments and privacy assessments.</p>
      </part>
      <part id="EI-1_gdn" name="guidance">
        <p>The purpose of control EI-1 is to fully understand the performance of their identity system, organizations will need to identify critical inputs to their continuous evaluation process.</p>
      </part>
    </control>
    <control id="EI-2">
      <title>Evaluation Inputs - Documentation</title>
      <prop name="label" class="index" value="3.5.1 B"/>
      <prop name="marking" class="target" value="CSP/IdP, RP"/>
      <prop name="marking" class="xal-level" value="Continuous evaluation and improvement"/>
      <part id="EI-2_smt" name="statement">
        <p>RPs SHALL document their metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service to ensure that expectations are appropriately communicated to partners and vendors.</p>
      </part>
      <part id="EI-2_obj" name="objective">
        <p>Determine if the RP has documented their metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service.</p>
        <link href="#EI-2_smt" rel="assessment-for"/>
      </part>
      <part id="EI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documents for the continuous evaluation and improvement process to ensure they include the RPs metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service.</p>
      </part>
      <part id="EI-2_gdn" name="guidance">
        <p>The documentation of metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service is to ensure that expectations are appropriately communicated to partners and vendors.</p>
      </part>
    </control>
    <control id="RED-1">
      <title>Redress - Issue Handling Process</title>
      <prop name="label" class="index" value="3.6 A"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-1_smt" name="statement">
        <p>RPs and CSPs SHALL enable individuals to convey grievances and seek redress through an issue handling process that is documented, accessible, trackable, and usable by all individuals and whose instructions are easy to find on a public-facing website.</p>
      </part>
      <part id="RED-1_obj" name="objective">
        <p>(1) Determine if the RPs and CSPs issues handline process is:</p>
        <p>(a) Documented,</p>
        <p>(b) Accessible,</p>
        <p>(c) Trackable,</p>
        <p>(e) Usable by all individuals, and has instructions on an easy-to-find, public-facing website.</p>
        <link href="#RED-1_smt" rel="assessment-for"/>
      </part>
      <part id="RED-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the issues handling process public-facing website to ensure  the instructions are easy to find and follow, and the issues are documented, accessible, trackable, and usable (i.e., 508 compliant).</p>
      </part>
    </control>
    <control id="RED-2">
      <title>Redress - Governance Model</title>
      <prop name="label" class="index" value="3.6 B"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-2_smt" name="statement">
        <p>RPs and CSPs SHALL institute a governance model for implementing this issue handling process, including documented roles and responsibilities.</p>
      </part>
      <part id="RED-2_obj" name="objective">
        <p>Determine if the RPs and CSPs instituted a governance model for implementing the issue handling process that includes documented roles and responsibilities.</p>
        <link href="#RED-2_smt" rel="assessment-for"/>
      </part>
      <part id="RED-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the issuance handling governance model documentation to ensure it includes documented roles and responsibilities.</p>
      </part>
    </control>
    <control id="RED-3a">
      <title>Redress - Issue Handling Function - Evidence Review</title>
      <prop name="label" class="index" value="3.6 C"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-3a_smt" name="statement">
        <p>The issue handling process SHALL be implemented as a dedicated function that includes procedures for impartially reviewing pertinent evidence.</p>
      </part>
      <part id="RED-3a_obj" name="objective">
        <p>Determine if the issue handling process is implemented as a dedicated function with procedures for impartially reviewing pertinent evidence.</p>
        <link href="#RED-3a_smt" rel="assessment-for"/>
      </part>
      <part id="RED-3a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the issuance handling documentation for descriptions of how it is implemented to ensure it is implemented as a dedicated function that includes procedures for impartially reviewing pertinent evidence.</p>
      </part>
    </control>
    <control id="RED-3b">
      <title>Redress - Issue Handling Function - Additional Evidence</title>
      <prop name="label" class="index" value="3.6 C"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-3b_smt" name="statement">
        <p>The issue handling process SHALL be implemented as a dedicated function that includes procedures for requesting and collecting additional evidence that informs the issues.</p>
      </part>
      <part id="RED-3b_obj" name="objective">
        <p>Determine if the issue handling process is implemented as a dedicated function with procedures for requesting and collecting additional evidence that informs the issues.</p>
        <link href="#RED-3b_smt" rel="assessment-for"/>
      </part>
      <part id="RED-3b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the issuance handling documentation for descriptions of how it is implemented to ensure it is implemented as a dedicated function that includes procedures for  requesting and collecting additional evidence that informs the issues.</p>
      </part>
    </control>
    <control id="RED-3c">
      <title>Redress - Issue Handling Function - Resolution</title>
      <prop name="label" class="index" value="3.6 C"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-3c_smt" name="statement">
        <p>The issue handling process SHALL be implemented as a dedicated function that includes procedures for expeditiously resolving issues and determining corrective action.</p>
      </part>
      <part id="RED-3c_obj" name="objective">
        <p>Determine if the issue handling process is implemented as a dedicated function with procedures for expeditiously resolving issues and determining corrective action.</p>
        <link href="#RED-3c_smt" rel="assessment-for"/>
      </part>
      <part id="RED-3c_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the issuance handling documentation for descriptions of how it is implemented to ensure it is implemented as a dedicated function that includes procedures for   expeditiously resolving issues and determining corrective action.</p>
      </part>
    </control>
    <control id="RED-4">
      <title>Redress - Support Personnel</title>
      <prop name="label" class="index" value="3.6 D"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-4_smt" name="statement">
        <p>RPs and CSPs SHALL make human support personnel available to intervene and override issue adjudication outputs generated by algorithmic support mechanisms.</p>
      </part>
      <part id="RED-4_obj" name="objective">
        <p>Determine if RPs and CSPs have made human support personnel available to intervene and override issue adjudication outputs generated by algorithmic support mechanisms.</p>
        <link href="#RED-4_smt" rel="assessment-for"/>
      </part>
      <part id="RED-4_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the human support personnel whose role is to intervene and override issue adjudication outputs generated by algorithmic support mechanisms to ensure they are available.</p>
      </part>
    </control>
    <control id="RED-5a">
      <title>Redress - Support Personnel Education - Issue Handling</title>
      <prop name="label" class="index" value="3.6 E"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-5a_smt" name="statement">
        <p>RPs and CSPs SHALL educate support personnel on issue handling procedures for the digital identity management system.</p>
      </part>
      <part id="RED-5a_obj" name="objective">
        <p>Determine if RPs and CSPs have educated support personnel on issue handling procedures for the digital identity management system.</p>
        <link href="#RED-5a_smt" rel="assessment-for"/>
      </part>
      <part id="RED-5a_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the support personnel to ensure they are educated on issue handling procedures for the digital identity management system.</p>
      </part>
      <part id="RED-5a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the training materials used to train the support personnel in issue handling procedures for the digital identity management system.</p>
      </part>
    </control>
    <control id="RED-5b">
      <title>Redress - Support Personnel Education - Redress</title>
      <prop name="label" class="index" value="3.6 E"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-5b_smt" name="statement">
        <p>RPs and CSPs SHALL educate support personnel on the avenues for redress.</p>
      </part>
      <part id="RED-5b_obj" name="objective">
        <p>Determine if RPs and CSPs have educated support personnel on the avenues for redress.</p>
        <link href="#RED-5b_smt" rel="assessment-for"/>
      </part>
      <part id="RED-5b_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the support personnel to ensure they are educated on the avenues for redress.</p>
      </part>
      <part id="RED-5b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the training materials used to train the support personnel on the avenues for redress.</p>
      </part>
    </control>
    <control id="RED-5c">
      <title>Redress - Support Personnel Education - Access Alternatives</title>
      <prop name="label" class="index" value="3.6 E"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-5c_smt" name="statement">
        <p>RPs and CSPs SHALL educate support personnel on the alternatives available to gain access to services.</p>
      </part>
      <part id="RED-5c_obj" name="objective">
        <p>Determine if RPs and CSPs have educated support personnel on the alternatives available to gain access to services.</p>
        <link href="#RED-5c_smt" rel="assessment-for"/>
      </part>
      <part id="RED-5c_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the support personnel to ensure they are educated on the alternatives available to gain access to services.</p>
      </part>
      <part id="RED-5c_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the training materials used to train the support personnel on the alternatives available to gain access to services.</p>
      </part>
    </control>
    <control id="RED-6">
      <title>Redress - Support Functions</title>
      <prop name="label" class="index" value="3.6 F"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-6_smt" name="statement">
        <p>RPs and CSPs SHALL implement a process for personnel and technologies that provides support functions to report and address major barriers that end users face and grievances they may have.</p>
      </part>
      <part id="RED-6_obj" name="objective">
        <p>Determine if the RP/CSP has implemented a process for personnel and technologies that provides support functions to report and address major barriers that end users face and grievances they may have.</p>
        <link href="#RED-6_smt" rel="assessment-for"/>
      </part>
      <part id="RED-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the issues handling process documentation to ensure it includes processes for personnel and technologies that support functions to report and address major barriers that end users face and grievances they may have.</p>
      </part>
    </control>
    <control id="RED-7">
      <title>Redress - Continuous Evaluation and Improvement</title>
      <prop name="label" class="index" value="3.6 G"/>
      <prop name="marking" class="target" value="RP, CSP"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-7_smt" name="statement">
        <p>RPs and CSPs SHALL incorporate findings derived from the issue handling process into continuous evaluation and improvement activities.</p>
      </part>
      <part id="RED-7_obj" name="objective">
        <p>Determine if the RP/CSP has incorporated findings derived from the issue handling process into continuous evaluation and improvement activities.</p>
        <link href="#RED-7_smt" rel="assessment-for"/>
      </part>
      <part id="RED-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the evaluation inputs for the continuous evaluation and improvement program to ensure they incorporate findings derived from the issue handline process.</p>
      </part>
    </control>
    <control id="RED-8a">
      <title>Redress - Integrity and Performance</title>
      <prop name="label" class="index" value="3.6 Ha"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-8a_smt" name="statement">
        <p>Organizations SHALL assess the integrity and performance of their redress mechanisms.</p>
      </part>
      <part id="RED-8a_obj" name="objective">
        <p>Determine if the integrity and performance of their redress mechanisms are being assessed.</p>
        <link href="#RED-8a_smt" rel="assessment-for"/>
      </part>
      <part id="RED-8a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the issues handling process documentation for policies and practices that describe how to assess the integrity and performance of their redress mechanisms.</p>
      </part>
    </control>
    <control id="RED-8b">
      <title>Redress - Fraud Detection</title>
      <prop name="label" class="index" value="3.6 Hb"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Redress"/>
      <part id="RED-8b_smt" name="statement">
        <p>Organizations SHALL implement controls to prevent, detect, and remediate attempted identity fraud involving those mechanisms.</p>
      </part>
      <part id="RED-8b_obj" name="objective">
        <p>Determine if controls to prevent, detect, and remediate attempted identity fraud involving the redress  mechanisms have been implemented.</p>
        <link href="#RED-8b_smt" rel="assessment-for"/>
      </part>
      <part id="RED-8b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the issues handling process documentation for policies and practices that describe the controls they implement to prevent, detect, and remediate attempted identity fraud involving those mechanisms.</p>
      </part>
    </control>
    <control id="CFI-1">
      <title>Cybersecurity, Fraud, and Identity Program Integrity - Information Exchange</title>
      <prop name="label" class="index" value="3.7 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="Program Integrity"/>
      <part id="CFI-1_smt" name="statement">
        <p>Organizations SHALL establish consistent mechanisms for the exchange of information between stakeholders that are responsible for critical internal security and fraud prevention.</p>
      </part>
      <part id="CFI-1_obj" name="objective">
        <p>Determine if consistent mechanisms for the exchange of information between stakeholders that are responsible for critical internal security and fraud prevention have been established.</p>
        <link href="#CFI-1_smt" rel="assessment-for"/>
      </part>
      <part id="CFI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine mechanisms used for the exchange of information between stakeholders that are responsible for critical internal security and fraud prevention.</p>
      </part>
    </control>
    <control id="CFI-2">
      <title>Cybersecurity, Fraud, and Identity Program Integrity - Privacy Assessment</title>
      <prop name="label" class="index" value="3.7 B"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="Program Integrity"/>
      <part id="CFI-2_smt" name="statement">
        <p>All data collected, transmitted, or shared by the identity service provider SHALL be subject to a detailed privacy and legal assessment by either the entity generating the data (e.g., a CSP) or the related RP for whom the service is provided.</p>
      </part>
      <part id="CFI-2_obj" name="objective">
        <p>Determine if all data collected, transmitted, or shared by the identity service provider is subject to a detailed privacy and legal assessment.</p>
        <link href="#CFI-2_smt" rel="assessment-for"/>
      </part>
      <part id="CFI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine privacy and legal assessments to ensure one exists for all data collected, transmitted, or shared by the identity service provider,</p>
      </part>
      <part id="CFI-2_gdn" name="guidance">
        <p>The privacy and legal assessment can be done by either the entity generating the data (e.g., a CSP) or the related RP for whom the service is provided.</p>
      </part>
    </control>
    <control id="AIML-1a">
      <title>Artificial Intelligence and Machine Learning in Identity Systems - Documentation</title>
      <prop name="label" class="index" value="3.8 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AI, ML, Artificial Intelligence, Machine Learning"/>
      <part id="AIML-1a_smt" name="statement">
        <p>All uses of AI/ML [in the identity system] SHALL be documented.</p>
      </part>
      <part id="AIML-1a_obj" name="objective">
        <p>Determine if all uses of AI/ML in the identity system have been documented.</p>
        <link href="#AIML-1a_smt" rel="assessment-for"/>
      </part>
      <part id="AIML-1a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation describing all uses of AI/ML.</p>
      </part>
    </control>
    <control id="AIML-1b">
      <title>Artificial Intelligence and Machine Learning in Identity Systems - Communication</title>
      <prop name="label" class="index" value="3.8 A"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AI, ML, Artificial Intelligence, Machine Learning"/>
      <part id="AIML-1b_smt" name="statement">
        <p>All uses of AI/ML [in the identity system] SHALL be communicated to organizations that rely on these systems.</p>
      </part>
      <part id="AIML-1b_obj" name="objective">
        <p>Determine if all uses of AI/ML in the identity system have been  communicated to organizations that rely on these systems.</p>
        <link href="#AIML-1b_smt" rel="assessment-for"/>
      </part>
      <part id="AIML-1b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine communications to ensure all uses of AI/ML in the identity system have been communicated to organizations that rely on them.</p>
      </part>
    </control>
    <control id="AIML-2">
      <title>Artificial Intelligence and Machine Learning in Identity Systems - Disclosure to RPs</title>
      <prop name="label" class="index" value="3.8 B"/>
      <prop name="marking" class="target" value="CSP, IdP, Verifier"/>
      <prop name="marking" class="xal-level" value="AI, ML, Artificial Intelligence, Machine Learning"/>
      <part id="AIML-2_smt" name="statement">
        <p>The use of integrated technologies that leverage AI/ML by CSPs, IdPs, or verifiers SHALL be disclosed to all RPs that make access decisions based on information from these systems.</p>
      </part>
      <part id="AIML-2_obj" name="objective">
        <p>Determine if the use of integrated technologies that leverage AI/ML is disclosed to all RPs that make access decisions based on information from these systems.</p>
        <link href="#AIML-2_smt" rel="assessment-for"/>
      </part>
      <part id="AIML-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine communications from CSP/IdPs to RPs that make access decisions based on information from systems to ensure disclosure of any use of integrated technologies that leverage AI/ML.</p>
      </part>
    </control>
    <control id="AIML-3a">
      <title>Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information -  Training Methods</title>
      <prop name="label" class="index" value="3.8 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AI, ML, Artificial Intelligence, Machine Learning"/>
      <part id="AIML-3a_smt" name="statement">
        <p>All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] the methods and techniques used for training their models.</p>
      </part>
      <part id="AIML-3a_obj" name="objective">
        <p>Determine if methods and techniques used for training AI/ML models have been provided to the entities using the AI/ML technology.</p>
        <link href="#AIML-3a_smt" rel="assessment-for"/>
      </part>
      <part id="AIML-3a_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes the methods and techniques used for training their AI/ML models.</p>
      </part>
    </control>
    <control id="AIML-3b">
      <title>Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information -  Training Data Sets</title>
      <prop name="label" class="index" value="3.8 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AI, ML, Artificial Intelligence, Machine Learning"/>
      <part id="AIML-3b_smt" name="statement">
        <p>All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] a description of the data sets used in training.</p>
      </part>
      <part id="AIML-3b_obj" name="objective">
        <p>Determine if a description of the data sets used in training the AI/ML models have been provided to the entities using the AI/ML technology.</p>
        <link href="#AIML-3b_smt" rel="assessment-for"/>
      </part>
      <part id="AIML-3b_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes a description of the data sets used in training.</p>
      </part>
    </control>
    <control id="AIML-3c">
      <title>Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information - Updates</title>
      <prop name="label" class="index" value="3.8 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AI, ML, Artificial Intelligence, Machine Learning"/>
      <part id="AIML-3c_smt" name="statement">
        <p>All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] the frequency of model updates.</p>
      </part>
      <part id="AIML-3c_obj" name="objective">
        <p>Determine if the frequency of  AI/ML model updates have been provided to the entities using the AI/ML technology.</p>
        <link href="#AIML-3c_smt" rel="assessment-for"/>
      </part>
      <part id="AIML-3c_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes the frequency of model updates.</p>
      </part>
    </control>
    <control id="AIMLIS-3d">
      <title>Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information - Algorithm Testing</title>
      <prop name="label" class="index" value="3.8 C"/>
      <prop name="marking" class="target" value="Organization"/>
      <prop name="marking" class="xal-level" value="AI, ML, Artificial Intelligence, Machine Learning"/>
      <part id="AIMLIS-3d_smt" name="statement">
        <p>All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] the results of all testing completed on their algorithms.</p>
      </part>
      <part id="AIMLIS-3d_obj" name="objective">
        <p>Determine if the results of all testing completed on their AI/ML algorithms have been provided to the entities using the AI/ML technology.</p>
        <link href="#AIMLIS-3d_smt" rel="assessment-for"/>
      </part>
      <part id="AIMLIS-3d_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes the results of all testing completed on their algorithms.</p>
      </part>
    </control>
  </group>
  <group class="revision" id="revision-63A">
    <title>63A</title>
    <control id="IDPRF-1">
      <title>Risk Evaluation</title>
      <prop name="label" class="index" value="2.0 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-1_smt" name="statement">
        <p>CSPs SHALL evaluate the risks associated with each identity proofing option offered (e.g., identity proofing types, validation sources, assistance mechanisms) and implement mitigating fraud controls, as appropriate.</p>
      </part>
      <part id="IDPRF-1_obj" name="objective">
        <p>Confirm that the CSP has assessed the risks associated with each identity proofing option offered and that they have employed appropriate mitigations to address those risks.</p>
        <link href="#IDPRF-1_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's risk assessment results and confirm it has assessed the risks associated with each identity proofing option offered and has implemented mitigating fraud controls, as appropriate.</p>
      </part>
      <part id="IDPRF-1_gdn" name="guidance">
        <p>CSPs are likely to provide different options for how applicants can complete the identity proofing process. This control ensures a risk assessment process is in place to evaluate these options and identify and address unique risks. It can be done as part of the DIRM process defined in NIST SP 800-63-4 or an organizational specific risk management process.</p>
      </part>
    </control>
    <control id="IDPRF-2">
      <title>Design Options</title>
      <prop name="label" class="index" value="2.0 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-2_smt" name="statement">
        <p>At a minimum, CSPs SHALL design each option such that the options provide comparable assurance in aggregate.</p>
      </part>
      <part id="IDPRF-2_obj" name="objective">
        <p>Confirm that the CSP has designed its identity services so that no identity proofing pathway (sequence of actions) results in a lower level of assurance than another.</p>
        <link href="#IDPRF-2_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's documentation to confirm that the risk assessment identifies the risks unique to each identity proofing option and that the risks have been mitigated sufficiently to provide comparable assurance.</p>
      </part>
    </control>
    <control id="IDPRF-3">
      <title>Identify Roles</title>
      <prop name="label" class="index" value="2.1.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-3_smt" name="statement">
        <p>CSPs SHALL identify which roles are applicable to their identity service.</p>
      </part>
      <part id="IDPRF-3_obj" name="objective">
        <p>Confirm that the CSP has identified the roles that are employed as part of its identity proofing service.</p>
        <link href="#IDPRF-3_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the roles it employs in its identity service.</p>
      </part>
      <part id="IDPRF-3_gdn" name="guidance">
        <p>Identity proofing roles are proofing agent, trusted referee, applicant reference, and process assistant.</p>
      </part>
    </control>
    <control id="IDPRF-4">
      <title>Training</title>
      <prop name="label" class="index" value="2.1.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-4_smt" name="statement">
        <p>CSPs SHALL provide training and support resources consistent with the requirements and expectations provided in Sec. 3.</p>
      </part>
      <part id="IDPRF-4_obj" name="objective">
        <p>Confirm that individuals with defined identity proofing roles are properly trained and provided with the resources they need to be effective in performing their identity proofing roles.</p>
        <link href="#IDPRF-4_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's documentation to confirm the CSP provides appropriate training and resources to persons performing identity proofing roles, consistent with the summary and references in SP 800-63A-4, Appendix B, Table 7.</p>
      </part>
      <part id="IDPRF-4_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview persons performing identity proofing roles for the CSP to identify what training and resources have been provided, and verify they satisfy the summary and references in SP 800-63A-4, Appendix B, Table 7.</p>
      </part>
    </control>
    <control id="IDPRF-5">
      <title>Government Identifier</title>
      <prop name="label" class="index" value="2.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-5_smt" name="statement">
        <p>CSPs SHALL include a government identifier as a part of its core attributes.</p>
      </part>
      <part id="IDPRF-5_obj" name="objective">
        <p>Determine that CSPs require the collection of a government identifier.</p>
        <link href="#IDPRF-5_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSPs documentation to confirm their set of core attributes includes a unique identifier that is associated with the applicant in government records.</p>
      </part>
      <part id="IDPRF-5_gdn" name="guidance">
        <p>A government identifier is a unique identifier that is associated with the applicant in government records (e.g., Social Security number, driver's license number, passport number).</p>
      </part>
    </control>
    <control id="IDPRF-6">
      <title>Document</title>
      <prop name="label" class="index" value="2.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-6_smt" name="statement">
        <p>The CSP and RP SHALL document all core attributes in trust agreements and practice statements.</p>
      </part>
      <part id="IDPRF-6_obj" name="objective">
        <p>Confirm that agreements between CSPs and RPs include the CSP's set of core attributes so that an RP can make risk-based decisions about using a CSP's identity service.</p>
        <link href="#IDPRF-6_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust agreements, contracts, or practices statements to confirm they include the list of attributes a CSP considers as it core attributes.</p>
      </part>
    </control>
    <control id="IDPRF-7">
      <title>FAIR Evidence</title>
      <prop name="label" class="index" value="2.4.1.1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-7_smt" name="statement">
        <p>To be considered FAIR, identity evidence SHALL meet all the requirements in Sec. 2.4.1.1.</p>
      </part>
      <part id="IDPRF-7_obj" name="objective">
        <p>Confirm that the CSP has documented the types of FAIR evidence it considers acceptable and provided justifications for each based on defined requirements.</p>
        <link href="#IDPRF-7_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP only accepts types of FAIR evidence that meet the requirements provided in Sec. 2.4.1.1.</p>
      </part>
    </control>
    <control id="IDPRF-8">
      <title>STRONG Evidence</title>
      <prop name="label" class="index" value="2.4.1.2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-8_smt" name="statement">
        <p>To be considered STRONG, identity evidence SHALL meet all the requirements in Sec. 2.4.1.2.</p>
      </part>
      <part id="IDPRF-8_obj" name="objective">
        <p>Determine that the CSP has documented the types of STRONG evidence it considers acceptable and provided justifications for each based on defined requirements.</p>
        <link href="#IDPRF-8_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP only accepts types of STRONG evidence that meet the requirements provided in Sec. 2.4.1.2.</p>
      </part>
    </control>
    <control id="IDPRF-9">
      <title>SUPERIOR Evidence</title>
      <prop name="label" class="index" value="2.4.1.3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-9_smt" name="statement">
        <p>To be considered SUPERIOR, identity evidence SHALL meet all the requirements in Sec. 2.4.1.3.</p>
      </part>
      <part id="IDPRF-9_obj" name="objective">
        <p>Determine that the CSP has documented the types of SUPERIOR evidence it considers acceptable and provided justifications for each based on defined requirements.</p>
        <link href="#IDPRF-9_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP only accepts types of SUPERIOR evidence that meet the requirements provided in Sec. 2.4.1.3.</p>
      </part>
    </control>
    <control id="IDPRF-10">
      <title>Evidence Validation</title>
      <prop name="label" class="index" value="2.4.2.1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-10_smt" name="statement">
        <p>The CSP SHALL validate the authenticity, accuracy, and validity of presented evidence by confirming that: the evidence is in the correct format and includes complete information for the identity evidence type; the evidence does not show signs of being counterfeit or tampered with; the evidence contains physical or digital security features; and the core attributes and data fields necessary to determine authenticity on the evidence are accurate.</p>
      </part>
      <part id="IDPRF-10_obj" name="objective">
        <p>Determine that the CSP validates all collected evidence according to a systematic and repeatable process that ensures its authenticity, accuracy, and validity.</p>
        <link href="#IDPRF-10_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm that its process for validating identity evidence meets all the criteria provided in Sec. 2.4.2.1.</p>
      </part>
      <part id="IDPRF-10_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate agents of the CSP to determine how presented identity evidence is validated.</p>
      </part>
    </control>
    <control id="IDPRF-11">
      <title>Attribute Validation</title>
      <prop name="label" class="index" value="2.4.2.3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-11_smt" name="statement">
        <p>The CSP SHALL validate all core attributes, whether obtained from identity evidence or self-asserted by the applicant, with an authoritative or credible source.</p>
      </part>
      <part id="IDPRF-11_obj" name="objective">
        <p>All core attributes are validated against  authoritative or credible sources to confirm they are accurate.</p>
        <link href="#IDPRF-11_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its processes and sources for validating the different types of core attributes.</p>
      </part>
    </control>
    <control id="IDPRF-12">
      <title>Validation Sources</title>
      <prop name="label" class="index" value="2.4.2.4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-12_smt" name="statement">
        <p>The CSP SHALL use authoritative or credible sources that meet [the criteria provided in Sec. 2.4.2.4].</p>
      </part>
      <part id="IDPRF-12_obj" name="objective">
        <p>CSPs use appropriate sources to validate core attributes and identity evidence.</p>
        <link href="#IDPRF-12_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm all authoritative and credible sources meet the criteria provided in Sect. 2.4.2.4.</p>
      </part>
      <part id="IDPRF-12_gdn" name="guidance">
        <p>An authoritative source is the issuing source of identity evidence or attributes or has direct access to the information maintained by issuing sources. A credible source has access to attribute information that can be traced to an authoritative source or maintains identity attribute information obtained from multiple sources that is correlated for accuracy, consistency, and currency.</p>
      </part>
    </control>
    <control id="IDPRF-13">
      <title>ID Verification Methods</title>
      <prop name="label" class="index" value="2.5.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-13_smt" name="statement">
        <p>The CSP SHALL verify the linkage between the claimed identity to the applicant engaged in the identity proofing process through one or more of the [methods provided in Sec. 2.5.1].</p>
      </part>
      <part id="IDPRF-13_obj" name="objective">
        <p>CSPs employ proven methods to perform identity verification.</p>
        <link href="#IDPRF-13_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's documentation to determine the method or methods it uses to perform identity verification.</p>
      </part>
      <part id="IDPRF-13_gdn" name="guidance">
        <p>Acceptable identity verification methods include, Confirmation code verification, Authentication and federation protocols, Transaction verification, Visual facial image comparison for on-site attended, and Visual facial image comparison for remote attended or remote unattended. Additional requirements on acceptable methods are addressed per assurance level.</p>
      </part>
    </control>
    <control id="IDPRF-14">
      <title>KBV</title>
      <prop name="label" class="index" value="2.5.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRF-14_smt" name="statement">
        <p>Knowledge-based verification (KBV) or knowledge-based authentication SHALL NOT be used for identity verification.</p>
      </part>
      <part id="IDPRF-14_obj" name="objective">
        <p>Confirm that the CSP does not employ KBV or KBA as part of its identity verification process.</p>
        <link href="#IDPRF-14_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRF-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's documentation to determine it does not employ KBV or KBA during the identity verification process.</p>
      </part>
      <part id="IDPRF-14_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the identity proofing workflow to confirm KBV or KBA is not employed for identity verification.</p>
      </part>
      <part id="IDPRF-14_gdn" name="guidance">
        <p>Because KBV can be easily subverted, it is not a suitable method for identity verification. However, CSPs may employ KBV as part of fraud management processes. Note that applicants may provide self-asserted attributes during the identity proofing process.  Provided the CSP validates these self-asserted attributes with an authoritative or credible source, they may be used by the CSP as core attributes for identity resolution and communication with RPs.  However, the CSP may not use the applicant's knowledge of these attributes as evidence the applicant is who they claim to be.</p>
      </part>
    </control>
    <control id="ISDR-1">
      <title>Documented Procedures Policy</title>
      <prop name="label" class="index" value="3.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-1_smt" name="statement">
        <p>The CSP SHALL conduct its operations according to documented procedures or a practice statement that details all identity proofing processes as they are implemented to achieve the defined IAL.</p>
      </part>
      <part id="ISDR-1_obj" name="objective">
        <p>Confirm that the CSP has documented its procedures to achieve the defined IALs.</p>
        <link href="#ISDR-1_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the processes it employs to achieve a defined IAL.</p>
      </part>
    </control>
    <control id="ISDR-2">
      <title>Service Description Policy</title>
      <prop name="label" class="index" value="3.1 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-2_smt" name="statement">
        <p>The CSP's documented procedures SHALL include a complete service description including the particular steps that it follows to identity-proof applicants at each offered assurance level.</p>
      </part>
      <part id="ISDR-2_obj" name="objective">
        <p>Confirm that the CSP has documented the particular steps it employs to identity proof applicants at each offered assurance level.</p>
        <link href="#ISDR-2_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it has documented the steps it follows to identity proof applicants at a specified assurance level.</p>
      </part>
      <part id="ISDR-2_gdn" name="guidance">
        <p>Documentation of the complete service description allows CSPs to communicate to RPs and others the scope and components of their services and how they achieve specific IALs.</p>
      </part>
    </control>
    <control id="ISDR-3">
      <title>Notice Policy</title>
      <prop name="label" class="index" value="3.1 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-3_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for providing notice to applicants about the types of identity proofing processes available, the evidence and attribute collection requirements for the IALs offered by the CSP, the purpose for collecting personal information, and the purposes for collecting, using, and retaining biometrics.</p>
      </part>
      <part id="ISDR-3_obj" name="objective">
        <p>Confirm that the CSP has documented its procedures for providing notice to applicants, as specified in item #2 of Sec. 3.1.</p>
        <link href="#ISDR-3_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its applicant notice policies.</p>
      </part>
      <part id="ISDR-3_gdn" name="guidance">
        <p>Notice is essential to promoting informed decision-making while conducting identity proofing processes. Since CSPs collect sensitive information, documented set of policies supports informed consent from applicants before engaging with the service.</p>
      </part>
    </control>
    <control id="ISDR-4">
      <title>Timeliness Policy</title>
      <prop name="label" class="index" value="3.1 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-4_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for ensuring that the identity proofing process concludes in a timely manner once the applicant has met all of the requirements.</p>
      </part>
      <part id="ISDR-4_obj" name="objective">
        <p>Confirm that the CSP has a documented policy for ensuring the identity proofing process concludes in a timely manner.</p>
        <link href="#ISDR-4_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for the timely conclusion of the identity proofing process.</p>
      </part>
      <part id="ISDR-4_gdn" name="guidance">
        <p>Lack of timeliness results in the degradation of mission delivery as it affects the ability of the organization to perform mission functions and increases burden on applicants seeking services. Providing policies for the timely completion of identity proofing services sets expectations for RPs and enables communication to applicants about the anticipated timing of the process.</p>
      </part>
    </control>
    <control id="ISDR-5">
      <title>Evidence Policy</title>
      <prop name="label" class="index" value="3.1 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-5_smt" name="statement">
        <p>The CSP's documented procedures SHALL include the types of evidence that it accepts and the justification for how the evidence fulfills the strength requirements of the level at which it will be accepted by the CSP.</p>
      </part>
      <part id="ISDR-5_obj" name="objective">
        <p>Confirm that the CSP has documented the types of evidence it accepts and the justification for how the evidence fulfills the strength requirements of the specified IAL.</p>
        <link href="#ISDR-5_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the types of evidence it accepts and the justification for how the types fulfill the strength requirements for the specified IAL.</p>
      </part>
      <part id="ISDR-5_gdn" name="guidance">
        <p>The policy for identity evidence collection and classification of evidence acceptance allows open communication between the CSP and the RP, which can then be communicated to the applicant to build trust between the applicant and RP as the identity evidence collection is a sensitive process.</p>
      </part>
    </control>
    <control id="ISDR-6">
      <title>Verification Policy</title>
      <prop name="label" class="index" value="3.1 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-6_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy and process for validating and verifying identity evidence, including training and qualification requirements for personnel who serve in identity proofing roles.</p>
      </part>
      <part id="ISDR-6_obj" name="objective">
        <p>Confirm that the CSP has documented its policy and process for validating and verifying evidence, including any training and qualification requirements for proofing agents.</p>
        <link href="#ISDR-6_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its evidence validation and verification policies, and polices for training and qualifying proofing agents or other personnel.</p>
      </part>
      <part id="ISDR-6_gdn" name="guidance">
        <p>The CSP documenting policy and process for validating and verifying identity evidence offers knowledge for the RP that may be employed for communication to the applicant.</p>
      </part>
    </control>
    <control id="ISDR-7">
      <title>Technology Policy</title>
      <prop name="label" class="index" value="3.1 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-7_smt" name="statement">
        <p>The CSP's documented procedures SHALL include the specific technologies that the CSP employs for evidence validation and verification.</p>
      </part>
      <part id="ISDR-7_obj" name="objective">
        <p>Confirm that the CSP documents the technologies it uses for evidence validation and verification.</p>
        <link href="#ISDR-7_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the technologies it uses for evidence validation and verification.</p>
      </part>
      <part id="ISDR-7_gdn" name="guidance">
        <p>Documenting the details of specific technologies that the CSP uses opens the doors for the RP to determine if they are adequate for them as well as communicating to the end-user what technology and services will have access to their identity evidence.</p>
      </part>
    </control>
    <control id="ISDR-8">
      <title>Exception Handling Policy</title>
      <prop name="label" class="index" value="3.1 #7"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-8_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy and processes for supporting applicants who lack sufficient identity evidence for the required IAL and for addressing identity proofing exceptions and errors.</p>
      </part>
      <part id="ISDR-8_obj" name="objective">
        <p>Confirm that the CSP has documented procedures for exception handling and identity proofing errors, including for the identity proofing of applicants who lack the required identity evidence.</p>
        <link href="#ISDR-8_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its procedures for exception handling and identity proofing errors, including for the identity proofing of applicants who lack the required identity evidence.</p>
      </part>
      <part id="ISDR-8_gdn" name="guidance">
        <p>The CSPs outlining support mechanisms for applicants that lack evidence or have exceptions or errors allow the RPs to serve the end-user while ensuring that the identity is valid and informs them of what is required of them.</p>
      </part>
    </control>
    <control id="ISDR-9">
      <title>Attributes Validation Policy</title>
      <prop name="label" class="index" value="3.1 #8"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-9_smt" name="statement">
        <p>The CSP's documented procedures SHALL include the attributes that it considers to be core attributes and the authoritative and credible sources it uses for validating those attributes.</p>
      </part>
      <part id="ISDR-9_obj" name="objective">
        <p>Confirm that the CSP has documented the attributes it considers to be core attributes and the validation sources it uses to validate those attributes.</p>
        <link href="#ISDR-9_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the attributes it considers to be core attributes and the validation sources it uses to validate those attributes</p>
      </part>
      <part id="ISDR-9_gdn" name="guidance">
        <p>The CSPs outlining support mechanisms for applicants that lack evidence or have exceptions or errors allow the RPs to serve the end-user while ensuring that the identity is valid and informs them of what is required of them.</p>
      </part>
    </control>
    <control id="ISDR-10">
      <title>Service Change Policy</title>
      <prop name="label" class="index" value="3.1 #9"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-10_smt" name="statement">
        <p>The CSP's documented procedures SHALL include the CSP's policy for managing and communicating service changes to RPs, such as changes in data sources, integrated vendors, or biometric algorithms.</p>
      </part>
      <part id="ISDR-10_obj" name="objective">
        <p>Confirm that the CSP has documented policies for managing and communicating service changes to the RPs that use its service.</p>
        <link href="#ISDR-10_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for managing and communicating changes to its service to its RPs.</p>
      </part>
      <part id="ISDR-10_gdn" name="guidance">
        <p>The CSPs outlining support mechanisms for applicants that lack evidence or have exceptions or errors allows the RPs to serve the end-user while ensuring that the identity is valid and informing them of what is required of them.</p>
      </part>
    </control>
    <control id="ISDR-11">
      <title>Fraud Management Policy</title>
      <prop name="label" class="index" value="3.1 #10"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-11_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its approach to fraud management, including its policy and process for identifying and remediating suspected or confirmed fraudulent accounts and communicating such information to RPs and affected individuals.</p>
      </part>
      <part id="ISDR-11_obj" name="objective">
        <p>Confirm the CSP has documented its fraud management procedures, including its policy and process for identifying and remediating suspected or confirmed fraudulent accounts and communicating such information to RPs and affected individuals.</p>
        <link href="#ISDR-11_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its fraud management procedures, including its remediation and communication policies and processes.</p>
      </part>
      <part id="ISDR-11_gdn" name="guidance">
        <p>CSP documentation of the fraud management approach allows the RP to be informed on the status of its end users and policies that determine the state of its users' accounts, as well as allowing them to be informed and communicative of any effects that the fraud management process has on the end users' account.</p>
      </part>
    </control>
    <control id="ISDR-12">
      <title>Reverification Policy</title>
      <prop name="label" class="index" value="3.1 #11"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-12_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for any conditions that would require reverification of the user.</p>
      </part>
      <part id="ISDR-12_obj" name="objective">
        <p>Confirm that the CSP has documented policies on any conditions that require the reverification of the subscriber already enrolled in its identity service.</p>
        <link href="#ISDR-12_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policies on subscriber reverification.</p>
      </part>
      <part id="ISDR-12_gdn" name="guidance">
        <p>Examples of reverification include account recovery, account abandonment, and regulatory "recertification" requirements. Documentation of this allows RPs to inform end-users of these processes, the status of the accounts, what triggers them, and enables the RP to communicate any changes desired to the CSP.</p>
      </part>
    </control>
    <control id="ISDR-13">
      <title>Privacy Risk Policy</title>
      <prop name="label" class="index" value="3.1 #12"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-13_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for conducting privacy risk assessments, including the timing of its periodic reviews and specific conditions that will trigger an updated privacy risk assessment.</p>
      </part>
      <part id="ISDR-13_obj" name="objective">
        <p>Confirm the CSP has documented its policy for conducting risk assessments, including the timing of its periodic reviews and specific conditions that will trigger an updated privacy risk assessment.</p>
        <link href="#ISDR-13_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its risk assessment policies.</p>
      </part>
      <part id="ISDR-13_gdn" name="guidance">
        <p>Communicating this policy ensures that the RPs are aware of the privacy risks that could affect end-users, potentially communicate to them those results, and allows the RPs and CSP to work together on changes based on the results.</p>
      </part>
    </control>
    <control id="ISDR-14">
      <title>Customer Experience Assessment Policy</title>
      <prop name="label" class="index" value="3.1 #13"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-14_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for assessing customer experience, including the testing methods employed, timing of its periodic reviews, and any specific conditions that will trigger an out-of-cycle review.</p>
      </part>
      <part id="ISDR-14_obj" name="objective">
        <p>Confirm the CSP has a documented policy for assessing customer experience, including the testing methods employed, timing of its periodic reviews, and any specific conditions that will trigger an out-of-cycle review.</p>
        <link href="#ISDR-14_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policies for assessing customer experience.</p>
      </part>
      <part id="ISDR-14_gdn" name="guidance">
        <p>These procedures and the results of them can be used by the RP to determine if any changes need to be made to promote continuous improvement and address concerns, which ultimately improves the end-user experience.</p>
      </part>
    </control>
    <control id="ISDR-15">
      <title>Data Deletion Policy</title>
      <prop name="label" class="index" value="3.1 #14"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-15_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for the retention, protection, and deletion of all personal, sensitive, and biometric data, including the treatment of all such data if the CSP ceases operation or merges or transfers operations to another CSP.</p>
      </part>
      <part id="ISDR-15_obj" name="objective">
        <p>Confirm the CSP has documented policies for the retention, protection, and deletion of all personal, sensitive, and biometric data, including the treatment of all such data if the CSP ceases operation or merges or transfers operations to another CSP.</p>
        <link href="#ISDR-15_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its data management policies.</p>
      </part>
    </control>
    <control id="ISDR-16">
      <title>Continuous Assessment Policy</title>
      <prop name="label" class="index" value="3.1 #15"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-16_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for reporting and updating performance metrics.</p>
      </part>
      <part id="ISDR-16_obj" name="objective">
        <p>Confirm that the CSP has documented policies for reporting and updating performance metrics.</p>
        <link href="#ISDR-16_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policies for reporting and updating performance metrics.</p>
      </part>
      <part id="ISDR-16_gdn" name="guidance">
        <p>Meeting performance metrics starts with standardizing how it is reported and updated, as it is critical to RPs in being able to provide an adequate system and interface to the end-user, and communicate any changes as a result.</p>
      </part>
    </control>
    <control id="ISDR-17">
      <title>Digital Estate Policy</title>
      <prop name="label" class="index" value="3.1 #16"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-17_smt" name="statement">
        <p>The CSP's documented procedures SHALL include its policy for accessing or removing a subscriber's account in the event of their death or incapacitation.</p>
      </part>
      <part id="ISDR-17_obj" name="objective">
        <p>Confirm that the CSP has documented policies for the access or removal of a subscriber's account in the event of their death or incapacitation.</p>
        <link href="#ISDR-17_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its digital estate policies.</p>
      </part>
    </control>
    <control id="ISDR-18">
      <title>Documentation Availability</title>
      <prop name="label" class="index" value="3.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ISDR-18_smt" name="statement">
        <p>CSPs SHALL make their documented procedures or practice statements available to RPs that use their identity service.</p>
      </part>
      <part id="ISDR-18_obj" name="objective">
        <p>Confirm that the CSP makes its practices statement or other documentation available to the RPs that use its services.</p>
        <link href="#ISDR-18_smt" rel="assessment-for"/>
      </part>
      <part id="ISDR-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy on communicating its procedures with the RPs that use its service.</p>
      </part>
      <part id="ISDR-18_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview RPs to determine if the appropriate documentation has been made available.</p>
      </part>
      <part id="ISDR-18_gdn" name="guidance">
        <p>CSPs maintaining the transparency and availability of their statements and procedures creates a proactive environment between CSPs and RPs where the end-users are served.</p>
      </part>
    </control>
    <control id="FRAUD-1">
      <title>Fraud Mgmt Program</title>
      <prop name="label" class="index" value="3.2.1 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-1_smt" name="statement">
        <p>CSPs SHALL establish and maintain a fraud management program that provides fraud identification, detection, investigation, reporting, and resolution capabilities. The specific capabilities and details of this program SHALL be documented within their CSP practice statement.</p>
      </part>
      <part id="FRAUD-1_obj" name="objective">
        <p>Determine that CSPs proactively manage risks associated with fraud.</p>
        <link href="#FRAUD-1_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation for details about its fraud management program.</p>
      </part>
      <part id="FRAUD-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to obtain details about the CSP's fraud management program.</p>
      </part>
      <part id="FRAUD-1_gdn" name="guidance">
        <p>A critical aspect of the identity proofing process is to mitigate fraudulent attempts to gain access to benefits, services, data, or assets that are protected by identity management systems. Resolution, validation, and verification processes are designed to mitigate many types of attacks. However, with the constantly changing threat environment, layering additional checks and controls can provide increased confidence in proofing identities and additional protections against advanced and emerging types of attacks. The ability to identify, detect, and resolve instances of potential fraud is a critical functionality for CSPs and RPs.</p>
      </part>
    </control>
    <control id="FRAUD-2">
      <title>Fraud Privacy Risk Assessment</title>
      <prop name="label" class="index" value="3.2.1 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-2_smt" name="statement">
        <p>CSPs SHALL conduct a privacy risk assessment of all fraud checks and fraud mitigation technologies prior to implementation.</p>
      </part>
      <part id="FRAUD-2_obj" name="objective">
        <p>Determine that the CSP assesses the privacy risks associated with employing fraud management mechanisms.</p>
        <link href="#FRAUD-2_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented results of CSP's privacy risk assessment of the fraud checks and mitigation technologies it employs as part of its identity service.</p>
      </part>
    </control>
    <control id="FRAUD-3">
      <title>Fraud Self-Reporting</title>
      <prop name="label" class="index" value="3.2.1 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-3_smt" name="statement">
        <p>The CSP SHALL establish a self-reporting mechanism and investigation capability for subjects who believe they have been the victim of fraud or an attempt to compromise their involvement in the identity proofing processes.</p>
      </part>
      <part id="FRAUD-3_obj" name="objective">
        <p>Confirm that the CSP provides a mechanism for users to self-report if they believe they have been a victim of fraud or an attempt to compromise their involvement in the identity proofing process.</p>
        <link href="#FRAUD-3_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design document or documented procedures for details about how users can self-report potential fraud.</p>
      </part>
      <part id="FRAUD-3_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to obtain details about the CSP's fraud self-reporting mechanisms.</p>
      </part>
    </control>
    <control id="FRAUD-4">
      <title>High Risk Channels</title>
      <prop name="label" class="index" value="3.2.1 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-4_smt" name="statement">
        <p>CSPs SHALL analyze all remote proofing communication channels to look for high-risk indicators (e.g., blocklisted proxies and IP addresses).</p>
      </part>
      <part id="FRAUD-4_obj" name="objective">
        <p>Confirm that the CSP monitors ID proofing communication channels for indicators of fraud or attacks.</p>
        <link href="#FRAUD-4_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design documentation or its documented procedures to determine that it monitors and analyzes all remote ID proofing communication channels for evidence of fraudulent activity or attacks.</p>
      </part>
      <part id="FRAUD-4_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine how the CSP monitors its remote ID proofing channels for indicators of fraud or attacks.</p>
      </part>
    </control>
    <control id="FRAUD-5">
      <title>Data Washing</title>
      <prop name="label" class="index" value="3.2.1 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-5_smt" name="statement">
        <p>The CSP SHALL take measures to prevent unsuccessful applicants from inferring the accuracy of any self-asserted information with that confirmed by authoritative or credible sources.</p>
      </part>
      <part id="FRAUD-5_obj" name="objective">
        <p>Determine the measures a CSP takes to prevent attackers from determining the accuracy of self-asserted information that has been compared to authoritative or credible sources as part of the validation step.</p>
        <link href="#FRAUD-5_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design documentation or practices statement to determine the measures a CSP employs to prevent attackers from determining the accuracy of self-asserted information that has been compared to authoritative or credible sources as part of the validation step.</p>
      </part>
      <part id="FRAUD-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating an identity proofing session and self-asserting attributes. Confirm that no information is revealed that can aid in determining the accuracy of submitted attributes.</p>
      </part>
      <part id="FRAUD-5_gdn" name="guidance">
        <p>This is often called "data washing" and typically occurs when an attacker manipulates or cleans up stolen attribute information to make it appear legitimate by removing inconsistencies or red flags that might trigger fraud detection systems. Data washing can be prevented through a number of methods, depending on the interfaces deployed by a CSP. As such, these guidelines do not dictate specific mechanisms to prevent this practice.</p>
      </part>
    </control>
    <control id="FRAUD-6">
      <title>Fraud Check Monitoring</title>
      <prop name="label" class="index" value="3.2.1 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-6_smt" name="statement">
        <p>CSPs SHALL monitor the performance of their fraud checks and fraud mitigation technologies to ensure continued effectiveness in mitigating fraud risks.</p>
      </part>
      <part id="FRAUD-6_obj" name="objective">
        <p>Determine that the CSP monitors the effectiveness of their fraud mitigation measures in addressing new and changing types of fraud and attacks.</p>
        <link href="#FRAUD-6_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design documentation or other documentation to determine that the CSP monitors the performance of its fraud management measures.</p>
      </part>
      <part id="FRAUD-6_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine the CSP's approach to monitoring the effectiveness of its fraud management measures.</p>
      </part>
    </control>
    <control id="FRAUD-7">
      <title>Fraud Communication</title>
      <prop name="label" class="index" value="3.2.1 #7"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-7_smt" name="statement">
        <p>CSPs SHALL establish a technical or process-based mechanism to communicate suspected and confirmed fraudulent events to RPs.</p>
      </part>
      <part id="FRAUD-7_obj" name="objective">
        <p>Determine that the CSP has a process for communicating incidents of suspected or confirmed fraud to its RPs.</p>
        <link href="#FRAUD-7_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the CSP's process for communicating instances of suspected or confirmed fraud to its RPs.</p>
      </part>
      <part id="FRAUD-7_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine the CSP's process for communicating instances of suspected or confirmed fraud to its RPs.</p>
      </part>
    </control>
    <control id="FRAUD-8">
      <title>Death Records Check</title>
      <prop name="label" class="index" value="3.2.1 #8"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-8_smt" name="statement">
        <p>CSPs SHALL implement a death records check for all identity proofing processes by confirming with a credible, authoritative, or issuing source that the applicant is not deceased.</p>
      </part>
      <part id="FRAUD-8_obj" name="objective">
        <p>Determine that the CSP checks against a death record repository to confirm that an applicant is not claiming to be someone who has died.</p>
        <link href="#FRAUD-8_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine how the CSP conducts its death records check.</p>
      </part>
      <part id="FRAUD-8_gdn" name="guidance">
        <p>Death records are typically maintained by state and local vital records offices. The Social Security Administration (SSA) also collects and manages death information for its programs, but it does not hold comprehensive records of all deaths in the country. Checking against these repositories can aid in preventing synthetic identity fraud, the use of stolen identity information, and exploitation by a close associate or relative.</p>
      </part>
    </control>
    <control id="FRAUD-9">
      <title>Detect Fraud Indicators</title>
      <prop name="label" class="index" value="3.2.1 #12"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-9_smt" name="statement">
        <p>For attended proofing processes, CSPs SHALL train proofing agents to detect indicators of fraud and SHALL provide proofing agents and trusted referees with tools to flag suspected fraudulent events for further treatment and investigation.</p>
      </part>
      <part id="FRAUD-9_obj" name="objective">
        <p>[If a CSP provides an attended identity proofing process,] confirm that its agents are trained to detect potential fraud and are provided with mechanisms to flag incidents of suspected fraud.</p>
        <link href="#FRAUD-9_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP trains its agents to identify potential fraud and provides them with a way to flag suspected fraud for further investigation and treatment.</p>
      </part>
      <part id="FRAUD-9_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine how the CSP trains its agents to identify potential fraud and how it provides them with a way to flag suspected fraud for further investigation and treatment.</p>
      </part>
    </control>
    <control id="FRAUD-10">
      <title>Insider Threat Controls</title>
      <prop name="label" class="index" value="3.2.1 #13"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-10_smt" name="statement">
        <p>CSPs SHALL implement insider threat controls to detect and prevent collusion involving CSP representatives that are directly involved with or can intervene in proofing processes or decisions.</p>
      </part>
      <part id="FRAUD-10_obj" name="objective">
        <p>Determine that the CSP has implemented appropriate insider threat controls to help detect and prevent collusion.</p>
        <link href="#FRAUD-10_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine if the CSP employs insider threat controls to prevent collusion.</p>
      </part>
      <part id="FRAUD-10_gdn" name="guidance">
        <p>Collusion is possible whenever CSP representatives are directly involved in proofing processes or decisions.</p>
      </part>
    </control>
    <control id="FRAUD-11">
      <title>Compensating Controls</title>
      <prop name="label" class="index" value="3.2.1 #16"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-11_smt" name="statement">
        <p>If fraud mitigation measures are employed as compensating controls, they SHALL be documented as deviations from the normative guidance of these guidelines and SHALL be conveyed to all RPs through a Digital Identity Acceptance Statement (DIAS) prior to integration.</p>
      </part>
      <part id="FRAUD-11_obj" name="objective">
        <p>Determine if a CSP employs fraud mitigation measures as compensating controls, and if it does, determine that the CSP has documented these controls as deviations from the normative guidance of these guidelines and conveys this information to its RPs through a Digital Identity Acceptance Statement (DIAS).</p>
        <link href="#FRAUD-11_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or Digital Identity Acceptance Statement to determine that the CSP has documented any compensating controls and has a process for communicating these deviations to its CSPs through DIASs.</p>
      </part>
      <part id="FRAUD-11_gdn" name="guidance">
        <p>See SP 800-63-4, section 3.4.4, for more information about DIAS.</p>
      </part>
    </control>
    <control id="FRAUD-12">
      <title>AI and ML</title>
      <prop name="label" class="index" value="3.2.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-12_smt" name="statement">
        <p>CSPs that employ artificial intelligence (AI) or machine learning (ML) as part of their identity service SHALL adhere to the requirements provided in Sec. 3.8 of [SP800-63], as applicable.</p>
      </part>
      <part id="FRAUD-12_obj" name="objective">
        <p>Determine if the CSP employs AI or ML as part of its identity service and if it does, confirm that it adheres to all the requirements provided in Section 8 of NIST SP 800-63-4.</p>
        <link href="#FRAUD-12_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design documentation or other documentation to determine that any AI or ML it employs adheres to the requirements provided in Section 8 of NIST SP 800-63-4.</p>
      </part>
    </control>
    <control id="FRAUD-13">
      <title>Fraud POC</title>
      <prop name="label" class="index" value="3.2.2 #1"/>
      <prop name="marking" class="target" value="RPs"/>
      <prop name="marking" class="xal-level" value="RPs"/>
      <part id="FRAUD-13_smt" name="statement">
        <p>RPs SHALL establish a point of contact with whom CSPs can interact and communicate fraud data.</p>
      </part>
      <part id="FRAUD-13_obj" name="objective">
        <p>Confirm the RP has established a point of contact to receive fraud and other information from its CSPs.</p>
        <link href="#FRAUD-13_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example agreement or contract to determine that the RP has an identified point of contact (POC) to interact with and receive fraud and other information for CSPs.</p>
      </part>
      <part id="FRAUD-13_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine that the RP has an identified POC to interact with and receive fraud and other information for CSPs.</p>
      </part>
    </control>
    <control id="FRAUD-14">
      <title>Fraud PRA</title>
      <prop name="label" class="index" value="3.2.2 #2a"/>
      <prop name="marking" class="target" value="RPs"/>
      <prop name="marking" class="xal-level" value="RPs"/>
      <part id="FRAUD-14_smt" name="statement">
        <p>RPs SHALL conduct a privacy risk assessment (see Sec. 3.3.1) of any CSP fraud checks and mitigation technologies to identify potential privacy risks or unintended harms.</p>
      </part>
      <part id="FRAUD-14_obj" name="objective">
        <p>Determine that the RP has conducted a privacy risk assessment of all fraud checks or mitigations used by CSPs.</p>
        <link href="#FRAUD-14_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the results of the privacy risk assessment the RP conducted of all fraud checks and mitigations used by its CSPs.</p>
      </part>
    </control>
    <control id="FRAUD-15">
      <title>Fed Fraud PRA</title>
      <prop name="label" class="index" value="3.2.2 #2b"/>
      <prop name="marking" class="target" value="Federal Agency"/>
      <prop name="marking" class="xal-level" value="FedAgen"/>
      <part id="FRAUD-15_smt" name="statement">
        <p>Federal agency RPs SHALL implement the privacy risk assessment consistent with the requirements contained in Sec. 3.7.</p>
      </part>
      <part id="FRAUD-15_obj" name="objective">
        <p>Determine that the Federal agency RP has conducted a privacy risk assessment for all fraud checks and mitigations used by its CSPs in accordance with the requirements provided in section 3.7 of SP 800-63A-4.</p>
        <link href="#FRAUD-15_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented results of any privacy risk assessments conducted for fraud checks and mitigations used by its CSPs.</p>
      </part>
    </control>
    <control id="FRAUD-16">
      <title>Fraud Reviews</title>
      <prop name="label" class="index" value="3.2.2 #4"/>
      <prop name="marking" class="target" value="RPs"/>
      <prop name="marking" class="xal-level" value="RPs"/>
      <part id="FRAUD-16_smt" name="statement">
        <p>RPs SHALL conduct periodic reviews of their CSP's fraud management program, fraud checks, and fraud technologies to adjust thresholds, review investigations into fraud events, and evaluate the effectiveness and efficacy of fraud controls.</p>
      </part>
      <part id="FRAUD-16_obj" name="objective">
        <p>Confirm the RP conducts periodic re-reviews of its fraud management program activities to ensure its ongoing effectiveness against existing and emerging risks and threats.</p>
        <link href="#FRAUD-16_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented process and results of any periodic reviews and assessments of the RPs' fraud management program and activities.</p>
      </part>
      <part id="FRAUD-16_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel for information about the RPs' ongoing reviews and assessments of its fraud management program activities.</p>
      </part>
    </control>
    <control id="FRAUD-17">
      <title>Risk Tolerance</title>
      <prop name="label" class="index" value="3.2.2 #5a"/>
      <prop name="marking" class="target" value="RPs"/>
      <prop name="marking" class="xal-level" value="RPs"/>
      <part id="FRAUD-17_smt" name="statement">
        <p>RPs SHALL review all fraud mitigation measures that have been deployed as compensating or supplemental controls by CSPs to align with their internal risk tolerance and acceptance.</p>
      </part>
      <part id="FRAUD-17_obj" name="objective">
        <p>Determine that the RP has reviewed and accepted all risks associated with fraud mitigation measures employed by its CSP as compensating controls and confirmed they align with the RP's own risk acceptance profile.</p>
        <link href="#FRAUD-17_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented results of any reviews of the risks associated with any fraud mitigation measures used as compensating controls by its CSPs.</p>
      </part>
      <part id="FRAUD-17_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine that the RP has reviewed and accepted the risks associated with any fraud mitigation measures used as compensating controls by its CSPs.</p>
      </part>
    </control>
    <control id="FRAUD-18">
      <title>RP DIAS</title>
      <prop name="label" class="index" value="3.2.2 #5b"/>
      <prop name="marking" class="target" value="RPs"/>
      <prop name="marking" class="xal-level" value="RPs"/>
      <part id="FRAUD-18_smt" name="statement">
        <p>The RP SHALL record the CSP's compensating controls in their own DIAS prior to integration.</p>
      </part>
      <part id="FRAUD-18_obj" name="objective">
        <p>Determine if the CSP employs any compensating controls and, if so, determine that the RP as included the controls from the CSP's DIAS into its own DIAS.</p>
        <link href="#FRAUD-18_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's DIAS to determine if it has integrated compensating controls from the CSP's DIAS into its own DIAS.</p>
      </part>
      <part id="FRAUD-18_gdn" name="guidance">
        <p>From NIST SP 800-63-4: Organizations SHALL develop a Digital Identity Acceptance Statement (DIAS) to document the results of the DIRM process for (i) each online service managed by the organization, and (ii) each external online service used to support the mission of the organization, including software-as-a-service offerings (e.g., social media platforms, email services, online marketing services). RPs who intend to use a particular CSP/IdP SHALL review the latter's DIAS and incorporate relevant information into the organization's DIAS for each online service.</p>
      </part>
    </control>
    <control id="FRAUD-19">
      <title>Fraud Check Practices</title>
      <prop name="label" class="index" value="3.2.3 #1"/>
      <prop name="marking" class="target" value="RPs"/>
      <prop name="marking" class="xal-level" value="RPs"/>
      <part id="FRAUD-19_smt" name="statement">
        <p>CSPs SHALL establish and document actions and practices related to each of their fraud checks and provide these actions and practices to RPs.</p>
      </part>
      <part id="FRAUD-19_obj" name="objective">
        <p>Confirm that the CSP has established and documented actions and practices associated with its fraud checks, and that it communicates this information to its RPs.</p>
        <link href="#FRAUD-19_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-19_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practice statements and/or other documentation to determine that the CSP has established and documented actions and practices associated with its fraud checks, and that it communicates this information to its RPs.</p>
      </part>
    </control>
    <control id="FRAUD-20">
      <title>Redress</title>
      <prop name="label" class="index" value="3.2.3 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-20_smt" name="statement">
        <p>CSPs SHALL establish procedures for redress to allow applicants to resolve issues associated with fraud checks and mitigation technologies.</p>
      </part>
      <part id="FRAUD-20_obj" name="objective">
        <p>Determine that the CSP has established redress procedures specific to issues associated with its fraud checks and mitigation measures.</p>
        <link href="#FRAUD-20_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-20_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm it provides a way for applicants to seek redress to resolve issues associated with the CSP's fraud checks or other fraud mitigation measures.</p>
      </part>
      <part id="FRAUD-20_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine how the CSP provides a way for applicants to seek redress to resolve issues associated with the CSP's fraud checks or other fraud mitigation measures.</p>
      </part>
      <part id="FRAUD-20_gdn" name="guidance">
        <p>See Sec. 3.6 of [SP800-63] for more information about redress.</p>
      </part>
    </control>
    <control id="FRAUD-21">
      <title>Failed Fraud Checks</title>
      <prop name="label" class="index" value="3.2.3 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FRAUD-21_smt" name="statement">
        <p>If trusted referees are offered to applicants who fail fraud checks in unattended remote processes, the trusted referees SHALL be provided with a summary of the results of the fraud failures to inform their risk-based decision-making processes.</p>
      </part>
      <part id="FRAUD-21_obj" name="objective">
        <p>Determine if the CSP offers Trusted Referee services to applicants who fail fraud checks and, if it does, confirm that these Trusted Referees are provided with the results of the fraud checks.</p>
        <link href="#FRAUD-21_smt" rel="assessment-for"/>
      </part>
      <part id="FRAUD-21_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it provides the results of any failed fraud checks for an applicant to Trusted Referees.</p>
      </part>
      <part id="FRAUD-21_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview Trusted Referees to confirm that they are provided with the results of any failed fraud checks for an applicant.</p>
      </part>
      <part id="FRAUD-21_gdn" name="guidance">
        <p>The CSP SHOULD offer trusted referee services to applicants who fail fraud checks in unattended remote processes.</p>
      </part>
    </control>
    <control id="PRIVACY-1">
      <title>Privacy Risk Assessment</title>
      <prop name="label" class="index" value="3.3 #1a"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-1_smt" name="statement">
        <p>The CSP SHALL conduct and document a privacy risk assessment for the processes used for identity proofing and enrollment.</p>
      </part>
      <part id="PRIVACY-1_obj" name="objective">
        <p>Determine that the CSP has conducted a privacy risk assessment of its identity service processes.</p>
        <link href="#PRIVACY-1_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the results of the CSP's privacy risk assessment.</p>
      </part>
      <part id="PRIVACY-1_gdn" name="guidance">
        <p>For more information about privacy risk assessments, refer to the NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management at https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.01162020.pdf.</p>
      </part>
    </control>
    <control id="PRIVACY-2">
      <title>Min Privacy Risk Assessment Requirements</title>
      <prop name="label" class="index" value="3.3.1 #1b"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-2_smt" name="statement">
        <p>At a minimum, the privacy risk assessment SHALL assess the risks associated with:</p>
        <p>(a) Processing personal information for the purposes of identity proofing, enrollment, or fraud management, including identity attributes, biometrics, images, video, scans, or copies of identity evidence.</p>
        <p>(b) Additional steps that the CSP takes to verify the identity of an applicant beyond the mandatory requirements specified herein.</p>
        <p>(c) Processing of personal information for purposes outside of the scope of identity proofing and enrollment, except to comply with law or legal processes.</p>
        <p>(d) The retention schedule for identity records and personal information.</p>
        <p>(e) Processing non-personal information that could be used to identify a person when aggregated or processed by an algorithm.</p>
        <p>(f) Personal information that is processed by a third-party service on behalf of the CSP.</p>
      </part>
      <part id="PRIVACY-2_obj" name="objective">
        <p>Determine that the CSP has assessed the privacy risks associated with all the aspects of its identity service, as specified in item #1 of section 3.3.1.</p>
        <link href="#PRIVACY-2_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the results of the CSP's privacy risk assessment.</p>
      </part>
    </control>
    <control id="PRIVACY-3">
      <title>Privacy Mgmt</title>
      <prop name="label" class="index" value="3.3.1 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-3_smt" name="statement">
        <p>Based on the results of its privacy risk assessment, the CSP SHALL document the measures it takes to maintain the disassociability, predictability, manageability, confidentiality, integrity, and availability of any personal information it collects or processes.</p>
      </part>
      <part id="PRIVACY-3_obj" name="objective">
        <p>Determine that the CSP has documented the measures it takes to manage its privacy risks, as identified by the CSP's privacy risk assessment.</p>
        <link href="#PRIVACY-3_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's privacy risk or other documentation to determine what measures it takes to manage its privacy risks.</p>
      </part>
      <part id="PRIVACY-3_gdn" name="guidance">
        <p>NIST IR 8062 provides an overview of predictability, manageability, and disassociability, including examples of how these objectives can be met.</p>
      </part>
    </control>
    <control id="PRIVACY-4">
      <title>Reassess Privacy Risks</title>
      <prop name="label" class="index" value="3.3.1 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-4_smt" name="statement">
        <p>The CSP SHALL reassess privacy risks and update its privacy risk assessment any time it makes changes to its identity service that affect the processing of personal information.</p>
      </part>
      <part id="PRIVACY-4_obj" name="objective">
        <p>Determine that the CSP has a policy and/or procedure for reassessing its associated privacy risks anytime changes to its identity service affect the processing of personal information.</p>
        <link href="#PRIVACY-4_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it has a policy and/or procedure for reassessing its associated privacy risks anytime changes to its identity service affect the processing of personal information.</p>
      </part>
    </control>
    <control id="PRIVACY-5">
      <title>PIA Review</title>
      <prop name="label" class="index" value="3.3.1 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-5_smt" name="statement">
        <p>The CSP SHALL review its privacy risk assessment periodically, as documented in its practice statement, to ensure that it accurately reflects the current risks associated with the collection and processing of personal information.</p>
      </part>
      <part id="PRIVACY-5_obj" name="objective">
        <p>Determine that the CSP reviews its privacy risk assessment process and/or results to ensure that it accurately reflects the current privacy risks associated with operating its identity service.</p>
        <link href="#PRIVACY-5_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other document to determine that it has a policy or procedure for periodically reviewing its privacy risk assessment process and/or results.</p>
      </part>
    </control>
    <control id="PRIVACY-6">
      <title>PIA Summary</title>
      <prop name="label" class="index" value="3.3.1 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-6_smt" name="statement">
        <p>The CSP SHALL make a summary of its privacy risk assessment available to any RPs that use its services. The summary SHALL be in sufficient detail to enable such RPs to make reasonable determinations about privacy risks associated with the CSP's services and to complete their own privacy risk assessments.</p>
      </part>
      <part id="PRIVACY-6_obj" name="objective">
        <p>Determine that the CSP has a process for communicating summarized results of its privacy risk assessment to its RPs and that such summaries are in sufficient detail to allow those RPs to determine if the risks of using the CSP's identity services are acceptable.</p>
        <link href="#PRIVACY-6_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's privacy risk or other documentation, such as agreements or contracts, to determine how it communicates the results of its risk assessment to the RPs that use its services.</p>
      </part>
    </control>
    <control id="PRIVACY-7">
      <title>Sub Account PIA</title>
      <prop name="label" class="index" value="3.3.1 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-7_smt" name="statement">
        <p>The CSP SHALL perform a privacy risk assessment for the processing of any personal information maintained in subscriber accounts.</p>
      </part>
      <part id="PRIVACY-7_obj" name="objective">
        <p>Determine that the CSP performed a privacy risk assessment of its subscriber accounts.</p>
        <link href="#PRIVACY-7_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's privacy risk or other documentation to determine it has conducted a privacy risk assessment of its subscriber accounts.</p>
      </part>
    </control>
    <control id="PRIVACY-8">
      <title>Min Personal Info</title>
      <prop name="label" class="index" value="3.3.2 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-8_smt" name="statement">
        <p>The processing of personal information SHALL be limited to the minimum necessary to validate the existence of the claimed identity, associate the claimed identity with the applicant, mitigate fraud, and provide RPs with attributes that they may use to make authorization decisions.</p>
      </part>
      <part id="PRIVACY-8_obj" name="objective">
        <p>Determine that the CSP applies the privacy-protecting principle of data minimization.</p>
        <link href="#PRIVACY-8_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement, privacy risk documentation, or other documentation to determine that the CSP limits the personal information it collects to the minimum necessary.</p>
      </part>
    </control>
    <control id="PRIVACY-9">
      <title>Privacy Training</title>
      <prop name="label" class="index" value="3.3.2 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-9_smt" name="statement">
        <p>The CSP SHALL provide privacy training to all personnel and any third-party service providers who have access to sensitive information associated with the CSP's identity service.</p>
      </part>
      <part id="PRIVACY-9_obj" name="objective">
        <p>Determine that the CSP provides privacy training to all its personnel and to those third-party service providers who have access to any personal or sensitive information associated with the CSP's identity service operations.</p>
        <link href="#PRIVACY-9_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's applicable documentation to determine that it provides privacy training to all its personnel and to any third-parties that have access to personal information processed by the CSP's identity service.</p>
      </part>
    </control>
    <control id="PRIVACY-10">
      <title>SSN Collection</title>
      <prop name="label" class="index" value="3.3.2 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-10_smt" name="statement">
        <p>[If the SSN is collected on behalf of a federal, state, or local government agency,] the CSP SHALL provide notice to the applicant for the collection in accordance with applicable laws.</p>
      </part>
      <part id="PRIVACY-10_obj" name="objective">
        <p>Determine if the CSP collects SSNs, and if it does, confirm that it provides notice to the applicant for the collection.</p>
        <link href="#PRIVACY-10_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it provides notice to applicants for the collection in accordance with applicable laws if the CSP collects a social security number (SSN) from applicants.</p>
      </part>
      <part id="PRIVACY-10_gdn" name="guidance">
        <p>The CSP MAY collect a Social Security number (SSN) as an attribute when necessary for identity resolution. Knowledge of an SSN is not sufficient to act as evidence of identity, nor is it considered an acceptable method of verifying possession of the Social Security card when used as evidence.</p>
      </part>
    </control>
    <control id="PRIVACY-11">
      <title>Explicit Notice</title>
      <prop name="label" class="index" value="3.3.2 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVACY-11_smt" name="statement">
        <p>At the time of collection, the CSP SHALL provide explicit notice to the applicant regarding the purpose for collecting any attributes and personal information. Such a notice SHALL include whether the personal information and attributes are voluntary or mandatory to complete the identity proofing process; the specific attributes and other sensitive data that the CSP intends to store in the applicant's subsequent subscriber account; the consequences of not providing the attributes; and the details of any records retention requirement if one is in place, including an applicant's right to request data deletion or engage in other forms of redress.</p>
      </part>
      <part id="PRIVACY-11_obj" name="objective">
        <p>Determine that the CSP provides explicit notice to the applicant for the collection of attributes and personal information and that such notice includes all the elements provided in item #4 of section 3.3.2.</p>
        <link href="#PRIVACY-11_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVACY-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a sample of the notice the CSP provides to applicants for the collection of personal information.</p>
      </part>
    </control>
    <control id="CUSTOMER-1">
      <title>CX Challenges</title>
      <prop name="label" class="index" value="3.4 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CUSTOMER-1_smt" name="statement">
        <p>The CSP SHALL assess the elements of its identity proofing processes to identify processes or technologies that can result in customer experience challenges, particularly if those challenges prevent the CSP from consistently delivering identity proofing services to all users served by an RP.</p>
      </part>
      <part id="CUSTOMER-1_obj" name="objective">
        <p>Determine that the CSP has assessed its identity proofing process and identified any potential customer experience challenges.</p>
        <link href="#CUSTOMER-1_smt" rel="assessment-for"/>
      </part>
      <part id="CUSTOMER-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP has assessed its identity service for potential customer experience challenges.</p>
      </part>
      <part id="CUSTOMER-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine that the CSP has assessed its identity service for potential customer experience challenges.</p>
      </part>
      <part id="CUSTOMER-1_gdn" name="guidance">
        <p>CSPs assess the elements of their identity services to identify processes and technologies that may result in customer experience challenges for the populations they serve. If risks to customer experience are identified, CSPs proactively employ mitigations that will reduce or eliminate these issues consistent with their assurance levels and risk posture.</p>
      </part>
    </control>
    <control id="CUSTOMER-2">
      <title>CX Assessments</title>
      <prop name="label" class="index" value="3.4 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CUSTOMER-2_smt" name="statement">
        <p>CSPs SHALL provide RPs with a summary of their customer experience assessments that includes information about common challenges or issues faced by users.</p>
      </part>
      <part id="CUSTOMER-2_obj" name="objective">
        <p>Determine that the CSP has a process for communicating the results of its customer experience assessments to the RPs that use its service.</p>
        <link href="#CUSTOMER-2_smt" rel="assessment-for"/>
      </part>
      <part id="CUSTOMER-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine how the CSP communicates the results of its customer experience assessment to its RPs.</p>
      </part>
    </control>
    <control id="CUSTOMER-3">
      <title>CX Mitigations</title>
      <prop name="label" class="index" value="3.4 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CUSTOMER-3_smt" name="statement">
        <p>Based on the results of its assessment, the CSP SHALL document any measures it takes to mitigate the possible access challenges.</p>
      </part>
      <part id="CUSTOMER-3_obj" name="objective">
        <p>Determine that the CSP has documented any measures it takes to mitigate the potential customer experience challenges it identified through its customer experience assessment.</p>
        <link href="#CUSTOMER-3_smt" rel="assessment-for"/>
      </part>
      <part id="CUSTOMER-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine any measures it takes to mitigate the potential customer experience challenges it identified through its customer experience assessment.</p>
      </part>
    </control>
    <control id="CUSTOMER-4">
      <title>Periodic CX Reassessment</title>
      <prop name="label" class="index" value="3.4 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CUSTOMER-4_smt" name="statement">
        <p>The CSP SHALL reassess the customer experience risks periodically and any time the CSP makes changes to its identity service that affect the processes or technologies that impact customer experience.</p>
      </part>
      <part id="CUSTOMER-4_obj" name="objective">
        <p>Determine that the CSP periodically reassesses its customer experience risks (challenges) and any time it makes changes to its identity service that could impact the customer experience.</p>
        <link href="#CUSTOMER-4_smt" rel="assessment-for"/>
      </part>
      <part id="CUSTOMER-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its stated policy or practice of reassessing customer experience challenges and risks associated with its identity services.</p>
      </part>
    </control>
    <control id="CUSTOMER-5">
      <title>Applicant Participation</title>
      <prop name="label" class="index" value="3.4 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CUSTOMER-5_smt" name="statement">
        <p>The CSP SHALL NOT make applicant participation in these risk assessments mandatory.</p>
      </part>
      <part id="CUSTOMER-5_obj" name="objective">
        <p>Confirm that the CSP does not make applicant participation in customer experience risk assessments mandatory.</p>
        <link href="#CUSTOMER-5_smt" rel="assessment-for"/>
      </part>
      <part id="CUSTOMER-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm its policy on applicant participation in customer experience risk assessments. Test the customer experience risk assessment workflow.</p>
      </part>
    </control>
    <control id="SECURITY-1">
      <title>Protected Channel</title>
      <prop name="label" class="index" value="3.5 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECURITY-1_smt" name="statement">
        <p>Each online transaction within the identity proofing process, including transactions that involve third parties, SHALL occur over an authenticated, protected channel.</p>
      </part>
      <part id="SECURITY-1_obj" name="objective">
        <p>Determine that all communications are protected by approved cryptography.</p>
        <link href="#SECURITY-1_smt" rel="assessment-for"/>
      </part>
      <part id="SECURITY-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's identity service design document or other documentation, to determine that all communications occur via authenticated, protected channels.</p>
      </part>
      <part id="SECURITY-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test identity service transactions to determine that they are protected by approved cryptography.</p>
      </part>
      <part id="SECURITY-1_gdn" name="guidance">
        <p>An authenticated protected channel is an encrypted communication channel that uses approved cryptography in which the connection initiator (client) has authenticated the recipient (server). Authenticated protected channels are encrypted to provide confidentiality and protection against active intermediaries and are frequently used in the user authentication process. Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) [RFC9325] are examples of authenticated protected channels in which the certificate presented by the recipient is verified by the initiator. Unless otherwise specified, authenticated protected channels do not require the server to authenticate the client. Authentication of the server is often accomplished through a certificate chain that leads to a trusted root rather than individually with each server.</p>
      </part>
    </control>
    <control id="SECURITY-2">
      <title>Auto Attack Protections</title>
      <prop name="label" class="index" value="3.5 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECURITY-2_smt" name="statement">
        <p>The CSP SHALL implement automated attack protections for the identity proofing process, such as bot detection, mitigation, and management solutions; behavioral analytics; web application firewall settings; and network traffic analysis.</p>
      </part>
      <part id="SECURITY-2_obj" name="objective">
        <p>Confirm that the CSP has identified which automated attacks its identity service is vulnerable to and has implemented appropriate attack detection mechanisms.</p>
        <link href="#SECURITY-2_smt" rel="assessment-for"/>
      </part>
      <part id="SECURITY-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's identity service design document, or other documentation, to determine that it employs appropriate automated attack detection mechanisms.</p>
      </part>
      <part id="SECURITY-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test whether the identity service is able to detect automated attacks.</p>
      </part>
      <part id="SECURITY-2_gdn" name="guidance">
        <p>Behavioral analytics in this context is used to determine whether an interaction is indicative of an automated attack and not an effort to identify or authenticate a specific user based on a captured reference template for that user.</p>
      </part>
    </control>
    <control id="SECURITY-3">
      <title>Data Protection</title>
      <prop name="label" class="index" value="3.5 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECURITY-3_smt" name="statement">
        <p>All personal information that is collected as part of the identity proofing process SHALL be protected to maintain the confidentiality and integrity of the information, including the encryption of data at rest and the exchange of information using authenticated, protected channels.</p>
      </part>
      <part id="SECURITY-3_obj" name="objective">
        <p>Determine that the CSP protects all identity service data.</p>
        <link href="#SECURITY-3_smt" rel="assessment-for"/>
      </part>
      <part id="SECURITY-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's identity service design document, certification information, or other documentation, to determine that it employs data protection mechanisms for data at rest and during transmission.</p>
      </part>
    </control>
    <control id="SECURITY-4">
      <title>Risk Assessment</title>
      <prop name="label" class="index" value="3.5 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECURITY-4_smt" name="statement">
        <p>The CSP SHALL assess the information security and privacy risks associated with operating its identity service, according to the NIST Risk Management Framework or equivalent risk management guidelines. At a minimum, the CSP SHALL apply appropriate controls consistent with the NIST SP 800-53 moderate baseline, regardless of IAL.</p>
      </part>
      <part id="SECURITY-4_obj" name="objective">
        <p>Determine that the CSP has conducted a risk assessment and that it employs appropriate security controls consistent with the NIST SP 800-53 MODERATE baseline or greater.</p>
        <link href="#SECURITY-4_smt" rel="assessment-for"/>
      </part>
      <part id="SECURITY-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's risk assessment results document, or other documentation, to confirm it has conducted a security risk assessment.</p>
      </part>
      <part id="SECURITY-4_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's identity service design document, certification information, or other documentation, to determine if it employs MODERATE baseline controls or greater.</p>
      </part>
    </control>
    <control id="SECURITY-5">
      <title>Third-Party Risk</title>
      <prop name="label" class="index" value="3.5 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECURITY-5_smt" name="statement">
        <p>The CSP SHALL assess risks associated with its use of third-party services and apply appropriate controls, as provided in the Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.</p>
      </part>
      <part id="SECURITY-5_obj" name="objective">
        <p>Determine that the CSP has assessed the risks associated with its user of third-party services and has applied appropriate controls.</p>
        <link href="#SECURITY-5_smt" rel="assessment-for"/>
      </part>
      <part id="SECURITY-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the results of the CSP's supply chain risk assessment.</p>
      </part>
    </control>
    <control id="REDIP-1">
      <title>Redress Mechanisms</title>
      <prop name="label" class="index" value="3.6 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REDIP-1_smt" name="statement">
        <p>The CSP SHALL provide mechanisms for the redress of applicant complaints and problems that arise from the identity proofing process, including proofing failures; delays; difficulties; and the recovery of a compromised subscriber account (e.g., as a result of a scam or fraud).</p>
      </part>
      <part id="REDIP-1_obj" name="objective">
        <p>Determine that the CSP provides a mechanism for applicants to seek redress for errors or harms associated with their use of the CSP's identity service.</p>
        <link href="#REDIP-1_smt" rel="assessment-for"/>
      </part>
      <part id="REDIP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement, or other documentation, to determine its redress mechanism(s).</p>
      </part>
      <part id="REDIP-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine the CSP's redress mechanism(s).</p>
      </part>
      <part id="REDIP-1_gdn" name="guidance">
        <p>See section 3.6 of NIST SP 800-63-4 for more information about redress.</p>
      </part>
    </control>
    <control id="REDIP-2">
      <title>Easy Redress</title>
      <prop name="label" class="index" value="3.6 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REDIP-2_smt" name="statement">
        <p>These redress mechanisms SHALL be easy for applicants to find and use.</p>
      </part>
      <part id="REDIP-2_obj" name="objective">
        <p>Determine that the CSP's redress mechanisms are easy to find and use.</p>
        <link href="#REDIP-2_smt" rel="assessment-for"/>
      </part>
      <part id="REDIP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's website to determine how easy it is to find information about its redress process.</p>
      </part>
    </control>
    <control id="REDIP-3">
      <title>Redress Efficacy</title>
      <prop name="label" class="index" value="3.6 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REDIP-3_smt" name="statement">
        <p>The CSP SHALL assess the mechanisms for their efficacy in achieving a resolution of complaints or problems.</p>
      </part>
      <part id="REDIP-3_obj" name="objective">
        <p>Determine that the CSP assesses its redress process and mechanisms to confirm they are effective.</p>
        <link href="#REDIP-3_smt" rel="assessment-for"/>
      </part>
      <part id="REDIP-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement, or other documentation, to determine that it assesses the efficacy of its redress process.</p>
      </part>
    </control>
    <control id="FED-1">
      <title>SAOP Consult</title>
      <prop name="label" class="index" value="3.7 #1"/>
      <prop name="marking" class="target" value="Federal Agency"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FED-1_smt" name="statement">
        <p>The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) to determine whether the collection of personal information, including biometrics, to conduct identity proofing triggers Privacy Act requirements.</p>
      </part>
      <part id="FED-1_obj" name="objective">
        <p>Confirm that the Federal Agency has consulted with its SAOP to determine if the collection of personal information in association with the use of the identity service triggers Privacy Act requirements.</p>
        <link href="#FED-1_smt" rel="assessment-for"/>
      </part>
      <part id="FED-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the Federal Agency's documentation to determine if it has consulted with its SAOP whether its use of an identity service triggers requirements under the Privacy Act.</p>
      </part>
      <part id="FED-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine whether the Federal Agency has consulted with is SAOP whether its use of an identity service triggers requirements under the Privacy Act.</p>
      </part>
    </control>
    <control id="FED-2">
      <title>E-Gov Act</title>
      <prop name="label" class="index" value="3.7 #2"/>
      <prop name="marking" class="target" value="Federal Agency"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FED-2_smt" name="statement">
        <p>The agency SHALL consult with their SAOP to determine whether the collection of personal information, including biometrics, to conduct identity proofing triggers E-Government Act of 2002 requirements.</p>
      </part>
      <part id="FED-2_obj" name="objective">
        <p>Confirm that the Federal Agency has consulted with its SAOP to determine if the collection of personal information in association with the use of the identity service triggers E-Government Act of 2002 requirements.</p>
        <link href="#FED-2_smt" rel="assessment-for"/>
      </part>
      <part id="FED-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the Federal Agency's documentation to determine if it has consulted with its SAOP whether its use of an identity service triggers requirements under the E-Government Act of 2002.</p>
      </part>
      <part id="FED-2_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine whether the Federal Agency has consulted with is SAOP and whether its use of an identity service triggers requirements under the E-Government Act of 2002.</p>
      </part>
    </control>
    <control id="FED-3">
      <title>SORN</title>
      <prop name="label" class="index" value="3.7 #3"/>
      <prop name="marking" class="target" value="Federal Agency"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FED-3_smt" name="statement">
        <p>The agency SHALL publish a System of Records Notice (SORN) to cover such collections, as applicable.</p>
      </part>
      <part id="FED-3_obj" name="objective">
        <p>Determine that the Federal Agency has  published a SORN, as applicable, for its use of an identity service.</p>
        <link href="#FED-3_smt" rel="assessment-for"/>
      </part>
      <part id="FED-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the Federal Agency's documentation to determine that it has published a SORN for its identity service(s).</p>
      </part>
      <part id="FED-3_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine that it has published a SORN for its identity service(s).</p>
      </part>
      <part id="FED-3_gdn" name="guidance">
        <p>For more information about SORNs, see OPM's System of Records Notice (SORN) Guide(https://www.opm.gov/information-management/privacy-policy/privacy-references/sornguide.pdf).</p>
      </part>
    </control>
    <control id="FED-4">
      <title>Fed PIA</title>
      <prop name="label" class="index" value="3.7 #4"/>
      <prop name="marking" class="target" value="Federal Agency"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FED-4_smt" name="statement">
        <p>The agency SHALL publish a Privacy Impact Assessment (PIA) to cover such collections, as applicable.</p>
      </part>
      <part id="FED-4_obj" name="objective">
        <p>Determine that the Federal Agency has conducted a PIA for its identity service.</p>
        <link href="#FED-4_smt" rel="assessment-for"/>
      </part>
      <part id="FED-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the Federal Agency's PIA document to determine if it has conducted a privacy assessment of its identity service(s).</p>
      </part>
    </control>
    <control id="FED-5">
      <title>PIA Input</title>
      <prop name="label" class="index" value="3.7 #6"/>
      <prop name="marking" class="target" value="Federal Agency"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FED-5_smt" name="statement">
        <p>If the agency uses a third-party CSP, the agency SHALL conduct its own PIA and use the CSP's privacy risk assessment as input.</p>
      </part>
      <part id="FED-5_obj" name="objective">
        <p>Determine if the Federal Agency uses a third-party CSP and, if it does, confirm it has conducted a PIA and included the CSP's PIA as an input.</p>
        <link href="#FED-5_smt" rel="assessment-for"/>
      </part>
      <part id="FED-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the agency PIA documentation to determine it has included the results of the CSP's privacy assessment into its own PIA.</p>
      </part>
    </control>
    <control id="CONFIRM-1">
      <title>Confirm Codes</title>
      <prop name="label" class="index" value="3.8 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONFIRM-1_smt" name="statement">
        <p>Confirmation codes SHALL include at least 6 decimal digits (or equivalent) from an approved random bit generator (see Sec. 3.2.12 of SP800-63B).</p>
      </part>
      <part id="CONFIRM-1_obj" name="objective">
        <p>Determine if the CSP uses confirmation codes and, if it does, confirm that these codes are comprised of at least 6 digits (or equivalent) from a random bit generator.</p>
        <link href="#CONFIRM-1_smt" rel="assessment-for"/>
      </part>
      <part id="CONFIRM-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its confirmation codes include at least 6 decimal digits (or equivalent) from an approved random bit generator.</p>
      </part>
      <part id="CONFIRM-1_gdn" name="guidance">
        <p>Confirmation codes are used to confirm that an applicant has access to a postal address, email address, or phone number for the purposes of future communications.</p>
        <p>A random bit generator (RGB) is a device or algorithm that can produce a sequence of bits that appear to be both statistically independent and unbiased.</p>
      </part>
    </control>
    <control id="CONFIRM-2">
      <title>Confirm Code Validity</title>
      <prop name="label" class="index" value="3.8 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONFIRM-2_smt" name="statement">
        <p>Confirmation codes SHALL be valid for at most 21 days when sent to a validated postal address within the contiguous United States; 30 days when sent to a validated postal address outside of the contiguous United States; 10 minutes when sent to a validated telephone number (SMS or voice); and 24 hours when sent to a validated email address.</p>
      </part>
      <part id="CONFIRM-2_obj" name="objective">
        <p>Determine if the CSP uses confirmation codes and, if it does, confirm that they meet the validity requirements specified in section 3.8.</p>
        <link href="#CONFIRM-2_smt" rel="assessment-for"/>
      </part>
      <part id="CONFIRM-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its confirmation codes meet the validity requirements specified in Section 3.8.</p>
      </part>
    </control>
    <control id="CONFIRM-3">
      <title>Invalidate Confirm Code</title>
      <prop name="label" class="index" value="3.8 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONFIRM-3_smt" name="statement">
        <p>Upon its use, the CSP SHALL invalidate the confirmation code.</p>
      </part>
      <part id="CONFIRM-3_obj" name="objective">
        <p>Determine if the CSP uses confirmation codes and, if it does, confirm the codes are invalidated upon use.</p>
        <link href="#CONFIRM-3_smt" rel="assessment-for"/>
      </part>
      <part id="CONFIRM-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine confirmation codes are invalidated upon use.</p>
      </part>
      <part id="CONFIRM-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting confirmation codes and attempting to use them after their validity period has expired.</p>
      </part>
    </control>
    <control id="CONTINUE-1">
      <title>Continue Codes</title>
      <prop name="label" class="index" value="3.9 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONTINUE-1_smt" name="statement">
        <p>Continuation codes SHALL include at least 64 bits from an approved random bit generator (see Sec. 3.2.12 of [SP800-63B]).</p>
      </part>
      <part id="CONTINUE-1_obj" name="objective">
        <p>Determine if the CSP uses continuation codes and, if it does, confirm that these codes are comprised of at least 64 bits from a random bit generator.</p>
        <link href="#CONTINUE-1_smt" rel="assessment-for"/>
      </part>
      <part id="CONTINUE-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its confirmation codes include at least 64 bits from an approved random bit generator.</p>
      </part>
      <part id="CONTINUE-1_gdn" name="guidance">
        <p>Continuation codes are used to reestablish an applicant's linkage to an incomplete identity proofing or enrollment process. The continuation code provides a temporary secret that can connect one session to another.</p>
        <p>A random bit generator (RGB) is a device or algorithm that can produce a sequence of bits that appear to be both statistically independent and unbiased.</p>
      </part>
    </control>
    <control id="CONTINUE-2">
      <title>Continue Code Throttling</title>
      <prop name="label" class="index" value="3.9 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONTINUE-2_smt" name="statement">
        <p>The verification of continuation codes SHALL be subject to throttling requirements, as provided in Sec. 3.2.2 of [SP800-63B].</p>
      </part>
      <part id="CONTINUE-2_obj" name="objective">
        <p>Determine if the CSP uses continuation codes and, if it does, confirm that the use of these codes is subject to throttling requirements provided in NIST SP 800-63B-4, Sec. 3.2.2.</p>
        <link href="#CONTINUE-2_smt" rel="assessment-for"/>
      </part>
      <part id="CONTINUE-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the use of continuation codes is subject to the throttling requirements provided in NIST SP 9800-63B-4 Sec. 3.2.2.</p>
      </part>
      <part id="CONTINUE-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to submit invalid continuation codes at a rate that would trigger throttling requirements.</p>
      </part>
      <part id="CONTINUE-2_gdn" name="guidance">
        <p>In the case of continuation codes, throttling is a mechanism that limits the number of failed attempts at entering a continuation code.</p>
      </part>
    </control>
    <control id="CONTINUE-3">
      <title>Hashed Continue Codes</title>
      <prop name="label" class="index" value="3.9 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONTINUE-3_smt" name="statement">
        <p>Continuation codes SHALL be stored in hashed form using a Federal Information Processing Standards (FIPS)-approved or NIST-recommended one-way function.</p>
      </part>
      <part id="CONTINUE-3_obj" name="objective">
        <p>Determine if the CSP uses continuation codes and, if it does, confirm that these codes are stored in hashed form, as specified in item #5 of Sec. 3.9.</p>
        <link href="#CONTINUE-3_smt" rel="assessment-for"/>
      </part>
      <part id="CONTINUE-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that these codes are stored in hashed form, as specified in item #5 of Sec. 3.9.</p>
      </part>
    </control>
    <control id="CONTINUE-4">
      <title>Invalidate Continue Code</title>
      <prop name="label" class="index" value="3.9 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONTINUE-4_smt" name="statement">
        <p>Upon its use, the CSP SHALL invalidate the continuation code.</p>
      </part>
      <part id="CONTINUE-4_obj" name="objective">
        <p>Determine if the CSP uses continuation codes and, if it does, confirm that the codes are invalidated upon use.</p>
        <link href="#CONTINUE-4_smt" rel="assessment-for"/>
      </part>
      <part id="CONTINUE-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that these codes are invalidated upon use.</p>
      </part>
      <part id="CONTINUE-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting several continuation codes and attempting to use them after their validity period has expired.</p>
      </part>
      <part id="CONTINUE-4_gdn" name="guidance">
        <p>Since substantial time may elapse between when an applicant receives their continuation code and when they are able to complete the proofing process, expiry is not defined in these guidelines. Expiry will need to be defined by the CSP based on their processes, technologies, and partnerships.</p>
      </part>
    </control>
    <control id="NOTIFS-1">
      <title>Validated Addresses</title>
      <prop name="label" class="index" value="3.10 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="NOTIFS-1_smt" name="statement">
        <p>Notifications of proofing SHALL be sent to a validated postal address or phone number at all IALs or MAY be sent to a validated email address at IAL1.</p>
      </part>
      <part id="NOTIFS-1_obj" name="objective">
        <p>Confirm that the CSP sends notifications of proofing at IALs 2 and 3 to validated postal addresses or phone numbers.</p>
        <link href="#NOTIFS-1_smt" rel="assessment-for"/>
      </part>
      <part id="NOTIFS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that, for IALs 2 or 3, it only sends notifications of proofing to validated postal addresses and/or phone numbers.</p>
      </part>
      <part id="NOTIFS-1_gdn" name="guidance">
        <p>Notifications of proofing are sent to the applicant's validated address to inform them that they have been successfully identity-proofed and provide them with information about the identity proofing event and subsequent enrollment. Additionally, the notification explains how the recipient can dispute their involvement in the identity proofing events. Per Sec. 2.4.2.3, validated postal addresses or phone numbers are those that have been confirmed (validated) with an authoritative source or credible source, such as a mobile network operator or AAMVA.</p>
      </part>
    </control>
    <control id="NOTIFS-2">
      <title>ID Proofing Details</title>
      <prop name="label" class="index" value="3.10 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="NOTIFS-2_smt" name="statement">
        <p>Notifications of proofing SHALL include details about the identity proofing event, including the name of the identity service and the date on which the identity proofing was completed.</p>
      </part>
      <part id="NOTIFS-2_obj" name="objective">
        <p>Confirm that the CSP includes appropriate details about the identity proofing event in its notifications of proofing.</p>
        <link href="#NOTIFS-2_smt" rel="assessment-for"/>
      </part>
      <part id="NOTIFS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of the CSP's notification of proofing to determine it includes adequate details about the identity proofing event.</p>
      </part>
    </control>
    <control id="NOTIFS-3">
      <title>Repudiation Instructions</title>
      <prop name="label" class="index" value="3.10 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="NOTIFS-3_smt" name="statement">
        <p>Notifications of proofing SHALL provide clear instructions, including contact information, on actions for the recipient to take if they repudiate their participation in the identity proofing event.</p>
      </part>
      <part id="NOTIFS-3_obj" name="objective">
        <p>Confirm that the CSP's notifications of proofing include clear instructions for how recipients can deny their participation in an identity proofing event with the CSP.</p>
        <link href="#NOTIFS-3_smt" rel="assessment-for"/>
      </part>
      <part id="NOTIFS-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of the CSP's notification of proofing to determine it includes clear and easy-to-follow instructions to the recipient for repudiating their participation in the identity proofing event with the CSP.</p>
      </part>
    </control>
    <control id="NOTIFS-4">
      <title>Security Protections</title>
      <prop name="label" class="index" value="3.10 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="NOTIFS-4_smt" name="statement">
        <p>Notifications of proofing SHALL provide information about how the organization or CSP protects the security and confidentiality of the information it collects.</p>
      </part>
      <part id="NOTIFS-4_obj" name="objective">
        <p>Confirm that the CSP's notifications of proofing include information about how it protects the security and confidentiality of the recipient's personal information.</p>
        <link href="#NOTIFS-4_smt" rel="assessment-for"/>
      </part>
      <part id="NOTIFS-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of the CSP's notification of proofing to determine it includes information about how the CSP protects the security and confidentiality of the information it collects and processes.</p>
      </part>
    </control>
    <control id="NOTIFS-5">
      <title>Subscriber Responsibilities</title>
      <prop name="label" class="index" value="3.10 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="NOTIFS-5_smt" name="statement">
        <p>Notifications of proofing SHALL provide information about any responsibilities that the recipient has as a subscriber of the identity service.</p>
      </part>
      <part id="NOTIFS-5_obj" name="objective">
        <p>Confirm that the CSP's notifications of proofing include information about any responsibilities that the recipient has as a subscriber of the identity service.</p>
        <link href="#NOTIFS-5_smt" rel="assessment-for"/>
      </part>
      <part id="NOTIFS-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of the CSP's notification of proofing to determine it includes information about any responsibilities that the recipient has as a subscriber of the identity service.</p>
      </part>
      <part id="NOTIFS-5_gdn" name="guidance">
        <p>Examples of subscriber responsibilities may be to not share their account information with anyone else or to report any suspected fraud associated with their account to the CSP as soon as possible.</p>
      </part>
    </control>
    <control id="NOTIFS-6">
      <title>Subscriber Repudiation Response</title>
      <prop name="label" class="index" value="3.10 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="NOTIFS-6_smt" name="statement">
        <p>If a subscriber repudiates having been identity-proofed by the identity service, the CSP or RP SHALL respond in accordance with its established fraud management and redress policies.</p>
      </part>
      <part id="NOTIFS-6_obj" name="objective">
        <p>Confirm that the CSP or RP has a defined policy for responding to subscriber repudiations.</p>
        <link href="#NOTIFS-6_smt" rel="assessment-for"/>
      </part>
      <part id="NOTIFS-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's or RP's policies or other documentation to determine if it has a defined policy for responding to situations where a subscriber repudiates having been identity proofed by the CSP.</p>
      </part>
    </control>
    <control id="BIO-1">
      <title>Bio Disclosure</title>
      <prop name="label" class="index" value="3.11 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-1_smt" name="statement">
        <p>CSPs SHALL provide clear, publicly available information about all uses of biometrics, including what biometric data is collected, how it is stored and protected, and how to remove biometric data consistent with applicable laws and regulations.</p>
      </part>
      <part id="BIO-1_obj" name="objective">
        <p>Confirm that the CSP discloses complete information about its uses of biometrics in a way that is clear and understandable to the general public.</p>
        <link href="#BIO-1_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy about publicly disclosing information about its uses of biometrics.</p>
      </part>
      <part id="BIO-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's website and user facing privacy policies to confirm biometric disclosure is addressed.</p>
      </part>
    </control>
    <control id="BIO-2">
      <title>Bio Consent</title>
      <prop name="label" class="index" value="3.11 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-2_smt" name="statement">
        <p>CSPs SHALL obtain explicit informed consent to collect and use biometrics from all applicants.</p>
      </part>
      <part id="BIO-2_obj" name="objective">
        <p>Confirm that the CSP obtains informed consent from applicants prior to the collection and use of their biometric attributes.</p>
        <link href="#BIO-2_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy about obtaining consent from applicants prior to collecting and using biometrics.</p>
      </part>
      <part id="BIO-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's identity proofing workflow to determine how it obtains consent from applicants prior to collecting and using biometrics.</p>
      </part>
    </control>
    <control id="BIO-3">
      <title>Stored Consent</title>
      <prop name="label" class="index" value="3.11 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-3_smt" name="statement">
        <p>CSPs SHALL store a record of the subscriber's consent for biometric use and associate it with the subscriber's account.</p>
      </part>
      <part id="BIO-3_obj" name="objective">
        <p>Confirm that the CSP stores a record of the subscriber's consent for biometric use and that it is associated with the subscriber's account.</p>
        <link href="#BIO-3_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for associating a record of the subscriber's consent for biometric use with their account.</p>
      </part>
      <part id="BIO-3_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine and test the subscriber account to determine that it includes a record of the subscriber's consent for biometric use.</p>
      </part>
    </control>
    <control id="BIO-4">
      <title>BIO Deletion Process</title>
      <prop name="label" class="index" value="3.11 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-4_smt" name="statement">
        <p>CSPs SHALL have a documented and publicly available deletion process and default retention period for all biometric information. Retention periods SHALL be consistent with applicable regulations, policies, and statutes for the regions and sectors that the CSP serves.</p>
      </part>
      <part id="BIO-4_obj" name="objective">
        <p>Determine the applicable biometric retention regulations, policies, and statutes applicable to the CSP's identity service and confirm that the CSP has documented and made publicly available its process and default retention period(s) for all biometric information, in accordance with these requirements.</p>
        <link href="#BIO-4_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine 1) which regulations, policies, and statutes are applicable to its identity service and 2) that it has documented and made publicly available its deletion process and default retention period(s) for all biometric information.</p>
      </part>
      <part id="BIO-4_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's website to confirm that information about the availability of deletion processes are available to the public.</p>
      </part>
    </control>
    <control id="BIO-5">
      <title>Non-Deletion Justification</title>
      <prop name="label" class="index" value="3.11 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-5_smt" name="statement">
        <p>If a CSP does not support biometric deletion requests, it SHALL publicly document the regulatory, statutory, or risk-based justification for their policy.</p>
      </part>
      <part id="BIO-5_obj" name="objective">
        <p>If the CSP DOES NOT support biometric deletion request, confirm that it has publicly disclosed the regulatory, statutory, and risk-based justification for their policy.</p>
        <link href="#BIO-5_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's public notice justifying why it does not support biometric deletion requests.</p>
      </part>
      <part id="BIO-5_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's website to confirm it includes an explanation as to why it does not support biometric deletion requests.</p>
      </part>
      <part id="BIO-5_gdn" name="guidance">
        <p>CSPs SHOULD support the deletion of all of a subscriber's biometric information upon the subscriber's request, except where otherwise restricted by regulation, law, or policy.</p>
      </part>
    </control>
    <control id="BIO-6">
      <title>Biometric Algorithm Testing</title>
      <prop name="label" class="index" value="3.11 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-6_smt" name="statement">
        <p>CSPs SHALL have their biometric recognition and attack detection algorithms periodically tested by independent entities for their performance characteristics, including performance across demographic groups.</p>
      </part>
      <part id="BIO-6_obj" name="objective">
        <p>Confirm that the CSP periodically employs independent organizations to test its biometric algorithms testing for their performance characteristics, including performance across demographic groups.</p>
        <link href="#BIO-6_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine: 1) that it employs independent organizations to test its biometric algorithms, and 2) how often or under what conditions it employs these organizations.</p>
      </part>
      <part id="BIO-6_gdn" name="guidance">
        <p>In addition, the CSP SHOULD conduct internal testing on biometric algorithms based on the update schedule of the provider.(Ref.Sec.3.11 #6A)</p>
      </part>
    </control>
    <control id="BIO-7">
      <title>Demographic Impacts</title>
      <prop name="label" class="index" value="3.11 #7A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-7_smt" name="statement">
        <p>CSPs SHALL assess the performance and demographic impacts of employed biometric technologies in conditions that are substantially similar to the operational environment and user base of the system.</p>
      </part>
      <part id="BIO-7_obj" name="objective">
        <p>Confirm that the CSP assesses the performance of any employed biometric technologies under conditions that are substantially similar to the operational environment and the user base(s) of the identity service.</p>
        <link href="#BIO-7_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the conditions under which it assesses the performance of its employed biometric technologies.</p>
      </part>
      <part id="BIO-7_gdn" name="guidance">
        <p>The user base is defined by both the expected users and the devices they are expected to use.</p>
      </part>
    </control>
    <control id="BIO-8">
      <title>Voluntary Participation</title>
      <prop name="label" class="index" value="3.11 #7B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-8_smt" name="statement">
        <p>When biometric performance assessments include real-world users, participation by users SHALL be voluntary.</p>
      </part>
      <part id="BIO-8_obj" name="objective">
        <p>Determine if the CSP's biometric performance assessments include real-world users and, if so, confirm that participation by these users is entirely voluntary.</p>
        <link href="#BIO-8_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for assessing biometric performance using real-world users.</p>
      </part>
    </control>
    <control id="BIO-9">
      <title>1:1 Comparison Performance</title>
      <prop name="label" class="index" value="3.11 #8"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-9_smt" name="statement">
        <p>CSPs SHALL meet the following performance thresholds if one-to-one (1:1) comparison algorithms are used for verification against a claimed identity: false match rate: 1:10,000 or better; and false non-match rate: 1:100 or better.</p>
      </part>
      <part id="BIO-9_obj" name="objective">
        <p>Determine if the CSP employs 1:1 comparison algorithms as part of the identity verification process and, if it does, confirm the algorithms meet the required performance thresholds.</p>
        <link href="#BIO-9_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's biometric testing results to determine that the performance of 1:1 biometric comparison algorithms meet or surpass the required thresholds.</p>
      </part>
    </control>
    <control id="BIO-10">
      <title>1:N Minimum Performance</title>
      <prop name="label" class="index" value="3.11 #9"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-10_smt" name="statement">
        <p>If a CSP uses one-to-many (1:N) scenarios, it SHALL meet a minimum performance threshold for false positive identification of 1:1,000 or better.</p>
      </part>
      <part id="BIO-10_obj" name="objective">
        <p>Determine if the CSP employs 1:N identification and, if it does, confirm the algorithms meet or surpass the stated performance threshold.</p>
        <link href="#BIO-10_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's biometric testing results to determine that use of any 1:N scenarios meet or surpass the stated performance threshold.</p>
      </part>
      <part id="BIO-10_gdn" name="guidance">
        <p>CSPs MAY use one-to-many (1:N) identification in support of resolution or deduplication, pursuant to a privacy risk assessment.</p>
      </part>
    </control>
    <control id="BIO-11">
      <title>FPIR Test Gallery</title>
      <prop name="label" class="index" value="3.11 #10"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-11_smt" name="statement">
        <p>Tests that demonstrate this requirement SHALL employ a gallery no smaller than 90% of the current or intended operational size (N).</p>
      </part>
      <part id="BIO-11_obj" name="objective">
        <p>Confirm that the tests the CSP uses to test FPIR for 1:N comparisons employs a gallery of at least 90% of the current intended operational size (N).</p>
        <link href="#BIO-11_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's biometric testing procedures and results to determine that the tests to determine the FPIR for 1:N comparisons employs a gallery of at least 90% of the current intended operational size (N).</p>
      </part>
      <part id="BIO-11_gdn" name="guidance">
        <p>A 1:N search of an applicant's collected biometric characteristics against a database is done to determine whether the applicant is already present in the database, possibly under a different name. The false positive identification rate (FPIR) refers to the proportion of 1:N searches in which a biometric system incorrectly identifies another person as a match, which is a false positive result. The performance metric of 1:1,000 means that a false positive outcome occurs for no more than 1 in every 1,000 searches.</p>
      </part>
    </control>
    <control id="BIO-12">
      <title>1:N Manual Review</title>
      <prop name="label" class="index" value="3.11 #11"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-12_smt" name="statement">
        <p>CSPs that make use of 1:N biometric identification for resolution, deduplication, or fraud detection purposes SHALL NOT decline a user's enrollment without a manual review to confirm the automated search results and confirm that the results are not a false positive identification.</p>
      </part>
      <part id="BIO-12_obj" name="objective">
        <p>If a CSP employs 1:N biometric identification, confirm that it does not decline a user's enrollment into an identity service based on a positive 1:N comparison match.</p>
        <link href="#BIO-12_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP employs a manual review of any positive 1:N matches.</p>
      </part>
      <part id="BIO-12_gdn" name="guidance">
        <p>One possible reason for a false positive result is twins submitting face photographs for different accounts with the same CSP.</p>
      </part>
    </control>
    <control id="BIO-13">
      <title>Demographic Performance</title>
      <prop name="label" class="index" value="3.11 #12A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-13_smt" name="statement">
        <p>Biometric verification technologies SHALL provide performance for applicants of different demographic types that is no more than 25% worse than the performance for the overall population.</p>
      </part>
      <part id="BIO-13_obj" name="objective">
        <p>Confirm that the CSP employs biometric verification technologies that have been tested across different demographic groups and whose demonstrated performance differences do not exceed 25%.</p>
        <link href="#BIO-13_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's biometric testing results to determine the performance characteristics of any biometric verification technologies across  demographic groups.</p>
      </part>
      <part id="BIO-13_gdn" name="guidance">
        <p>For example, if the measured false nonmatch rate (FNMR) for the overall population is 0.006, the FNMR for a specific demographic group cannot exceed 0.0075. Similarly, if the false match rate (FMR) for the overall population is 0.0001, the FMR for each demographic group cannot exceed 0.000125.</p>
      </part>
    </control>
    <control id="BIO-14">
      <title>Biometric Threshold</title>
      <prop name="label" class="index" value="3.11 #12B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-14_smt" name="statement">
        <p>The biometric system SHALL be configured with a fixed threshold; it is not feasible to change the threshold for each demographic group.</p>
      </part>
      <part id="BIO-14_obj" name="objective">
        <p>Confirm that the CSP employs a biometric threshold that is consistent across all demographic groups.</p>
        <link href="#BIO-14_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that the biometric threshold is fixed and consistent across all demographic groups.</p>
      </part>
    </control>
    <control id="BIO-15">
      <title>Demographic Categories</title>
      <prop name="label" class="index" value="3.11 #12C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-15_smt" name="statement">
        <p>Demographic categories to be considered SHALL include sex, age, and skin tone when these factors affect biometric performance.</p>
      </part>
      <part id="BIO-15_obj" name="objective">
        <p>Confirm that the CSP considers sex, age, and skin tone as  demographic categories for its biometric performance testing.</p>
        <link href="#BIO-15_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that its biometric performance testing includes categories for sex, age, and skin tone.</p>
      </part>
    </control>
    <control id="BIO-16">
      <title>Biometric Testing Standards</title>
      <prop name="label" class="index" value="3.11 #13A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-16_smt" name="statement">
        <p>All biometric performance tests SHALL be conformant to ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024, including demographics testing.</p>
      </part>
      <part id="BIO-16_obj" name="objective">
        <p>Confirm that all biometric performance testing, including demographics testing, employed by the CSP adheres to ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024.</p>
        <link href="#BIO-16_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine  the CSP's biometric test procedures to determine all its biometric performance testing adheres to ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024.</p>
      </part>
    </control>
    <control id="BIO-17">
      <title>Testing Results Availability</title>
      <prop name="label" class="index" value="3.11 #14"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-17_smt" name="statement">
        <p>CSPs SHALL make the results of their biometric algorithm performance and biometric system operational test results publicly available.</p>
      </part>
      <part id="BIO-17_obj" name="objective">
        <p>Confirm that the CSP makes the results of its biometric algorithm performance and biometric system operational test publicly available.</p>
        <link href="#BIO-17_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it makes the results of all its biometric systems testing publicly available.</p>
      </part>
      <part id="BIO-17_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a public website or other platform where the CSP has made the results of all biometric systems testing available.</p>
      </part>
      <part id="BIO-17_gdn" name="guidance">
        <p>The CSP MAY provide these test results in summary form if the results indicate performance against the defined metrics in these guidelines and across the tested demographic groups.</p>
      </part>
    </control>
    <control id="BIO-18">
      <title>Reasonable Assurance</title>
      <prop name="label" class="index" value="3.11 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-18_smt" name="statement">
        <p>If a CSP collects biometric samples from applicants, it SHALL collect them in a way that provides reasonable assurance that the biometric characteristic is collected from the applicant and not another subject.</p>
      </part>
      <part id="BIO-18_obj" name="objective">
        <p>Determine if the CSP collects biometric samples from applicants and, if it does, confirm that it has employed mechanisms to increase the assurance that the sample is being collected from the applicant and not a different subject.</p>
        <link href="#BIO-18_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that it employs mechanisms, such as liveness detection and presentation attack detection, to increase the assurance that the sample being collected is from the applicant and not another subject.</p>
      </part>
      <part id="BIO-18_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the biometric collection system by employing a spoofing attack.</p>
      </part>
      <part id="BIO-18_gdn" name="guidance">
        <p>Mechanisms that mitigate risks associated with biometric collection fraud include liveness detection, and digital injection and other types of presentation attack detection (such as mechanisms to detect the presence of a foreign object).</p>
      </part>
    </control>
    <control id="BIO-19">
      <title>Remote Biometric Collection</title>
      <prop name="label" class="index" value="3.11 #2a"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-19_smt" name="statement">
        <p>When collecting and comparing biometric characteristics remotely, the CSP SHALL implement presentation attack detection (PAD) capabilities that meet the impostor attack presentation accept rate (IAPAR) performance metric of &lt;0.07 to confirm the genuine presence of a live human being and to mitigate spoofing and impersonation attempts.</p>
      </part>
      <part id="BIO-19_obj" name="objective">
        <p>Confirm that the CSP has employed PAD capabilities that meet the specified IAPAR performance metric for its remote biometric collection or comparison functions.</p>
        <link href="#BIO-19_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-19_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's PAD testing results to determine that any remote biometric collection and comparison functions meet the specific IAPAR performance metric.</p>
      </part>
    </control>
    <control id="BIO-20">
      <title>PAD Tests</title>
      <prop name="label" class="index" value="3.11 #2b"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-20_smt" name="statement">
        <p>All biometric presentation attack detection tests SHALL be conformant to ISO/IEC 30107-3:2023.</p>
      </part>
      <part id="BIO-20_obj" name="objective">
        <p>Confirm that all biometric PAD tests employed by the CSP conform to ISO/IEC 30107-3:2023.</p>
        <link href="#BIO-20_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-20_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's PAD testing procedures to determine that its biometric PAD tests conform to ISO/IEC 30107-3:2023.</p>
      </part>
    </control>
    <control id="BIO-21">
      <title>On-Site Biometric Collection</title>
      <prop name="label" class="index" value="3.11 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BIO-21_smt" name="statement">
        <p>When collecting biometric characteristics on-site, the CSP SHALL have the operator view the biometric source (e.g., fingers, face) for the presence of unexpected non-natural materials and perform such inspections as part of the proofing process.</p>
      </part>
      <part id="BIO-21_obj" name="objective">
        <p>Confirm that, for on-site biometric collection as part of the identity proofing process, human agents of the CSP examine the source of the biometric (e.g., fingers, face) for the presence of any unexpected, non-natural materials.</p>
        <link href="#BIO-21_smt" rel="assessment-for"/>
      </part>
      <part id="BIO-21_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that, for during on-site identity proofing processes, it has human operators view the source of any collected biometrics for the source of unexpected foreign materials.</p>
      </part>
    </control>
    <control id="VISUAL-1">
      <title>Image Comparison Training</title>
      <prop name="label" class="index" value="3.12 #1A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-1_smt" name="statement">
        <p>Proofing agents and trusted referees SHALL be trained to conduct visual facial image comparison.</p>
      </part>
      <part id="VISUAL-1_obj" name="objective">
        <p>Confirm that the CSP trains its proofing agents and trusted referees in how to effectively conduct visual comparisons of facial images.</p>
        <link href="#VISUAL-1_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the training it provides to its agents that conduct visual comparison of facial images.</p>
      </part>
      <part id="VISUAL-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents or trusted referees to determine the training they received on the visual comparison of facial images.</p>
      </part>
    </control>
    <control id="VISUAL-2">
      <title>Visual Match Training</title>
      <prop name="label" class="index" value="3.12 #1B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-2_smt" name="statement">
        <p>This training SHALL include techniques and methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence.</p>
      </part>
      <part id="VISUAL-2_obj" name="objective">
        <p>Confirm that the training the CSP provides for its proofing agents and trusted referees includes methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence.</p>
        <link href="#VISUAL-2_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that its proofing agents and trusted referees have been trained in methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence.</p>
      </part>
      <part id="VISUAL-2_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents or trusted referees to determine that they have been trained in methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence.</p>
      </part>
    </control>
    <control id="VISUAL-3">
      <title>Agent Assessment</title>
      <prop name="label" class="index" value="3.12 #2A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-3_smt" name="statement">
        <p>Proofing agents and trusted referees SHALL be assessed on their ability to conduct visual facial image comparisons.</p>
      </part>
      <part id="VISUAL-3_obj" name="objective">
        <p>Confirm that the CSP assesses its proofing agents and trusted referees on their ability to conduct visual facial image comparisons.</p>
        <link href="#VISUAL-3_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it assesses its proofing agents and/or trusted referees on their ability to conduct visual facial image comparisons.</p>
      </part>
      <part id="VISUAL-3_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents or trusted referees to determine that they have been assessed on their ability to conduct visual facial image comparisons.</p>
      </part>
    </control>
    <control id="VISUAL-4">
      <title>Annual Reassessment</title>
      <prop name="label" class="index" value="3.12 #2B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-4_smt" name="statement">
        <p>Additionally, proofing agents and trusted referees SHALL be reassessed on an annual basis and remedially trained, if needed.</p>
      </part>
      <part id="VISUAL-4_obj" name="objective">
        <p>Confirm that the CSP annually reassesses its proofing agents and trusted referees on their ability to conduct visual facial image comparisons and provides remedial training, if needed.</p>
        <link href="#VISUAL-4_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for annually reassessing, and remedially training if needed, its proofing agents and/or trusted referees on their ability to conduct visual facial image comparisons.</p>
      </part>
    </control>
    <control id="VISUAL-5">
      <title>Attack Training</title>
      <prop name="label" class="index" value="3.12 #2C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-5_smt" name="statement">
        <p>Training SHALL be designed to reflect potential real-world attack scenarios, such as comparing applicants to images of relatives, twins, and individuals with a similar appearance.</p>
      </part>
      <part id="VISUAL-5_obj" name="objective">
        <p>Confirm that the CSP designs its visual image comparison training to address real-world scenarios that might result in incorrect visual comparison determinations.</p>
        <link href="#VISUAL-5_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that it has designed its visual image comparison training to reflect potential real-world scenarios.</p>
      </part>
    </control>
    <control id="VISUAL-6">
      <title>Visual Comparison Resources</title>
      <prop name="label" class="index" value="3.12 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-6_smt" name="statement">
        <p>CSPs SHALL provide proofing agents and trusted referees that conduct visual facial comparisons during remote attended transactions with resources that support accurate comparisons, such as high-quality image feeds, high-definition monitors, and image analysis software.</p>
      </part>
      <part id="VISUAL-6_obj" name="objective">
        <p>Confirm that the CSP provides its proofing agents and trusted referees that conduct visual facial comparisons during remote transactions with resources that support the accuracy of those comparisons.</p>
        <link href="#VISUAL-6_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it provides its agents with resources that support the accurate visual comparison of facial images during remote transactions.</p>
      </part>
      <part id="VISUAL-6_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents or trusted referees to determine that the CSP has provided them with resources that support the accurate visual comparison of facial images during remote transactions.</p>
      </part>
    </control>
    <control id="VISUAL-7">
      <title>Documented Training Procedures</title>
      <prop name="label" class="index" value="3.12 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-7_smt" name="statement">
        <p>CSPs SHALL document their training and assessment procedures for visual image comparisons and make them available to RPs upon request.</p>
      </part>
      <part id="VISUAL-7_obj" name="objective">
        <p>Confirm that the CSP has documented its visual image comparison training and assessment procedures and makes them available to their RPs upon request.</p>
        <link href="#VISUAL-7_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it has documented its training and assessment procedures for its agents that perform visual image comparisons AND its policy for providing this information to its RPs if requested.</p>
      </part>
      <part id="VISUAL-7_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of the information it provides to RPs about its visual image comparison training and assessment procedures.</p>
      </part>
    </control>
    <control id="VISUAL-8">
      <title>Manual Review Training</title>
      <prop name="label" class="index" value="3.12 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VISUAL-8_smt" name="statement">
        <p>These requirements SHALL apply for visual facial image comparisons done as manual reviews for failures of automated biometric comparisons (e.g., failure of 1:N checks conducted for resolution or deduplication).</p>
      </part>
      <part id="VISUAL-8_obj" name="objective">
        <p>Confirm that the CSP trains and assesses its proofing agents and trusted referees who conduct manual reviews for failures of automated biometric comparisons, in accordance with the requirements provided in Sec. 3.12.</p>
        <link href="#VISUAL-8_smt" rel="assessment-for"/>
      </part>
      <part id="VISUAL-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it trains and assesses its proofing agents and trusted referees who conduct manual reviews for failures of automated biometric comparisons, in accordance with the requirements provided in Sec. 3.12.</p>
      </part>
      <part id="VISUAL-8_gdn" name="guidance">
        <p>Also see Sec. 3.11 #11 and Sec. 3.15.2 #2.</p>
      </part>
    </control>
    <control id="PHYS-1">
      <title>Auto Evidence Validation</title>
      <prop name="label" class="index" value="3.13 A #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-1_smt" name="statement">
        <p>Automated evidence validation technology SHALL meet the following performance measures: document false acceptance rate (DFAR) of 0.1 or less; and document false rejection rate (DFRR) of 0.1 or less.</p>
      </part>
      <part id="PHYS-1_obj" name="objective">
        <p>If the CSP employs automated evidence validation technology, confirm that it meets the specified performance metrics.</p>
        <link href="#PHYS-1_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's evidence validation technology testing results to confirm that any automated evidence validation technology it employs meets the following performance metrics: document false acceptance rate (DFAR) of 0.1 or less; and document false rejection rate (DFRR) of 0.1 or less.</p>
      </part>
      <part id="PHYS-1_gdn" name="guidance">
        <p>For the purposes of this document, the DFAR is the proportion of processed, fraudulent documents that the document validation system determined to be valid divided by the number of processed fraudulent documents. For the purposes of this document, DFRR is the proportion of processed, genuine documents that the document validation system determined to be invalid divided by the number of processed genuine documents.</p>
      </part>
    </control>
    <control id="PHYS-2">
      <title>MRZ Data</title>
      <prop name="label" class="index" value="3.13 A #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-2_smt" name="statement">
        <p>If a Machine Readable Zone (MRZ) or barcode is present on the evidence, the optical capture and inspection SHALL compare the MRZ data to the printed data on the evidence for consistency.</p>
      </part>
      <part id="PHYS-2_obj" name="objective">
        <p>For evidence with MRZs or barcodes, confirm that the CSP employs optical capture and inspection capabilities that compare the MRZ data with the printed data on the evidence.</p>
        <link href="#PHYS-2_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that it employs optical capture and inspection capabilities that are able to compare evidence MRZ data to printed data.</p>
      </part>
      <part id="PHYS-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSPs implemented evidence validation technology to confirm it compares the MRZ to the printed data.</p>
      </part>
    </control>
    <control id="PHYS-3">
      <title>Live Document Capture</title>
      <prop name="label" class="index" value="3.13 A #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-3_smt" name="statement">
        <p>CSPs SHALL implement live capture of documents during the validation process and SHALL implement passive or active document presence checks (also called document liveness).</p>
      </part>
      <part id="PHYS-3_obj" name="objective">
        <p>Confirm that the CSP employs live capture of documents during its validation process and that the live capture capabilities include document presence checks.</p>
        <link href="#PHYS-3_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that it employs the live capture capabilities, including document presence checks.</p>
      </part>
      <part id="PHYS-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSPs evidence validation technologies to confirm that only live capture of documents is used and that images cannot be directly uploaded to the service.</p>
      </part>
      <part id="PHYS-3_gdn" name="guidance">
        <p>Live capture techniques confirm that the document is physically present and that the image captured during the identity proofing session is not a manipulated digital copy. For additional requirements to prevent the injection of modified media (i.e., digitally generated video or images of evidence), see Sec. 3.14.</p>
      </part>
    </control>
    <control id="PHYS-4">
      <title>Optical Capture Peformance 1</title>
      <prop name="label" class="index" value="3.13 A #4a"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-4_smt" name="statement">
        <p>CSPs SHALL assess the performance of employed optical capture and inspection technologies in conditions that are substantially similar to the operational environment and the types of evidence presented by the user base of the system.</p>
      </part>
      <part id="PHYS-4_obj" name="objective">
        <p>Confirm that the CSP assesses the performance of any employed optical capture and inspection technologies under conditions that are substantially similar to the operational environment and the types of evidence presented by the user base of the system.</p>
        <link href="#PHYS-4_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the conditions under which it assesses the performance of any employed optical capture and inspection technologies.</p>
      </part>
    </control>
    <control id="PHYS-5">
      <title>Optical Capture Peformance 2</title>
      <prop name="label" class="index" value="3.13 A #4b"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-5_smt" name="statement">
        <p>These tests SHALL account for all available identity evidence types that the CSPs allow to be validated using optical capture and inspection technology.</p>
      </part>
      <part id="PHYS-5_obj" name="objective">
        <p>Confirm that the CSP's optical capture and inspection performance testing incorporates all the types of evidence it accepts to be validated using optical capture and inspection capabilities.</p>
        <link href="#PHYS-5_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the types of evidence it includes in its performance assessments of optical capture and inspection technologies.</p>
      </part>
    </control>
    <control id="PHYS-6">
      <title>Optical Capture Peformance 3</title>
      <prop name="label" class="index" value="3.13 A #4c"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-6_smt" name="statement">
        <p>If subscribers' documents, personal information, or images are used as part of the testing, it SHALL be on a voluntary basis and with subscriber notification and consent.</p>
      </part>
      <part id="PHYS-6_obj" name="objective">
        <p>If the CSP uses documents, personal information, or images belonging to real users as part of its image capture performance testing, confirm that participation by the user is entirely voluntary and that the CSP first provides notification to the user and obtains their consent.</p>
        <link href="#PHYS-6_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy on using documents, personal information, and/or images from real users as part of its image capture performance testing.</p>
      </part>
      <part id="PHYS-6_gdn" name="guidance">
        <p>These requirements apply to technologies that capture and validate images of physical identity evidence. They do not apply to validation techniques that rely on PKI or other cryptographic technologies that are embedded in the evidence itself.</p>
      </part>
    </control>
    <control id="PHYS-7">
      <title>Capture Assessment Results</title>
      <prop name="label" class="index" value="3.13 A #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-7_smt" name="statement">
        <p>CSPs SHALL make the results of their testing publicly available.</p>
      </part>
      <part id="PHYS-7_obj" name="objective">
        <p>Confirm that the CSP makes publicly available the results of any performance assessments it conducts on its image capture and validation technologies.</p>
        <link href="#PHYS-7_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it makes publicly available the results of any performance assessments it conducts on its image capture and validation technologies.</p>
      </part>
      <part id="PHYS-7_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's performance assessment results on a publicly available website or platform.</p>
      </part>
      <part id="PHYS-7_gdn" name="guidance">
        <p>CSPs SHOULD have their evidence validation technology periodically tested by independent entities (e.g., accredited laboratories or research institutions) for their performance characteristic.</p>
      </part>
    </control>
    <control id="PHYS-8">
      <title>Visual Inspection Training</title>
      <prop name="label" class="index" value="3.13 B #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-8_smt" name="statement">
        <p>Proofing agents and trusted referees SHALL be trained and provided with the resources to visually inspect all forms of evidence supported by the CSP. This training SHALL include: authentic layouts and topography of evidence types; physical security features (e.g., raised letters, holographic features, microprinting); techniques for assessing features (e.g., tools to be used, where tactile inspection is needed, manipulation required to view specific features); and common indications of tampering (e.g., damage to the lamination, image modification).</p>
      </part>
      <part id="PHYS-8_obj" name="objective">
        <p>Confirm that the CSP trains its proofing agents and trusted referees and provides them with the resources they need to visually inspect all forms of evidence supported by the CSP and confirm that this training includes all the specified elements.</p>
        <link href="#PHYS-8_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it trains its proofing agents and trusted referees and provides them with the resources they need to effectively visually inspect all forms of supported evidence.</p>
      </part>
      <part id="PHYS-8_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents or trusted referees to determine what training and resources the CSP has provided to them on visually inspecting all forms of supported evidence.</p>
      </part>
    </control>
    <control id="PHYS-9">
      <title>Visual Inspection Assessment</title>
      <prop name="label" class="index" value="3.13 B #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-9_smt" name="statement">
        <p>Proofing agents and trusted referees SHALL be assessed regarding their ability to visually inspect evidence based on their training. Additionally, proofing agents and trusted referees SHALL be reassessed on an annual basis or whenever significant new threats to the evidence validation process are identified and remedially trained as needed.</p>
      </part>
      <part id="PHYS-9_obj" name="objective">
        <p>Confirm that the CSP (1) assesses the ability of its trained proofing agents and trusted referees to visually inspect all types of supported evidence, (2) re-assesses these agents on an annual basis, and (3) provides remedial training as needed.</p>
        <link href="#PHYS-9_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for assessing and annually reassessing its proofing agents and trusted referees on their ability to visually inspect all types of supported evidence.</p>
      </part>
    </control>
    <control id="PHYS-10">
      <title>Visual Inspection Tools</title>
      <prop name="label" class="index" value="3.13 B #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-10_smt" name="statement">
        <p>Proofing agents and trusted referees SHALL be provided with specialized tools and equipment to support the visual inspection of evidence as appropriate for the identity evidence type.</p>
      </part>
      <part id="PHYS-10_obj" name="objective">
        <p>Confirm that the CSP provides its proofing agents and trusted referees with specialized tools that support the visual inspection of supported evidence types.</p>
        <link href="#PHYS-10_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the types of tools it provides to its proofing agents and trusted referees to support the visual inspection of supported evidence types.</p>
      </part>
      <part id="PHYS-10_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more of the CSP's proofing agents and/or trusted referee to determine that they are provided with the specialized tools they need to effectively conduct visual inspection of supported evidence types.</p>
      </part>
      <part id="PHYS-10_gdn" name="guidance">
        <p>Specialized tools may include magnifiers, ultraviolet lights, barcode readers, etc.</p>
      </part>
    </control>
    <control id="PHYS-11">
      <title>Remote Visual Inspections</title>
      <prop name="label" class="index" value="3.13 B #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-11_smt" name="statement">
        <p>Proofing agents and trusted referees who conduct visual inspections via remote means SHALL be provided with devices and internet connections that support sufficiently high-quality imagery to be able to effectively inspect presented evidence.</p>
      </part>
      <part id="PHYS-11_obj" name="objective">
        <p>Confirm that the CSP provides its proofing agents and trusted referees who conduct visual inspections in remote scenarios with  devices and internet connections that support sufficiently high-quality imagery.</p>
        <link href="#PHYS-11_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it provides its proofing agents and trusted referees who conduct visual inspection in remote scenarios with devices and internet connections that support high-quality imagery.</p>
      </part>
      <part id="PHYS-11_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more of the CSP's proofing agents and/or trusted referee who conduct visual inspection in remote scenarios to determine the types of devices and internet connections the CSP has provided them with.</p>
      </part>
    </control>
    <control id="PHYS-12">
      <title>Documented Inspection Training</title>
      <prop name="label" class="index" value="3.13 B #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PHYS-12_smt" name="statement">
        <p>CSPs SHALL document their training and assessment procedures for visual inspections of evidence and make them available to RPs upon request.</p>
      </part>
      <part id="PHYS-12_obj" name="objective">
        <p>Confirm the CSP has documented its training and assessment procedures for visual inspections of evidence and makes them available to its RPs upon request.</p>
        <link href="#PHYS-12_smt" rel="assessment-for"/>
      </part>
      <part id="PHYS-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it has documented its training and assessment procedures for visual inspection of evidence AND its policy for providing this information to its RPs if requested.</p>
      </part>
      <part id="PHYS-12_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of the information it provides to RPs about its evidence visual inspection training and assessment procedures.</p>
      </part>
    </control>
    <control id="DIGINJ-1">
      <title>Media Technical Controls</title>
      <prop name="label" class="index" value="3.14 A #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DIGINJ-1_smt" name="statement">
        <p>CSPs SHALL implement technical controls to increase confidence that digital media is being produced by a genuine sensor during the proofing process.</p>
      </part>
      <part id="DIGINJ-1_obj" name="objective">
        <p>Confirm that the CSP has implemented technical controls that check for the use of genuine sensors during the identity proofing process.</p>
        <link href="#DIGINJ-1_smt" rel="assessment-for"/>
      </part>
      <part id="DIGINJ-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine the types of checks it employs to determine that sensors used during the identity proofing process are genuine.</p>
      </part>
      <part id="DIGINJ-1_gdn" name="guidance">
        <p>Many emerging attacks on both attended and unattended remote identity proofing processes pair digital injection attacks with increasingly effective and available generative AI tools. These AI tools are used to create or modify media that contain images or videos of applicants and evidence (i.e., deepfakes) to defeat automated document validation processes, biometric operations, and visual comparisons done by proofing agents. Injection attacks insert modified or forged media between the capture point (e.g., a device) and the element conducting the comparison or other operation (e.g., a server running the algorithms, a workstation used by a proofing agent).</p>
      </part>
    </control>
    <control id="DIGINJ-2">
      <title>Analyze Digital Media</title>
      <prop name="label" class="index" value="3.14 A #2a"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DIGINJ-2_smt" name="statement">
        <p>CSPs SHALL analyze all digital media submitted during the identity proofing process for artifacts and indicators of potential modification, manipulation, tampering, or forgery.</p>
      </part>
      <part id="DIGINJ-2_obj" name="objective">
        <p>Confirm that the CSP employs a mechanism to analyze whether submitted digital media contains artifacts or other indicators of having been modified or forged.</p>
        <link href="#DIGINJ-2_smt" rel="assessment-for"/>
      </part>
      <part id="DIGINJ-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that it employs mechanisms for detecting indicators of digital media tampering or forgery.</p>
      </part>
      <part id="DIGINJ-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's identity proofing workflow by attempting to submit an image or other type of media that has been digitally modified or forged.</p>
      </part>
    </control>
    <control id="DIGINJ-3">
      <title>Image Analysis Algorithms</title>
      <prop name="label" class="index" value="3.14 A #2b"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DIGINJ-3_smt" name="statement">
        <p>Automated image analysis algorithms SHALL be tested against available attack artifacts and genuine media to provide a baseline of performance and to determine the expected rate of false positives and false negatives generated by the system.</p>
      </part>
      <part id="DIGINJ-3_obj" name="objective">
        <p>If a CSP employs automated image analysis algorithms, confirm that these algorithms has been tested against available attack artifacts and genuine media and that expected rates of false positives and false negatives have been determined.</p>
        <link href="#DIGINJ-3_smt" rel="assessment-for"/>
      </part>
      <part id="DIGINJ-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that any automated image analysis algorithms have been tested and the expected rates of false positives and false negatives have been determined.</p>
      </part>
      <part id="DIGINJ-3_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the results of automated image analysis testing.</p>
      </part>
    </control>
    <control id="DIGINJ-4">
      <title>Attack Artifact Testing</title>
      <prop name="label" class="index" value="3.14 A #2c"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DIGINJ-4_smt" name="statement">
        <p>The kinds of available attack artifacts that were tested and the corresponding false negative rates SHALL be documented and made available to RPs upon request.</p>
      </part>
      <part id="DIGINJ-4_obj" name="objective">
        <p>If a CSP employs automated image analysis algorithms, confirm that is has documented the types of attack artifacts that were tested and the corresponding false negatives and that this information has been made available to any of its RPs that request it.</p>
        <link href="#DIGINJ-4_smt" rel="assessment-for"/>
      </part>
      <part id="DIGINJ-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's testing procedures and results to determine which attack artifacts were tested and the corresponding false negative rates.</p>
      </part>
      <part id="DIGINJ-4_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example contract for an RP to determine it includes the option for RPs to request this information.</p>
      </part>
    </control>
    <control id="DIGINJ-5">
      <title>Authenticated Protected Channels</title>
      <prop name="label" class="index" value="3.14 A #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DIGINJ-5_smt" name="statement">
        <p>CSPs SHALL only use authenticated protected channels for the exchange of data during remote identity proofing processes.</p>
      </part>
      <part id="DIGINJ-5_obj" name="objective">
        <p>Confirm that the CSP always employs authenticated protected channels for the exchange of date during remote identity proofing processes.</p>
        <link href="#DIGINJ-5_smt" rel="assessment-for"/>
      </part>
      <part id="DIGINJ-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that it uses authenticated protected channels for all exchanges of data.</p>
      </part>
    </control>
    <control id="DIGINJ-6">
      <title>Manipulated Media Detection</title>
      <prop name="label" class="index" value="3.14 B #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DIGINJ-6_smt" name="statement">
        <p>For remote attended scenarios, CSPs SHALL train proofing agents and trusted referees to look for indications of manipulated media.</p>
      </part>
      <part id="DIGINJ-6_obj" name="objective">
        <p>Confirm that the CSP trains its proofing agents and trusted referees how to look for indications of digital media fraud in remote attended scenarios.</p>
        <link href="#DIGINJ-6_smt" rel="assessment-for"/>
      </part>
      <part id="DIGINJ-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it trains its proofing agents and trusted referees on how to look for indications that digital media has been manipulated.</p>
      </part>
      <part id="DIGINJ-6_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents and/or trusted referees to determine they have been trained how to look for manipulated digital media during attended remote scenarios.</p>
      </part>
    </control>
    <control id="DIGINJ-7">
      <title>Human In The Loop</title>
      <prop name="label" class="index" value="3.14 B #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DIGINJ-7_smt" name="statement">
        <p>For remote attended scenarios, CSPs SHALL introduce random "human-in-the-loop" cues into their capture processes to increase the possibility of forged or manipulated media being detected.</p>
      </part>
      <part id="DIGINJ-7_obj" name="objective">
        <p>Confirm that the CSP introduces random "human-in-the-loop" cues into its capture processes during remote attended scenarios</p>
        <link href="#DIGINJ-7_smt" rel="assessment-for"/>
      </part>
      <part id="DIGINJ-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's design or other documentation to determine that it incorporates random "human-in-the-loop" cues into its digital media capture processes in remote attended scenarios.</p>
      </part>
      <part id="DIGINJ-7_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents or other personnel to determine that the CSP incorporates random "human-in-the-loop" cues into its digital media capture processes.</p>
      </part>
      <part id="DIGINJ-7_gdn" name="guidance">
        <p>Examples of "human-in-the-loop" cues include requesting user movements or requesting that the user move objects between the capture sensor and their face.</p>
      </part>
    </control>
    <control id="EXCEPT-1">
      <title>Documented Exception Handling</title>
      <prop name="label" class="index" value="3.15 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-1_smt" name="statement">
        <p>CSPs SHALL document their operational processes for dealing with errors and handling exceptions.</p>
      </part>
      <part id="EXCEPT-1_obj" name="objective">
        <p>Confirm that the CSP has documented its error and exception handling processes.</p>
        <link href="#EXCEPT-1_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its operational processes for dealing with errors and handling exceptions.</p>
      </part>
      <part id="EXCEPT-1_gdn" name="guidance">
        <p>Throughout the identity proofing process, there are many points at which errors or failures may occur. Such exceptions to a standard identity proofing workflow include process failures (e.g., when a user does not possess the required evidence), technical failures (e.g., when an integrated service is not available), and failures due to user error (e.g., when an applicant is unable to capture a clear image of their identity evidence using remote validation tools). These documented processes SHOULD include providing trusted referees to support applicants who are otherwise unable to meet the requirements of IALs 1 and 2. Additionally, CSPs SHOULD support the use of applicant references who can vouch for an applicant's attributes, conditions, or identity.</p>
      </part>
    </control>
    <control id="EXCEPT-2">
      <title>Trusted Referee Notification</title>
      <prop name="label" class="index" value="3.15.1 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-2_smt" name="statement">
        <p>The CSP SHALL notify the public of the availability of trusted referee services and how such services are obtained.</p>
      </part>
      <part id="EXCEPT-2_obj" name="objective">
        <p>[If the CSP provides trusted referees], confirm that it notifies the public of their availability and how to obtain their services.</p>
        <link href="#EXCEPT-2_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine how it notifies the public about the availability of trusted referee services.</p>
      </part>
      <part id="EXCEPT-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the information about the availability and use of trusted referees on the CSPs website or identity system.</p>
      </part>
      <part id="EXCEPT-2_gdn" name="guidance">
        <p>Trusted referees are used to increase access to online services by facilitating the identity proofing and enrollment of individuals who are otherwise unable to prove their identities using the usual identity proofing process for a specific IAL. A non-exhaustive list of examples of individuals who may need the assistance of trusted referees includes those who do not possess and cannot obtain the required identity evidence, persons with disabilities, older individuals, persons experiencing homelessness, individuals with limited access to online services or computing devices, persons without a bank account or with limited credit history, victims of identity theft, individuals displaced or affected by natural disasters, and children under 18. Trusted referees can be provided by the CSP, a third party, or an RP.</p>
      </part>
    </control>
    <control id="EXCEPT-3">
      <title>Trusted Referee Policies</title>
      <prop name="label" class="index" value="3.15.1 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-3_smt" name="statement">
        <p>The CSP SHALL establish written policies and procedures for the use of trusted referees as part of its practice statement, as specified in Sec. 3.1.</p>
      </part>
      <part id="EXCEPT-3_obj" name="objective">
        <p>Confirm that the CSP has established written policies and procedures for the use of trusted referees.</p>
        <link href="#EXCEPT-3_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine is has established written procedures for the use of trusted referees.</p>
      </part>
    </control>
    <control id="EXCEPT-4">
      <title>Trusted Referee Training</title>
      <prop name="label" class="index" value="3.15.1 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-4_smt" name="statement">
        <p>The CSP SHALL train and certify its trusted referees to make risk-based decisions that allow applicants to be successfully identity-proofed based on their unique circumstances. At a minimum, such training SHALL include:</p>
        <p>(a) Document identification and validation, such as common templates, security features, layouts, and topography (see Sec. 3.13).</p>
        <p>(b) Indicators of fraudulent documents, such as damage, tampering, modification, fabrication, or forgery (see Sec. 3.13).</p>
        <p>(c) Facial image comparisons to verify applicants against presented documents (see Sec. 3.12).</p>
        <p>(d) Indicators of social engineering exhibited by an applicant, such as distress, confusion, or coercion.</p>
        <p>(e) An annual review of the trusted referee's abilities to visually inspect evidence and make visual facial image comparisons (see Sec. 3.12).</p>
      </part>
      <part id="EXCEPT-4_obj" name="objective">
        <p>Confirm that the CSP trains and certifies its trusted referees in accordance to the specified requirements.</p>
        <link href="#EXCEPT-4_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the training and certification it provides to its trusted referees.</p>
      </part>
      <part id="EXCEPT-4_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more of the CSP's trusted referees to determine that they were certified by the CSP and received the specified training.</p>
      </part>
    </control>
    <control id="EXCEPT-5">
      <title>TR Usage Record</title>
      <prop name="label" class="index" value="3.15.1 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-5_smt" name="statement">
        <p>The CSP SHALL establish a record of any identity proofing session that involves a trusted referee, including the reasons why a trusted referee was used (e.g., automated process failure, applicant request, established exception policy), the identity of the trusted referee, what evidence was presented, which processes were completed (e.g., validation or verification), and the trusted referee's decision and, if negative, their rationale.</p>
      </part>
      <part id="EXCEPT-5_obj" name="objective">
        <p>Confirm that the CSP establishes a record whenever a trusted referee is involved in the identity proofing of an applicant, and that this record includes, at the minimum, the details specified in this requirement.</p>
        <link href="#EXCEPT-5_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it establishes detailed records of identity proofing transactions that involve a trusted referee.</p>
      </part>
      <part id="EXCEPT-5_gdn" name="guidance">
        <p>While the details of trusted referee usage will necessarily be associated with the subject being identity proofed, it is expected that some or all of this information will not be visible to the subject through in subscriber account.</p>
      </part>
    </control>
    <control id="EXCEPT-6">
      <title>ALL Applicable Requirements</title>
      <prop name="label" class="index" value="3.15.1 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-6_smt" name="statement">
        <p>These sessions SHALL be consistent with the requirements of these proofing types based on the IAL of the proofing event.</p>
      </part>
      <part id="EXCEPT-6_obj" name="objective">
        <p>Confirm the CSP's policy on meeting all applicable requirements for identity proofing transactions, regardless of whether or not a trusted referee is involved.</p>
        <link href="#EXCEPT-6_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that all applicable requirements for identity proofing transactions, regardless of whether or not a trusted referee is involved.</p>
      </part>
      <part id="EXCEPT-6_gdn" name="guidance">
        <p>All applicable requirements must be met, regardless of the use of trusted referees.</p>
      </part>
    </control>
    <control id="EXCEPT-7">
      <title>Trusted Referee Use</title>
      <prop name="label" class="index" value="3.15.2 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-7_smt" name="statement">
        <p>CSPs SHALL document which types of exceptions and failures are eligible for the use of a trusted referee.</p>
      </part>
      <part id="EXCEPT-7_obj" name="objective">
        <p>Confirm the  CSP has documented the scenarios that are eligible for trusted referee involvement in an identity proofing transaction.</p>
        <link href="#EXCEPT-7_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine which scenarios are eligible for the use of a trusted referee.</p>
      </part>
    </control>
    <control id="EXCEPT-8">
      <title>Automated Validation Failures</title>
      <prop name="label" class="index" value="3.15.2 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-8_smt" name="statement">
        <p>If a CSP offers trusted referees [are offered for failures in completing automated validation processes], the following requirements apply:</p>
        <p>(a) CSPs SHALL provide a policy for additional evidence types that may be used to corroborate core attributes or changes in core attributes.</p>
        <p>(b) Trusted referees SHALL review additional evidence types for authenticity to the greatest degree allowed by the evidence.</p>
        <p>(c) If no authoritative or credible records are available to support validation, the trusted referee MAY compare the attributes on additional pieces of evidence with the strongest piece of evidence available to corroborate the consistency of core attributes.</p>
        <p>(d) If there is a partial mismatch of core attributes to authoritative records, the trusted referee SHALL review evidence that supports the legitimacy of the asserted attribute value (e.g., recent move or change of name).</p>
      </part>
      <part id="EXCEPT-8_obj" name="objective">
        <p>Determine if the CSP offers trusted referees to assist with automated validation failures and, if it does, confirm that their involvement in these scenarios adheres to the specified requirements.</p>
        <link href="#EXCEPT-8_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy on trusted referee involvement in automated validation failures.</p>
      </part>
      <part id="EXCEPT-8_gdn" name="guidance">
        <p>CSPs SHOULD offer trusted referee services for failures in completing automated validation processes, such as mismatched core attributes or the absence of the applicant in a record source.</p>
      </part>
    </control>
    <control id="EXCEPT-9">
      <title>Applicant Reference Notification</title>
      <prop name="label" class="index" value="3.15.3 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-9_smt" name="statement">
        <p>The CSP SHALL notify the public of the allowability of applicant references and any requirements for the relationship between the reference and an applicant.</p>
      </part>
      <part id="EXCEPT-9_obj" name="objective">
        <p>Confirm if the CSP provides a notice to the public about the allowability of applicant references to assist in identity proofing transactions along with any requirements for their use.</p>
        <link href="#EXCEPT-9_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it notifies the public about the allowability of applicant references and the requirements for their use.</p>
      </part>
      <part id="EXCEPT-9_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the information about the allowability of and requirements for applicant reference use on the CSP's public website or identity system.</p>
      </part>
      <part id="EXCEPT-9_gdn" name="guidance">
        <p>Applicant references are individuals who participate in the identity proofing of an applicant in order to vouch for the applicant's identity, attributes, or circumstances related to the applicant's ability to complete identity proofing. Applicant references are not agents of the CSP, but rather representatives of the applicant who have sufficient knowledge to aid in the completion of identity proofing when other forms of evidence, validation, and verification are not available. Applicant references are permissible at IAL 1 and IAL 2 only.</p>
      </part>
    </control>
    <control id="EXCEPT-10">
      <title>Applicant Reference Policy</title>
      <prop name="label" class="index" value="3.15.3 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-10_smt" name="statement">
        <p>The CSP SHALL establish written policies and procedures for the use of applicant references as part of its practice statement, as specified in Sec. 3.1.</p>
      </part>
      <part id="EXCEPT-10_obj" name="objective">
        <p>Confirm that the CSP has written policies and procedures for the use of applicant references.</p>
        <link href="#EXCEPT-10_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it has written policies for the use of applicant references.</p>
      </part>
    </control>
    <control id="EXCEPT-11">
      <title>Applicant Reference Proofing</title>
      <prop name="label" class="index" value="3.15.3 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-11_smt" name="statement">
        <p>The CSP SHALL identity-proof an applicant reference to the same or higher IAL intended for the applicant.</p>
      </part>
      <part id="EXCEPT-11_obj" name="objective">
        <p>Determine if the CSP allows the use of applicant references and, if it does, confirm that all applicant references are identity-proofed to the same or higher IAL as the applicant or applicants they are supporting.</p>
        <link href="#EXCEPT-11_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it identity proofs applicant reference to the same or higher IAL as the applicants.</p>
      </part>
      <part id="EXCEPT-11_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine one or more sample records of subscribers who were identity proofed using an applicant reference and determine the IAL associated with both the subscriber and their reference.</p>
      </part>
    </control>
    <control id="EXCEPT-12">
      <title>AR Privacy Assessment</title>
      <prop name="label" class="index" value="3.15.3 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-12_smt" name="statement">
        <p>The CSP SHALL include the information collected, recorded, and retained for identity proofing the applicant references in its privacy risk assessment, as required in section Sec. 3.3.1.</p>
      </part>
      <part id="EXCEPT-12_obj" name="objective">
        <p>Confirm that the CSP included all personal data associated with the use of applicant references in its privacy risk assessment.</p>
        <link href="#EXCEPT-12_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's privacy risk assessment documentation to determine it has included data associated with the use of applicant references.</p>
      </part>
    </control>
    <control id="EXCEPT-13">
      <title>Applicant Reference Record</title>
      <prop name="label" class="index" value="3.15.3 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-13_smt" name="statement">
        <p>The CSP SHALL record the use of an applicant reference in the subscriber account and maintain a record of the applicant reference and their relationship to the applicant.</p>
      </part>
      <part id="EXCEPT-13_obj" name="objective">
        <p>Confirm that the CSP records the use of applicant references in the associated subscriber accounts, including their relationship to the applicant.</p>
        <link href="#EXCEPT-13_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine how it records the use of applicant references.</p>
      </part>
      <part id="EXCEPT-13_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine one or more subscriber accounts to determine how it records the use of an applicant reference.</p>
      </part>
    </control>
    <control id="EXCEPT-14">
      <title>RP Risk Assessment</title>
      <prop name="label" class="index" value="3.15.3 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-14_smt" name="statement">
        <p>The RP SHALL conduct a risk assessment to determine the applicability, business requirements, and potential risks associated with excluding or including applicant references for proofing events.</p>
      </part>
      <part id="EXCEPT-14_obj" name="objective">
        <p>Confirm that the RP has conducted a risk assessment that considers the impacts of both allowing and not allowing the use of applicant references.</p>
        <link href="#EXCEPT-14_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the results of the RP's risk assessment to determine it has thoroughly considered whether or not to allow the acceptance of users whose identity proofing process was supported by applicant references.</p>
      </part>
    </control>
    <control id="EXCEPT-15">
      <title>Acceptable AR Uses</title>
      <prop name="label" class="index" value="3.15.4 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-15_smt" name="statement">
        <p>If CSPs allow the use of applicant references, the CSPs and the RPs that use their services SHALL document all acceptable uses for applicant references in their contracts or trust agreements.</p>
      </part>
      <part id="EXCEPT-15_obj" name="objective">
        <p>If CSPs allow for the use of applicant references, confirm that acceptable uses of their services are documented in any contacts or trust agreements with RPs.</p>
        <link href="#EXCEPT-15_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a sample RP contract or trust agreement and determine that the CSP has included acceptable uses, if any, for applicant references.</p>
      </part>
      <part id="EXCEPT-15_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine that the CSP includes information about the acceptable uses of applicant references in its contracts or trust agreements with the RPs that use its service.</p>
      </part>
    </control>
    <control id="EXCEPT-16">
      <title>AR Legal Requirements</title>
      <prop name="label" class="index" value="3.15.4 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-16_smt" name="statement">
        <p>In all instances, the CSP SHALL establish a record of the role that the applicant reference played in the process and document these actions sufficient to support any applicable legal and regulatory requirements.</p>
      </part>
      <part id="EXCEPT-16_obj" name="objective">
        <p>Determine that the CSP has identified any legal or regulatory requirements associated with the use of applicant references, and confirm that it records sufficient details about the use of an applicant reference to support those requirements.</p>
        <link href="#EXCEPT-16_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine any legal or regulatory requirements that apply to the use of applicant references, and determine that the CSP records sufficient details about each use of an applicant reference to meet these requirements.</p>
      </part>
    </control>
    <control id="EXCEPT-17">
      <title>Applicant Reference Liability</title>
      <prop name="label" class="index" value="3.15.4 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-17_smt" name="statement">
        <p>CSPs SHALL make available to the applicant reference clear and understandable information relative to the legal and liability impacts that may result from their participation as an applicant reference.</p>
      </part>
      <part id="EXCEPT-17_obj" name="objective">
        <p>Confirm that the CSP makes information available to potential applicant references about any legal or liability implications associated with their participation in the identity proofing of an applicant.</p>
        <link href="#EXCEPT-17_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the information it provides to potential applicant references.</p>
      </part>
      <part id="EXCEPT-17_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the actual information it provides to applicant references.</p>
      </part>
    </control>
    <control id="EXCEPT-18">
      <title>AR Relationship Requirements</title>
      <prop name="label" class="index" value="3.15.5 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-18_smt" name="statement">
        <p>The CSP and RP SHALL establish requirements for applicant reference relationship confirmation processes and document them in any contracts or trust agreements.</p>
      </part>
      <part id="EXCEPT-18_obj" name="objective">
        <p>Confirm that the requirements and process for confirming the relationship between an applicant and their applicant reference is documented in any contracts or trust agreements between CSPs and RPs.</p>
        <link href="#EXCEPT-18_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a sample contract or trust agreement to determine that it includes information about the requirements and process for confirming the relationship between an applicant and their applicant reference.</p>
      </part>
    </control>
    <control id="EXCEPT-19">
      <title>Applicant Reference Evidence</title>
      <prop name="label" class="index" value="3.15.5 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-19_smt" name="statement">
        <p>The CSP SHALL make a list of acceptable evidence of relationship available to the applicant reference prior to initiating the relationship confirmation process.</p>
      </part>
      <part id="EXCEPT-19_obj" name="objective">
        <p>Confirm that the CSP provides a list of acceptable evidence of the relationship between an applicant and their applicant reference prior to initiating the relationship confirmation process.</p>
        <link href="#EXCEPT-19_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-19_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP provides a list of acceptable evidence of the relationship between an applicant and their applicant reference prior to initiating the relationship confirmation process.</p>
      </part>
      <part id="EXCEPT-19_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the applicant reference workflow to determine that the CSP provides a list of acceptable evidence of the relationship between an applicant and their reference prior to initiating the relationship confirmation process.</p>
      </part>
    </control>
    <control id="EXCEPT-20">
      <title>AR Relationship Evidence</title>
      <prop name="label" class="index" value="3.15.5 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-20_smt" name="statement">
        <p>The CSP SHALL request evidence of the applicant's relationship (e.g., notarized power of attorney, a professional certification).</p>
      </part>
      <part id="EXCEPT-20_obj" name="objective">
        <p>Confirm that the CSP collects evidence supporting the relationship between an applicant and their applicant reference.</p>
        <link href="#EXCEPT-20_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-20_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that the CSP collects evidence supporting the relationship between an applicant and their applicant reference.</p>
      </part>
      <part id="EXCEPT-20_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the applicant reference workflow to determine that the CSP collects evidence supporting the relationship between an applicant and their applicant reference.</p>
      </part>
    </control>
    <control id="EXCEPT-21">
      <title>Record Relationship Evidence</title>
      <prop name="label" class="index" value="3.15.5 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-21_smt" name="statement">
        <p>Upon successfully identity proofing an applicant, the CSP SHALL record the evidence used to confirm the applicant reference's relationship to the applicant in the subscriber account.</p>
      </part>
      <part id="EXCEPT-21_obj" name="objective">
        <p>Confirm that the CSP records the evidence used to confirm the relationship between an applicant and their applicant reference and associates it with the subscriber's account.</p>
        <link href="#EXCEPT-21_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-21_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that records the evidence used to confirm the relationship between an applicant and their applicant reference in the subscriber's account.</p>
      </part>
      <part id="EXCEPT-21_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine one or more sample records of subscribers who were identity proofed using an applicant reference and determine that it includes information about the type(s) of evidence used to confirm the relationship between the applicant and their applicant reference.</p>
      </part>
    </control>
    <control id="EXCEPT-22">
      <title>Minors Evidence Policy</title>
      <prop name="label" class="index" value="3.15.6 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-22_smt" name="statement">
        <p>The CSP SHALL establish a written policy and procedures as part of its practice statement for identity proofing minors who may not be able to meet the evidence requirements for a given IAL.</p>
      </part>
      <part id="EXCEPT-22_obj" name="objective">
        <p>Confirm that the CSP has documented its policy and procedures for the identity proofing of minors who are unable to meet the evidence requirements for a given IAL.</p>
        <link href="#EXCEPT-22_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-22_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and procedures for identity proofing minors who are unable to meet the IAL evidence requirements.</p>
      </part>
    </control>
    <control id="EXCEPT-23">
      <title>COPPA</title>
      <prop name="label" class="index" value="3.15.6 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-23_smt" name="statement">
        <p>When interacting with persons under the age of 13, the CSP SHALL ensure compliance with the Children's Online Privacy Protection Act of 1998 [COPPA] or other laws and regulations that deal with the protection of minors, as applicable.</p>
      </part>
      <part id="EXCEPT-23_obj" name="objective">
        <p>Confirm that the CSP complies with COPPA and any other laws and regulations that deal with the protection of minors.</p>
        <link href="#EXCEPT-23_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-23_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for complying with COPPA and any other applicable laws and regulations that deal with the protection of minors.</p>
      </part>
    </control>
    <control id="EXCEPT-24">
      <title>Minors' Applicant References</title>
      <prop name="label" class="index" value="3.15.6 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXCEPT-24_smt" name="statement">
        <p>CSPs SHALL support the use of applicant references when interacting with individuals under the age of 18.</p>
      </part>
      <part id="EXCEPT-24_obj" name="objective">
        <p>Confirm that the CSP allows for the use of applicant references for the identity proofing of individuals under the age of 18.</p>
        <link href="#EXCEPT-24_smt" rel="assessment-for"/>
      </part>
      <part id="EXCEPT-24_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for complying for supporting the use of applicant references for the identity proofing of individuals under the age of 18.</p>
      </part>
    </control>
    <control id="ELEVATE-1">
      <title>Elevating Assurance Levels</title>
      <prop name="label" class="index" value="3.16 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ELEVATE-1_smt" name="statement">
        <p>CSPs SHALL document their approved approaches for elevating assurance levels in their practice statements.</p>
      </part>
      <part id="ELEVATE-1_obj" name="objective">
        <p>If the CSP supports the elevation of subscriber assurance levels, confirm that the CSP has documented its policy and approved approaches for this process.</p>
        <link href="#ELEVATE-1_smt" rel="assessment-for"/>
      </part>
      <part id="ELEVATE-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and approaches for elevating subscriber assurance levels.</p>
      </part>
      <part id="ELEVATE-1_gdn" name="guidance">
        <p>CSPs SHOULD allow subscribers to elevate IALs related to their subscriber accounts to support higher assurance transactions with RPs.</p>
      </part>
    </control>
    <control id="ELEVATE-2">
      <title>Account Upgrade Authentication</title>
      <prop name="label" class="index" value="3.16 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ELEVATE-2_smt" name="statement">
        <p>CSPs SHALL require subscribers to authenticate at the highest authentication assurance level (AAL) available on their account prior to initiating the upgrade process.</p>
      </part>
      <part id="ELEVATE-2_obj" name="objective">
        <p>If the CSP supports the elevation of subscriber assurance levels, confirm that it requires subscribers to authenticate at the highest AAL available on their account prior to initiating the upgrade process.</p>
        <link href="#ELEVATE-2_smt" rel="assessment-for"/>
      </part>
      <part id="ELEVATE-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it subscribers to authenticate at the highest AAL available on their account prior to initiating the upgrade process.</p>
      </part>
    </control>
    <control id="ELEVATE-3">
      <title>Additional Evidence Requirements</title>
      <prop name="label" class="index" value="3.16 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ELEVATE-3_smt" name="statement">
        <p>CSPs SHALL collect, validate, and verify additional evidence, as mandated to achieve the higher IAL.</p>
      </part>
      <part id="ELEVATE-3_obj" name="objective">
        <p>If the CSP supports the elevation of subscriber assurance levels, confirm that it collects, validates, and verifies additional evidence, as needed to meet the requirements of the higher IAL.</p>
        <link href="#ELEVATE-3_smt" rel="assessment-for"/>
      </part>
      <part id="ELEVATE-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it collects, validates, and verifies additional evidence, as needed to meet the requirements of the higher IAL.</p>
      </part>
    </control>
    <control id="IAL1-1">
      <title>IAL1 Documented Process</title>
      <prop name="label" class="index" value="4.1.1 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-1_smt" name="statement">
        <p>CSPs that combine elements of different proofing types SHALL document their hybrid process and state how the applicable requirements for each of the employed proofing types are met.</p>
      </part>
      <part id="IAL1-1_obj" name="objective">
        <p>If the CSP employs a hybrid process, confirm that it is documented, and such documentation includes details about how the applicable requirements for each proofing type are met.</p>
        <link href="#IAL1-1_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine how its hybrid identity proofing process meets the applicable requirements.</p>
      </part>
      <part id="IAL1-1_gdn" name="guidance">
        <p>IAL1 identity proofing MAY be delivered through any proofing type, as described in Sec. 2.1.3. CSPs MAY combine proofing types and their stated requirements to create hybrid processes. For example, a CSP might leverage remote unattended identity proofing validation processes in advance of a remote attended session where the verification will take place.</p>
      </part>
    </control>
    <control id="IAL1-2">
      <title>IAL1 Evidence Collection</title>
      <prop name="label" class="index" value="4.1.2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-2_smt" name="statement">
        <p>For identity proofing at IAL1, the CSP SHALL collect: one piece of FAIR evidence that can be digitally validated or that includes a facial portrait or other biometric; OR, one piece of STRONG evidence; OR, one piece of SUPERIOR evidence.</p>
      </part>
      <part id="IAL1-2_obj" name="objective">
        <p>Confirm that the CSP collects the specified evidence for identity proofing at IAL 1.</p>
        <link href="#IAL1-2_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practice statement or other documentation to determine its evidence collection requirements for IAL 1.</p>
      </part>
      <part id="IAL1-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's identity proofing workflow to determine that documented evidence collection processes are followed.</p>
      </part>
    </control>
    <control id="IAL1-3">
      <title>IAL1 Attribute Collection</title>
      <prop name="label" class="index" value="4.1.3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-3_smt" name="statement">
        <p>The CSP SHALL collect all core attributes, including at least one government identifier.</p>
      </part>
      <part id="IAL1-3_obj" name="objective">
        <p>Confirm that the CSP collects all core attributes, including at least one government identifier.</p>
        <link href="#IAL1-3_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for collecting core attributes.</p>
      </part>
      <part id="IAL1-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's  identity proofing workflow to determine that all documented core attribute collection processes are followed.</p>
      </part>
      <part id="IAL1-3_gdn" name="guidance">
        <p>Validated evidence is the preferred source of identity attributes. If the presented identity evidence does not provide all of the attributes that the CSP considers to be core attributes, it MAY collect attributes that are self-asserted by the applicant.</p>
      </part>
    </control>
    <control id="IAL1-4">
      <title>IAL1 Evidence Validation</title>
      <prop name="label" class="index" value="4.1.4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-4_smt" name="statement">
        <p>Each piece of evidence presented SHALL be validated using one of the methods [provided in Sec. 4.1.4].</p>
      </part>
      <part id="IAL1-4_obj" name="objective">
        <p>Confirm that the CSP validates all collected evidence as specified.</p>
        <link href="#IAL1-4_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its evidence validation policy and processes.</p>
      </part>
      <part id="IAL1-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's identity proofing workflow to determine that all documented validation processes are followed.</p>
      </part>
    </control>
    <control id="IAL1-5">
      <title>IAL1 Attribute Validation</title>
      <prop name="label" class="index" value="4.1.5 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-5_smt" name="statement">
        <p>The CSP SHALL validate all core attributes and the government identifier against an authoritative or credible source to determine accuracy.</p>
      </part>
      <part id="IAL1-5_obj" name="objective">
        <p>Confirm that the CSP validates all collected core attributes as specified.</p>
        <link href="#IAL1-5_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its core attribute validation policy and processes.</p>
      </part>
      <part id="IAL1-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's identity proofing workflow to determine that all core attribute validation processes are followed.</p>
      </part>
      <part id="IAL1-5_gdn" name="guidance">
        <p>CSPs SHOULD evaluate attributes obtained from different sources (e.g., presented evidence, self-asserted, authoritative or credible sources) for consistency.</p>
        <p>CSPs SHOULD validate any reference numbers on the presented identity evidence, if available.</p>
      </part>
    </control>
    <control id="IAL1-6">
      <title>IAL1 Verification Requirements</title>
      <prop name="label" class="index" value="4.1.6 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-6_smt" name="statement">
        <p>The CSP SHALL verify the applicant's ownership of one piece of evidence using one of the methods [provided in 4.1.6].</p>
      </part>
      <part id="IAL1-6_obj" name="objective">
        <p>Confirm that the CSP verifies the applicant's ownership of at least one piece of collected evidence using one of the specified methods.</p>
        <link href="#IAL1-6_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and processes for performing verification.</p>
      </part>
      <part id="IAL1-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's identity proofing workflow to determine that all documented verification processes are followed.</p>
      </part>
    </control>
    <control id="IAL1-7">
      <title>Async Visual Comparison</title>
      <prop name="label" class="index" value="4.1.6 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-7_smt" name="statement">
        <p>If the visual comparison is performed asynchronously at a later time, the CSP SHALL implement PAD and passive or active document presence checks to increase confidence that both the live applicant and physical documents are present during the submission or capture event.</p>
      </part>
      <part id="IAL1-7_obj" name="objective">
        <p>Confirm that the CSP has implemented PAD and passive and active document liveness checks for the asynchronous visual comparison of an applicant to their identity evidence.</p>
        <link href="#IAL1-7_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it has implemented PAD and passive and active document liveness checks for the asynchronous visual comparison of an applicant to their identity evidence.</p>
      </part>
    </control>
    <control id="IAL1-8">
      <title>IAL1 Video Session</title>
      <prop name="label" class="index" value="4.1.8 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-8_smt" name="statement">
        <p>For Remote Attended identity proofing, the applicant SHALL remain in view of the proofing agent during each step of the proofing process.</p>
      </part>
      <part id="IAL1-8_obj" name="objective">
        <p>For remote attended video sessions, confirm the CSP requires that the applicant is visible to the proofing agent for each step of the identity proofing process.</p>
        <link href="#IAL1-8_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its requirements for applicant visibility during remote attended identity proofing sessions.</p>
      </part>
      <part id="IAL1-8_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine the process for viewing applicants during each step of remote attended identity proofing sessions.</p>
      </part>
    </control>
    <control id="IAL1-9">
      <title>IAL1 Video Quality</title>
      <prop name="label" class="index" value="4.1.8 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-9_smt" name="statement">
        <p>For Remote Attended identity proofing, the video quality SHALL be sufficient to support the necessary steps in the validation and verification processes, such as inspecting evidence and comparing the applicant to the evidence.</p>
      </part>
      <part id="IAL1-9_obj" name="objective">
        <p>For remote attended video sessions, confirm the video quality is sufficient to support the needs of the identity proofing process.</p>
        <link href="#IAL1-9_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it employs video technologies of sufficient quality to support the identity proofing processes.</p>
      </part>
    </control>
    <control id="IAL1-10">
      <title>IAL1 Remote Attended Coercion Training</title>
      <prop name="label" class="index" value="4.1.8 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-10_smt" name="statement">
        <p>For Remote Attended identity proofing, the proofing agent SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the session.</p>
      </part>
      <part id="IAL1-10_obj" name="objective">
        <p>Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process.</p>
        <link href="#IAL1-10_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering.</p>
      </part>
      <part id="IAL1-10_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the training they've received to identify these signs.</p>
      </part>
    </control>
    <control id="IAL1-11">
      <title>IAL1 Remote Attended Recorded Video</title>
      <prop name="label" class="index" value="4.1.8 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-11_smt" name="statement">
        <p>For Remote Attended identity proofing, if the CSP records a video session, the following further requirements apply:</p>
        <p>(a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session.</p>
        <p>(b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session.</p>
        <p>(c) The CSP SHALL publish their retention schedule and deletion processes for all video records.</p>
      </part>
      <part id="IAL1-11_obj" name="objective">
        <p>If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met.</p>
        <link href="#IAL1-11_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording remote attended identity proofing sessions.</p>
      </part>
      <part id="IAL1-11_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the remote attended identity proofing process and determine that all the specified requirements for recording remote attended identity proofing sessions are met.</p>
      </part>
    </control>
    <control id="IAL1-12">
      <title>IAL1 Injection Protection</title>
      <prop name="label" class="index" value="4.1.8 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-12_smt" name="statement">
        <p>For Remote Attended identity proofing,  the CSP SHALL implement injection protection and modified media controls, as defined in Sec. 3.14.</p>
      </part>
      <part id="IAL1-12_obj" name="objective">
        <p>Confirm that the CSP employs injection protection and controls against modified media.</p>
        <link href="#IAL1-12_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it has implemented injection project and modified media controls.</p>
      </part>
    </control>
    <control id="IAL1-13">
      <title>IAL1 Remote Attended Fraud Flags</title>
      <prop name="label" class="index" value="4.1.8 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-13_smt" name="statement">
        <p>For Remote Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to flag events for potential fraud.</p>
      </part>
      <part id="IAL1-13_obj" name="objective">
        <p>Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud.</p>
        <link href="#IAL1-13_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud.</p>
      </part>
      <part id="IAL1-13_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud.</p>
      </part>
    </control>
    <control id="IAL1-14">
      <title>IAL1 On-Site Attended Physical Setting</title>
      <prop name="label" class="index" value="4.1.9 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-14_smt" name="statement">
        <p>For On-site Attended identity proofing, the CSP SHALL provide a physical setting in which on-site identity proofing sessions are conducted.</p>
      </part>
      <part id="IAL1-14_obj" name="objective">
        <p>Confirm the CSP provides physical location in for on-site attended identity proofing.</p>
        <link href="#IAL1-14_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that is provides a physical setting for on-site attended identity proofing sessions.</p>
      </part>
      <part id="IAL1-14_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a location where the CSPs conducts on-site identity proofing.</p>
      </part>
    </control>
    <control id="IAL1-15">
      <title>IAL1 On-Site Attended Security Controls</title>
      <prop name="label" class="index" value="4.1.9 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-15_smt" name="statement">
        <p>For On-site Attended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes.</p>
      </part>
      <part id="IAL1-15_obj" name="objective">
        <p>Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing.</p>
        <link href="#IAL1-15_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement, certification information,  or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher.</p>
      </part>
    </control>
    <control id="IAL1-16">
      <title>IAL1 On-Site Attended Coercion Training</title>
      <prop name="label" class="index" value="4.1.9 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-16_smt" name="statement">
        <p>For On-site Attended identity proofing, CSP proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the on-site session.</p>
      </part>
      <part id="IAL1-16_obj" name="objective">
        <p>Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process.</p>
        <link href="#IAL1-16_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering.</p>
      </part>
      <part id="IAL1-16_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the training they've received to identify these signs.</p>
      </part>
    </control>
    <control id="IAL1-17">
      <title>IAL1 On-Site Attended Recorded Video</title>
      <prop name="label" class="index" value="4.1.9 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-17_smt" name="statement">
        <p>For On-site Attended identity proofing, if the CSP records a video session, the following additional requirements apply:</p>
        <p>(a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session.</p>
        <p>(b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session.</p>
        <p>(c) The CSP SHALL publish their retention schedule and deletion processes for all video records.</p>
      </part>
      <part id="IAL1-17_obj" name="objective">
        <p>If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met.</p>
        <link href="#IAL1-17_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site attended identity proofing sessions.</p>
      </part>
      <part id="IAL1-17_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the on-site attended identity proofing process to determine that all the requirements for recording video sessions are met.</p>
      </part>
    </control>
    <control id="IAL1-18">
      <title>IAL1 On-Site Attended Fraud Flags</title>
      <prop name="label" class="index" value="4.1.9 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-18_smt" name="statement">
        <p>For On-site Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to covertly flag events for potential fraud.</p>
      </part>
      <part id="IAL1-18_obj" name="objective">
        <p>Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud.</p>
        <link href="#IAL1-18_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud.</p>
      </part>
      <part id="IAL1-18_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud.</p>
      </part>
    </control>
    <control id="IAL1-19">
      <title>IAL1 On-Site Unattended Physical Setting</title>
      <prop name="label" class="index" value="4.1.10 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-19_smt" name="statement">
        <p>For On-site Unattended identity proofing, the CSP SHALL provide a physical setting in which on-site identity proofing sessions are conducted.</p>
      </part>
      <part id="IAL1-19_obj" name="objective">
        <p>Confirm the CSP provides physical location in for on-site attended identity proofing.</p>
        <link href="#IAL1-19_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-19_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that is provides a physical setting for on-site attended identity proofing sessions.</p>
      </part>
      <part id="IAL1-19_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a location where the CSPs conducts on-site identity proofing.</p>
      </part>
    </control>
    <control id="IAL1-20">
      <title>IAL1 On-Site Unattended Security Controls</title>
      <prop name="label" class="index" value="4.1.10 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-20_smt" name="statement">
        <p>For On-site Unattended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes.</p>
      </part>
      <part id="IAL1-20_obj" name="objective">
        <p>Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing.</p>
        <link href="#IAL1-20_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-20_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement, certification information,  or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher.</p>
      </part>
    </control>
    <control id="IAL1-21">
      <title>IAL1 Device Inspection</title>
      <prop name="label" class="index" value="4.1.10 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-21_smt" name="statement">
        <p>For On-site Unattended identity proofing, all devices SHALL be inspected periodically by trained technicians to deter tampering, modification, or damage.</p>
      </part>
      <part id="IAL1-21_obj" name="objective">
        <p>Confirm that the CSP has a policy for ensuring that all equipment used for on-site attended identity proofing is periodically inspected by technicians who are trained to detect tampering, modification, and damage.</p>
        <link href="#IAL1-21_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-21_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for inspecting equipment used for on-site attended identity proofing.</p>
      </part>
    </control>
    <control id="IAL1-22">
      <title>IAL1 On-Site Unattended Recorded Video</title>
      <prop name="label" class="index" value="4.1.10 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-22_smt" name="statement">
        <p>For On-site Unattended identity proofing, if the CSP records a video session, the following additional requirements apply:</p>
        <p>(a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session.</p>
        <p>(b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session.</p>
        <p>(c) The CSP SHALL publish their retention schedule and deletion processes for all video records.</p>
      </part>
      <part id="IAL1-22_obj" name="objective">
        <p>If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met.</p>
        <link href="#IAL1-22_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-22_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site unattended identity proofing sessions.</p>
      </part>
      <part id="IAL1-22_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the on-site unattended identity proofing process to determine that all the requirements for recording video sessions are met.</p>
      </part>
    </control>
    <control id="IAL1-23">
      <title>IAL1 Proofing Notification</title>
      <prop name="label" class="index" value="4.1.11"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-23_smt" name="statement">
        <p>Upon the successful completion of identity proofing at IAL1, the CSP SHALL send a notification of proofing to a validated address for the applicant, as specified in Sec. 3.10.</p>
      </part>
      <part id="IAL1-23_obj" name="objective">
        <p>Confirm that the CSP sends notifications of proofing to validated addresses for applicants after they have successfully complete identity proofing.</p>
        <link href="#IAL1-23_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-23_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it sends notifications of proofing to applicant's validated addresses, upon successful completion of identity proofing.</p>
      </part>
      <part id="IAL1-23_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the identity proofing workflow to confirm that appropriate notifications are delivered to a validated address.</p>
      </part>
      <part id="IAL1-23_gdn" name="guidance">
        <p>Notifications can be delivered to test accounts and addresses as appropriate based on the capabilities of the assessor or the testing environment available to them and any privacy restrictions on the use of legitimate addresses.</p>
      </part>
    </control>
    <control id="IAL1-24">
      <title>IAL1 Authenticator Binding</title>
      <prop name="label" class="index" value="4.1.12 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-24_smt" name="statement">
        <p>The CSP SHALL provide the ability for the applicant to bind an authenticator using one of the following methods:</p>
        <p>(a) Remote enrollment of a subscriber-provided authenticator consistent with the requirements for the authenticator type, as defined in Sec. 4.1.3 of [SP800-63B].</p>
        <p>(b) Distribution of a physical authenticator to a validated address.</p>
        <p>(c) Distribution or on-site enrollment of an authenticator.</p>
      </part>
      <part id="IAL1-24_obj" name="objective">
        <p>Confirm that the CSP provides the ability for an applicant to bind an authenticator using one of the specified methods.</p>
        <link href="#IAL1-24_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-24_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and process for allowing an applicant to bind one or more authenticators to their subscriber account.</p>
      </part>
      <part id="IAL1-24_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the identity proofing workflow to confirm that the applicants are able to bind authenticators using one or more of the specified methods.</p>
      </part>
    </control>
    <control id="IAL1-25">
      <title>IAL1 Subscriber Verification</title>
      <prop name="label" class="index" value="4.1.12 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL1"/>
      <part id="IAL1-25_smt" name="statement">
        <p>If authenticators are bound outside of a single protected session with the user, the CSP SHALL confirm the presence of the intended subscriber through one of the following methods:</p>
        <p>(a) Return of a continuation code.</p>
        <p>(b) Comparison against a biometric collected at the time of proofing.</p>
      </part>
      <part id="IAL1-25_obj" name="objective">
        <p>For authenticators that are bound outside of a single, protection session, confirm that the CSP validates the presence of the intended subscriber through using one of the specified methods.</p>
        <link href="#IAL1-25_smt" rel="assessment-for"/>
      </part>
      <part id="IAL1-25_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its process for confirming the presence of the intended subscriber prior to binding authenticators that were issued after the identity proofing session.</p>
      </part>
      <part id="IAL1-25_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the identity proofing workflow to confirm that the CSP employs its documented processes for using continuation codes or biometrics for confirming the presence of the intended subscriber prior to binding authenticators that were issued outside of the original identity proofing session.</p>
      </part>
    </control>
    <control id="IAL2-1">
      <title>IAL2 Documented Process</title>
      <prop name="label" class="index" value="4.2.1 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-1_smt" name="statement">
        <p>If such steps are combined, CSPs SHALL document their hybrid process and state how the applicable requirements for each of the employed proofing types are met.</p>
      </part>
      <part id="IAL2-1_obj" name="objective">
        <p>[If the CSP employs a hybrid process], confirm that it is documented, and such documentation includes details about how the applicable requirements for each proofing type are met.</p>
        <link href="#IAL2-1_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine how its hybrid identity proofing process meets the applicable requirements.</p>
      </part>
      <part id="IAL2-1_gdn" name="guidance">
        <p>IAL2 identity proofing MAY be delivered through any proofing type, as described in Sec. 2.1.3. CSPs MAY combine proofing types and their stated requirements to create hybrid processes. For example, a CSP might leverage remote unattended identity proofing validation processes in advance of a remote attended session where the verification will take place.</p>
      </part>
    </control>
    <control id="IAL2-2">
      <title>IAL2 Evidence Collection</title>
      <prop name="label" class="index" value="4.2.2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-2_smt" name="statement">
        <p>For identity proofing at IAL2, the CSP SHALL collect: one piece of FAIR evidence and one piece of STRONG evidence; OR, two pieces of STRONG evidence; OR, one piece of SUPERIOR evidence.</p>
      </part>
      <part id="IAL2-2_obj" name="objective">
        <p>Confirm that the CSP collects the specified evidence for identity proofing at IAL 2.</p>
        <link href="#IAL2-2_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its evidence collection requirements for IAL 2.</p>
      </part>
      <part id="IAL2-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL2 identity proofing workflow to determine that documented evidence collection processes are followed.</p>
      </part>
    </control>
    <control id="IAL2-3">
      <title>IAL2 Attribute Collection</title>
      <prop name="label" class="index" value="4.2.3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-3_smt" name="statement">
        <p>The CSP SHALL collect all core attributes, including at least one government identifier. Validated evidence is the preferred source of identity attributes.</p>
      </part>
      <part id="IAL2-3_obj" name="objective">
        <p>Confirm that the CSP collects all core attributes, including at least one government identifier.</p>
        <link href="#IAL2-3_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for collecting core attributes.</p>
      </part>
      <part id="IAL2-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL2 identity proofing workflow to determine that all documented core attribute collection processes are followed.</p>
      </part>
      <part id="IAL2-3_gdn" name="guidance">
        <p>If the presented identity evidence does not provide all of the attributes that the CSP considers to be core attributes, it MAY collect attributes that are self-asserted by the applicant.</p>
      </part>
    </control>
    <control id="IAL2-4">
      <title>IAL2 Fair/Strong Validation</title>
      <prop name="label" class="index" value="4.2.4 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-4_smt" name="statement">
        <p>Each piece of FAIR or STRONG evidence that is presented SHALL be validated using one of the following techniques:</p>
        <p>(a) Confirming the authenticity of the digital evidence by interrogating the digital security features (e.g., signatures on assertions or data).</p>
        <p>(b) Confirming the authenticity of the physical evidence using automated scanning technology that can detect physical security features.</p>
        <p>(c) Confirming the integrity of any physical security features through a visual inspection by a proofing agent using a real-time or asynchronous process (e.g., offline manual review).</p>
        <p>(d) Confirming the integrity of any physical security features through physical and tactile inspection by a proofing agent at an on-site location.</p>
      </part>
      <part id="IAL2-4_obj" name="objective">
        <p>Confirm that the CSP validates each piece of FAIR and STRONG evidence as specified.</p>
        <link href="#IAL2-4_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its process for validating  FAIR and STRONG evidence.</p>
      </part>
      <part id="IAL2-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL2 identity proofing workflow to determine that all documented validation processes for FAIR and STRONG evidence are followed.</p>
      </part>
    </control>
    <control id="IAL2-5">
      <title>IAL2 Superior Validation</title>
      <prop name="label" class="index" value="4.2.4 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-5_smt" name="statement">
        <p>Each piece of SUPERIOR evidence SHALL be validated through the cryptographic verification of the evidence contents and the issuing source, including digital signature verification and the validation of any trust chain back to a trust anchor.</p>
      </part>
      <part id="IAL2-5_obj" name="objective">
        <p>Confirm that the CSP validates each piece of SUPERIOR evidence as specified.</p>
        <link href="#IAL2-5_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its process for validating SUPERIOR evidence.</p>
      </part>
      <part id="IAL2-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL2 identity proofing workflow to determine that all documented validation processes for SUPERIOR evidence are followed.</p>
      </part>
    </control>
    <control id="IAL2-6">
      <title>IAL2 Attribute Validation</title>
      <prop name="label" class="index" value="4.2.5 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-6_smt" name="statement">
        <p>The CSP SHALL validate all core attributes by either:</p>
        <p>(a) Comparing the government identifier and other core attributes against an authoritative or credible source to determine accuracy.</p>
        <p>(b) Validating the accuracy of digitally signed attributes that are contained on SUPERIOR evidence through the public key of the issuing source.</p>
      </part>
      <part id="IAL2-6_obj" name="objective">
        <p>Confirm that the CSP validates all collected core attributes as specified.</p>
        <link href="#IAL2-6_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its core attribute validation policy and processes.</p>
      </part>
      <part id="IAL2-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL2 identity proofing workflow to determine that all core attribute validation processes are followed.</p>
      </part>
      <part id="IAL2-6_gdn" name="guidance">
        <p>CSPs SHOULD evaluate attributes obtained from different sources (e.g., presented evidence, self-asserted, authoritative or credible sources) for consistency.</p>
        <p>CSPs SHOULD validate any reference numbers on the presented identity evidence, if available.</p>
      </part>
    </control>
    <control id="IAL2-7">
      <title>IAL2 Pathway Record</title>
      <prop name="label" class="index" value="4.2.6 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-7_smt" name="statement">
        <p>CSPs that offer multiple verification pathways SHALL record in the subscriber record which pathways were followed to achieve IAL2 and SHALL make that information available to RPs in the assertion, API, or as part of their trust agreement.</p>
      </part>
      <part id="IAL2-7_obj" name="objective">
        <p>If the CSP offers more than one verification pathway at IAL2, confirm that it records the employed pathway in its subscriber accounts.</p>
        <link href="#IAL2-7_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it records which verification pathway was followed in its subscriber accounts.</p>
      </part>
    </control>
    <control id="IAL2-8">
      <title>IAL2 Pathway Assertion</title>
      <prop name="label" class="index" value="4.2.6 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-8_smt" name="statement">
        <p>CSPs that offer multiple verification pathways SHALL make that information available to RPs in the assertion, API, or as part of their trust agreement.</p>
      </part>
      <part id="IAL2-8_obj" name="objective">
        <p>If the CSP offers more than one verification pathway at IAL2, confirm that it makes this information available to RPs that use its service.</p>
        <link href="#IAL2-8_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it makes information about what verification pathway was followed by a subscriber to RPs that use its service.</p>
      </part>
      <part id="IAL2-8_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a sample trust agreement or service contract to determine it makes this information available to its RPs.</p>
      </part>
    </control>
    <control id="IAL2-9">
      <title>IAL2 Non-Bio Pathway</title>
      <prop name="label" class="index" value="4.2.6 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-9_smt" name="statement">
        <p>When the Non-Biometric Pathway is used, the CSP SHALL additionally record whether a mailed confirmation code or a visual comparison of the applicant against evidence was used for verification.</p>
      </part>
      <part id="IAL2-9_obj" name="objective">
        <p>When the Non-Biometric Pathway is used, confirm the CSP records whether verification was accomplished through a mailed confirmation code or a visual comparison of the applicant against evidence.</p>
        <link href="#IAL2-9_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it records the method used to perform verification.</p>
      </part>
    </control>
    <control id="IAL2-10">
      <title>IAL2 Non-Bio Communication</title>
      <prop name="label" class="index" value="4.2.6.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-10_smt" name="statement">
        <p>If provided as an option at IAL2, CSPs SHALL communicate their use of the Non-Biometric Pathway to all RPs that use their identity service.</p>
      </part>
      <part id="IAL2-10_obj" name="objective">
        <p>Confirm that the CSP communicates its use of the Non-Biometric Pathway to all RPs that use its service.</p>
        <link href="#IAL2-10_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it communicates its use of the Non-Biometric Pathway for verification to the RPs that use its service.</p>
      </part>
      <part id="IAL2-10_gdn" name="guidance">
        <p>The IAL2 Non-Biometric Pathway provides verification methods that do not use an automated comparison of biometric samples provided by the applicant. This pathway can still involve the collection and verification of biometric data (e.g., visual comparison to a facial image contained on identity evidence performed by a proofing agent), but such comparisons are done through manual rather than automated means. Additional verification methods that do not require the use of automated biometric comparison are also included in the Digital Evidence Pathway requirements specified in Sec. 4.2.6.2.</p>
      </part>
    </control>
    <control id="IAL2-11">
      <title>IAL2 Non-Bio Evidence</title>
      <prop name="label" class="index" value="4.2.6.1 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-11_smt" name="statement">
        <p>For remote attended, remote unattended, and on-site unattended identity proofing, the CSP SHALL verify the applicant's ownership of all pieces of presented identity evidence. For on-site attended identity proofing, the CSP SHALL verify the applicant's ownership of the strongest piece of presented identity evidence.</p>
      </part>
      <part id="IAL2-11_obj" name="objective">
        <p>For the Non-Biometric Pathway, confirm that the CSP meets the evidence ownership verification requirements associated with the identity proofing type.</p>
        <link href="#IAL2-11_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policies for verifying ownership of identity evidence when using the Non-Biometric Pathway based on the identity proofing type (i.e., remote attended, remote unattended, on-site unattended, on-site attended).</p>
      </part>
      <part id="IAL2-11_gdn" name="guidance">
        <p>Approved non-biometric methods for verifying FAIR evidence at IAL2 include:</p>
        <p>(a) Confirming the applicant's ability to return a confirmation code delivered to a validated address associated with the evidence (e.g., postal address, phone number).</p>
        <p>(b) Visually comparing the applicant's facial image to a facial portrait on the presented evidence (e.g., student or employee ID card) or in records associated with the evidence during an on-site attended session (i.e., in-person with a proofing agent), a remote attended session (i.e., live video with a proofing agent), or an asynchronous process (i.e., visual comparison made by a proofing agent at a different time).</p>
        <p>Approved non-biometric methods for verifying STRONG and SUPERIOR evidence at IAL2 include:</p>
        <p>(b) Visually comparing the applicant's facial image to a facial portrait on the presented evidence or in records associated with the evidence during an on-site attended session (i.e., in-person with a proofing agent), a remote attended session (i.e., live video with a proofing agent), or an asynchronous process (i.e., visual comparison made by a proofing agent at a different time). If the comparison is performed asynchronously at a later time, the CSP SHALL implement PAD and passive or active document presence checks to increase confidence that both the live applicant and physical documents are present during the captured identity proofing event.</p>
      </part>
    </control>
    <control id="IAL2-12">
      <title>IAL2 Digital Evidence</title>
      <prop name="label" class="index" value="4.2.6.2 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-12_smt" name="statement">
        <p>For remote attended, remote unattended, and on-site unattended identity proofing, the CSP SHALL verify the applicant's ownership of all pieces of presented identity evidence. For on-site attended identity proofing, the CSP SHALL verify the applicant's ownership of the strongest piece of presented identity evidence.</p>
      </part>
      <part id="IAL2-12_obj" name="objective">
        <p>For the Digital Evidence Pathway, confirm that the CSP meets the evidence ownership verification requirements associated with the identity proofing type.</p>
        <link href="#IAL2-12_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policies for verifying ownership of identity evidence when using the Digital Evidence Pathway based on the identity proofing type (i.e., remote attended, remote unattended, on-site unattended, on-site attended).</p>
      </part>
      <part id="IAL2-12_gdn" name="guidance">
        <p>Approved digital evidence verification methods for FAIR evidence at IAL2 include: (a Confirming the applicant's ability to return a microtransaction value delivered to a validated account (e.g., checking account owned by the applicant that has been validated by an authoritative or credible source).</p>
        <p>(b) Confirming the applicant's ability to return a confirmation code delivered to a validated digital address associated with the digital evidence (e.g., MNO/phone account).</p>
        <p>(c) Confirming the applicant's ability to successfully complete an authentication and federation protocol equivalent to AAL2/FAL2 to access an account related to the identity evidence.</p>
        <p>Approved digital evidence verification methods for STRONG evidence at IAL2 involve confirming the applicant's ability to successfully complete an authentication and federation protocol equivalent to AAL2/FAL2 or higher to access an account related to the identity evidence.</p>
        <p>Approved digital evidence verification methods for SUPERIOR evidence at IAL2 include confirming the applicant's possession of the evidence through the use of a local activation factor and the presentation of a cryptographically verifiable attribute bundle.</p>
      </part>
    </control>
    <control id="IAL2-13">
      <title>IAL2 Biometric Pathway</title>
      <prop name="label" class="index" value="4.2.6.3 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-13_smt" name="statement">
        <p>For remote attended, remote unattended, and on-site unattended identity proofing, the CSP SHALL verify the applicant's ownership of all pieces of presented identity evidence. For on-site attended identity proofing, the CSP SHALL verify the applicant's ownership of the strongest piece of presented identity evidence.</p>
      </part>
      <part id="IAL2-13_obj" name="objective">
        <p>For the Biometric Pathway, confirm that the CSP meets the evidence ownership verification requirements associated with the identity proofing type.</p>
        <link href="#IAL2-13_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policies for verifying ownership of identity evidence when using the Biometric Pathway based on the identity proofing type (i.e., remote attended, remote unattended, on-site unattended, on-site attended).</p>
      </part>
      <part id="IAL2-13_gdn" name="guidance">
        <p>Approved methods for verifying FAIR, STRONG, and SUPERIOR evidence for use in the IAL2 Biometric Pathway include:</p>
        <p>(a) Using automated means to compare a facial image represented on or stored in the identity evidence or in records associated with the evidence to a live sample provided by the applicant.</p>
        <p>(b) Using automated means to compare a biometric characteristic other than a facial image stored on the identity evidence or in records associated with the evidence to a live sample provided by the applicant.</p>
      </part>
    </control>
    <control id="IAL2-14">
      <title>IAL2 Video Session</title>
      <prop name="label" class="index" value="4.2.8 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-14_smt" name="statement">
        <p>For Remote Attended identity proofing, during the video session, the applicant SHALL remain in view of the proofing agent during each step of the proofing process.</p>
      </part>
      <part id="IAL2-14_obj" name="objective">
        <p>For remote attended video sessions, confirm the CSP requires that the applicant is visible to the proofing agent for each step of the identity proofing process.</p>
        <link href="#IAL2-14_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its requirements for applicant visibility during remote attended identity proofing sessions.</p>
      </part>
      <part id="IAL2-14_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview appropriate personnel to determine the process for viewing applicants during each step of remote attended identity proofing sessions.</p>
      </part>
    </control>
    <control id="IAL2-15">
      <title>IAL2 Video Quality</title>
      <prop name="label" class="index" value="4.2.8 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-15_smt" name="statement">
        <p>For Remote Attended identity proofing, the video quality SHALL be sufficient to support the necessary steps in the validation and verification processes, such as inspecting evidence and comparing the applicant to the evidence.</p>
      </part>
      <part id="IAL2-15_obj" name="objective">
        <p>For remote attended video sessions, confirm the video quality is sufficient to support the needs of the identity proofing process.</p>
        <link href="#IAL2-15_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it employs video technologies of sufficient quality to support the identity proofing processes.</p>
      </part>
    </control>
    <control id="IAL2-16">
      <title>IAL2 Remote Attended Coercion Training</title>
      <prop name="label" class="index" value="4.2.8 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-16_smt" name="statement">
        <p>For Remote Attended identity proofing, proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the session.</p>
      </part>
      <part id="IAL2-16_obj" name="objective">
        <p>Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process.</p>
        <link href="#IAL2-16_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering.</p>
      </part>
      <part id="IAL2-16_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the training they've received to identify these signs.</p>
      </part>
    </control>
    <control id="IAL2-17">
      <title>IAL2 Remote Attended Recorded Video</title>
      <prop name="label" class="index" value="4.2.8 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-17_smt" name="statement">
        <p>For Remote Attended identity proofing, if the CSP records a video session, the following additional requirements apply:</p>
        <p>(a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session.</p>
        <p>(b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session.</p>
        <p>(c) The CSP SHALL publish their retention schedule and deletion processes for all video records.</p>
      </part>
      <part id="IAL2-17_obj" name="objective">
        <p>If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met.</p>
        <link href="#IAL2-17_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording remote attended identity proofing sessions.</p>
      </part>
      <part id="IAL2-17_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the remote attended identity proofing process and determine that all the specified requirements for recording remote attended identity proofing sessions are met.</p>
      </part>
      <part id="IAL2-17_gdn" name="guidance">
        <p>CSPs MAY record and maintain video sessions for fraud prevention and prosecution purposes pursuant to a privacy risk assessment, as defined in Sec. 3.3.1.</p>
      </part>
    </control>
    <control id="IAL2-18">
      <title>IAL2 Injection Protection</title>
      <prop name="label" class="index" value="4.2.8 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-18_smt" name="statement">
        <p>For Remote Attended identity proofing, the CSP SHALL implement injection protection and modified media controls, as defined in Sec. 3.14.</p>
      </part>
      <part id="IAL2-18_obj" name="objective">
        <p>Confirm that the CSP employs injection protection and controls against modified media.</p>
        <link href="#IAL2-18_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it has implemented injection project and modified media controls.</p>
      </part>
    </control>
    <control id="IAL2-19">
      <title>IAL2 Remote Attended Fraud Flags</title>
      <prop name="label" class="index" value="4.2.8 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-19_smt" name="statement">
        <p>For Remote Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to flag events for potential fraud.</p>
      </part>
      <part id="IAL2-19_obj" name="objective">
        <p>Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud.</p>
        <link href="#IAL2-19_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-19_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud.</p>
      </part>
      <part id="IAL2-19_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud.</p>
      </part>
    </control>
    <control id="IAL2-20">
      <title>IAL2 Physical Setting</title>
      <prop name="label" class="index" value="4.2.9 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-20_smt" name="statement">
        <p>For On-site Attended identity proofing, the CSP SHALL provide a physical setting in which on-site identity proofing sessions are conducted.</p>
      </part>
      <part id="IAL2-20_obj" name="objective">
        <p>Confirm the CSP provides physical location in for on-site attended identity proofing.</p>
        <link href="#IAL2-20_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-20_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that is provides a physical setting for on-site attended identity proofing sessions.</p>
      </part>
      <part id="IAL2-20_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a location where the CSPs conducts on-site identity proofing.</p>
      </part>
    </control>
    <control id="IAL2-21">
      <title>IAL2 On-Site Attended Security Controls</title>
      <prop name="label" class="index" value="4.2.9 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-21_smt" name="statement">
        <p>For On-site Attended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes.</p>
      </part>
      <part id="IAL2-21_obj" name="objective">
        <p>Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing.</p>
        <link href="#IAL2-21_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-21_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher.</p>
      </part>
    </control>
    <control id="IAL2-22">
      <title>IAL2 On-Site Attended Coercion Training</title>
      <prop name="label" class="index" value="4.2.9 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-22_smt" name="statement">
        <p>For On-site Attended identity proofing, CSP proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the on-site session.</p>
      </part>
      <part id="IAL2-22_obj" name="objective">
        <p>Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process.</p>
        <link href="#IAL2-22_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-22_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering.</p>
      </part>
      <part id="IAL2-22_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the training they've received to identify these signs.</p>
      </part>
    </control>
    <control id="IAL2-23">
      <title>IAL2 On-Site Attended Recorded Video</title>
      <prop name="label" class="index" value="4.2.9 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-23_smt" name="statement">
        <p>For On-site Attended identity proofing, if the CSP records a video session, the following additional requirements apply:</p>
        <p>(a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session.</p>
        <p>(b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session.</p>
        <p>(c) The CSP SHALL publish their retention schedule and deletion processes for all video records.</p>
      </part>
      <part id="IAL2-23_obj" name="objective">
        <p>If the CSP records on-site attended video identity proofing sessions, confirm that the specified requirements are met.</p>
        <link href="#IAL2-23_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-23_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site attended identity proofing sessions.</p>
      </part>
      <part id="IAL2-23_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the on-site attended identity proofing process to determine that all the requirements for recording video sessions are met.</p>
      </part>
      <part id="IAL2-23_gdn" name="guidance">
        <p>CSPs MAY record and maintain video sessions for fraud prevention and prosecution purposes pursuant to a privacy risk assessment, as defined in Sec. 3.3.1.</p>
      </part>
    </control>
    <control id="IAL2-24">
      <title>IAL2 On-Site Attended Fraud Flags</title>
      <prop name="label" class="index" value="4.2.9 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-24_smt" name="statement">
        <p>For On-site Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to covertly flag events for potential fraud.</p>
      </part>
      <part id="IAL2-24_obj" name="objective">
        <p>Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud.</p>
        <link href="#IAL2-24_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-24_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud.</p>
      </part>
      <part id="IAL2-24_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud.</p>
      </part>
    </control>
    <control id="IAL2-25">
      <title>IAL2 Tamper Prevention</title>
      <prop name="label" class="index" value="4.2.10 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-25_smt" name="statement">
        <p>For On-site Unattended identity proofing, all devices SHALL be safeguarded from tampering through observation by CSP representatives and/or physical and digital tamper prevention features.</p>
      </part>
      <part id="IAL2-25_obj" name="objective">
        <p>Confirm that the CSP safeguards all devices and equipment used for on-site unattended identity proofing at IAL2 are safeguarded from tampering.</p>
        <link href="#IAL2-25_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-25_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it safeguards the devices it uses for on-site attended identity proofing from tampering.</p>
      </part>
    </control>
    <control id="IAL2-26">
      <title>IAL2 On-Site Unattended Security Controls</title>
      <prop name="label" class="index" value="4.2.10 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-26_smt" name="statement">
        <p>For On-site Unattended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes.</p>
      </part>
      <part id="IAL2-26_obj" name="objective">
        <p>Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing.</p>
        <link href="#IAL2-26_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-26_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher.</p>
      </part>
    </control>
    <control id="IAL2-27">
      <title>IAL2 Device Inspection</title>
      <prop name="label" class="index" value="4.2.10 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-27_smt" name="statement">
        <p>For On-site Unattended identity proofing, all devices SHALL be inspected periodically by trained technicians to deter tampering, modification, or damage.</p>
      </part>
      <part id="IAL2-27_obj" name="objective">
        <p>Confirm that the CSP has a policy for ensuring that all equipment used for on-site attended identity proofing is periodically inspected by technicians who are trained to detect tampering, modification, and damage.</p>
        <link href="#IAL2-27_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-27_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for inspecting equipment used for on-site attended identity proofing.</p>
      </part>
    </control>
    <control id="IAL2-28">
      <title>IAL2 On-Site Unattended Recorded Video</title>
      <prop name="label" class="index" value="4.2.10 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-28_smt" name="statement">
        <p>For On-site Unattended identity proofing, if the CSP records a video session, the following additional requirements apply:</p>
        <p>(a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session.</p>
        <p>(b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session.</p>
        <p>(c) The CSP SHALL publish their retention schedule and deletion processes for all video records.</p>
      </part>
      <part id="IAL2-28_obj" name="objective">
        <p>If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met.</p>
        <link href="#IAL2-28_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-28_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site unattended identity proofing sessions.</p>
      </part>
      <part id="IAL2-28_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the on-site unattended identity proofing process to determine that all the requirements for recording video sessions are met.</p>
      </part>
    </control>
    <control id="IAL2-29">
      <title>IAL2 Proofing Notification</title>
      <prop name="label" class="index" value="4.2.11"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-29_smt" name="statement">
        <p>Upon the successful completion of identity proofing at IAL2, the CSP SHALL send a notification of proofing to a validated address for the applicant, as specified in Sec. 3.10.</p>
      </part>
      <part id="IAL2-29_obj" name="objective">
        <p>Confirm that the CSP sends notifications of proofing to validated addresses for applicants after they have successfully complete identity proofing.</p>
        <link href="#IAL2-29_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-29_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it sends notifications of proofing to applicant's validated addresses, upon successful completion of identity proofing.</p>
      </part>
      <part id="IAL2-29_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the identity proofing workflow to confirm that appropriate notifications are delivered to a validated address.</p>
      </part>
      <part id="IAL2-29_gdn" name="guidance">
        <p>CSPs SHOULD send the notification of proofing to the applicant's postal address. Note to assessors: Notifications can be delivered to test accounts and addresses as appropriate based on the capabilities of the assessor or the testing environment available to them and any privacy restrictions on the use of legitimate addresses.</p>
      </part>
    </control>
    <control id="IAL2-30">
      <title>IAL2 Authenticator Binding</title>
      <prop name="label" class="index" value="4.2.12 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-30_smt" name="statement">
        <p>The CSP SHALL provide the ability for the applicant to bind an authenticator using one of the following methods:</p>
        <p>(a) Remote enrollment of a subscriber-provided authenticator consistent with the requirements for the authenticator type, as defined in Sec. 4.1.3 of [SP800-63B].</p>
        <p>(b) Distribution of a physical authenticator to a validated address.</p>
        <p>(c) Distribution or on-site enrollment of an authenticator.</p>
      </part>
      <part id="IAL2-30_obj" name="objective">
        <p>Confirm that the CSP provides the ability for an applicant to bind an authenticator using one of the specified methods.</p>
        <link href="#IAL2-30_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-30_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and process for allowing an applicant to bind one or more authenticators to their subscriber account.</p>
      </part>
      <part id="IAL2-30_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the identity proofing workflow to confirm that the applicants are able to bind authenticators using one or more of the specified methods.</p>
      </part>
    </control>
    <control id="IAL2-31">
      <title>IAL2 Subscriber Verification</title>
      <prop name="label" class="index" value="4.2.12 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL2"/>
      <part id="IAL2-31_smt" name="statement">
        <p>If authenticators are bound outside of a single protected session with the user, the CSP SHALL confirm the presence of the intended subscriber through one of the following methods:</p>
        <p>(a) Return of a continuation code.</p>
        <p>(b) Comparison against a biometric collected at the time of proofing.</p>
      </part>
      <part id="IAL2-31_obj" name="objective">
        <p>For authenticators that are bound outside of a single, protection session, confirm that the CSP validates the presence of the intended subscriber through using one of the specified methods.</p>
        <link href="#IAL2-31_smt" rel="assessment-for"/>
      </part>
      <part id="IAL2-31_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its process for verifying subscribers prior to binding authenticators outside of a single protected session.</p>
      </part>
      <part id="IAL2-31_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the authenticator binding workflow to confirm that the CSP employs its documented processes for using continuation codes or biometrics to confirm the presence of the intended subscriber prior to binding authenticators that were issued outside of the original identity proofing session.</p>
      </part>
    </control>
    <control id="IAL3-1">
      <title>IAL3 On-Site Attended</title>
      <prop name="label" class="index" value="4.3.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-1_smt" name="statement">
        <p>IAL3 identity proofing SHALL only be delivered as on-site attended.</p>
      </part>
      <part id="IAL3-1_obj" name="objective">
        <p>Confirm that the CSP only offers on-site attended (Collocated Agent or Kiosk-based) identity proofing for IAL3.</p>
        <link href="#IAL3-1_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that all IAL3 identity proofing is conducted via on-site attended processes.</p>
      </part>
      <part id="IAL3-1_gdn" name="guidance">
        <p>The proofing agent MAY be co-located with the applicant or attend the identity proofing session via a CSP-controlled kiosk or device.</p>
      </part>
    </control>
    <control id="IAL3-2">
      <title>IAL3 Evidence Collection</title>
      <prop name="label" class="index" value="4.3.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-2_smt" name="statement">
        <p>For identity proofing at IAL3, the CSP SHALL collect: one piece of FAIR evidence and one piece of STRONG evidence; OR, two pieces of STRONG evidence; OR one piece of SUPERIOR evidence.</p>
      </part>
      <part id="IAL3-2_obj" name="objective">
        <p>Confirm that the CSP collects the specified evidence for identity proofing at IAL .</p>
        <link href="#IAL3-2_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its evidence collection requirements for IAL 3.</p>
      </part>
      <part id="IAL3-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL3 identity proofing workflow to determine that documented evidence collection processes are followed.</p>
      </part>
    </control>
    <control id="IAL3-3">
      <title>IAL3 Attribute Collection</title>
      <prop name="label" class="index" value="4.3.3 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-3_smt" name="statement">
        <p>The CSP SHALL collect all core attributes, including at least one government identifier.</p>
      </part>
      <part id="IAL3-3_obj" name="objective">
        <p>Confirm that the CSP collects all core attributes, including at least one government identifier.</p>
        <link href="#IAL3-3_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for collecting core attributes.</p>
      </part>
      <part id="IAL3-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL3 identity proofing workflow to determine that all documented core attribute collection processes are followed.</p>
      </part>
      <part id="IAL3-3_gdn" name="guidance">
        <p>Validated evidence is the preferred source of identity attributes. If the presented identity evidence does not provide all of the attributes that a CSP considers to be core attributes, the CSP MAY collect attributes that are self asserted by the applicant.</p>
      </part>
    </control>
    <control id="IAL3-4">
      <title>IAL3 Fair Strong</title>
      <prop name="label" class="index" value="4.3.4 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-4_smt" name="statement">
        <p>Each piece of FAIR or STRONG evidence that is presented SHALL be validated using one of the following techniques:</p>
        <p>(a) Confirming the authenticity of the digital evidence by interrogating the digital security features (e.g., signatures on assertions or data).</p>
        <p>(b) Confirming the authenticity of the physical evidence using automated scanning technology that can detect physical security features.</p>
        <p>(c) Confirming the integrity of any physical security features through a visual inspection by a proofing agent using a real-time or asynchronous process (e.g., offline manual review).</p>
      </part>
      <part id="IAL3-4_obj" name="objective">
        <p>Confirm that the CSP validates each piece of FAIR or STRONG evidence using the one of the techniques provided in item #1 of Sec. 4.3.4.</p>
        <link href="#IAL3-4_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and process for validating FAIR and STRONG evidence at IAL3.</p>
      </part>
      <part id="IAL3-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL3 identity proofing workflow to determine that all documented validation processes for FAIR and STRONG evidence are followed.</p>
      </part>
    </control>
    <control id="IAL3-5">
      <title>IAL3 Superior Evidence</title>
      <prop name="label" class="index" value="4.3.4 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-5_smt" name="statement">
        <p>Each piece of SUPERIOR evidence SHALL be validated through the cryptographic verification of the evidence contents and the issuing source, including digital signature verification and the validation of any trust chain back to a trust anchor.</p>
      </part>
      <part id="IAL3-5_obj" name="objective">
        <p>Confirm that the CSP validates each piece of presented SUPERIOR evidence through the cryptographic verification of the evidence contents and the issuing source.</p>
        <link href="#IAL3-5_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and process for validating SUPERIOR evidence at IAL3.</p>
      </part>
      <part id="IAL3-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL3 identity proofing workflow to determine that all documented validation processes for SUPERIOR evidence are followed.</p>
      </part>
    </control>
    <control id="IAL3-6">
      <title>IAL3 ID Verification</title>
      <prop name="label" class="index" value="4.3.6 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-6_smt" name="statement">
        <p>The CSP SHALL verify the applicant's ownership of the strongest piece of evidence (STRONG or SUPERIOR) by one of the following methods:</p>
        <p>(a) Confirming the applicant's ability to successfully authenticate to a physical device or application (e.g., a mobile driver's license) and comparing a digitally protected and transmitted facial portrait to the applicant.</p>
        <p>(b) Comparing the applicant's facial image to the facial portrait on the presented evidence via an automated comparison.</p>
        <p>(c) Visually comparing the applicant's facial image to the facial portrait on the presented evidence during an on-site attended session or a remote attended session.</p>
        <p>(d) Performing an automated comparison of a stored biometric on the identity evidence or in the authoritative records associated with the evidence to a sample provided by the applicant.</p>
      </part>
      <part id="IAL3-6_obj" name="objective">
        <p>Confirm that the CSP verifies the applicant's ownership of the strongest piece of evidence by one of the methods provided in Sec 4.3.6.</p>
        <link href="#IAL3-6_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine how it verifies an applicant's ownership of the strongest piece of presented evidence.</p>
      </part>
      <part id="IAL3-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the CSP's IAL3 identity proofing workflow to determine that all documented verification processes for evidence are followed.</p>
      </part>
    </control>
    <control id="IAL3-7">
      <title>IAL3 Secure Setting</title>
      <prop name="label" class="index" value="4.3.7 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-7_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, the CSP SHALL provide a secure, physical setting in which on-site identity proofing sessions are conducted.</p>
      </part>
      <part id="IAL3-7_obj" name="objective">
        <p>Confirm that the CSP provides a secure, physical setting for on-site attended identity proofing sessions with collocated agents.</p>
        <link href="#IAL3-7_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides a secure, physical setting for on-site attended identity proofing sessions with collocated agents to determine the setting is secure.</p>
      </part>
      <part id="IAL3-7_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine one or more locations where the CSP conducts on-site attended identity proofing with collocated agents.</p>
      </part>
    </control>
    <control id="IAL3-8">
      <title>IAL3 Biometric Capture</title>
      <prop name="label" class="index" value="4.3.7 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-8_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, the CSP SHALL provide sensors and capture devices for the collection of biometrics from the applicant.</p>
      </part>
      <part id="IAL3-8_obj" name="objective">
        <p>Confirm that the workstations the CSP employs for on-site identity proofing at IAL3 include devices for the secure collection of biometric samples.</p>
        <link href="#IAL3-8_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the workstations it employs for on-site identity proofing include sensors and capture devices for the secure collection of biometric samples.</p>
      </part>
      <part id="IAL3-8_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine one or more identity proofing sites to determine the CSP provides sensors and capture devices for the collection of biometrics.</p>
      </part>
    </control>
    <control id="IAL3-9">
      <title>View Biometric Source</title>
      <prop name="label" class="index" value="4.3.7 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-9_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, the CSP SHALL have the proofing agent view the source of the collected biometric for the presence of any non-natural materials (e.g., putty, glue).</p>
      </part>
      <part id="IAL3-9_obj" name="objective">
        <p>Confirm that the CSP requires its IAL3 proofing agents to view the source of the biometric (applicant's face, fingers, etc.) for the presence of any non-natural materials.</p>
        <link href="#IAL3-9_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it requires its collocated proofing agents to view the source of biometric samples.</p>
      </part>
      <part id="IAL3-9_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents to determine that they are required and understand how to view the source(s) of biometric samples for the presences of non-natural materials.</p>
      </part>
    </control>
    <control id="IAL3-10">
      <title>Biometric Collection Source</title>
      <prop name="label" class="index" value="4.3.7 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-10_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, the CSP SHALL have the proofing agent collect the biometric samples in such a way that ensures the sample was collected from the applicant and no other source.</p>
      </part>
      <part id="IAL3-10_obj" name="objective">
        <p>Confirm that the CSP employs practices and mechanisms that ensure that all biometric samples are collected from the intended applicant.</p>
        <link href="#IAL3-10_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it employs practices and mechanisms to ensure that all biometric samples are collected from the intended applicants.</p>
      </part>
    </control>
    <control id="IAL3-11">
      <title>IAL3 Colocated Agent Security Controls</title>
      <prop name="label" class="index" value="4.3.7 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-11_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, the CSP SHALL ensure that all information systems and technology leveraged by proofing agents and trusted referees are protected consistent with at least FISMA moderate or comparable levels of controls, including physical controls for the proofing facility.</p>
      </part>
      <part id="IAL3-11_obj" name="objective">
        <p>Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all information systems and equipment used for on-site attended identity proofing with collocated agents.</p>
        <link href="#IAL3-11_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm it protects all information systems and equipment used in on-site attended identity proofing with collocated agents by security controls comparable to FISMA moderate or higher.</p>
      </part>
    </control>
    <control id="IAL3-12">
      <title>IAL3 Coercion Training</title>
      <prop name="label" class="index" value="4.3.7 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-12_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, CSP proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the on-site session.</p>
      </part>
      <part id="IAL3-12_obj" name="objective">
        <p>Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process.</p>
        <link href="#IAL3-12_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering.</p>
      </part>
      <part id="IAL3-12_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the training they've received to identify these signs.</p>
      </part>
    </control>
    <control id="IAL3-13">
      <title>IAL3 Recorded Video</title>
      <prop name="label" class="index" value="4.3.7 #7"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-13_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, if the CSP records a session, the following additional requirements apply:</p>
        <p>(a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session.</p>
        <p>(b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session.</p>
        <p>(c) The CSP SHALL publish their retention schedule and deletion processes for all video records.</p>
      </part>
      <part id="IAL3-13_obj" name="objective">
        <p>If the CSP records video sessions of on-site attended identity proofing with collocated agents at IAL3, confirm that the requirements specified in Sec. 4.3.7 #7 are met.</p>
        <link href="#IAL3-13_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site attended with collocated agent identity proofing sessions.</p>
      </part>
      <part id="IAL3-13_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the on-site attended with collocated agent identity proofing process and determine that all the specified requirements for recording remote attended identity proofing sessions are met.</p>
      </part>
      <part id="IAL3-13_gdn" name="guidance">
        <p>CSPs MAY record and maintain video sessions for fraud prevention and prosecution purposes pursuant to a privacy risk assessment, as defined in Sec. 3.3.1.</p>
      </part>
    </control>
    <control id="IAL3-14">
      <title>IAL3 Fraud Flags</title>
      <prop name="label" class="index" value="4.3.7 #8"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-14_smt" name="statement">
        <p>For on-site attended identity proofing with collocated agents, the CSP SHALL provide proofing agents with a method or mechanism to discretely flag events or actions as potential fraud.</p>
      </part>
      <part id="IAL3-14_obj" name="objective">
        <p>Confirm the CSP provides its collocated proofing agents with a mechanism to flag potential fraud.</p>
        <link href="#IAL3-14_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud.</p>
      </part>
      <part id="IAL3-14_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud.</p>
      </part>
    </control>
    <control id="IAL3-15">
      <title>Kiosk Video Transmission</title>
      <prop name="label" class="index" value="4.3.8 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-15_smt" name="statement">
        <p>For kiosk-based on-site attended identity proofing, the CSP SHALL monitor the entire identity proofing session through a high-resolution video transmission with the applicant.</p>
      </part>
      <part id="IAL3-15_obj" name="objective">
        <p>Confirm that all workstations and kiosks employed by the CSP for kiosk-based on-site attended identity proofing at IAL3 include video cameras that support high-resolution video transmission.</p>
        <link href="#IAL3-15_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it employs high-resolution video cameras in the kiosk used for kiosk-based on-site attended identity proofing at IAL3.</p>
      </part>
    </control>
    <control id="IAL3-16">
      <title>Live Agent Participation</title>
      <prop name="label" class="index" value="4.3.8 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-16_smt" name="statement">
        <p>For kiosk-based on-site attended identity proofing, the CSP SHALL have a live proofing agent participate remotely with the applicant for the evidence collection, evidence validation, and verification steps of the identity proofing process.</p>
      </part>
      <part id="IAL3-16_obj" name="objective">
        <p>Confirm that the CSP's proofing agents participate remotely in the evidence collection, evidence validation, and identity verification steps of kiosk-based on-site attended identity proofing at IAL3.</p>
        <link href="#IAL3-16_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its agents participate remotely in the evidence collection, evidence validation, and identity verification steps for kiosk-based on-site attended identity proofing at IAL3.</p>
      </part>
      <part id="IAL3-16_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents of the CSP to determine that, for kiosk-based on-site attended identity proofing, they are required to participate remotely, at a minimum, in the evidence collection, evidence validation, and identity verification steps of the identity proofing process for IAL3.</p>
      </part>
    </control>
    <control id="IAL3-17">
      <title>Clearly Visible Actions</title>
      <prop name="label" class="index" value="4.3.8 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-17_smt" name="statement">
        <p>For kiosk-based on-site attended identity proofing, the CSP SHALL require all actions taken by the applicant during the evidence collection, evidence validation, and verification steps to be clearly visible to the remote proofing agent.</p>
      </part>
      <part id="IAL3-17_obj" name="objective">
        <p>Confirm that the CSP designs the workstations used for kiosk-based on-site attended identity proofing at IAL3 so that all specified actions taken by the applicants are clearly visible to proofing agents who are participating remotely.</p>
        <link href="#IAL3-17_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that all specified actions taken by the applicant in kiosk-based on-site attended identity proofing at IAL3 are visible to the remote proofing agent.</p>
      </part>
      <part id="IAL3-17_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents of the CSP to determine that, for kiosk-based on-site attended identity proofing, all specified actions taken by the applicant are visible to the remote proofing agent.</p>
      </part>
    </control>
    <control id="IAL3-18">
      <title>IAL3 Integrated Sensors</title>
      <prop name="label" class="index" value="4.3.8 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-18_smt" name="statement">
        <p>For kiosk-based on-site attended identity proofing, the CSP SHALL require that all digital validation and verification of evidence be performed by integrated scanners and sensors.</p>
      </part>
      <part id="IAL3-18_obj" name="objective">
        <p>Confirm that the CSP's kiosk-based identity proofing stations employ integrated scanners and sensors.</p>
        <link href="#IAL3-18_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that kiosk-based identity proofing stations employ integrated scanners and sensors.</p>
      </part>
      <part id="IAL3-18_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine one or more stations used for kiosk-based on-site attended identity proofing to determine it includes integrated scanners and sensors.</p>
      </part>
      <part id="IAL3-18_gdn" name="guidance">
        <p>Scanners and sensors that are built into the</p>
      </part>
    </control>
    <control id="IAL3-19">
      <title>Kiosk Tamper Prevention</title>
      <prop name="label" class="index" value="4.3.8 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-19_smt" name="statement">
        <p>For kiosk-based on-site attended identity proofing, all devices used to support interaction between the proofing agent and the applicant SHALL be safeguarded from tampering through observation by CSP representatives or monitoring devices (e.g., cameras) and through physical and digital tamper prevention features.</p>
      </part>
      <part id="IAL3-19_obj" name="objective">
        <p>Confirm that the CSP employs mechanisms to safeguard the equipment and devices used for kiosk-based on-site attended identity proofing from tampering.</p>
        <link href="#IAL3-19_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-19_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the safeguards it employs to protect its kiosk-based on-site attended identity proofing stations from tampering.</p>
      </part>
    </control>
    <control id="IAL3-20">
      <title>IAL3 Kiosk-Based Security Controls</title>
      <prop name="label" class="index" value="4.3.8 #6"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-20_smt" name="statement">
        <p>For kiosk-based on-site attended identity proofing, all devices used to support interaction between the proofing agent and the applicant SHALL be protected by appropriate baseline security features that are comparable to at least FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes.</p>
      </part>
      <part id="IAL3-20_obj" name="objective">
        <p>Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all information systems and equipment used for kiosk-based on-site attended identity proofing.</p>
        <link href="#IAL3-20_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-20_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to confirm it protects all information systems and equipment used in kiosk-based on-site attended identity proofing by security controls comparable to FISMA moderate or higher.</p>
      </part>
    </control>
    <control id="IAL3-21">
      <title>IAL3 Device Inspection</title>
      <prop name="label" class="index" value="4.3.8 #7"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-21_smt" name="statement">
        <p>For kiosk-based on-site attended identity proofing, all devices used to support interaction between the proofing agent and the applicant SHALL be inspected periodically by trained technicians to deter tampering, modification, or damage.</p>
      </part>
      <part id="IAL3-21_obj" name="objective">
        <p>Confirm that the CSP ensures that the devices and stations used for kiosk-based on-site attended identity proofing are inspected periodically by trained technicians.</p>
        <link href="#IAL3-21_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-21_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it employs trained technicians to periodically inspect the equipment and area used for kiosk-based on-site attended identity proofing for evidence of tampering, modification, or damage.</p>
      </part>
    </control>
    <control id="IAL3-22">
      <title>IAL3 Proofing Notification</title>
      <prop name="label" class="index" value="4.3.9 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-22_smt" name="statement">
        <p>Upon the successful completion of identity proofing at IAL3, the CSP SHALL send a notification of proofing to a validated address for the applicant, as specified in Sec. 3.10.</p>
      </part>
      <part id="IAL3-22_obj" name="objective">
        <p>Confirm that the CSP sends notifications of proofing to validated addresses for applicants after they have successfully complete identity proofing.</p>
        <link href="#IAL3-22_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-22_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it sends notifications of proofing to applicant's validated addresses, upon successful completion of identity proofing.</p>
      </part>
      <part id="IAL3-22_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the identity proofing workflow to confirm that appropriate notifications are delivered to a validated address.</p>
      </part>
      <part id="IAL3-22_gdn" name="guidance">
        <p>CSPs SHOULD send the notification of proofing to the applicant's postal address. Note to assessors: Notifications can be delivered to test accounts and addresses as appropriate based on the capabilities of the assessor or the testing environment available.</p>
      </part>
    </control>
    <control id="IAL3-23">
      <title>IAL3 Authenticator Binding</title>
      <prop name="label" class="index" value="4.3.10 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-23_smt" name="statement">
        <p>The CSP SHALL distribute or enroll the subscriber's initial authenticator during an on-site attended interaction with a proofing agent.</p>
      </part>
      <part id="IAL3-23_obj" name="objective">
        <p>Confirm that the CSP distributes and/or enrolls the subscriber's initial authenticator during an on-site attended session with a proofing agent.</p>
        <link href="#IAL3-23_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-23_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and process for distributing and/or enrolling the subscriber's initial authenticator.</p>
      </part>
      <part id="IAL3-23_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview one or more proofing agents to determine that the CSP distributes and enrolls initial authenticators during on-site attended identity proofing sessions.</p>
      </part>
    </control>
    <control id="IAL3-24">
      <title>IAL3 Subscriber Verification</title>
      <prop name="label" class="index" value="4.3.10 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="IAL3"/>
      <part id="IAL3-24_smt" name="statement">
        <p>If the CSP distributes or enrolls the initial authenticator outside of a single authenticated protected session with the subscriber, the CSP SHALL compare a biometric sample collected from the subscriber to the one collected at the time of proofing prior to registration of the authenticator.</p>
      </part>
      <part id="IAL3-24_obj" name="objective">
        <p>For initial authenticators that are distributed or enrolled outside a single authenticated protected session with the subscriber, confirm that the  CSP compares a biometric sample collected from the subscriber to the one collected at the time of proofing prior to registration of the authenticator.</p>
        <link href="#IAL3-24_smt" rel="assessment-for"/>
      </part>
      <part id="IAL3-24_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its process for verifying subscribers prior to binding authenticators outside of a single protected session.</p>
      </part>
      <part id="IAL3-24_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the authenticator binding workflow to confirm that the CSP employs biometric comparison to confirm the presence of the intended subscriber prior to binding authenticators that were issued outside of the original identity proofing session.</p>
      </part>
      <part id="IAL3-24_gdn" name="guidance">
        <p>The CSP MAY request that the subscriber bring the identity evidence used during the proofing process to further strengthen the process of binding the authenticator to the subscriber.</p>
      </part>
    </control>
    <control id="SUB-1">
      <title>Unique Subscriber Account</title>
      <prop name="label" class="index" value="5.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-1_smt" name="statement">
        <p>The CSP SHALL establish and maintain a unique subscriber account for each active subscriber in its identity system from the time of enrollment to the time of account closure.</p>
      </part>
      <part id="SUB-1_obj" name="objective">
        <p>Confirm that the CSP establishes and maintains subscriber accounts for all its active subscribers.</p>
        <link href="#SUB-1_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it establishes and maintains unique accounts for its active subscribers.</p>
      </part>
      <part id="SUB-1_gdn" name="guidance">
        <p>The CSP establishes a subscriber account to record each subscriber as a unique identity within its identity service and to maintain a record of all authenticators associated with that account.</p>
      </part>
    </control>
    <control id="SUB-2">
      <title>Subscriber Identifier</title>
      <prop name="label" class="index" value="5.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-2_smt" name="statement">
        <p>The CSP SHALL assign a unique identifier to each subscriber account.</p>
      </part>
      <part id="SUB-2_obj" name="objective">
        <p>Confirm that the CSP assigns a unique identifier to each subscriber account.</p>
        <link href="#SUB-2_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it assigns a unique identifier to each subscriber account.</p>
      </part>
      <part id="SUB-2_gdn" name="guidance">
        <p>The identifier SHOULD be randomly generated by the CSP's system and of sufficient length and entropy to ensure uniqueness within its user population and to support federation with RPs, where applicable. The identifier MAY be used as a subject identifier in the generation of assertions, consistent with [SP800-63C].</p>
      </part>
    </control>
    <control id="SUB-3">
      <title>Subscriber Account Information</title>
      <prop name="label" class="index" value="5.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-3_smt" name="statement">
        <p>At a minimum, the CSP SHALL include the following information in each subscriber account: the unique identifier associated with the subscriber account; any subject identifiers established for the subscriber, including any RP-specific subject identifiers; a record of the identity proofing steps completed for the subscriber;* maximum IAL successfully achieved for the identity proofing of the subscriber; records of any applicant consent agreements related to the collection and processing of information about the applicant throughout the subscriber account life cycle, including biometrics; all authenticators currently bound to the subscriber account, whether registered at enrollment or subsequent to enrollment; and attributes that were validated during the identity proofing process or in subsequent transactions to support RP access.</p>
      </part>
      <part id="SUB-3_obj" name="objective">
        <p>Confirm that CSP's subscriber accounts include all the specified information.</p>
        <link href="#SUB-3_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine what information it stores in its subscriber accounts.</p>
      </part>
      <part id="SUB-3_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine one or more example subscriber accounts to determine it includes, at a minimum, the specified information.</p>
      </part>
      <part id="SUB-3_gdn" name="guidance">
        <ul>
          <li>
            <p>Required details about the identity proofing steps completed for the subscriber include:</p>
          </li>
          <li>
            <p>The type and issuer of identity evidence.</p>
          </li>
          <li>
            <p>The type of proofing (i.e., remote unattended, remote attended, on-site attended, on-site unattended).</p>
          </li>
          <li>
            <p>The validation and verification methods used.</p>
          </li>
          <li>
            <p>The use of a trusted referee or other exception handling process.</p>
          </li>
          <li>
            <p>The use of an applicant reference, including a unique identifier for the applicant reference.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="SUB-4">
      <title>Subscriber Account Access</title>
      <prop name="label" class="index" value="5.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-4_smt" name="statement">
        <p>The CSP SHALL provide the capability for subscribers to authenticate and access information in their subscriber account.</p>
      </part>
      <part id="SUB-4_obj" name="objective">
        <p>Confirm that the CSP provides subscribers with the ability to access their subscriber accounts.</p>
        <link href="#SUB-4_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides subscribers with the ability to access their accounts.</p>
      </part>
      <part id="SUB-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine that appropriately authenticated subscribers can access their subscriber account information.</p>
      </part>
    </control>
    <control id="SUB-5">
      <title>Subscriber Account AAL</title>
      <prop name="label" class="index" value="5.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-5_smt" name="statement">
        <p>For subscriber accounts that contain personal information, this capability SHALL be accomplished through AAL2 or AAL3 authentication processes using authenticators that are registered to the subscriber account.</p>
      </part>
      <part id="SUB-5_obj" name="objective">
        <p>Confirm that the CSP requires subscribers to authenticate to their accounts using registered authenticators and AAL2 or AAL3 processes.</p>
        <link href="#SUB-5_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the authentication processes associated with accessing subscriber accounts that contain personal information.</p>
      </part>
      <part id="SUB-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine that a subscriber account with PII requires at least AAL2 authentication.</p>
      </part>
    </control>
    <control id="SUB-6">
      <title>SA Update Requests</title>
      <prop name="label" class="index" value="5.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-6_smt" name="statement">
        <p>The CSP SHALL provide the capability for a subscriber to request that information be updated in their subscriber account.</p>
      </part>
      <part id="SUB-6_obj" name="objective">
        <p>Confirm that the CSP provides the ability for subscribers to request updates to the information contained in their accounts.</p>
        <link href="#SUB-6_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and process for subscribers to request information be updated in their subscriber accounts.</p>
      </part>
      <part id="SUB-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine that subscribers can request changes to their subscriber information.</p>
      </part>
    </control>
    <control id="SUB-7">
      <title>Core Attribute Updates</title>
      <prop name="label" class="index" value="5.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-7_smt" name="statement">
        <p>With the exception of physical addresses, the CSP SHALL validate any changes to core attribute information maintained in the subscriber account.</p>
      </part>
      <part id="SUB-7_obj" name="objective">
        <p>Confirm that the CSP validates any updated core attribute information maintained in a subscriber's account, with the exception of physical address.</p>
        <link href="#SUB-7_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for validating updated core attribute information stored in a subscriber's account.</p>
      </part>
    </control>
    <control id="SUB-8">
      <title>SA Update Notifications</title>
      <prop name="label" class="index" value="5.3 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-8_smt" name="statement">
        <p>The CSP SHALL notify the subscriber of any updates made to information in the subscriber account.</p>
      </part>
      <part id="SUB-8_obj" name="objective">
        <p>Confirm that the CSP notifies its subscribers anytime information in their subscriber accounts changes.</p>
        <link href="#SUB-8_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy or process for notifying subscribers when information in their accounts is updated.</p>
      </part>
      <part id="SUB-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine that subscribers can request changes to their subscriber information.</p>
      </part>
    </control>
    <control id="SUB-9">
      <title>Subscriber Account Compromise</title>
      <prop name="label" class="index" value="5.3 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-9_smt" name="statement">
        <p>The CSP SHALL provide the capability for the subscriber to report any unauthorized access or potential compromise to information in their subscriber account.</p>
      </part>
      <part id="SUB-9_obj" name="objective">
        <p>Confirm that the CSP provides a mechanism for subscribers to report suspected or confirmed incidents of fraud associated with their accounts.</p>
        <link href="#SUB-9_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine it provides the capability for subscribers to report any unauthorized access or suspect incidence of fraud in association with their subscriber accounts.</p>
      </part>
      <part id="SUB-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test this capability.</p>
      </part>
    </control>
    <control id="SUB-10">
      <title>Subscriber Account Termination</title>
      <prop name="label" class="index" value="5.4 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-10_smt" name="statement">
        <p>The CSP SHALL promptly suspend or terminate the subscriber account when [any of events listed in Sec. 5.4 occurs].</p>
      </part>
      <part id="SUB-10_obj" name="objective">
        <p>Confirm that the CSP suspends or terminates subscriber accounts when any of the specified conditions occurs.</p>
        <link href="#SUB-10_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy and process for suspending or terminating subscriber accounts based on the specified conditions.</p>
      </part>
    </control>
    <control id="SUB-11">
      <title>Account Status Notification</title>
      <prop name="label" class="index" value="5.4 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-11_smt" name="statement">
        <p>The CSP SHALL notify the subscriber if their account has been suspended or terminated.</p>
      </part>
      <part id="SUB-11_obj" name="objective">
        <p>Confirm that the CSP notifies subscribers if their subscriber account has been suspended or terminated.</p>
        <link href="#SUB-11_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for notifying a subscriber if their account has been suspended or terminated.</p>
      </part>
      <part id="SUB-11_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of such a notice.</p>
      </part>
    </control>
    <control id="SUB-12">
      <title>SA Notification Details</title>
      <prop name="label" class="index" value="5.4 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-12_smt" name="statement">
        <p>Such notices SHALL include information about why the account was suspended or terminated, reactivation or renewal options, and any options for redress if the subscriber thinks the account was suspended or terminated in error.</p>
      </part>
      <part id="SUB-12_obj" name="objective">
        <p>Confirm that the CSP's account suspension or termination notices include sufficient details about the action and options for redress in the case of error.</p>
        <link href="#SUB-12_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine what information is included in its account suspension or termination notices.</p>
      </part>
      <part id="SUB-12_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example of such a notice.</p>
      </part>
    </control>
    <control id="SUB-13">
      <title>SA Information Deletion</title>
      <prop name="label" class="index" value="5.4 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-13_smt" name="statement">
        <p>The CSP SHALL delete all personal information from the subscriber account records following account termination in accordance with the record retention and disposal requirements, as documented in its practices statement (see Sec. 3.1).</p>
      </part>
      <part id="SUB-13_obj" name="objective">
        <p>Confirm that the CSP has a documented records retention and disposal policy, and that it deletes all  personal information upon subscriber account determination in accordance with this policy.</p>
        <link href="#SUB-13_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for deleting all personal information from subscriber accounts following account termination.</p>
      </part>
    </control>
    <control id="SUB-14">
      <title>Data Breach Notification</title>
      <prop name="label" class="index" value="5.5 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-14_smt" name="statement">
        <p>In the event of a data breach of CSP records, the CSP SHALL provide notification to subscribers whose personal information may have been exposed to unauthorized access.</p>
      </part>
      <part id="SUB-14_obj" name="objective">
        <p>Confirm that the CSP has a documented policy and process for data breach notifications.</p>
        <link href="#SUB-14_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its data breach notification policy.</p>
      </part>
    </control>
    <control id="SUB-15">
      <title>Breach Notification Details</title>
      <prop name="label" class="index" value="5.5 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-15_smt" name="statement">
        <p>Such notification SHALL include information about the breach and actions for subscribers to take to recover or maintain access to their accounts and to protect against any unauthorized disclosure of their personal information.</p>
      </part>
      <part id="SUB-15_obj" name="objective">
        <p>Confirm that the CSP's data breach notifications include, at a minimum, information about the breach and any actions the subscriber needs to take with regard to their subscriber account.</p>
        <link href="#SUB-15_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-15_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine the information it includes in its data breach notifications.</p>
      </part>
      <part id="SUB-15_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine an example data breach notification.</p>
      </part>
    </control>
    <control id="SUB-16">
      <title>Expeditious Breach Notification</title>
      <prop name="label" class="index" value="5.5 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-16_smt" name="statement">
        <p>The CSP SHALL send such notifications as expeditiously as possible to the subscribers' validated address.</p>
      </part>
      <part id="SUB-16_obj" name="objective">
        <p>Confirm that the CSP sends its data breach notifications as soon as reasonably possible, and that such notifications are sent to validated addresses for its subscribers.</p>
        <link href="#SUB-16_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that its policy for sending data breach notifications.</p>
      </part>
    </control>
    <control id="SUB-17">
      <title>Multiple Account Reviews</title>
      <prop name="label" class="index" value="5.6 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-17_smt" name="statement">
        <p>The CSP SHALL develop and document their process for reviewing and assessing subscribers with multiple accounts to identify possible fraud.</p>
      </part>
      <part id="SUB-17_obj" name="objective">
        <p>Confirm that the CSP has a policy and process for assessing fraud associated with multiple accounts for a single subscriber.</p>
        <link href="#SUB-17_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its policy for dealing with multiple accounts associated with a single subscriber.</p>
      </part>
      <part id="SUB-17_gdn" name="guidance">
        <p>Some CSPs need to support a single user's ability to interact with the CSP while fulfilling different roles or personas. To limit fraud and avoid redundant costs and processes, CSPs SHOULD provide users with a means to manage multiple user personas without having to create multiple subscriber accounts. If this is not possible, and multiple subscriber accounts are supported for a single subscriber, the CSP SHOULD implement its subscriber accounts in a manner that avoids unnecessary re-proofing of the same subscriber (e.g., linking accounts via a common identifier or through biometric or attribute resolution).</p>
      </part>
    </control>
    <control id="SUB-18">
      <title>Multiple Accounts Tracking</title>
      <prop name="label" class="index" value="5.6 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-18_smt" name="statement">
        <p>The CSP SHALL maintain a mapping of all accounts associated with a unique government identifier or common core attributes.</p>
      </part>
      <part id="SUB-18_obj" name="objective">
        <p>Confirm the CSP has a mechanism for tracking all subscriber accounts associated with an individual.</p>
        <link href="#SUB-18_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-18_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine its approach for mapping all subscriber accounts associated with a subscriber.</p>
      </part>
    </control>
    <control id="SUB-19">
      <title>Multiple Accounts Visibility</title>
      <prop name="label" class="index" value="5.6 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SUB-19_smt" name="statement">
        <p>The CSP SHALL provide individuals with visibility into the full list of subscriber accounts associated with their identity.</p>
      </part>
      <part id="SUB-19_obj" name="objective">
        <p>Confirm that the CSP provides a mechanism for subscribers to view a list of all subscriber accounts associated with their identity.</p>
        <link href="#SUB-19_smt" rel="assessment-for"/>
      </part>
      <part id="SUB-19_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's practices statement or other documentation to determine that it allows subscribers to view and track all subscriber accounts associated with their identity.</p>
      </part>
    </control>
  </group>
  <group class="revision" id="revision-63B">
    <title>63B</title>
    <control id="AAL-1">
      <title>AAL Minimum Requirements</title>
      <prop name="label" class="index" value="2.0 A"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAL-1_smt" name="statement">
        <p>To satisfy the requirements of a given AAL and be recognized as a subscriber, a claimant SHALL authenticate to an RP (or IdP, as described in [SP800-63C]) with a process whose strength is equal to or greater than the requirements at that level.</p>
      </part>
      <part id="AAL-1_obj" name="objective">
        <p>Authentication requirements meet the requirements of assessed AALs.</p>
        <link href="#AAL-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP documentation to determine that authentication requirements for supported assurance levels address requirements.</p>
      </part>
      <part id="AAL-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test online processes to ensure that authentication is required whenever identification as a subscriber is required.</p>
      </part>
    </control>
    <control id="AAL-2">
      <title>Personal Information AAL</title>
      <prop name="label" class="index" value="2.0 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAL-2_smt" name="statement">
        <p>Federal agencies SHALL select a minimum of AAL2 when personal information is made available online.</p>
      </part>
      <part id="AAL-2_obj" name="objective">
        <p>Comply with Section 3 of Executive Order 13681 requiring multifactor authentication</p>
        <link href="#AAL-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>For federal agency relying parties, where personal information is made available online,</p>
        <p>Examine policies defining accepted authentication methods to determine that all meet a minimum of AAL2.</p>
      </part>
      <part id="AAL-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test online authentication processes for identified applications that handle personal information to confirm AAL2 authentication policies are enforced.</p>
      </part>
      <part id="AAL-2_gdn" name="guidance">
        <p>Applies to federal agencies only.</p>
      </part>
    </control>
    <control id="AAL-3">
      <title>Fraud Indications</title>
      <prop name="label" class="index" value="2.0 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAL-3_smt" name="statement">
        <p>CSPs or verifiers SHALL assess their use of indicators of potential fraud for efficacy and to identify and mitigate potential negative impacts on their user populations.</p>
      </part>
      <part id="AAL-3_obj" name="objective">
        <p>Minimize fraud and potential negative impacts on authentication where possible.</p>
        <link href="#AAL-3_smt" rel="assessment-for"/>
      </part>
      <part id="AAL-3_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSPs and verifier operators to determine that they have evaluated potential fraud indicators.</p>
      </part>
      <part id="AAL-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP UX testing procedures and results to confirm that processes are in place to identify and address UX challenges for user populations.</p>
      </part>
    </control>
    <control id="AAL-4">
      <title>Privacy Fraud Indications</title>
      <prop name="label" class="index" value="2.0 D"/>
      <prop name="marking" class="target" value="CSP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAL-4_smt" name="statement">
        <p>CSPs or verifiers SHALL include fraud indicators in the authentication privacy risk assessment.</p>
      </part>
      <part id="AAL-4_obj" name="objective">
        <p>Minimize potential privacy impacts stemming from use of fraud indicators.</p>
        <link href="#AAL-4_smt" rel="assessment-for"/>
      </part>
      <part id="AAL-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine privacy risk assessment to confirm that it includes any identified uses of fraud indicators.</p>
      </part>
    </control>
    <control id="AAL1PAT-1">
      <title>AAL1 Authenticator Types</title>
      <prop name="label" class="index" value="2.1.1 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL1"/>
      <part id="AAL1PAT-1_smt" name="statement">
        <p>AAL1 authentication SHALL use any of the following authentication types, which are further defined in Sec. 3:</p>
        <p>(a) Password (Sec. 3.1.1): A memorizable secret typically chosen by the subscriber.</p>
        <p>(b) Look-up secret (Sec. 3.1.2): A secret determined by the claimant by looking up a prompted value in a list held by the subscriber.</p>
        <p>(c) Out-of-band device (Sec. 3.1.3): A secret sent or received through a separate communication channel with the subscriber.</p>
        <p>(d) Single-factor one-time password (OTP) (Sec. 3.1.4): A one-time secret obtained from a device or application held by the subscriber.</p>
        <p>(e) Multi-factor OTP (Sec. 3.1.5): A one-time secret obtained from a device or application held by the subscriber that requires activation by a second authentication factor.</p>
        <p>(f) Single-factor cryptographic authentication (Sec. 3.1.6): Proof of possession and control via an authentication protocol of a cryptographic key held by the subscriber.</p>
        <p>(g) Multi-factor cryptographic authentication (Sec. 3.1.7): Proof of possession and control via an authentication protocol of a cryptographic key held by the subscriber that requires activation by a second authentication factor.</p>
      </part>
      <part id="AAL1PAT-1_obj" name="objective">
        <p>Identify acceptable authenticator types at AAL1.</p>
        <link href="#AAL1PAT-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL1PAT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation defining authentication interactions to determine that all authentication methods meet the requirements of one of the defined authenticator types.</p>
      </part>
      <part id="AAL1PAT-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authentication events at AAL1 to confirm that implemented processes meet the requirement one of the defined authenticator types.</p>
      </part>
    </control>
    <control id="AAL1AVR-1">
      <title>AAL1 Approved Cryptography</title>
      <prop name="label" class="index" value="2.1.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL1"/>
      <part id="AAL1AVR-1_smt" name="statement">
        <p>Authenticators used at AAL1 SHALL use approved cryptography.</p>
      </part>
      <part id="AAL1AVR-1_obj" name="objective">
        <p>Use secure cryptographic algorithms.</p>
        <link href="#AAL1AVR-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL1AVR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or practices to determine that only cryptographic algorithms specified in NIST cryptographic guidelines are used.</p>
      </part>
      <part id="AAL1AVR-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the system's functionality to observe the cryptographic algorithm(s) being accepted and determine whether the algorithms are specified in NIST cryptographic guidelines.</p>
      </part>
    </control>
    <control id="AAL1AVR-2">
      <title>AAL1 Authenticated Protected Channels</title>
      <prop name="label" class="index" value="2.1.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL1"/>
      <part id="AAL1AVR-2_smt" name="statement">
        <p>Communication between the claimant and verifier SHALL occur via one or more authenticated protected channels.</p>
      </part>
      <part id="AAL1AVR-2_obj" name="objective">
        <p>Protect the exchange of authenticator information between the verifier and the claimant.</p>
        <link href="#AAL1AVR-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAL1AVR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the verifier's documentation to ensure that TLS or a similarly secure protocol is used in conjunction with an approved encryption protocol.</p>
      </part>
      <part id="AAL1AVR-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the verifier's interactions and observe that TLS or similarly secure protocol is used in conjunction with an approved encryption protocol.</p>
      </part>
    </control>
    <control id="AAL1AVR-3">
      <title>AAL1 FIPS140 Validation</title>
      <prop name="label" class="index" value="2.1.2 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL1"/>
      <part id="AAL1AVR-3_smt" name="statement">
        <p>Cryptography used by verifiers operated by or on behalf of federal agencies at AAL1 SHALL be validated to meet the requirements of [FIPS140] Level 1.</p>
      </part>
      <part id="AAL1AVR-3_obj" name="objective">
        <p>Use validated cryptographic modules and components.</p>
        <link href="#AAL1AVR-3_smt" rel="assessment-for"/>
      </part>
      <part id="AAL1AVR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system documentation or software information to identify the cryptographic modules used by the verifiers and verify associated CMVP validation certificates.</p>
      </part>
      <part id="AAL1AVR-3_gdn" name="guidance">
        <p>Applies to federal agencies and those acting on their behalf (e.g., contractors) only.</p>
      </part>
    </control>
    <control id="AAL1REA-1">
      <title>AAL1 Reauthentication</title>
      <prop name="label" class="index" value="2.1.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="AAL1"/>
      <part id="AAL1REA-1_smt" name="statement">
        <p>Periodic reauthentication of subscriber sessions SHALL be performed, as described in Sec. 5.2.</p>
      </part>
      <part id="AAL1REA-1_obj" name="objective">
        <p>Mitigate theft of session secrets, session hijacking,  and unauthorized use of open session.</p>
        <link href="#AAL1REA-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL1REA-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>See REAUTH 1 - 5</p>
      </part>
    </control>
    <control id="AAL1REA-2">
      <title>AAL1 Overall Timeout</title>
      <prop name="label" class="index" value="2.1.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="AAL1"/>
      <part id="AAL1REA-2_smt" name="statement">
        <p>A definite reauthentication overall timeout SHALL be established, which SHOULD be no more than 30 days at AAL1.</p>
      </part>
      <part id="AAL1REA-2_obj" name="objective">
        <p>Mitigate theft of session secrets, session hijacking,  and unauthorized use of open session.</p>
        <link href="#AAL1REA-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAL1REA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation for defined reauthentication intervals.</p>
      </part>
      <part id="AAL1REA-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test implemented controls to confirm reauthentication behavior is consistent with documented AAL1 reauthentication intervals.</p>
      </part>
    </control>
    <control id="AAL2PAT-1">
      <title>AAL2 Multiple Factors</title>
      <prop name="label" class="index" value="2.2.1 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2PAT-1_smt" name="statement">
        <p>At AAL2, authentication SHALL use either a multi-factor authenticator (MFA) or a combination of two separate authentication factors.</p>
      </part>
      <part id="AAL2PAT-1_obj" name="objective">
        <p>Enforce MFA at AAL2.</p>
        <link href="#AAL2PAT-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2PAT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation defining authentication interactions to determine that all authentication methods meet the requirements of AAL2  authenticator types and combinations.</p>
      </part>
      <part id="AAL2PAT-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authentication events at AAL2 to confirm that implemented processes meet the requirements of the defined authenticator types and combinations.</p>
      </part>
    </control>
    <control id="AAL2PAT-2">
      <title>AAL2 Authenticator Combinations</title>
      <prop name="label" class="index" value="2.2.1 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2PAT-2_smt" name="statement">
        <p>When a combination of two single-factor authenticators is used, the combination SHALL include one physical authenticator (i.e., "something you have") from the following list in conjunction with either a password (Sec. 3.1.1) or a biometric comparison:</p>
        <p>(a) Look-up secret (Sec. 3.1.2)</p>
        <p>(b) Out-of-band device (Sec. 3.1.3)</p>
        <p>(c) Single-factor OTP (Sec. 3.1.4)</p>
        <p>(d) Single-factor cryptographic authentication (Sec. 3.1.6)</p>
      </part>
      <part id="AAL2PAT-2_obj" name="objective">
        <p>Enforce MFA at AAL2.</p>
        <link href="#AAL2PAT-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2PAT-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>See AAL2PAT-1</p>
      </part>
      <part id="AAL2PAT-2_gdn" name="guidance">
        <p>Applies when multiple authenticators are used to achieve AAL2.</p>
      </part>
    </control>
    <control id="AAL2AVR-1">
      <title>AAL2 Approved Cryptography</title>
      <prop name="label" class="index" value="2.2.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2AVR-1_smt" name="statement">
        <p>Authenticators used at AAL2 SHALL use approved cryptography.</p>
      </part>
      <part id="AAL2AVR-1_obj" name="objective">
        <p>Use secure cryptographic algorithms.</p>
        <link href="#AAL2AVR-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2AVR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or practices to determine that only cryptographic algorithms specified in NIST cryptographic guidelines are used.</p>
      </part>
      <part id="AAL2AVR-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the system's functionality to observe the cryptographic algorithm(s) being accepted and determine whether the algorithms are specified in NIST cryptographic guidelines.</p>
      </part>
    </control>
    <control id="AAL2AVR-2">
      <title>AAL2 FIPS140 Authenticators</title>
      <prop name="label" class="index" value="2.2.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2AVR-2_smt" name="statement">
        <p>Cryptographic authenticators procured by federal agencies SHALL be validated to meet the requirements of [FIPS140] Level 1.</p>
      </part>
      <part id="AAL2AVR-2_obj" name="objective">
        <p>Authenticators procured by or on behalf of government agencies use validated cryptographic modules and components.</p>
        <link href="#AAL2AVR-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2AVR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system documentation or vendor documentation to identify the cryptographic modules used by authenticators and verify associated CMVP validation certificates.</p>
      </part>
      <part id="AAL2AVR-2_gdn" name="guidance">
        <p>Applies to authenticators procured by federal agencies only.</p>
      </part>
    </control>
    <control id="AAL2AVR-3">
      <title>AAL2 Replay Resistance</title>
      <prop name="label" class="index" value="2.2.2 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2AVR-3_smt" name="statement">
        <p>At least one authenticator used at AAL2 SHALL be replay-resistant, as described in Sec. 3.2.7.</p>
      </part>
      <part id="AAL2AVR-3_obj" name="objective">
        <p>Prevent attackers from reusing stolen or observed authentication data to hijack accounts.</p>
        <link href="#AAL2AVR-3_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2AVR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the combinations of authenticators that can be used at AAL2 and verify that for each combination, at least one authenticator is replay-resistant.  OTP authenticators, cryptographic authenticators, and look-up secrets are considered replay resistant.</p>
      </part>
      <part id="AAL2AVR-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test if verifying a physical authenticator that does not implement a cryptographic challenge/response protocol, attempt to authenticate more than once using the same authenticator output (during its validity period, if time-based). If a subsequent authentication succeeds, the test of replay resistance has failed.</p>
      </part>
    </control>
    <control id="AAL2AVR-4">
      <title>AAL2 Authenticated Protected Channels</title>
      <prop name="label" class="index" value="2.2.2 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2AVR-4_smt" name="statement">
        <p>Communication between the claimant and verifier SHALL occur via one or more authenticated protected channels.</p>
      </part>
      <part id="AAL2AVR-4_obj" name="objective">
        <p>Determine that the communication channel meets the requirements of an authenticated protected channel as defined in SP 800-63B-4 Appendix D.</p>
        <link href="#AAL2AVR-4_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2AVR-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the verifier's documentation to ensure that TLS or a similarly secure protocol is used in conjunction with an approved encryption protocol.</p>
      </part>
      <part id="AAL2AVR-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the verifier's interactions and observe that TLS or similarly secure protocol is used in conjunction with an approved encryption protocol.</p>
      </part>
    </control>
    <control id="AAL2AVR-5">
      <title>AAL2 FIPS140 Verifiers</title>
      <prop name="label" class="index" value="2.2.2 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2AVR-5_smt" name="statement">
        <p>Cryptography used by verifiers operated by or on behalf of federal agencies at AAL2 SHALL be validated to meet the requirements of [FIPS140] Level 1 unless otherwise specified.</p>
      </part>
      <part id="AAL2AVR-5_obj" name="objective">
        <p>Verifiers operated by or on behalf of government agencies are required to be validated to meet FIPS 140 requirements. The FIPS 140 requirements generally apply to cryptographic modules (both hardware and software).</p>
        <link href="#AAL2AVR-5_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2AVR-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system documentation or software information to identify the cryptographic modules used by the verifiers and verify associated CMVP validation certificates.</p>
      </part>
      <part id="AAL2AVR-5_gdn" name="guidance">
        <p>Applies to federal agencies and those acting on their behalf (e.g., contractors) only.</p>
      </part>
    </control>
    <control id="AAL2AVR-6">
      <title>AAL2 Phishing Resistance Offer</title>
      <prop name="label" class="index" value="2.2.2 F"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2AVR-6_smt" name="statement">
        <p>Verifiers SHALL offer at least one phishing-resistant authentication option at AAL2, as described in Sec. 3.2.5.</p>
      </part>
      <part id="AAL2AVR-6_obj" name="objective">
        <p>Ensure that phishing-resistant authentication methods are available to subscribers who wish to use them.</p>
        <link href="#AAL2AVR-6_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2AVR-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation to determine that authentication at AAL2 always includes a phishing-resistant option.</p>
      </part>
      <part id="AAL2AVR-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authentication selection screens at AAL2 to confirm that a phishing resistant authentication options is presented to users.</p>
      </part>
    </control>
    <control id="AAL2AVR-7">
      <title>AAL2 Phishing Resistance Requirement</title>
      <prop name="label" class="index" value="2.2.2 G"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2AVR-7_smt" name="statement">
        <p>Federal agencies SHALL require their staff, contractors, and partners to use phishing-resistant authentication to access federal information systems.</p>
      </part>
      <part id="AAL2AVR-7_obj" name="objective">
        <p>Ensure phishing resistance for applications used by federal staff, contractors, and partners.</p>
        <link href="#AAL2AVR-7_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2AVR-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation  to determine that authentication of internal applications at AAL2 requires use of a phishing-resistant authenticator.</p>
      </part>
      <part id="AAL2AVR-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authentication to determine that authentication at AAL2 requires use of a phishing-resistant authenticator.</p>
      </part>
      <part id="AAL2AVR-7_gdn" name="guidance">
        <p>Applies to federal agencies only.</p>
      </part>
    </control>
    <control id="AAL2REA-1">
      <title>AAL2 Reauthentication</title>
      <prop name="label" class="index" value="2.2.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="AAL2REA-1_smt" name="statement">
        <p>Periodic reauthentication of subscriber sessions SHALL be performed, as described in Sec. 5.2.</p>
      </part>
      <part id="AAL2REA-1_obj" name="objective">
        <p>Determine that appropriate expiration of sessions occurs to mitigate theft of session secrets or use of a forgotten session.</p>
        <link href="#AAL2REA-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL2REA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation to determine that required reauthentication requirements are enforced.</p>
      </part>
      <part id="AAL2REA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by authenticating, then idle for documented inactivity timeout and determine that reauthentication is required. Maintain a session for at least the overall timeout period and observe that reauthentication is required.</p>
      </part>
    </control>
    <control id="AAL3PAT-1">
      <title>AAL3 Authenticator Combinations</title>
      <prop name="label" class="index" value="2.3.1 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3PAT-1_smt" name="statement">
        <p>AAL3 authentication SHALL require an authenticator combination consisting of either multi-factor cryptographic authentication (Sec. 3.1.7); or  single-factor cryptographic authentication (Sec. 3.1.6) used in conjunction with either a password (Sec. 3.1.1) or a biometric comparison.</p>
      </part>
      <part id="AAL3PAT-1_obj" name="objective">
        <p>Require use of highest security authenticators at AAL3.</p>
        <link href="#AAL3PAT-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3PAT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or practices to determine authenticator types that can be used.</p>
      </part>
      <part id="AAL3PAT-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the system's functionality to observe the authenticator types being  made available to users and accepted.</p>
      </part>
    </control>
    <control id="AAL3AVR-1">
      <title>AAL3 Approved Cryptography</title>
      <prop name="label" class="index" value="2.3.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-1_smt" name="statement">
        <p>Authenticators used at AAL3 SHALL use approved cryptography.</p>
      </part>
      <part id="AAL3AVR-1_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms are being used.</p>
        <link href="#AAL3AVR-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or practices to determine that only approved cryptographic algorithms can be used.</p>
      </part>
      <part id="AAL3AVR-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the system's functionality to observe the cryptographic algorithm(s) being accepted and determine whether the algorithms are approved.</p>
      </part>
    </control>
    <control id="AAL3AVR-2">
      <title>AAL3 Authenticated Protected Channels</title>
      <prop name="label" class="index" value="2.3.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-2_smt" name="statement">
        <p>Communication between the claimant and verifier SHALL occur via one or more authenticated protected channels.</p>
      </part>
      <part id="AAL3AVR-2_obj" name="objective">
        <p>Determine that the communication channel meets the requirements of an authenticated protected channel as defined in SP 800-63B-4 Appendix D.</p>
        <link href="#AAL3AVR-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the verifier's documentation to ensure that TLS or a similarly secure protocol is used in conjunction with an approved encryption protocol.</p>
      </part>
    </control>
    <control id="AAL3AVR-3">
      <title>AAL3 Non-Exportable Key</title>
      <prop name="label" class="index" value="2.3.2 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-3_smt" name="statement">
        <p>The cryptographic authenticator used at AAL3 SHALL have a non-exportable private key.</p>
      </part>
      <part id="AAL3AVR-3_obj" name="objective">
        <p>Require use of high-security authenticators at AAL3.</p>
        <link href="#AAL3AVR-3_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the authenticators and their associated architecture/documentation offered by the CSP to determine how keys are protected and that they meet non-exportability requirements.</p>
      </part>
      <part id="AAL3AVR-3_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine signed authenticator attestations (if available) to determine key protection characteristics and that they meet non-exportability requirements.</p>
      </part>
    </control>
    <control id="AAL3AVR-3.5">
      <title>AAL3 Phishing Resistance</title>
      <prop name="label" class="index" value="2.3.2 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-3.5_smt" name="statement">
        <p>The cryptographic authenticator used at AAL3 SHALL provide phishing resistance, as described in Sec. 3.2.5.</p>
      </part>
      <part id="AAL3AVR-3.5_obj" name="objective">
        <p>Require use of phishing resistant authenticators at AAL3.</p>
        <link href="#AAL3AVR-3.5_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-3.5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation  to determine that authentication at AAL3 requires use of a phishing-resistant authenticator.</p>
      </part>
      <part id="AAL3AVR-3.5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authentication to determine that authentication at AAL3 requires use of a phishing-resistant authenticator.</p>
      </part>
    </control>
    <control id="AAL3AVR-3.7">
      <title>AAL3 Replay Resistance</title>
      <prop name="label" class="index" value="2.3.2 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-3.7_smt" name="statement">
        <p>The cryptographic authentication protocol SHALL be replay-resistant.</p>
      </part>
      <part id="AAL3AVR-3.7_obj" name="objective">
        <p>Ensure that the authentication transaction cannot be replayed by an attacker.</p>
        <link href="#AAL3AVR-3.7_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-3.7_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Requirement is met by satisfying requirement to use a cryptographic authenticator (AAL3PAT-1).</p>
      </part>
    </control>
    <control id="AAL3AVR-4">
      <title>AAL3 Intent</title>
      <prop name="label" class="index" value="2.3.2 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-4_smt" name="statement">
        <p>All authentication and reauthentication processes at AAL3 SHALL demonstrate authentication intent from at least one authenticator, as described in Sec. 3.2.8.</p>
      </part>
      <part id="AAL3AVR-4_obj" name="objective">
        <p>Ensure that authentication is actively requested, and not accidental.</p>
        <link href="#AAL3AVR-4_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP documentation to determine the acceptable combinations of authenticators that are available to subscribers authenticating at AAL3.</p>
      </part>
    </control>
    <control id="AAL3AVR-5">
      <title>AAL3 Public-Key Cryptography</title>
      <prop name="label" class="index" value="2.3.2 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-5_smt" name="statement">
        <p>Cryptographic authenticators used at AAL3 SHALL use public-key cryptography to protect the authentication secrets from compromise of the verifier.</p>
      </part>
      <part id="AAL3AVR-5_obj" name="objective">
        <p>Avoid the use of shared authentication secrets that could be compromised by an attacker.</p>
        <link href="#AAL3AVR-5_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation of verifiers to determine that they only store public keys for cryptographic authenticators used at AAL3.</p>
      </part>
    </control>
    <control id="AAL3AVR-6">
      <title>AAL3 FIPS140 Authenticators</title>
      <prop name="label" class="index" value="2.3.2 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-6_smt" name="statement">
        <p>Single-factor and multi-factor authenticators used at AAL3 SHALL be validated to meet the requirements of [FIPS140] Level 1 or higher overall.</p>
      </part>
      <part id="AAL3AVR-6_obj" name="objective">
        <p>Cryptographic authenticators at AAL3 are required to be validated to meet FIPS 140 requirements. The FIPS 140 requirements generally apply to cryptographic modules (both hardware and software).</p>
        <link href="#AAL3AVR-6_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system documentation or software information to identify the cryptographic modules used by the authenticators and verify associated CMVP validation certificates.</p>
      </part>
    </control>
    <control id="AAL3AVR-7">
      <title>AAL3 Unsyncability</title>
      <prop name="label" class="index" value="2.3.2 H"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-7_smt" name="statement">
        <p>Syncable authenticators SHALL NOT be used at AAL3.</p>
      </part>
      <part id="AAL3AVR-7_obj" name="objective">
        <p>Ensure that syncable authenticators, which have exportable authentication keys, are not used.</p>
        <link href="#AAL3AVR-7_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-7_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Requirement is met by authenticators meeting AAL3AVR-3.</p>
      </part>
    </control>
    <control id="AAL3AVR-8">
      <title>AAL3 FIPS140 Verifiers</title>
      <prop name="label" class="index" value="2.3.2 I"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3AVR-8_smt" name="statement">
        <p>Cryptography used by verifiers at AAL3 SHALL be validated at [FIPS140] Level 1 or higher.</p>
      </part>
      <part id="AAL3AVR-8_obj" name="objective">
        <p>Verifiers operated by or on behalf of government agencies are required to be validated to meet FIPS 140 requirements. The FIPS 140 requirements generally apply to cryptographic modules (both hardware and software).</p>
        <link href="#AAL3AVR-8_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3AVR-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system documentation or software information to identify the cryptographic modules used by the verifiers and verify associated CMVP validation certificates.</p>
      </part>
    </control>
    <control id="AAL3REA-1">
      <title>AAL3 Reauthentication</title>
      <prop name="label" class="index" value="2.3.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3REA-1_smt" name="statement">
        <p>Periodic reauthentication of subscriber sessions SHALL be performed, as described in Sec. 5.2.</p>
      </part>
      <part id="AAL3REA-1_obj" name="objective">
        <p>Determine that appropriate expiration of sessions occurs to mitigate theft of session secrets or use of a forgotten session.</p>
        <link href="#AAL3REA-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3REA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to authenticate, then idle for documented inactivity timeout and determine that reauthentication is required. Maintain a session for at least the overall timeout period and observe that reauthentication is required.</p>
      </part>
      <part id="AAL3REA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine verifier or CSP documentation to determine that required reauthentication requirements are enforced.</p>
      </part>
    </control>
    <control id="AAL3REA-2">
      <title>AAL3 Reauthentication Limit</title>
      <prop name="label" class="index" value="2.3.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="AAL3REA-2_smt" name="statement">
        <p>At AAL3, the overall timeout for reauthentication SHALL be no more than 12 hours.</p>
      </part>
      <part id="AAL3REA-2_obj" name="objective">
        <p>Establish upper bound on session lifetime.</p>
        <link href="#AAL3REA-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAL3REA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP documentation to see that maximum overall session timeout is less than or equal to 12 hours.</p>
      </part>
    </control>
    <control id="SC-1">
      <title>Security Controls</title>
      <prop name="label" class="index" value="2.4.1 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SC-1_smt" name="statement">
        <p>The verifier SHALL employ appropriately tailored security controls from the moderate baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard that the organization has chosen for the information systems, applications, and online services that these guidelines are used to protect.</p>
      </part>
      <part id="SC-1_obj" name="objective">
        <p>Determine compliance with relevant overall security controls.</p>
        <link href="#SC-1_smt" rel="assessment-for"/>
      </part>
      <part id="SC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's documentation to determine it employs appropriately tailored security controls to include control enhancements, from the medium baseline of security controls defined in SP 800-53 or equivalent federal (e.g., FEDRAMP) or industry standard.</p>
      </part>
    </control>
    <control id="RRP-1">
      <title>Records Retention</title>
      <prop name="label" class="index" value="2.4.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RRP-1_smt" name="statement">
        <p>The verifier SHALL comply with its respective records retention policies in accordance with applicable laws, regulations, and policies, including any National Archives and Records Administration (NARA) records retention schedules that may apply.</p>
      </part>
      <part id="RRP-1_obj" name="objective">
        <p>Determine compliance with records retention policy requirements.</p>
        <link href="#RRP-1_smt" rel="assessment-for"/>
      </part>
      <part id="RRP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's records retention policy and evaluate its applicability with laws and regulations. Where applicable, audit a sample of retained records to ensure that their retention is consistent with policy.</p>
      </part>
    </control>
    <control id="RRP-2">
      <title>Records Retention Risk</title>
      <prop name="label" class="index" value="2.4.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RRP-2_smt" name="statement">
        <p>If the verifier opts to retain records in the absence of mandatory requirements, the verifier or the CSP or IdP of which it is a part SHALL conduct a risk management process [NISTRMF], including assessments of privacy and security risks, to determine how long records should be retained and SHALL inform the subscriber of that retention policy.</p>
      </part>
      <part id="RRP-2_obj" name="objective">
        <p>Verify justification for records retention not covered by mandatory requirements.</p>
        <link href="#RRP-2_smt" rel="assessment-for"/>
      </part>
      <part id="RRP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine evidence to determine risk-based decision for records retention was used, and that notice to subscribers is provided.</p>
      </part>
      <part id="RRP-2_gdn" name="guidance">
        <p>Non-mandatory records retention.</p>
      </part>
    </control>
    <control id="PR-1">
      <title>Privacy Controls</title>
      <prop name="label" class="index" value="2.4.3 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PR-1_smt" name="statement">
        <p>The verifier SHALL employ appropriately tailored privacy controls defined in [SP800-53] or an equivalent industry standard.</p>
      </part>
      <part id="PR-1_obj" name="objective">
        <p>Determine compliance with relevant overall privacy requirements.</p>
        <link href="#PR-1_smt" rel="assessment-for"/>
      </part>
      <part id="PR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's operating procedure documentation and, as applicable, authority-to-operate (ATO) for consistency with SP 800-53 or equivalent standard.</p>
      </part>
    </control>
    <control id="PR-2">
      <title>Attribute Privacy Management</title>
      <prop name="label" class="index" value="2.4.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PR-2_smt" name="statement">
        <p>If CSPs or IdPs process attributes for purposes other than identity services (i.e., identity proofing, authentication, or attribute assertions), related fraud mitigation, or compliance with laws or legal processes, they SHALL implement measures to maintain predictability and manageability commensurate with the privacy risks that arise from the additional processing.</p>
      </part>
      <part id="PR-2_obj" name="objective">
        <p>Determine compliance with relevant privacy requirements for supplemental services.</p>
        <link href="#PR-2_smt" rel="assessment-for"/>
      </part>
      <part id="PR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's documented policies or practices to determine which predictability and manageability measures it employs, (e.g., notice, consent, selective disclosure).</p>
      </part>
      <part id="PR-2_gdn" name="guidance">
        <p>Applies when there is non-identity use of identity attributes.</p>
      </part>
    </control>
    <control id="PR-3">
      <title>Consent Non-Mandatory</title>
      <prop name="label" class="index" value="2.4.3 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PR-3_smt" name="statement">
        <p>When CSPs or IdPs use consent measures, they SHALL NOT make consent for the additional processing a condition of the identity service.</p>
      </part>
      <part id="PR-3_obj" name="objective">
        <p>Ensure that consent measures are voluntary.</p>
        <link href="#PR-3_smt" rel="assessment-for"/>
      </part>
      <part id="PR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine terms of use to ensure that additional consent is not a requirement.</p>
      </part>
      <part id="PR-3_gdn" name="guidance">
        <p>Applies when consent is requested from subscriber.</p>
      </part>
    </control>
    <control id="PR-4">
      <title>Privacy Act Consultation</title>
      <prop name="label" class="index" value="2.4.3 #1"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PR-4_smt" name="statement">
        <p>The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) and conduct an analysis to determine whether the collection of personal information to issue or maintain authenticators triggers the requirements of the Privacy Act of 1974 [Privacy Act] (see Sec. 7.4).</p>
      </part>
      <part id="PR-4_obj" name="objective">
        <p>Determine when Privacy Act requirements are triggered.</p>
        <link href="#PR-4_smt" rel="assessment-for"/>
      </part>
      <part id="PR-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation to determine that consultation with the SAOP occurred and that all determinations of whether the service is subject to the privacy act of 1974 have been recorded.</p>
      </part>
      <part id="PR-4_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview to confirm that the agency has consulted with its SAOP to determine if the service is subject to the Privacy Act of 1974.</p>
      </part>
      <part id="PR-4_gdn" name="guidance">
        <p>Applies to federal agencies and others acting on their behalf.</p>
      </part>
    </control>
    <control id="PR-5">
      <title>SORN Publication</title>
      <prop name="label" class="index" value="2.4.3 #2"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PR-5_smt" name="statement">
        <p>The agency SHALL publish a System of Records Notice (SORN) to cover such collections, as applicable.</p>
      </part>
      <part id="PR-5_obj" name="objective">
        <p>Determine that a SORN is published when required.</p>
        <link href="#PR-5_smt" rel="assessment-for"/>
      </part>
      <part id="PR-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the agency's System of Records Notice, as applicable.</p>
      </part>
      <part id="PR-5_gdn" name="guidance">
        <p>Applies to federal agencies only.</p>
      </part>
    </control>
    <control id="PR-6">
      <title>E-Government Consultation</title>
      <prop name="label" class="index" value="2.4.3 #3"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PR-6_smt" name="statement">
        <p>The agency SHALL consult with its SAOP and conduct an analysis to determine whether the collection of personal information to issue or maintain authenticators triggers the requirements of the E-Government Act of 2002 [E-Gov].</p>
      </part>
      <part id="PR-6_obj" name="objective">
        <p>Determine when E-Government Act requirements are triggered.</p>
        <link href="#PR-6_smt" rel="assessment-for"/>
      </part>
      <part id="PR-6_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview to confirm that the agency offering or using the identity proofing service has consulted with its SAOP to determine if the service is subject to the E-Government Act of 2002.</p>
      </part>
      <part id="PR-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation of the SAOP assessment.</p>
      </part>
      <part id="PR-6_gdn" name="guidance">
        <p>Applies to federal agencies only.</p>
      </part>
    </control>
    <control id="PR-7">
      <title>Privacy Impact Assessment Publication</title>
      <prop name="label" class="index" value="2.4.3 #4"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PR-7_smt" name="statement">
        <p>The agency SHALL publish a Privacy Impact Assessment (PIA) to cover such collection, as applicable.</p>
      </part>
      <part id="PR-7_obj" name="objective">
        <p>Determine that a PIA is published when required.</p>
        <link href="#PR-7_smt" rel="assessment-for"/>
      </part>
      <part id="PR-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the agency's Privacy Impact Assessment, as applicable.</p>
      </part>
      <part id="PR-7_gdn" name="guidance">
        <p>Applies to federal agencies and others providing services to federal agencies.</p>
      </part>
    </control>
    <control id="REDAUTH-1">
      <title>Redress Provision</title>
      <prop name="label" class="index" value="2.4.4 A"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REDAUTH-1_smt" name="statement">
        <p>The verifier and associated CSP or IdP SHALL provide mechanisms for the redress of subscriber complaints and problems that arise from subscriber authentication processes, as described in Sec. 5.6 of [SP800-63].</p>
      </part>
      <part id="REDAUTH-1_obj" name="objective">
        <p>Determine that useful redress for authentication problems is provided.</p>
        <link href="#REDAUTH-1_smt" rel="assessment-for"/>
      </part>
      <part id="REDAUTH-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test redress mechanisms from the viewpoint of the claimant.</p>
      </part>
      <part id="REDAUTH-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine redress mechanisms from the viewpoint of the claimant.</p>
      </part>
    </control>
    <control id="REDAUTH-2">
      <title>Redress Usability</title>
      <prop name="label" class="index" value="2.4.4 B"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REDAUTH-2_smt" name="statement">
        <p>These mechanisms SHALL be easy for subscribers to find and use.</p>
      </part>
      <part id="REDAUTH-2_obj" name="objective">
        <p>Ensure that redress mechanisms are usable by the population of subscribers.</p>
        <link href="#REDAUTH-2_smt" rel="assessment-for"/>
      </part>
      <part id="REDAUTH-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test redress mechanisms to determine their ease of use.</p>
      </part>
    </control>
    <control id="REDAUTH-3">
      <title>Redress Efficacy</title>
      <prop name="label" class="index" value="2.4.4 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REDAUTH-3_smt" name="statement">
        <p>The CSP or IdP SHALL assess the mechanisms for efficacy in resolving complaints or problems.</p>
      </part>
      <part id="REDAUTH-3_obj" name="objective">
        <p>Ensure that redress mechanisms are sufficient to resolve expected authentication problems.</p>
        <link href="#REDAUTH-3_smt" rel="assessment-for"/>
      </part>
      <part id="REDAUTH-3_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP or IdP operator to determine the results of their assessment.</p>
      </part>
    </control>
    <control id="PASSAUTH-1">
      <title>Password Choice</title>
      <prop name="label" class="index" value="3.1.1.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PASSAUTH-1_smt" name="statement">
        <p>Passwords SHALL either be chosen by the subscriber or assigned randomly by the CSP.</p>
      </part>
      <part id="PASSAUTH-1_obj" name="objective">
        <p>Establish acceptable methods of password creation (e.g., no default passwords).</p>
        <link href="#PASSAUTH-1_smt" rel="assessment-for"/>
      </part>
      <part id="PASSAUTH-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by creating a new account or changing a password to determine how password is chosen. If the password is not chosen by the subscriber.</p>
      </part>
      <part id="PASSAUTH-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP to establish that the password is assigned randomly.</p>
      </part>
    </control>
    <control id="PASSAUTH-2">
      <title>Password Blocklist</title>
      <prop name="label" class="index" value="3.1.1.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PASSAUTH-2_smt" name="statement">
        <p>If the CSP disallows a chosen password because it is on a blocklist of commonly used, expected, or compromised values (see Sec. 3.1.1.2), the subscriber SHALL be required to choose a different password.</p>
      </part>
      <part id="PASSAUTH-2_obj" name="objective">
        <p>Prohibit use of passwords expected to be commonly chosen.</p>
        <link href="#PASSAUTH-2_smt" rel="assessment-for"/>
      </part>
      <part id="PASSAUTH-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to set an account to use a memorized secret that is on the blocklist. The attempt should fail.</p>
      </part>
    </control>
    <control id="PASSAUTH-3">
      <title>Password Composition</title>
      <prop name="label" class="index" value="3.1.1.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PASSAUTH-3_smt" name="statement">
        <p>Other composition requirements for passwords SHALL NOT be imposed.</p>
      </part>
      <part id="PASSAUTH-3_obj" name="objective">
        <p>Prohibit composition rules (e.g., requirement for specific character types).</p>
        <link href="#PASSAUTH-3_smt" rel="assessment-for"/>
      </part>
      <part id="PASSAUTH-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to create an unusual password that does not meet usual composition requirements (e.g., all lower case letters) and determine that it is accepted.</p>
      </part>
    </control>
    <control id="PV-1">
      <title>Password Length</title>
      <prop name="label" class="index" value="3.1.1.2 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-1_smt" name="statement">
        <p>Verifiers and CSPs SHALL require passwords that are used as a single-factor authentication mechanism to be a minimum of 15 characters in length. Verifiers and CSPs MAY allow passwords that are only used as part of multi-factor authentication processes to be shorter but SHALL require them to be a minimum of eight characters in length.</p>
      </part>
      <part id="PV-1_obj" name="objective">
        <p>Require passwords to be long enough to provide baseline security.</p>
        <link href="#PV-1_smt" rel="assessment-for"/>
      </part>
      <part id="PV-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by trying to create a password that does not meet the minimum length requirements and verify that it is not accepted.</p>
      </part>
    </control>
    <control id="PV-2">
      <title>Unicode Passwords</title>
      <prop name="label" class="index" value="3.1.1.2 #4"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-2_smt" name="statement">
        <p>Verifiers and CSPs SHOULD accept Unicode [ISO/IEC 10646] characters in passwords. Each Unicode code point SHALL be counted as a single character when evaluating password length.</p>
      </part>
      <part id="PV-2_obj" name="objective">
        <p>Allow use of characters memorable to the subscriber, even if they use a language not represented by ASCII.</p>
        <link href="#PV-2_smt" rel="assessment-for"/>
      </part>
      <part id="PV-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by creating a password containing a Unicode character such as an accented vowel and determine that it is accepted, and that the unaccented version of the same character does not allow successful authentication.</p>
      </part>
    </control>
    <control id="PV-3">
      <title>Password Verifier Composition</title>
      <prop name="label" class="index" value="3.1.1.2 #5"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-3_smt" name="statement">
        <p>Verifiers and CSPs SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords.</p>
      </part>
      <part id="PV-3_obj" name="objective">
        <p>Prohibit composition rules (e.g., requirement for specific character types)</p>
        <link href="#PV-3_smt" rel="assessment-for"/>
      </part>
      <part id="PV-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>See PASSAUTH-3</p>
      </part>
    </control>
    <control id="PV-4">
      <title>Password Non-Expiration</title>
      <prop name="label" class="index" value="3.1.1.2 #6"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-4_smt" name="statement">
        <p>Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically. However, verifiers SHALL force a change if there is evidence that the authenticator has been compromised.</p>
      </part>
      <part id="PV-4_obj" name="objective">
        <p>Prohibit password rotation, which has been shown to cause selection of weaker passwords.</p>
        <link href="#PV-4_smt" rel="assessment-for"/>
      </part>
      <part id="PV-4_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview to determine from CSP that periodic password changes are not required, but that a mechanism is in place to force password changes for affected subscribers after a breach.</p>
      </part>
    </control>
    <control id="PV-5">
      <title>Password Hints</title>
      <prop name="label" class="index" value="3.1.1.2 #7"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-5_smt" name="statement">
        <p>Verifiers and CSPs SHALL NOT permit the subscriber to store a hint (e.g., a reminder of how the password was created) that is accessible to an unauthenticated claimant.</p>
      </part>
      <part id="PV-5_obj" name="objective">
        <p>Prohibit use of password hints, which greatly weaken security.</p>
        <link href="#PV-5_smt" rel="assessment-for"/>
      </part>
      <part id="PV-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to ensure that there is no provision for a password hint to be displayed to unauthenticated claimants and that there is no provision for storing a hint in subscribers' account management.</p>
      </part>
    </control>
    <control id="PV-6">
      <title>Passwords Not KBA</title>
      <prop name="label" class="index" value="3.1.1.2 #8"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-6_smt" name="statement">
        <p>Verifiers and CSPs SHALL NOT prompt subscribers to use knowledge-based authentication (KBA) (e.g., "What was the name of your first pet?") or security questions when choosing passwords.</p>
      </part>
      <part id="PV-6_obj" name="objective">
        <p>Prohibit use of KBA, which greatly weakens security.</p>
        <link href="#PV-6_smt" rel="assessment-for"/>
      </part>
      <part id="PV-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to ensure that there is no authentication flow that involves the use of KBA and that there is no provision for storing authentication questions and answers in subscribers' account management.</p>
      </part>
    </control>
    <control id="PV-7">
      <title>Password Full Verification</title>
      <prop name="label" class="index" value="3.1.1.2 #9"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-7_smt" name="statement">
        <p>Verifiers SHALL request the password to be provided in full (not a subset of it) and SHALL verify the entire submitted password (e.g., not truncate it).</p>
      </part>
      <part id="PV-7_obj" name="objective">
        <p>Require use of the entire password for authentication to maximize the security benefit of the whole password.</p>
        <link href="#PV-7_smt" rel="assessment-for"/>
      </part>
      <part id="PV-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine verification code to ensure that entire password is verified.</p>
      </part>
      <part id="PV-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by creating long passwords and attempting to authenticate with truncated passwords.</p>
      </part>
    </control>
    <control id="PV-8">
      <title>Password Verifier Blocklist</title>
      <prop name="label" class="index" value="3.1.1.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-8_smt" name="statement">
        <p>When processing a request to establish or change a password, verifiers SHALL compare the prospective secret against a blocklist that contains known commonly used, expected, or compromised passwords.</p>
      </part>
      <part id="PV-8_obj" name="objective">
        <p>Require use of a blocklist to prevent selection of excessively weak passwords.</p>
        <link href="#PV-8_smt" rel="assessment-for"/>
      </part>
      <part id="PV-8_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP to determine contents of the blocklist.</p>
      </part>
      <part id="PV-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to ensure that it is not possible to change a password to a blocklist entry.</p>
      </part>
    </control>
    <control id="PV-9">
      <title>Verifier Blocklist Substrings</title>
      <prop name="label" class="index" value="3.1.1.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-9_smt" name="statement">
        <p>The entire password SHALL be subject to comparison, not substrings or words that might be contained therein.</p>
      </part>
      <part id="PV-9_obj" name="objective">
        <p>Ensure that the entire password is verified so that the full security benefit of long passwords is realized.</p>
        <link href="#PV-9_smt" rel="assessment-for"/>
      </part>
      <part id="PV-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to ensure that a long password containing a blocklist entry is accepted.</p>
      </part>
    </control>
    <control id="PV-10">
      <title>Verifier Blocklist Response</title>
      <prop name="label" class="index" value="3.1.1.2 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-10_smt" name="statement">
        <p>If the chosen password is found on the blocklist, the CSP SHALL require the subscriber to select a different secret and SHALL provide the reason for rejection.</p>
      </part>
      <part id="PV-10_obj" name="objective">
        <p>Require selection of a different password if a weak one is chosen.</p>
        <link href="#PV-10_smt" rel="assessment-for"/>
      </part>
      <part id="PV-10_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to ensure that a substitute for a blocklisted password is requested.</p>
      </part>
    </control>
    <control id="PV-11">
      <title>Strong Password Guidance</title>
      <prop name="label" class="index" value="3.1.1.2 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-11_smt" name="statement">
        <p>Verifiers SHALL offer guidance to the subscriber to help the subscriber choose a strong password. This is particularly important following the rejection of a password on the blocklist as it discourages trivial modifications of listed weak passwords [Blocklists].</p>
      </part>
      <part id="PV-11_obj" name="objective">
        <p>Require coaching of the subscriber on selection of better passwords if a weak one is initially chosen.</p>
        <link href="#PV-11_smt" rel="assessment-for"/>
      </part>
      <part id="PV-11_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine that helpful advice on choosing strong passwords is offered.</p>
      </part>
    </control>
    <control id="PV-12">
      <title>Password Rate-Limiting</title>
      <prop name="label" class="index" value="3.1.1.2 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-12_smt" name="statement">
        <p>Verifiers SHALL implement a rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on the subscriber account, as described in Sec. 3.2.2.</p>
      </part>
      <part id="PV-12_obj" name="objective">
        <p>Strengthen verifier against online password guessing attacks.</p>
        <link href="#PV-12_smt" rel="assessment-for"/>
      </part>
      <part id="PV-12_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited.</p>
      </part>
    </control>
    <control id="PV-13">
      <title>Password Manager Use</title>
      <prop name="label" class="index" value="3.1.1.2 F"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-13_smt" name="statement">
        <p>Verifiers SHALL allow the use of password managers and autofill functionality.</p>
      </part>
      <part id="PV-13_obj" name="objective">
        <p>Allow subscriber to use a password manager, which aids in the use of strong and unguessable passwords.</p>
        <link href="#PV-13_smt" rel="assessment-for"/>
      </part>
      <part id="PV-13_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to authenticate using one or more popular password managers and verify that a password stored in the manager can be filled in.</p>
      </part>
    </control>
    <control id="PV-14">
      <title>Password Authenticated Protected Channels</title>
      <prop name="label" class="index" value="3.1.1.2 G"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-14_smt" name="statement">
        <p>Verifiers and CSPs SHALL use approved encryption and an authenticated protected channel when requesting passwords.</p>
      </part>
      <part id="PV-14_obj" name="objective">
        <p>Ensure that the communication channel to the verifier is secure against eavesdropping.</p>
        <link href="#PV-14_smt" rel="assessment-for"/>
      </part>
      <part id="PV-14_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test password transmission to verify that an authenticated protected channel such as TLS is used.</p>
      </part>
      <part id="PV-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine encryption algorithms used to verify that they are approved.</p>
      </part>
    </control>
    <control id="PV-15">
      <title>Password Offline Attack Resistance</title>
      <prop name="label" class="index" value="3.1.1.2 H"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-15_smt" name="statement">
        <p>Verifiers SHALL store passwords in a form that is resistant to offline attacks.</p>
      </part>
      <part id="PV-15_obj" name="objective">
        <p>Require strong storage to protect against offline attacks.</p>
        <link href="#PV-15_smt" rel="assessment-for"/>
      </part>
      <part id="PV-15_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Requirement is satisfied by PV-16 through PV-18.</p>
      </part>
    </control>
    <control id="PV-16">
      <title>Password Salted Hashing</title>
      <prop name="label" class="index" value="3.1.1.2 I"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-16_smt" name="statement">
        <p>Passwords SHALL be salted and hashed using a suitable password hashing scheme.</p>
      </part>
      <part id="PV-16_obj" name="objective">
        <p>At a minimum, require salting and hashing of passwords as protection against offline attacks should the verifier be breached.</p>
        <link href="#PV-16_smt" rel="assessment-for"/>
      </part>
      <part id="PV-16_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine password verification storage to determine evidence of password hashing and salt storage.</p>
      </part>
    </control>
    <control id="PV-17">
      <title>Salt Requirements</title>
      <prop name="label" class="index" value="3.1.1.2 J"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-17_smt" name="statement">
        <p>The salt SHALL be at least 32 bits in length and chosen to minimize salt value collisions among stored hashes (i.e., to prevent multiple subscriber accounts from having the same hashed password).</p>
      </part>
      <part id="PV-17_obj" name="objective">
        <p>Require use of a salt sufficient to ensure that two subscribers with the same password do not hash to the same value in the verifier.</p>
        <link href="#PV-17_smt" rel="assessment-for"/>
      </part>
      <part id="PV-17_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine stored salt values to ensure that they are at least 32 bits in length.</p>
      </part>
      <part id="PV-17_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP personnel to determine that salt is chosen to avoid collisions.</p>
      </part>
    </control>
    <control id="PV-18">
      <title>Salt Storage</title>
      <prop name="label" class="index" value="3.1.1.2 K"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-18_smt" name="statement">
        <p>Both the salt value and the resulting hash SHALL be stored for each password.</p>
      </part>
      <part id="PV-18_obj" name="objective">
        <p>Describes the use of a salt.</p>
        <link href="#PV-18_smt" rel="assessment-for"/>
      </part>
      <part id="PV-18_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Requirement is satisfied by verification method of PV-16.</p>
      </part>
    </control>
    <control id="PV-19">
      <title>Hashing Key Generation</title>
      <prop name="label" class="index" value="3.1.1.2 L"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-19_smt" name="statement">
        <p>If used, this key value SHALL be generated by an approved random bit generator, as described in Sec. 3.2.1.2.</p>
      </part>
      <part id="PV-19_obj" name="objective">
        <p>For keyed hashing, require appropriate selection of the key.</p>
        <link href="#PV-19_smt" rel="assessment-for"/>
      </part>
      <part id="PV-19_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP personnel to determine how the key value is generated.</p>
      </part>
      <part id="PV-19_gdn" name="guidance">
        <p>Applies when keyed hashing is used.</p>
      </part>
    </control>
    <control id="PV-20">
      <title>Hashing Key Storage</title>
      <prop name="label" class="index" value="3.1.1.2 M"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PV-20_smt" name="statement">
        <p>The secret key value SHALL be stored separately from the hashed passwords.</p>
      </part>
      <part id="PV-20_obj" name="objective">
        <p>Require separate storage for a keyed hash key so it is not also breached if the hashed passwords are.</p>
        <link href="#PV-20_smt" rel="assessment-for"/>
      </part>
      <part id="PV-20_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP personnel to determine how the key value is stored.</p>
      </part>
      <part id="PV-20_gdn" name="guidance">
        <p>Applies when keyed hashing is used.</p>
      </part>
    </control>
    <control id="LSA-1">
      <title>Look-Up Secret Generation</title>
      <prop name="label" class="index" value="3.1.2.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSA-1_smt" name="statement">
        <p>CSPs that create look-up secret authenticators SHALL use an approved random bit generator, as described in Sec. 3.2.12, to generate the list of secrets.</p>
      </part>
      <part id="LSA-1_obj" name="objective">
        <p>Require selection of sufficiently random look-up secrets</p>
        <link href="#LSA-1_smt" rel="assessment-for"/>
      </part>
      <part id="LSA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code used to generate look-up secrets.</p>
      </part>
    </control>
    <control id="LSA-1.5">
      <title>Look-Up Secret Delivery</title>
      <prop name="label" class="index" value="3.1.2.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSA-1.5_smt" name="statement">
        <p>CSPs that create look-up secret authenticators SHALL deliver the authenticator list securely to the subscriber (e.g., in an in-person session, via an online session, through the postal mail to a contact address).</p>
      </part>
      <part id="LSA-1.5_obj" name="objective">
        <p>Ensure that eavesdroppers and other intermediaries do not have access to look-up secrets being delivered to the subscriber.</p>
        <link href="#LSA-1.5_smt" rel="assessment-for"/>
      </part>
      <part id="LSA-1.5_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP to determine the possible methods for delivering look-up secrets to subscribers.</p>
      </part>
    </control>
    <control id="LSA-2">
      <title>Online Look-Up Secret Delivery</title>
      <prop name="label" class="index" value="3.1.2.1 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSA-2_smt" name="statement">
        <p>If delivered via an online session, the session SHALL be authenticated by the subscriber at AAL2 or higher and SHALL deliver the secrets through an authenticated protected channel and in accordance with the post-enrollment binding requirements in Sec. 4.1.2.</p>
      </part>
      <part id="LSA-2_obj" name="objective">
        <p>Ensure that online delivery of look-up secrets is sufficiently secure.</p>
        <link href="#LSA-2_smt" rel="assessment-for"/>
      </part>
      <part id="LSA-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting delivery of look-up secrets online, and ensure that a minimum of AAL2 authentication is required and that an authenticated protected channel such as TLS is used.</p>
      </part>
      <part id="LSA-2_gdn" name="guidance">
        <p>Applies when look-up secrets are delivered online.</p>
      </part>
    </control>
    <control id="LSA-3">
      <title>Look-Up Secret Length</title>
      <prop name="label" class="index" value="3.1.2.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSA-3_smt" name="statement">
        <p>Look-up secrets SHALL be at least six decimal digits (or equivalent) in length. Additional requirements described in Sec. 3.1.2.2 may also apply, depending on their length.</p>
      </part>
      <part id="LSA-3_obj" name="objective">
        <p>Verify that look-up secrets are sufficiently long to provide adequate security.</p>
        <link href="#LSA-3_smt" rel="assessment-for"/>
      </part>
      <part id="LSA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine look-up secrets received in response to a request and verify that they are at least six decimal digits or equivalent in length.</p>
      </part>
    </control>
    <control id="LSV-1">
      <title>Look-Up Secret Prompt</title>
      <prop name="label" class="index" value="3.1.2.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-1_smt" name="statement">
        <p>Verifiers of look-up secrets SHALL prompt the claimant for a secret from their authenticator.</p>
      </part>
      <part id="LSV-1_obj" name="objective">
        <p>Verify appropriate authentication flow.</p>
        <link href="#LSV-1_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by authenticating with a look-up secret authenticator and verify the prompt.</p>
      </part>
    </control>
    <control id="LSV-2">
      <title>Look-Up Secret Reuse</title>
      <prop name="label" class="index" value="3.1.2.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-2_smt" name="statement">
        <p>A secret from a look-up secret authenticator SHALL be used successfully only once.</p>
      </part>
      <part id="LSV-2_obj" name="objective">
        <p>Ensure that look-up secrets are replay resistant.</p>
        <link href="#LSV-2_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to authenticate using the same look-up secret more than once and verify that subsequent attempts are unsuccessful.</p>
      </part>
    </control>
    <control id="LSV-3">
      <title>Look-Up Secret Offline Attack Resistance</title>
      <prop name="label" class="index" value="3.1.2.2 C"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-3_smt" name="statement">
        <p>Verifiers SHALL store look-up secrets in a form that is resistant to offline attacks.</p>
      </part>
      <part id="LSV-3_obj" name="objective">
        <p>Require strong storage to protect against offline attacks.</p>
        <link href="#LSV-3_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Requirement is satisfied by LSV-4 and LSV-6 through LSV-8.</p>
      </part>
    </control>
    <control id="LSV-4">
      <title>Look-Up Secret Storage</title>
      <prop name="label" class="index" value="3.1.2.2 D"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-4_smt" name="statement">
        <p>All lookup secrets SHALL be stored in a hashed form using an approved hashing function.</p>
      </part>
      <part id="LSV-4_obj" name="objective">
        <p>Require use of a hashing function known to be sufficiently secure.</p>
        <link href="#LSV-4_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine hashing function used.</p>
      </part>
    </control>
    <control id="LSV-5">
      <title>Look-Up Secret Verifier Length</title>
      <prop name="label" class="index" value="3.1.2.2 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-5_smt" name="statement">
        <p>Look-up secrets SHALL be at least six decimal digits (or equivalent) in length, as specified in Sec. 3.1.2.1.</p>
      </part>
      <part id="LSV-5_obj" name="objective">
        <p>Verify that look-up secrets are sufficiently long to provide adequate security.</p>
        <link href="#LSV-5_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-5_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>See LSA-3.</p>
      </part>
    </control>
    <control id="LSV-6">
      <title>Look-Up Secret Salted Hashing</title>
      <prop name="label" class="index" value="3.1.2.2 F"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-6_smt" name="statement">
        <p>Look-up secrets that are shorter than the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication) SHALL be stored in a salted and hashed form using a suitable password hashing scheme, as described in Sec. 3.1.1.2.</p>
      </part>
      <part id="LSV-6_obj" name="objective">
        <p>Require salting for look-up secrets that are at risk of collision with other secrets.</p>
        <link href="#LSV-6_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine look-up secret verification storage to determine evidence of password hashing and salt storage.</p>
      </part>
      <part id="LSV-6_gdn" name="guidance">
        <p>Applies to look-up secrets shorter than 112 bits.</p>
      </part>
    </control>
    <control id="LSV-7">
      <title>Look-Up Secret Salt Length</title>
      <prop name="label" class="index" value="3.1.2.2 G"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-7_smt" name="statement">
        <p>The salt value SHALL be at least 32 bits in length and arbitrarily chosen to minimize salt value collisions among stored hashes.</p>
      </part>
      <part id="LSV-7_obj" name="objective">
        <p>Require use of a salt sufficient to ensure that two subscribers with the same look-up secrets do not hash to the same value in the verifier.</p>
        <link href="#LSV-7_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine stored salt values to ensure that they are at least 32 bits in length.</p>
      </part>
      <part id="LSV-7_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP personnel to determine that salt is chosen to avoid collisions.</p>
      </part>
      <part id="LSV-7_gdn" name="guidance">
        <p>Applies to look-up secrets shorter than 112 bits.</p>
      </part>
    </control>
    <control id="LSV-8">
      <title>Look-Up Secret Salt Storage</title>
      <prop name="label" class="index" value="3.1.2.2 H"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-8_smt" name="statement">
        <p>Both the salt value and the resulting hash SHALL be stored for each lookup secret.</p>
      </part>
      <part id="LSV-8_obj" name="objective">
        <p>Describes the use of a salt.</p>
        <link href="#LSV-8_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-8_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Requirement is satisfied by verification method of LSV-6.</p>
      </part>
      <part id="LSV-8_gdn" name="guidance">
        <p>Applies to look-up secrets shorter than 112 bits.</p>
      </part>
    </control>
    <control id="LSV-9">
      <title>Look-Up Secret Rate Limiting</title>
      <prop name="label" class="index" value="3.1.2.2 I"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-9_smt" name="statement">
        <p>The verifier SHALL implement a rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on the subscriber account, as described in Sec. 3.2.2.</p>
      </part>
      <part id="LSV-9_obj" name="objective">
        <p>Strengthen verifier against online look-up secret guessing attacks.</p>
        <link href="#LSV-9_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited.</p>
      </part>
    </control>
    <control id="LSV-10">
      <title>Look-Up Secret Authenticated Protected Channel</title>
      <prop name="label" class="index" value="3.1.2.2 J"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LSV-10_smt" name="statement">
        <p>The verifier SHALL use approved encryption and an authenticated protected channel when requesting look-up secrets.</p>
      </part>
      <part id="LSV-10_obj" name="objective">
        <p>Ensure that online delivery of look-up secrets is sufficiently secure.</p>
        <link href="#LSV-10_smt" rel="assessment-for"/>
      </part>
      <part id="LSV-10_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Requirement is satisfied by LSA-2.</p>
      </part>
    </control>
    <control id="OBA-1">
      <title>Out-Of-Band Channel Independence</title>
      <prop name="label" class="index" value="3.1.3.1 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBA-1_smt" name="statement">
        <p>The out-of-band authenticator SHALL establish a separate channel with the verifier to retrieve the out-of-band secret or authentication request.</p>
      </part>
      <part id="OBA-1_obj" name="objective">
        <p>Verify that a separate channel is used to communicate with the verifier.</p>
        <link href="#OBA-1_smt" rel="assessment-for"/>
      </part>
      <part id="OBA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to verify that the secondary channel is established with a separate device or that it is established with an independent application on the  authenticating device.</p>
      </part>
    </control>
    <control id="OBA-2">
      <title>Out-Of-Band Approved Encryption</title>
      <prop name="label" class="index" value="3.1.3.1 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBA-2_smt" name="statement">
        <p>Communication over the secondary channel SHALL use approved encryption unless sent via the public switched telephone network (PSTN).</p>
      </part>
      <part id="OBA-2_obj" name="objective">
        <p>Establish that delivery of the out-of-band secret is delivered securely.</p>
        <link href="#OBA-2_smt" rel="assessment-for"/>
      </part>
      <part id="OBA-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting an out-of-band secret and verify that an authenticated protected channel such as TLS is used or that is it delivered via the PSTN.</p>
      </part>
    </control>
    <control id="OBA-3">
      <title>Out-Of-Band Email Prohibition</title>
      <prop name="label" class="index" value="3.1.3.1 C"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBA-3_smt" name="statement">
        <p>Email SHALL NOT be used for out-of-band authentication because it may be vulnerable to:</p>
        <p>(a) Access using only a password.</p>
        <p>(b) Interception in transit or at intermediate mail servers.</p>
        <p>(c) Rerouting attacks, such as those caused by Domain Name System (DNS) spoofing.</p>
      </part>
      <part id="OBA-3_obj" name="objective">
        <p>Prohibit the use of email for delivery of out-of-band secrets because of multiple security vulnerabilities.</p>
        <link href="#OBA-3_smt" rel="assessment-for"/>
      </part>
      <part id="OBA-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to authenticate and verify that there is no option to use email for out-of-band authentication.</p>
      </part>
    </control>
    <control id="OBA-4">
      <title>Out-Of-Band Communication Methods</title>
      <prop name="label" class="index" value="3.1.3.1 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBA-4_smt" name="statement">
        <p>The out-of-band authenticator SHALL uniquely authenticate itself in one of the following ways when communicating with the verifier:</p>
        <p>(a) Using approved cryptography, establish a mutually authenticated protected channel (e.g., client-authenticated transport layer security (TLS) [RFC8446]) with the verifier. Communication between the out-of-band authenticator and the verifier MAY use a trusted intermediary service to which each authenticates. The key used to establish the channel SHALL be provisioned in a mutually authenticated session during authenticator binding, as described in Sec. 4.1.</p>
        <p>(b) Authenticate to a public mobile telephone network using a SIM card or equivalent secret that uniquely identifies the subscriber. This method SHALL only be used if a secret is sent from the verifier to the out-of-band device via the PSTN (i.e., SMS or voice) or an encrypted instant messaging service; use a wired connection to the PSTN that the verifier can call and dictate the out-of-band secret. For the purposes of this definition, "wired connection" includes services such as cable providers that offer PSTN services through other wired media and fiber via analog telephone adapters.</p>
      </part>
      <part id="OBA-4_obj" name="objective">
        <p>Confirm that out-of-band secrets are delivered only to authenticated devices.</p>
        <link href="#OBA-4_smt" rel="assessment-for"/>
      </part>
      <part id="OBA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to verify that one of the specified methods is used to authenticate the device receiving an out-of-band secret.</p>
      </part>
    </control>
    <control id="OBA-5">
      <title>Out-Of-Band Secondary Approval</title>
      <prop name="label" class="index" value="3.1.3.1 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBA-5_smt" name="statement">
        <p>If the out-of-band authenticator requests approval over the secondary communication channel rather than by presenting a secret that the claimant transfers to the primary communication channel, it SHALL accept a transfer of the secret from the primary channel and send it to the verifier over the secondary channel to associate the approval with the authentication transaction.</p>
      </part>
      <part id="OBA-5_obj" name="objective">
        <p>Ensure that authentication approval over the secondary channel requires transfer of a secret from the primary channel to avoid approval fatigue attacks.</p>
        <link href="#OBA-5_smt" rel="assessment-for"/>
      </part>
      <part id="OBA-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test, if present, secondary channel approval to verify that it requires entry of a secret obtained from the primary channel.</p>
      </part>
    </control>
    <control id="OBV-1">
      <title>Out-Of-Band Key Verification</title>
      <prop name="label" class="index" value="3.1.3.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-1_smt" name="statement">
        <p>The verifier SHALL NOT store the identifying key itself but SHALL use a verification method (e.g., an approved hash function or proof of possession of the identifying key) to uniquely identify the authenticator.</p>
      </part>
      <part id="OBV-1_obj" name="objective">
        <p>Ensure that, should the verifier be compromised, any active out-of-band secrets are protected from disclosure.</p>
        <link href="#OBV-1_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine verifier storage of out-of-band secrets to verify that they are protected from compromise.</p>
      </part>
    </control>
    <control id="OBV-2">
      <title>Out-Of-Band Transfer Methods</title>
      <prop name="label" class="index" value="3.1.3.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-2_smt" name="statement">
        <p>Depending on the type of out-of-band authenticator, one of the following SHALL take place:</p>
        <p>(a) Transfer of the secret from the secondary to the primary channel. As shown in Fig. 1, the verifier MAY signal the device that contains the subscriber's authenticator to indicate a readiness to authenticate. It SHALL then transmit a random secret to the out-of-band authenticator and wait for the secret to be returned via the primary communication channel.</p>
        <p>(b) Transfer of the secret from the primary to the secondary channel. As shown in Fig. 2, the verifier SHALL transmit a random authentication secret to the claimant via the primary channel. It SHALL then wait for the secret to be returned via the secondary channel from the claimant's out-of-band authenticator. The verifier MAY additionally display an address, such as a phone number or VoIP address, for the claimant to use in addressing its response to the verifier.</p>
      </part>
      <part id="OBV-2_obj" name="objective">
        <p>Ensure that one of the approved authentication flows involving the transfer of a secret from one device or application to another is used.</p>
        <link href="#OBV-2_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test out-of-band authentication to verify that one of the given authentication flows is used.</p>
      </part>
    </control>
    <control id="OBV-3">
      <title>Out-Of-Band Time Limit</title>
      <prop name="label" class="index" value="3.1.3.2 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-3_smt" name="statement">
        <p>In all cases, the authentication SHALL be considered invalid unless completed within 10 minutes.</p>
      </part>
      <part id="OBV-3_obj" name="objective">
        <p>Make sure that out-of-band secrets are only valid for the short term.</p>
        <link href="#OBV-3_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test out-of-band authentication by delaying slightly more than 10 minutes before transferring the secret and verify that authentication is unsuccessful.</p>
      </part>
    </control>
    <control id="OBV-4">
      <title>Out-Of-Band Replay Resistance</title>
      <prop name="label" class="index" value="3.1.3.2 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-4_smt" name="statement">
        <p>Verifiers SHALL accept a given authentication secret as valid only once during the validity period to provide replay resistance, as described in Sec. 3.2.7.</p>
      </part>
      <part id="OBV-4_obj" name="objective">
        <p>Verify that out-of-band secrets are replay resistant.</p>
        <link href="#OBV-4_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to authenticate and ensure that a given out-of-band secret can be used only once.</p>
      </part>
    </control>
    <control id="OBV-5">
      <title>Out-Of-Band Secret Length</title>
      <prop name="label" class="index" value="3.1.3.2 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-5_smt" name="statement">
        <p>The verifier SHALL generate random authentication secrets that are at least six decimal digits (or equivalent) in length.</p>
      </part>
      <part id="OBV-5_obj" name="objective">
        <p>Verify that out-of-band secrets are sufficiently long to provide adequate security.</p>
        <link href="#OBV-5_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine look-up secrets received in response to a request and verify that they are at least six decimal digits or equivalent in length.</p>
      </part>
    </control>
    <control id="OBV-5.5">
      <title>Out-Of-Band Secret Generation</title>
      <prop name="label" class="index" value="3.1.3.2 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-5.5_smt" name="statement">
        <p>The verifier SHALL generate random authentication secrets using an approved random bit generator as described in Sec. 3.2.12.</p>
      </part>
      <part id="OBV-5.5_obj" name="objective">
        <p>Require selection of sufficiently random look-up secrets.</p>
        <link href="#OBV-5.5_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-5.5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code used to generate look-up secrets.</p>
      </part>
    </control>
    <control id="OBV-6">
      <title>Out-Of-Band Rate Limiting</title>
      <prop name="label" class="index" value="3.1.3.2 F"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-6_smt" name="statement">
        <p>If the authentication secret is less than 64 bits long, the verifier SHALL implement a rate-limiting mechanism that effectively limits the total number of consecutive failed authentication attempts that can be made on the subscriber account as described in Sec. 3.2.2.</p>
      </part>
      <part id="OBV-6_obj" name="objective">
        <p>Ensure that out-of-band authentication is sufficiently protected against online guessing attacks.</p>
        <link href="#OBV-6_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited.</p>
      </part>
    </control>
    <control id="OBV-7">
      <title>Out-Of-Band Failure Count</title>
      <prop name="label" class="index" value="3.1.3.2 G"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="OBV-7_smt" name="statement">
        <p>Generating a new authentication secret SHALL NOT reset the failed authentication count.</p>
      </part>
      <part id="OBV-7_obj" name="objective">
        <p>Ensure that obtaining a new out-of-band secret does not bypass the rate limiting mechanism.</p>
        <link href="#OBV-7_smt" rel="assessment-for"/>
      </part>
      <part id="OBV-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited even if a new authentication secret is obtained.</p>
      </part>
    </control>
    <control id="AUPSTN-1">
      <title>Pstn Restricted</title>
      <prop name="label" class="index" value="3.1.3.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUPSTN-1_smt" name="statement">
        <p>Use of the PSTN for out-of-band verification is restricted as described in this section and SHALL satisfy the requirements of Sec. 3.2.9.</p>
      </part>
      <part id="AUPSTN-1_obj" name="objective">
        <p>Invoke restricted authenticator provisions.</p>
        <link href="#AUPSTN-1_smt" rel="assessment-for"/>
      </part>
      <part id="AUPSTN-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RESTA-1 and RESTA-2.</p>
      </part>
    </control>
    <control id="AUPSTN-2">
      <title>Pstn Modification Binding</title>
      <prop name="label" class="index" value="3.1.3.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUPSTN-2_smt" name="statement">
        <p>Setting or changing the pre-registered telephone number is considered to be the binding of a new authenticator and SHALL only occur as described in Sec. 4.1.2.</p>
      </part>
      <part id="AUPSTN-2_obj" name="objective">
        <p>Defend against attackers who attempt to change the pre-registered telephone number.</p>
        <link href="#AUPSTN-2_smt" rel="assessment-for"/>
      </part>
      <part id="AUPSTN-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by changing pre-registered telephone number and verify that requirements BAA-2 and BAA-3 are satisfied.</p>
      </part>
    </control>
    <control id="AUPSTN-3">
      <title>Pstn Alternatives</title>
      <prop name="label" class="index" value="3.1.3.3 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUPSTN-3_smt" name="statement">
        <p>Verifiers SHALL ensure that alternative authenticator types are available to all subscribers and SHOULD remind subscribers of this limitation of PSTN out-of-band authenticators before binding one or more devices controlled by the subscriber.</p>
      </part>
      <part id="AUPSTN-3_obj" name="objective">
        <p>Ensure that subscribers understand the risks associated with PSTN out-of-band authentication.</p>
        <link href="#AUPSTN-3_smt" rel="assessment-for"/>
      </part>
      <part id="AUPSTN-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RESTA-2.</p>
      </part>
    </control>
    <control id="MFOBA-1">
      <title>MF-OOB Activation</title>
      <prop name="label" class="index" value="3.1.3.4 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MFOBA-1_smt" name="statement">
        <p>Each use of the authenticator SHALL require the presentation of the activation factor.</p>
      </part>
      <part id="MFOBA-1_obj" name="objective">
        <p>Ensure that a previously activated authenticator cannot be coopted by an attacker.</p>
        <link href="#MFOBA-1_smt" rel="assessment-for"/>
      </part>
      <part id="MFOBA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by authenticating more than once with the same authenticator and verify that the activation factor is required each time. Also satisfied by MFOBA-4.</p>
      </part>
    </control>
    <control id="MFOBA-2">
      <title>MF-OOB Activation Secrets</title>
      <prop name="label" class="index" value="3.1.3.4 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MFOBA-2_smt" name="statement">
        <p>Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10.</p>
      </part>
      <part id="MFOBA-2_obj" name="objective">
        <p>Invoke requirements for activation secrets.</p>
        <link href="#MFOBA-2_smt" rel="assessment-for"/>
      </part>
      <part id="MFOBA-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AS-1 through AS-8.</p>
      </part>
    </control>
    <control id="MFOBA-3">
      <title>MF-OOB Biometric Requirements</title>
      <prop name="label" class="index" value="3.1.3.4 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MFOBA-3_smt" name="statement">
        <p>A biometric activation factor SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures.</p>
      </part>
      <part id="MFOBA-3_obj" name="objective">
        <p>Invoke requirements for biometric authentication factors.</p>
        <link href="#MFOBA-3_smt" rel="assessment-for"/>
      </part>
      <part id="MFOBA-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by UB-1 through UB-4.</p>
      </part>
    </control>
    <control id="MFOBA-4">
      <title>MF-OOB Activation Erasure</title>
      <prop name="label" class="index" value="3.1.3.4 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MFOBA-4_smt" name="statement">
        <p>The password or biometric sample used for activation and any biometric data derived from the biometric sample (e.g., a fingerprint image and feature locations produced by a fingerprint feature extractor) SHALL be erased immediately after an authentication operation.</p>
      </part>
      <part id="MFOBA-4_obj" name="objective">
        <p>Ensure that the activation factor cannot be used or extracted following an authentication operation.</p>
        <link href="#MFOBA-4_smt" rel="assessment-for"/>
      </part>
      <part id="MFOBA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to establish that activation factor is erased as required.</p>
      </part>
    </control>
    <control id="SFOA-1">
      <title>OTP Generation Key Strength</title>
      <prop name="label" class="index" value="3.1.4.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOA-1_smt" name="statement">
        <p>The secret key and its algorithm SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication).</p>
      </part>
      <part id="SFOA-1_obj" name="objective">
        <p>Ensure that the key used to generate the OTP is of sufficient size to be secure.</p>
        <link href="#SFOA-1_smt" rel="assessment-for"/>
      </part>
      <part id="SFOA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine the security strength of the key used to generate the OTP.</p>
      </part>
    </control>
    <control id="SFOA-2">
      <title>OTP Nonce Length</title>
      <prop name="label" class="index" value="3.1.4.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOA-2_smt" name="statement">
        <p>The nonce SHALL be of sufficient length to ensure that it is unique for each operation of the authenticator over its lifetime.</p>
      </part>
      <part id="SFOA-2_obj" name="objective">
        <p>Ensure that the nonce is large enough that the OTP sequence doesn't repeat.</p>
        <link href="#SFOA-2_smt" rel="assessment-for"/>
      </part>
      <part id="SFOA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine if the nonce is sufficiently long to not repeat during the expected lifetime of the authenticator.</p>
      </part>
    </control>
    <control id="SFOA-3">
      <title>TOTP Change Frequency</title>
      <prop name="label" class="index" value="3.1.4.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOA-3_smt" name="statement">
        <p>If the nonce used to generate the authenticator output is based on a real-time clock, the nonce SHALL be changed at least once every two minutes.</p>
      </part>
      <part id="SFOA-3_obj" name="objective">
        <p>Ensure that the nonce of a time-based OTP changes frequently enough.</p>
        <link href="#SFOA-3_smt" rel="assessment-for"/>
      </part>
      <part id="SFOA-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine that the OTP changes at least once every two minutes.</p>
      </part>
      <part id="SFOA-3_gdn" name="guidance">
        <p>Applies to time-based OTP authenticators.</p>
      </part>
    </control>
    <control id="SFOV-1">
      <title>OTP Verifier Key Protection</title>
      <prop name="label" class="index" value="3.1.3.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOV-1_smt" name="statement">
        <p>The symmetric keys used by authenticators are also present in the verifier and SHALL be strongly protected against unauthorized disclosure by access controls that limit access to the keys to only those software components that require access.</p>
      </part>
      <part id="SFOV-1_obj" name="objective">
        <p>Protect against attacks on verifier.</p>
        <link href="#SFOV-1_smt" rel="assessment-for"/>
      </part>
      <part id="SFOV-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of OTP generation keys to determine whether they are strongly protected.</p>
      </part>
    </control>
    <control id="SFOV-2">
      <title>OTP Key Establishment</title>
      <prop name="label" class="index" value="3.1.4.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOV-2_smt" name="statement">
        <p>When binding a single-factor OTP authenticator to a subscriber account, the verifier or associated CSP SHALL use approved cryptography for key establishment to generate and exchange keys or to obtain the secrets required to duplicate the authenticator output.</p>
      </part>
      <part id="SFOV-2_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms are being used.</p>
        <link href="#SFOV-2_smt" rel="assessment-for"/>
      </part>
      <part id="SFOV-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code or documentation showing the algorithms being used and verify that they are NIST approved.</p>
      </part>
    </control>
    <control id="SFOV-3">
      <title>OTP Authenticated Protected Channels</title>
      <prop name="label" class="index" value="3.1.4.2 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOV-3_smt" name="statement">
        <p>The verifier SHALL use approved encryption and an authenticated protected channel when collecting the OTP.</p>
      </part>
      <part id="SFOV-3_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms and protocols are being used.</p>
        <link href="#SFOV-3_smt" rel="assessment-for"/>
      </part>
      <part id="SFOV-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or code to determine that only approved cryptographic algorithms can be used.</p>
      </part>
      <part id="SFOV-3_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine secure use of a protocol such as TLS for communication with the claimant.</p>
      </part>
    </control>
    <control id="SFOV-4">
      <title>OTP Replay Protection</title>
      <prop name="label" class="index" value="3.1.4.2 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOV-4_smt" name="statement">
        <p>Verifiers SHALL accept a given OTP only once while it is valid to provide replay resistance, as described in Sec. 3.2.7.</p>
      </part>
      <part id="SFOV-4_obj" name="objective">
        <p>Ensure that OTP use is replay resistant.</p>
        <link href="#SFOV-4_smt" rel="assessment-for"/>
      </part>
      <part id="SFOV-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to ensure that it is not possible to successfully use the same OTP value for two different authentication transactions while it is valid.</p>
      </part>
    </control>
    <control id="SFOV-5">
      <title>TOTP Key Lifetime</title>
      <prop name="label" class="index" value="3.1.4.2 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOV-5_smt" name="statement">
        <p>Time-based OTPs [TOTP] SHALL have a defined lifetime that is determined by the expected clock drift in either direction of the authenticator over its lifetime plus an allowance for network delay and claimant entry of the OTP.</p>
      </part>
      <part id="SFOV-5_obj" name="objective">
        <p>Ensure that OTP will not fail prematurely due to clock drift.</p>
        <link href="#SFOV-5_smt" rel="assessment-for"/>
      </part>
      <part id="SFOV-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine specifications for authenticator clock drift and planned lifetime and ensure that time tolerance of OTP entry is sufficiently long.</p>
      </part>
      <part id="SFOV-5_gdn" name="guidance">
        <p>Applies to time-based OTP authenticators.</p>
      </part>
    </control>
    <control id="SFOV-6">
      <title>OTP Rate Limiting</title>
      <prop name="label" class="index" value="3.1.4.2 F"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFOV-6_smt" name="statement">
        <p>The verifier SHOULD implement or, if the authenticator output is less than 64 bits in length, SHALL implement a rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on the subscriber account, as described in Sec. 3.2.2.</p>
      </part>
      <part id="SFOV-6_obj" name="objective">
        <p>Protect against OTP guessing attacks</p>
        <link href="#SFOV-6_smt" rel="assessment-for"/>
      </part>
      <part id="SFOV-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited.</p>
      </part>
      <part id="SFOV-6_gdn" name="guidance">
        <p>Applies when authenticator output if less than 64 bits in length.</p>
      </part>
    </control>
    <control id="MFOA-1">
      <title>MF-OTP Activation</title>
      <prop name="label" class="index" value="3.1.5.1 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOA-1_smt" name="statement">
        <p>Each use of the authenticator SHALL require the input of the activation factor.</p>
      </part>
      <part id="MFOA-1_obj" name="objective">
        <p>Ensure that all use of the authenticator is protected by the activation factor.</p>
        <link href="#MFOA-1_smt" rel="assessment-for"/>
      </part>
      <part id="MFOA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to authenticate and verify that the activation factor is needed for each authentication.</p>
      </part>
    </control>
    <control id="MFOA-2">
      <title>MF-OTP Generation Key Strength</title>
      <prop name="label" class="index" value="3.1.5.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOA-2_smt" name="statement">
        <p>The secret key and its algorithm SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication).</p>
      </part>
      <part id="MFOA-2_obj" name="objective">
        <p>Ensure that the key used to generate the OTP is of sufficient size to be secure.</p>
        <link href="#MFOA-2_smt" rel="assessment-for"/>
      </part>
      <part id="MFOA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine the security strength of the key used to generate the OTP.</p>
      </part>
    </control>
    <control id="MFOA-3">
      <title>MF-OTP Nonce Length</title>
      <prop name="label" class="index" value="3.1.5.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOA-3_smt" name="statement">
        <p>The nonce SHALL be of sufficient length to ensure that it is unique for each operation of the authenticator over its lifetime.</p>
      </part>
      <part id="MFOA-3_obj" name="objective">
        <p>Ensure that the nonce is large enough that the OTP sequence doesn't repeat.</p>
        <link href="#MFOA-3_smt" rel="assessment-for"/>
      </part>
      <part id="MFOA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine if the nonce is sufficiently long to not repeat during the expected lifetime of the authenticator.</p>
      </part>
    </control>
    <control id="MFOA-4">
      <title>MF-TOTP Change Frequency</title>
      <prop name="label" class="index" value="3.1.5.1 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOA-4_smt" name="statement">
        <p>If the nonce used to generate the authenticator output is based on a real-time clock, the nonce SHALL be changed at least once every two minutes.</p>
      </part>
      <part id="MFOA-4_obj" name="objective">
        <p>Ensure that the nonce of a time-based OTP changes frequently enough.</p>
        <link href="#MFOA-4_smt" rel="assessment-for"/>
      </part>
      <part id="MFOA-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine that the OTP changes at least once every two minutes.</p>
      </part>
      <part id="MFOA-4_gdn" name="guidance">
        <p>Applies to time-based OTP authenticators.</p>
      </part>
    </control>
    <control id="MFOA-5">
      <title>MF-OTP Activation Secrets</title>
      <prop name="label" class="index" value="3.1.5.1 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOA-5_smt" name="statement">
        <p>Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10.</p>
      </part>
      <part id="MFOA-5_obj" name="objective">
        <p>Invoke requirements for activation secrets.</p>
        <link href="#MFOA-5_smt" rel="assessment-for"/>
      </part>
      <part id="MFOA-5_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AS-1 through AS-8.</p>
      </part>
      <part id="MFOA-5_gdn" name="guidance">
        <p>Authenticator uses activation secrets.</p>
      </part>
    </control>
    <control id="MFOA-6">
      <title>MF-OTP Biometric Requirements</title>
      <prop name="label" class="index" value="3.1.5.1 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOA-6_smt" name="statement">
        <p>A biometric activation factor SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures.</p>
      </part>
      <part id="MFOA-6_obj" name="objective">
        <p>Invoke requirements for biometric authentication factors.</p>
        <link href="#MFOA-6_smt" rel="assessment-for"/>
      </part>
      <part id="MFOA-6_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by UB-1 through UB-4.</p>
      </part>
      <part id="MFOA-6_gdn" name="guidance">
        <p>Authenticator uses biometric activation.</p>
      </part>
    </control>
    <control id="MFOA-7">
      <title>MF-OTP Activation Erasure</title>
      <prop name="label" class="index" value="3.1.5.1 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOA-7_smt" name="statement">
        <p>The unencrypted key and activation secret or biometric sample and any biometric data derived from the biometric sample (e.g., a fingerprint image and feature locations produced by a fingerprint feature extractor) SHALL be erased immediately after an OTP has been generated.</p>
      </part>
      <part id="MFOA-7_obj" name="objective">
        <p>Ensure that the activation factor cannot be used or extracted following an authentication operation.</p>
        <link href="#MFOA-7_smt" rel="assessment-for"/>
      </part>
      <part id="MFOA-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to establish that activation factor is erased as required.</p>
      </part>
    </control>
    <control id="MFOV-1">
      <title>MF-OTP Verifier Key Protection</title>
      <prop name="label" class="index" value="3.1.5.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOV-1_smt" name="statement">
        <p>The symmetric keys used by authenticators SHALL be strongly protected against unauthorized disclosure by access controls that limit access to the keys to only those software components that require access.</p>
      </part>
      <part id="MFOV-1_obj" name="objective">
        <p>Protect against attacks on verifier.</p>
        <link href="#MFOV-1_smt" rel="assessment-for"/>
      </part>
      <part id="MFOV-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of OTP generation keys to determine whether they are strongly protected.</p>
      </part>
    </control>
    <control id="MFOV-2">
      <title>MF-OTP Key Establishment</title>
      <prop name="label" class="index" value="3.1.5.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOV-2_smt" name="statement">
        <p>When binding a multi-factor OTP authenticator to a subscriber account, the verifier or associated CSP SHALL use approved cryptography for key establishment to generate and exchange keys or to obtain the secrets required to duplicate the authenticator output.</p>
      </part>
      <part id="MFOV-2_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms are being used.</p>
        <link href="#MFOV-2_smt" rel="assessment-for"/>
      </part>
      <part id="MFOV-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code or documentation showing the algorithms being used and verify that they are NIST approved.</p>
      </part>
    </control>
    <control id="MFOV-3">
      <title>MF-OTP Authenticated Protected Channels</title>
      <prop name="label" class="index" value="3.1.5.2 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOV-3_smt" name="statement">
        <p>The verifier SHALL use approved encryption and an authenticated protected channel when collecting the OTP.</p>
      </part>
      <part id="MFOV-3_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms and protocols are being used.</p>
        <link href="#MFOV-3_smt" rel="assessment-for"/>
      </part>
      <part id="MFOV-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or code to determine that only approved cryptographic algorithms can be used.</p>
      </part>
      <part id="MFOV-3_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine secure use of a protocol such as TLS for communication with the claimant.</p>
      </part>
    </control>
    <control id="MFOV-4">
      <title>MF-OTP Replay Protection</title>
      <prop name="label" class="index" value="3.1.5.2 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOV-4_smt" name="statement">
        <p>Verifiers SHALL accept a given OTP only once while it is valid to provide replay resistance, as described in Sec. 3.2.7.</p>
      </part>
      <part id="MFOV-4_obj" name="objective">
        <p>Ensure that OTP use is replay resistant.</p>
        <link href="#MFOV-4_smt" rel="assessment-for"/>
      </part>
      <part id="MFOV-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to ensure that it is not possible to successfully use the same OTP value for two different authentication transactions while it is valid.</p>
      </part>
    </control>
    <control id="MFOV-5">
      <title>MF-TOTP Key Lifetime</title>
      <prop name="label" class="index" value="3.1.5.2 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOV-5_smt" name="statement">
        <p>Time-based OTPs [TOTP] SHALL have a defined lifetime that is determined by the expected clock drift in either direction of the authenticator over its lifetime plus an allowance for network delay and claimant entry of the OTP.</p>
      </part>
      <part id="MFOV-5_obj" name="objective">
        <p>Ensure that OTP will not fail prematurely due to clock drift.</p>
        <link href="#MFOV-5_smt" rel="assessment-for"/>
      </part>
      <part id="MFOV-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine specifications for authenticator clock drift and planned lifetime and ensure that time tolerance of OTP entry is sufficiently long.</p>
      </part>
    </control>
    <control id="MFOV-6">
      <title>MF-OTP Rate Limiting</title>
      <prop name="label" class="index" value="3.1.5.2 F"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFOV-6_smt" name="statement">
        <p>The verifier SHALL implement a rate-limiting mechanism that effectively limits the number of consecutive failed authentication attempts that can be made on the subscriber account, as required by Sec. 3.2.10.</p>
      </part>
      <part id="MFOV-6_obj" name="objective">
        <p>Protect against OTP guessing attacks</p>
        <link href="#MFOV-6_smt" rel="assessment-for"/>
      </part>
      <part id="MFOV-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited.</p>
      </part>
    </control>
    <control id="SFCATION-1">
      <title>SF Crypto Public Key</title>
      <prop name="label" class="index" value="3.1.6 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="SFCATION-1_smt" name="statement">
        <p>Single-factor cryptographic authenticators used at AAL3 SHALL use public-key cryptography to protect the authentication secrets from compromise of the verifier.</p>
      </part>
      <part id="SFCATION-1_obj" name="objective">
        <p>Avoid the use of shared authentication secrets that could be compromised by an attacker.</p>
        <link href="#SFCATION-1_smt" rel="assessment-for"/>
      </part>
      <part id="SFCATION-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation of verifiers to determine that they only store public keys for cryptographic authenticators</p>
      </part>
    </control>
    <control id="SFCATORS-1">
      <title>SF Exportable Authentication Key Protection</title>
      <prop name="label" class="index" value="3.1.6.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="SFCATORS-1_smt" name="statement">
        <p>If they are accessible to the endpoint being authenticated, exportable authentication keys SHALL be strongly protected against unauthorized disclosure with access controls that limit access to the key to only those software components that require access.</p>
      </part>
      <part id="SFCATORS-1_obj" name="objective">
        <p>Protect against attacks on authenticator.</p>
        <link href="#SFCATORS-1_smt" rel="assessment-for"/>
      </part>
      <part id="SFCATORS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of authentication keys to determine whether they are strongly protected.</p>
      </part>
      <part id="SFCATORS-1_gdn" name="guidance">
        <p>Applies to exportable authentication keys.</p>
      </part>
    </control>
    <control id="SFCATORS-2">
      <title>SF Non-Exportable Authentication Key Storage</title>
      <prop name="label" class="index" value="3.1.6.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFCATORS-2_smt" name="statement">
        <p>Nonexportable authentication keys (usable at AAL3 or below) SHALL be stored in an isolated execution environment that is protected by hardware or in a separate processor with a controlled interface to the central processing unit of the user endpoint.</p>
      </part>
      <part id="SFCATORS-2_obj" name="objective">
        <p>Protect against attacks on authenticator.</p>
        <link href="#SFCATORS-2_smt" rel="assessment-for"/>
      </part>
      <part id="SFCATORS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of authentication keys to determine whether they are stored in an isolated execution environment.</p>
      </part>
      <part id="SFCATORS-2_gdn" name="guidance">
        <p>Applies to non-exportable authentication keys.</p>
      </part>
    </control>
    <control id="SFCATORS-3">
      <title>SF External Authentication Key Requirements</title>
      <prop name="label" class="index" value="3.1.6.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFCATORS-3_smt" name="statement">
        <p>External (i.e., non-embedded) cryptographic authenticators SHALL meet the requirements for connected authenticators in Sec. 3.2.11.</p>
      </part>
      <part id="SFCATORS-3_obj" name="objective">
        <p>Ensure integrity of endpoint-authenticator connection.</p>
        <link href="#SFCATORS-3_smt" rel="assessment-for"/>
      </part>
      <part id="SFCATORS-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by CONNAUTH-1 through CONNAUTH-3, and if wireless, WC-1 through WC-7.</p>
      </part>
      <part id="SFCATORS-3_gdn" name="guidance">
        <p>Applies to non-embedded cryptographic authenticators.</p>
      </part>
    </control>
    <control id="SFCVER-1">
      <title>Cryptographic Verifier Symmetric Key Protection</title>
      <prop name="label" class="index" value="3.1.6.2 A"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFCVER-1_smt" name="statement">
        <p>While both types of keys SHALL be protected against modification, symmetric keys SHALL additionally be protected against unauthorized disclosure by access controls that limit access to the key to only those software components that require access.</p>
      </part>
      <part id="SFCVER-1_obj" name="objective">
        <p>Protect against attacks on verifier.</p>
        <link href="#SFCVER-1_smt" rel="assessment-for"/>
      </part>
      <part id="SFCVER-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of authentication keys to determine whether they are strongly protected.</p>
      </part>
      <part id="SFCVER-1_gdn" name="guidance">
        <p>Applies when symmetric authentication keys are used.</p>
      </part>
    </control>
    <control id="SFCVER-2">
      <title>Cryptographic Authentication Key Strength</title>
      <prop name="label" class="index" value="3.1.6.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFCVER-2_smt" name="statement">
        <p>The authentication key and its algorithm SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication).</p>
      </part>
      <part id="SFCVER-2_obj" name="objective">
        <p>Ensure that the authentication key is of sufficient size to be secure.</p>
        <link href="#SFCVER-2_smt" rel="assessment-for"/>
      </part>
      <part id="SFCVER-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine the security strength of the authentication key.</p>
      </part>
    </control>
    <control id="SFCVER-3">
      <title>Cryptographic Nonce Length</title>
      <prop name="label" class="index" value="3.1.6.2 C"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFCVER-3_smt" name="statement">
        <p>The challenge nonce SHALL be at least 64 bits in length and SHALL either be unique over the authenticator's lifetime or statistically unique (i.e., generated using an approved random bit generator, as described in Sec. 3.2.12).</p>
      </part>
      <part id="SFCVER-3_obj" name="objective">
        <p>Provide strong protection against replay attacks.</p>
        <link href="#SFCVER-3_smt" rel="assessment-for"/>
      </part>
      <part id="SFCVER-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code used to generate the authentication nonce.</p>
      </part>
    </control>
    <control id="SFCVER-4">
      <title>Cryptographic Verifier Approved Cryptography</title>
      <prop name="label" class="index" value="3.1.6.2 D"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SFCVER-4_smt" name="statement">
        <p>The verification operation SHALL use approved cryptography.</p>
      </part>
      <part id="SFCVER-4_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms and protocols are being used.</p>
        <link href="#SFCVER-4_smt" rel="assessment-for"/>
      </part>
      <part id="SFCVER-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or code to determine that only approved cryptographic algorithms can be used.</p>
      </part>
    </control>
    <control id="MFCTION-1">
      <title>MF Crypto Public Key</title>
      <prop name="label" class="index" value="3.1.7 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="MFCTION-1_smt" name="statement">
        <p>Multi-factor cryptographic authenticators used at AAL3 SHALL use public-key cryptography to protect the authentication secrets from compromise of the verifier.</p>
      </part>
      <part id="MFCTION-1_obj" name="objective">
        <p>Avoid the use of shared authentication secrets that could be compromised by an attacker.</p>
        <link href="#MFCTION-1_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTION-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation of verifiers to determine that they only store public keys for cryptographic authenticators.</p>
      </part>
    </control>
    <control id="MFCTORS-1">
      <title>MF Crypto Authenticator Activation Required</title>
      <prop name="label" class="index" value="3.1.7.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="MFCTORS-1_smt" name="statement">
        <p>Multi-factor cryptographic authenticators encapsulate one or more authentication keys that SHALL only be accessible through the presentation and verification of an activation factor (i.e., a password or a biometric characteristic).</p>
      </part>
      <part id="MFCTORS-1_obj" name="objective">
        <p>Ensure that authenticator enforces use of an activation factor.</p>
        <link href="#MFCTORS-1_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of authentication secret to determine that the secret is only accessible upon presentation of a valid activation factor.</p>
      </part>
    </control>
    <control id="MFCTORS-2">
      <title>MF Non-Exportable Authentication Key Storage</title>
      <prop name="label" class="index" value="3.1.7.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="MFCTORS-2_smt" name="statement">
        <p>Non-exportable authentication keys, suitable for use at AAL3, SHALL be stored in an isolated execution environment that is protected by hardware or in a separate processor with a controlled interface to the central processing unit of the user endpoint.</p>
      </part>
      <part id="MFCTORS-2_obj" name="objective">
        <p>Protect against attacks on authenticator.</p>
        <link href="#MFCTORS-2_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of authentication keys to determine whether they are stored in an isolated execution environment.</p>
      </part>
      <part id="MFCTORS-2_gdn" name="guidance">
        <p>Applies to non-exportable authentication keys.</p>
      </part>
    </control>
    <control id="MFCTORS-3">
      <title>MF Exportable Authentication Key Protection</title>
      <prop name="label" class="index" value="3.1.7.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="MFCTORS-3_smt" name="statement">
        <p>If accessible to the endpoint being authenticated, authentication keys SHALL be strongly protected against unauthorized disclosure by using access controls that limit access to the authentication keys to only those software components that require access.</p>
      </part>
      <part id="MFCTORS-3_obj" name="objective">
        <p>Protect against attacks on authenticator.</p>
        <link href="#MFCTORS-3_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of authentication keys to determine whether they are strongly protected.</p>
      </part>
      <part id="MFCTORS-3_gdn" name="guidance">
        <p>Applies to exportable authentication keys.</p>
      </part>
    </control>
    <control id="MFCTORS-4">
      <title>MF External Authentication Key Requirements</title>
      <prop name="label" class="index" value="3.1.7.1 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="MFCTORS-4_smt" name="statement">
        <p>External (non-embedded) cryptographic authenticators SHALL meet the requirements for connected authenticators in Sec. 3.2.11.</p>
      </part>
      <part id="MFCTORS-4_obj" name="objective">
        <p>Ensure integrity of endpoint-authenticator connection.</p>
        <link href="#MFCTORS-4_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by CONNAUTH-1 through CONNAUTH-3, and if wireless, WC-1 through WC-7.</p>
      </part>
      <part id="MFCTORS-4_gdn" name="guidance">
        <p>Applies to non-embedded cryptographic authenticators.</p>
      </part>
    </control>
    <control id="MFCTORS-5">
      <title>MF Crypto Activation</title>
      <prop name="label" class="index" value="3.1.7.1 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="MFCTORS-5_smt" name="statement">
        <p>Each authentication event SHALL require input and verification of the local activation factor.</p>
      </part>
      <part id="MFCTORS-5_obj" name="objective">
        <p>Ensure that a previously activated authenticator cannot be coopted by an attacker.</p>
        <link href="#MFCTORS-5_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by authenticating more than once with the same authenticator and verify that the activation factor is required each time.</p>
      </part>
    </control>
    <control id="MFCTORS-6">
      <title>MF Crypto Activation Secrets</title>
      <prop name="label" class="index" value="3.1.7.1 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="MFCTORS-6_smt" name="statement">
        <p>Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10.</p>
      </part>
      <part id="MFCTORS-6_obj" name="objective">
        <p>Invoke requirements for activation secrets.</p>
        <link href="#MFCTORS-6_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-6_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AS-1 through AS-8.</p>
      </part>
      <part id="MFCTORS-6_gdn" name="guidance">
        <p>Authenticator uses activation secrets.</p>
      </part>
    </control>
    <control id="MFCTORS-7">
      <title>MF Crypto Biometric Requirements</title>
      <prop name="label" class="index" value="3.1.7.1 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="MFCTORS-7_smt" name="statement">
        <p>A biometric activation factor SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures.</p>
      </part>
      <part id="MFCTORS-7_obj" name="objective">
        <p>Invoke requirements for biometric authentication factors.</p>
        <link href="#MFCTORS-7_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-7_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by UB-1 through UB-4.</p>
      </part>
      <part id="MFCTORS-7_gdn" name="guidance">
        <p>Authenticator uses biometric activation.</p>
      </part>
    </control>
    <control id="MFCTORS-8">
      <title>MF Crypto Activation Erasure</title>
      <prop name="label" class="index" value="3.1.7.1 H"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="MFCTORS-8_smt" name="statement">
        <p>The activation secret or biometric sample and any biometric data derived from the biometric sample (e.g., a fingerprint image and feature locations produced by a fingerprint feature extractor) SHALL be erased after an authentication transaction.</p>
      </part>
      <part id="MFCTORS-8_obj" name="objective">
        <p>Ensure that the activation factor cannot be used or extracted following an authentication operation.</p>
        <link href="#MFCTORS-8_smt" rel="assessment-for"/>
      </part>
      <part id="MFCTORS-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to establish that activation factor is erased as required.</p>
      </part>
    </control>
    <control id="MFCFIERS-0.5">
      <title>MF Crypto Verifier Requirements</title>
      <prop name="label" class="index" value="3.1.7.2"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAl3"/>
      <part id="MFCFIERS-0.5_smt" name="statement">
        <p>Requirements for a multi-factor cryptographic verifier are identical to those for a single-factor cryptographic verifier.</p>
      </part>
      <part id="MFCFIERS-0.5_obj" name="objective">
        <p>Ensure baseline requirements for cryptographic verifiers are met.</p>
        <link href="#MFCFIERS-0.5_smt" rel="assessment-for"/>
      </part>
      <part id="MFCFIERS-0.5_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SFCVER-1 through SFCVER-4</p>
      </part>
    </control>
    <control id="MFCFIERS-1">
      <title>MF Crypto Activation Flag</title>
      <prop name="label" class="index" value="3.1.7.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="MFCFIERS-1_smt" name="statement">
        <p>If a flag indicating use of an activation factor is present and indicates that an activation factor was not used, the authentication SHALL be treated as single-factor.</p>
      </part>
      <part id="MFCFIERS-1_obj" name="objective">
        <p>Ensure that an activation factor was used if indication was provided.</p>
        <link href="#MFCFIERS-1_smt" rel="assessment-for"/>
      </part>
      <part id="MFCFIERS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine if the activation factor flag is checked and heeded, if provided.</p>
      </part>
    </control>
    <control id="UWSCW-1">
      <title>Wallet Activation Required</title>
      <prop name="label" class="index" value="3.1.7.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UWSCW-1_smt" name="statement">
        <p>Access to the private key SHALL require an activation factor.</p>
      </part>
      <part id="UWSCW-1_obj" name="objective">
        <p>Ensure that authenticator enforces use of an activation factor.</p>
        <link href="#UWSCW-1_smt" rel="assessment-for"/>
      </part>
      <part id="UWSCW-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of authentication secret to determine that the secret is only accessible upon presentation of a valid activation factor.</p>
      </part>
    </control>
    <control id="UWSCW-2">
      <title>Wallet Activation Secrets</title>
      <prop name="label" class="index" value="3.1.7.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UWSCW-2_smt" name="statement">
        <p>Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10.</p>
      </part>
      <part id="UWSCW-2_obj" name="objective">
        <p>Invoke requirements for activation secrets.</p>
        <link href="#UWSCW-2_smt" rel="assessment-for"/>
      </part>
      <part id="UWSCW-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AS-1 through AS-8.</p>
      </part>
      <part id="UWSCW-2_gdn" name="guidance">
        <p>Authenticator uses activation secrets.</p>
      </part>
    </control>
    <control id="UWSCW-3">
      <title>Wallet Biometric Requirements</title>
      <prop name="label" class="index" value="3.1.7.3 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UWSCW-3_smt" name="statement">
        <p>Biometric activation factors SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures.</p>
      </part>
      <part id="UWSCW-3_obj" name="objective">
        <p>Invoke requirements for biometric authentication factors.</p>
        <link href="#UWSCW-3_smt" rel="assessment-for"/>
      </part>
      <part id="UWSCW-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by UB-1 through UB-4.</p>
      </part>
      <part id="UWSCW-3_gdn" name="guidance">
        <p>Authenticator uses biometric activation.</p>
      </part>
    </control>
    <control id="UWSCW-4">
      <title>Wallet Activation Erasure</title>
      <prop name="label" class="index" value="3.1.7.3 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UWSCW-4_smt" name="statement">
        <p>The password or biometric sample used for activation and any biometric data derived from the biometric sample SHALL be erased immediately after an authentication transaction.</p>
      </part>
      <part id="UWSCW-4_obj" name="objective">
        <p>Ensure that the activation factor cannot be used or extracted following an authentication operation.</p>
        <link href="#UWSCW-4_smt" rel="assessment-for"/>
      </part>
      <part id="UWSCW-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to establish that activation factor is erased as required.</p>
      </part>
    </control>
    <control id="UWSCW-5">
      <title>Wallet Federation</title>
      <prop name="label" class="index" value="3.1.7.3 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UWSCW-5_smt" name="statement">
        <p>Authentication processes using subscriber-controlled wallets SHALL be used with a federation process as detailed in Sec. 5 of [SP800-63C].</p>
      </part>
      <part id="UWSCW-5_obj" name="objective">
        <p>Ensure that subscriber-controlled wallets are used in connection with federation requirements.</p>
        <link href="#UWSCW-5_smt" rel="assessment-for"/>
      </part>
      <part id="UWSCW-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine federation process and verify compliance with requirements in Section 5 of SP 800-63C</p>
      </part>
    </control>
    <control id="UWSCW-6">
      <title>Wallet Phishing-Resistance Conditions</title>
      <prop name="label" class="index" value="3.1.7.3 F"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UWSCW-6_smt" name="statement">
        <p>Assertions that lack a valid signature from the wallet or an audience restriction SHALL NOT be considered phishing-resistant.</p>
      </part>
      <part id="UWSCW-6_obj" name="objective">
        <p>Ensure that wallets satisfy applications requiring phishing resistance.</p>
        <link href="#UWSCW-6_smt" rel="assessment-for"/>
      </part>
      <part id="UWSCW-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine assertions or code generating them to determine if valid signatures or audience restrictions are present.</p>
      </part>
    </control>
    <control id="UWSCW-7">
      <title>Wallet Activation Information</title>
      <prop name="label" class="index" value="3.1.7.3 G"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UWSCW-7_smt" name="statement">
        <p>Assertions SHALL also include sufficient information to determine the nature of the activation method used to activate the wallet.</p>
      </part>
      <part id="UWSCW-7_obj" name="objective">
        <p>Ensure that activation information is provided to relying parties.</p>
        <link href="#UWSCW-7_smt" rel="assessment-for"/>
      </part>
      <part id="UWSCW-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine assertions or code generating them to determine if the activation method is included.</p>
      </part>
    </control>
    <control id="PHYSA-1">
      <title>Physical Authenticator Instructions</title>
      <prop name="label" class="index" value="3.2.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="PHYSA-1_smt" name="statement">
        <p>CSPs SHALL provide subscriber instructions for appropriately protecting the authenticator against theft or loss.</p>
      </part>
      <part id="PHYSA-1_obj" name="objective">
        <p>Ensure that subscribers understand their responsibilities for protecting authenticators.</p>
        <link href="#PHYSA-1_smt" rel="assessment-for"/>
      </part>
      <part id="PHYSA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by establishing a new subscriber account and observe whether sufficient instructions are provided.</p>
      </part>
    </control>
    <control id="PHYSA-2">
      <title>Physical Authenticator Invalidation</title>
      <prop name="label" class="index" value="3.2.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="PHYSA-2_smt" name="statement">
        <p>The CSP SHALL provide a mechanism to invalidate the authenticator immediately upon notification from a subscriber that the authenticator's loss, theft, or compromise is suspected.</p>
      </part>
      <part id="PHYSA-2_obj" name="objective">
        <p>Ensure that subscribers have a meaningful way to report authenticator issues and that appropriate action is taken.</p>
        <link href="#PHYSA-2_smt" rel="assessment-for"/>
      </part>
      <part id="PHYSA-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by simulating the loss of an authenticator and determine whether instructions are provided to the subscriber to handle this situation and that appropriate action is taken when reported.</p>
      </part>
    </control>
    <control id="RL-1">
      <title>Rate Limiting Requirement</title>
      <prop name="label" class="index" value="3.2.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="RL-1_smt" name="statement">
        <p>When required by the authenticator type descriptions in Sec. 3.1, the verifier SHALL implement controls to protect against online guessing attacks.</p>
      </part>
      <part id="RL-1_obj" name="objective">
        <p>Control online guessing attacks.</p>
        <link href="#RL-1_smt" rel="assessment-for"/>
      </part>
      <part id="RL-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RL-2 through RL-6</p>
      </part>
    </control>
    <control id="RL-2">
      <title>Rate Limiting Upper Bound</title>
      <prop name="label" class="index" value="3.2.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="RL-2_smt" name="statement">
        <p>Unless otherwise specified in the description of a given authenticator, the verifier SHALL limit consecutive failed authentication attempts using a specific authenticator on a single subscriber account to no more than 100 by disabling that authenticator.</p>
      </part>
      <part id="RL-2_obj" name="objective">
        <p>Set overall upper limit on consecutive failed authentication attempts.</p>
        <link href="#RL-2_smt" rel="assessment-for"/>
      </part>
      <part id="RL-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making 101 authentication failures with an authenticator.</p>
      </part>
      <part id="RL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine subscriber account to verify that the authenticator has been disabled.</p>
      </part>
    </control>
    <control id="RL-3">
      <title>Rate Limiting Authenticator Association</title>
      <prop name="label" class="index" value="3.2.2 C"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="RL-3_smt" name="statement">
        <p>If more than one authenticator is involved with an excessive number of authentication attempts (e.g., single-factor cryptographic authenticator and centrally verified password), both authenticators SHALL be disabled.</p>
      </part>
      <part id="RL-3_obj" name="objective">
        <p>Address excessive authentication failures involving more than one authenticator.</p>
        <link href="#RL-3_smt" rel="assessment-for"/>
      </part>
      <part id="RL-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making excessive authentication failures with two authenticators.</p>
      </part>
      <part id="RL-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine subscriber account to verify that both authenticators have been disabled.</p>
      </part>
    </control>
    <control id="RL-4">
      <title>Rate Limiting Rebinding</title>
      <prop name="label" class="index" value="3.2.2 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="RL-4_smt" name="statement">
        <p>Authenticators that have been disabled SHALL be required to rebind to the subscriber account, as described in Sec. 4.1, to be usable in the future.</p>
      </part>
      <part id="RL-4_obj" name="objective">
        <p>Ensure that disabled authenticators are treated as unbound to the subscriber account.</p>
        <link href="#RL-4_smt" rel="assessment-for"/>
      </part>
      <part id="RL-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by causing an authenticator to be disabled due to excessive authentication failures and verify that there is no way to successfully use the authenticator other than to go through the authenticator binding procedure.</p>
      </part>
    </control>
    <control id="RL-5">
      <title>Rate Limiting AAL Limitation</title>
      <prop name="label" class="index" value="3.2.2 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="RL-5_smt" name="statement">
        <p>If the retry count of an authenticator is reset following a successful authentication, the maximum AAL of the authenticator being reset SHALL not exceed the AAL of the session from which it is being reset.</p>
      </part>
      <part id="RL-5_obj" name="objective">
        <p>Prevent AAL escalation due to authenticator retry count reset.</p>
        <link href="#RL-5_smt" rel="assessment-for"/>
      </part>
      <part id="RL-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by authenticating unsuccessfully and then successfully with a given authenticator and examine the maximum AAL at which it can be used to verify that it does not increase.</p>
      </part>
      <part id="RL-5_gdn" name="guidance">
        <p>Applies to verifiers that reset the unsuccessful authentication count after successful authentication.</p>
      </part>
    </control>
    <control id="RL-6">
      <title>Rate Limiting Recovery Requirement</title>
      <prop name="label" class="index" value="3.2.2 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="RL-6_smt" name="statement">
        <p>If the subscriber cannot authenticate at the required AAL, the account recovery procedures in Sec. 4.2 SHALL be used.</p>
      </part>
      <part id="RL-6_obj" name="objective">
        <p>Require account recovery in the event that authenticator rebinding is unavailable.</p>
        <link href="#RL-6_smt" rel="assessment-for"/>
      </part>
      <part id="RL-6_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by section 4.2 compliance</p>
      </part>
    </control>
    <control id="UB-1">
      <title>Biometrics Applicability</title>
      <prop name="label" class="index" value="3.2.3 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UB-1_smt" name="statement">
        <p>Biometrics SHALL only be used as part of multi-factor authentication with a physical authenticator (i.e., "something you have").</p>
      </part>
      <part id="UB-1_obj" name="objective">
        <p>Block use of biometric comparison as a single factor or with only a password.</p>
        <link href="#UB-1_smt" rel="assessment-for"/>
      </part>
      <part id="UB-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test available authentication methods to ensure that all require a physical authenticator.</p>
      </part>
    </control>
    <control id="UB-2">
      <title>Biometrics Not Cached</title>
      <prop name="label" class="index" value="3.2.3 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UB-2_smt" name="statement">
        <p>The biometric characteristic SHALL be presented and compared for each authentication operation.</p>
      </part>
      <part id="UB-2_obj" name="objective">
        <p>Do not allow biometric characteristics to be cached.</p>
        <link href="#UB-2_smt" rel="assessment-for"/>
      </part>
      <part id="UB-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making multiple authentications using biometric comparison and verify that the biometric characteristic is required to be presented each time.</p>
      </part>
    </control>
    <control id="UB-3">
      <title>Biometrics Alternatives</title>
      <prop name="label" class="index" value="3.2.3 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UB-3_smt" name="statement">
        <p>An alternative nonbiometric authentication option SHALL always be provided to the subscriber.</p>
      </part>
      <part id="UB-3_obj" name="objective">
        <p>Require alternatives in the event that a biometric characteristic cannot be presented for some reason.</p>
        <link href="#UB-3_smt" rel="assessment-for"/>
      </part>
      <part id="UB-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test available authentication methods to ensure that an alternative to biometric comparison is always available.</p>
      </part>
    </control>
    <control id="UB-4">
      <title>Biometrics Sensitivity</title>
      <prop name="label" class="index" value="3.2.3 D"/>
      <prop name="marking" class="target" value="Verifier/CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UB-4_smt" name="statement">
        <p>Biometric data SHALL be treated and secured as sensitive personal information.</p>
      </part>
      <part id="UB-4_obj" name="objective">
        <p>Ensure that biometric data is sufficiently protected.</p>
        <link href="#UB-4_smt" rel="assessment-for"/>
      </part>
      <part id="UB-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of biometric data and evaluate access controls for that data.</p>
      </part>
    </control>
    <control id="BA-1">
      <title>Biometric FMR</title>
      <prop name="label" class="index" value="3.2.3.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="BA-1_smt" name="statement">
        <p>The biometric system SHALL operate with an FMR [ISO/IEC2382-37] of one in 10000 or better for all demographic groups.</p>
      </part>
      <part id="BA-1_obj" name="objective">
        <p>Ensure biometric comparison is   sufficiently secure against false matches.</p>
        <link href="#BA-1_smt" rel="assessment-for"/>
      </part>
      <part id="BA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine test results or certifications for biometric system</p>
      </part>
    </control>
    <control id="BA-2">
      <title>Biometric Demographic Categories</title>
      <prop name="label" class="index" value="3.2.3.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="BA-2_smt" name="statement">
        <p>Demographic categories to be considered SHALL include sex and skin tone when these factors affect biometric performance.</p>
      </part>
      <part id="BA-2_obj" name="objective">
        <p>Ensure biometric comparison works for a wide demographic range.</p>
        <link href="#BA-2_smt" rel="assessment-for"/>
      </part>
      <part id="BA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine test procedure for biometric system to verify that a wide demographic range was included.</p>
      </part>
    </control>
    <control id="BA-3">
      <title>Biometric Test Conditions</title>
      <prop name="label" class="index" value="3.2.3.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="BA-3_smt" name="statement">
        <p>This FMR SHALL be achieved under the conditions of a conformant attack (i.e., zero-effort impostor attempt), as defined in [ISO/IEC30107-1].</p>
      </part>
      <part id="BA-3_obj" name="objective">
        <p>Define test conditions for false match rate test.</p>
        <link href="#BA-3_smt" rel="assessment-for"/>
      </part>
      <part id="BA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine test procedure to determine test conditions.</p>
      </part>
    </control>
    <control id="BA-4">
      <title>Biometric Test Procedure</title>
      <prop name="label" class="index" value="3.2.3.1 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="BA-4_smt" name="statement">
        <p>Biometric performance SHALL be tested in accordance with [ISO/IEC19795-1].</p>
      </part>
      <part id="BA-4_obj" name="objective">
        <p>Define test conditions for false match rate test.</p>
        <link href="#BA-4_smt" rel="assessment-for"/>
      </part>
      <part id="BA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine test procedure to determine test conditions.</p>
      </part>
    </control>
    <control id="BA-5">
      <title>Biometric Threshold</title>
      <prop name="label" class="index" value="3.2.3.1 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="BA-5_smt" name="statement">
        <p>The biometric system SHALL be configured with a fixed threshold; it is not feasible to change the threshold for each demographic.</p>
      </part>
      <part id="BA-5_obj" name="objective">
        <p>Require consistent match criteria for all demographic groups.</p>
        <link href="#BA-5_smt" rel="assessment-for"/>
      </part>
      <part id="BA-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine comparison algorithm to verify that it uses a single threshold.</p>
      </part>
    </control>
    <control id="PAD-1">
      <title>Biometric Pad</title>
      <prop name="label" class="index" value="3.2.3.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="PAD-1_smt" name="statement">
        <p>The biometric system SHOULD implement PAD for iris and fingerprint modalities and SHALL implement PAD for facial recognition.</p>
      </part>
      <part id="PAD-1_obj" name="objective">
        <p>Require PAD for facial recognition to counter deepfakes.</p>
        <link href="#PAD-1_smt" rel="assessment-for"/>
      </part>
      <part id="PAD-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test facial recognition with a synthetic image to verify use of presentation attack detection.</p>
      </part>
      <part id="PAD-1_gdn" name="guidance">
        <p>Applies to facial recognition modality.</p>
      </part>
    </control>
    <control id="PAD-2">
      <title>Biometric Voice Prohibition</title>
      <prop name="label" class="index" value="3.2.3.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="PAD-2_smt" name="statement">
        <p>Biometric comparison based on voice SHALL NOT be used.</p>
      </part>
      <part id="PAD-2_obj" name="objective">
        <p>Prohibit use of voice recognition due to ease in spoofing.</p>
        <link href="#PAD-2_smt" rel="assessment-for"/>
      </part>
      <part id="PAD-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test available authentication methods to verify that voice recognition is not available.</p>
      </part>
      <part id="PAD-2_gdn" name="guidance">
        <p>Applies to voice recognition modality.</p>
      </part>
    </control>
    <control id="IAD-1">
      <title>Biometric Failure Threshold</title>
      <prop name="label" class="index" value="3.2.3.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="IAD-1_smt" name="statement">
        <p>The biometric system SHALL allow no more than five consecutive failed authentication attempts or 10 consecutive failed attempts if PAD is implemented and meets the above requirements.</p>
      </part>
      <part id="IAD-1_obj" name="objective">
        <p>Limit opportunity to spoof biometric comparison.</p>
        <link href="#IAD-1_smt" rel="assessment-for"/>
      </part>
      <part id="IAD-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by creating unsuccessful comparisons and verify that requests are throttled after the specified limit is reached.</p>
      </part>
    </control>
    <control id="IAD-2">
      <title>Biometric Failure Delay</title>
      <prop name="label" class="index" value="3.2.3.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="IAD-2_smt" name="statement">
        <p>Once that limit has been reached, the biometric authenticator SHALL impose a delay of at least 30 seconds before each subsequent attempt with an overall limit of no more than 50 consecutive failed authentication attempts or 100 if PAD is implemented due to the mitigation of presentation attacks.</p>
      </part>
      <part id="IAD-2_obj" name="objective">
        <p>Limit opportunity to spoof biometric comparison.</p>
        <link href="#IAD-2_smt" rel="assessment-for"/>
      </part>
      <part id="IAD-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by creating unsuccessful comparisons and verify that requests are throttled after the specified limit is reached.</p>
      </part>
    </control>
    <control id="IAD-3">
      <title>Biometric Failure Limit</title>
      <prop name="label" class="index" value="3.2.3.3 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="IAD-3_smt" name="statement">
        <p>Once the overall limit is reached, the biometric system SHALL disable biometric authentication and offer another factor (e.g., a different biometric modality or an activation secret if it is not a required factor) if such an alternative method is already available.</p>
      </part>
      <part id="IAD-3_obj" name="objective">
        <p>Limit opportunity to spoof biometric comparison.</p>
        <link href="#IAD-3_smt" rel="assessment-for"/>
      </part>
      <part id="IAD-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by creating unsuccessful comparisons and verify that biometric comparison is disabled when the specified limit is reached.</p>
      </part>
    </control>
    <control id="IAD-4">
      <title>Biometric Unlocking Independence</title>
      <prop name="label" class="index" value="3.2.3.3 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="IAD-4_smt" name="statement">
        <p>The presentation of a biometric factor for authenticator activation SHALL be a separate operation from unlocking the host device (e.g., smartphone).</p>
      </part>
      <part id="IAD-4_obj" name="objective">
        <p>Minimize opportunity for an attacker to authenticate on an already unlocked device.</p>
        <link href="#IAD-4_smt" rel="assessment-for"/>
      </part>
      <part id="IAD-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to authenticate on an already unlocked device and verify that an additional biometric comparison is required.</p>
      </part>
    </control>
    <control id="IAD-5">
      <title>Biometric Endpoint Authentication</title>
      <prop name="label" class="index" value="3.2.3.3 E"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="IAD-5_smt" name="statement">
        <p>If the comparison is performed centrally, the sender or endpoint SHALL be authenticated before capturing the biometric sample from the claimant.</p>
      </part>
      <part id="IAD-5_obj" name="objective">
        <p>Protect against injection attacks from rogue hardware devices.</p>
        <link href="#IAD-5_smt" rel="assessment-for"/>
      </part>
      <part id="IAD-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine method for authenticating sensor or endpoint and evaluate its security</p>
      </part>
      <part id="IAD-5_gdn" name="guidance">
        <p>Central biometric comparison.</p>
      </part>
    </control>
    <control id="IAD-5.1">
      <title>Biometric Central Protection</title>
      <prop name="label" class="index" value="3.2.3.3 F"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="IAD-5.1_smt" name="statement">
        <p>If the comparison is performed centrally, appropriate controls (e.g., encryption and access controls) for sensitive personal information SHALL be implemented.</p>
      </part>
      <part id="IAD-5.1_obj" name="objective">
        <p>Ensure that centrally stored biometric data is sufficiently secure.</p>
        <link href="#IAD-5.1_smt" rel="assessment-for"/>
      </part>
      <part id="IAD-5.1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of biometric data and evaluate access controls for that data.</p>
      </part>
      <part id="IAD-5.1_gdn" name="guidance">
        <p>Central biometric comparison.</p>
      </part>
    </control>
    <control id="IAD-5.2">
      <title>Biometric Authenticated Protected Channel</title>
      <prop name="label" class="index" value="3.2.3.3 G"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="IAD-5.2_smt" name="statement">
        <p>If the comparison is performed centrally, an authenticated protected channel between the sensor (or an endpoint containing a sensor that resists sensor replacement) and the verifier SHALL be established. All transmission of biometric information SHALL be conducted over that authenticated protected channel.</p>
      </part>
      <part id="IAD-5.2_obj" name="objective">
        <p>Ensure that biometric data is transmitted securely for central comparison.</p>
        <link href="#IAD-5.2_smt" rel="assessment-for"/>
      </part>
      <part id="IAD-5.2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code or communications protocol to verify that all biometric data is transmitted over an authenticated protected channel.</p>
      </part>
      <part id="IAD-5.2_gdn" name="guidance">
        <p>Central biometric comparison.</p>
      </part>
    </control>
    <control id="UBS-1">
      <title>Biometric Sample Erasure</title>
      <prop name="label" class="index" value="3.2.3.4 A"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UBS-1_smt" name="statement">
        <p>The biometric samples and any other biometric data derived from them SHALL be erased immediately after any adaptation or research data has been derived.</p>
      </part>
      <part id="UBS-1_obj" name="objective">
        <p>Ensure that biometric samples are securely erased as soon as they are no longer needed.</p>
        <link href="#UBS-1_smt" rel="assessment-for"/>
      </part>
      <part id="UBS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to verify erasure of biometric samples.</p>
      </part>
    </control>
    <control id="UBS-2">
      <title>Biometric Sample Storage Limit</title>
      <prop name="label" class="index" value="3.2.3.4 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="UBS-2_smt" name="statement">
        <p>A limit on the allowable time for adaptation SHALL be established and enforced by the authenticator or the CSP.</p>
      </part>
      <part id="UBS-2_obj" name="objective">
        <p>Establish reasonable limits on adaptation time to limit persistence of biometric samples.</p>
        <link href="#UBS-2_smt" rel="assessment-for"/>
      </part>
      <part id="UBS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation to determine adaptation time limit.</p>
      </part>
      <part id="UBS-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to verify that biometric samples are erased at or before that time limit.</p>
      </part>
    </control>
    <control id="ATT-1">
      <title>Attestation Signature Requirements</title>
      <prop name="label" class="index" value="3.2.4 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ATT-1_smt" name="statement">
        <p>Attestations SHALL be signed using a digital signature that provides at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication).</p>
      </part>
      <part id="ATT-1_obj" name="objective">
        <p>Ensure that the key used to sign the attestation is of sufficient size to be secure.</p>
        <link href="#ATT-1_smt" rel="assessment-for"/>
      </part>
      <part id="ATT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine the security strength of the attestation key.</p>
      </part>
    </control>
    <control id="PHIRES-1">
      <title>Phishing Resistance Approved Algorithms</title>
      <prop name="label" class="index" value="3.2.5 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="PHIRES-1_smt" name="statement">
        <p>Approved cryptographic algorithms SHALL be used to establish phishing resistance where required.</p>
      </part>
      <part id="PHIRES-1_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms and protocols are being used.</p>
        <link href="#PHIRES-1_smt" rel="assessment-for"/>
      </part>
      <part id="PHIRES-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or code to determine that only approved cryptographic algorithms can be used.</p>
      </part>
    </control>
    <control id="PHIRES-2">
      <title>Phishing Resistance Key Strength</title>
      <prop name="label" class="index" value="3.2.5 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="PHIRES-2_smt" name="statement">
        <p>Keys used for phishing resistance SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication).</p>
      </part>
      <part id="PHIRES-2_obj" name="objective">
        <p>Ensure that the authentication key is of sufficient size to be secure.</p>
        <link href="#PHIRES-2_smt" rel="assessment-for"/>
      </part>
      <part id="PHIRES-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine the security strength of the authentication key.</p>
      </part>
    </control>
    <control id="PHIRES-3">
      <title>Phishing Resistance Manual Prohibition</title>
      <prop name="label" class="index" value="3.2.5 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="PHIRES-3_smt" name="statement">
        <p>Authenticators that involve the manual entry of an authenticator output (e.g., out-of-band and OTP authenticators) SHALL NOT be considered phishing-resistant because the manual entry does not bind the authenticator output to the specific session being authenticated.</p>
      </part>
      <part id="PHIRES-3_obj" name="objective">
        <p>Ensure that manual intervention, which can be socially engineered, is not part of phishing-resistant authentication.</p>
        <link href="#PHIRES-3_smt" rel="assessment-for"/>
      </part>
      <part id="PHIRES-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test available authentication methods to ensure that phishing -resistant authentication methods do not use manual entry.</p>
      </part>
    </control>
    <control id="CB-1">
      <title>Channel Binding Authenticated Protected Channel</title>
      <prop name="label" class="index" value="3.2.5.1 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="CB-1_smt" name="statement">
        <p>An authentication protocol with channel binding SHALL establish an authenticated protected channel with the verifier.</p>
      </part>
      <part id="CB-1_obj" name="objective">
        <p>Ensure that phishing-resistant authentication uses a secure channel that authenticates the verifier.</p>
        <link href="#CB-1_smt" rel="assessment-for"/>
      </part>
      <part id="CB-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by to verify that authenticated protected channel such as TLS is used.</p>
      </part>
    </control>
    <control id="CB-2">
      <title>Channel Binding Identifier</title>
      <prop name="label" class="index" value="3.2.5.1 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="CB-2_smt" name="statement">
        <p>The protocol SHALL then strongly and irreversibly bind a channel identifier negotiated in establishing the authenticated protected channel to the authenticator output (e.g., by signing the two values together using a private key controlled by the claimant for which the public key is known to the verifier).</p>
      </part>
      <part id="CB-2_obj" name="objective">
        <p>Ensure that the authentication protocol is bound to the communications channel.</p>
        <link href="#CB-2_smt" rel="assessment-for"/>
      </part>
      <part id="CB-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to determine if client-authenticated TLS is being used or analyze protocol to verify channel binding.</p>
      </part>
    </control>
    <control id="CB-3">
      <title>Channel Binding Validation</title>
      <prop name="label" class="index" value="3.2.5.1 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="CB-3_smt" name="statement">
        <p>The verifier SHALL validate the signature or other information used to prove phishing resistance.</p>
      </part>
      <part id="CB-3_obj" name="objective">
        <p>Ensure that authentication requires a valid signature.</p>
        <link href="#CB-3_smt" rel="assessment-for"/>
      </part>
      <part id="CB-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to verify that invalid signatures are not accepted.</p>
      </part>
    </control>
    <control id="VNB-1">
      <title>Name Binding Authenticated Protected Channel</title>
      <prop name="label" class="index" value="3.2.5.2 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="VNB-1_smt" name="statement">
        <p>An authentication protocol with verifier name binding SHALL establish an authenticated protected channel with the verifier.</p>
      </part>
      <part id="VNB-1_obj" name="objective">
        <p>Ensure that phishing-resistant authentication uses a secure channel that authenticates the verifier.</p>
        <link href="#VNB-1_smt" rel="assessment-for"/>
      </part>
      <part id="VNB-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by to verify that authenticated protected channel such as TLS is used.</p>
      </part>
    </control>
    <control id="VNB-2">
      <title>Name Binding Authenticated Verifier</title>
      <prop name="label" class="index" value="3.2.5.2 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="VNB-2_smt" name="statement">
        <p>The protocol SHALL generate an authenticator output that is cryptographically bound to a verifier identifier that is authenticated as part of the protocol.</p>
      </part>
      <part id="VNB-2_obj" name="objective">
        <p>Ensure that the authentication transaction can only succeed when connected to a specific host or domain.</p>
        <link href="#VNB-2_smt" rel="assessment-for"/>
      </part>
      <part id="VNB-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by simulating connection to a different host or domain and verify that the transaction does not succeed.</p>
      </part>
    </control>
    <control id="VNB-3">
      <title>Name Binding Hostname</title>
      <prop name="label" class="index" value="3.2.5.2 C"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="VNB-3_smt" name="statement">
        <p>In the case of DNS identifiers, the verifier identifier SHALL be either the authenticated hostname of the verifier or a parent domain that is at least one level below the public suffix [PSL] associated with that hostname.</p>
      </part>
      <part id="VNB-3_obj" name="objective">
        <p>Ensure the correct relationship between the transaction hostname and the bound verifier name.</p>
        <link href="#VNB-3_smt" rel="assessment-for"/>
      </part>
      <part id="VNB-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine code to determine that the correct comparison is made between the bound host/domain and the hostname of the authenticated protected channel.</p>
      </part>
    </control>
    <control id="VCIC-1">
      <title>Separate Verifier Mutually Authenticated Channel</title>
      <prop name="label" class="index" value="3.2.6 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="VCIC-1_smt" name="statement">
        <p>If the verifier and CSP or IdP are separate entities (as shown by the dotted line in Fig. 3 of [SP800-63]), communications between the verifier and CSP or IdP SHALL occur through a mutually authenticated protected channel (e.g., a client-authenticated TLS connection) using approved cryptography.</p>
      </part>
      <part id="VCIC-1_obj" name="objective">
        <p>Ensure a secure relationship between verifier and CSP/IdP.</p>
        <link href="#VCIC-1_smt" rel="assessment-for"/>
      </part>
      <part id="VCIC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine communications channel between verifier and CSP/IdP and verify that client-authenticated TLS or equivalent is used.</p>
      </part>
      <part id="VCIC-1_gdn" name="guidance">
        <p>Applies when verifier and CSP/IdP are separate entities.</p>
      </part>
    </control>
    <control id="AI-1">
      <title>Intent Requirement</title>
      <prop name="label" class="index" value="3.2.8 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AI-1_smt" name="statement">
        <p>The authenticator itself SHALL establish authentication intent.</p>
      </part>
      <part id="AI-1_obj" name="objective">
        <p>Ensure that authentication only occurs when intended by the claimant.</p>
        <link href="#AI-1_smt" rel="assessment-for"/>
      </part>
      <part id="AI-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test available authentication methods to ensure that all require some action on the part of the claimant.</p>
      </part>
    </control>
    <control id="AI-2">
      <title>Intent Explicit</title>
      <prop name="label" class="index" value="3.2.8 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AI-2_smt" name="statement">
        <p>In scenarios involving biometric authentication not requiring claimant action, an explicit mechanism (e.g., tapping a software or physical button) SHALL be provided to establish authentication intent.</p>
      </part>
      <part id="AI-2_obj" name="objective">
        <p>Ensure that "passive" biometric authentication is not sufficient to establish intent.</p>
        <link href="#AI-2_smt" rel="assessment-for"/>
      </part>
      <part id="AI-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test available authentication methods using biometrics to ensure that all require some action on the part of the claimant.</p>
      </part>
      <part id="AI-2_gdn" name="guidance">
        <p>Applies to authentication methods using biometric comparison.</p>
      </part>
    </control>
    <control id="RESTA-1">
      <title>Restricted Authenticator Risk Determination</title>
      <prop name="label" class="index" value="3.2.9 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RESTA-1_smt" name="statement">
        <p>If the RP determines that the risk to any party is unacceptable, the restricted authenticator SHALL NOT be used, and an alternative authenticator type SHALL be used.</p>
      </part>
      <part id="RESTA-1_obj" name="objective">
        <p>Ensure that restricted authenticators are not used in high-risk situations.</p>
        <link href="#RESTA-1_smt" rel="assessment-for"/>
      </part>
      <part id="RESTA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine risk assessment for evaluation and acceptability of risks.</p>
      </part>
    </control>
    <control id="RESTA-2">
      <title>Non-Restricted Authenticator Requirement</title>
      <prop name="label" class="index" value="3.2.9 B #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RESTA-2_smt" name="statement">
        <p>The CSP SHALL offer subscribers at least one alternative authenticator that is not restricted and can be used to authenticate at the required AAL.</p>
      </part>
      <part id="RESTA-2_obj" name="objective">
        <p>Ensure that alternative authentication methods not using restricted authenticators are provided.</p>
        <link href="#RESTA-2_smt" rel="assessment-for"/>
      </part>
      <part id="RESTA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine available authentication methods to verify that one or more non-restricted authenticators can be used.</p>
      </part>
    </control>
    <control id="RESTA-3">
      <title>Restricted Authenticator Risk Notice</title>
      <prop name="label" class="index" value="3.2.9 B #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RESTA-3_smt" name="statement">
        <p>The CSP SHALL provide subscribers with meaningful notice regarding the restricted authenticator's security risks and the availability of unrestricted alternatives.</p>
      </part>
      <part id="RESTA-3_obj" name="objective">
        <p>Ensure that subscribers are aware of the risks and alternatives.</p>
        <link href="#RESTA-3_smt" rel="assessment-for"/>
      </part>
      <part id="RESTA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine text displayed to subscriber when binding a restricted authenticator to make sure meaningful notice is displayed.</p>
      </part>
    </control>
    <control id="RESTA-4">
      <title>Restricted Authenticator Risk Documentation</title>
      <prop name="label" class="index" value="3.2.9 B #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RESTA-4_smt" name="statement">
        <p>The CSP SHALL address any additional risks to subscribers and RPs in its risk assessment.</p>
      </part>
      <part id="RESTA-4_obj" name="objective">
        <p>Ensure that risks are documented.</p>
        <link href="#RESTA-4_smt" rel="assessment-for"/>
      </part>
      <part id="RESTA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine risk assessment for documentation of any additional risks.</p>
      </part>
    </control>
    <control id="RESTA-5">
      <title>Restricted Authenticator Migration Plan</title>
      <prop name="label" class="index" value="3.2.9 B #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RESTA-5_smt" name="statement">
        <p>The CSP SHALL develop a migration plan for the possibility that the restricted authenticator will not be acceptable in the future and include this migration plan in its Digital Identity Acceptance Statement (see Sec. 3.4.4 of [SP800-63]).</p>
      </part>
      <part id="RESTA-5_obj" name="objective">
        <p>Plan for the likelihood that restricted authenticators will be non-compliant in the future.</p>
        <link href="#RESTA-5_smt" rel="assessment-for"/>
      </part>
      <part id="RESTA-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine migration plan to verify a plan for deprecation/removal of restricted authenticator.</p>
      </part>
    </control>
    <control id="AS-1">
      <title>Activation Secret Non-Transferable</title>
      <prop name="label" class="index" value="3.2.10 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-1_smt" name="statement">
        <p>In all cases, the activation secret SHALL remain within the authenticator and its associated user endpoint.</p>
      </part>
      <part id="AS-1_obj" name="objective">
        <p>Ensure that activation secret remains secure.</p>
        <link href="#AS-1_smt" rel="assessment-for"/>
      </part>
      <part id="AS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine protocol between authenticator or endpoint and verifier and confirm that activation secret is not transmitted.</p>
      </part>
    </control>
    <control id="AS-2">
      <title>Activation Secret Minimum Length</title>
      <prop name="label" class="index" value="3.2.10 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-2_smt" name="statement">
        <p>Authenticators that use activation secrets SHALL require the secrets to be at least four characters in length and SHOULD require the secrets to be at least six characters in length.</p>
      </part>
      <part id="AS-2_obj" name="objective">
        <p>Ensure that activation secret is not too easy to guess.</p>
        <link href="#AS-2_smt" rel="assessment-for"/>
      </part>
      <part id="AS-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to establish an activation secret that is three characters or less and verify that it is not accepted.</p>
      </part>
    </control>
    <control id="AS-3">
      <title>Activation Secret Retry Limit</title>
      <prop name="label" class="index" value="3.2.10 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-3_smt" name="statement">
        <p>The authenticator or verifier SHALL implement a retry-limiting mechanism that limits the number of consecutive failed activation attempts using the authenticator to no more than 10.</p>
      </part>
      <part id="AS-3_obj" name="objective">
        <p>Ensure that the verification process limits excessive retries that would indicate a brute force attack.</p>
        <link href="#AS-3_smt" rel="assessment-for"/>
      </part>
      <part id="AS-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by making more than 10 consecutive incorrect activation secret entries followed by a successful one and verify that authentication does not succeed.</p>
      </part>
    </control>
    <control id="AS-4">
      <title>Retry Limit Authenticator Implementation</title>
      <prop name="label" class="index" value="3.2.10 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-4_smt" name="statement">
        <p>Unless the authenticator generates an invalid output when an incorrect activation secret is provided, retry limiting SHALL be implemented in the authenticator.</p>
      </part>
      <part id="AS-4_obj" name="objective">
        <p>Ensure that it is not possible to do an offline activation attack by  observing the authenticator output.</p>
        <link href="#AS-4_smt" rel="assessment-for"/>
      </part>
      <part id="AS-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to activate the authenticator offline and ensure that it is locally throttled.</p>
      </part>
      <part id="AS-4_gdn" name="guidance">
        <p>Does not apply when the authenticator provides an output, but a wrong one, when an activation secret is provided.</p>
      </part>
    </control>
    <control id="AS-5">
      <title>Retry Limit Exceeded Disables</title>
      <prop name="label" class="index" value="3.2.10 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-5_smt" name="statement">
        <p>Once the limit of attempts is reached, the authenticator SHALL be disabled, and a different authenticator SHALL be required for authentication.</p>
      </part>
      <part id="AS-5_obj" name="objective">
        <p>Ensure that an authenticator that has reached its limit of activation attempts cannot be easily reactivated.</p>
        <link href="#AS-5_smt" rel="assessment-for"/>
      </part>
      <part id="AS-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures for use of an authenticator that has reached its activation attempts limit and verify that rebinding of the authenticator to the subscriber account is required.</p>
      </part>
    </control>
    <control id="AS-6">
      <title>AAL3 Hardware-Protected Authentication Secret Verification</title>
      <prop name="label" class="index" value="3.2.10 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-6_smt" name="statement">
        <p>For authenticators that are usable at AAL3, verification of activation secrets SHALL be performed in a hardware-protected environment (e.g., a secure element, TPM, or TEE).</p>
      </part>
      <part id="AS-6_obj" name="objective">
        <p>Ensure that authenticator protects activation secrets sufficiently for use at AAL3.</p>
        <link href="#AS-6_smt" rel="assessment-for"/>
      </part>
      <part id="AS-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation of authenticator to verify that activation secret verification is hardware-protected.</p>
      </part>
    </control>
    <control id="AS-7">
      <title>AAL2 Activation Secret Derivation</title>
      <prop name="label" class="index" value="3.2.10 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-7_smt" name="statement">
        <p>At AAL2, if a hardware-protected environment is not used, the authenticator SHALL use the activation secret to derive a key used to decrypt the authentication key.</p>
      </part>
      <part id="AS-7_obj" name="objective">
        <p>Ensure that the authentication key is protected by knowledge of the activation secret.</p>
        <link href="#AS-7_smt" rel="assessment-for"/>
      </part>
      <part id="AS-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine storage of the authentication key and verify it is the result of a decrypting the stored key with a key derived from the activation secret.</p>
      </part>
      <part id="AS-7_gdn" name="guidance">
        <p>Applies when authentication key is stored in a software protected environment.</p>
      </part>
    </control>
    <control id="AS-8">
      <title>Activation Secret Independence</title>
      <prop name="label" class="index" value="3.2.10 H"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="AS-8_smt" name="statement">
        <p>Submitting the activation factor SHALL be a separate operation from unlocking the host device (e.g., smartphone).</p>
      </part>
      <part id="AS-8_obj" name="objective">
        <p>Minimize opportunity for an attacker to authenticate on an already unlocked device.</p>
        <link href="#AS-8_smt" rel="assessment-for"/>
      </part>
      <part id="AS-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to authenticate on an already unlocked device and verify that a separate entry of the activation secret is required.</p>
      </part>
    </control>
    <control id="CONNAUTH-1">
      <title>Authenticator Connection Types</title>
      <prop name="label" class="index" value="3.2.11 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONNAUTH-1_smt" name="statement">
        <p>This connection SHALL be made using a wired connection (e.g., USB or direct connection with a smartcard), a wireless technology, or a hybrid of those technologies, including network connections.</p>
      </part>
      <part id="CONNAUTH-1_obj" name="objective">
        <p>Ensure that connection to the authenticator meets an accepted model.</p>
        <link href="#CONNAUTH-1_smt" rel="assessment-for"/>
      </part>
      <part id="CONNAUTH-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine ways that a connected authenticator can be used and verify that it meets one of the three models for connection.</p>
      </part>
    </control>
    <control id="CONNAUTH-2">
      <title>Connected Authenticator Approved Cryptography</title>
      <prop name="label" class="index" value="3.2.11 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONNAUTH-2_smt" name="statement">
        <p>Approved cryptography SHALL be used for all cases in which cryptographic operations are required.</p>
      </part>
      <part id="CONNAUTH-2_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms and protocols are being used.</p>
        <link href="#CONNAUTH-2_smt" rel="assessment-for"/>
      </part>
      <part id="CONNAUTH-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or code to determine that only approved cryptographic algorithms can be used.</p>
      </part>
    </control>
    <control id="CONNAUTH-3">
      <title>Connected Authenticator Authenticated Protected Channel</title>
      <prop name="label" class="index" value="3.2.11 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CONNAUTH-3_smt" name="statement">
        <p>All communication of authentication data between authenticators and endpoints SHALL occur directly between those devices or through an authenticated protected channel between the authenticator and endpoint.</p>
      </part>
      <part id="CONNAUTH-3_obj" name="objective">
        <p>Require secure communications between authenticator and endpoint.</p>
        <link href="#CONNAUTH-3_smt" rel="assessment-for"/>
      </part>
      <part id="CONNAUTH-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine protocol for any communications between authenticator and endpoint that may be indirect (through intermediaries).</p>
      </part>
      <part id="CONNAUTH-3_gdn" name="guidance">
        <p>Applies when communication between authenticator and endpoint is not point-to-point.</p>
      </part>
    </control>
    <control id="WC-1">
      <title>Wireless Authenticator Physical Proximity Requirement</title>
      <prop name="label" class="index" value="3.2.11.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-1_smt" name="statement">
        <p>To minimize the attack surface for threats to the authenticator-endpoint connection, the authentication process SHALL require physical proximity between the authenticator and endpoint by establishing a wireless connection with a range of no more than 240 meters.</p>
      </part>
      <part id="WC-1_obj" name="objective">
        <p>Limit opportunity for attack by remotely located attackers.</p>
        <link href="#WC-1_smt" rel="assessment-for"/>
      </part>
      <part id="WC-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authentication process with a remotely located authenticator and verify that it fails.</p>
      </part>
    </control>
    <control id="WC-2">
      <title>Wireless  Authenticator Key Establishment</title>
      <prop name="label" class="index" value="3.2.11.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-2_smt" name="statement">
        <p>Wireless connections SHALL establish a key for encrypted communication between the authenticator and endpoint in one of the following ways:</p>
        <p>(1) Through a temporary wired connection between the devices.</p>
        <p>(2) Through an association process that is similar to a pairing process but does not require a persistent relationship between devices to establish a key for encrypted communication between the authenticator and endpoint.</p>
      </part>
      <part id="WC-2_obj" name="objective">
        <p>Define acceptable methods for associating authenticator and endpoint.</p>
        <link href="#WC-2_smt" rel="assessment-for"/>
      </part>
      <part id="WC-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test key establishment between endpoint and authenticator and verify that it is done in an acceptable way.</p>
      </part>
    </control>
    <control id="WC-2.1">
      <title>Wireless Authenticator Pairing Code</title>
      <prop name="label" class="index" value="3.2.11.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-2.1_smt" name="statement">
        <p>If an association process is used, it SHALL employ a pairing code or other shared secret between the devices.</p>
      </part>
      <part id="WC-2.1_obj" name="objective">
        <p>Require use of a shared secret to identify the parties to the association.</p>
        <link href="#WC-2.1_smt" rel="assessment-for"/>
      </part>
      <part id="WC-2.1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test association process and verify that a pairing code or shared secret is required.</p>
      </part>
      <part id="WC-2.1_gdn" name="guidance">
        <p>Applies when an association process is used instead of a temporary wired connection.</p>
      </part>
    </control>
    <control id="WC-2.2">
      <title>Wireless Authenticator Pairing Code Length</title>
      <prop name="label" class="index" value="3.2.11.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-2.2_smt" name="statement">
        <p>If an association process is used, either the authenticator or endpoint SHALL have a pairing code that is at least six decimal digits (or equivalent) in length that MAY be printed on the device.</p>
      </part>
      <part id="WC-2.2_obj" name="objective">
        <p>Require that the pairing code be long enough to provide appropriate security.</p>
        <link href="#WC-2.2_smt" rel="assessment-for"/>
      </part>
      <part id="WC-2.2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test association process and verify that the pairing code or shared secret is long enough.</p>
      </part>
      <part id="WC-2.2_gdn" name="guidance">
        <p>Applies when an association process is used instead of a temporary wired connection.</p>
      </part>
    </control>
    <control id="WC-2.3">
      <title>Wireless Authenticator Association Methods</title>
      <prop name="label" class="index" value="3.2.11.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-2.3_smt" name="statement">
        <p>If an association process is used, the pairing code SHALL be conveyed between the devices by manual entry or using a QR code or similar representation that is optically communicated.</p>
      </part>
      <part id="WC-2.3_obj" name="objective">
        <p>Allow use of manual or optically-assisted entry of pairing code.</p>
        <link href="#WC-2.3_smt" rel="assessment-for"/>
      </part>
      <part id="WC-2.3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test association process to verify that the pairing code is manually entered or optically communicated.</p>
      </part>
      <part id="WC-2.3_gdn" name="guidance">
        <p>Applies when an association process is used instead of a temporary wired connection.</p>
      </part>
    </control>
    <control id="WC-3">
      <title>Wireless Authenticator Proximate Activation Secret</title>
      <prop name="label" class="index" value="3.2.11.2 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-3_smt" name="statement">
        <p>When using a wireless technology with an effective range of less than 1 meter (e.g., NFC), any activation secret transmitted from the endpoint to the authenticator SHALL be encrypted using a key that is established between the devices.</p>
      </part>
      <part id="WC-3_obj" name="objective">
        <p>Ensure secure transmission of the activation secret from the endpoint to the authenticator.</p>
        <link href="#WC-3_smt" rel="assessment-for"/>
      </part>
      <part id="WC-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that transmission of the activation secret is encrypted using a key established between the devices.</p>
      </part>
      <part id="WC-3_gdn" name="guidance">
        <p>Applies when very short range (&lt;1 m) wireless technologies are used.</p>
      </part>
    </control>
    <control id="WC-4">
      <title>Wireless Authenticator Pairing Code Use</title>
      <prop name="label" class="index" value="3.2.11.2 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-4_smt" name="statement">
        <p>A pairing code SHALL be used if the authenticator is configured to require authenticated pairing.</p>
      </part>
      <part id="WC-4_obj" name="objective">
        <p>Use pairing processes appropriate for the authenticator.</p>
        <link href="#WC-4_smt" rel="assessment-for"/>
      </part>
      <part id="WC-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to verify that a pairing code is used when authenticated pairing is required.</p>
      </part>
      <part id="WC-4_gdn" name="guidance">
        <p>Applies when authenticator uses authenticated pairing.</p>
      </part>
    </control>
    <control id="WC-5">
      <title>Wireless Authenticator Non-Proximate Authenticated Protected Channel</title>
      <prop name="label" class="index" value="3.2.11.2 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-5_smt" name="statement">
        <p>Network connections and wireless technologies with an effective range of 1 meter or more (e.g., Bluetooth Low Energy [BLE]) SHALL use an authenticated protected channel between the authenticator and endpoint.</p>
      </part>
      <part id="WC-5_obj" name="objective">
        <p>Require stronger protections for wireless connections with longer range.</p>
        <link href="#WC-5_smt" rel="assessment-for"/>
      </part>
      <part id="WC-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that an authenticated protected channel such as TLS is used.</p>
      </part>
      <part id="WC-5_gdn" name="guidance">
        <p>Applies when longer range (&gt;=1 m) wireless technologies are used.</p>
      </part>
    </control>
    <control id="WC-6">
      <title>Wireless Authenticator Encryption</title>
      <prop name="label" class="index" value="3.2.11.2 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-6_smt" name="statement">
        <p>The entire authentication transaction SHALL be encrypted.</p>
      </part>
      <part id="WC-6_obj" name="objective">
        <p>Protect authentication transaction in transit between devices.</p>
        <link href="#WC-6_smt" rel="assessment-for"/>
      </part>
      <part id="WC-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that the entire transaction is authenticated.</p>
      </part>
    </control>
    <control id="WC-7">
      <title>Wireless Authenticator Persistent Key Removal</title>
      <prop name="label" class="index" value="3.2.11.2 H"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WC-7_smt" name="statement">
        <p>A mechanism for endpoints to remove persistent keys SHALL be provided.</p>
      </part>
      <part id="WC-7_obj" name="objective">
        <p>Require removal of associations between authenticator and endpoint when no longer needed.</p>
        <link href="#WC-7_smt" rel="assessment-for"/>
      </part>
      <part id="WC-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authenticator and/or endpoint to verify that a mechanism to remove persistent keys exists.</p>
      </part>
    </control>
    <control id="HYBC-1">
      <title>Hybrid Connection Establishment</title>
      <prop name="label" class="index" value="3.2.11.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="HYBC-1_smt" name="statement">
        <p>Hybrid connections (e.g., hybrid transports specified by the CTAP2.2 protocol) SHALL be established between authenticators and endpoints in one of the following ways:</p>
        <p>(1) By communicating initial keying information and the identity of the tunnel service to be used via a displayed QR code or similar visual representation coupled with the receipt by the endpoint of wireless data containing the additional information required to establish the tunnel connection.</p>
        <p>(2) Through cached keying and tunnel information retained by the authenticator and endpoint from a previous authentication transaction.</p>
      </part>
      <part id="HYBC-1_obj" name="objective">
        <p>Require hybrid connections to be established securely or to be based on cached information.</p>
        <link href="#HYBC-1_smt" rel="assessment-for"/>
      </part>
      <part id="HYBC-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test establishment of hybrid connections between authenticators and endpoints to verify that they are established in one of the permitted methods.</p>
      </part>
    </control>
    <control id="HYBC-1.1">
      <title>Hybrid Connection Proximity</title>
      <prop name="label" class="index" value="3.2.11.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="HYBC-1.1_smt" name="statement">
        <p>The wireless data SHALL be conveyed over a technology with a maximum effective range of no more than 240 meters.</p>
      </part>
      <part id="HYBC-1.1_obj" name="objective">
        <p>Limit opportunity for attack by remotely located attackers.</p>
        <link href="#HYBC-1.1_smt" rel="assessment-for"/>
      </part>
      <part id="HYBC-1.1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authentication process with a remotely located authenticator and verify that it fails.</p>
      </part>
      <part id="HYBC-1.1_gdn" name="guidance">
        <p>Applies when initial keying information is being established.</p>
      </part>
    </control>
    <control id="HYBC-2">
      <title>Hybrid Connection Association Removal</title>
      <prop name="label" class="index" value="3.2.11.3 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="HYBC-2_smt" name="statement">
        <p>A mechanism for endpoints to remove cached associations with authenticators SHALL be provided.</p>
      </part>
      <part id="HYBC-2_obj" name="objective">
        <p>Require removal of associations between authenticator and endpoint when no longer needed.</p>
        <link href="#HYBC-2_smt" rel="assessment-for"/>
      </part>
      <part id="HYBC-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test authenticator and/or endpoint to verify that a mechanism to remove persistent keys exists.</p>
      </part>
    </control>
    <control id="RANV-1">
      <title>Random Value Generation Requirements</title>
      <prop name="label" class="index" value="3.2.12 A"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RANV-1_smt" name="statement">
        <p>Unless otherwise specified, random values that reference this section SHALL be generated by an approved random bit generator that provides at least the minimum security strength specified in the latest revision of SP800-131A (i.e., 112 bits as of the date of this publication).</p>
      </part>
      <part id="RANV-1_obj" name="objective">
        <p>Require use of sufficiently secure random values.</p>
        <link href="#RANV-1_smt" rel="assessment-for"/>
      </part>
      <part id="RANV-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation of random bit generator to verify that it meets SP 800-131A requirements.</p>
      </part>
    </control>
    <control id="EXPO-1">
      <title>Non-Exportability Hardware Requirements</title>
      <prop name="label" class="index" value="3.2.13 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL1/AAL2"/>
      <part id="EXPO-1_smt" name="statement">
        <p>To be considered non-exportable, an authenticator SHALL either be a separate piece of hardware or an embedded processor or execution environment (e.g., secure element, TEE, TPM).</p>
      </part>
      <part id="EXPO-1_obj" name="objective">
        <p>Require that non-exportable keys not be directly accessible to the endpoint.</p>
        <link href="#EXPO-1_smt" rel="assessment-for"/>
      </part>
      <part id="EXPO-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation, including APIs, to ensure that authentication keys are not sent or accessible outside the authenticator.</p>
      </part>
    </control>
    <control id="EXPO-2">
      <title>Non-Exportable Authentication Key Protection</title>
      <prop name="label" class="index" value="3.2.13 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL1/AAL2"/>
      <part id="EXPO-2_smt" name="statement">
        <p>A non-exportable authenticator SHALL be designed to prohibit the export of the authentication secret to the host processor and SHALL NOT be capable of being reprogrammed by the host processor to allow the secret to be extracted.</p>
      </part>
      <part id="EXPO-2_obj" name="objective">
        <p>Ensure that reprogramming of the secure environment is not possible as a back door to obtain access to authentication secrets.</p>
        <link href="#EXPO-2_smt" rel="assessment-for"/>
      </part>
      <part id="EXPO-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine APIs between the endpoint and authenticator to verify that it is not possible for the endpoint to reprogram the authenticator.</p>
      </part>
    </control>
    <control id="AUTHB-1">
      <title>Authenticator Binding Requirements</title>
      <prop name="label" class="index" value="4.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUTHB-1_smt" name="statement">
        <p>Authenticators SHALL be bound to subscriber accounts by either: being issued by the CSP as part of enrollment; or using a subscriber-provided authenticator that is acceptable to the CSP.</p>
      </part>
      <part id="AUTHB-1_obj" name="objective">
        <p>Allow CSP to verify that all authenticators bound to subscriber accounts meet their requirements.</p>
        <link href="#AUTHB-1_smt" rel="assessment-for"/>
      </part>
      <part id="AUTHB-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures for binding authenticators and verify that they provide an opportunity for the CSP to verify the authenticator's security.</p>
      </part>
    </control>
    <control id="AUTHB-2">
      <title>Authenticator Record-Keeping</title>
      <prop name="label" class="index" value="4.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUTHB-2_smt" name="statement">
        <p>Throughout the lifetime of a digital identity, CSPs SHALL maintain a record of all authenticators that are bound to each subscriber account.</p>
      </part>
      <part id="AUTHB-2_obj" name="objective">
        <p>Maintain the ability to audit authenticators that are or have been bound to subscriber accounts.</p>
        <link href="#AUTHB-2_smt" rel="assessment-for"/>
      </part>
      <part id="AUTHB-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP records to verify that records of current and past bound authenticators are maintained.</p>
      </part>
    </control>
    <control id="AUTHB-3">
      <title>CSP Authenticator Characteristics Determination</title>
      <prop name="label" class="index" value="4.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUTHB-3_smt" name="statement">
        <p>The CSP SHALL determine the characteristics of the authenticator being bound (e.g., single-factor versus multifactor, phishing-resistant or not) so that verifiers can assess compliance with the requirements at each AAL.</p>
      </part>
      <part id="AUTHB-3_obj" name="objective">
        <p>Ensure that authenticators bound to subscriber accounts meet requirements for the AALs at which they will be used.</p>
        <link href="#AUTHB-3_smt" rel="assessment-for"/>
      </part>
      <part id="AUTHB-3_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview CSP to determine the sufficiency of procedures for approving authenticators.</p>
      </part>
    </control>
    <control id="AUTHB-4">
      <title>CSP Authenticator State Storage</title>
      <prop name="label" class="index" value="4.1 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUTHB-4_smt" name="statement">
        <p>The CSP SHALL also maintain other state information that is required to meet the authenticator verification requirements.</p>
      </part>
      <part id="AUTHB-4_obj" name="objective">
        <p>Ensure that the CSP is equipped to maintain other state information such as that required for throttling.</p>
        <link href="#AUTHB-4_smt" rel="assessment-for"/>
      </part>
      <part id="AUTHB-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP records to verify that required state information is maintained.</p>
      </part>
    </control>
    <control id="AUTHB-5">
      <title>CSP Authenticator Lifecycle Logging</title>
      <prop name="label" class="index" value="4.1 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUTHB-5_smt" name="statement">
        <p>The record created by the CSP SHALL contain the date and time of significant authenticator life cycle events (e.g., binding to the subscriber account, renewal, update, expiration).</p>
      </part>
      <part id="AUTHB-5_obj" name="objective">
        <p>Maintain the ability to audit authenticator life cycle events.</p>
        <link href="#AUTHB-5_smt" rel="assessment-for"/>
      </part>
      <part id="AUTHB-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP records to verify that authenticator life cycle events are documented.</p>
      </part>
    </control>
    <control id="BAA-1">
      <title>Multiple Authenticator Binding</title>
      <prop name="label" class="index" value="4.1.2.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BAA-1_smt" name="statement">
        <p>Accordingly, CSPs SHALL permit the binding of multiple authenticators to a subscriber account.</p>
      </part>
      <part id="BAA-1_obj" name="objective">
        <p>Allow subscribers to bind multiple authenticators to guard against loss or failure of a given authenticator.</p>
        <link href="#BAA-1_smt" rel="assessment-for"/>
      </part>
      <part id="BAA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to bind multiple authenticators and verify that it is successful.</p>
      </part>
    </control>
    <control id="BAA-2">
      <title>Binding Authentication Requirement</title>
      <prop name="label" class="index" value="4.1.2.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BAA-2_smt" name="statement">
        <p>When any new authenticator is bound to a subscriber account, the CSP SHALL ensure that the process requires authentication at either the maximum AAL currently available in the subscriber account or the maximum AAL at which the new authenticator will be used, whichever is lower.</p>
      </part>
      <part id="BAA-2_obj" name="objective">
        <p>Ensure that it is not possible to increase authenticated AAL by binding a new authenticator.</p>
        <link href="#BAA-2_smt" rel="assessment-for"/>
      </part>
      <part id="BAA-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by binding a new authenticator for use at AAL2 or AAL3 and verify that it requires authentication at the corresponding AAL.</p>
      </part>
    </control>
    <control id="BAA-3">
      <title>Binding Notification Requirement</title>
      <prop name="label" class="index" value="4.1.2.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BAA-3_smt" name="statement">
        <p>When an authenticator is added, the CSP SHALL notify the subscriber via a mechanism independent of the transaction binding the new authenticator, as described in Sec. 4.6.</p>
      </part>
      <part id="BAA-3_obj" name="objective">
        <p>Warn subscriber in case an authenticator is bound without their knowledge.</p>
        <link href="#BAA-3_smt" rel="assessment-for"/>
      </part>
      <part id="BAA-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by binding an additional authenticator and verify that the subscriber receives a notification as described.</p>
      </part>
    </control>
    <control id="BINAE-1">
      <title>External Authenticator Binding</title>
      <prop name="label" class="index" value="4.1.2.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-1_smt" name="statement">
        <p>The binding process SHALL proceed in one of the following ways:</p>
        <p>(1) An endpoint that has authenticated to the CSP requests a binding code from the CSP. The binding code is input into the endpoint associated with the new authenticator and sent to the CSP.</p>
        <p>(2) The endpoint associated with the new authenticator obtains a binding code from the CSP. The binding code is input to an authenticated endpoint and sent to the CSP.</p>
      </part>
      <part id="BINAE-1_obj" name="objective">
        <p>Ensure that the binding of authenticators not directly connected to an authenticated session uses a secure process.</p>
        <link href="#BINAE-1_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by binding an authenticator that is not connected to the authenticated endpoint, and ensure that it uses one of the described processes.</p>
      </part>
    </control>
    <control id="BINAE-2">
      <title>External Authenticator Authenticated Protected Channel</title>
      <prop name="label" class="index" value="4.1.2.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-2_smt" name="statement">
        <p>When binding an external authenticator, an authenticated protected channel SHALL be established by the endpoint associated with the new authenticator and the CSP.</p>
      </part>
      <part id="BINAE-2_obj" name="objective">
        <p>Ensure that channel between authenticator and endpoint are protected against eavesdropping and intermediaries.</p>
        <link href="#BINAE-2_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that an authenticated protected channel such as TLS is used.</p>
      </part>
    </control>
    <control id="BINAE-3">
      <title>External Authenticator Binding Code</title>
      <prop name="label" class="index" value="4.1.2.2 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-3_smt" name="statement">
        <p>When binding an external authenticator, the CSP SHALL generate a binding code using an approved random bit generator as described in Sec. 3.2.12 and send it to either the new authenticator endpoint or the authenticated endpoint approving the binding.</p>
      </part>
      <part id="BINAE-3_obj" name="objective">
        <p>Ensure that a sufficiently random binding code is used and transmitted to the endpoint or authenticator.</p>
        <link href="#BINAE-3_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to see how the binding code is generated.</p>
      </part>
    </control>
    <control id="BINAE-4">
      <title>External Authenticator Identifier Binding Code Length</title>
      <prop name="label" class="index" value="4.1.2.2 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-4_smt" name="statement">
        <p>The binding code SHALL be at least 40 bits in length if it is used with an identifier entered by the subscriber on the new authenticator.</p>
      </part>
      <part id="BINAE-4_obj" name="objective">
        <p>Ensure that the binding code is sufficiently large to provide the required level of security.</p>
        <link href="#BINAE-4_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by binding an external authenticator and verify that the binding code is sufficiently long.</p>
      </part>
      <part id="BINAE-4_gdn" name="guidance">
        <p>Applies when an identifier is entered by the subscriber on the new authenticator.</p>
      </part>
    </control>
    <control id="BINAE-5">
      <title>External Authenticator Non-Identifier Binding Code Length</title>
      <prop name="label" class="index" value="4.1.2.2 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-5_smt" name="statement">
        <p>The binding code SHALL be at least 112 bits in length if it is not used with an identifier entered by the subscriber on the new authenticator.</p>
      </part>
      <part id="BINAE-5_obj" name="objective">
        <p>Ensure that the binding code is sufficiently large to provide the required level of security.</p>
        <link href="#BINAE-5_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by binding an external authenticator and verify that the binding code is sufficiently long.</p>
      </part>
      <part id="BINAE-5_gdn" name="guidance">
        <p>Applies when no identifier is entered by the subscriber on the new authenticator.</p>
      </part>
    </control>
    <control id="BINAE-6">
      <title>External Authenticator Association Methods</title>
      <prop name="label" class="index" value="4.1.2.2 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-6_smt" name="statement">
        <p>When binding an external authenticator, the subscriber SHALL transfer the binding code to the other endpoint manually or via a local out-of-band method such as a QR code.</p>
      </part>
      <part id="BINAE-6_obj" name="objective">
        <p>Ensure that the binding code is transferred through action by the subscriber.</p>
        <link href="#BINAE-6_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test all supported methods for binding an external authenticator and verify that manual or local out-of-band action is required.</p>
      </part>
    </control>
    <control id="BINAE-7">
      <title>External Authenticator Binding Code Security</title>
      <prop name="label" class="index" value="4.1.2.2 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-7_smt" name="statement">
        <p>The binding code SHALL NOT be communicated over an insecure channel.</p>
      </part>
      <part id="BINAE-7_obj" name="objective">
        <p>Ensure that the binding code is not available to an attacker.</p>
        <link href="#BINAE-7_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test all supported methods for binding an external authenticator and verify that no insecure channels are used.</p>
      </part>
    </control>
    <control id="BINAE-8">
      <title>External Authenticator Binding Code Replay</title>
      <prop name="label" class="index" value="4.1.2.2 H"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-8_smt" name="statement">
        <p>When binding an external authenticator, the binding code SHALL be usable only once.</p>
      </part>
      <part id="BINAE-8_obj" name="objective">
        <p>Guard against replay of the binding code.</p>
        <link href="#BINAE-8_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to use the same binding code more than once and verify that it fails.</p>
      </part>
    </control>
    <control id="BINAE-9">
      <title>External Authenticator Binding Code Lifetime</title>
      <prop name="label" class="index" value="4.1.2.2 I"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-9_smt" name="statement">
        <p>The binding code SHALL be valid for a maximum of 10 minutes.</p>
      </part>
      <part id="BINAE-9_obj" name="objective">
        <p>Limit usability of a binding code that may have been part of an incomplete binding transaction.</p>
        <link href="#BINAE-9_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to bind an external authenticator while delaying transfer of the binding code for more than 10 minutes, and verify that it fails.</p>
      </part>
    </control>
    <control id="BINAE-10">
      <title>External Authenticator Binding Instructions</title>
      <prop name="label" class="index" value="4.1.2.2 J"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BINAE-10_smt" name="statement">
        <p>The CSP SHALL provide clear instructions on what the subscriber should do in the event of an authenticator binding mishap.</p>
      </part>
      <part id="BINAE-10_obj" name="objective">
        <p>Provide recourse for binding transactions that do not occur normally.</p>
        <link href="#BINAE-10_smt" rel="assessment-for"/>
      </part>
      <part id="BINAE-10_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to bind an external authenticator and verify that suitable guidance to the subscriber is provided.</p>
      </part>
    </control>
    <control id="BSPA-1">
      <title>Subscriber Provided Authenticator Procedure</title>
      <prop name="label" class="index" value="4.1.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BSPA-1_smt" name="statement">
        <p>The binding of subscriber-provided authenticators SHALL be done as described in Sec. 4.1.2.</p>
      </part>
      <part id="BSPA-1_obj" name="objective">
        <p>Ensure that subscriber-provided authenticators are bound in a secure manner.</p>
        <link href="#BSPA-1_smt" rel="assessment-for"/>
      </part>
      <part id="BSPA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures for binding subscriber-controlled authenticators and verify that they meet BAA-1 through BAA-3 and BINAE-1 through BINAE-9 as applicable.</p>
      </part>
    </control>
    <control id="BSPA-2">
      <title>Authenticator Type Documentation</title>
      <prop name="label" class="index" value="4.1.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BSPA-2_smt" name="statement">
        <p>The types of authenticators accepted by the CSP SHALL be documented in the CSP practice statement.</p>
      </part>
      <part id="BSPA-2_obj" name="objective">
        <p>Make sure clear guidelines for subscriber acceptability are published.</p>
        <link href="#BSPA-2_smt" rel="assessment-for"/>
      </part>
      <part id="BSPA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP practice statement to verify that acceptable types of subscriber-provided authenticators are documented.</p>
      </part>
    </control>
    <control id="ARM-1">
      <title>Account Recovery Requirement</title>
      <prop name="label" class="index" value="4.2.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARM-1_smt" name="statement">
        <p>CSPs SHALL support one or more of the four account recovery mechanisms described.</p>
      </part>
      <part id="ARM-1_obj" name="objective">
        <p>Ensure that secure account recovery mechanisms are provided.</p>
        <link href="#ARM-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARM-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine available recovery procedures to verify that at least one of the described account recovery mechanisms is supported.</p>
      </part>
    </control>
    <control id="ARM-2">
      <title>Account Recovery Alternatives</title>
      <prop name="label" class="index" value="4.2.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARM-2_smt" name="statement">
        <p>The use of alternative methods SHALL be based on a risk analysis and documented by the CSP.</p>
      </part>
      <part id="ARM-2_obj" name="objective">
        <p>Require that alternative recovery mechanisms by documented and accompanied by a valid risk analysis.</p>
        <link href="#ARM-2_smt" rel="assessment-for"/>
      </part>
      <part id="ARM-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine risk analysis for any alternative account recovery mechanisms that are supported.</p>
      </part>
    </control>
    <control id="SRC-1">
      <title>Saved Recovery Code Generation</title>
      <prop name="label" class="index" value="4.2.1.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SRC-1_smt" name="statement">
        <p>The recovery code SHALL include at least 64 bits from an approved random bit generator.</p>
      </part>
      <part id="SRC-1_obj" name="objective">
        <p>Ensure that a sufficiently random recovery code is used.</p>
        <link href="#SRC-1_smt" rel="assessment-for"/>
      </part>
      <part id="SRC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to see how the recovery code is generated.</p>
      </part>
    </control>
    <control id="SRC-2">
      <title>Saved Recovery Code Issuance Notification</title>
      <prop name="label" class="index" value="4.2.1.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SRC-2_smt" name="statement">
        <p>The issuance of a replacement recovery code SHALL result in an account recovery notification, as described in Sec. 4.6.</p>
      </part>
      <part id="SRC-2_obj" name="objective">
        <p>Confirm that subscriber is notified of account recovery events.</p>
        <link href="#SRC-2_smt" rel="assessment-for"/>
      </part>
      <part id="SRC-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by performing a recovery using a saved recovery code and verify that the subscriber is notified in one of the ways described.</p>
      </part>
    </control>
    <control id="SRC-3">
      <title>Saved Recovery Code Rate Limitation</title>
      <prop name="label" class="index" value="4.2.1.1 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SRC-3_smt" name="statement">
        <p>The verification of saved recovery codes SHALL be subject to the throttling requirements in Sec. 3.2.2.</p>
      </part>
      <part id="SRC-3_obj" name="objective">
        <p>Limit ability to guess recovery codes.</p>
        <link href="#SRC-3_smt" rel="assessment-for"/>
      </part>
      <part id="SRC-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by performing a recovery using a number of invalid recovery codes followed by a correct code and confirm that throttling has occurred.</p>
      </part>
    </control>
    <control id="SRC-4">
      <title>Saved Recovery Code Storage</title>
      <prop name="label" class="index" value="4.2.1.1 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SRC-4_smt" name="statement">
        <p>Saved recovery codes SHALL be stored in the subscriber account in hashed form using an approved one-way function, as described in Sec. 3.1.1.2.</p>
      </part>
      <part id="SRC-4_obj" name="objective">
        <p>At a minimum, require salting and hashing of recovery codes as protection against offline attacks should the verifier be breached.</p>
        <link href="#SRC-4_smt" rel="assessment-for"/>
      </part>
      <part id="SRC-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine recovery code verification storage to determine evidence of  hashing.</p>
      </part>
    </control>
    <control id="SRC-5">
      <title>Saved Recovery Code Replay</title>
      <prop name="label" class="index" value="4.2.1.1 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SRC-5_smt" name="statement">
        <p>Following the use of a saved recovery code, the CSP SHALL invalidate that recovery code and SHALL issue a new saved recovery code to the subscriber.</p>
      </part>
      <part id="SRC-5_obj" name="objective">
        <p>Prevent replay of recovery codes.</p>
        <link href="#SRC-5_smt" rel="assessment-for"/>
      </part>
      <part id="SRC-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting a second recovery using a saved recovery code and verify that it is unsuccessful.</p>
      </part>
    </control>
    <control id="IRC-1">
      <title>Issued Recovery Code Generation</title>
      <prop name="label" class="index" value="4.2.1.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IRC-1_smt" name="statement">
        <p>The issued recovery code SHALL include at least six decimal digits (or equivalent) from an approved random bit generator, as described in Sec. 3.2.12.</p>
      </part>
      <part id="IRC-1_obj" name="objective">
        <p>Ensure that a sufficiently random recovery code is used.</p>
        <link href="#IRC-1_smt" rel="assessment-for"/>
      </part>
      <part id="IRC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to see how the recovery code is generated.</p>
      </part>
    </control>
    <control id="IRC-2">
      <title>Issued Recovery Code Validity</title>
      <prop name="label" class="index" value="4.2.1.2 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IRC-2_smt" name="statement">
        <p>Issued recovery codes SHALL be valid for at most:</p>
        <p>(a) 21 days when sent to a postal address within the contiguous United States.</p>
        <p>(b) 30 days when sent to a postal address outside of the contiguous United States.</p>
        <p>(c) 10 minutes when sent via text message or voice.</p>
        <p>(d) 24 hours when sent to an email address.</p>
      </part>
      <part id="IRC-2_obj" name="objective">
        <p>Limit lifetimes of issued recovery codes based on expected delivery times.</p>
        <link href="#IRC-2_smt" rel="assessment-for"/>
      </part>
      <part id="IRC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine methods for issued recovery code delivery and verify that implementation limits their validity to within the specified timeframes.</p>
      </part>
    </control>
    <control id="IRC-3">
      <title>Issued Recovery Code Rate Limitation</title>
      <prop name="label" class="index" value="4.2.1.2 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IRC-3_smt" name="statement">
        <p>The verification of issued recovery codes SHALL be subject to the throttling requirements in Sec. 3.2.2.</p>
      </part>
      <part id="IRC-3_obj" name="objective">
        <p>Limit ability to guess recovery codes.</p>
        <link href="#IRC-3_smt" rel="assessment-for"/>
      </part>
      <part id="IRC-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by performing a recovery using a number of invalid recovery codes followed by a correct code and confirm that throttling has occurred.</p>
      </part>
    </control>
    <control id="IRC-4">
      <title>Issued Recovery Code Address Verification</title>
      <prop name="label" class="index" value="4.2.1.2 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IRC-4_smt" name="statement">
        <p>When establishing recovery addresses other than those validated or verified as part of the identity proofing process, the address SHALL be verified.</p>
      </part>
      <part id="IRC-4_obj" name="objective">
        <p>Confirm reliability of recovery addresses.</p>
        <link href="#IRC-4_smt" rel="assessment-for"/>
      </part>
      <part id="IRC-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine metadata associated with recovery addresses and verify that a confirmation flag is present and is required in order to be used for recovery.</p>
      </part>
    </control>
    <control id="IRC-5">
      <title>Issued Recovery Code Address Verification Procedure</title>
      <prop name="label" class="index" value="4.2.1.2 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IRC-5_smt" name="statement">
        <p>To verify an address, the CSP SHALL send a confirmation code with the same characteristics as a recovery code to the newly established recovery address and require that the subscriber return the same confirmation code to the CSP.</p>
      </part>
      <part id="IRC-5_obj" name="objective">
        <p>Specify procedure for address confirmation.</p>
        <link href="#IRC-5_smt" rel="assessment-for"/>
      </part>
      <part id="IRC-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by establishing a new recovery address and verify that it is only usable for recovery after having been confirmed.</p>
      </part>
    </control>
    <control id="IRC-6">
      <title>Issued Recovery Code Multiple Address Requirement</title>
      <prop name="label" class="index" value="4.2.1.2 H"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IRC-6_smt" name="statement">
        <p>CSPs SHALL allow the subscriber to establish at least two recovery addresses.</p>
      </part>
      <part id="IRC-6_obj" name="objective">
        <p>Provide backup in case subscriber loses control of a recovery address.</p>
        <link href="#IRC-6_smt" rel="assessment-for"/>
      </part>
      <part id="IRC-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by verifying that it is possible to establish more than one recovery address.</p>
      </part>
    </control>
    <control id="RECC-1">
      <title>Recovery Contact Addresses</title>
      <prop name="label" class="index" value="4.2.1.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RECC-1_smt" name="statement">
        <p>CSPs that support the use of recovery contacts SHALL allow the subscriber to specify one or more addresses of trusted associates to receive issued recovery codes.</p>
      </part>
      <part id="RECC-1_obj" name="objective">
        <p>Define recovery contacts mechanism.</p>
        <link href="#RECC-1_smt" rel="assessment-for"/>
      </part>
      <part id="RECC-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by establishing a recovery contact and performing account recovery to verify that associate received recovery code and instructions on what to do with it.</p>
      </part>
    </control>
    <control id="RECC-2">
      <title>Recovery Contact Management</title>
      <prop name="label" class="index" value="4.2.1.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RECC-2_smt" name="statement">
        <p>If the CSP supports the use of recovery contacts, the CSP SHALL provide methods for subscribers to view and manage recovery contacts.</p>
      </part>
      <part id="RECC-2_obj" name="objective">
        <p>Allow subscriber to manage recovery contacts (e.g., to change them).</p>
        <link href="#RECC-2_smt" rel="assessment-for"/>
      </part>
      <part id="RECC-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by changing and deleting recovery contacts and verify that it is possible to do so.</p>
      </part>
    </control>
    <control id="RIP-1">
      <title>Repeated Proofing Account Recovery</title>
      <prop name="label" class="index" value="4.2.1.4 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RIP-1_smt" name="statement">
        <p>The CSP SHALL repeat the necessary steps of identity proofing consistent with the level of initial identity proofing and SHALL confirm that the claimant's identity is consistent with the previously established account.</p>
      </part>
      <part id="RIP-1_obj" name="objective">
        <p>Define requirements for recovery via repeated identity proofing.</p>
        <link href="#RIP-1_smt" rel="assessment-for"/>
      </part>
      <part id="RIP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures for recovery via identity proofing to verify their usability and security.</p>
      </part>
    </control>
    <control id="RWIP-1">
      <title>Non-Proofing Recovery</title>
      <prop name="label" class="index" value="4.2.2.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL1"/>
      <part id="RWIP-1_smt" name="statement">
        <p>The recovery of such subscriber accounts SHALL require the successful use of a saved recovery code, issued recovery code, or recovery contact.</p>
      </part>
      <part id="RWIP-1_obj" name="objective">
        <p>Define non-proofing recovery.</p>
        <link href="#RWIP-1_smt" rel="assessment-for"/>
      </part>
      <part id="RWIP-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ARM, IRC, and RECC controls</p>
      </part>
    </control>
    <control id="RAAL2-1">
      <title>AAL2 Recovery Requirements</title>
      <prop name="label" class="index" value="4.2.2.2 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2"/>
      <part id="RAAL2-1_smt" name="statement">
        <p>To recover an account that can authenticate at a maximum of AAL2, the CSP SHALL require the subscriber to complete one of the following:</p>
        <p>(1) Two recovery codes obtained using different methods from the set (i.e., saved, issued, and recovery contacts).</p>
        <p>(2) One recovery code from the set (i.e., saved, issued, and recovery contacts) plus authentication with a single-factor authenticator that is bound to the subscriber account.</p>
        <p>(3) Repeated identity proofing (provided that the subscriber account has been identity-proofed).</p>
      </part>
      <part id="RAAL2-1_obj" name="objective">
        <p>Specify methods of account recovery at AAL2.</p>
        <link href="#RAAL2-1_smt" rel="assessment-for"/>
      </part>
      <part id="RAAL2-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to verify that one recovery method is required to recover a single authentication factor, two methods are required to recover two authentication factors, or repeated identity proofing is required at AAL2.</p>
      </part>
    </control>
    <control id="RAAL3-1">
      <title>AAL3/IAL3 Recovery Requirements</title>
      <prop name="label" class="index" value="4.2.2.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL3"/>
      <part id="RAAL3-1_smt" name="statement">
        <p>If an account that can authenticate at AAL3 has been identity-proofed at IAL3, the CSP SHALL successfully perform a successful biometric comparison against the biometric characteristic collected during an initial on-site attended identity proofing session, as described in [SP800-63A].</p>
      </part>
      <part id="RAAL3-1_obj" name="objective">
        <p>Require biometric comparison for subscriber accounts to meet AAL3/IAL3 security requirements.</p>
        <link href="#RAAL3-1_smt" rel="assessment-for"/>
      </part>
      <part id="RAAL3-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures for account recovery at AAL3/IAL3 and verify that a successful biometric comparison is required.</p>
      </part>
    </control>
    <control id="ACCRN-1">
      <title>Account Recovery Notification</title>
      <prop name="label" class="index" value="4.2.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ACCRN-1_smt" name="statement">
        <p>In all cases, account recovery SHALL cause a notification to be sent to the subscriber or their designee, as described in Sec. 4.6.</p>
      </part>
      <part id="ACCRN-1_obj" name="objective">
        <p>Confirm that subscriber is notified of account recovery events.</p>
        <link href="#ACCRN-1_smt" rel="assessment-for"/>
      </part>
      <part id="ACCRN-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by performing a recovery and verify that the subscriber is notified in one of the ways described.</p>
      </part>
    </control>
    <control id="LTDC-1">
      <title>Compromise Suspension Requirement</title>
      <prop name="label" class="index" value="4.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LTDC-1_smt" name="statement">
        <p>The CSP SHALL suspend, invalidate, or destroy compromised authenticators from the subscriber's account promptly following compromise detection.</p>
      </part>
      <part id="LTDC-1_obj" name="objective">
        <p>Require processes for rendering compromised authenticators inoperative.</p>
        <link href="#LTDC-1_smt" rel="assessment-for"/>
      </part>
      <part id="LTDC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures for handling compromised authenticators and verify that such authenticators are disabled.</p>
      </part>
    </control>
    <control id="LTDC-2">
      <title>Compromise Reporting Authenticators</title>
      <prop name="label" class="index" value="4.3 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="LTDC-2_smt" name="statement">
        <p>Backup authenticators used for secure reporting of compromise SHALL be a password or a physical authenticator.</p>
      </part>
      <part id="LTDC-2_obj" name="objective">
        <p>Establish requirements for authenticators reporting compromise.</p>
        <link href="#LTDC-2_smt" rel="assessment-for"/>
      </part>
      <part id="LTDC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures for issuing backup authenticators for reporting.</p>
      </part>
      <part id="LTDC-2_gdn" name="guidance">
        <p>Applies if CSP issues an authenticator for reporting.</p>
      </part>
    </control>
    <control id="EXP-1">
      <title>Expired Authenticators Unusable</title>
      <prop name="label" class="index" value="4.4 A"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXP-1_smt" name="statement">
        <p>When an authenticator expires, it SHALL NOT be usable for authentication.</p>
      </part>
      <part id="EXP-1_obj" name="objective">
        <p>Ensure that expired authenticators are not usable.</p>
        <link href="#EXP-1_smt" rel="assessment-for"/>
      </part>
      <part id="EXP-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by trying to authenticate with an expired authenticator and verify that it is unsuccessful.</p>
      </part>
      <part id="EXP-1_gdn" name="guidance">
        <p>Applies if authenticators that expire are used.</p>
      </part>
    </control>
    <control id="EXP-2">
      <title>Expired Authenticator Replacement</title>
      <prop name="label" class="index" value="4.4 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EXP-2_smt" name="statement">
        <p>The replacement of expired authenticators SHALL conform to the binding process for an additional authenticator, as described in Sec. 4.1.2.</p>
      </part>
      <part id="EXP-2_obj" name="objective">
        <p>Require standard issuance process for issuance of replacements for expired authenticators.</p>
        <link href="#EXP-2_smt" rel="assessment-for"/>
      </part>
      <part id="EXP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP procedures for issuing replacements for expired authenticators and verify that the full issuance process is used.</p>
      </part>
      <part id="EXP-2_gdn" name="guidance">
        <p>Applies if authenticators that expire are used.</p>
      </part>
    </control>
    <control id="INVAL-1">
      <title>Authenticator Invalidation</title>
      <prop name="label" class="index" value="4.5 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="INVAL-1_smt" name="statement">
        <p>CSPs SHALL promptly invalidate authenticators when a subscriber account ceases to exist (e.g., subscriber's death, the discovery of a fraudulent subscriber), when requested by the subscriber, when the authenticator is compromised, or when the CSP determines that the subscriber no longer meets its eligibility requirements.</p>
      </part>
      <part id="INVAL-1_obj" name="objective">
        <p>Require a process for invalidating authenticators when required.</p>
        <link href="#INVAL-1_smt" rel="assessment-for"/>
      </part>
      <part id="INVAL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine process for receiving and processing invalidation requests from subscriber and other appropriate sources.</p>
      </part>
    </control>
    <control id="INVAL-2">
      <title>Authenticator Invalidation Reporting Risk</title>
      <prop name="label" class="index" value="4.5 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="INVAL-2_smt" name="statement">
        <p>The CSP SHALL make a risk-based determination of the authenticity of invalidation requests from the subscriber.</p>
      </part>
      <part id="INVAL-2_obj" name="objective">
        <p>Guard against denial-of-service attacks from spurious invalidation requests.</p>
        <link href="#INVAL-2_smt" rel="assessment-for"/>
      </part>
      <part id="INVAL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine process for evaluating invalidation requests that are received.</p>
      </part>
    </control>
    <control id="ANOT-1">
      <title>Notification Addresses</title>
      <prop name="label" class="index" value="4.6 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ANOT-1_smt" name="statement">
        <p>Events that require notification SHALL cause a notification to be sent to the notification addresses stored in the subscriber account. Notification addresses may be any means by which the subscriber can be reliably contacted, such as: postal address; email address; address (e.g., telephone number) to which a text message or voice message may be sent; and reference to the subscriber in a push notification service.</p>
      </part>
      <part id="ANOT-1_obj" name="objective">
        <p>Define overall requirement for notification.</p>
        <link href="#ANOT-1_smt" rel="assessment-for"/>
      </part>
      <part id="ANOT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that notification infrastructure exists.</p>
      </part>
    </control>
    <control id="ANOT-2">
      <title>Notification Multiple Address Support</title>
      <prop name="label" class="index" value="4.6 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ANOT-2_smt" name="statement">
        <p>CSPs SHALL support at least two notification addresses per subscriber account.</p>
      </part>
      <part id="ANOT-2_obj" name="objective">
        <p>Require ability to establish multiple notification addresses for redundancy.</p>
        <link href="#ANOT-2_smt" rel="assessment-for"/>
      </part>
      <part id="ANOT-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test establishment of multiple notification addresses and verify that it is possible to establish at least two.</p>
      </part>
    </control>
    <control id="ANOT-3">
      <title>Notification Address Validation</title>
      <prop name="label" class="index" value="4.6 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="AAL2/AAL3"/>
      <part id="ANOT-3_smt" name="statement">
        <p>For subscriber accounts that have undergone identity proofing, at least one address SHALL have been validated during the identity proofing process.</p>
      </part>
      <part id="ANOT-3_obj" name="objective">
        <p>Require use of an identity proofed address for reliability.</p>
        <link href="#ANOT-3_smt" rel="assessment-for"/>
      </part>
      <part id="ANOT-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test with an identity proofed subscriber account to verify that an identity proofed address is already used.</p>
      </part>
      <part id="ANOT-3_gdn" name="guidance">
        <p>Applies when subscriber account has been identity proofed.</p>
      </part>
    </control>
    <control id="ANOT-4">
      <title>Notification Multiplicity</title>
      <prop name="label" class="index" value="4.6 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ANOT-4_smt" name="statement">
        <p>Notifications SHALL be sent to all notification addresses except postal addresses.</p>
      </part>
      <part id="ANOT-4_obj" name="objective">
        <p>Require transmission to multiple addresses except postal addresses due to cost considerations.</p>
        <link href="#ANOT-4_smt" rel="assessment-for"/>
      </part>
      <part id="ANOT-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating a notification to a subscriber account with multiple non-postal notification addresses, and verify that the notification is sent to all of them.</p>
      </part>
    </control>
    <control id="ANOT-5">
      <title>Postal Notification</title>
      <prop name="label" class="index" value="4.6 E"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ANOT-5_smt" name="statement">
        <p>However, notifications SHALL be sent to postal addresses if no other form of notification address is stored in the subscriber account or if the notification is for account recovery at AAL3.</p>
      </part>
      <part id="ANOT-5_obj" name="objective">
        <p>Require notifications to postal addresses when they are the only notification address or for high assurance account recovery.</p>
        <link href="#ANOT-5_smt" rel="assessment-for"/>
      </part>
      <part id="ANOT-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating a notification to subscriber accounts with only a postal address and by performing AAL3 account recovery and verify that a postal notification would be sent.</p>
      </part>
      <part id="ANOT-5_gdn" name="guidance">
        <p>Applies when the only notification address is a postal address or AAL3 recovery.</p>
      </part>
    </control>
    <control id="ANOT-6">
      <title>Postal Recovery Notification</title>
      <prop name="label" class="index" value="4.6 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ANOT-6_smt" name="statement">
        <p>Account recovery notifications SHALL also be sent to a postal address if the only other notification address in the subscriber account is the address to which an issued recovery code was sent.</p>
      </part>
      <part id="ANOT-6_obj" name="objective">
        <p>Provide postal notification when needed to provide notification independent of account recovery.</p>
        <link href="#ANOT-6_smt" rel="assessment-for"/>
      </part>
      <part id="ANOT-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by using an issued recovery code and verify that a postal notification would be sent if no other notification address exists.</p>
      </part>
      <part id="ANOT-6_gdn" name="guidance">
        <p>Applies when using issued recovery codes and the only other notification address is postal.</p>
      </part>
    </control>
    <control id="ANOT-7">
      <title>Notification Repudiation Instructions</title>
      <prop name="label" class="index" value="4.6 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ANOT-7_smt" name="statement">
        <p>The notification SHALL provide clear instructions, including contact information, in case the recipient repudiates the event associated with the notification.</p>
      </part>
      <part id="ANOT-7_obj" name="objective">
        <p>Provide recourse for account holders receiving notification of events they did not authorize.</p>
        <link href="#ANOT-7_smt" rel="assessment-for"/>
      </part>
      <part id="ANOT-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine notification and verify presence of instructions and contact information.</p>
      </part>
    </control>
    <control id="SB-1">
      <title>Session Secret Requirement</title>
      <prop name="label" class="index" value="5.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-1_smt" name="statement">
        <p>A session secret SHALL be shared between the subscriber's software and the accessed service.</p>
      </part>
      <part id="SB-1_obj" name="objective">
        <p>Require that a session establishment be based on a shared secret.</p>
        <link href="#SB-1_smt" rel="assessment-for"/>
      </part>
      <part id="SB-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that a session secret is shared when a session is established based on authentication.</p>
      </part>
    </control>
    <control id="SB-2">
      <title>Session Secret Presentation</title>
      <prop name="label" class="index" value="5.1 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-2_smt" name="statement">
        <p>The secret SHALL be directly presented by the subscriber's software, or possession of the secret SHALL be proven using a cryptographic mechanism.</p>
      </part>
      <part id="SB-2_obj" name="objective">
        <p>Allow verification of the secret to be either direct or cryptographic</p>
        <link href="#SB-2_smt" rel="assessment-for"/>
      </part>
      <part id="SB-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine process for verifying the shared secret to verify how it is verified.</p>
      </part>
    </control>
    <control id="SB-3">
      <title>Session Continuity Secrets</title>
      <prop name="label" class="index" value="5.1 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-3_smt" name="statement">
        <p>The continuity of authenticated sessions SHALL be based on the possession of a session secret that is issued by the session host at the time of authentication and optionally refreshed during the session. The nature of a session depends on the application, such as: a web browser session with a "session" cookie; and an instance of a mobile application that retains a session secret.</p>
      </part>
      <part id="SB-3_obj" name="objective">
        <p>Provide examples of session verification methods.</p>
        <link href="#SB-3_smt" rel="assessment-for"/>
      </part>
      <part id="SB-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SB-1 and SB-2.</p>
      </part>
    </control>
    <control id="SB-4">
      <title>Session Secrets Not Replace Authentication</title>
      <prop name="label" class="index" value="5.1 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-4_smt" name="statement">
        <p>Cookies and similar "remember my browser" features SHALL NOT be used instead of authentication except as provided for reauthentication at AAL2 in Sec. 2.2.3 when the inactivity limit has been exceeded but the time limit has not.</p>
      </part>
      <part id="SB-4_obj" name="objective">
        <p>Emphasize that secrets may not be used to bypass multifactor authentication requirements.</p>
        <link href="#SB-4_smt" rel="assessment-for"/>
      </part>
      <part id="SB-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that multifactor authentication requirements are enforced regardless of session secrets.</p>
      </part>
    </control>
    <control id="SB-5">
      <title>Session Lifetime Limits</title>
      <prop name="label" class="index" value="5.1 E"/>
      <prop name="marking" class="target" value="RP/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-5_smt" name="statement">
        <p>However, RPs and CSPs SHALL ensure that the session lifetime limits described in Sec. 2.2.3 are enforced even when a knowledge of the session secret is demonstrated.</p>
      </part>
      <part id="SB-5_obj" name="objective">
        <p>Emphasize that secrets may not be used to bypass reauthentication time limits.</p>
        <link href="#SB-5_smt" rel="assessment-for"/>
      </part>
      <part id="SB-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that reauthentication requirements are enforced regardless of session secrets.</p>
      </part>
    </control>
    <control id="SB-6">
      <title>Session Secret Generation</title>
      <prop name="label" class="index" value="5.1 F"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-6_smt" name="statement">
        <p>The secret used for session binding SHALL be generated by the session host in direct response to an authentication event.</p>
      </part>
      <part id="SB-6_obj" name="objective">
        <p>Specify party generating session secret.</p>
        <link href="#SB-6_smt" rel="assessment-for"/>
      </part>
      <part id="SB-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine protocol to verify that session secret is generated by host upon authentication.</p>
      </part>
    </control>
    <control id="SB-7">
      <title>Session AAL Limitation</title>
      <prop name="label" class="index" value="5.1 G"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-7_smt" name="statement">
        <p>A session MAY be considered at a lower AAL than the authentication event but SHALL NOT be considered at a higher AAL than the authentication event.</p>
      </part>
      <part id="SB-7_obj" name="objective">
        <p>Allow sessions to be used at lower AALs than authenticated.</p>
        <link href="#SB-7_smt" rel="assessment-for"/>
      </part>
      <part id="SB-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to verify that it is possible to use a session at a lower AAL than was authenticated but not a higher AAL.</p>
      </part>
      <part id="SB-7_gdn" name="guidance">
        <p>Applies to relying parties that support applications at multiple AALs.</p>
      </part>
    </control>
    <control id="SB-8">
      <title>Session Secrets Result From Authentication</title>
      <prop name="label" class="index" value="5.1 #1"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-8_smt" name="statement">
        <p>Secrets used for session binding SHALL be established during or immediately following authentication.</p>
      </part>
      <part id="SB-8_obj" name="objective">
        <p>Require tight relationship between authentication and session binding.</p>
        <link href="#SB-8_smt" rel="assessment-for"/>
      </part>
      <part id="SB-8_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SB-6.</p>
      </part>
    </control>
    <control id="SB-8.1">
      <title>Session Secret Generation Requirements</title>
      <prop name="label" class="index" value="5.1 #2"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-8.1_smt" name="statement">
        <p>Secrets used for session binding SHALL be established using input from an approved random bit generator, as described in Sec. 3.2.12, and are at least 64 bits in length.</p>
      </part>
      <part id="SB-8.1_obj" name="objective">
        <p>Ensure that a sufficiently random session secret is used.</p>
        <link href="#SB-8.1_smt" rel="assessment-for"/>
      </part>
      <part id="SB-8.1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to see how the session secret is generated and verify that it uses an approved random bit generator and is of sufficient length.</p>
      </part>
    </control>
    <control id="SB-8.2">
      <title>Session Secret Logout Invalidation</title>
      <prop name="label" class="index" value="5.1 #3"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-8.2_smt" name="statement">
        <p>Secrets used for session binding SHALL be erased or invalidated by the session subject when the subscriber logs out.</p>
      </part>
      <part id="SB-8.2_obj" name="objective">
        <p>Ensure that sessions are no longer usable following logout.</p>
        <link href="#SB-8.2_smt" rel="assessment-for"/>
      </part>
      <part id="SB-8.2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that session secrets are no longer valid following logout.</p>
      </part>
    </control>
    <control id="SB-8.3">
      <title>Session Secret Establishment</title>
      <prop name="label" class="index" value="5.1 #4"/>
      <prop name="marking" class="target" value="RP/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-8.3_smt" name="statement">
        <p>Secrets used for session binding SHALL be either transferred from the session host to the RP or CSP via an authenticated protected channel or derived from keys that are established as part of establishing a valid, mutually authenticated protected channel.</p>
      </part>
      <part id="SB-8.3_obj" name="objective">
        <p>Define secure methods of establishing the session secret.</p>
        <link href="#SB-8.3_smt" rel="assessment-for"/>
      </part>
      <part id="SB-8.3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that the session secret is transferred or derived as described.</p>
      </part>
    </control>
    <control id="SB-8.4">
      <title>Session Secret Time Limits</title>
      <prop name="label" class="index" value="5.1 #5"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-8.4_smt" name="statement">
        <p>Secrets used for session binding SHALL time out and not be accepted after the times specified in Sec. 2.1.3, Sec. 2.2.3, and Sec. 2.3.3, as appropriate for the AAL.</p>
      </part>
      <part id="SB-8.4_obj" name="objective">
        <p>Ensure that session secrets are invalidated when time out times are met.</p>
        <link href="#SB-8.4_smt" rel="assessment-for"/>
      </part>
      <part id="SB-8.4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that necessary timers are in place and used to invalidate session secrets.</p>
      </part>
    </control>
    <control id="SB-8.5">
      <title>Session Secret Intermediary Protection</title>
      <prop name="label" class="index" value="5.1 #6"/>
      <prop name="marking" class="target" value="RP/CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-8.5_smt" name="statement">
        <p>Secrets used for session binding SHALL be unavailable to intermediaries between the host and the subscriber's endpoint.</p>
      </part>
      <part id="SB-8.5_obj" name="objective">
        <p>Prevent intermediaries and eavesdroppers from accessing session secrets</p>
        <link href="#SB-8.5_smt" rel="assessment-for"/>
      </part>
      <part id="SB-8.5_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SB-8.3.</p>
      </part>
    </control>
    <control id="SB-9">
      <title>Session Transport Security Maintenance</title>
      <prop name="label" class="index" value="5.1 I"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-9_smt" name="statement">
        <p>Following authentication, authenticated sessions SHALL NOT fall back to an insecure transport (e.g., from https to http).</p>
      </part>
      <part id="SB-9_obj" name="objective">
        <p>Prevent sessions from falling back to an insecure state</p>
        <link href="#SB-9_smt" rel="assessment-for"/>
      </part>
      <part id="SB-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test, if insecure transport is supported at all, by attempting to substitute an insecure transport and verify that it is unsuccessful.</p>
      </part>
    </control>
    <control id="SB-10">
      <title>CSRF Protection Requirement</title>
      <prop name="label" class="index" value="5.1 J"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SB-10_smt" name="statement">
        <p>POST/PUT content SHALL contain a session identifier that the RP SHALL verify to protect against cross-site request forgery (CSRF).</p>
      </part>
      <part id="SB-10_obj" name="objective">
        <p>Protect against cross-site request forgery.</p>
        <link href="#SB-10_smt" rel="assessment-for"/>
      </part>
      <part id="SB-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine content (e.g., with browser developer tools) to verify that session identifiers are present.</p>
      </part>
    </control>
    <control id="AT-1">
      <title>Access Tokens Not Presence</title>
      <prop name="label" class="index" value="5.1.2 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AT-1_smt" name="statement">
        <p>The RP SHALL NOT interpret the presence of an access token as an indicator of the subscriber's presence in the absence of other signals.</p>
      </part>
      <part id="AT-1_obj" name="objective">
        <p>Ensure that session secrets rather than access/refresh tokens define validity of a session.</p>
        <link href="#AT-1_smt" rel="assessment-for"/>
      </part>
      <part id="AT-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by logging out of a federated session while a valid access token exists and verify that the session has been terminated.</p>
      </part>
      <part id="AT-1_gdn" name="guidance">
        <p>Applies to sessions established through federation. Note: last sentence of 5.1.2, "authentication session" -&gt; "authenticated session"</p>
      </part>
    </control>
    <control id="REAUTH-1">
      <title>Periodic Reauthentication Requirement</title>
      <prop name="label" class="index" value="5.2 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REAUTH-1_smt" name="statement">
        <p>The periodic reauthentication of sessions SHALL be performed to confirm the subscriber's continued presence at an authenticated session (e.g., that the subscriber has not walked away without logging out).</p>
      </part>
      <part id="REAUTH-1_obj" name="objective">
        <p>Ensure that a reauthentication process exists.</p>
        <link href="#REAUTH-1_smt" rel="assessment-for"/>
      </part>
      <part id="REAUTH-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify use of a reauthentication process following session time out.</p>
      </part>
    </control>
    <control id="REAUTH-2">
      <title>Reauthentication Timeout Terminates Session</title>
      <prop name="label" class="index" value="5.2 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REAUTH-2_smt" name="statement">
        <p>When either the overall or inactivity timeout expires, the session SHALL be terminated.</p>
      </part>
      <part id="REAUTH-2_obj" name="objective">
        <p>Ensure that time out results in process termination.</p>
        <link href="#REAUTH-2_smt" rel="assessment-for"/>
      </part>
      <part id="REAUTH-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SB-8.4.</p>
      </part>
    </control>
    <control id="REAUTH-3">
      <title>Reauthentication Timeout Reset</title>
      <prop name="label" class="index" value="5.2 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REAUTH-3_smt" name="statement">
        <p>Session activity SHALL reset the inactivity timeout, and successful reauthentication during a session SHALL reset both timeouts.</p>
      </part>
      <part id="REAUTH-3_obj" name="objective">
        <p>Define criteria for resetting timeouts.</p>
        <link href="#REAUTH-3_smt" rel="assessment-for"/>
      </part>
      <part id="REAUTH-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation of timeouts to verify that they are reset under these circumstances.</p>
      </part>
    </control>
    <control id="REAUTH-4">
      <title>Reauthentication Documentation</title>
      <prop name="label" class="index" value="5.2 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REAUTH-4_smt" name="statement">
        <p>Agencies SHALL establish and document the inactivity and overall time limits being enforced in a system security plan, such as that described in [SP800-39].</p>
      </part>
      <part id="REAUTH-4_obj" name="objective">
        <p>Verify documentation of timeouts.</p>
        <link href="#REAUTH-4_smt" rel="assessment-for"/>
      </part>
      <part id="REAUTH-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system security plan to verify that timeouts are described.</p>
      </part>
    </control>
    <control id="REAUTH-5">
      <title>Reauthentication RP Authoritative</title>
      <prop name="label" class="index" value="5.2 E"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="REAUTH-5_smt" name="statement">
        <p>The IdP can communicate the time and details of the authentication event to the RP, but the RP SHALL be authoritative as to whether the reauthentication requirements have been met.</p>
      </part>
      <part id="REAUTH-5_obj" name="objective">
        <p>Establish precedence for control of session timing.</p>
        <link href="#REAUTH-5_smt" rel="assessment-for"/>
      </part>
      <part id="REAUTH-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation of timeouts at the RP to verify that it is not over-dependent on timing from the IdP.</p>
      </part>
      <part id="REAUTH-5_gdn" name="guidance">
        <p>Applies to sessions established through federation.</p>
      </part>
    </control>
    <control id="SESSM-1">
      <title>Session Monitoring Documentation</title>
      <prop name="label" class="index" value="5.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SESSM-1_smt" name="statement">
        <p>Collection, the storage of expected subscriber characteristics, and the processing of session characteristics SHALL be included in the privacy risk assessment described in Sec. 7.</p>
      </part>
      <part id="SESSM-1_obj" name="objective">
        <p>Verify documentation of session monitoring.</p>
        <link href="#SESSM-1_smt" rel="assessment-for"/>
      </part>
      <part id="SESSM-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine privacy risk assessment to verify that any use of session monitoring is included.</p>
      </part>
    </control>
    <control id="USEL-1">
      <title>Consent Measures Voluntary</title>
      <prop name="label" class="index" value="7.3 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="USEL-1_smt" name="statement">
        <p>Therefore, as stated in Sec. 2.4.3, when CSPs use consent measures, the subscriber's acceptance of additional uses SHALL NOT be a condition of providing authentication services.</p>
      </part>
      <part id="USEL-1_obj" name="objective">
        <p>Ensure that consent measures are voluntary.</p>
        <link href="#USEL-1_smt" rel="assessment-for"/>
      </part>
      <part id="USEL-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by PR-3.</p>
      </part>
    </control>
    <control id="CAK-1">
      <title>Syncable Authentication Key Generation</title>
      <prop name="label" class="index" value="B.2 #1"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-1_smt" name="statement">
        <p>All keys SHALL be generated using approved cryptography.</p>
      </part>
      <part id="CAK-1_obj" name="objective">
        <p>Determine that only secure, well-vetted cryptographic algorithms are being used.</p>
        <link href="#CAK-1_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented policies or practices to determine that only approved cryptographic algorithms can be used.</p>
      </part>
    </control>
    <control id="CAK-2">
      <title>Syncable Authentication Key Fabric Requirements</title>
      <prop name="label" class="index" value="B.2 #2"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-2_smt" name="statement">
        <p>Authentication keys that are cloned or exported from a device to a sync fabric SHALL only be stored in an encrypted form using a key with the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication).</p>
      </part>
      <part id="CAK-2_obj" name="objective">
        <p>Protection of authentication keys in the sync fabric.</p>
        <link href="#CAK-2_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sync fabric implementation(s) to verify that keys are stored in encrypted form with sufficient strength.</p>
      </part>
    </control>
    <control id="CAK-3">
      <title>Syncable Private-Key Operations Local</title>
      <prop name="label" class="index" value="B.2 #3"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-3_smt" name="statement">
        <p>All authentication transactions SHALL perform private-key operations on the local device using cryptographic keys that are generated on-device or recovered from the sync fabric.</p>
      </part>
      <part id="CAK-3_obj" name="objective">
        <p>Require cryptographic operations to be performed locally.</p>
        <link href="#CAK-3_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that the source of private keys is local or from the sync fabric.</p>
      </part>
    </control>
    <control id="CAK-4">
      <title>Syncable Key Fabric Access Control</title>
      <prop name="label" class="index" value="B.2 #4"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-4_smt" name="statement">
        <p>Authentication keys stored in the sync fabric SHALL be protected by access control mechanisms such that only the authenticated user can access their authentication keys in the sync fabric.</p>
      </part>
      <part id="CAK-4_obj" name="objective">
        <p>Control access to keys in the sync fabric.</p>
        <link href="#CAK-4_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that authentication keys are only available to the subscriber.</p>
      </part>
    </control>
    <control id="CAK-5">
      <title>Syncable Key Fabric MFA</title>
      <prop name="label" class="index" value="B.2 #5"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-5_smt" name="statement">
        <p>User access to authentication keys in the sync fabric SHALL be protected by AAL2-equivalent MFA to preserve the integrity of the authentication protocols using the synced keys.</p>
      </part>
      <part id="CAK-5_obj" name="objective">
        <p>Require sufficient authentication to access keys in the sync fabric.</p>
        <link href="#CAK-5_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sync fabric implementation(s) to verify that at least AAL2 authentication is required to access authentication keys.</p>
      </part>
    </control>
    <control id="CAK-6">
      <title>Syncable Authenticator Documentation</title>
      <prop name="label" class="index" value="B.2 #6"/>
      <prop name="marking" class="target" value="CSP/Verifier"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-6_smt" name="statement">
        <p>These general requirements and any other agency-specific requirements for using syncable authenticators SHALL be documented and communicated, including on public-facing websites and digital service policies, where applicable.</p>
      </part>
      <part id="CAK-6_obj" name="objective">
        <p>Clearly document controls on use of syncable authenticators.</p>
        <link href="#CAK-6_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation, including on websites, of syncable authenticator guidelines.</p>
      </part>
    </control>
    <control id="CAK-7">
      <title>Syncable Key Management</title>
      <prop name="label" class="index" value="B.2 #7"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-7_smt" name="statement">
        <p>Authenticators that enable the use of syncable authentication keys SHOULD provide a user interface (UI) that allows subscribers to view the services for which they have created a syncable authentication key, whether that key has been synced, and where that key has been synced. The UI SHALL NOT expose the authentication key itself.</p>
      </part>
      <part id="CAK-7_obj" name="objective">
        <p>Require manageability of syncable authentication keys by the subscriber.</p>
        <link href="#CAK-7_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test to verify the ability of the subscriber to obtain information about their syncable keys, but not the key itself.</p>
      </part>
    </control>
    <control id="CAK-8">
      <title>Syncable Key Fabric FISMA</title>
      <prop name="label" class="index" value="B.2 #8"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-8_smt" name="statement">
        <p>Federal enterprise authentication keys SHALL be stored in sync fabrics that have achieved Federal Information Security Modernization Act (FISMA) [FISMA] moderate protections or equivalent.</p>
      </part>
      <part id="CAK-8_obj" name="objective">
        <p>Require FISMA compliance for federal enterprise authentication keys.</p>
        <link href="#CAK-8_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine FISMA certification of sync fabric to verify that it meets provides moderate protection.</p>
      </part>
      <part id="CAK-8_gdn" name="guidance">
        <p>Applies to federal enterprise use cases only.</p>
      </part>
    </control>
    <control id="CAK-9">
      <title>Syncable Key Device Management</title>
      <prop name="label" class="index" value="B.2 #9"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-9_smt" name="statement">
        <p>Devices (e.g., mobile phones, laptops, tablets) that generate, store, and sync authenticators containing federal enterprise authentication keys SHALL be protected by mobile device management software or other device configuration controls that prevent the syncing or sharing of keys to unauthorized devices or sync fabrics.</p>
      </part>
      <part id="CAK-9_obj" name="objective">
        <p>Restrict choices of sync fabric to those approved by the agency.</p>
        <link href="#CAK-9_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine acceptance of authentication using syncable authenticators to verify that authentication requires appropriate device configuration management.</p>
      </part>
      <part id="CAK-9_gdn" name="guidance">
        <p>Applies to federal enterprise use cases only.</p>
      </part>
    </control>
    <control id="CAK-10">
      <title>Syncable Key Fabric Management</title>
      <prop name="label" class="index" value="B.2 #10"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="CAK-10_smt" name="statement">
        <p>Access to the sync fabric SHALL be controlled by agency-managed accounts (e.g., a central identity and access management solution, platform-based managed account) to maintain federal enterprise control over the authentication key's life cycle.</p>
      </part>
      <part id="CAK-10_obj" name="objective">
        <p>Maintain federal control over authentication keys throughout their life cycle.</p>
        <link href="#CAK-10_smt" rel="assessment-for"/>
      </part>
      <part id="CAK-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine choices of sync fabric approved by the agency to verify that it manages access to the fabric.</p>
      </part>
      <part id="CAK-10_gdn" name="guidance">
        <p>Applies to federal enterprise use cases only.</p>
      </part>
    </control>
    <control id="IMPR-1">
      <title>Syncable Key User Verification</title>
      <prop name="label" class="index" value="B.3 A"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="IMPR-1_smt" name="statement">
        <p>Verifiers SHALL indicate that user verification (UV) is preferred and SHALL inspect responses to confirm the value of the UV flag.</p>
      </part>
      <part id="IMPR-1_obj" name="objective">
        <p>Prefer syncable authenticators providing multi-factor authentication.</p>
        <link href="#IMPR-1_smt" rel="assessment-for"/>
      </part>
      <part id="IMPR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that the value of the UV flag is observed.</p>
      </part>
    </control>
    <control id="IMPR-2">
      <title>Syncable Non-UV Key SF</title>
      <prop name="label" class="index" value="B.3 B"/>
      <prop name="marking" class="target" value="Verifier"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="IMPR-2_smt" name="statement">
        <p>If the user is not verified, agencies SHALL treat the authenticator as a single-factor cryptographic authenticator.</p>
      </part>
      <part id="IMPR-2_obj" name="objective">
        <p>Authentication without user verification is single-factor.</p>
        <link href="#IMPR-2_smt" rel="assessment-for"/>
      </part>
      <part id="IMPR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine implementation to verify that authentication without user verification requires an additional password or biometric factor.</p>
      </part>
    </control>
    <control id="IMPR-3">
      <title>Syncable Key Flag Trust</title>
      <prop name="label" class="index" value="B.3 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="Syncable"/>
      <part id="IMPR-3_smt" name="statement">
        <p>Agencies SHALL evaluate the use cases for syncable authenticators and determine the appropriate access policy decisions that they intend to make based on returned information including flags and attestation.</p>
      </part>
      <part id="IMPR-3_obj" name="objective">
        <p>Provide basis for trusting information such as flags received from the authenticator.</p>
        <link href="#IMPR-3_smt" rel="assessment-for"/>
      </part>
      <part id="IMPR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine procedures and their basis to determine that appropriate attention has been paid to reliability of information received from syncable authenticators.</p>
      </part>
    </control>
  </group>
  <group class="revision" id="revision-63C">
    <title>63C</title>
    <control id="FAL-1">
      <title>FAL Compliance</title>
      <prop name="label" class="index" value="2.0 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FAL-1_smt" name="statement">
        <p>In order to fulfill the requirements for a given FAL, the federation transaction SHALL meet or exceed all requirements listed for that FAL.</p>
      </part>
      <part id="FAL-1_obj" name="objective">
        <p>Determine that the IdP and RP each enforce all requirements associated with the applicable FAL and that every federation transaction meets or exceeds the criteria defined for that FAL.</p>
        <link href="#FAL-1_smt" rel="assessment-for"/>
      </part>
      <part id="FAL-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied when all controls applicable to the asserted FAL are satisfied.</p>
      </part>
      <part id="FAL-1_gdn" name="guidance">
        <p>This requirement ensures that the assurance level claimed in a federation transaction reflects the actual technical protections in use. Each FAL defines minimum requirements for audience restriction, replay protection, assertion injection protection, trust agreement establishment, identifier and key establishment, and presentation. Both the IdP and RP must enforce those requirements so that no transaction is represented as operating at a higher FAL than the implemented controls support.</p>
        <p>See also SECC-4, which is a summative control for xAL baseline compliance.</p>
      </part>
    </control>
    <control id="CFAL-1">
      <title>Federation Requirements</title>
      <prop name="label" class="index" value="2.1 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CFAL-1_smt" name="statement">
        <p>At all FALs, all federation transactions SHALL comply with the requirements in Sec. 3 to deliver an assertion to the RP and create an authenticated session at the RP.</p>
      </part>
      <part id="CFAL-1_obj" name="objective">
        <p>Determine whether all federation transactions comply with the requirements in Section 3 for assertion delivery and RP session establishment.</p>
        <link href="#CFAL-1_smt" rel="assessment-for"/>
      </part>
      <part id="CFAL-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For IdPs, satisfied by AAD-1, AAD-4, AAD-6, TSI-1, IDA-1 through IDA-3, ARTP-1, ARTI-1, SIGNA-1, SIGNA-3, SIGNA-4, and AUDR-1; also by PROXY-1, PROXY-3 if proxied federation is used; PPI-1, PPI-4 through PPI-8, PPI-10 if PPIs are used; DAV-1 if derived attribute values are used; and ENCA-1 if encrypted assertions are used. If FAL3, satisfied by HKA-1, HKA-3, HKA-5 when HoK assertions are used, and BAUTH-1 when the bound-authenticators are used.</p>
        <p>For RPs, satisfied by ASRP-1, SIGNA-2, and AUDR-2; also by FEDID-1, FEDID-2 when federated identifiers are used or ACCR-1 when account resolution is used; ABUN-2 and ABUN-3 if attribute bundles are used; and IDAP-3 if identity APIs are used. If FAL3, satisfied by ASRP-2; also HKA-2, RPPHBA-1, RPPHBA-3, RPPHBA-4 when HoK assertions are used; and BAUTH-5, BAUTH-7, RPPHBA-1, RPPHBA-3, and RPPHBA-4 when the bound-authenticators are used.</p>
      </part>
      <part id="CFAL-1_gdn" name="guidance">
        <p>This is a summative control based on the outcomes of all controls governing assertion delivery and RP session creation. Compliance is demonstrated when all applicable Section 3 requirements are met.</p>
      </part>
    </control>
    <control id="CFAL-2">
      <title>Assertion Validation</title>
      <prop name="label" class="index" value="2.1 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CFAL-2_smt" name="statement">
        <p>At all FALs, the RP SHALL validate the assertion from the IdP, since the RP needs to trust the IdP to provide valid assertions representing the subscriber's authentication event.</p>
      </part>
      <part id="CFAL-2_obj" name="objective">
        <p>Determine whether the RP validates each assertion received from the IdP to ensure its authenticity, integrity, and origin before establishing a session.</p>
        <link href="#CFAL-2_smt" rel="assessment-for"/>
      </part>
      <part id="CFAL-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ARTC-10 and ARTVL-3.</p>
      </part>
      <part id="CFAL-2_gdn" name="guidance">
        <p>This is a summative control. Assertion validation is assessed under ARTC-10 (traditional federation) and ARTVL-3 (subscriber-controlled wallets).</p>
      </part>
    </control>
    <control id="CFAL-3">
      <title>Security Control Requirements</title>
      <prop name="label" class="index" value="2.1 C"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CFAL-3_smt" name="statement">
        <p>All parties in the federation SHALL employ security controls, as discussed in Sec. 3.11.</p>
      </part>
      <part id="CFAL-3_obj" name="objective">
        <p>Determine whether the party undergoing assessment employs the security controls required in Section 3.11.</p>
        <link href="#CFAL-3_smt" rel="assessment-for"/>
      </part>
      <part id="CFAL-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For IdPs/CSPs, satisfied by SECC-1, SECC-4, PSI-1 through PSI-3, and SSIN-2.</p>
        <p>For RPs, satisfied by SECC-2 through SECC-4, PSI-1 through PSI-3, and SSIN-1 through SSIN-3.</p>
      </part>
      <part id="CFAL-3_gdn" name="guidance">
        <p>Section 3.11 establishes a tiered security controls baseline for federation participants. CSPs and IdPs must implement appropriately tailored controls from at least the SP 800-53 moderate baseline (or equivalent federal or industry standard such as FedRAMP). RPs must implement at least the low baseline, but RPs that request or process personal information must step up to the moderate baseline. All parties must also satisfy the minimum assurance-related controls for their systems.</p>
        <p>This is a summative control that relies on the conclusions of all applicable assessments related to Section 3.11 in this catalog. Compliance is demonstrated when all Section 3.11 requirements applicable to the assessed party are met.</p>
      </part>
    </control>
    <control id="FAL1-1">
      <title>Approved Cryptography: Assertion Signatures</title>
      <prop name="label" class="index" value="2.2 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FAL1-1_smt" name="statement">
        <p>At FAL1, the IdP SHALL sign the assertion using approved cryptography.</p>
      </part>
      <part id="FAL1-1_obj" name="objective">
        <p>Determine whether approved cryptography is used for the assertion signature.</p>
        <link href="#FAL1-1_smt" rel="assessment-for"/>
      </part>
      <part id="FAL1-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion signing configuration to confirm that all assertions are cryptographically signed using approved algorithms and key sizes.</p>
      </part>
      <part id="FAL1-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating an assertion from the IdP and verifying the presence of a cryptographic signature using approved cryptography. See SIGNA-4 for assessment of the specific signature mechanism and key type.</p>
      </part>
      <part id="FAL1-1_gdn" name="guidance">
        <p>SP 800-63-4 defines approved cryptography as any algorithm, hash function, random bit generator, or similar technique that is FIPS-approved or NIST-recommended. For assertion signatures, the relevant standards are FIPS 186-5 (Digital Signature Standard, covering RSA, ECDSA, and EdDSA) and SP 800-131A (algorithm and key length transition schedules). Assessors should verify the IdP's signing algorithm and key size against these references.</p>
      </part>
    </control>
    <control id="FAL1-2">
      <title>Signature Verification</title>
      <prop name="label" class="index" value="2.2 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FAL1-2_smt" name="statement">
        <p>The RP SHALL validate the signature using the verification key associated with the expected IdP.</p>
      </part>
      <part id="FAL1-2_obj" name="objective">
        <p>Determine whether the RP validates the assertion signature using the verification key associated with the expected IdP.</p>
        <link href="#FAL1-2_smt" rel="assessment-for"/>
      </part>
      <part id="FAL1-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's signature-validation logic, configuration, and key-establishment documentation to verify that the RP selects the verification key based on the expected IdP identifier and validates assertion signatures only with the verification key associated with that IdP.</p>
      </part>
      <part id="FAL1-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented results of conformance testing to the IdP/RP implemented standards, protocols, and profiles if available (e.g., OIDC federation OP test)</p>
      </part>
      <part id="FAL1-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by setting up a test IdP and (1) Presenting a valid assertion signed by the expected IdP's key. Verify acceptance. (2) Presenting an assertion signed by a different trusted IdP's valid key. Verify rejection. (3) Presenting an assertion claiming the expected IdP as issuer but signed with a different IdP's key. Verify rejection. (4) Presenting an assertion signed with an unknown or untrusted key. Verify rejection. (5) Presenting an assertion with no signature. Verify rejection.</p>
      </part>
      <part id="FAL1-2_gdn" name="guidance">
        <p>This requirement ensures that the RP verifies the cryptographic signature on assertions to confirm their authenticity and integrity. The RP must use the verification key specifically associated with the expected IdP. For assessment of how the RP obtains and establishes that key through trusted mechanisms (discovery, registration, manual exchange, or federation authorities), see ICKM-1 and ICKM-2. For assessment of the specific signature mechanism type, see SIGNA-4.</p>
      </part>
    </control>
    <control id="FAL1-3">
      <title>FAL1 Audience Restriction</title>
      <prop name="label" class="index" value="2.2 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL1"/>
      <part id="FAL1-3_smt" name="statement">
        <p>At FAL1, the assertion SHALL be audience-restricted to a specific RP or set of RPs.</p>
      </part>
      <part id="FAL1-3_obj" name="objective">
        <p>Determine whether the IdP includes audience restrictions in all FAL1 assertions targeting specific RP(s).</p>
        <link href="#FAL1-3_smt" rel="assessment-for"/>
      </part>
      <part id="FAL1-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AUDR-1.</p>
      </part>
      <part id="FAL1-3_gdn" name="guidance">
        <p>At all FALs, the IdP must include audience restrictions identifying the intended recipient(s). FAL1 allows multiple RPs per assertion, but the assertion must explicitly list all intended recipients. This prevents unscoped assertions that could be accepted by any RP. To reduce the risk of assertion replay, IdPs SHOULD issue assertions designated for a single audience whenever possible. Restriction to a single audience becomes mandatory at FAL2 and higher.</p>
      </part>
    </control>
    <control id="FAL1-4">
      <title>FAL1 RP Audience Validation</title>
      <prop name="label" class="index" value="2.2 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL1"/>
      <part id="FAL1-4_smt" name="statement">
        <p>At FAL1, the RP SHALL validate that it is one of the targeted RPs for the given assertion.</p>
      </part>
      <part id="FAL1-4_obj" name="objective">
        <p>Verify that the RP validates each received assertion to ensure its own identifier appears in the audience restriction and rejects any assertion not explicitly targeted to it.</p>
        <link href="#FAL1-4_smt" rel="assessment-for"/>
      </part>
      <part id="FAL1-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AUDR-2.</p>
      </part>
      <part id="FAL1-4_gdn" name="guidance">
        <p>The RP must check that its identifier appears in the assertion's audience field. This prevents replay attacks where assertions intended for other RPs are injected at an unintended RP. If the RP utilizes an IdP that lists multiple RPs in a single assertion at FAL1, confirm that the RP correctly handles assertions containing multiple RP identifiers.</p>
      </part>
    </control>
    <control id="FAL1-5">
      <title>FAL1 RP Assertion Replay Protection</title>
      <prop name="label" class="index" value="2.2 E"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FAL1-5_smt" name="statement">
        <p>Each RP in the [assertion] audience SHALL enforce replay protection mechanisms in the assertion to ensure that the same assertion is not accepted by a given RP multiple times.</p>
      </part>
      <part id="FAL1-5_obj" name="objective">
        <p>Verify that the RP enforces replay protection by detecting and rejecting any assertion that has already been accepted, ensuring the same assertion cannot be used more than once.</p>
        <link href="#FAL1-5_smt" rel="assessment-for"/>
      </part>
      <part id="FAL1-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP documentation, federation configuration, code, and test results to confirm that replay detection mechanisms exist (e.g., nonce validation, assertion ID, and timestamp) and that repeated assertions are rejected.</p>
      </part>
      <part id="FAL1-5_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented results of conformance testing to the standards, protocols, and profiles implemented by the RP, if available.</p>
      </part>
      <part id="FAL1-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the RP configuration by replaying a previously accepted, valid assertion. Confirm rejection.</p>
      </part>
      <part id="FAL1-5_gdn" name="guidance">
        <p>Replay protection ensures that a given RP does not accept the same assertion more than once within its validity time window. At FAL1, where multi-audience assertions are permitted, each RP in the audience may accept the assertion once - but no individual RP may accept it a second time. Common replay detection mechanisms include tracking assertion identifiers, validating nonces, and enforcing timestamp-based expiration windows.</p>
      </part>
    </control>
    <control id="FAL2-1">
      <title>Assertion Injection Protection</title>
      <prop name="label" class="index" value="2.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL2-1_smt" name="statement">
        <p>At FAL2, the assertion SHALL be strongly protected from assertion injection attacks, as discussed in Sec. 3.11.1.</p>
      </part>
      <part id="FAL2-1_obj" name="objective">
        <p>Determine whether the RP implements strong protections against assertion injection attacks consistent with Sec. 3.11.1.</p>
        <link href="#FAL2-1_smt" rel="assessment-for"/>
      </part>
      <part id="FAL2-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by implementing all of the following: FAL1-1, FAL1-2, FAL1-5, FAL2-2, ARTRQ-1, AUDR-1, ARTC-7, ARTC-10 items 3 and 5, AUDR-2, BCP-1 through BCP-10, FCP-1 through FCP-3.</p>
      </part>
      <part id="FAL2-1_gdn" name="guidance">
        <p>An assertion injection attack in the context of a federated protocol consists of an attacker attempting to force an RP to accept or process an assertion or assertion reference in order to gain access to the RP or deny a legitimate subscriber access to the RP. The attacker does this by taking an assertion or assertion reference and injecting it into a vulnerable RP. A successful attacker can trick an RP into binding the attacker's session to the federated identifier in the assertion. The attacker's assertion could be either stolen from a legitimate subscriber or manufactured to perpetrate the attack.</p>
        <p>Protection from assertion injection attacks is recommended at all FALs and required at FAL2 and above. In all cases, the RP needs to take reasonable steps to prevent an attacker from presenting an injected assertion or assertion reference based on the nature of the RP software, the capabilities of the federation protocol in use, and the needs of the overall system.</p>
      </part>
    </control>
    <control id="FAL2-2">
      <title>RP-Initiated Transactions</title>
      <prop name="label" class="index" value="2.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL2-2_smt" name="statement">
        <p>The federation transaction SHALL be initiated by the RP.</p>
      </part>
      <part id="FAL2-2_obj" name="objective">
        <p>Verify that, at FAL2 and above, all federation transactions are initiated by the RP rather than the IdP.</p>
        <link href="#FAL2-2_smt" rel="assessment-for"/>
      </part>
      <part id="FAL2-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's federation implementation and protocol configuration to confirm that all authentication requests originate from the RP. Verify that unsolicited IdP-initiated assertions are not accepted at FAL2 or above.</p>
      </part>
      <part id="FAL2-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the RP flow by delivering an assertion directly to the RP's federation endpoint without initiating the transaction at the RP. Confirm the RP rejects it.</p>
      </part>
      <part id="FAL2-2_gdn" name="guidance">
        <p>IdP-initiated federation processes are prohibited at FAL2 and FAL3 to prevent the RP from accepting unsolicited assertions and assertion references from the IdP. Inclusion and validation of RP-provided nonces in assertions is an indication of an RP-initiated transaction. However, this prohibition does not include processes in which an external party (e.g., the IdP or a federation authority) signals the RP to start a federation process with the IdP, allowing the RP to begin the federation transaction and securely await a response within that transaction.</p>
      </part>
    </control>
    <control id="FAL2-3">
      <title>FAL2+ Audience Restriction</title>
      <prop name="label" class="index" value="2.3 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL2-3_smt" name="statement">
        <p>At FAL2, the assertion SHALL be audience restricted to a single RP.</p>
      </part>
      <part id="FAL2-3_obj" name="objective">
        <p>Verify that, at FAL2 and above, the IdP includes an audience restriction in each assertion that designates exactly one RP as the intended recipient.</p>
        <link href="#FAL2-3_smt" rel="assessment-for"/>
      </part>
      <part id="FAL2-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AUDR-1.</p>
      </part>
      <part id="FAL2-3_gdn" name="guidance">
        <p>At FAL2, assertions must be explicitly scoped to a single RP to prevent cross-RP assertion replay. Unlike FAL1, where multiple audiences are permitted, FAL2 and above require one-to-one binding between the assertion and the RP, ensuring that a captured assertion cannot be reused at another RP within the federation.</p>
      </part>
    </control>
    <control id="FAL2-4">
      <title>RP Assertion Replay Protection Enforcement</title>
      <prop name="label" class="index" value="2.3 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL2-4_smt" name="statement">
        <p>The RP SHALL enforce replay protection mechanisms in the assertion.</p>
      </part>
      <part id="FAL2-4_obj" name="objective">
        <p>Determine whether the RP enforces replay protection mechanisms.</p>
        <link href="#FAL2-4_smt" rel="assessment-for"/>
      </part>
      <part id="FAL2-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by FAL1-5.</p>
      </part>
      <part id="FAL2-4_gdn" name="guidance">
        <p>This is the FAL2/FAL3 restatement of the replay protection requirement from Sec. 2.2 (see FAL1-5). At FAL2+, multi-audience assertions are not permitted, so replay protection applies to single-audience assertions only. The assessment methodology and test procedures are the same as FAL1-5.</p>
      </part>
    </control>
    <control id="FAL2-5">
      <title>Federated Identifier Privacy Protection</title>
      <prop name="label" class="index" value="2.3 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL2-5_smt" name="statement">
        <p>At FAL2, federated identifiers SHALL NOT contain plaintext personal information, such as usernames, email addresses, employee numbers, etc.</p>
      </part>
      <part id="FAL2-5_obj" name="objective">
        <p>Verify that, at FAL2 and above, the IdP issues federated identifiers that do not include any plaintext personal information such as usernames, email addresses, employee numbers, or other directly identifying data.</p>
        <link href="#FAL2-5_smt" rel="assessment-for"/>
      </part>
      <part id="FAL2-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's federated identifier construction rules, documentation, and representative issued identifiers to determine whether any federated identifier contains plaintext personal information, such as usernames, email addresses, employee numbers, names, phone numbers, or similar directly identifying values.</p>
      </part>
      <part id="FAL2-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating representative identifiers for sample subscriber accounts and verifying that no identifier reveals plaintext personal information.</p>
      </part>
      <part id="FAL2-5_gdn" name="guidance">
        <p>At FAL2 and higher, identifiers must be privacy-preserving and non-identifying. This protects subscriber privacy if assertions are intercepted.</p>
      </part>
    </control>
    <control id="FAL2-6">
      <title>Pre-Established trust agreements</title>
      <prop name="label" class="index" value="2.3 F"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL2-6_smt" name="statement">
        <p>At FAL2 [or higher], a trust agreement SHALL be established prior to the federation transaction taking place (i.e., a "pre-established" trust agreement), as discussed in Sec. 4.3.1.</p>
      </part>
      <part id="FAL2-6_obj" name="objective">
        <p>Verify that, at FAL2 and above, a trust agreement between the IdP and RP is established and in effect before any federation transaction occurs.</p>
        <link href="#FAL2-6_smt" rel="assessment-for"/>
      </part>
      <part id="FAL2-6_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by PETA-1, PETA-2, PETA-3, PETA-4, and PETA-7; additionally satisfied by PETA-6 where shared signaling is used, and by PETA-5 where FAL3 is permitted within the trust agreement.</p>
      </part>
      <part id="FAL2-6_gdn" name="guidance">
        <p>At FAL2 and above, the IdP and RP must have a trust agreement in place before any federation transaction occurs. The agreement must cover all terms identified in Section 4.3.1, but those terms need not appear in a single document. The required content may be spread across multiple artifacts that, together, establish the technical, operational, and legal basis for trust.</p>
        <p>Acceptable artifacts can include binding documents such as contracts, memoranda of understanding, or service agreements, and non-binding but authoritative materials such as CSP practice statements, federation authority agreements, or published federation policies. For example, an IdP may publish a policy describing the assurance levels (xALs) it supports, the security controls it enforces, and the responsibilities of RPs. If the RP documents that it has received and accepted that policy, those terms satisfy the corresponding portion of the trust agreement.</p>
      </part>
    </control>
    <control id="FAL2-7">
      <title>Key Protection</title>
      <prop name="label" class="index" value="2.3 G"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL2-7_smt" name="statement">
        <p>IdPs operated by or on behalf of federal agencies that present assertions at FAL2 or higher SHALL protect signing keys used to generate assertions with mechanisms validated at [FIPS140] Level 1 or higher.</p>
      </part>
      <part id="FAL2-7_obj" name="objective">
        <p>Determine whether the IdP protects assertion-signing keys using cryptographic modules validated at FIPS 140 Level 1 or higher.</p>
        <link href="#FAL2-7_smt" rel="assessment-for"/>
      </part>
      <part id="FAL2-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's federation system documentation and configuration to verify that assertion-signing keys are generated, stored, and used only within a FIPS 140-validated cryptographic module. Confirm that the module appears on the CMVP validation list with a status of Active and is validated at Level 1 or higher.</p>
      </part>
      <part id="FAL2-7_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides assertions to one or more federal agencies or the IdP is a federal agency.</p>
      </part>
    </control>
    <control id="FAL3-1">
      <title>RP Verification of Subscriber Authenticator Control</title>
      <prop name="label" class="index" value="2.4 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="FAL3-1_smt" name="statement">
        <p>At FAL3, the RP SHALL verify that the subscriber is in control of an authenticator in addition to the assertion.</p>
      </part>
      <part id="FAL3-1_obj" name="objective">
        <p>Determine whether the RP verifies subscriber control of an authenticator beyond the assertion at FAL3.</p>
        <link href="#FAL3-1_smt" rel="assessment-for"/>
      </part>
      <part id="FAL3-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For holder-of-key assertions, satisfied by HKA-2.</p>
        <p>For bound authenticators, satisfied by RPPHBA-1 and RPPHBA-4.</p>
      </part>
      <part id="FAL3-1_gdn" name="guidance">
        <p>This is a summative control. Compliance is demonstrated when the authenticator control mechanism(s) utilized by the RP have been assessed. At least one of these two mechanisms must be implemented to achieve compliance.</p>
        <p>At FAL3, the RP must verify both that it has received a valid assertion from the IdP and that the subscriber controls an authenticator in addition to the assertion. The subscriber-controlled authenticator is either identified in a holder-of-key assertion (see Sec. 3.15) or is an authenticator bound to the RP subscriber account (see Sec. 3.16). In both cases, the authenticator must be phishing-resistant, and the RP must verify proof of control before granting access.</p>
      </part>
    </control>
    <control id="FAL3-2">
      <title>FAL3 Pre-Established Trust Agreements</title>
      <prop name="label" class="index" value="2.4 B"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="FAL3-2_smt" name="statement">
        <p>At FAL3, a trust agreement SHALL be established prior to the federation transaction taking place (i.e., a "pre-established" trust agreement), as discussed in Sec. 4.3.1.</p>
      </part>
      <part id="FAL3-2_obj" name="objective">
        <p>Determine whether trust agreement artifact(s) are pre-established prior to the federation transaction.</p>
        <link href="#FAL3-2_smt" rel="assessment-for"/>
      </part>
      <part id="FAL3-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by FAL2-6.</p>
      </part>
    </control>
    <control id="FAL3-3">
      <title>Manual Identifier Establishment at FAL3</title>
      <prop name="label" class="index" value="2.4 C"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="FAL3-3_smt" name="statement">
        <p>At FAL3, the identifiers for the CSP, IdP, and RP SHALL be established manually.</p>
      </part>
      <part id="FAL3-3_obj" name="objective">
        <p>Determine whether identifiers for all federation parties are established through manual processes at FAL3.</p>
        <link href="#FAL3-3_smt" rel="assessment-for"/>
      </part>
      <part id="FAL3-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine configuration documentation to confirm that federation identifiers (e.g., entity IDs, issuer URIs) for the CSP, IdP, and RP are manually configured by authorized personnel.  Verify that dynamic registration (Sec. 4.4.2) is not enabled for FAL3 transactions.</p>
      </part>
      <part id="FAL3-3_gdn" name="guidance">
        <p>FAL3 prohibits dynamic or automated identifier establishment. Party identifiers must be manually configured through direct administrative action. This requirement reduces automated attack vectors and ensures human verification of party identity before establishing FAL3 connections.</p>
      </part>
    </control>
    <control id="FAL3-4">
      <title>Identifier-Key Association</title>
      <prop name="label" class="index" value="2.4 D"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="FAL3-4_smt" name="statement">
        <p>Each [CSP, IdP, and RP] identifier SHALL be uniquely associated with the verification keys for the party represented.</p>
      </part>
      <part id="FAL3-4_obj" name="objective">
        <p>Determine whether each party identifier is uniquely bound to that party's verification keys.</p>
        <link href="#FAL3-4_smt" rel="assessment-for"/>
      </part>
      <part id="FAL3-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine configuration data or metadata to confirm that each federation participant's identifier (e.g., entity ID) maps to a distinct and authorized verification key or key set. Verify that no key is shared across different identifiers and that key rotation procedures preserve this one-to-one mapping.</p>
      </part>
      <part id="FAL3-4_gdn" name="guidance">
        <p>This control prevents key-substitution and impersonation attacks by ensuring that when a signature verifies under a stored key, it can only be attributed to the single, specific party whose identifier is bound to that key in the local configuration.</p>
      </part>
    </control>
    <control id="FAL3-5">
      <title>Verification Key Transmission</title>
      <prop name="label" class="index" value="2.4 E"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="FAL3-5_smt" name="statement">
        <p>Verification keys SHALL be transmitted through a trusted mechanism, which could be manual or automated, as indicated in the trust agreement.</p>
      </part>
      <part id="FAL3-5_obj" name="objective">
        <p>Determine whether verification keys are transmitted through a trusted mechanism, ensuring that key material is received from an authenticated and authorized source, and that the mechanism is documented as part of the trust agreement.</p>
        <link href="#FAL3-5_smt" rel="assessment-for"/>
      </part>
      <part id="FAL3-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documented procedures to determine how verification keys are exchanged, confirming that the mechanism matches the trusted method specified in the relevant trust agreement artifact(s). Determine whether the key exchange mechanism is manual or automated. For automated mechanisms, confirm conformance with ICKM-2. For manual mechanisms, verify that procedures are in place to confirm that the requesting party's identity has been sufficiently verified. Verify that the mechanism for transmitting the verification key is accurately documented and made available to the key recipients.</p>
      </part>
      <part id="FAL3-5_gdn" name="guidance">
        <p>This requirement ensures that each participant obtains verification keys only from validated sources consistent with the established trust agreement. For example, a public-key certificate that represents the RP is uploaded to the IdP during a manual registration process. The RP is manually configured with a URL that it can use to download the IdP's public key. Alternatively, the IdP and RP could each upload their respective public keys to a federation authority and then download each other's keys from that same location. For a subscriber-controlled wallet, the RP could be manually configured with the URL that represents the CSP's public key. The RP fetches this public key and uses it to validate the signature of the attribute bundle presented by the subscriber-controlled wallet. See Sec. 3.6 for more information on the establishment, management, rotation, and revocation of keys and their association with identifiers.</p>
      </part>
    </control>
    <control id="RXAL-1">
      <title>RP-Specified Minimum Acceptable xALs</title>
      <prop name="label" class="index" value="2.5 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-1_smt" name="statement">
        <p>IdPs SHALL support a mechanism for RPs to specify a set of minimum acceptable xALs as part of the trust agreement.</p>
      </part>
      <part id="RXAL-1_obj" name="objective">
        <p>Determine whether the IdP provides a mechanism for RPs to specify minimum acceptable xALs in the trust agreement.</p>
        <link href="#RXAL-1_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by PETA-1, item (n).</p>
      </part>
      <part id="RXAL-1_gdn" name="guidance">
        <p>PETA-1, item (n) requires the trust agreement artifact(s) to document the xALs required by the RPs the IdP supports.</p>
      </part>
    </control>
    <control id="RXAL-2">
      <title>xAL Reporting</title>
      <prop name="label" class="index" value="2.5 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-2_smt" name="statement">
        <p>The IdP SHALL always indicate the resulting xAL in the assertion, even if the request has not been met.</p>
      </part>
      <part id="RXAL-2_obj" name="objective">
        <p>Determine whether the IdP includes the actual xAL values achieved in every assertion.</p>
        <link href="#RXAL-2_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>The presence of xALs in assertions is satisfied by RXAL-3 (IAL), RXAL-4 (AAL), and RXAL-5 (FAL).</p>
        <p>Examine the IdP's federation processing logic, assertion-generation logic, configuration, and documentation to determine how the IdP handles transactions in which the RP requests xAL values that the IdP cannot satisfy. Determine whether the IdP issues an assertion containing the xAL values actually achieved, or fails the request and does not issue an assertion.</p>
      </part>
      <part id="RXAL-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the IdP using a transaction in which the RP requests xAL values that the IdP cannot satisfy. If the IdP is designed to issue an assertion in that case, determine that the assertion contains the xAL values actually achieved rather than the xAL values requested by the RP. If the IdP is designed to fail the request in that case, determine that the transaction fails and that no assertion is issued.</p>
      </part>
      <part id="RXAL-2_gdn" name="guidance">
        <p>IdPs must report the actual IAL, AAL, and FAL in the assertion, regardless of what the RP requested. This allows RPs to make informed access decisions when requirements aren't met. For example, if the subscriber has an active session that was authenticated at AAL1, but the RP has requested AAL2, the IdP needs to prompt the subscriber for AAL2 authentication to increase the security of the session at the IdP during the subscriber's interaction at the IdP, if possible. The IdP sends the resulting AAL as part of the returned assertion, whether it is AAL1 (i.e., the step-up authentication request was not met) or AAL2 (i.e., the step-up authentication request was met successfully).</p>
      </part>
    </control>
    <control id="RXAL-3">
      <title>IAL Reporting</title>
      <prop name="label" class="index" value="2.5 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-3_smt" name="statement">
        <p>The IdP SHALL inform the RP of the following information for each federation transaction: The IAL of the subscriber account being presented to the RP, or an indication that no IAL claim is being made.</p>
      </part>
      <part id="RXAL-3_obj" name="objective">
        <p>Determine whether the IdP informs the RP of the IAL for each federation transaction.</p>
        <link href="#RXAL-3_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>If the IAL is static: Satisfied by RXAL-6.</p>
        <p>If the IAL is variable: Examine the IdP assertion schema, metadata, or other documentation to confirm that the IdP provides either a claim or attribute conveying the IAL of the subscriber account, or a defined mechanism by which no IAL claim is made in the assertion format used by the IdP.</p>
      </part>
      <part id="RXAL-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a transaction in which the IdP asserts an IAL value and determine that the assertion or associated message includes that value. Then, initiate a transaction in which the IdP omits an IAL claim and determine that the assertion output matches the IdP's documented no-claim mechanism.</p>
      </part>
      <part id="RXAL-3_gdn" name="guidance">
        <p>The RP obtains this IAL information from a combination of the terms of the trust agreement (see Sec. 3.5) and information included in the assertion (see Sec. 4.9 and Sec. 5.8).</p>
      </part>
    </control>
    <control id="RXAL-4">
      <title>AAL Reporting</title>
      <prop name="label" class="index" value="2.5 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-4_smt" name="statement">
        <p>The IdP SHALL inform the RP of the following information for each federation transaction: The AAL of the currently active session of the subscriber at the IdP, or an indication that no AAL claim is being made.</p>
      </part>
      <part id="RXAL-4_obj" name="objective">
        <p>Determine whether the IdP informs the RP of the AAL for each federation transaction.</p>
        <link href="#RXAL-4_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>If the AAL is static: Satisfied by RXAL-6.</p>
        <p>If the AAL is variable: Examine the IdP assertion schema, metadata, or other documentation to confirm that the IdP provides either a claim or attribute conveying the AAL of the subscriber account, or a defined mechanism by which no AAL claim is made in the assertion format used by the IdP.</p>
      </part>
      <part id="RXAL-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a transaction in which the IdP asserts an AAL value and determine that the assertion or associated message includes that value. Then, initiate a transaction in which the IdP omits an AAL claim and determine that the assertion output matches the IdP's documented no-claim mechanism.</p>
      </part>
      <part id="RXAL-4_gdn" name="guidance">
        <p>The RP obtains this AAL information from a combination of the terms of the trust agreement (see Sec. 3.5) and information included in the assertion (see Sec. 4.9 and Sec. 5.8).</p>
      </part>
    </control>
    <control id="RXAL-5">
      <title>FAL Reporting</title>
      <prop name="label" class="index" value="2.5 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-5_smt" name="statement">
        <p>The IdP SHALL inform the RP of the following information for each federation transaction: The FAL of the federation transaction.</p>
      </part>
      <part id="RXAL-5_obj" name="objective">
        <p>Determine whether the IdP informs the RP of the FAL for each federation transaction.</p>
        <link href="#RXAL-5_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>If the FAL is static: Satisfied by RXAL-6.</p>
        <p>If the FAL is variable: Examine the IdP assertion schema, metadata, or other documentation to confirm that the IdP provides a claim or attribute that conveys the FAL of the federation transaction.</p>
      </part>
      <part id="RXAL-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a transaction where the IdP asserts an FAL value - verify that the assertion or associated message includes that value.</p>
      </part>
      <part id="RXAL-5_gdn" name="guidance">
        <p>The RP obtains this FAL information from a combination of the terms of the trust agreement (see Sec. 3.5) and information included in the assertion (see Sec. 4.9 and Sec. 5.8).</p>
      </part>
    </control>
    <control id="RXAL-6">
      <title>Static xALs</title>
      <prop name="label" class="index" value="2.5 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-6_smt" name="statement">
        <p>If the xAL is unchanging for all messages between the IdP and RP (e.g., enterprise scenarios in which all subscribers are identity-proofed at the same IAL and use the same authenticator type), the xAL information SHALL be included in the terms of the trust agreement between the IdP and RP.</p>
      </part>
      <part id="RXAL-6_obj" name="objective">
        <p>Determine whether the xAL information is included in the terms of the trust agreement between the IdP and RP when the xAL is unchanging for all messages.</p>
        <link href="#RXAL-6_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) the IdP has established with its RPs to verify that values are stated for all static xALs. If PETA-1 item (m) documents fixed xAL values, confirm those values reflect the actual, unchanging xALs for all transactions between the IdP and each RP.</p>
      </part>
      <part id="RXAL-6_gdn" name="guidance">
        <p>Assessment is required when: The xAL is the same for all messages between the IdP and RP (e.g., enterprise scenarios in which all subscribers are identity-proofed at the same IAL and use the same authenticator type).</p>
        <p>The IdP MAY indicate that no claim is made to the IAL or AAL for a given federation transaction. In such cases, no default value is assigned to the resulting xAL by the RP. That is, a federation transaction without an IAL declaration in either the trust agreement or the assertion is functionally considered to have "no IAL" and the RP cannot assume the account meets "IAL1," which is the lowest numbered IAL described in this suite.</p>
      </part>
    </control>
    <control id="RXAL-7">
      <title>Variable xALs</title>
      <prop name="label" class="index" value="2.5 G"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-7_smt" name="statement">
        <p>If the xAL could be within a range of possible values specified by the trust agreement, then sufficient information SHALL be included as part of the assertion contents to allow the RP to determine the xALs.</p>
      </part>
      <part id="RXAL-7_obj" name="objective">
        <p>Determine whether the IdP includes sufficient information in assertions for RPs to determine xALs when values vary within a range.</p>
        <link href="#RXAL-7_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-7_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For IALs: Satisfied by the variable-xAL case in RXAL-3.</p>
        <p>For AALs: Satisfied by the variable-xAL case in RXAL-4.</p>
        <p>For FALs: Satisfied by the variable-xAL case in RXAL-5.</p>
      </part>
      <part id="RXAL-7_gdn" name="guidance">
        <p>Assessment is required when: The xAL is within a range of possible values specified by the trust agreement</p>
      </part>
    </control>
    <control id="RXAL-8">
      <title>xAL Requirements</title>
      <prop name="label" class="index" value="2.5 H"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-8_smt" name="statement">
        <p>The RP SHALL determine the minimum IAL, AAL, and FAL that it is willing to accept for access to any offered functionality and assess all IdP assertions to ensure that these xALs have been met before granting access to protected resources.</p>
      </part>
      <part id="RXAL-8_obj" name="objective">
        <p>Determine whether the RP defines minimum acceptable xALs and validates that incoming assertions meet these requirements before granting access.</p>
        <link href="#RXAL-8_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's Digital Identity Acceptance Statement (DIAS) to confirm that it specifies the minimum IAL, AAL, and FAL required for each offered function. Verify that RP configuration, authorization logic, or policy enforcement mechanisms use these DIAS-defined minimums when evaluating xAL information. Confirm that the RP's evaluation process accepts xALs conveyed through assertions, trust-agreement terms, or both, consistent with how the IdP provides them.</p>
      </part>
      <part id="RXAL-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting transactions where the xALs meet the DIAS-defined minimums - verify that access is granted.</p>
      </part>
      <part id="RXAL-8_asm-test-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting transactions where any xAL falls below the DIAS-defined minimum - verify that access is denied.</p>
      </part>
      <part id="RXAL-8_asm-test-3" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting transactions where required xAL information is absent from both the assertion and trust-agreement terms - verify that access is denied.</p>
      </part>
      <part id="RXAL-8_gdn" name="guidance">
        <p>This requirement mandates that the RP determine the minimum IAL, AAL, and FAL it is willing to accept for access to any offered functionality through the Digital Identity Risk Management (DIRM) process outlined in NIST SP 800-63-4, Section 3, which requires RPs to conduct impact assessments, select initial xALs based on impact, tailor controls if needed, and document decisions in a Digital Identity Acceptance Statement (DIAS). The RP must then assess all IdP assertions to ensure these xALs have been met before granting access to protected resources. The RP must validate the indicated xALs in the assertion (or trust agreement for fixed xALs) against its required minimums, denying access if these requirements are not met. If no xAL claim is made, the RP must treat it as "no level" without defaults (e.g., no assumption of IAL1).</p>
      </part>
    </control>
    <control id="RXAL-9">
      <title>Unmet xAL Requirements</title>
      <prop name="label" class="index" value="2.5 I"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-9_smt" name="statement">
        <p>If IdP responses do not meet the requested parameters, the RP SHALL have a mechanism for addressing these requests (e.g., declining the request or routing the user to an exception handling process).</p>
      </part>
      <part id="RXAL-9_obj" name="objective">
        <p>Determine that the RP has a defined mechanism for handling cases where IdP responses do not meet the RP's requested or required xAL parameters.</p>
        <link href="#RXAL-9_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's documentation and access-control logic to confirm the presence of a defined mechanism, such as request rejection, access denial, or an exception-handling workflow (such as a step-up mechanism) for transactions that do not satisfy the RP's minimum xAL requirements.</p>
      </part>
      <part id="RXAL-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting transactions in which asserted xALs do not meet the RP's required minimums, or required xAL information is missing, and verify that the RP invokes the documented handling mechanism and does not grant protected access unless and until the RP's documented exception process is successfully completed.</p>
      </part>
      <part id="RXAL-9_gdn" name="guidance">
        <p>If an IdP response does not satisfy the RP's required xALs, the RP must have a mechanism for handling the mismatch. Acceptable mechanisms include denying the request or redirecting the user to an exception-handling process.</p>
      </part>
    </control>
    <control id="RXAL-10">
      <title>IAL, AAL, &amp; FAL Reporting</title>
      <prop name="label" class="index" value="2.5 J"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-10_smt" name="statement">
        <p>Consequently, the IdP SHALL provide the RP with sufficient information to determine the IAL, AAL, and the IdP's intended FAL for each federation transaction.</p>
      </part>
      <part id="RXAL-10_obj" name="objective">
        <p>Determine whether the IdP provides the RP with sufficient information to determine the IAL, AAL, and FAL for each federation transaction.</p>
        <link href="#RXAL-10_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-10_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RXAL-3 (IAL), RXAL-4 (AAL), and RXAL-5 (FAL).</p>
      </part>
    </control>
    <control id="RXAL-11">
      <title>RP FAL Compliance</title>
      <prop name="label" class="index" value="2.5 K"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RXAL-11_smt" name="statement">
        <p>The RP SHALL ensure that it meets its obligations in the federation transaction for the FAL declared in the transaction.</p>
      </part>
      <part id="RXAL-11_obj" name="objective">
        <p>Verify that the RP fulfills all RP-specific requirements associated with the FAL declared in each federation transaction.</p>
        <link href="#RXAL-11_smt" rel="assessment-for"/>
      </part>
      <part id="RXAL-11_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by the RP components of the following controls: CFAL-1, CFAL-2, CFAL-3, FAL1-2, FAL1-4, and FAL1-5; additionally by FAL2-1, FAL2-2, and FAL2-6 at FAL2 and above; and at FAL3, by FAL3-3, FAL3-4, FAL3-5, and ASRP-2, and as applicable, HKA-2 plus RPPHBA-1, RPPHBA-3, and RPPHBA-4 when holder-of-key assertions are used, or BAUTH-5 plus RPPHBA-1, RPPHBA-3, and RPPHBA-4 when bound authenticators are used.</p>
      </part>
      <part id="RXAL-11_gdn" name="guidance">
        <p>This requirement states that the RP must adhere to all RP-directed obligations for the FAL declared for the transaction, either in the assertion or the trust agreement. Compliance is demonstrated when the RP satisfies all controls relevant to that FAL.</p>
      </part>
    </control>
    <control id="PROXY-1">
      <title>Proxy FAL Accuracy</title>
      <prop name="label" class="index" value="3.3.3 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PROXY-1_smt" name="statement">
        <p>The FAL of the connection between the proxy and the downstream RP is considered to be the lowest FAL along the entire path, and the proxy SHALL accurately represent this to the downstream RP.</p>
      </part>
      <part id="PROXY-1_obj" name="objective">
        <p>Determine whether a proxy does not mask a lower level FAL from its inbound side.</p>
        <link href="#PROXY-1_smt" rel="assessment-for"/>
      </part>
      <part id="PROXY-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the proxy's downstream federation configuration, xAL signaling logic, and applicable trust agreement terms to determine how the proxy communicates the resulting FAL to the downstream RP.</p>
      </part>
      <part id="PROXY-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a proxied transaction in which the inbound federation leg is at a lower FAL than the downstream leg supports, and determine that the proxy represents the resulting overall FAL to the downstream RP as the lower FAL through the mechanism used in that deployment.</p>
      </part>
      <part id="PROXY-1_gdn" name="guidance">
        <p>Assessment is required when: Proxied federation is used.</p>
        <p>When using a proxy, different federation processes could be used on either side of the proxy. To avoid accidental upgrading of the transaction giving a false perception of security, the overall FAL for the transaction is limited to the lowest FAL used on either side of the proxy. For example, if FAL1 is used inbound to the proxy, but FAL2 (assertion encryption) is used outbound from the proxy, the proxy has to report the entire transaction at FAL1 to the downstream RP.</p>
      </part>
    </control>
    <control id="PROXY-2">
      <title>Proxy Compliance</title>
      <prop name="label" class="index" value="3.3.3 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PROXY-2_smt" name="statement">
        <p>As a consequence, all normative requirements that apply to IdPs and RPs SHALL apply to proxies in their respective roles on each side.</p>
      </part>
      <part id="PROXY-2_obj" name="objective">
        <p>Determine whether a proxy functions as both a compliant IdP and a compliant RP.</p>
        <link href="#PROXY-2_smt" rel="assessment-for"/>
      </part>
      <part id="PROXY-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>This is a summative control. The proxy is assessed against all applicable IdP controls for its IdP-facing role and all applicable RP controls for its RP-facing role.</p>
      </part>
      <part id="PROXY-2_gdn" name="guidance">
        <p>Assessment is required when: Proxied federation is used.</p>
        <p>A proxy needs to fulfill all of the normative requirements for both RPs and IdPs in order to be considered compliant, in addition to any proxy-specific requirements.</p>
      </part>
    </control>
    <control id="PROXY-3">
      <title>Proxy Identifier</title>
      <prop name="label" class="index" value="3.3.3 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PROXY-3_smt" name="statement">
        <p>The federated identifier (see Sec. 3.4) of an assertion from a proxy SHALL indicate the proxy as the issuer of the assertion.</p>
      </part>
      <part id="PROXY-3_obj" name="objective">
        <p>Determine whether the federated identifier of an assertion from a proxy indicates the proxy as the issuer of the assertion.</p>
        <link href="#PROXY-3_smt" rel="assessment-for"/>
      </part>
      <part id="PROXY-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the proxy's assertion templates, identifier-generation logic, or documentation to confirm that assertions issued by the proxy use an identifier that unambiguously represents the proxy itself as the issuer. Verify that no upstream IdP identifiers appear as the federated identifier in proxy-issued assertions.</p>
      </part>
      <part id="PROXY-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by first receiving an assertion from the upstream IdP at the proxy and verifying the upstream IdP is the issuer in the assertion, then by generating an assertion from the proxy to the downstream RP and verifying that the proxy is the issuer in the assertion.</p>
      </part>
      <part id="PROXY-3_gdn" name="guidance">
        <p>Assessment is required when: Proxied federation is used.</p>
        <p>When a proxy acts as an intermediary between an upstream IdP and downstream RP, it creates new assertions based on upstream assertions. The federated identifier in the proxy's assertion must show the proxy as the issuer, not the original upstream IdP. This ensures proper attribution and prevents confusion about the assertion's source.</p>
      </part>
    </control>
    <control id="FEDID-1">
      <title>Unique Federated Identifiers</title>
      <prop name="label" class="index" value="3.4 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FEDID-1_smt" name="statement">
        <p>When federated identifiers are used, the federated identifier SHALL be unique to that subscriber.</p>
      </part>
      <part id="FEDID-1_obj" name="objective">
        <p>Determine whether the IdP/CSP assigns identifiers that are unique to each subscriber.</p>
        <link href="#FEDID-1_smt" rel="assessment-for"/>
      </part>
      <part id="FEDID-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>This is a definitional statement, not an independently assessable requirement. Subject identifier uniqueness is an inherent property of any functioning IdP or CSP identity system. Enforcement of federated identifier uniqueness is satisfied by FEDID-2.</p>
      </part>
      <part id="FEDID-1_gdn" name="guidance">
        <p>Assessment is required when: Federated identifiers are used.</p>
      </part>
    </control>
    <control id="FEDID-2">
      <title>Federated Identifier Single-Subscriber Association</title>
      <prop name="label" class="index" value="3.4 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FEDID-2_smt" name="statement">
        <p>Federated identifiers SHALL be associated with a single subscriber at the RP.</p>
      </part>
      <part id="FEDID-2_obj" name="objective">
        <p>Determine whether the RP associates each federated identifier with a single subscriber.</p>
        <link href="#FEDID-2_smt" rel="assessment-for"/>
      </part>
      <part id="FEDID-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For IdP transactions: Satisfied by ARTC-11.</p>
        <p>For subscriber-controlled wallet transactions: Satisfied by ARTCN-11.</p>
      </part>
      <part id="FEDID-2_gdn" name="guidance">
        <p>Assessment is required when: Federated identifiers are used.</p>
        <p>Different IdPs manage their subject identifiers independently and may assign identical values to different subscribers. The RP must never process a subject identifier without accounting for the issuer. Failure to do so creates a collision risk where subscribers from different IdPs are incorrectly mapped to the same RP subscriber account.</p>
      </part>
    </control>
    <control id="PPI-1">
      <title>PPI Uniqueness</title>
      <prop name="label" class="index" value="3.4.1.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-1_smt" name="statement">
        <p>When using pairwise pseudonymous identifiers within the assertions generated by the IdP for the RP, the IdP SHALL generate a different federated identifier for each RP (see Sec. 3.4.1.2) or set of RPs (see Sec. 3.4.1.3).</p>
      </part>
      <part id="PPI-1_obj" name="objective">
        <p>Determine whether the IdP generates unique pairwise pseudonymous identifiers for each RP or authorized set of RPs.</p>
        <link href="#PPI-1_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the PPI generation algorithm to confirm that it produces different outputs for each RP or authorized RP set.</p>
      </part>
      <part id="PPI-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by logging the same subscriber into two unrelated RPs - verify different identifiers are asserted.</p>
      </part>
      <part id="PPI-1_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used.</p>
        <p>In some circumstances, it is desirable to prevent the subscriber account from being easily linked at multiple RPs through the use of a common subject identifier. A pairwise pseudonymous identifier (PPI) allows an IdP to provide multiple distinct federated identifiers to different RPs for a single subscriber account. The use of a PPI prevents different RPs from colluding to track the subscriber using the federated identifier.</p>
      </part>
    </control>
    <control id="PPI-2">
      <title>PPI Correlation Prevention</title>
      <prop name="label" class="index" value="3.4.1.1 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-2_smt" name="statement">
        <p>If PPIs are used alongside identifying attributes, RPs SHALL establish privacy policies, processes, and procedures to prevent the correlation of subscriber data consistent with applicable legal and regulatory requirements.</p>
      </part>
      <part id="PPI-2_obj" name="objective">
        <p>Determine whether RPs prevent correlation of subscriber data when using PPIs alongside identifying attributes.</p>
        <link href="#PPI-2_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the privacy policies, data-handling procedures, and data-sharing agreements to confirm they explicitly address the use of PPIs together with identifying attributes and prohibit correlating subscriber records or activity across organizations except where required or explicitly permitted by applicable law or regulation.</p>
      </part>
      <part id="PPI-2_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used.</p>
        <p>Some identity attributes such as names, physical addresses, phone numbers, email addresses, and others can be used to identify a subscriber outside of a federation transaction. When PPIs are used alongside these kinds of identifying attributes, it may still be possible for multiple colluding RPs to re-identify a subscriber by correlation across systems. For example, if two independent RPs each see the same subscriber identified with a different PPI, the RPs could still determine that the subscriber is the same person by comparing the name, email address, physical address, or other identifying attributes carried alongside the PPI in the respective assertions.</p>
      </part>
    </control>
    <control id="PPI-3">
      <title>PPI Mapping as Subscriber Information</title>
      <prop name="label" class="index" value="3.4.1.1 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-3_smt" name="statement">
        <p>If a proxy is used: The mapping of a PPI to other identifiers is considered subscriber information and SHALL be treated in accordance with the requirements in Sec. 3.10.1.</p>
      </part>
      <part id="PPI-3_obj" name="objective">
        <p>Determine whether the proxy treats PPI-to-identifier mappings as subscriber information subject to Section 3.10.1 requirements.</p>
        <link href="#PPI-3_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by applying TSI-1,  TSI-2, and TSI-3 to the PPI mapping data.</p>
      </part>
      <part id="PPI-3_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used.</p>
        <p>In a proxied federation model (see Sec. 3.3.3), the upstream IdP may not be able to generate a PPI for the downstream RP, since the proxy could blind the IdP from knowing which RP is being accessed by the subscriber. In such situations, the PPI is generally established between the IdP and the federation proxy. Acting as an IdP, the proxy can provide a PPI to the downstream RP. Depending on the protocol, the federation proxy may need to map the PPI back to the associated identifiers from upstream IdPs in order to allow the identity protocol to function. In such cases, the proxy will be able to track and determine which PPIs represent the same subscriber at different RPs.</p>
      </part>
    </control>
    <control id="PPI-4">
      <title>Anonymous PPIs</title>
      <prop name="label" class="index" value="3.4.1.2 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-4_smt" name="statement">
        <p>The PPI SHALL contain no identifying information about the subscriber (e.g., username, email address, employee number).</p>
      </part>
      <part id="PPI-4_obj" name="objective">
        <p>Determine whether pairwise identifiers contain any identifying information about the subscriber.</p>
        <link href="#PPI-4_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation and generation algorithm used by the IdP to assign a pairwise identifier to a subscriber at an RP.</p>
      </part>
      <part id="PPI-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating an assertion containing a PPI, then inspecting the resulting identifier to confirm it contains no readable personal information, such as usernames, email addresses, or employee numbers.</p>
      </part>
      <part id="PPI-4_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used.</p>
        <p>Pairwise identifiers are intended to protect the privacy of the subscriber and prevent collation of subscriber information. If the identifier itself has any identifying information in it, such as a username or employee number, this protection is lost. To prevent this, pairwise identifiers should be random and unguessable values or generated using information known only to the IdP, such as a secret key. If pairwise identifiers are not used, this requirement does not apply.</p>
      </part>
    </control>
    <control id="PPI-5">
      <title>Unguessable PPIs</title>
      <prop name="label" class="index" value="3.4.1.2 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-5_smt" name="statement">
        <p>The PPI SHALL be difficult to guess by a party with access to information about the subscriber.</p>
      </part>
      <part id="PPI-5_obj" name="objective">
        <p>Determine whether pairwise identifiers can be guessed or easily generated by a party with access to subscriber information.</p>
        <link href="#PPI-5_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the PPI generation algorithm to confirm that outputs cannot be predicted by a party with knowledge of the subscriber's attributes. Verify that generation relies on inputs known only to the IdP (e.g., a secret key) or uses an approved random bit generator.</p>
      </part>
      <part id="PPI-5_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used.</p>
      </part>
    </control>
    <control id="PPI-6">
      <title>PPI Brute Force Protection</title>
      <prop name="label" class="index" value="3.4.1.2 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-6_smt" name="statement">
        <p>The PPI...SHALL provide sufficient entropy as to be unguessable by an attacker.</p>
      </part>
      <part id="PPI-6_obj" name="objective">
        <p>Determine whether PPIs provide sufficient entropy to be unguessable by an attacker.</p>
        <link href="#PPI-6_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the mechanism used to generate the Pairwise Pseudonymous Identifier (PPI). If the PPI is generated as a random value, verify it is produced by an approved random bit generator with a security strength of at least 112 bits. If the PPI is derived from other subscriber information (e.g., using a key derivation function), verify the derivation uses an approved key derivation function with a secret key of at least 112 bits of security strength, as discussed in SP 800-131A.</p>
      </part>
      <part id="PPI-6_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used.</p>
        <p>Per NIST SP 800-131A Rev 2, Section 1.2.1, "a security strength of at least 112 bits is required at this time for applying cryptographic protection." This establishes the technical floor for what constitutes "sufficient entropy" to be "unguessable."</p>
      </part>
    </control>
    <control id="PPI-7">
      <title>PPIs Unique to Each RP</title>
      <prop name="label" class="index" value="3.4.1.2 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-7_smt" name="statement">
        <p>Unless the PPI is designated as shared by the trust agreement, the PPI SHALL be disclosed to only a single RP.</p>
      </part>
      <part id="PPI-7_obj" name="objective">
        <p>Determine whether PPIs are disclosed to only a single RP unless designated as shared by the trust agreement artifact(s).</p>
        <link href="#PPI-7_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-7_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by  PPI-1.</p>
      </part>
      <part id="PPI-7_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used.</p>
      </part>
    </control>
    <control id="PPI-8">
      <title>Justification and Consent for Shared PPIs</title>
      <prop name="label" class="index" value="3.4.1.3 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-8_smt" name="statement">
        <p>The same shared PPI SHALL be used for a specific set of RPs if all of the following criteria are met:</p>
        <p>(a) The trust agreement stipulates a shared PPI for a specific set of RPs.</p>
        <p>(b) The authorized party consents to and is notified of the use of a shared PPI.</p>
        <p>(c) Those RPs have a demonstrable relationship that justifies an operational need for the correlation, such as a shared security domain or shared legal ownership.</p>
        <p>(d) All RPs in the set of a shared PPI consent to being correlated in such a manner (i.e., one RP cannot request to have another RP's PPI without that other RP's knowledge and consent).</p>
      </part>
      <part id="PPI-8_obj" name="objective">
        <p>Determine whether shared PPIs are issued only when all four criteria are satisfied.</p>
        <link href="#PPI-8_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust agreement artifact(s) to confirm they stipulate a shared PPI for a specific, named set of RPs. Identify the authorized party and confirm documentation of their notification and consent to the shared PPI. Review documentation of the relationship between the RPs in the set to confirm a demonstrable operational need for correlation (e.g., shared security domain, shared legal ownership). Confirm that each RP in the set has documented consent to being correlated with the other RPs in the set.</p>
      </part>
      <part id="PPI-8_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used and common pairwise identifiers are requested by RPs.</p>
      </part>
    </control>
    <control id="PPI-9">
      <title>Privacy Risks with Shared PPIs</title>
      <prop name="label" class="index" value="3.4.1.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-9_smt" name="statement">
        <p>The RPs SHALL conduct a privacy risk assessment to consider the privacy risks associated with requesting a shared PPI. See Sec. 7.2 for further privacy considerations.</p>
      </part>
      <part id="PPI-9_obj" name="objective">
        <p>Determine whether the RPs have conducted a privacy risk assessment before requesting a common identifier.</p>
        <link href="#PPI-9_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP privacy risk assessment specific to its use of a shared PPI, verifying that it addresses the risks of subscriber correlation across the RPs in the shared set.</p>
      </part>
      <part id="PPI-9_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used and common pairwise identifiers are requested by RPs.</p>
        <p>If an RP requests a common pairwise identifier, a privacy risk assessment can help the RP consider the likelihood that requesting the same identifier for a subscriber at multiple RPs could create a problem for the applicant and the impact if a problem did occur. The RP should be able to justify any response it takes to identified privacy risks, including accepting the risk, mitigating the risk, and sharing the risk. If common pairwise identifiers are not used, this requirement does not apply.</p>
      </part>
    </control>
    <control id="PPI-10">
      <title>Shared PPIs only between Authorized RPs</title>
      <prop name="label" class="index" value="3.4.1.3 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PPI-10_smt" name="statement">
        <p>The IdP SHALL ensure that only intended RPs are included in the set.</p>
      </part>
      <part id="PPI-10_obj" name="objective">
        <p>Determine whether only RPs that have been explicitly configured to use a common identifier are given the common identifier.</p>
        <link href="#PPI-10_smt" rel="assessment-for"/>
      </part>
      <part id="PPI-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine by comparing the IdP's configured shared PPI sets against the authorized RP sets documented in the trust agreement artifact(s). Confirm that no RP appears in a shared PPI set without corresponding authorization.</p>
      </part>
      <part id="PPI-10_gdn" name="guidance">
        <p>Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used and common pairwise identifiers are requested by RPs.</p>
      </part>
    </control>
    <control id="TRUST-1">
      <title>Trust Agreement Establishment</title>
      <prop name="label" class="index" value="3.5 A"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-1_smt" name="statement">
        <p>A trust agreement SHALL address one or more of the following relationships: IdP to CSP: The IdP trusts the CSP to provide access to attributes in subscriber accounts, through either an IdP onboarding process or the issuance of attribute bundles. The IdP trusts the CSP's identity proofing processes used in the establishment of the subscriber account.</p>
        <p>CSP to IdP: The CSP trusts the IdP to accurately represent subscriber identity attributes to RPs and to not disclose identity attributes outside of agreed-upon functionality. The CSP trusts the IdP to protect the release of attributes, such as requiring authentication of the subscriber or the presentation of an activation factor before attributes are released.</p>
        <p>RP to IdP: The RP trusts the IdP to accurately represent subscriber identity attributes as provided by the CSP. The RP trusts the IdP to authenticate or identify the subscriber when representing an authentication event.</p>
        <p>IdP to RP: The IdP trusts the RP to only use the requested attributes for its stated purposes</p>
        <p>RP to CSP: The RP trusts the CSP to provide access to subscriber identity attributes through IdPs. The RP trusts that the CSP has identity-proofed the subscriber and is managing the subscriber account.</p>
      </part>
      <part id="TRUST-1_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) address the trust relationships applicable to the federation deployment.</p>
        <link href="#TRUST-1_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the set of federation relationships and verify that the trust agreement artifact(s) address each one. For each relationship addressed, verify that the artifact(s) document the parties' specific trust expectations.</p>
      </part>
    </control>
    <control id="TRUST-2">
      <title>TAs for All Federation Transactions</title>
      <prop name="label" class="index" value="3.5 B"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-2_smt" name="statement">
        <p>All federation transactions SHALL be governed by the terms of one or more trust agreements between the applicable parties.</p>
      </part>
      <part id="TRUST-2_obj" name="objective">
        <p>Determine whether all trust agreement requirements are met by all federation parties for all federation transactions.</p>
        <link href="#TRUST-2_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by PETA-1 through PETA-7 for pre-established trust agreements, or SDTAE-1 through SDTAE-4 for subscriber-driven trust agreements; by MTA-1 through MTA-9 when a multilateral trust agreement is used; and by TAGREE-1 through TAGREE-3, CR-1, CR-2, CSCW-1, CSCW-2, and RSCW-1 when subscriber-controlled wallets are used.</p>
      </part>
      <part id="TRUST-2_gdn" name="guidance">
        <p>Trust agreements can take different forms, including formal contractual agreements, informal dynamic user agreements, and other documented bilateral or multilateral trust decisions by the parties in the federation. In many cases, trust agreements can be implemented using a trust framework, which formalizes a set of rules for parties to connect with each other. Trust frameworks are often used by federation authorities to formalize the rules for the federation being managed by the federation authority.</p>
      </part>
    </control>
    <control id="TRUST-3">
      <title>TA Customer Experience</title>
      <prop name="label" class="index" value="3.5 C"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-3_smt" name="statement">
        <p>The trust agreement SHALL establish customer experience requirements for the federation transaction, as discussed in Sec. 8.</p>
      </part>
      <part id="TRUST-3_obj" name="objective">
        <p>Determine whether trust agreements establish customer experience requirements for federation transactions that involve the user.</p>
        <link href="#TRUST-3_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to verify that they include customer experience requirements for the federation transaction.</p>
      </part>
      <part id="TRUST-3_gdn" name="guidance">
        <p>Trust agreements must define customer experience parameters for federation transactions. Section 8 provides informative guidance that parties should consider when establishing these requirements. The specific customer experience requirements will vary based on the federation implementation and use case.</p>
      </part>
    </control>
    <control id="TRUST-4">
      <title>TA CSP Proofing Process</title>
      <prop name="label" class="index" value="3.5 D"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-4_smt" name="statement">
        <p>The trust agreement SHALL include details of the proofing process used at the CSP for subscribers covered by the trust agreement, including any compensating controls and exception handling processes.</p>
      </part>
      <part id="TRUST-4_obj" name="objective">
        <p>Determine whether the RP has access to the details of the proofing process used at the CSP for subscribers covered by the trust agreement, including any compensating controls and exception handling processes.</p>
        <link href="#TRUST-4_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifacts for details on the CSP proofing process, compensating controls, and exception-handling procedures.</p>
      </part>
      <part id="TRUST-4_gdn" name="guidance">
        <p>The required information may be conveyed directly by the CSP or relayed through the IdP, but it must be available to the relying party because the relying party is responsible for making risk based decisions.</p>
      </part>
    </control>
    <control id="TRUST-5">
      <title>TA Subscriber Population</title>
      <prop name="label" class="index" value="3.5 E"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-5_smt" name="statement">
        <p>All trust agreements SHALL define a specific population of subscriber accounts to which the agreement is applicable.</p>
      </part>
      <part id="TRUST-5_obj" name="objective">
        <p>Determine whether each participating party identifies the set of subscriber accounts covered by the relationship and documents how that population is scoped.</p>
        <link href="#TRUST-5_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifacts to verify that the population of subscriber accounts covered by the federated relationship is explicitly defined.</p>
      </part>
      <part id="TRUST-5_gdn" name="guidance">
        <p>The exact means of defining this population are out of scope for this document. In many cases, the population is defined as the full set of subscriber accounts that the CSP manages and makes available through an IdP. In other cases, the population is a demarcated subset of accounts that are available through an IdP. It is also possible for an RP to have a distinct trust agreement established with an IdP for a single subscriber account, such as in a subscriber-driven trust agreement. For pre-established trust agreement artifact(s), this requirement is also addressed by PETA-1 item (e).</p>
      </part>
    </control>
    <control id="TRUST-6">
      <title>Combined Trust Agreement Artifact(s)</title>
      <prop name="label" class="index" value="3.5 F"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-6_smt" name="statement">
        <p>If more than one trust agreement is applicable to a federation transaction, the combined set of terms of all applicable trust agreements SHALL constitute the effective trust agreement of that transaction.</p>
      </part>
      <part id="TRUST-6_obj" name="objective">
        <p>Determine whether federation transactions are governed by an unambiguous set of trust agreement artifact(s) and whether each transaction meets the requirements of all applicable trust agreement artifact(s).</p>
        <link href="#TRUST-6_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the set of trust agreement artifacts applicable to the federation relationship (e.g., bilateral contracts, Memoranda of Understanding (MOUs), Interconnection Security Agreements (ISAs), federation authority operating rules, or subscriber terms of service). Then, review a representative sample of federation transactions, verifying that each transaction adheres to the combined requirements of all applicable trust agreement artifacts.</p>
      </part>
      <part id="TRUST-6_gdn" name="guidance">
        <p>If the combination of multiple agreements creates the potential for conflicting requirements, the parties should have a documented process or order of precedence to resolve those conflicts.</p>
      </part>
    </control>
    <control id="TRUST-7">
      <title>Expected and Acceptable xALs</title>
      <prop name="label" class="index" value="3.5 G"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-7_smt" name="statement">
        <p>Trust agreements SHALL establish terms regarding expected and acceptable IALs, AALs, and FALs in connection with the federated relationship.</p>
      </part>
      <part id="TRUST-7_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) establish terms regarding expected and acceptable IALs, AALs, and FALs for the federation relationship.</p>
        <link href="#TRUST-7_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-7_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For pre-established trust agreement artifact(s): Satisfied by PETA-1 items (m) and (n).</p>
        <p>For subscriber-driven trust agreement artifact(s): Satisfied by SDTAE-1.</p>
      </part>
    </control>
    <control id="TRUST-8">
      <title>Redress Coordination</title>
      <prop name="label" class="index" value="3.5 H"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-8_smt" name="statement">
        <p>Trust agreements SHALL define necessary mechanisms and materials to coordinate redress and issues between the different participants in the federation, as discussed in Sec. 3.5.3.</p>
      </part>
      <part id="TRUST-8_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) explicitly define the mechanisms (e.g., processes, protocols, escalation paths) and materials (e.g., templates, contact information, shared documentation) required for coordinating the resolution of issues and providing redress among all participants in the federation.</p>
        <link href="#TRUST-8_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifacts (e.g., federation agreements, operating rules, policies, metadata, onboarding documentation) for provisions addressing inter-party coordination of redress and issues, including: contact information or escalation paths for each party, procedures for routing subscriber complaints across party boundaries, defined responsibilities when issues span multiple parties, and timelines or service-level expectations for inter-party communications on subscriber issues.</p>
      </part>
      <part id="TRUST-8_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview representatives from each federation party to verify awareness of and adherence to documented coordination mechanisms, including understanding of how to escalate issues to partner organizations and what information is exchanged during coordination.</p>
      </part>
      <part id="TRUST-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by simulating a cross-party redress scenario (e.g., a subscriber complaint involving inaccurate attributes from the CSP affecting an RP session) and observing whether the agreement's mechanisms enable effective coordination and resolution.</p>
      </part>
      <part id="TRUST-8_gdn" name="guidance">
        <p>Federation transactions occur between multiple parties that are often controlled by multiple entities, and different stages of the federation transaction can lead to situations in which a subscriber would need to seek redress from the other parties.</p>
        <p>Federation, therefore, creates distributed responsibility for subscriber redress. A subscriber issue may originate at the RP but require resolution by the IdP or CSP, or may involve multiple parties simultaneously. Section 3.5.3 establishes specific redress obligations for each party type, but those individual requirements (covered in controls RR-1 through RR-6) address subscriber-facing mechanisms. This control addresses the coordination layer: how parties coordinate to resolve cross-organizational issues.</p>
        <p>The "mechanisms and materials" may include escalation procedures, contact directories, agreed-upon response timeframes, information-sharing protocols for issue investigation, and processes for jointly resolving disputes. In federations operating under a federation authority, these coordination mechanisms may be defined in the trust framework's operating rules. In bilateral relationships, they may be documented in contracts or service agreements.</p>
        <p>This control is a prerequisite for RR-2, which requires the RP to provide the subscriber with a means of initiating the redress process with the IdP or CSP. That subscriber-facing capability depends on the inter-party coordination mechanisms assessed here.</p>
        <p>This control does not assess whether subscribers have access to redress (see RR-1 through RR-6); it assesses whether the parties have established the infrastructure to work together when redress requires coordination.</p>
      </part>
    </control>
    <control id="TRUST-9">
      <title>Data Retention Policies</title>
      <prop name="label" class="index" value="3.5 I"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-9_smt" name="statement">
        <p>Trust agreements SHALL declare the data retention policies expected of all parties.</p>
      </part>
      <part id="TRUST-9_obj" name="objective">
        <p>Determine whether trust agreement artifact(s) declare the data retention policies expected of each federation party.</p>
        <link href="#TRUST-9_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifacts (e.g., federation agreements, operating rules, data processing agreements, privacy policies referenced in agreements) for declarations of data retention policies applicable to each party, including: types of data subject to retention requirements, retention periods or criteria for determining retention periods, conditions under which retention requirements may differ (e.g., regulatory constraints, risk-based justifications), and expectations for data deletion upon account termination.</p>
      </part>
      <part id="TRUST-9_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview representatives from each federation party to confirm awareness of declared retention policies and how those policies are operationalized within their organization.</p>
      </part>
      <part id="TRUST-9_gdn" name="guidance">
        <p>Data retention policies govern how long each party retains subscriber information, under what conditions, and what happens to that data when accounts are terminated. Declaring these policies in the trust agreement ensures that all parties share expectations and enables subscribers to understand how their data will be handled across the federation.</p>
        <p>Section 2.4.2 of SP 800-63B-4 requires verifiers to comply with applicable records retention policies and conduct risk management processes to determine retention periods when no mandatory requirements apply. The trust agreement should reflect these determinations for federation contexts.</p>
        <p>Different parties may have different retention requirements based on their regulatory environment (e.g., NARA schedules for federal agencies, industry-specific requirements). The trust agreement need not mandate uniform retention periods but must declare what each party's policies are so that expectations are clear.</p>
      </part>
    </control>
    <control id="TRUST-10">
      <title>Subscriber Disclosure</title>
      <prop name="label" class="index" value="3.5 J"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-10_smt" name="statement">
        <p>As such, the relevant terms of the trust agreement SHALL be made available to subscribers in clear and understandable language.</p>
      </part>
      <part id="TRUST-10_obj" name="objective">
        <p>Determine whether the relevant terms of the trust agreement are made available to subscribers in clear and understandable language.</p>
        <link href="#TRUST-10_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the subscriber-facing disclosures of trust agreement terms (e.g., web pages, notices, runtime decision summaries) for clarity, readability (e.g. a Flesch-Kincaid score of 70 or higher), and avoidance of technical jargon. Verify that the disclosure mechanism is accessible to subscribers and that the content addresses the terms relevant to the subscriber's participation in the federation.</p>
      </part>
      <part id="TRUST-10_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to access trust agreement terms through subscriber-facing channels, then evaluating whether the terms are presented in plain language appropriate to the expected subscriber population.</p>
      </part>
      <part id="TRUST-10_gdn" name="guidance">
        <p>Although subscribers are not generally directly involved in the trust agreement's terms, they are affected by those terms and the resulting federation transactions. This requirement ensures that subscribers can understand how their identity information will be handled, what attributes may be shared, and what rights and recourse they have. As stated in section 7.2, "a link to a complex, legalistic privacy policy or general terms and conditions that a substantial number of subscribers do not read or understand is never an effective notice." The disclosure must be genuinely comprehensible, not merely technically available. Common disclosure methods identified in Section 3.5 include: providing a subscriber-accessible web page with relevant terms, sending a notice to the subscriber, or displaying a summary of the terms during a runtime decision, with an option to review the full terms. The party responsible for disclosure varies based on the trust agreement. Section 3.5 does not specify which party must provide notice; parties may use contracts or trust framework policies to determine responsibility. This control assesses whether disclosure occurs and meets clarity requirements, regardless of which party provides it. SP 800-63A-4 Section 8.1.1 provides guidance applicable here: write in plain language, avoid technical jargon, tailor language to the literacy level of the intended population, use active voice and conversational style, and follow good information design practices. Related controls PETA-3 (4.3.1 C) and SDTAE-1 (4.3.2 A) address specific disclosure requirements for pre-established and subscriber-driven trust agreements, respectively.</p>
      </part>
    </control>
    <control id="TRUST-11">
      <title>Disclosure Security Review</title>
      <prop name="label" class="index" value="3.5 K"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUST-11_smt" name="statement">
        <p>The terms of the trust agreement SHALL be reviewed by all parties (e.g., the CSP, IdP, RP, or a federation authority) that are responsible for informing the subscriber of the terms of the trust agreement before the disclosure to the subscriber occurs in order to avoid revealing sensitive security information.</p>
      </part>
      <part id="TRUST-11_obj" name="objective">
        <p>Determine whether all parties responsible for informing subscribers of trust agreement terms have reviewed those terms before disclosure to avoid revealing sensitive security information.</p>
        <link href="#TRUST-11_smt" rel="assessment-for"/>
      </part>
      <part id="TRUST-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation of the review process, including records of which parties participated in the review, what was reviewed, and any redactions or modifications made to protect sensitive security information. Examine the subscriber-facing disclosure to verify that sensitive security details (e.g., security monitoring capabilities, fraud detection thresholds) are not exposed.</p>
      </part>
      <part id="TRUST-11_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview representatives from each party responsible for subscriber disclosure to confirm that a review occurred prior to disclosure and to understand the criteria used to identify and protect sensitive security information.</p>
      </part>
      <part id="TRUST-11_gdn" name="guidance">
        <p>This control is a prerequisite for TRUST-10, which requires that trust agreement terms be disclosed to subscribers in clear, understandable language. While subscribers need sufficient information to understand how their data is handled, the disclosure must not inadvertently reveal security details that could be exploited by attackers. Sensitive security information that should be protected from disclosure may include specific fraud-detection mechanisms, security-monitoring thresholds, incident-response procedures, cryptographic implementation details beyond what is necessary for subscriber understanding, and internal system architecture that could aid targeted attacks. The review must include all parties responsible for informing subscribers. Which parties bear this responsibility depends on the trust agreement structure: in bilateral agreements, the IdP and RP coordinate directly; in multilateral agreements, the federation authority may also be involved.</p>
      </part>
    </control>
    <control id="MTA-1">
      <title>MTA Vetting Practices</title>
      <prop name="label" class="index" value="3.5.2 A"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-1_smt" name="statement">
        <p>The trust agreement SHALL enumerate the required practices for vetting all parties.</p>
      </part>
      <part id="MTA-1_obj" name="objective">
        <p>Determine whether the multilateral trust agreement (MTA) artifact(s) enumerate(s) the required practices for vetting all parties.</p>
        <link href="#MTA-1_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust framework documentation (e.g., operating rules, membership agreements, onboarding policies) for enumeration of vetting practices applicable to CSPs, IdPs, and RPs.</p>
      </part>
      <part id="MTA-1_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>This control applies to multilateral trust agreements in which a federation authority facilitates onboarding of CSPs, IdPs, and RPs. The subsequent requirements in Section 3.5.2 (MTA-2 and following) establish minimum criteria that vetting must address. This control assesses whether the trust agreement documents vetting practices; the substantive vetting criteria are assessed separately.</p>
        <p>NISTIR 8149 (Developing Trust Frameworks to Support Identity Federations) provides additional context on conformance assessment approaches, including self-assessment, third-party assessment, and audit, which federations may use to implement vetting.</p>
      </part>
    </control>
    <control id="MTA-2">
      <title>MTA Vetting Responsibility</title>
      <prop name="label" class="index" value="3.5.2 B"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-2_smt" name="statement">
        <p>The trust agreement ... SHALL indicate the party or parties that are responsible for performing the vetting process.</p>
      </part>
      <part id="MTA-2_obj" name="objective">
        <p>Determine whether the multilateral trust agreement artifact(s) indicate(s) the party or parties responsible for performing the vetting process.</p>
        <link href="#MTA-2_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust framework documentation  (e.g., operating rules, membership agreements, onboarding policies) for an explicit designation of the party or parties responsible for vetting CSPs, IdPs, and RPs.</p>
      </part>
      <part id="MTA-2_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>This control complements MTA-1, which requires enumeration of vetting practices. This control ensures accountability by requiring a clear assignment of vetting responsibility.</p>
        <p>Section 3.5.2 notes that "the federation authority can outsource the vetting process to another party, but the federation authority is ultimately responsible for the results of the vetting process." The trust agreement must make clear who performs vetting, whether that is the federation authority itself, a delegated third-party assessor, or another arrangement. Outsourcing vetting does not transfer ultimate accountability from the federation authority.</p>
      </part>
    </control>
    <control id="MTA-3">
      <title>MTA Vetting: CSP Subscriber Proofing</title>
      <prop name="label" class="index" value="3.5.2 C"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-3_smt" name="statement">
        <p>At a minimum, the vetting of CSPs, IdPs, and RPs SHALL establish that:</p>
        <p>(1) CSPs identity proof subscriber accounts in accordance with [SP800-63A].</p>
      </part>
      <part id="MTA-3_obj" name="objective">
        <p>Determine whether the federation authority's vetting process establishes that CSPs identity proof subscriber accounts in accordance with SP 800-63A.</p>
        <link href="#MTA-3_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine federation authority vetting procedures, checklists, and assessment criteria to verify that CSP identity proofing practices are evaluated against SP 800-63A requirements for each IAL offered by the CSP.</p>
      </part>
      <part id="MTA-3_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>This is the first of six minimum vetting criteria specified in Section 3.5.2. The federation authority's vetting process must verify that CSPs perform identity proofing consistent with SP 800-63A requirements for the applicable IAL(s) supported by the federation. SP 800-63A-4 establishes requirements for identity proofing at IAL1, IAL2, and IAL3, including evidence collection, validation, and verification processes. The depth of vetting should be commensurate with the IALs the federation supports.</p>
      </part>
    </control>
    <control id="MTA-4">
      <title>MTA Vetting: CSP Subscriber Onboarding</title>
      <prop name="label" class="index" value="3.5.2 D"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-4_smt" name="statement">
        <p>The vetting of CSPs, IdPs, and RPs SHALL establish that:</p>
        <p>(2) CSPs onboard subscriber accounts (including attributes, derived attribute values, and attribute bundles) to IdPs in a secure fashion in adherence to the requirements in Sec. 4.1 or Sec. 5.1, as applicable.</p>
      </part>
      <part id="MTA-4_obj" name="objective">
        <p>Determine whether the federation authority's vetting process establishes that CSPs onboard subscriber accounts to IdPs securely in accordance with Section 4.1 (general-purpose IdPs) or Section 5.1 (subscriber-controlled wallets), as applicable to the federation model.</p>
        <link href="#MTA-4_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine federation authority vetting procedures, checklists, and assessment criteria to verify that CSP onboarding practices are evaluated against the requirements in Section 4.1 for IdP account provisioning or Section 5.1 for attribute bundle issuance to subscriber-controlled wallets, as applicable to the federation's supported models.</p>
      </part>
      <part id="MTA-4_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>Section 4.1 governs how CSPs provision subscriber accounts to general-purpose IdPs, including the disclosure of provisioning methods in the trust agreement, and the relationship between subscriber accounts and federation-specific attributes. Section 5.1 governs how CSPs issue attribute bundles to subscriber-controlled wallets, including the steps for subscriber identity verification, wallet activation, key generation, and attribute bundle creation. The applicable section depends on the federation model: Section 4.1 applies when the federation uses general-purpose IdPs hosted on remote services; Section 5.1 applies when the federation supports subscriber-controlled wallets. A federation may support both models, in which case vetting must address both sections.</p>
      </part>
    </control>
    <control id="MTA-5">
      <title>MTA Vetting: Subscriber Authenticators</title>
      <prop name="label" class="index" value="3.5.2 E"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-5_smt" name="statement">
        <p>The vetting of CSPs, IdPs, and RPs SHALL establish that:</p>
        <p>(3) The authenticators used to authenticate the subscriber at the IdP (during a federation transaction) or CSP (while issuing attribute bundles to a subscriber controlled wallet) are used in accordance with [SP800-63B].</p>
      </part>
      <part id="MTA-5_obj" name="objective">
        <p>Determine whether the federation authority's vetting process establishes that the authenticators used to authenticate subscribers at the IdP and/or CSP comply with SP 800-63B requirements.</p>
        <link href="#MTA-5_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine federation authority vetting procedures, checklists, and assessment criteria to verify that authenticator usage is evaluated against SP 800-63B requirements for each AAL supported by the IdP or CSP.</p>
      </part>
      <part id="MTA-5_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>This requirement addresses two authentication contexts: (1) authentication of the subscriber at the IdP during a federation transaction with a general-purpose IdP, and (2) authentication of the subscriber at the CSP when issuing attribute bundles to a subscriber-controlled wallet.</p>
        <p>SP 800-63B-4 establishes requirements for authenticator types, authenticator lifecycle management, and authentication processes at AAL1, AAL2, and AAL3. The depth of vetting should be commensurate with the AALs the federation supports.</p>
      </part>
    </control>
    <control id="MTA-6">
      <title>MTA Vetting: IdP Assertions</title>
      <prop name="label" class="index" value="3.5.2 F"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-6_smt" name="statement">
        <p>The vetting of CSPs, IdPs, and RPs SHALL establish that:</p>
        <p>(4) The assertions generated by IdPs adhere to the requirements in Sec. 4.9 or Sec. 5.8, as applicable.</p>
      </part>
      <part id="MTA-6_obj" name="objective">
        <p>Determine whether the federation authority's vetting process establishes that assertions generated by IdPs comply with the requirements in Section 4.9 (general-purpose IdPs) or Section 5.8 (subscriber-controlled wallets), as applicable.</p>
        <link href="#MTA-6_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the federation authority's vetting procedures, checklists, assessment criteria, and records to determine whether the vetting process for IdPs addresses the applicable assertion-content requirements in Sec. 4.9 for general-purpose IdPs or Sec. 5.8 for subscriber-controlled wallets, as applicable to the supported federation models.</p>
      </part>
      <part id="MTA-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by selecting a representative vetted IdP or subscriber-controlled wallet implementation and determining that the vetting record shows assessment of the applicable assertion-content requirements.</p>
      </part>
      <part id="MTA-6_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
      </part>
    </control>
    <control id="MTA-7">
      <title>MTA Vetting: RP Data Handling</title>
      <prop name="label" class="index" value="3.5.2 G"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-7_smt" name="statement">
        <p>The vetting of CSPs, IdPs, and RPs SHALL establish that:</p>
        <p>(5) RPs adhere to requirements for handling subscriber attribute data, such as retention, aggregation, deletion, and disclosure to third parties.</p>
      </part>
      <part id="MTA-7_obj" name="objective">
        <p>Determine whether the federation authority's vetting process establishes that RPs adhere to requirements for handling subscriber attribute data, including retention, aggregation, deletion, and disclosure to third parties.</p>
        <link href="#MTA-7_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine federation authority vetting procedures, checklists, and assessment criteria to verify that RP data-handling practices are included in the vetting scope. The federation authority's vetting process must address the following controls:</p>
        <p>(1) Retention/Storage: SSIN-1 (3.11.3), SSIN-3 (3.11.3), CAARP-1 (4.6.6);</p>
        <p>(2) Deletion: SSIN-2 (3.11.3), SSIN-3 (3.11.3), CAARP-5 (4.6.6);</p>
        <p>(3) Disclosure: CAARP-2 (4.6.6), CAARP-6 (4.6.6, Federal only);</p>
        <p>(4) Transmission: TSI-4 (3.10.1), TSI-5 (3.10.1), CAARP-4 (4.6.6); and (5)Usage Limitation: CAARP-3 (4.6.6).</p>
      </part>
      <part id="MTA-7_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>Before adding an RP to the federation, the federation authority must ensure that the party in question handles all subscriber information appropriately.</p>
        <p>This is a summative control that verifies that the federation authority's vetting process complies with RP data-handling requirements. The detailed requirements are assessed against the controls in Section 3.10.1 (limitations on transmission of subscriber information), Section 3.11.3 (storage requirements and deletion upon account termination), and Section 4.6.6 (handling of attributes collected outside the federation transaction).</p>
      </part>
    </control>
    <control id="MTA-8">
      <title>MTA Vetting: Protocol Profiles</title>
      <prop name="label" class="index" value="3.5.2 H"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-8_smt" name="statement">
        <p>The vetting of CSPs, IdPs, and RPs SHALL establish that:</p>
        <p>(6) RP and IdP systems use agreed-upon profiles of federation protocols, as specified by the federation authority.</p>
      </part>
      <part id="MTA-8_obj" name="objective">
        <p>Determine whether the federation authority documents acceptable profiles and that IdPs and RPs follow these profiles.</p>
        <link href="#MTA-8_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the federation authority's documentation of acceptable profiles and its enforcement of adherence to those profiles (e.g., SAML 2.0 Web Browser SSO Profile, OpenID Connect Core, specific FAPI profiles).</p>
      </part>
      <part id="MTA-8_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>The federation authority determines which federation protocol profiles are approved for use within the federation and must ensure that all federation participants use only these profiles. The federation authority must verify that IdPs and RPs adhere to these profiles before they are added to the federation.</p>
        <p>NISTIR 8149 Section 5.7 (Technical Specifications) notes that trust frameworks promote interoperability by identifying common protocols and standards.</p>
        <p>The federation authority's specifications should rely on existing profiles whenever possible, but may create their own profiles if necessary. Whether requiring existing profiles or designing a new profile, vendor support should be carefully considered.</p>
      </part>
    </control>
    <control id="MTA-9">
      <title>MTA Periodic Reevaluation</title>
      <prop name="label" class="index" value="3.5.2 I"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MTA-9_smt" name="statement">
        <p>Federation authorities SHALL periodically reevaluate members for compliance, in terms disclosed in the trust agreement.</p>
      </part>
      <part id="MTA-9_obj" name="objective">
        <p>Determine whether the federation authority periodically reevaluates members for compliance and whether the reevaluation schedule is disclosed in the trust agreement artifact(s).</p>
        <link href="#MTA-9_smt" rel="assessment-for"/>
      </part>
      <part id="MTA-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust agreement artifact(s) for disclosed reevaluation terms (e.g., frequency, scope, criteria). Examine the federation authority records of completed reevaluations to verify that the schedule is followed.</p>
      </part>
      <part id="MTA-9_gdn" name="guidance">
        <p>Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement.</p>
        <p>Initial vetting (MTA-1 through MTA-8) establishes baseline compliance at onboarding. This control ensures ongoing compliance throughout membership. The trust agreement must disclose the reevaluation terms so members understand their continuing obligations.</p>
        <p>Reevaluation frequency may vary based on risk, federation model, or member role. The trust agreement should specify whether reevaluation applies uniformly or varies by party type (CSP, IdP, RP). Reevaluation may include reassessment of the criteria established in MTA-3 through MTA-8.</p>
      </part>
    </control>
    <control id="RR-1">
      <title>RP Subscriber Redress</title>
      <prop name="label" class="index" value="3.5.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RR-1_smt" name="statement">
        <p>For matters that involve the RP subscriber account (including any attributes stored in the account), RP functionality, bound authenticators, RP allowlists, and other items under the RP's control, the RP SHALL provide a clear and accessible means of redress to the subscriber.</p>
      </part>
      <part id="RR-1_obj" name="objective">
        <p>Determine whether the RP provides a clear and accessible means for subscribers to seek redress for matters under the RP's control.</p>
        <link href="#RR-1_smt" rel="assessment-for"/>
      </part>
      <part id="RR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP documentation, subscriber-facing interfaces, and help resources for redress mechanisms. Verify that redress mechanisms are clearly presented and accessible to subscribers, and that they address RP subscriber accounts, attributes stored by the RP, RP functionality, bound authenticators, and RP allowlists. Review RP documentation to determine whether there are any other items under the RP's control, and if so, verify that redress mechanisms are sufficient.</p>
      </part>
      <part id="RR-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the redress process by locating and initiating it as a test subscriber to verify accessibility.</p>
      </part>
      <part id="RR-1_gdn" name="guidance">
        <p>Section 3.5.3 establishes that the RP is the subscriber's primary point of access to the federated system, and in some cases, subscribers may be unaware that an IdP is involved. This control addresses redress for matters solely within the RP's control.</p>
        <p>"Clear and accessible" means the redress mechanism must be easy to find and use. Complex processes, hidden contact information, or technical jargon that prevents subscribers from understanding how to seek redress would fail this requirement.</p>
      </part>
    </control>
    <control id="RR-2">
      <title>RP Redress Routing</title>
      <prop name="label" class="index" value="3.5.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RR-2_smt" name="statement">
        <p>For matters that involve the IdP or CSP, the RP SHALL provide the subscriber with a means of initiating the redress process with the IdP or CSP, as appropriate.</p>
      </part>
      <part id="RR-2_obj" name="objective">
        <p>Determine whether the RP provides subscribers with a means of initiating the redress process with the IdP or CSP for matters outside the RP's control.</p>
        <link href="#RR-2_smt" rel="assessment-for"/>
      </part>
      <part id="RR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP documentation, subscriber-facing interfaces, and help resources for mechanisms that direct subscribers to IdP or CSP redress processes when appropriate. Verify that the RP distinguishes between matters it handles directly (RR-1) and matters requiring IdP or CSP involvement.</p>
      </part>
      <part id="RR-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the RP's interfaces by attempting to locate information for initiating redress with the IdP or CSP, acting as a test subscriber.</p>
      </part>
      <part id="RR-2_gdn" name="guidance">
        <p>Since the RP is typically the subscriber's primary point of access to the federated system, subscribers may not know how to reach the IdP or CSP, or when an issue is more appropriately addressed by the IdP or CSP. This control ensures the RP acts as a bridge, directing subscribers to the appropriate party for matters outside the RP's control.</p>
        <p>TRUST-8 (Redress Coordination) establishes the inter-party infrastructure that enables this routing. This control assesses whether the RP makes that routing accessible to subscribers.</p>
      </part>
    </control>
    <control id="RR-3">
      <title>IdP Subscriber Redress</title>
      <prop name="label" class="index" value="3.5.3 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RR-3_smt" name="statement">
        <p>For matters that involve the use of the subscriber account in federation transactions, including attribute values and derived attribute values made available over federation transactions, IdP functionality, holder-of-key authenticators, IdP allowlists, and other items in the IdP's control, the IdP SHALL provide a clear and accessible means of redress to the subscriber.</p>
      </part>
      <part id="RR-3_obj" name="objective">
        <p>Determine whether the IdP provides clear and accessible means for subscribers to seek redress for matters under the IdP's control.</p>
        <link href="#RR-3_smt" rel="assessment-for"/>
      </part>
      <part id="RR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP documentation, subscriber-facing interfaces, and help resources for redress mechanisms. Verify that redress mechanisms are clearly presented and accessible to subscribers, and that they address subscriber account usage in federation transactions, attribute values, and, if applicable, derived attribute values, IdP functionality, holder-of-key authenticators, and IdP allowlists. Review IdP documentation to determine whether there are any other items under the IdP's control, and if so, verify that redress mechanisms are sufficient.</p>
      </part>
      <part id="RR-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by locating and initiating the redress process to verify clarity and accessibility.</p>
      </part>
      <part id="RR-3_gdn" name="guidance">
        <p>This is the IdP counterpart to RR-1 (RP Subscriber Redress). This control addresses redress for matters solely within the IdP's control.</p>
        <p>"Clear and accessible" means the redress mechanism must be easy to find and use. Complex processes, hidden contact information, or technical jargon that prevents subscribers from understanding how to seek redress would fail this requirement.</p>
      </part>
    </control>
    <control id="RR-4">
      <title>IdP Redress Routing: RP</title>
      <prop name="label" class="index" value="3.5.3 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RR-4_smt" name="statement">
        <p>For matters that also involve a particular RP, the IdP SHALL provide the subscriber with a means of initiating the redress process with the RP.</p>
      </part>
      <part id="RR-4_obj" name="objective">
        <p>Determine whether the IdP provides subscribers with a means of initiating the redress process with the RP for matters that involve a particular RP.</p>
        <link href="#RR-4_smt" rel="assessment-for"/>
      </part>
      <part id="RR-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP documentation, subscriber-facing interfaces, and help resources for mechanisms that direct subscribers to RP redress processes when appropriate. Verify that the IdP distinguishes between matters it handles directly (RR-3) and matters requiring RP involvement.</p>
      </part>
      <part id="RR-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the IdP's interfaces by attempting to locate information to initiate redress with the RP, acting as a test subscriber.</p>
      </part>
      <part id="RR-4_gdn" name="guidance">
        <p>This is the IdP counterpart to RR-2 (RP Redress Routing). Subscribers may contact the IdP for issues that are more appropriately resolved by a specific RP (e.g., RP mishandling attributes received from the IdP, RP subscriber account issues). This control ensures the IdP directs subscribers to the appropriate RP.</p>
        <p>TRUST-8 (Redress Coordination) establishes the inter-party infrastructure that enables this routing. This control assesses whether the IdP makes that routing accessible to subscribers.</p>
      </part>
    </control>
    <control id="RR-5">
      <title>IdP Redress Routing: CSP</title>
      <prop name="label" class="index" value="3.5.3 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RR-5_smt" name="statement">
        <p>For matters that involve a subscriber account that has been made available to the IdP, the IdP SHALL provide the subscriber with a means of initiating the redress process with the CSP.</p>
      </part>
      <part id="RR-5_obj" name="objective">
        <p>Determine whether the IdP provides subscribers with a means of initiating the redress process with the CSP for matters involving the CSP subscriber account.</p>
        <link href="#RR-5_smt" rel="assessment-for"/>
      </part>
      <part id="RR-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP documentation, subscriber-facing interfaces, and help resources for mechanisms that direct subscribers to CSP redress processes when appropriate. Verify that the IdP distinguishes between matters it handles directly (RR-3) and matters requiring CSP involvement.</p>
      </part>
      <part id="RR-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the IdP's interfaces by attempting to locate information for initiating redress with the CSP, acting as a test subscriber.</p>
      </part>
      <part id="RR-5_gdn" name="guidance">
        <p>When the IdP is separate from the CSP, the subscriber may contact the IdP for issues that are more appropriately resolved by CSP (e.g., identity proofing errors, incorrect attributes in the CSP subscriber account, authenticator binding issues). This control ensures the IdP correctly redirects subscribers to the CSP.</p>
        <p>TRUST-8 (Redress Coordination) establishes the inter-party infrastructure that enables this routing. This control assesses whether the IdP makes that routing accessible to subscribers.</p>
      </part>
    </control>
    <control id="RR-6">
      <title>CSP Redress</title>
      <prop name="label" class="index" value="3.5.3 F"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RR-6_smt" name="statement">
        <p>For matters that involve the subscriber account, including identity attributes and authenticators in the subscriber account, the CSP SHALL provide the subscriber with a clear and accessible means of redress.</p>
      </part>
      <part id="RR-6_obj" name="objective">
        <p>Determine whether the CSP provides a clear and accessible means for subscribers to seek redress for matters involving the CSP subscriber account.</p>
        <link href="#RR-6_smt" rel="assessment-for"/>
      </part>
      <part id="RR-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP documentation, subscriber-facing interfaces, and help resources for redress mechanisms. Verify that redress mechanisms are clearly presented and accessible to subscribers, and that all potential areas of redress are addressed, including the CSP subscriber account, identity attributes (if collected), and authenticators. Review CSP documentation to determine whether there are any other items under the CSP's control, and if so, verify that redress mechanisms are sufficient.</p>
      </part>
      <part id="RR-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the redress process by attempting to locate and initiate it as a test subscriber to verify accessibility.</p>
      </part>
      <part id="RR-6_gdn" name="guidance">
        <p>This is the CSP counterpart to RR-1 (RP Subscriber Redress) and RR-3 (IdP Subscriber Redress). This control addresses redress for matters solely within the CSP's control.</p>
        <p>"Clear and accessible" means the redress mechanism must be easy to find and use. Complex processes, hidden contact information, or technical jargon that prevents subscribers from understanding how to seek redress would fail this requirement.</p>
      </part>
    </control>
    <control id="ICKM-1">
      <title>Secure Discovery and Registration</title>
      <prop name="label" class="index" value="3.6 A"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ICKM-1_smt" name="statement">
        <p>The discovery and registration processes SHALL be established in a secure fashion as defined by the trust agreement that governs the federation transaction.</p>
      </part>
      <part id="ICKM-1_obj" name="objective">
        <p>Determine whether discovery and registration processes are established securely in accordance with the trust agreement artifact(s).</p>
        <link href="#ICKM-1_smt" rel="assessment-for"/>
      </part>
      <part id="ICKM-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust agreement artifact(s) to verify that they define security requirements for discovery and registration processes. The specific implementation requirements are satisfied by ICKM-2 (authenticated protected channel for key exchange); ICKM-3 (symmetric key uniqueness); ICKM-4 (wildcard identifier prohibition); DR-1, DR-2, and DR-3 (IdP discovery and RP registration, Sec. 4.4); MR-1 (manual registration, Sec. 4.4.1); DYR-1 (dynamic registration channel protection, Sec. 4.4.2); and DISCR-1 (CSP verification key determination for wallets, Sec. 5.5).</p>
        <p>If the trust agreement artifact(s) do not define security requirements for discovery and registration, this control fails regardless of downstream control results.</p>
      </part>
      <part id="ICKM-1_gdn" name="guidance">
        <p>This control requires that the trust agreement artifact(s) define the security for discovery and registration. The downstream controls assess whether the implementation conforms to specific technical requirements. A federation could pass all downstream controls individually but fail this control if the trust agreement artifact(s) are silent on discovery and registration security, leaving parties without a documented basis for their security expectations.</p>
      </part>
    </control>
    <control id="ICKM-2">
      <title>Secure Key Exchange</title>
      <prop name="label" class="index" value="3.6 B"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ICKM-2_smt" name="statement">
        <p>Protocols that require the transfer of cryptographic key information SHALL use an authenticated protected channel to exchange the cryptographic key information needed to operate the federated relationship, including any shared secrets or public keys.</p>
      </part>
      <part id="ICKM-2_obj" name="objective">
        <p>Determine whether all cryptographic key information is exchanged over an authenticated protected channel.</p>
        <link href="#ICKM-2_smt" rel="assessment-for"/>
      </part>
      <part id="ICKM-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation describing the key exchange processes for all federation relationships. For each relationship, verify that the documented process specifies the use of an authenticated protected channel for all transfers of cryptographic key information, including shared secrets and public keys.</p>
      </part>
      <part id="ICKM-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by selecting a sample of key exchange operations across the federation deployment. For each, verify that the authenticated protected channel is properly implemented (e.g., TLS with server-side certificate validation).</p>
        <p>Specific key exchange scenarios are satisfied by their respective controls: DR-2 for RP retrieval of IdP keys over a network, DR-3: RP for registration with an IdP, DYR-1 for dynamic registration, and DISCR-1 for RP discovery of CSP wallet keys.</p>
        <p>If any key exchange in the deployment is not covered by a downstream control (e.g., key exchange between a separated CSP and IdP), document and assess it here.</p>
      </part>
      <part id="ICKM-2_gdn" name="guidance">
        <p>The IdP, CSP, and RP need access to cryptographic keying materials to validate signatures and encrypt content. The association of these keys with specific parties is vital to the security of the protocol. In order to prevent an attacker impersonating an IdP/CSP or RP, all keys have to be transferred using secure methods. Methods include the publication of asymmetric public keys over HTTPS (and therefore TLS) at a well-known and trusted URL associated with the IdP/CSP or RP, or the use of TLS to transfer keying material in the registration process. Alternatively, keys could be transferred and configured manually by administrators to ensure a strong mapping between the intended party and the value of the key itself.</p>
      </part>
    </control>
    <control id="ICKM-3">
      <title>Symmetric Key Uniqueness</title>
      <prop name="label" class="index" value="3.6 C"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ICKM-3_smt" name="statement">
        <p>Any symmetric keys used in this relationship SHALL be unique to a pair of federation participants.</p>
      </part>
      <part id="ICKM-3_obj" name="objective">
        <p>Determine whether symmetric keys are unique to each pair of federation participants.</p>
        <link href="#ICKM-3_smt" rel="assessment-for"/>
      </part>
      <part id="ICKM-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation describing symmetric key generation and assignment processes. Verify that the documented process produces a unique symmetric key for each pair of federation participants. Determine whether the process ensures that any symmetric key used for one pair of federation participants is not reused for any other pair.</p>
      </part>
      <part id="ICKM-3_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine key management system records or configuration entries for a sample of federation relationships. Verify that distinct key identifiers or key entries exist for each pair of participants.</p>
      </part>
      <part id="ICKM-3_gdn" name="guidance">
        <p>Assessment is required when: Symmetric keys, rather than asymmetric key pairs, are used for the federation relationship.</p>
        <p>Since symmetric keys allow for both the creation and verification of both signed and encrypted content by all parties who possess the key, it's important that any symmetric keys be limited to use between only a single pair of connected parties. If symmetric keys are made available to any other parties, those parties can impersonate each other.</p>
        <p>Reusing symmetric keys across multiple federation relationships also increases the risk of key compromise: a compromise of one relationship would compromise all relationships that use the same key. This control ensures that a key shared between an IdP and RP-A is different from the key shared between the same IdP and RP-B.</p>
      </part>
    </control>
    <control id="ICKM-4">
      <title>Wildcard Identifier Prohibition</title>
      <prop name="label" class="index" value="3.6 D"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ICKM-4_smt" name="statement">
        <p>When domain names, URIs, or other structured identifiers are used to identify parties, wildcards SHALL NOT be used.</p>
      </part>
      <part id="ICKM-4_obj" name="objective">
        <p>Determine whether party identifiers avoid the use of wildcards.</p>
        <link href="#ICKM-4_smt" rel="assessment-for"/>
      </part>
      <part id="ICKM-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system configurations, discovery/registration records, and trust agreement artifact(s) for party identifiers. Verify that no identifiers contain wildcards (e.g., "*.csp.com").</p>
      </part>
      <part id="ICKM-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to register or configure a party identifier containing a wildcard and verify that the system rejects it, if identifier establishment is performed through an automated interface.</p>
      </part>
      <part id="ICKM-4_gdn" name="guidance">
        <p>Wildcards in identifiers create ambiguity about which party is being identified, potentially allowing unintended parties to match the identifier. For example, if an RP is deployed at "www.example.com", "service.example.com", and "gateway.example.com", each identifier must be registered separately. A wildcard of "*.example.com" cannot be used, as it would unintentionally match "user.example.com" and "unknown.example.com" under the same RP identifier.</p>
      </part>
    </control>
    <control id="CKR-1">
      <title>Key Rotation Documentation</title>
      <prop name="label" class="index" value="3.6.1 A"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CKR-1_smt" name="statement">
        <p>The allowable update process for any identifiers and cryptographic keys SHALL be defined by the trust agreement.</p>
      </part>
      <part id="CKR-1_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) define the allowable update process for identifiers and cryptographic keys.</p>
        <link href="#CKR-1_smt" rel="assessment-for"/>
      </part>
      <part id="CKR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust agreement artifact(s) for documentation of the allowable key and identifier update process, including permitted methods, timing, and any restrictions.</p>
      </part>
      <part id="CKR-1_gdn" name="guidance">
        <p>Over time, it may be desirable or necessary to update cryptographic keys associated with a CSP, IdP, or RP due to key expiration, suspected compromise, algorithm deprecation, or organizational changes. The trust agreement must define how these updates are performed so all parties understand the process.</p>
        <p>Related Controls:</p>
        <ul>
          <li>
            <p>CKR-2 requires that the update process be executed over an authenticated, protected channel.</p>
          </li>
          <li>
            <p>ICKM-2 establishes the same requirement for initial key exchange.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="CKR-2">
      <title>Key Rotation Security</title>
      <prop name="label" class="index" value="3.6.1 B"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CKR-2_smt" name="statement">
        <p>The allowable update process for any identifiers and cryptographic keys... SHALL be executed using an authenticated protected channel, as in the initial cryptographic key establishment.</p>
      </part>
      <part id="CKR-2_obj" name="objective">
        <p>Determine whether updates to identifiers and cryptographic keys are executed using an authenticated protected channel.</p>
        <link href="#CKR-2_smt" rel="assessment-for"/>
      </part>
      <part id="CKR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine system configurations for key rotation mechanisms. Verify that the update process matches the process defined in the trust agreement artifact(s) (see CKR-1).</p>
      </part>
      <part id="CKR-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by performing or observing a key rotation process. For authenticated protected channel verification, see ICKM-2.</p>
      </part>
      <part id="CKR-2_gdn" name="guidance">
        <p>Key rotation requires the same security protection as initial key establishment. Using an authenticated protected channel ensures that updated key material is not intercepted or modified during exchange.</p>
      </part>
    </control>
    <control id="CKS-1">
      <title>Secure Key Storage</title>
      <prop name="label" class="index" value="3.6.2 A"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CKS-1_smt" name="statement">
        <p>CSPs, IdPs (including subscriber-controlled wallets), and RPs SHALL store all signing keys, decryption keys, and all symmetric keys in a secure fashion. Cryptographic key storage is subject to applicable [FIPS140] requirements, including applicable tamper resistance requirements.</p>
      </part>
      <part id="CKS-1_obj" name="objective">
        <p>Determine whether the assessed party stores signing keys, decryption keys, and symmetric keys securely and in accordance with applicable FIPS 140 requirements.</p>
        <link href="#CKS-1_smt" rel="assessment-for"/>
      </part>
      <part id="CKS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine (1) Documentation describing key storage mechanisms for signing keys, decryption keys, and symmetric keys. Verify that the documented storage approach addresses protection from unauthorized access. (2) FIPS 140 validation certificates for cryptographic modules used to store keys, if applicable. Verify that the validated level meets the organization's requirements and applicable policies. (3) System configurations and access controls for key storage to verify that keys are protected consistent with the documented approach and FIPS 140 requirements.</p>
      </part>
      <part id="CKS-1_gdn" name="guidance">
        <p>FIPS 140 establishes security requirements for cryptographic modules, including tamper resistance at higher levels. Federal agencies and their service providers are typically required to use FIPS 140-validated modules. The applicable FIPS 140 level depends on the organization's security requirements and applicable policies.</p>
        <p>Related Controls:</p>
        <ul>
          <li>
            <p>FAL2-7 requires Federal IdPs at FAL2 or higher to protect assertion signing keys with FIPS 140 Level 1 or higher validated mechanisms.</p>
          </li>
          <li>
            <p>CKS-2, CKS-3, and CKS-4 establish requirements for non-exportable key storage.</p>
          </li>
          <li>
            <p>KS-1 and KS-2 establish key storage requirements specific to subscriber-controlled wallets.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="CKS-2">
      <title>Non-Exportable Key Storage Definition</title>
      <prop name="label" class="index" value="3.6.2 B"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CKS-2_smt" name="statement">
        <p>To be considered non-exportable, key storage SHALL either be a separate piece of hardware or an embedded processor or execution environment, such as a secure element, trusted execution environment (TEE), or trusted platform module (TPM).</p>
      </part>
      <part id="CKS-2_obj" name="objective">
        <p>Determine whether key storage claimed as non-exportable meets the hardware or embedded processor/execution environment requirements.</p>
        <link href="#CKS-2_smt" rel="assessment-for"/>
      </part>
      <part id="CKS-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation describing key storage mechanisms. Verify that any key storage claimed as non-exportable is either a separate piece of hardware or an embedded processor or execution environment that is separate from the host processor (e.g., secure element, TEE, TPM).</p>
      </part>
      <part id="CKS-2_gdn" name="guidance">
        <p>Assessment is required when: Non-exportable key storage is required or claimed.</p>
        <p>Some circumstances require the cryptographic keys to be stored in a non-exportable manner, such as reaching FAL3 with a subscriber-controlled wallet on a subscriber's device (see Sec. 5.4.1). This control establishes the criteria for key storage to be considered non-exportable. Software-only key stores do not meet the definition of non-exportable, regardless of access controls or encryption applied to the stored keys.</p>
      </part>
    </control>
    <control id="CKS-3">
      <title>Non-Exportable Key Isolation</title>
      <prop name="label" class="index" value="3.6.2 C"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CKS-3_smt" name="statement">
        <p>Non-exportable key storage SHALL be designed to prohibit the export of the secret keys to the host processor...</p>
      </part>
      <part id="CKS-3_obj" name="objective">
        <p>Determine whether non-exportable key storage is designed to prohibit export of secret keys to the host processor.</p>
        <link href="#CKS-3_smt" rel="assessment-for"/>
      </part>
      <part id="CKS-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation and technical specifications for the key storage mechanism. Verify that the design does not include any interface or function that would allow secret keys to be exported to the host processor.</p>
      </part>
      <part id="CKS-3_gdn" name="guidance">
        <p>Assessment is required when: Non-exportable key storage is required or claimed.</p>
        <p>This control ensures that the key storage interface does not permit secret key extraction. Cryptographic operations using the keys must occur within the secure storage environment itself, with only the results (e.g., signatures, decrypted data) returned to the host processor.</p>
        <p>Related Controls:</p>
        <ul>
          <li>
            <p>CKS-2 defines what qualifies as non-exportable key storage.</p>
          </li>
          <li>
            <p>CKS-4 requires that non-exportable key storage cannot be reprogrammed to allow key extraction.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="CKS-4">
      <title>Non-Exportable Storage Immutability</title>
      <prop name="label" class="index" value="3.6.2 D"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CKS-4_smt" name="statement">
        <p>Non-exportable key storage... SHALL NOT be capable of being reprogrammed by the host processor to allow the secret keys to be extracted.</p>
      </part>
      <part id="CKS-4_obj" name="objective">
        <p>Determine whether non-exportable key storage is protected against reprogramming by the host processor to allow secret key extraction.</p>
        <link href="#CKS-4_smt" rel="assessment-for"/>
      </part>
      <part id="CKS-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation and technical specifications for the key storage mechanism. Verify that the host processor cannot modify firmware, configuration, or behavior of the key storage in a way that would enable secret key extraction.</p>
      </part>
      <part id="CKS-4_gdn" name="guidance">
        <p>Assessment is required when: Non-exportable key storage is required or claimed.</p>
        <p>This control addresses a different attack vector than CKS-3. Even if the key storage interface does not permit key export during normal operation (CKS-3), an attacker with host processor access could potentially modify the storage's firmware to add an export capability. This control requires that the key storage be designed such that the host processor cannot modify its firmware, configuration, or behavior in ways that would enable key extraction.</p>
        <p>Related Controls:</p>
        <ul>
          <li>
            <p>CKS-2 defines what qualifies as non-exportable key storage.</p>
          </li>
          <li>
            <p>CKS-3 requires that non-exportable key storage prohibit key export to the host processor.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="SATT-1">
      <title>Software Attestation Validation</title>
      <prop name="label" class="index" value="3.6.3 A"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SATT-1_smt" name="statement">
        <p>When attestations are required by the trust agreement or requested as part of the federation protocol, received attestations SHALL be validated by the receiver.</p>
      </part>
      <part id="SATT-1_obj" name="objective">
        <p>Determine whether the receiver validates software or device attestations received as part of the federation protocol.</p>
        <link href="#SATT-1_smt" rel="assessment-for"/>
      </part>
      <part id="SATT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine trust agreement artifact(s) to identify whether software or device attestations are required and, if so, the validation criteria. Examine system documentation and configurations to verify that attestation validation is implemented.</p>
      </part>
      <part id="SATT-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by (1) presenting a valid attestation and verifying that it is accepted; (2) presenting an invalid attestation and verifying that it is rejected; and (3) presenting an assertion that is missing a required attestation and verifying that it is rejected.</p>
      </part>
      <part id="SATT-1_gdn" name="guidance">
        <p>Assessment is required when: Software or device attestations are required or received.</p>
        <p>Software and device attestations can augment the establishment of identifiers and cryptographic keys, especially in dynamic and distributed systems. Attestations in this usage are cryptographically bound statements that a particular piece of software, device, or runtime system meets a set of agreed-upon parameters. The attestation is presented by the software in the context of establishing the identity of the software, device, or system with which the receiver is interacting. The attestation allows the receiver to verify the request with a higher degree of certainty than they would be able to otherwise.</p>
      </part>
    </control>
    <control id="AAD-1">
      <title>Permissible Attribute Transmission</title>
      <prop name="label" class="index" value="3.7 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAD-1_smt" name="statement">
        <p>A subscriber's identity attributes SHALL only be transmitted between the IdP and the RP for federation transactions or support functions, such as identification of compromised subscriber accounts (see Sec. 3.10.1), even when parties are allowlisted for federation purposes.</p>
      </part>
      <part id="AAD-1_obj" name="objective">
        <p>Determine whether the IdP and RP limit transmission of subscriber identity attributes to permitted purposes.</p>
        <link href="#AAD-1_smt" rel="assessment-for"/>
      </part>
      <part id="AAD-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP and RP policies, trust agreement artifact(s), data flow documentation, federation configuration, and any identity API, provisioning API, or attribute synchronization mechanisms used to transmit subscriber identity attributes between the IdP and RP. Verify that the policies do not authorize transmission for purposes outside of federation transactions and support functions (as defined in Sec. 3.10.1).</p>
      </part>
      <part id="AAD-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to verify that the permitted purposes for attribute transmission fall within these boundaries.</p>
        <p>The operational enforcement of transmission limits is satisfied by TSI-1 (IdP transmission limits) and TSI-4 (RP transmission limits to the IdP). This control verifies that the governing policies themselves do not permit out-of-scope transmission.</p>
      </part>
      <part id="AAD-1_gdn" name="guidance">
        <p>This restriction applies even when parties are allowlisted for federation purposes; allowlisting permits federation transactions, not unlimited data sharing.</p>
      </part>
    </control>
    <control id="AAD-2">
      <title>RP Attribute Use Limitation</title>
      <prop name="label" class="index" value="3.7 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAD-2_smt" name="statement">
        <p>A subscriber's identity attributes SHALL NOT be used by the RP for purposes other than those stipulated in the trust agreement unless the subscriber specifically consents to such purposes.</p>
      </part>
      <part id="AAD-2_obj" name="objective">
        <p>Determine whether the RP limits use of subscriber identity attributes to purposes stipulated in the trust agreement or consented to by the subscriber.</p>
        <link href="#AAD-2_smt" rel="assessment-for"/>
      </part>
      <part id="AAD-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by TSI-5.</p>
      </part>
      <part id="AAD-2_gdn" name="guidance">
        <p>TSI-5 establishes the RP's obligation to inform subscribers and obtain consent when using identity information for purposes beyond those described in the trust agreement artifact(s).</p>
      </part>
    </control>
    <control id="AAD-3">
      <title>Subscriber Attribute Storage</title>
      <prop name="label" class="index" value="3.7 C"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAD-3_smt" name="statement">
        <p>A subscriber's attributes SHALL be stored and managed in accordance with Sec. 3.11.3.</p>
      </part>
      <part id="AAD-3_obj" name="objective">
        <p>Determine whether subscriber attributes are stored and managed in accordance with Section 3.11.3.</p>
        <link href="#AAD-3_smt" rel="assessment-for"/>
      </part>
      <part id="AAD-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SSIN-1 through SSIN-3.</p>
      </part>
    </control>
    <control id="AAD-4">
      <title>Subscriber Attribute Transmission Notification</title>
      <prop name="label" class="index" value="3.7 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAD-4_smt" name="statement">
        <p>The subscriber SHALL be informed of the transmission of attributes to an RP.</p>
      </part>
      <part id="AAD-4_obj" name="objective">
        <p>Determine whether the subscriber is informed of the transmission of their attributes to an RP.</p>
        <link href="#AAD-4_smt" rel="assessment-for"/>
      </part>
      <part id="AAD-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>If the organization is the authorized party: Satisfied by AAD-5.</p>
        <p>If the subscriber is the authorized party: Satisfied by AAD-6.</p>
        <p>For non-allowlisted RPs, the notification mechanism assessment is satisfied by IDPRD-2 and IDPRD-3.</p>
      </part>
      <part id="AAD-4_gdn" name="guidance">
        <p>This is a summative control.</p>
      </part>
    </control>
    <control id="AAD-5">
      <title>Disclosure of Attributes by an Organization</title>
      <prop name="label" class="index" value="3.7 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAD-5_smt" name="statement">
        <p>If the authorized party is the organization, the organization SHALL make the list of approved RPs and the associated sets of attributes sent to those RPs available to the subscriber.</p>
      </part>
      <part id="AAD-5_obj" name="objective">
        <p>Determine whether the organization makes the list of approved RPs and associated attributes available to subscribers.</p>
        <link href="#AAD-5_smt" rel="assessment-for"/>
      </part>
      <part id="AAD-5_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by IALRP-3  and IALRP-5.</p>
      </part>
      <part id="AAD-5_gdn" name="guidance">
        <p>Assessment is required when: The authorized party is the organization.</p>
        <p>This is a summative control. Compliance is demonstrated by meeting the requirements of the following controls: IALRP-3 (RP Allowlist availability to subscribers) and IALRP-5 (attribute indication in allowlist entries). When the organization acts as the authorized party, the subscriber does not directly approve each federation transaction. To maintain transparency, the organization must disclose which RPs receive subscriber attributes and what attributes are sent.</p>
      </part>
    </control>
    <control id="AAD-6">
      <title>Subscriber Attribute Release Approval</title>
      <prop name="label" class="index" value="3.7 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AAD-6_smt" name="statement">
        <p>If the authorized party is the subscriber, the subscriber SHALL be prompted prior to the release of attributes using a runtime decision at the IdP as described in Sec. 4.6.1.3.</p>
      </part>
      <part id="AAD-6_obj" name="objective">
        <p>Determine whether the IdP prompts subscribers prior to attribute release using a runtime decision when the subscriber is the authorized party.</p>
        <link href="#AAD-6_smt" rel="assessment-for"/>
      </part>
      <part id="AAD-6_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by  IDPRD-1 through IDPRD-6.</p>
      </part>
      <part id="AAD-6_gdn" name="guidance">
        <p>Assessment is required when: The authorized party is the subscriber.</p>
        <p>This is a summative control. Compliance is demonstrated when the requirements of the following controls have been met:</p>
        <ul>
          <li>
            <p>IDPRD-1: Runtime authorization</p>
          </li>
          <li>
            <p>IDPRD-2: Attribute release consent</p>
          </li>
          <li>
            <p>IDPRD-3: Attribute disclosure before release</p>
          </li>
          <li>
            <p>IDPRD-4: Selective attribute disclosure</p>
          </li>
          <li>
            <p>IDPRD-5: Attribute value viewing mechanism</p>
          </li>
          <li>
            <p>IDPRD-6: Sensitive information masking</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="RPSA-1">
      <title>RP Subscriber Account Termination Data Removal</title>
      <prop name="label" class="index" value="3.8 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSA-1_smt" name="statement">
        <p>Termination SHALL include the removal of all federated identifiers, bound authenticators, attributes, and identity information associated with the account, in accordance with Sec. 3.11.3.</p>
      </part>
      <part id="RPSA-1_obj" name="objective">
        <p>Determine whether termination of an RP subscriber account includes removal of all federated identifiers, bound authenticators, attributes, and identity information associated with the account, except when otherwise restricted from doing so by regulations, laws, or policies, or when the risk of an application deems it essential (Sec. 3.11.3).</p>
        <link href="#RPSA-1_smt" rel="assessment-for"/>
      </part>
      <part id="RPSA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP policies and procedures for account termination. Examine system implementation to verify that termination processes address the removal of federated identifiers, bound authenticators, attributes, and identity information.</p>
        <p>If any attributes are not removed, confirm that the reasons for retention are documented and are appropriately attributed to regulations, laws, policies, or risk assessments.</p>
      </part>
      <part id="RPSA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by terminating a test RP subscriber account and verify that all subscriber information is removed from storage as expected.</p>
      </part>
      <part id="RPSA-1_gdn" name="guidance">
        <p>An RP subscriber account is terminated when the RP removes all access to the account at the RP.</p>
        <p>The reference to Sec. 3.11.3 recognizes that RPs may be required to retain certain subscriber information after account termination due to regulatory or legal obligations, organizational policies, or application risk assessments.</p>
      </part>
    </control>
    <control id="RPSA-2">
      <title>Inaccessible Account Policy Documentation</title>
      <prop name="label" class="index" value="3.8 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSA-2_smt" name="statement">
        <p>The RP SHALL document the practices and policies that it enacts when an RP subscriber account reaches a state of having zero associated federated identifiers; no means of access, including alternative authenticators (see Sec. 3.8.3); and no means of recovery, including account linking (see Sec. 3.8.1) and account resolution (see Sec. 3.8.2).</p>
      </part>
      <part id="RPSA-2_obj" name="objective">
        <p>Determine whether the RP documents the practices and policies enacted when an RP subscriber account becomes inaccessible.</p>
        <link href="#RPSA-2_smt" rel="assessment-for"/>
      </part>
      <part id="RPSA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP documentation for policies addressing RP subscriber accounts that have no associated federated identifiers, no alternative authenticators, and no means of recovery. Verify that the documentation specifies the actions taken (e.g., disable, terminate, retain for investigation).</p>
      </part>
      <part id="RPSA-2_gdn" name="guidance">
        <p>An RP subscriber account may reach a state where the subscriber can no longer access it - for example, when the sole federated identifier is removed, no alternative authenticators exist, and no account linking or account resolution process is available. The RP must have documented policies for handling such accounts.</p>
        <p>Common approaches include:</p>
        <ul>
          <li>
            <p>Disabling the account</p>
          </li>
          <li>
            <p>Terminating the account</p>
          </li>
          <li>
            <p>Retaining the account for investigation if suspicious activity is suspected The specific policy depends on the RP's business requirements, regulatory obligations, and risk posture.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="RPSA-3">
      <title>Federated Identifier Change Notifications</title>
      <prop name="label" class="index" value="3.8 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSA-3_smt" name="statement">
        <p>The RP SHALL provide a notice to the subscriber when:</p>
        <p>(a) A new federated identifier is added to an existing RP subscriber account, or</p>
        <p>(b) A federated identifier is removed from an RP subscriber account, but the account is not terminated.</p>
      </part>
      <part id="RPSA-3_obj" name="objective">
        <p>Determine whether the RP provides notice to the subscriber when a federated identifier is added to or removed from an RP subscriber account.</p>
        <link href="#RPSA-3_smt" rel="assessment-for"/>
      </part>
      <part id="RPSA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP notification mechanisms and configurations to verify that notices are sent when federated identifiers are added or removed.</p>
      </part>
      <part id="RPSA-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by adding a new federated identifier to a test RP subscriber account and verifying that the subscriber receives a notification. Next, remove a federated identifier from a test RP subscriber account without terminating the account, and verify that the subscriber is notified.</p>
      </part>
      <part id="RPSA-3_gdn" name="guidance">
        <p>Changes to federated identifiers associated with an RP subscriber account are security-relevant events. Adding a federated identifier grants a new means of access; removing one revokes access from that identity. Notifying the subscriber allows them to detect unauthorized account linking or removal.</p>
      </part>
    </control>
    <control id="RPSA-4">
      <title>Termination Notice Consideration</title>
      <prop name="label" class="index" value="3.8 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSA-4_smt" name="statement">
        <p>The RP SHALL consider the reason for termination when determining whether to send a notice to the subscriber, as discussed in Sec. 5.4 of [SP800-63A].</p>
      </part>
      <part id="RPSA-4_obj" name="objective">
        <p>Determine whether the RP considers the reason for termination when deciding whether to send a notice to the subscriber.</p>
        <link href="#RPSA-4_smt" rel="assessment-for"/>
      </part>
      <part id="RPSA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP policies and procedures for account termination to verify that the reason for termination is considered when determining whether to notify the subscriber.</p>
      </part>
      <part id="RPSA-4_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview personnel responsible for account termination or notification decisions to determine how the reason for termination is considered in practice.</p>
      </part>
      <part id="RPSA-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by reviewing a sample of terminated or disabled RP subscriber accounts with different termination reasons and determine that the notice decision in each case reflects consideration of the reason for termination.</p>
      </part>
      <part id="RPSA-4_gdn" name="guidance">
        <p>Not all termination scenarios warrant subscriber notification. SP 800-63A Section 5.4 identifies various reasons for account termination, including scenarios that may warrant withholding notice, such as an account termination due to suspected fraud, since the notification could alert a malicious actor.</p>
      </part>
    </control>
    <control id="ACCL-1">
      <title>Account Linking Authentication Requirement</title>
      <prop name="label" class="index" value="3.8.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ACCL-1_smt" name="statement">
        <p>If the RP allows a subscriber to link multiple subscriber accounts..., the RP SHALL require an authenticated session with the subscriber account for all linking functions.</p>
      </part>
      <part id="ACCL-1_obj" name="objective">
        <p>Determine whether the RP requires an authenticated session for account linking functions.</p>
        <link href="#ACCL-1_smt" rel="assessment-for"/>
      </part>
      <part id="ACCL-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP policies and system configurations to verify that account linking functions require an authenticated session.</p>
      </part>
      <part id="ACCL-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to link a new federated identifier to an RP subscriber account and verify that an authenticated session is required before the linking function is permitted.</p>
      </part>
      <part id="ACCL-1_gdn" name="guidance">
        <p>Assessment is required when: The RP allows a subscriber to link multiple subscriber accounts.</p>
        <p>Account linking allows a subscriber to associate multiple federated identifiers with a single RP subscriber account. This is a security-sensitive operation - without an authenticated session, an attacker could link their own federated identifier to a victim's account and gain unauthorized access.</p>
        <p>Requiring an authenticated session ensures that only the legitimate account holder can add new federated identifiers.</p>
      </part>
    </control>
    <control id="ACCL-2">
      <title>Removed Federated Identifier Access Prohibition</title>
      <prop name="label" class="index" value="3.8.1 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ACCL-2_smt" name="statement">
        <p>When a federated identifier is removed from an RP subscriber account, the RP SHALL disallow access to the RP subscriber account from the removed federated identifier.</p>
      </part>
      <part id="ACCL-2_obj" name="objective">
        <p>Determine whether the RP disallows access to the RP subscriber account from a removed federated identifier.</p>
        <link href="#ACCL-2_smt" rel="assessment-for"/>
      </part>
      <part id="ACCL-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP implementation logic to verify that removing a federated identifier immediately revokes access to the account previously associated with that identifier.</p>
      </part>
      <part id="ACCL-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by removing a federated identifier from a test RP subscriber account and attempting to authenticate using the removed federated identifier. Verify that access is denied.</p>
      </part>
      <part id="ACCL-2_gdn" name="guidance">
        <p>When a federated identifier is unlinked from an RP subscriber account, it must no longer grant access to that account. While this may seem self-evident, the requirement addresses potential implementation patterns that could inadvertently preserve access, such as soft-deleting or marking the identifier as "inactive" without enforcing access prohibition and caching mechanisms that do not immediately reflect the removal.</p>
        <p>The assessment verifies that removal is immediately and completely effective.</p>
      </part>
    </control>
    <control id="ACCR-1">
      <title>Account Resolution Attribute Sufficiency</title>
      <prop name="label" class="index" value="3.8.2 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ACCR-1_smt" name="statement">
        <p>An RP that performs account resolution SHALL ensure that the attributes requested from the IdP are sufficient to uniquely resolve the subscriber within the RP's system before linking the federated identifier with the RP subscriber account and granting access.</p>
      </part>
      <part id="ACCR-1_obj" name="objective">
        <p>Determine whether the RP ensures that the attributes requested from the IdP for account resolution are sufficient to uniquely identify the subscriber before linking the federated identifier with the RP subscriber account and granting access.</p>
        <link href="#ACCR-1_smt" rel="assessment-for"/>
      </part>
      <part id="ACCR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP's account resolution process, including the specific attributes used for matching. Then, examine the RP's analysis or justification demonstrating that the selected attribute combination is sufficient to uniquely resolve subscribers within its population.</p>
      </part>
      <part id="ACCR-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting account resolution as a test subscriber and verify that the federated identifier is linked only after a unique match is confirmed.</p>
      </part>
      <part id="ACCR-1_gdn" name="guidance">
        <p>Assessment is required when: The RP performs account resolution.</p>
        <p>Account resolution occurs when the RP has existing subscriber information (e.g., from a pre-existing database) that is not yet associated with a federated identifier. When a subscriber authenticates via federation, the RP must match the incoming assertion to the correct existing account.</p>
        <p>Using insufficient attributes risks incorrect matching - for example, matching on common name and DOB alone could link a federated identifier to the wrong subscriber's account. The RP must request and use attributes that, in combination, uniquely identify the subscriber within the RP's population.</p>
      </part>
    </control>
    <control id="ACCR-2">
      <title>Account Resolution Accuracy</title>
      <prop name="label" class="index" value="3.8.2 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ACCR-2_smt" name="statement">
        <p>An RP that performs account resolution SHALL design the process such that it does not associate an RP subscriber account's information with a federated identifier that does not belong to the subscriber.</p>
      </part>
      <part id="ACCR-2_obj" name="objective">
        <p>Determine whether the RP's account resolution process is designed to prevent associating an RP subscriber account with a federated identifier that does not belong to the subscriber.</p>
        <link href="#ACCR-2_smt" rel="assessment-for"/>
      </part>
      <part id="ACCR-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ACCR-1.</p>
      </part>
      <part id="ACCR-2_gdn" name="guidance">
        <p>Assessment is required when: The RP performs account resolution.</p>
        <p>This control requires the RP to design the account resolution process to ensure accurate association between RP subscriber accounts and federated identifiers. Account resolution may occur in scenarios where a federated identifier is not directly provided - for example, a subscriber-controlled wallet providing an attribute bundle without a federated identifier, or a pre-provisioned account being matched to an incoming assertion based on agreed-upon attributes. The RP must design the process so that the resolution correctly identifies the subscriber and does not mistakenly associate account information with an identifier belonging to a different person.</p>
      </part>
    </control>
    <control id="ACCR-3">
      <title>Holder-of-Key Account Resolution</title>
      <prop name="label" class="index" value="3.8.2 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="ACCR-3_smt" name="statement">
        <p>A similar account resolution process is also used when the RP verifies an authenticator used in a holder-of-key assertion for the first time. In this case, the RP SHALL ensure that the attributes carried with the authenticator uniquely resolve to the RP subscriber account before accepting the authenticator.</p>
      </part>
      <part id="ACCR-3_obj" name="objective">
        <p>Determine whether the RP ensures that attributes carried with a holder-of-key authenticator uniquely resolve to an RP subscriber account before accepting the authenticator.</p>
        <link href="#ACCR-3_smt" rel="assessment-for"/>
      </part>
      <part id="ACCR-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ACCR-1.</p>
      </part>
      <part id="ACCR-3_gdn" name="guidance">
        <p>Assessment is required when: The RP performs account resolution when verifying an authenticator used in a holder-of-key assertion for the first time.</p>
        <p>When an RP encounters a holder-of-key authenticator for the first time, it must associate that authenticator with an RP subscriber account. Since the RP did not issue the authenticator, it does not know which account it belongs to. The RP uses attributes carried with the authenticator to resolve to the correct account before accepting the authenticator for FAL3 sessions.</p>
      </part>
    </control>
    <control id="ALTAP-1">
      <title>Alternative Authenticator Management</title>
      <prop name="label" class="index" value="3.8.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ALTAP-1_smt" name="statement">
        <p>The RP SHALL follow the requirements in [SP800-63B] to manage all alternative authenticators.</p>
      </part>
      <part id="ALTAP-1_obj" name="objective">
        <p>Determine whether the RP follows SP 800-63B requirements for managing alternative authenticators.</p>
        <link href="#ALTAP-1_smt" rel="assessment-for"/>
      </part>
      <part id="ALTAP-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>This is a summative control. The requirements for this control are met when the RP's management of alternative authenticators meets the applicable requirements in SP 800-63B.</p>
      </part>
      <part id="ALTAP-1_gdn" name="guidance">
        <p>Assessment is required when: The RP allows subscribers to access their RP subscriber account using direct authentication processes by allowing the subscriber to add and remove authenticators in the RP subscriber account.</p>
        <p>Since the RP is using the direct authentication model discussed in [SP800-63], there is no federation transaction and therefore no FAL assigned.</p>
      </part>
    </control>
    <control id="ALTAP-2">
      <title>Bound vs. Alternative Authenticators</title>
      <prop name="label" class="index" value="3.8.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="ALTAP-2_smt" name="statement">
        <p>While it is possible for bound authenticators (see Sec. 3.16) to be used as an alternative authenticator for direct access to the RP, these uses are distinct from each other and an RP SHALL determine whether a given authenticator can be used in one or both scenarios.</p>
      </part>
      <part id="ALTAP-2_obj" name="objective">
        <p>Determine whether the RP has determined whether bound authenticators can be utilized as alternative authenticators, and vice versa.</p>
        <link href="#ALTAP-2_smt" rel="assessment-for"/>
      </part>
      <part id="ALTAP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP documentation and policies to verify that the RP has explicitly determined whether bound authenticators can also be used for direct access, and vice versa.</p>
      </part>
      <part id="ALTAP-2_gdn" name="guidance">
        <p>Assessment is required when: An RP supports both bound and alternative authenticators.</p>
        <p>A single authenticator may potentially serve two purposes at the RP:</p>
        <ol>
          <li>
            <p>As a bound authenticator for FAL3 federation transactions</p>
          </li>
          <li>
            <p>As an alternative authenticator for direct access without federation These are distinct use cases with different security implications. The RP must explicitly determine which authenticators are permitted for each scenario.</p>
          </li>
        </ol>
      </part>
    </control>
    <control id="ASRP-1">
      <title>RP Authenticated Session Requirements</title>
      <prop name="label" class="index" value="3.9 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ASRP-1_smt" name="statement">
        <p>An authenticated session SHALL be created by the RP only when the following conditions are true:</p>
        <p>(a) The RP has processed and verified a valid assertion.</p>
        <p>(b) The assertion is from the expected IdP for a transaction.</p>
        <p>(c) The IdP that issued the assertion is the IdP identified in the federated identifier of the assertion.</p>
        <p>(d) The assertion is associated with an RP subscriber account, which may be ephemeral.</p>
        <p>(e) The RP subscriber account has been provisioned at the RP through the method specified in the trust agreement.</p>
      </part>
      <part id="ASRP-1_obj" name="objective">
        <p>Determine whether the RP creates authenticated sessions only once all required conditions are met.</p>
        <link href="#ASRP-1_smt" rel="assessment-for"/>
      </part>
      <part id="ASRP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP assertion processing logic and session management documentation to verify that: (a) The assertion's signature and validity are verified before session creation; (b) The assertion's issuing IdP is checked against the expected IdP for the transaction, and the assertion is from the expected IdP; (c) The federated identifier's IdP matches the assertion's issuer; (d) The assertion is linked to an RP subscriber account; and (e) The provisioning method matches what is specified in the trust agreement artifact(s).</p>
      </part>
      <part id="ASRP-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting a valid assertion meeting all conditions and verify that an authenticated session is created. Then present assertions that fail one or more conditions and verify that no authenticated session is created.</p>
      </part>
      <part id="ASRP-1_gdn" name="guidance">
        <p>The RP must verify all five conditions before creating an authenticated session. This prevents session creation based on invalid or incomplete assertions.</p>
      </part>
    </control>
    <control id="ASRP-2">
      <title>RP Authenticated Session Requirements: HoK Verification</title>
      <prop name="label" class="index" value="3.9 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="ASRP-2_smt" name="statement">
        <p>If the assertion is a holder-of-key assertion at FAL3, the authenticator indicated in the assertion SHALL be verified before the RP subscriber account is associated with an authenticated session, as discussed in Sec. 3.15.</p>
      </part>
      <part id="ASRP-2_obj" name="objective">
        <p>Determine whether the RP verifies the authenticator indicated in a holder-of-key assertion before associating the RP subscriber account with an authenticated session.</p>
        <link href="#ASRP-2_smt" rel="assessment-for"/>
      </part>
      <part id="ASRP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP documentation to verify that holder-of-key authenticator verification occurs before session creation.</p>
      </part>
      <part id="ASRP-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting a holder-of-key assertion and verifying that the RP requires proof of the indicated authenticator before creating an authenticated session.</p>
      </part>
      <part id="ASRP-2_gdn" name="guidance">
        <p>Assessment is required when: The assertion is a holder-of-key assertion at FAL3.</p>
        <p>A holder-of-key assertion contains a reference to an authenticator. Before creating an authenticated session, the RP must verify that the subscriber controls this authenticator - the assertion signature alone is insufficient.</p>
      </part>
    </control>
    <control id="ASRP-3">
      <title>RP Authenticated Session Requirements: Bound Authenticator Verification</title>
      <prop name="label" class="index" value="3.9 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="ASRP-3_smt" name="statement">
        <p>If the assertion also requires authentication with a bound authenticator at FAL3, a bound authenticator SHALL be verified before the RP subscriber account is associated with an authenticated session, as discussed in Sec. 3.16.</p>
      </part>
      <part id="ASRP-3_obj" name="objective">
        <p>If the assertion requires authentication with a bound authenticator, determine whether the RP verifies a bound authenticator before associating the RP subscriber account with an authenticated session.</p>
        <link href="#ASRP-3_smt" rel="assessment-for"/>
      </part>
      <part id="ASRP-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RPPHBA-1 and RPPHBA-4.</p>
      </part>
      <part id="ASRP-3_gdn" name="guidance">
        <p>Assessment is required when: The assertion requires authentication with a bound authenticator at FAL3.</p>
        <p>When an assertion indicates that a bound authenticator is required for FAL3, the RP must verify the bound authenticator before creating an authenticated session - the assertion signature alone is not sufficient. The bound authenticator is registered to the RP subscriber account and managed by the RP.</p>
        <p>Note: If bound authenticator verification occurs as part of a binding ceremony (see SUBPB-7), this requirement is not satisfied. A new FAL3 federation transaction must be initiated after the binding ceremony completes.</p>
      </part>
    </control>
    <control id="PRIVR-1">
      <title>Privacy Act Analysis</title>
      <prop name="label" class="index" value="3.10 #1"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-1_smt" name="statement">
        <p>The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) to conduct an analysis that determines whether the requirements of the Privacy Act are triggered by the agency that is acting as an IdP, by the agency that is acting as an RP, or both (see Sec. 7.4).</p>
      </part>
      <part id="PRIVR-1_obj" name="objective">
        <p>Determine whether the agency has consulted with its SAOP to analyze Privacy Act applicability for its RP and/or IdP roles.</p>
        <link href="#PRIVR-1_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation of the SAOP consultation and the resulting Privacy Act analysis, covering the agency's role(s) as an RP, an IdP, or both.</p>
      </part>
      <part id="PRIVR-1_gdn" name="guidance">
        <p>Assessment is required when: The assessment target (IdP or RP) is a federal agency.</p>
        <p>It is critical to involve an agency's SAOP in the earliest stages of federation implementation development to assess and mitigate privacy risks and advise the agency on compliance obligations, such as whether the federation triggers the Privacy Act of 1974 or the E-Government Act of 2002 requirement to conduct a PIA. For example, if the Agency is serving as an IdP in a federation, it is likely that the Privacy Act requirements will be triggered and that coverage is required under either a new or existing Privacy Act system of records, since credentials would be maintained at the IdP on behalf of any RP it federates with. If, however, the agency is an RP and using a third-party IdP, federated authentication may not trigger the requirements of the Privacy Act, depending on what data passed from the RP is maintained by the agency as the RP (in such instances, the agency may have a broader programmatic SORN that covers such data). Due to the many components involved in federation, it is important for the SAOP to have awareness and understanding of each component. For example, other privacy artifacts may be applicable to an agency offering or using federated IdP or RP services, such as Data Use Agreements, Computer Matching Agreements, etc. The SAOP can assist the agency in determining what additional requirements apply. Moreover, a thorough understanding of the individual components of digital authentication will enable the SAOP to assess and mitigate privacy risks through compliance processes or other means.</p>
      </part>
    </control>
    <control id="PRIVR-2">
      <title>SORN</title>
      <prop name="label" class="index" value="3.10 #2"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-2_smt" name="statement">
        <p>The agency SHALL publish or identify coverage by a System of Records Notice (SORN), as applicable.</p>
      </part>
      <part id="PRIVR-2_obj" name="objective">
        <p>Determine whether the agency has published or identified coverage by a SORN, as applicable.</p>
        <link href="#PRIVR-2_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the agency's SORN documentation to verify that federation activities are covered by either a dedicated SORN or an existing programmatic SORN.</p>
      </part>
      <part id="PRIVR-2_gdn" name="guidance">
        <p>Assessment is required when: The assessment target (IdP or RP) is a federal agency.</p>
        <p>This control applies when PRIVR-1 analysis determines that the Privacy Act is triggered. If the SAOP has determined that the Privacy Act is triggered, the agency is required to either publish or identify existing coverage by a SORN.</p>
      </part>
    </control>
    <control id="PRIVR-3">
      <title>E-Government Act</title>
      <prop name="label" class="index" value="3.10 #3"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-3_smt" name="statement">
        <p>The agency SHALL consult with their SAOP to conduct an analysis that determines whether the requirements of the E-Government Act are triggered by the agency that is acting as an IdP, the agency that is acting as an RP, or both.</p>
      </part>
      <part id="PRIVR-3_obj" name="objective">
        <p>Determine whether the agency has consulted with its SAOP to analyze E-Government Act applicability for its RP and/or IdP roles.</p>
        <link href="#PRIVR-3_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation of the SAOP consultation and the resulting E-Government Act analysis, covering the agency's role(s) as RP, IdP, or both.</p>
      </part>
      <part id="PRIVR-3_gdn" name="guidance">
        <p>Assessment is required when: The assessment target (IdP or RP) is a federal agency.</p>
        <p>The E-Government Act of 2002 may require the agency to conduct a Privacy Impact Assessment (PIA) for its federation activities. The SAOP can assist the agency in determining whether a PIA is required. As with PRIVR-1, these considerations should not be read as a requirement to develop a PIA for federation alone - in many cases, it will make the most sense to draft a PIA that encompasses the entire digital identity process or includes federation as part of a larger programmatic PIA.</p>
      </part>
    </control>
    <control id="PRIVR-4">
      <title>Privacy Impact Assessment</title>
      <prop name="label" class="index" value="3.10 #4"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-4_smt" name="statement">
        <p>The agency SHALL publish or identify coverage by a Privacy Impact Assessment (PIA), as applicable.</p>
      </part>
      <part id="PRIVR-4_obj" name="objective">
        <p>Determine whether the agency has published or identified coverage by a PIA, as applicable.</p>
        <link href="#PRIVR-4_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine agency's PIA documentation to verify that federation activities are covered, either by a dedicated PIA or by an existing programmatic PIA.</p>
      </part>
      <part id="PRIVR-4_gdn" name="guidance">
        <p>Assessment is required when: The assessment target (IdP or RP) is a federal agency.</p>
        <p>This control applies when PRIVR-3 analysis determines that the E-Government Act is triggered. The agency must either publish a new PIA or identify an existing PIA that covers the federation activities. A dedicated PIA for federation is not required - coverage may be provided by a broader programmatic PIA that encompasses the digital identity process or the program establishing online access.</p>
      </part>
    </control>
    <control id="PRIVR-5">
      <title>Privacy Risk Assessment</title>
      <prop name="label" class="index" value="3.10 #5"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-5_smt" name="statement">
        <p>The agency SHALL conduct a privacy risk assessment regarding the sharing of subscriber identity information between the IdP and RP.</p>
      </part>
      <part id="PRIVR-5_obj" name="objective">
        <p>Determine whether the agency has conducted a privacy risk assessment regarding the sharing of subscriber identity information between the IdP and RP.</p>
        <link href="#PRIVR-5_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the agency's privacy risk assessment documentation addressing the sharing of subscriber identity information in federation transactions.</p>
      </part>
      <part id="PRIVR-5_gdn" name="guidance">
        <p>Assessment is required when: The assessment target (IdP or RP) is a federal agency.</p>
        <p>This assessment focuses specifically on the risks associated with sharing subscriber identity information between federation parties. Unlike the Privacy Act and E-Government Act analyses (PRIVR-1, PRIVR-3), this assessment is required regardless of whether those statutes are triggered.</p>
      </part>
    </control>
    <control id="PRIVR-6">
      <title>Provisioning API Privacy Measures</title>
      <prop name="label" class="index" value="3.10 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-6_smt" name="statement">
        <p>If the RP subscriber account life cycle process gives the RP access to attributes through a provisioning API (see Sec. 4.6.3), additional privacy measures SHALL be implemented to account for the difference in the RP subscriber account life cycle (e.g., separation of non-active subscriber accounts, proactive removal of disabled and terminated accounts).</p>
      </part>
      <part id="PRIVR-6_obj" name="objective">
        <p>Determine whether the RP implements additional privacy measures to account for RP subscriber account life cycle differences when using a provisioning API.</p>
        <link href="#PRIVR-6_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's policies and system documentation for provisioning API integration to verify that additional privacy measures address any differences arising from the RP subscriber account lifecycle, such as the separation of non-active accounts and the proactive removal of disabled and terminated accounts.</p>
      </part>
      <part id="PRIVR-6_gdn" name="guidance">
        <p>Assessment is required when: The RP subscriber account life cycle process gives the RP access to attributes through a provisioning API.</p>
        <p>When an RP receives subscriber attributes through a provisioning API, the RP subscriber account life cycle may differ from the subscriber account life cycle at the IdP. For example, the RP may have accounts that are no longer active at the IdP. Additional privacy measures address these differences by ensuring that subscriber data is appropriately managed throughout the RP subscriber account lifecycle.</p>
      </part>
    </control>
    <control id="PRIVR-7">
      <title>Provisioning API Attribute Minimization</title>
      <prop name="label" class="index" value="3.10 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-7_smt" name="statement">
        <p>The IdP SHALL minimize the attributes that are made available to the RP through the provisioning API.</p>
      </part>
      <part id="PRIVR-7_obj" name="objective">
        <p>Determine whether the IdP minimizes the attributes made available to the RP through the provisioning API.</p>
        <link href="#PRIVR-7_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-7_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by TSI-1.</p>
      </part>
      <part id="PRIVR-7_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides attributes through a provisioning API.</p>
        <p>Provisioning APIs can expose a broader set of subscriber attributes than would typically be transmitted in individual federation transactions. The IdP must ensure that only the minimum necessary attributes are made available through this channel, consistent with data minimization principles.</p>
      </part>
    </control>
    <control id="PRIVR-8">
      <title>Provisioning API Population Limitation</title>
      <prop name="label" class="index" value="3.10 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-8_smt" name="statement">
        <p>The IdP SHALL limit the population of subscriber accounts that are available via the provisioning API to the population of subscribers authorized to use the RP by the trust agreement.</p>
      </part>
      <part id="PRIVR-8_obj" name="objective">
        <p>Determine whether the IdP limits the subscriber accounts available via the provisioning API to the population of subscribers authorized to use the RP as specified in the trust agreement artifact(s).</p>
        <link href="#PRIVR-8_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP provisioning API configuration and access control documentation to verify that only subscribers authorized to use the RP per the trust agreement artifact(s) are included in the provisioned population.</p>
      </part>
      <part id="PRIVR-8_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides attributes through a provisioning API.</p>
        <p>Provisioning APIs can pre-populate RP subscriber accounts before subscribers authenticate. The IdP must ensure that only subscribers authorized to use the RP under the trust agreement artifact(s) are included. This prevents the RP from receiving data about subscribers who have no relationship with the RP.</p>
      </part>
    </control>
    <control id="PRIVR-9">
      <title>Subscriber Account Deprovisioning via API</title>
      <prop name="label" class="index" value="3.10 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-9_smt" name="statement">
        <p>To prevent RP retention of identity attributes for accounts that have been terminated at the IdP, the IdP SHALL use the provisioning API to deprovision RP subscriber accounts for terminated subscriber accounts except where restricted by RP data retention requirements, policies, or regulation.</p>
      </part>
      <part id="PRIVR-9_obj" name="objective">
        <p>Determine whether the IdP actively uses the provisioning API to deprovision RP subscriber accounts when corresponding subscriber accounts are terminated at the IdP, when the IdP is not restricted from doing so by RP retention requirements, policies, or regulations.</p>
        <link href="#PRIVR-9_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) documenting any RP retention exceptions that restrict automatic deprovisioning. Examine audit logs that correlate subscriber account terminations at the IdP with corresponding deprovisioning actions sent to RPs, and ensure that deprovisioning occurs unless there is an RP exception, and that deprovisioning does not occur if any RP exception conditions have been met.</p>
      </part>
      <part id="PRIVR-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by terminating a test subscriber account at the IdP that should result in deprovisioning and verify that a deprovisioning action is sent to the RP via the provisioning API Then, terminate a test subscriber account at the IdP that should not result in deprovisioning and verify that no deprovisioning action is sent to the RP.</p>
      </part>
      <part id="PRIVR-9_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides attributes through a provisioning API.</p>
        <p>This requirement enforces data minimization principles by ensuring the IdP proactively removes subscriber data from RPs when accounts are terminated, rather than allowing indefinite retention of stale identity attributes. The exception clause acknowledges that RPs may have legitimate data retention requirements (legal, regulatory, or policy-based) that prevent immediate deletion. Trust agreement artifact(s) should document any such exceptions. Note that when an RP subscriber account is linked to multiple federated identifiers (see Sec. 3.8.1), deprovisioning one federated identifier may result in a persistent RP subscriber account linked to a different federated identifier.</p>
      </part>
    </control>
    <control id="PRIVR-10">
      <title>Data Exchange Minimization</title>
      <prop name="label" class="index" value="3.10 E"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PRIVR-10_smt" name="statement">
        <p>The IdP and RP SHALL exchange only the minimum data necessary to achieve the function of the system.</p>
      </part>
      <part id="PRIVR-10_obj" name="objective">
        <p>Determine whether the IdP and RP limit data exchanged between them to only what is necessary for system functionality.</p>
        <link href="#PRIVR-10_smt" rel="assessment-for"/>
      </part>
      <part id="PRIVR-10_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For IdPs: Satisfied by TSI-1.</p>
        <p>For RPs:                                                                                                                                                                                                                     Examine the trust agreement artifact(s) documenting the attributes to be exchanged and their stated purposes. Review data transmitted from RP to IdP and verify that each data element has a corresponding functional justification and that no extraneous data is transmitted.</p>
      </part>
      <part id="PRIVR-10_gdn" name="guidance">
        <p>Assessors should verify that each attribute exchanged has a documented purpose tied to system functionality-attributes exchanged "just in case" or for undefined future use would indicate non-compliance.</p>
        <p>Transmission of subscriber activities to the IdP is further restricted by TSI-4, which limits such transmission to fraud mitigation and security incident response purposes only.</p>
      </part>
    </control>
    <control id="TSI-1">
      <title>IdP Data Exchange Minimization</title>
      <prop name="label" class="index" value="3.10.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TSI-1_smt" name="statement">
        <p>The IdP SHALL limit the transmission of subscriber information to only that which is necessary for the system to function and is stipulated and disclosed by the trust agreement.</p>
      </part>
      <part id="TSI-1_obj" name="objective">
        <p>Determine whether the IdP limits transmission of subscriber information to only what is (1) necessary for permissible system functions and (2) stipulated and disclosed in the trust agreement artifact(s).</p>
        <link href="#TSI-1_smt" rel="assessment-for"/>
      </part>
      <part id="TSI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) documenting transmissible attributes and their purposes. For each attribute authorized for transmission, verify that it maps to a necessary system function (such as identity service, specific subscriber request, fraud mitigation, or security incident response) and has a documented functional justification. Review IdP attribute release configuration and compare against trust agreement artifact(s) to verify no unauthorized attributes are transmitted.</p>
      </part>
      <part id="TSI-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating an assertion for a test RP. Verify that no attributes appear in the assertion beyond those authorized by the trust agreement artifact(s). If the federation protocol permits runtime attribute requests, configure the test RP to request attributes outside the trust agreement artifact(s) and verify the IdP rejects or ignores the unauthorized request.</p>
      </part>
      <part id="TSI-1_gdn" name="guidance">
        <p>Typical system functions include the following:</p>
        <ul>
          <li>
            <p>Identity proofing, authentication, or attribute assertions (collectively "identity service");</p>
          </li>
          <li>
            <p>A specific subscriber request to transmit the information;</p>
          </li>
          <li>
            <p>Fraud mitigation related to the identity service; or - Responding to a security incident related to the identity service.</p>
          </li>
        </ul>
        <p>RP compliance with data exchange minimization is assessed under PRIVR-10.</p>
      </part>
    </control>
    <control id="TSI-2">
      <title>IdP Privacy Risk Management for Additional Processing</title>
      <prop name="label" class="index" value="3.10.1 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TSI-2_smt" name="statement">
        <p>If an IdP discloses information on subscriber activities at an RP to any party, or processes the subscriber's attributes for any purpose other than these cases [Identity proofing, authentication, or attribute assertions (collectively "identity service"); A specific subscriber request to transmit the information; Fraud mitigation related to the identity service; or Responding to a security incident related to the identity service], the IdP SHALL implement measures to maintain predictability and manageability commensurate with the privacy risks that arise from the additional processing.</p>
      </part>
      <part id="TSI-2_obj" name="objective">
        <p>Determine whether the IdP implements measures to maintain predictability and manageability commensurate with privacy risks, when the IdP discloses information on subscriber activities at an RP to any party or processes subscriber attributes for any purpose other than for an identity service, a specific subscriber request, fraud mitigation, or a security incident response.</p>
        <link href="#TSI-2_smt" rel="assessment-for"/>
      </part>
      <part id="TSI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's policies and practices regarding the processing of subscriber information. First, identify whether the IdP processes subscriber information for any purpose beyond these functions: identity proofing, authentication, or attribute assertions (collectively "identity service"); a specific subscriber request to transmit the information; fraud mitigation related to the identity service; or responding to a security incident related to the identity service.</p>
        <p>If additional processing occurs, review the IdP's privacy risk assessment for that processing and verify that implemented measures (such as notice, consent, or selective disclosure controls) are commensurate with the identified risks.</p>
      </part>
      <part id="TSI-2_gdn" name="guidance">
        <p>Assessment is required when: An IdP discloses information on subscriber activities at an RP to any party, or processes the subscriber's attributes for any purpose other than these case: Identity proofing, authentication, or attribute assertions (collectively "identity service"); A specific subscriber request to transmit the information; Fraud mitigation related to the identity service; or Responding to a security incident related to the identity service.</p>
        <p>By the nature of a federated protocol, the IdP will know which RPs a subscriber logs in to and will know which attributes have been released to which RPs. This information is used as part of the federated login process, identified here as "identity service", to facilitate login to an RP. IdPs need to use measures to maintain the objectives of predictability (enabling reliable assumptions by individuals, owners, and operators about PII and its processing by an information system) and manageability (providing the capability for granular administration of PII, including alteration, deletion, and selective disclosure) commensurate with privacy risks that can arise from the processing of information for purposes other than identity proofing, authentication, authorization, or attribute assertion, related fraud mitigation, or to comply with law or legal process as in [NISTIR8062].</p>
        <p>However, processing information for purposes other than the identity service can create privacy risks when individuals are not expecting or are not comfortable with the additional processing. These exception cases, which are not part of the federated identity protocol process, need to be managed in accordance with the risks associated with such additional processing of the subscriber's information. IdPs can use privacy risk assessments to determine the extent of privacy risks arising from such processing and implement measures commensurate with the privacy risk arising from the additional processing. Such measures may include providing clear notice, obtaining subscriber consent, or enabling selective use or disclosure of attributes, but other measures may be more effective in mitigating the privacy risks depending on the type of processing.</p>
      </part>
    </control>
    <control id="TSI-3">
      <title>Prohibition on Coerced Consent</title>
      <prop name="label" class="index" value="3.10.1 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TSI-3_smt" name="statement">
        <p>When an IdP gathers the subscriber's consent to use information outside the identity transaction, the IdP SHALL NOT make consent for the additional processing a condition of the identity service.</p>
      </part>
      <part id="TSI-3_obj" name="objective">
        <p>Determine whether the IdP refrains from making consent for additional processing a condition of the identity service, when the IdP gathers subscriber consent to use information outside the identity transaction.</p>
        <link href="#TSI-3_smt" rel="assessment-for"/>
      </part>
      <part id="TSI-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's consent mechanisms and user interface flows for gathering subscriber consent to additional processing. Verify that subscribers can decline consent for additional processing and still complete identity service functions.</p>
      </part>
      <part id="TSI-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to use the identity service while declining consent for any additional processing. Verify that the identity service remains available.</p>
      </part>
      <part id="TSI-3_gdn" name="guidance">
        <p>Assessment is required when: An IdP gathers the subscriber's consent to use information outside the identity transaction.</p>
        <p>Subscriber consent must be meaningful. When IdPs use consent measures for processing beyond identity service functions, they cannot make subscriber acceptance of additional processing a condition of providing the identity service. For example, an IdP cannot require a subscriber to consent to marketing use of their data as a condition of federated login.</p>
      </part>
    </control>
    <control id="TSI-4">
      <title>RP Subscriber Activity Transmission Limits</title>
      <prop name="label" class="index" value="3.10.1 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TSI-4_smt" name="statement">
        <p>An RP SHALL limit the transmission of subscriber activities to the associated IdP to the following cases, and only if stipulated and disclosed by the trust agreement:</p>
        <p>(a) Fraud mitigation related to the identity service</p>
        <p>(b) Responding to a security incident related to the identity service</p>
      </part>
      <part id="TSI-4_obj" name="objective">
        <p>Determine whether the RP limits transmission of subscriber activities to the IdP to only fraud mitigation or security incident response, and only when stipulated and disclosed by the trust agreement.</p>
        <link href="#TSI-4_smt" rel="assessment-for"/>
      </part>
      <part id="TSI-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's system configuration and data flow documentation to determine whether the RP transmits subscriber activity to the IdP. If transmission occurs, verify that (1) the transmission is stipulated and disclosed in the trust agreement artifact(s), and (2) the purpose is limited to fraud mitigation related to the identity service or to responding to a security incident related to the identity service.</p>
      </part>
      <part id="TSI-4_gdn" name="guidance">
        <p>"Subscriber activities" refers to actions the subscriber takes at the RP, such as login events, transactions, or usage patterns.</p>
      </part>
    </control>
    <control id="TSI-5">
      <title>Subscriber Notice &amp; Consent for Additional Uses</title>
      <prop name="label" class="index" value="3.10.1 E"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TSI-5_smt" name="statement">
        <p>If an RP uses the subscriber's identity information for any purpose other than those stipulated in the trust agreement, the RP SHALL inform the subscriber and obtain their consent for such additional uses.</p>
      </part>
      <part id="TSI-5_obj" name="objective">
        <p>Determine whether the RP informs the subscriber and obtains consent when using the subscriber's identity information for any purpose other than those stipulated in the trust agreement.</p>
        <link href="#TSI-5_smt" rel="assessment-for"/>
      </part>
      <part id="TSI-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine by reviewing all RP policies that document the purposes for which subscriber identity information is used, and compare that documentation to the purposes stipulated in the trust agreement artifact(s). If uses beyond the trust agreement exist, verify that (1) the RP provides notice to subscribers describing the additional use(s), and (2) the RP obtains subscriber consent prior to the additional use(s).</p>
      </part>
      <part id="TSI-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a representative subscriber flow for each category of additional use, and determine that the RP informs the subscriber of the additional use and obtains the subscriber's consent before that additional use occurs.</p>
      </part>
      <part id="TSI-5_gdn" name="guidance">
        <p>Assessment is required when: An RP uses the subscriber's identity information for any purpose other than those stipulated in the trust agreement.</p>
        <p>"Identity information" can include identity attributes received from the IdP as well as subscriber activities at the RP. "Specifically consents" indicates that general terms of service acceptance are insufficient-the subscriber must affirmatively agree to the specific additional use.</p>
      </part>
    </control>
    <control id="SIBC-1">
      <title>CSP/IdP Information Transmission Limitations</title>
      <prop name="label" class="index" value="3.10.2 A"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SIBC-1_smt" name="statement">
        <p>All information transmissions between CSPs and/or IdPs SHALL be subject to the limitations for IdPs enumerated in Sec. 3.10.1.</p>
      </part>
      <part id="SIBC-1_obj" name="objective">
        <p>Determine whether information transmissions between CSPs and/or IdPs comply with the limitations enumerated for IdPs in Sec. 3.10.1.</p>
        <link href="#SIBC-1_smt" rel="assessment-for"/>
      </part>
      <part id="SIBC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation that identifies all information transmitted between CSPs and/or IdPs. For each category of information/attributes transmitted, apply the assessment methods from TSI-1, TSI-2, and TSI-3 to verify that the transmission complies with the stated information-sharing limitations.</p>
      </part>
      <part id="SIBC-1_gdn" name="guidance">
        <p>In some larger federation systems, particularly multilateral federations managed by federation authorities, multiple CSPs may be involved in the same trust agreement. In such cases, it may be desirable for CSPs to share information with one another to support activities such as fraud mitigation (e.g., to prevent an attacker from jumping between CSPs with different accounts to avoid detection). While sharing information in this way can help mitigate fraud, there are also substantial privacy concerns, as CSPs could learn subscriber attributes and actions from each other that were not initially disclosed to all CSPs the subscriber uses. Similar information sharing could be desirable between IdPs that operate independently of the CSP, such as between subscriber-controlled wallets hosted on remote systems, and such sharing entails similar privacy considerations.</p>
        <p>(See NISTIR 8062 for guidance on privacy engineering objectives, including predictability and manageability.)</p>
      </part>
    </control>
    <control id="SIBC-2">
      <title>CSP/IdP Information Sharing Privacy Risk Assessment</title>
      <prop name="label" class="index" value="3.10.2 B"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SIBC-2_smt" name="statement">
        <p>Any such information sharing between CSPs and/or IdPs SHALL be included in their privacy risk assessments.</p>
      </part>
      <part id="SIBC-2_obj" name="objective">
        <p>Determine whether information sharing between CSPs and/or IdPs is included in each party's privacy risk assessment.</p>
        <link href="#SIBC-2_smt" rel="assessment-for"/>
      </part>
      <part id="SIBC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation that identifies all information transmitted between CSPs and/or IdPs. Review each participating CSP's and IdP's privacy risk assessment and verify that the identified information sharing is addressed.</p>
      </part>
      <part id="SIBC-2_gdn" name="guidance">
        <p>Assessment is required when: Information is shared between CSPs and/or IdPs.</p>
        <p>This control ensures that CSPs and IdPs explicitly consider the privacy implications of inter-party information sharing. While such sharing can support fraud mitigation, it also creates risks that CSPs could learn subscriber attributes and actions from each other that were not originally disclosed to all CSPs the subscriber uses.</p>
      </part>
    </control>
    <control id="SIBC-3">
      <title>CSP Information Transfer Policy</title>
      <prop name="label" class="index" value="3.10.2 C"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SIBC-3_smt" name="statement">
        <p>The terms of the trust agreement that connects CSPs SHALL define the policies that apply for the transfer of information shared between CSPs.</p>
      </part>
      <part id="SIBC-3_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) that connect CSPs define policies for the transfer of information shared between CSPs.</p>
        <link href="#SIBC-3_smt" rel="assessment-for"/>
      </part>
      <part id="SIBC-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) that establish the CSP connections. Verify that policies are defined for the transfer of information shared between CSPs, including what information may be transferred, under what circumstances, and any restrictions on use. Then, examine sample records of information shared between CSPs to verify that all sharing complies with the policies defined in the trust agreement artifact(s).</p>
      </part>
      <part id="SIBC-3_gdn" name="guidance">
        <p>Assessment is required when: Two or more CSPs are connected under a (set) of trust agreement artifact(s).</p>
        <p>In a trust agreement managed by a federation authority, the federation authority defines these terms.</p>
      </part>
    </control>
    <control id="SECC-1">
      <title>IdP/CSP Security Controls</title>
      <prop name="label" class="index" value="3.11 A"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECC-1_smt" name="statement">
        <p>IdPs and CSPs SHALL employ appropriately tailored security controls from at least the moderate baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard that the organization has determined for the information systems, applications, and online services that these guidelines are used to protect.</p>
      </part>
      <part id="SECC-1_obj" name="objective">
        <p>Determine whether the IdP/CSP employs appropriately tailored security controls from at least the moderate baseline defined in SP 800-53 or an equivalent standard.</p>
        <link href="#SECC-1_smt" rel="assessment-for"/>
      </part>
      <part id="SECC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine evidence that the IdP/CSP has been assessed against at least the moderate baseline security controls defined in SP 800-53 or an equivalent standard. Verify that the resulting authorization or certification is current and covers all systems supporting federation services.</p>
      </part>
      <part id="SECC-1_gdn" name="guidance">
        <p>A compromise of the IdP/CSP or its cryptographic material would be detrimental to the federation network. As a consequence, the IdP/CSP has to employ stringent security controls, and these controls help protect the network as a whole.</p>
        <p>NIST SP 800-53 rev.5 and SP 800-53B provide a comprehensive catalog of controls, three security control baselines (low, moderate, and high impact), and guidance for tailoring the appropriate baseline to specific needs and risk environments for federal information systems. These controls are the operational, technical, and management safeguards to maintain the integrity, confidentiality, and security of federal information systems and are intended to be used in conjunction with the NIST risk management framework outlined in SP 800-37 and SP 800-63-3 section 5, Digital Identity Risk Management. NIST SP 800-53B presents security control baselines determined by the security categorization of the information system (low, moderate or high) from NIST FIPS 199 Standards for Security Categorization of Federal Information and Information Systems. The moderate and high baseline controls may be considered the starting point for the selection, enhancement, and tailoring of the security controls presented. Guidance on tailoring the control baselines to best meet the organization's risk environment, systems and operations is presented in SP 800-53B section 2.4 Tailoring Baseline Security Controls.</p>
        <p>While SP 800-53B and other NIST Special Publications in the SP-800-XXX series apply to federal agencies for the implementation of the Federal information Security Modernization (Management) Act (FISMA), non-federal entities providing services for federal information systems may also need to demonstrate appropriate controls and should similarly use SP 800-53 and associated publications as resources. Non-federal entities may be subject to and conformant with other applicable controls systems and processes for information system security (e.g., FEDRAMP, ISO/IEC 27001).</p>
      </part>
    </control>
    <control id="SECC-2">
      <title>RP Security Controls</title>
      <prop name="label" class="index" value="3.11 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECC-2_smt" name="statement">
        <p>RPs SHALL employ appropriately tailored security controls from at least the low baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard that the organization has determined for the information systems, applications, and online services that these guidelines are used to protect.</p>
      </part>
      <part id="SECC-2_obj" name="objective">
        <p>Determine whether the RP employs appropriately tailored security controls from at least the low baseline defined in SP 800-53 or an equivalent standard.</p>
        <link href="#SECC-2_smt" rel="assessment-for"/>
      </part>
      <part id="SECC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine evidence that the RP has been assessed against at least the low baseline security controls defined in SP 800-53 or an equivalent standard. Verify that the resulting authorization or certification is current and covers all systems supporting federation services.</p>
      </part>
      <part id="SECC-2_gdn" name="guidance">
        <p>Assessment is required when: The RP does not request or process personal information.</p>
        <p>RPs that request or process personal information must implement security controls at the moderate baseline or higher (see SECC-3).</p>
      </part>
    </control>
    <control id="SECC-3">
      <title>RP Security Controls for Personal Information</title>
      <prop name="label" class="index" value="3.11 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECC-3_smt" name="statement">
        <p>RPs that request or process personal information SHALL employ appropriately tailored security controls from at least the moderate baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard.</p>
      </part>
      <part id="SECC-3_obj" name="objective">
        <p>Determine whether RPs that request or process personal information employ appropriately tailored security controls from at least the moderate baseline defined in [SP800-53] or an equivalent standard.</p>
        <link href="#SECC-3_smt" rel="assessment-for"/>
      </part>
      <part id="SECC-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine evidence that the RP has been assessed against at least the moderate baseline security controls defined in SP 800-53 or an equivalent standard. Verify that the resulting authorization or certification is current and covers the systems supporting federation services.</p>
      </part>
      <part id="SECC-3_gdn" name="guidance">
        <p>Assessment is required when: The RP processes personal information.</p>
        <p>This control supersedes SECC-2 for RPs handling personal information, raising the minimum baseline from low to moderate.</p>
      </part>
    </control>
    <control id="SECC-4">
      <title>Assurance Level Baseline Controls</title>
      <prop name="label" class="index" value="3.11 D"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SECC-4_smt" name="statement">
        <p>CSPs, IdPs, and RPs SHALL ensure that the minimum assurance-related controls for the appropriate systems or equivalent are satisfied or exceeded.</p>
      </part>
      <part id="SECC-4_obj" name="objective">
        <p>Determine whether CSPs, IdPs, and RPs satisfy or exceed the minimum assurance-related controls for their selected IAL(s), AAL(s), and FAL(s).</p>
        <link href="#SECC-4_smt" rel="assessment-for"/>
      </part>
      <part id="SECC-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation that identifies the IAL(s), AAL(s), and/or FAL(s) that the organization accepts/provides. Then, identify the applicable baseline controls from [SP800-63A] for the selected IAL(s), [SP800-63B] for the selected AAL(s), and [SP800-63C] for the selected FAL(s).  Assess or verify the assessment of each applicable set of baseline controls. Record the compliance status based on the results of the baseline control assessment. Determine whether the minimum assurance-related controls have been satisfied or exceeded.</p>
      </part>
      <part id="SECC-4_gdn" name="guidance">
        <p>Compliance with this control is demonstrated through the results of the applicable baseline control assessments from SP 800-63A, SP 800-63B, and SP 800-63C.</p>
      </part>
    </control>
    <control id="PSI-1">
      <title>IdP-RP Communication Protection</title>
      <prop name="label" class="index" value="3.11.2 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PSI-1_smt" name="statement">
        <p>Communications between the IdP and the RP SHALL be protected in transit using an authenticated protected channel.</p>
      </part>
      <part id="PSI-1_obj" name="objective">
        <p>Determine whether all communications between the IdP and RP are protected in transit using an authenticated protected channel.</p>
        <link href="#PSI-1_smt" rel="assessment-for"/>
      </part>
      <part id="PSI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation that reveals the functions for which the IdP and RP communicate (e.g., assertion exchange, provisioning API, key retrieval, dynamic registration), and list those functions. For communications covered by specific controls (BCP-8, DR-2, DYR-1, ICKM-2, CKR-2, PAPI-3), assess or verify assessment of each applicable control. For any IdP-RP communications not covered by a specific control, verify that the communication is configured to use an authenticated protected channel.</p>
      </part>
      <part id="PSI-1_gdn" name="guidance">
        <p>This control is the umbrella requirement for protecting IdP-RP communication. Most IdP-RP communication scenarios have dedicated controls with specific assessment procedures. This control catches any communication pathways that fall outside those dedicated controls. If all IdP-RP communications are covered by the specific controls listed in the assessment method, step (3) will have no additional items to assess, and the assessor should document that.</p>
      </part>
    </control>
    <control id="PSI-2">
      <title>Subscriber Communication Protection</title>
      <prop name="label" class="index" value="3.11.2 B"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PSI-2_smt" name="statement">
        <p>Communications between the subscriber and either the IdP or the RP (usually through a user agent) SHALL be made using an authenticated protected channel.</p>
      </part>
      <part id="PSI-2_obj" name="objective">
        <p>Determine whether communications between the subscriber and the IdP or RP occur over an authenticated protected channel.</p>
        <link href="#PSI-2_smt" rel="assessment-for"/>
      </part>
      <part id="PSI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation that reveals the functions for which the subscriber communicates with the IdP or RP (e.g., authentication, assertion conveyance, consent), and list those functions. For communications covered by specific controls (BCP-7, FCP-3), assess or verify the assessment of each applicable control. For any subscriber-IdP or subscriber-RP communications not covered by a specific control, verify that the communication is configured to use an authenticated protected channel. Record compliance status based on the results.</p>
      </part>
      <part id="PSI-2_gdn" name="guidance">
        <p>Compliance is determined by assessing the applicable specific controls (BCP-7, FCP-3) and verifying that any communications not covered by those controls also use an authenticated protected channel.</p>
        <p>"User agent" refers to the subscriber's browser or application.</p>
      </part>
    </control>
    <control id="PSI-3">
      <title>Identity API Enumeration in Trust Agreement</title>
      <prop name="label" class="index" value="3.11.2 C"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PSI-3_smt" name="statement">
        <p>The use of identity APIs SHALL be enumerated in the terms of the trust agreement.</p>
      </part>
      <part id="PSI-3_obj" name="objective">
        <p>Determine whether the use of identity APIs is enumerated in the trust agreement artifact(s).</p>
        <link href="#PSI-3_smt" rel="assessment-for"/>
      </part>
      <part id="PSI-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by IDAP-1.</p>
      </part>
      <part id="PSI-3_gdn" name="guidance">
        <p>Assessment is required when: An identity API is used.</p>
        <p>Identity attributes MAY be included outside of the assertion itself by authorizing access to an identity API, as discussed in Sec. 3.12.3. Splitting identity information in this manner can help protect subscriber privacy and can allow for the limited disclosure of personal information in addition to the essential information in the authentication assertion itself.</p>
        <p>IDAP-1 establishes the requirement to record and disclose all possible use of identity APIs in the trust agreement artifact(s), including which provisioning models are available through the API.</p>
      </part>
    </control>
    <control id="SSIN-1">
      <title>Personal Information Storage Security</title>
      <prop name="label" class="index" value="3.11.3 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIN-1_smt" name="statement">
        <p>Whether the account is active or not, the IdP and RP SHALL store personal information in a subscriber account or RP subscriber account using tailored security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard.</p>
      </part>
      <part id="SSIN-1_obj" name="objective">
        <p>Determine whether the IdP and RP store personal information in subscriber accounts using tailored security controls from [SP800-53] or an equivalent standard.</p>
        <link href="#SSIN-1_smt" rel="assessment-for"/>
      </part>
      <part id="SSIN-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For IdPs, satisfied by SECC-1.</p>
        <p>For satisfied by SECC-3.</p>
      </part>
      <part id="SSIN-1_gdn" name="guidance">
        <p>Storage of personal information is a form of processing. SECC-1 requires IdPs and CSPs to implement at least moderate baseline security controls. SECC-3 requires RPs that request or process personal information to implement at least moderate baseline security controls.</p>
      </part>
    </control>
    <control id="SSIN-2">
      <title>Justification for Non-Deletion</title>
      <prop name="label" class="index" value="3.11.3 B"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIN-2_smt" name="statement">
        <p>IdPs and RPs that do not support deletion SHALL provide a statutory or risk-based justification and document it in the trust agreement.</p>
      </part>
      <part id="SSIN-2_obj" name="objective">
        <p>Determine whether IdPs and RPs that do not support deletion provide a statutory or risk-based justification documented in the trust agreement artifact(s).</p>
        <link href="#SSIN-2_smt" rel="assessment-for"/>
      </part>
      <part id="SSIN-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine evidence to determine whether the IdP or RP supports the deletion of personal information. If deletion is not supported, verify that a statutory or risk-based justification is documented in the trust agreement artifact(s), as required by TRUST-9.</p>
      </part>
      <part id="SSIN-2_gdn" name="guidance">
        <p>Assessment is required when: The IdP/RP does not support the deletion of personal information.</p>
        <p>TRUST-9 requires trust agreement artifact(s) to declare data retention policies for all parties. This control adds the requirement that when deletion is not supported, a statutory or risk-based justification must be provided-general policy statements are insufficient.</p>
      </part>
    </control>
    <control id="SSIN-3">
      <title>Attribute Removal Upon Account Termination</title>
      <prop name="label" class="index" value="3.11.3 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIN-3_smt" name="statement">
        <p>When the RP subscriber account is terminated, the RP SHALL remove all subscriber attributes from storage, except when otherwise restricted by regulations, laws, or policies or when the risk of an application deems it essential.</p>
      </part>
      <part id="SSIN-3_obj" name="objective">
        <p>Determine whether the RP removes all subscriber attributes from storage when the RP subscriber account is terminated, except when restricted by regulations, laws, policies, or application risk requirements.</p>
        <link href="#SSIN-3_smt" rel="assessment-for"/>
      </part>
      <part id="SSIN-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RPSA-1.</p>
      </part>
      <part id="SSIN-3_gdn" name="guidance">
        <p>Assessment of attribute removal upon RP subscriber account termination is performed under RPSA-1, which covers the full scope of data removal, including federated identifiers, bound authenticators, attributes, and identity information. Exceptions must be documented with a specific regulatory, legal, policy, or risk-based justification; general data retention policies are insufficient.</p>
      </part>
    </control>
    <control id="IDA-1">
      <title>Attribute Presentation Documentation</title>
      <prop name="label" class="index" value="3.12 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDA-1_smt" name="statement">
        <p>Attributes SHALL be either unbundled (i.e., presented directly in an assertion by the IdP) or bundled into a package that is cryptographically signed by the CSP, as described in Sec. 3.12.1.</p>
      </part>
      <part id="IDA-1_obj" name="objective">
        <p>Determine whether the IdP documents which attribute presentation technique(s) it uses - unbundled, bundled, or both.</p>
        <link href="#IDA-1_smt" rel="assessment-for"/>
      </part>
      <part id="IDA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's technical documentation to confirm that the IdP specifies whether attributes are presented unbundled in assertions, bundled with CSP signatures per Section 3.12.1, or both. Verify that this documentation is available to RPs.</p>
      </part>
      <part id="IDA-1_gdn" name="guidance">
        <p>This documentation enables RPs to implement the appropriate validation logic. For unbundled attributes, the RP validates via the assertion signature. For bundled attributes, the RP must additionally validate the CSP's bundle signature per ABUN-2.</p>
      </part>
    </control>
    <control id="IDA-2">
      <title>Attribute Type Documentation</title>
      <prop name="label" class="index" value="3.12 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDA-2_smt" name="statement">
        <p>Attributes SHALL be either attribute values (e.g., a date of birth) or derived attribute values (e.g., an indication of age of majority).</p>
      </part>
      <part id="IDA-2_obj" name="objective">
        <p>Determine whether the IdP documents which attribute types it provides - attribute values, derived attribute values, or both.</p>
        <link href="#IDA-2_smt" rel="assessment-for"/>
      </part>
      <part id="IDA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's technical documentation to confirm that the IdP specifies, for each attribute, whether it is an attribute value or a derived attribute value. Verify that this information is available to RPs.</p>
      </part>
      <part id="IDA-2_gdn" name="guidance">
        <p>RPs need to know whether they will receive actual attribute values (e.g., "2/20/2000") or derived values (e.g., "over 21"). This affects RP business logic and data handling. Derived attribute values support privacy by disclosing only what is necessary; see DAV-1.</p>
      </part>
    </control>
    <control id="IDA-3">
      <title>Attribute Delivery Method Documentation</title>
      <prop name="label" class="index" value="3.12 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDA-3_smt" name="statement">
        <p>Attributes SHALL be either presented in the assertion and covered by the assertion's signature or be made available as part of a protected identity API.</p>
      </part>
      <part id="IDA-3_obj" name="objective">
        <p>Determine whether the IdP documents how attributes are delivered - in the assertion, via identity API, or both.</p>
        <link href="#IDA-3_smt" rel="assessment-for"/>
      </part>
      <part id="IDA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's technical documentation to confirm that the IdP specifies, for each attribute, whether it is delivered in the assertion or via an identity API. Verify that this information is available to RPs.</p>
      </part>
    </control>
    <control id="IDA-4">
      <title>CSP Practice Statement Reference</title>
      <prop name="label" class="index" value="3.12 D"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDA-4_smt" name="statement">
        <p>Trust agreements SHALL point to the CSP's practice statements that describe the processes and sources used for attribute validation.</p>
      </part>
      <part id="IDA-4_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) point to the CSP's practice statements describing the processes and sources used for attribute validation.</p>
        <link href="#IDA-4_smt" rel="assessment-for"/>
      </part>
      <part id="IDA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to verify that they include a reference to the CSP's practice statements. Review the referenced practice statements to verify that they describe the processes and sources used for attribute validation.</p>
      </part>
      <part id="IDA-4_gdn" name="guidance">
        <p>The CSP practice statement enables RPs to evaluate the trustworthiness of attributes by understanding how the CSP validates them. Practice statements typically describe evidence requirements, authoritative sources consulted, and validation procedures used during identity proofing or attribute collection.</p>
      </part>
    </control>
    <control id="ABUN-1">
      <title>Attribute Bundle Presentation Protection</title>
      <prop name="label" class="index" value="3.12.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ABUN-1_smt" name="statement">
        <p>The presentation of an attribute bundle SHALL be protected by the IdP in the same manner as non-bundled attributes.</p>
      </part>
      <part id="ABUN-1_obj" name="objective">
        <p>Determine whether the IdP protects the presentation of attribute bundles in the same manner as non-bundled attributes.</p>
        <link href="#ABUN-1_smt" rel="assessment-for"/>
      </part>
      <part id="ABUN-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SIGNA-1 and SIGNA-3.</p>
      </part>
      <part id="ABUN-1_gdn" name="guidance">
        <p>Attribute bundles are protected by the IdP's assertion signature per SIGNA-1 and SIGNA-3. The attribute bundle also retains its own CSP signature, which the RP must validate per ABUN-2.</p>
        <p>Note: Other protocols and specifications often refer to attribute bundles as credentials. However, this term would be in conflict with its use within these guidelines for a different concept. Consequently, these guidelines use the term "attribute bundle" instead.</p>
      </part>
    </control>
    <control id="ABUN-2">
      <title>Attribute Bundle Signature Validation</title>
      <prop name="label" class="index" value="3.12.1 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ABUN-2_smt" name="statement">
        <p>The RP SHALL validate the signature specific to the attribute bundle as well as any container signatures, such as the signature of the assertion as a whole.</p>
      </part>
      <part id="ABUN-2_obj" name="objective">
        <p>Determine whether the RP validates both the signature specific to the attribute bundle and any container signatures such as the assertion signature.</p>
        <link href="#ABUN-2_smt" rel="assessment-for"/>
      </part>
      <part id="ABUN-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>IdP assertion signature validation is satisfied by FAL1-2.</p>
        <p>For CSP-issued attribute bundles:                                                                                                                                                                Examine the RP's assertion processing documentation to verify that it validates the CSP's signature on the attribute bundle.</p>
        <p>Test by presenting an assertion containing an attribute bundle with an invalid bundle signature but a valid assertion signature. Verify that the RP rejects it.</p>
      </part>
      <part id="ABUN-2_gdn" name="guidance">
        <p>Attribute bundles carry the CSP's signature attesting to the authenticity of the attributes. The assertion signature (validated per FAL1-2) protects the bundle from substitution or tampering during the federation transaction. See ARTVL-1 for the equivalent requirement in subscriber-controlled wallet scenarios.</p>
      </part>
    </control>
    <control id="ABUN-3">
      <title>Bundle-Embedded IdP Verification Key Validation</title>
      <prop name="label" class="index" value="3.12.1 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ABUN-3_smt" name="statement">
        <p>The RP SHALL confirm that the assertion is presented by the identity claimed in the attribute bundle by verifying the signature over the assertion using the IdP's verification key in the signed attribute bundle.</p>
      </part>
      <part id="ABUN-3_obj" name="objective">
        <p>Determine whether the RP uses the IdP verification key embedded in the CSP-signed attribute bundle to verify the assertion signature, thereby confirming the assertion was issued by the IdP authorized by the CSP to present the bundle.</p>
        <link href="#ABUN-3_smt" rel="assessment-for"/>
      </part>
      <part id="ABUN-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's assertion-processing documentation to confirm that the RP extracts the IdP's verification key from the CSP-signed attribute bundle and uses it to verify the assertion's signature.</p>
      </part>
      <part id="ABUN-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting an assertion containing an attribute bundle with a valid embedded IdP verification key. Verify that the RP successfully validates the assertion signature using that key. Then, present an assertion signed by a different IdP than the one whose key is embedded in the attribute bundle. Verify the RP rejects the assertion.</p>
      </part>
      <part id="ABUN-3_gdn" name="guidance">
        <p>Assessment is required when: The attribute bundle includes a verification key for the IdP.</p>
        <p>This control establishes a CSP-to-IdP binding. When the CSP signs an attribute bundle containing a specific IdP's verification key, the CSP restricts which IdP may present that bundle. The RP enforces this restriction by verifying the assertion signature against the embedded key, rather than a key obtained from metadata or trust agreement artifact(s). Note: The phrase "identity claimed in the attribute bundle" in the source text refers to the IdP whose verification key is embedded in the CSP-signed bundle.</p>
      </part>
    </control>
    <control id="DAV-1">
      <title>Derived Attribute Value Non-Disclosure</title>
      <prop name="label" class="index" value="3.12.2 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DAV-1_smt" name="statement">
        <p>To preserve privacy, derived attribute values SHALL NOT disclose the underlying attribute value to a requester.</p>
      </part>
      <part id="DAV-1_obj" name="objective">
        <p>Determine whether derived attribute values are provided without disclosing the underlying attribute value.</p>
        <link href="#DAV-1_smt" rel="assessment-for"/>
      </part>
      <part id="DAV-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a sample or documentation describing IdP assertions and identity API responses containing derived attribute values. For each derived attribute (e.g., "over 21"), verify that the underlying attribute value (e.g., date of birth) is not also included in the same response.</p>
      </part>
      <part id="DAV-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by request a derived attribute value from the IdP. Verify the response contains only the derived value and does not include the underlying attribute value.</p>
      </part>
      <part id="DAV-1_gdn" name="guidance">
        <p>Assessment is required when: Derived attribute values are used.</p>
        <p>Derived attribute values exist to preserve privacy by disclosing only what is necessary. If the underlying value is also disclosed, the privacy benefit is negated. For example, if an RP only needs to know a subscriber is over 21, disclosing the full date of birth defeats the purpose.</p>
      </part>
    </control>
    <control id="IDAP-1">
      <title>Identity API Disclosure in Trust Agreement</title>
      <prop name="label" class="index" value="3.12.3 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDAP-1_smt" name="statement">
        <p>All possible use of identity APIs, including which provisioning models are available through the API, SHALL be recorded and disclosed as part of the trust agreement.</p>
      </part>
      <part id="IDAP-1_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) document the permitted uses of identity APIs and the provisioning models available through those APIs.</p>
        <link href="#IDAP-1_smt" rel="assessment-for"/>
      </part>
      <part id="IDAP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) for each identity API offered to verify that they document all supported uses of the identity API and the provisioning model(s) available through the API.</p>
      </part>
      <part id="IDAP-1_gdn" name="guidance">
        <p>Assessment is required when: An Identity API is offered by the IdP.</p>
        <p>Identity APIs allow RPs to retrieve subscriber attributes outside of the assertion itself. Provisioning models include pre-provisioning, just-in-time provisioning, and ephemeral provisioning (see Sec. 4.6.3).</p>
      </part>
    </control>
    <control id="IDAP-2">
      <title>Identity API Access Time Limitation</title>
      <prop name="label" class="index" value="3.12.3 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDAP-2_smt" name="statement">
        <p>Access to the identity API SHALL be time-limited by the trust agreement.</p>
      </part>
      <part id="IDAP-2_obj" name="objective">
        <p>Determine whether access to the identity API is time-limited as specified in the trust agreement artifact(s).</p>
        <link href="#IDAP-2_smt" rel="assessment-for"/>
      </part>
      <part id="IDAP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to verify that they specify time limits for identity API access. Review the IdP's identity API configuration to verify that access is time-limited in accordance with the trust agreement artifact(s).</p>
      </part>
      <part id="IDAP-2_gdn" name="guidance">
        <p>Assessment is required when: An Identity API is offered by the IdP.</p>
        <p>Access to the identity API should be limited to the duration of the federation transaction plus the time necessary to synchronize attributes (see Sec. 4.6.4). Time limits prevent indefinite access to subscriber attributes after a federation transaction.</p>
      </part>
    </control>
    <control id="IDAP-3">
      <title>Identity API Access Insufficient for Session Establishment</title>
      <prop name="label" class="index" value="3.12.3 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDAP-3_smt" name="statement">
        <p>Since the time limitation is separate from the validity time window of the assertion and the lifetime of the authenticated session at the RP, access to an identity API by the RP without an associated valid assertion SHALL NOT be sufficient for the establishment of an authenticated session at the RP.</p>
      </part>
      <part id="IDAP-3_obj" name="objective">
        <p>Determine whether the RP requires a valid assertion to establish an authenticated session for the subscriber, and does not establish sessions based solely on identity API access.</p>
        <link href="#IDAP-3_smt" rel="assessment-for"/>
      </part>
      <part id="IDAP-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's session establishment documentation to verify that a valid assertion is required to establish an authenticated session, and that identity API access alone is insufficient.</p>
      </part>
      <part id="IDAP-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to establish an RP session using only identity API access (without a valid assertion). Verify that the RP rejects session establishment.</p>
      </part>
      <part id="IDAP-3_gdn" name="guidance">
        <p>Assessment is required when: An Identity API is offered by the IdP.</p>
        <p>Identity API access is separate from assertion validity and from the lifetime of any authenticated session. Therefore, the ability to call an identity API must not be treated as evidence of a successful federation transaction or used to create an authenticated session.</p>
        <p>See also RASR-2, which prohibits using identity API access to extend an existing session.</p>
      </part>
    </control>
    <control id="IDAP-4">
      <title>Identity API Transaction Scope</title>
      <prop name="label" class="index" value="3.12.3 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDAP-4_smt" name="statement">
        <p>When access to the identity API is granted within the context of a federation transaction, the attributes provided by an identity API SHALL be associated with only the single subscriber identified in the associated assertion.</p>
      </part>
      <part id="IDAP-4_obj" name="objective">
        <p>Determine whether attributes provided by an identity API, when accessed within the context of a federation transaction, are associated only with the single subscriber identified in the associated assertion.</p>
        <link href="#IDAP-4_smt" rel="assessment-for"/>
      </part>
      <part id="IDAP-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's identity API documentation to verify that when access is granted within a federation transaction, returned attributes are scoped to the subscriber identified in the associated assertion.</p>
      </part>
      <part id="IDAP-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to use the identity API to retrieve attributes for a subscriber other than the one identified in the assertion, during a federation transaction. Verify that the IdP rejects or ignores the request.</p>
      </part>
      <part id="IDAP-4_gdn" name="guidance">
        <p>Assessment is required when: An Identity API is offered by the IdP.</p>
        <p>An identity API deployment may be capable of providing attributes for all subscribers for whom the IdP can create assertions. This control ensures that when API access is granted during a federation transaction, the RP cannot use that access to query attributes for other subscribers.</p>
      </part>
    </control>
    <control id="IDAP-5">
      <title>Identity API Subject Identifier Inclusion</title>
      <prop name="label" class="index" value="3.12.3 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDAP-5_smt" name="statement">
        <p>If the identity API is hosted by the IdP, the returned attributes SHALL include the subject identifier for the subscriber.</p>
      </part>
      <part id="IDAP-5_obj" name="objective">
        <p>Determine whether the identity API returns the subject identifier for the subscriber when the API is hosted by the IdP.</p>
        <link href="#IDAP-5_smt" rel="assessment-for"/>
      </part>
      <part id="IDAP-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the Identity API response structure to verify that the subject identifier is included in the returned attributes.</p>
      </part>
      <part id="IDAP-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by querying the identity API and verifying that the response includes the subject identifier for the subscriber.</p>
      </part>
      <part id="IDAP-5_gdn" name="guidance">
        <p>Assessment is required when: An Identity API is offered by the IdP.</p>
        <p>The subject identifier allows the RP to correlate the identity API response with the assertion's subject, ensuring attributes are associated with the correct subscriber.</p>
      </part>
    </control>
    <control id="IDAP-6">
      <title>Pre-Provisioning Privacy Evaluation</title>
      <prop name="label" class="index" value="3.12.3 F"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDAP-6_smt" name="statement">
        <p>For pre-provisioning use cases, the privacy considerations SHALL be evaluated and recorded as part of the trust agreement.</p>
      </part>
      <part id="IDAP-6_obj" name="objective">
        <p>Determine whether privacy considerations for pre-provisioning use cases are evaluated and recorded in the trust agreement artifact(s).</p>
        <link href="#IDAP-6_smt" rel="assessment-for"/>
      </part>
      <part id="IDAP-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to verify that the privacy considerations for pre-provisioning are documented.</p>
      </part>
      <part id="IDAP-6_gdn" name="guidance">
        <p>Assessment is required when: An Identity API is offered by the IdP and pre-provisioning is utilized.</p>
        <p>Pre-provisioning grants the RP access to subscriber attributes before any federation transaction, creating privacy risks that must be explicitly addressed.</p>
      </part>
    </control>
    <control id="EAI-1">
      <title>External Identity API Documentation</title>
      <prop name="label" class="index" value="3.12.3.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="EAI-1_smt" name="statement">
        <p>Any use of external identity APIs for providing attributes SHALL be enumerated by the trust agreement as part of listing attribute sources.</p>
      </part>
      <part id="EAI-1_obj" name="objective">
        <p>Determine whether any use of external identity APIs for providing attributes is enumerated in the trust agreement artifact(s) as part of listing attribute sources.</p>
        <link href="#EAI-1_smt" rel="assessment-for"/>
      </part>
      <part id="EAI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to verify that the external identity APIs are listed as attribute sources, including which attributes are provided by each external API.</p>
      </part>
      <part id="EAI-1_gdn" name="guidance">
        <p>Assessment is required when: External APIs are used for providing attributes.</p>
        <p>External identity APIs are hosted by a party other than the IdP and typically provide attributes from sources other than the CSP (e.g., a medical licensure agency providing license status). The IdP is responsible for associating the external identity API's content with the subscriber account.</p>
      </part>
    </control>
    <control id="ARTP-1">
      <title>Assertion Protection Requirements</title>
      <prop name="label" class="index" value="3.13 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTP-1_smt" name="statement">
        <p>Assertions SHALL include a set of protections to prevent attackers from manufacturing valid assertions or reusing captured assertions at different RPs.</p>
      </part>
      <part id="ARTP-1_obj" name="objective">
        <p>Determine whether assertions include the required protection mechanisms.</p>
        <link href="#ARTP-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARTP-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ARTI-1, SIGNA-1, SIGNA-3, SIGNA-4, and AUDR-1; and by ENCA-1 when assertions are encrypted.</p>
      </part>
      <part id="ARTP-1_gdn" name="guidance">
        <p>Assertions are the fundamental building block of a federated identity transaction, and protecting assertions is essential to the security of the overall system. If an attacker were able to create or modify an assertion and have that assertion accepted by an RP, the attacker would be able to impersonate a valid subscriber and log in to the target system. If an attacker were able to capture an assertion in transit and replay that assertion to a different RP, the attacker would be able to steal a valid session from the legitimate subscriber and log in to the target system. As a consequence, there are a suite of protections that are required for all assertions in a federated system, regardless of how the trust between the parties is established or how the assertion itself is.</p>
      </part>
    </control>
    <control id="ARTI-1">
      <title>Assertion Uniqueness</title>
      <prop name="label" class="index" value="3.13.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTI-1_smt" name="statement">
        <p>Assertions SHALL be sufficiently unique to permit unique identification by the target RP.</p>
      </part>
      <part id="ARTI-1_obj" name="objective">
        <p>Determine whether assertions are sufficiently unique to permit unique identification by the target RP.</p>
        <link href="#ARTI-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARTI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP's assertion structure(s) and documentation to verify inclusion of elements that enable unique identification (e.g., assertion identifier, embedded nonce, issuance timestamp).</p>
      </part>
      <part id="ARTI-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating multiple assertions and verifying that each can be uniquely identified by an RP.</p>
      </part>
      <part id="ARTI-1_gdn" name="guidance">
        <p>Unique identification supports replay protection, logging, auditing, and correlation of federation events. Common techniques include the use of an embedded nonce, an issuance timestamp, an assertion identifier, or a combination of these techniques.</p>
      </part>
    </control>
    <control id="SIGNA-1">
      <title>Signed Assertions</title>
      <prop name="label" class="index" value="3.13.2 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SIGNA-1_smt" name="statement">
        <p>Assertions SHALL be cryptographically signed by the issuer (IdP).</p>
      </part>
      <part id="SIGNA-1_obj" name="objective">
        <p>Determine whether assertions are signed by the IdP using appropriate cryptography.</p>
        <link href="#SIGNA-1_smt" rel="assessment-for"/>
      </part>
      <part id="SIGNA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion configuration and documentation to determine that assertions are cryptographically signed by the IdP.</p>
      </part>
      <part id="SIGNA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by having the IdP issue an assertion. Examine the assertion to determine whether it includes a digital signature or MAC that uses NIST-approved cryptography.</p>
      </part>
      <part id="SIGNA-1_gdn" name="guidance">
        <p>The IdP uses a signature to protect the contents of the assertion from modification by an attacker, and to prevent an attacker from creating a fraudulent assertion. Every assertion issued by the IdP needs to be signed and the signature attached to the assertion for transit and processing by the RP.</p>
      </part>
    </control>
    <control id="SIGNA-2">
      <title>RP Signed Assertion Validation</title>
      <prop name="label" class="index" value="3.13.2 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SIGNA-2_smt" name="statement">
        <p>The RP SHALL validate the digital signature or MAC of each such assertion based on the issuer's verification key.</p>
      </part>
      <part id="SIGNA-2_obj" name="objective">
        <p>Determine whether the RP validates the signature or MAC of an assertion.</p>
        <link href="#SIGNA-2_smt" rel="assessment-for"/>
      </part>
      <part id="SIGNA-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by FAL1-2.</p>
      </part>
      <part id="SIGNA-2_gdn" name="guidance">
        <p>It is not sufficient for the assertion to have a signature, the signature itself needs to have been made by the correct party (the IdP) and be valid for the signed content of the assertion. The RP is required to validate the signature as part of its processing.</p>
      </part>
    </control>
    <control id="SIGNA-3">
      <title>Signature Coverage</title>
      <prop name="label" class="index" value="3.13.2 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SIGNA-3_smt" name="statement">
        <p>This signature SHALL cover the entire assertion, including its identifier, issuer, audience, subject, and time validity window.</p>
      </part>
      <part id="SIGNA-3_obj" name="objective">
        <p>Determine whether the signature method used to protect the assertion covers all required components.</p>
        <link href="#SIGNA-3_smt" rel="assessment-for"/>
      </part>
      <part id="SIGNA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion configuration and documentation to determine that all necessary elements of the  assertions are covered by the IdP signature.</p>
      </part>
      <part id="SIGNA-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by having the IdP generate an assertion. Examine the assertion to determine whether all required assertion components are covered by the signature.</p>
      </part>
      <part id="SIGNA-3_gdn" name="guidance">
        <p>Some signature mechanisms allow for selective coverage of the signature, placing some items outside of the cryptographic protection. This requirement specifies that all the required fields and vital information of the assertion need to be covered by the signature mechanism in use.</p>
      </part>
    </control>
    <control id="SIGNA-4">
      <title>Signature Mechanisms</title>
      <prop name="label" class="index" value="3.13.2 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SIGNA-4_smt" name="statement">
        <p>The assertion signature SHALL either be a digital signature using asymmetric keys or a MAC using a symmetric key that is shared between the RP and issuer with approved cryptography.</p>
      </part>
      <part id="SIGNA-4_obj" name="objective">
        <p>Determine whether the signature method used to protect the assertion and the keys used to create and verify it falls under one of these defined categories.</p>
        <link href="#SIGNA-4_smt" rel="assessment-for"/>
      </part>
      <part id="SIGNA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion signing configuration and documentation to verify that (1) the assertion signature uses either a digital signature with asymmetric keys or a MAC with a symmetric key shared between the RP and IdP, and (2) that the algorithm and key size conform to NIST-approved cryptography requirements as defined in SP 800-63C-4.</p>
      </part>
      <part id="SIGNA-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating an assertion and verifying that the signature method is one of the two permitted mechanisms and uses approved cryptography.</p>
      </part>
      <part id="SIGNA-4_gdn" name="guidance">
        <p>Assertions must be signed using one of two mechanisms: a digital signature using asymmetric keys, or a MAC using a symmetric key shared between the IdP and RP. Both mechanisms must use approved cryptography as defined in SP 800-63C-4. For digital signatures, the relevant standard is FIPS 186-5 (Digital Signature Standard). For MACs, relevant standards include FIPS 198-1 (HMAC) and SP 800-38B (CMAC). Assessors should verify the algorithm and key size against SP 800-131A.</p>
      </part>
    </control>
    <control id="ENCA-1">
      <title>Encryption</title>
      <prop name="label" class="index" value="3.13.3 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ENCA-1_smt" name="statement">
        <p>When encrypting assertions, the IdP SHALL encrypt the contents of the assertion using the RP's encryption key with approved cryptography.</p>
      </part>
      <part id="ENCA-1_obj" name="objective">
        <p>Determine whether the IdP uses approved cryptography and the RP's encryption key when encrypting assertions.</p>
        <link href="#ENCA-1_smt" rel="assessment-for"/>
      </part>
      <part id="ENCA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion encryption configuration and documentation  to verify that assertions are encrypted using the RP's encryption key, and that the encryption algorithm and key size conform to NIST-approved cryptography requirements as defined in SP 800-63C-4.</p>
      </part>
      <part id="ENCA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating an encrypted assertion and determining that it is encrypted for the intended RP using the configured encryption mechanism.</p>
      </part>
      <part id="ENCA-1_gdn" name="guidance">
        <p>SP 800-63C-4 defines approved cryptography as an encryption algorithm, hash function, random bit generator, or similar technique that is FIPS-approved or NIST-recommended. Approved algorithms and techniques are either specified or adopted in a FIPS or NIST recommendation. Assessors must verify that the IdP's assertion encryption algorithm and key size conform to these requirements.</p>
      </part>
    </control>
    <control id="AUDR-1">
      <title>Assertion Audience Restriction</title>
      <prop name="label" class="index" value="3.13.4 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUDR-1_smt" name="statement">
        <p>Assertions SHALL use audience restriction techniques to allow an RP to recognize whether it is the intended target of an issued assertion.</p>
      </part>
      <part id="AUDR-1_obj" name="objective">
        <p>Determine whether all assertions include audience restrictions identifying the target RP.</p>
        <link href="#AUDR-1_smt" rel="assessment-for"/>
      </part>
      <part id="AUDR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP documentation to verify that an audience restriction technique is implemented for all assertions. For FAL2+ transactions, examine sample assertions to confirm that the audience restriction field contains exactly one RP identifier.</p>
      </part>
      <part id="AUDR-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction and verifying that the resulting assertion contains audience restriction information identifying the target RP. For FAL2+ transactions, examine sample assertions to confirm that the audience restriction field contains exactly one RP identifier.</p>
      </part>
      <part id="AUDR-1_gdn" name="guidance">
        <p>Assertions are targeted messages from an IdP to an RP that are created in direct response to a specific federated login process. Each assertion must be targeted to specific RPs so that an assertion intended for one RP cannot be used at an unintended RP, either by the subscriber or an attacker. At FAL1, an assertion may include multiple target RPs. At FAL2 and above, assertions must be restricted to a single RP.</p>
      </part>
    </control>
    <control id="AUDR-2">
      <title>RP Audience Validation</title>
      <prop name="label" class="index" value="3.13.4 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUDR-2_smt" name="statement">
        <p>All RPs SHALL check that the audience of an assertion contains an identifier for their RP to prevent the assertion injection and replay of an assertion generated for one RP at another RP.</p>
      </part>
      <part id="AUDR-2_obj" name="objective">
        <p>Determine whether RPs enforce audience restrictions in presented assertions.</p>
        <link href="#AUDR-2_smt" rel="assessment-for"/>
      </part>
      <part id="AUDR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP documentation and configuration to confirm that audience validation occurs and that only assertions listing the RP's identifier are accepted.</p>
      </part>
      <part id="AUDR-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documented results of conformance testing to the federation standards, protocols, and/or profiles implemented by the RP, if available.</p>
      </part>
      <part id="AUDR-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting an assertion whose audience contains the RP's identifier and determining that the RP accepts it, and an assertion whose audience does not contain the RP's identifier and determining that the RP rejects it. If the RP accepts assertions with multiple audience identifiers at FAL1, test an assertion that contains the RP's identifier along with other RP identifiers and determine that the RP processes it correctly.</p>
      </part>
      <part id="AUDR-2_gdn" name="guidance">
        <p>If the RP utilizes an IdP that lists multiple RPs in a single assertion at FAL1, confirm that the RP correctly handles assertions containing multiple RP identifiers.</p>
      </part>
    </control>
    <control id="HKA-1">
      <title>HoK Authenticator Identifier</title>
      <prop name="label" class="index" value="3.15 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="HKA-1_smt" name="statement">
        <p>A holder-of-key assertion (Fig. 3) SHALL include a unique identifier for an authenticator that can be verified independently by the RP, such as the public key of a certificate controlled by the subscriber.</p>
      </part>
      <part id="HKA-1_obj" name="objective">
        <p>Determine whether HoK assertions include the public key (or key identifier) of the authenticator controlled by the subscriber.</p>
        <link href="#HKA-1_smt" rel="assessment-for"/>
      </part>
      <part id="HKA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP HoK documentation to confirm that HoK assertions contain the necessary authenticator identifier.</p>
      </part>
      <part id="HKA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating a HoK assertion and verifying it contains a unique identifier for the subscriber's authenticator (e.g., a public key or key identifier).</p>
      </part>
      <part id="HKA-1_gdn" name="guidance">
        <p>The public key allows the RP to verify that the subscriber controls the corresponding private key, binding the assertion to the subscriber.</p>
      </part>
    </control>
    <control id="HKA-2">
      <title>HoK Validation</title>
      <prop name="label" class="index" value="3.15 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="HKA-2_smt" name="statement">
        <p>The RP SHALL verify that the subscriber possesses the authenticator identified by the assertion. Holder-of-key assertions are most often used when the authenticator technology is tied to a public-key infrastructure (PKI) trusted by both the IdP and RP.</p>
      </part>
      <part id="HKA-2_obj" name="objective">
        <p>Determine whether the RP validates the subscriber's key for holder-of-key assertions.</p>
        <link href="#HKA-2_smt" rel="assessment-for"/>
      </part>
      <part id="HKA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's assertion processing documentation to verify that holder-of-key authenticator verification is implemented before granting FAL3 access.</p>
      </part>
      <part id="HKA-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting a holder-of-key assertion and authenticating with the correct subscriber key. Verify that the RP grants FAL3 access. Next, present a holder-of-key assertion and authenticate with an incorrect key. Verify rejection. Finally, present a holder-of-key assertion without presenting any key. Verify rejection.</p>
      </part>
      <part id="HKA-2_gdn" name="guidance">
        <p>Holder-of-key assertions are built around proving that a subscriber is not only known to the IdP, and therefore able to get an assertion issued, but also able to present proof of a cryptographic key in the assertion. This key represents the subscriber, not the IdP or the RP, and the proof of possession of the key is presented by the subscriber directly to the RP. This requirement does not assume that the RP has registered the key for the subscriber, and the subscriber key might be unknown to the RP ahead of processing the assertion. Additionally, the technology in place might use different keys for a subscriber over time. Because of these aspects, the RP needs to validate the subscriber's key separately upon login.</p>
      </part>
    </control>
    <control id="HKA-3">
      <title>HoK Authenticator Phishing Resistance</title>
      <prop name="label" class="index" value="3.15 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="HKA-3_smt" name="statement">
        <p>The authenticator identified in a holder-of-key assertion SHALL be phishing-resistant, as defined by Sec. 3.2.5 of [SP800-63B].</p>
      </part>
      <part id="HKA-3_obj" name="objective">
        <p>Determine whether the authenticator identified in the HoK assertion is phishing-resistant as defined by Sec. 3.2.5 of [SP800-63B].</p>
        <link href="#HKA-3_smt" rel="assessment-for"/>
      </part>
      <part id="HKA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation indicating the authenticator type(s) used in HoK assertions to verify that they meet phishing-resistance requirements per [SP800-63B] Sec. 3.2.5.</p>
      </part>
    </control>
    <control id="HKA-4">
      <title>HoK Authenticator Account Resolution</title>
      <prop name="label" class="index" value="3.15 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="HKA-4_smt" name="statement">
        <p>When the RP encounters an authenticator in a holder-of-key assertion for the first time, the RP SHALL ensure that the authenticator can be uniquely resolved to the RP subscriber account, as discussed in Sec. 3.8.2.</p>
      </part>
      <part id="HKA-4_obj" name="objective">
        <p>Determine whether the RP ensures that a new HoK authenticator can be uniquely resolved to the RP subscriber account upon first encounter.</p>
        <link href="#HKA-4_smt" rel="assessment-for"/>
      </part>
      <part id="HKA-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ACCR-1.</p>
      </part>
    </control>
    <control id="HKA-5">
      <title>HoK Prohibitions</title>
      <prop name="label" class="index" value="3.15 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="HKA-5_smt" name="statement">
        <p>A holder-of-key assertion SHALL NOT include an unencrypted private key or symmetric key to be used as an authenticator.</p>
      </part>
      <part id="HKA-5_obj" name="objective">
        <p>Determine whether the subscriber keys present in a holder-of-key assertion are of an appropriate type.</p>
        <link href="#HKA-5_smt" rel="assessment-for"/>
      </part>
      <part id="HKA-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP assertion generation documentation to confirm that assertions do not result in exposure of private keys or symmetric keys. Examine test assertions and logs of assertion tests to validate the operational configuration.</p>
      </part>
      <part id="HKA-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating a holder-of-key assertion and ensure that the assertion does not include an unencrypted private key or symmetric key as the subscriber key.</p>
      </part>
      <part id="HKA-5_gdn" name="guidance">
        <p>The security of holder-of-key assertions stems from the separation of the key representing the subscriber and the assertion itself. The RP will need access to some set of keying material to verify the key presented by the subscriber in a holder-of-key assertion. There are different methods of identifying this keying material to the RP, such as including the public key of an asymmetric key pair in the assertion or including an identifier for a key that the RP can securely dereference. However, if the assertion were to include private key material or a symmetric key, then any reader of the assertion would be able to create a proof to present alongside the assertion. Therefore, these types of keys are not allowed to be included in the assertion in holder-of-key presentations.</p>
      </part>
    </control>
    <control id="BAUTH-1">
      <title>Bound Authenticator Indicator</title>
      <prop name="label" class="index" value="3.16 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-1_smt" name="statement">
        <p>The IdP SHALL include an indicator in the assertion when the assertion is to be used with a bound authenticator at FAL3.</p>
      </part>
      <part id="BAUTH-1_obj" name="objective">
        <p>Determine whether the IdP includes an indicator in the assertion when the assertion is to be used with a bound authenticator at FAL3.</p>
        <link href="#BAUTH-1_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the assertion structure to verify inclusion of a bound authenticator indicator when bound authenticators are used at FAL3.</p>
      </part>
      <part id="BAUTH-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting an FAL3 assertion for use with a bound authenticator. Verify the assertion contains the expected bound authenticator indicator.</p>
      </part>
      <part id="BAUTH-1_gdn" name="guidance">
        <p>The indicator signals to the RP that it must verify a bound authenticator before accepting the assertion.</p>
        <p>(Per ARTC-8, an FAL3 assertion must include either a HoK key identifier or a bound authenticator indicator.)</p>
      </part>
    </control>
    <control id="BAUTH-2">
      <title>Bound Authenticator Identifier Storage</title>
      <prop name="label" class="index" value="3.16 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-2_smt" name="statement">
        <p>The unique identifier for the authenticator (such as its public key) SHALL be stored in the RP subscriber account.</p>
      </part>
      <part id="BAUTH-2_obj" name="objective">
        <p>Determine whether the RP stores the unique identifier for the bound authenticator (such as its public key) in the RP subscriber account.</p>
        <link href="#BAUTH-2_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP subscriber account schema to identify where bound authenticator identifiers are stored. Then, examine sample RP subscriber accounts that have a bound authenticator and verify that the unique identifier (e.g., public key) is present.</p>
      </part>
    </control>
    <control id="BAUTH-3">
      <title>Bound Authenticator Uniqueness</title>
      <prop name="label" class="index" value="3.16 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-3_smt" name="statement">
        <p>A bound authenticator SHALL be unique per subscriber at the RP such that two subscribers cannot present the same authenticator for their separate RP subscriber accounts.</p>
      </part>
      <part id="BAUTH-3_obj" name="objective">
        <p>Determine whether bound authenticators are unique per subscriber at the RP, such that two subscribers cannot present the same authenticator for their separate RP subscriber accounts.</p>
        <link href="#BAUTH-3_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP-bound authenticator binding logic to verify that a uniqueness constraint prevents the same authenticator identifier from being associated with multiple RP subscriber accounts.</p>
      </part>
      <part id="BAUTH-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to bind the same authenticator to two different RP subscriber accounts. Verify that the RP rejects the second binding.</p>
      </part>
    </control>
    <control id="BAUTH-4">
      <title>Bound Authenticator Phishing Resistance</title>
      <prop name="label" class="index" value="3.16 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-4_smt" name="statement">
        <p>All bound authenticators SHALL use phishing-resistant authentication mechanisms, as defined by Sec. 3.2.5 of [SP800-63B].</p>
      </part>
      <part id="BAUTH-4_obj" name="objective">
        <p>Determine whether bound authenticators use phishing-resistant authentication mechanisms as defined by Sec. 3.2.5 of [SP800-63B].</p>
        <link href="#BAUTH-4_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the documentation of the authenticator types permitted as bound authenticators to verify that they meet phishing-resistance requirements per [SP800-63B] Sec. 3.2.5.</p>
      </part>
    </control>
    <control id="BAUTH-5">
      <title>Bound Authenticator Verification Timing</title>
      <prop name="label" class="index" value="3.16 E"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-5_smt" name="statement">
        <p>Bound authenticators SHALL be accepted for authentication in the context of processing an FAL3 assertion for a federated transaction.</p>
      </part>
      <part id="BAUTH-5_obj" name="objective">
        <p>Determine whether the RP verifies the bound authenticator during FAL3 assertion processing, rather than in a separate transaction.</p>
        <link href="#BAUTH-5_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's transaction flow documentation to verify that bound authenticator verification is integrated into the FAL3 assertion processing flow rather than performed as a separate authentication transaction.</p>
      </part>
      <part id="BAUTH-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating an FAL3 federated transaction requiring a bound authenticator, and successfully complete the bound authenticator verification. Verify that the RP accepts the bound authenticator and establishes the FAL3 session. Review the RP transaction logs to confirm the bound authenticator verification is recorded as part of the assertion processing event, not as a separate authentication event.</p>
      </part>
    </control>
    <control id="BAUTH-6">
      <title>Bound vs. Direct Authentication Documentation</title>
      <prop name="label" class="index" value="3.16 F"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-6_smt" name="statement">
        <p>While it is possible for the same authenticator to also be used for direct authentication to the RP (see Sec. 3.8.3), such use is not considered a bound authenticator, and the RP SHALL document these as distinct use cases.</p>
      </part>
      <part id="BAUTH-6_obj" name="objective">
        <p>Determine whether the RP documents for subscribers that bound authentication and direct authentication are distinct use cases, and whether the same authenticator may be used for both.</p>
        <link href="#BAUTH-6_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's subscriber-facing documentation (e.g., help pages, account settings, authenticator registration guidance) to verify that the RP explains that bound authentication and direct authentication are distinct use cases, and states whether the RP permits the same authenticator to be used for both.</p>
      </part>
      <part id="BAUTH-6_gdn" name="guidance">
        <p>Assessment is required when: An RP supports both bound and alternative authenticators.</p>
        <p>See ALTAP-2 for RP determination of permitted authenticator uses.</p>
      </part>
    </control>
    <control id="BAUTH-7">
      <title>Pre-existing Bound Authenticator Reference in RP Subscriber Account</title>
      <prop name="label" class="index" value="3.16 G"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-7_smt" name="statement">
        <p>Before an RP can successfully accept an FAL3 assertion, the RP subscriber account SHALL include a reference to a bound authenticator that is to be verified during the FAL3 transaction.</p>
      </part>
      <part id="BAUTH-7_obj" name="objective">
        <p>Determine whether the RP subscriber account includes a reference to a bound authenticator before the RP accepts an FAL3 bound authenticator assertion.</p>
        <link href="#BAUTH-7_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's FAL3 assertion processing logic to verify that it checks for a bound authenticator reference in the RP subscriber account before accepting the assertion.</p>
      </part>
      <part id="BAUTH-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to process an FAL3 assertion with a bound authenticator indicator for an RP subscriber account that has no bound authenticator reference. Verify the RP rejects the assertion.</p>
      </part>
      <part id="BAUTH-7_gdn" name="guidance">
        <p>The bound authenticator must be registered to the RP subscriber account before it can be verified during an FAL3 transaction.</p>
      </part>
    </control>
    <control id="BAUTH-8">
      <title>Bound Authenticator Change Notification</title>
      <prop name="label" class="index" value="3.16 H"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="BAUTH-8_smt" name="statement">
        <p>The RP SHALL send a notification to the subscriber via an out-of-band mechanism (e.g., an email to an address previously associated with the subscriber)...if any of the following events occur:</p>
        <p>(a) A new bound authenticator is added to the RP subscriber account.</p>
        <p>(b) An existing bound authenticator is removed from the RP subscriber account.</p>
      </part>
      <part id="BAUTH-8_obj" name="objective">
        <p>Determine whether the RP sends an out-of-band notification to the subscriber when a bound authenticator is added to or removed from the RP subscriber account.</p>
        <link href="#BAUTH-8_smt" rel="assessment-for"/>
      </part>
      <part id="BAUTH-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's bound authenticator management system to verify that out-of-band notifications are configured to be sent when authenticators are added or removed.</p>
      </part>
      <part id="BAUTH-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test as follows: (1) Add a bound authenticator to an RP subscriber account. Verify that the subscriber receives an out-of-band notification. (2) Remove a bound authenticator from an RP subscriber account. Verify that the subscriber receives an out-of-band notification.</p>
      </part>
      <part id="BAUTH-8_gdn" name="guidance">
        <p>Out-of-band notifications alert the subscriber to potentially unauthorized changes to their account. See [SP800-63B] Sec. 4.6 for notification requirements and considerations.</p>
      </part>
    </control>
    <control id="RPPBAI-1">
      <title>RP-Provided Bound Authenticator Issuance</title>
      <prop name="label" class="index" value="3.16.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="RPPBAI-1_smt" name="statement">
        <p>For RP-provided authenticators, the system administrator of the RP SHALL issue the authenticator directly to the subscriber for use with an FAL3 federation transaction.</p>
      </part>
      <part id="RPPBAI-1_obj" name="objective">
        <p>Determine whether RP-provided bound authenticators are issued directly to the subscriber for use with FAL3 federation transactions.</p>
        <link href="#RPPBAI-1_smt" rel="assessment-for"/>
      </part>
      <part id="RPPBAI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's authenticator issuance procedures and a sample of issuance records, tracking records, or other issuance evidence to determine that RP-provided bound authenticators are issued directly to the subscriber for use with an FAL3 federation transaction.</p>
      </part>
      <part id="RPPBAI-1_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the system administrator to determine that RP-provided bound authenticators are issued directly to the subscriber for use with an FAL3 federation transaction, if no recent issuance records are available.</p>
      </part>
    </control>
    <control id="RPPBAI-2">
      <title>RP-Provided Bound Authenticator Subscriber Verification</title>
      <prop name="label" class="index" value="3.16.1 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="RPPBAI-2_smt" name="statement">
        <p>The system administrator of the RP SHALL use an independent means to determine whether the identified subject of the RP subscriber account is the party to which the authenticator is issued. The system administrator of the RP SHALL follow the initial authenticator binding requirements in Sec. 4 of [SP800-63A] or the post-enrollment binding requirements in Sec. 4.1.2 of [SP800-63B], as appropriate.</p>
      </part>
      <part id="RPPBAI-2_obj" name="objective">
        <p>Determine whether the RP system administrator verifies that the subscriber receiving the bound authenticator is the subject of the RP subscriber account by following the initial authenticator binding requirements in Sec. 4 of [SP800-63A] or the post-enrollment binding requirements in Sec. 4.1.2 of [SP800-63B].</p>
        <link href="#RPPBAI-2_smt" rel="assessment-for"/>
      </part>
      <part id="RPPBAI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's bound authenticator issuance procedures to identify which binding path is used in each applicable case: Sec. 4 of SP 800-63A for initial binding or Sec. 4.1.2 of SP 800-63B for post-enrollment binding.</p>
      </part>
      <part id="RPPBAI-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine a sample of issuance records or other issuance evidence to determine that, for each sampled issuance, the system administrator used an independent means to determine that the identified subject of the RP subscriber account was the party receiving the authenticator and followed the applicable binding path.</p>
      </part>
      <part id="RPPBAI-2_asm-interview" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="INTERVIEW"/>
        <p>Interview the system administrator if the records are insufficient to establish how the determination was made.</p>
      </part>
      <part id="RPPBAI-2_gdn" name="guidance">
        <p>The choice between 63A and 63B requirements depends on context: if the RP subscriber account was just established and this is the initial authenticator binding, use 63A requirements. If the subscriber already has an established account with authenticators and is adding an RP-provided bound authenticator, use 63B post-enrollment requirements.</p>
      </part>
    </control>
    <control id="RPPBAI-3">
      <title>RP-Provided Bound Authenticator Identifier Storage</title>
      <prop name="label" class="index" value="3.16.1 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="RPPBAI-3_smt" name="statement">
        <p>The system administrator of the RP SHALL store a unique identifier for the bound authenticator in the RP subscriber account, such as the public key of the authenticator.</p>
      </part>
      <part id="RPPBAI-3_obj" name="objective">
        <p>Determine whether the RP stores a unique identifier for each RP-provided bound authenticator in the associated RP subscriber account.</p>
        <link href="#RPPBAI-3_smt" rel="assessment-for"/>
      </part>
      <part id="RPPBAI-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by BAUTH-2.</p>
      </part>
    </control>
    <control id="SUBPB-1">
      <title>Binding Ceremony for Subscriber-Provided Bound Authenticators</title>
      <prop name="label" class="index" value="3.16.2 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-1_smt" name="statement">
        <p>If no bound authenticators are associated with the RP subscriber account, the RP SHALL perform a binding ceremony to establish the connection between the authenticator, the subscriber, and the RP subscriber account, as shown in Fig. 5.</p>
      </part>
      <part id="SUBPB-1_obj" name="objective">
        <p>Determine whether the RP performs a binding ceremony to establish the connection between the authenticator, the subscriber, and the RP subscriber account, as shown in Fig. 5, when no bound authenticators are associated with the RP subscriber account.</p>
        <link href="#SUBPB-1_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SUBPB-2 through SUBPB-12.</p>
      </part>
      <part id="SUBPB-1_gdn" name="guidance">
        <p>This is a summative control. Compliance is determined by the results of all binding ceremony controls: SUBPB-2 through SUBPB-12.</p>
        <p>The RP MAY provide a process for associating subscriber-provided authenticators to the RP subscriber account on a trust-on-first-use basis. This process is known as a binding ceremony and has additional requirements beyond a typical FAL3 federation process.</p>
      </part>
    </control>
    <control id="SUBPB-2">
      <title>Binding Ceremony Session Establishment</title>
      <prop name="label" class="index" value="3.16.2 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-2_smt" name="statement">
        <p>The RP SHALL first establish an authenticated session using federation with an assertion that meets all the other requirements of FAL3, including an indication that the assertion is intended for use at FAL3 with a bound authenticator (e.g., the assertion contains an authentication class reference or a Vectors of Trust [RFC8485] value indicating this).</p>
      </part>
      <part id="SUBPB-2_obj" name="objective">
        <p>Determine whether the RP requires a valid FAL3 assertion with a bound authenticator indicator before initiating a binding ceremony.</p>
        <link href="#SUBPB-2_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP binding ceremony implementation to verify that it requires an FAL3 assertion containing a bound authenticator indicator before the ceremony proceeds.</p>
      </part>
      <part id="SUBPB-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating an FAL3 bound authenticator request for an account that lacks a bound authenticator. Verify that the RP performs validation per CFAL-2 and initiates a binding ceremony session only if validation succeeds.</p>
      </part>
      <part id="SUBPB-2_gdn" name="guidance">
        <p>Note: SUBPB-2 through SUBPB-12 should be evaluated together.</p>
        <p>This applies to the initial binding ceremony when no bound authenticator is yet associated with the RP subscriber account. The subscriber cannot prove possession of a bound authenticator at this stage because none has been bound yet.</p>
      </part>
    </control>
    <control id="SUBPB-3">
      <title>Binding Ceremony Authenticator Prompt</title>
      <prop name="label" class="index" value="3.16.2 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-3_smt" name="statement">
        <p>The subscriber SHALL immediately be prompted to present and authenticate with the proposed authenticator.</p>
      </part>
      <part id="SUBPB-3_obj" name="objective">
        <p>Determine whether the RP immediately prompts the subscriber to present and authenticate with the proposed authenticator after establishing the binding ceremony session.</p>
        <link href="#SUBPB-3_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Continue from SUBPB-2 (binding ceremony session established).</p>
        <p>Test by verifying that the RP immediately prompts the subscriber to present and authenticate with the proposed authenticator.</p>
      </part>
    </control>
    <control id="SUBPB-4">
      <title>Binding Ceremony Authenticator Identifier Storage</title>
      <prop name="label" class="index" value="3.16.2 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-4_smt" name="statement">
        <p>Upon successful presentation of the authenticator, the RP SHALL store a unique identifier for the authenticator (such as its public key) and associate this with the RP subscriber account that is associated with the federated identifier.</p>
      </part>
      <part id="SUBPB-4_obj" name="objective">
        <p>Determine whether, during the binding ceremony, the RP stores a unique identifier for the authenticator and associates it with the RP subscriber account upon successful authenticator presentation.</p>
        <link href="#SUBPB-4_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Continue from SUBPB-3 (successful authenticator presentation).</p>
        <p>Test by authenticating with an appropriate authenticator, then inspecting the RP subscriber account record to confirm that an authenticator identifier was stored that uniquely identifies the authenticator.</p>
      </part>
      <part id="SUBPB-4_gdn" name="guidance">
        <p>This is functionally equivalent to RPPBAI-3 but is evaluated as a discrete step during a binding ceremony.</p>
      </part>
    </control>
    <control id="SUBPB-5">
      <title>Binding Ceremony Session Timeout</title>
      <prop name="label" class="index" value="3.16.2 E"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-5_smt" name="statement">
        <p>The binding ceremony session SHALL have a timeout of five minutes or less.</p>
      </part>
      <part id="SUBPB-5_obj" name="objective">
        <p>Determine whether the binding ceremony session has a timeout of five minutes or less.</p>
        <link href="#SUBPB-5_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a binding ceremony session and continuing through the RP prompt to the subscriber to present and authenticate with the proposed authenticator (SUBPB-3). Then, wait five minutes without authenticating. Verify that the session expires and the binding ceremony fails.</p>
      </part>
      <part id="SUBPB-5_gdn" name="guidance">
        <p>If the subscriber fails to successfully authenticate to the RP using an appropriate authenticator within five minutes of being prompted to do so, the binding ceremony fails.</p>
      </part>
    </control>
    <control id="SUBPB-6">
      <title>Binding Ceremony Session Restriction</title>
      <prop name="label" class="index" value="3.16.2 F"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-6_smt" name="statement">
        <p>The binding ceremony session... SHALL NOT be used as an authenticated session for any other purpose, as described in Sec. 3.9.</p>
      </part>
      <part id="SUBPB-6_obj" name="objective">
        <p>Determine whether the RP restricts the binding ceremony session to binding purposes only and does not use it as an authenticated session for any other purpose.</p>
        <link href="#SUBPB-6_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to access RP functions or resources that require an authenticated session during a binding ceremony session. Verify that the RP denies access.</p>
      </part>
      <part id="SUBPB-6_gdn" name="guidance">
        <p>Per Sec. 3.9, an authenticated session allows subscriber access to RP functions, identification, or attribute processing. The binding ceremony session exists solely to complete the binding process and must not grant these capabilities.</p>
      </part>
    </control>
    <control id="SUBPB-7">
      <title>Post-Binding Ceremony Transaction Initiation</title>
      <prop name="label" class="index" value="3.16.2 G"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-7_smt" name="statement">
        <p>Upon successful completion of the binding ceremony, the RP SHALL immediately request a new assertion from the IdP at FAL3.</p>
      </part>
      <part id="SUBPB-7_obj" name="objective">
        <p>Determine whether the RP initiates a new FAL3 federation transaction immediately upon successful completion of the binding ceremony.</p>
        <link href="#SUBPB-7_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by verifying that the RP immediately initiates a new federation transaction requesting a new assertion at FAL3, following the completion of the binding ceremony.</p>
      </part>
    </control>
    <control id="SUBPB-8">
      <title>Post-Binding Ceremony Authenticator Prompt</title>
      <prop name="label" class="index" value="3.16.2 H"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-8_smt" name="statement">
        <p>Upon receiving the new assertion, the RP SHALL prompt the subscriber for the newly bound authenticator and SHALL validate the authenticator output.</p>
      </part>
      <part id="SUBPB-8_obj" name="objective">
        <p>Determine whether the RP prompts the subscriber to authenticate with the newly bound authenticator upon receiving the new FAL3 assertion.</p>
        <link href="#SUBPB-8_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-8_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RPPHBA-1.</p>
      </part>
      <part id="SUBPB-8_gdn" name="guidance">
        <p>This is standard FAL3 bound authenticator processing applied to the post-binding ceremony context.</p>
      </part>
    </control>
    <control id="SUBPB-9">
      <title>Adding an Additional Bound Authenticator (1)</title>
      <prop name="label" class="index" value="3.16.2 I"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-9_smt" name="statement">
        <p>During the initial authentication step of the binding ceremony, the RP SHALL request authentication with an existing bound authenticator to reach FAL3.</p>
      </part>
      <part id="SUBPB-9_obj" name="objective">
        <p>Determine whether the RP requires authentication with an existing bound authenticator during the initial step of the binding ceremony when adding additional bound authenticators to an account that already has one or more.</p>
        <link href="#SUBPB-9_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's binding ceremony implementation to confirm that when a subscriber account has one or more existing bound authenticators, the workflow for adding additional authenticators requires initial authentication with an existing bound authenticator at FAL3.</p>
      </part>
      <part id="SUBPB-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by identifying a test subscriber account with at least one existing bound authenticator. Using that account, initiate a binding ceremony for an additional authenticator.  Verify the RP requests authentication with an existing bound authenticator as the initial step. Next, attempt to proceed with the binding ceremony without authenticating with an existing bound authenticator; verify the RP rejects the attempt.</p>
      </part>
      <part id="SUBPB-9_gdn" name="guidance">
        <p>This requirement applies to the alternative binding ceremony workflow for adding authenticators to accounts that already have bound authenticators. Unlike the initial binding ceremony (SUBPB-1 through SUBPB-8), which uses federation at FAL3 with a trust-on-first-use approach, this workflow requires proof of possession of an existing bound authenticator before new authenticators can be bound.</p>
        <p>See SUBPB-10 for the subsequent step of authenticating with and associating the new authenticator.</p>
      </part>
    </control>
    <control id="SUBPB-10">
      <title>Adding an Additional Bound Authenticator (2)</title>
      <prop name="label" class="index" value="3.16.2 J"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-10_smt" name="statement">
        <p>Once this authentication is complete and the binding ceremony session is established, the RP SHALL request authentication with the new authenticator and associate it with the RP subscriber account as a bound authenticator.</p>
      </part>
      <part id="SUBPB-10_obj" name="objective">
        <p>Determine whether the RP, after the subscriber authenticates with an existing bound authenticator (SUBPB-9), requests authentication with the new bound authenticator and stores its identifier in the RP subscriber account.</p>
        <link href="#SUBPB-10_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-10_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by identifying a test subscriber account with at least one existing bound authenticator. Using that account, complete a binding ceremony to add an additional authenticator. Verify that the RP then prompts the subscriber to authenticate with that new authenticator. Authenticate with the new authenticator. Then, inspect the RP subscriber account record to confirm that a unique identifier for the new authenticator (such as its public key) was stored and associated with the account as a bound authenticator. Confirm that the account now contains at least two unique bound authenticator identifiers. Verify that the new authenticator can be used for subsequent FAL3 transactions.</p>
      </part>
    </control>
    <control id="SUBPB-11">
      <title>Bound Authenticator Removal - Session Termination</title>
      <prop name="label" class="index" value="3.16.2 K"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-11_smt" name="statement">
        <p>When a bound authenticator is removed, the RP SHALL terminate all current FAL3 sessions for the subscriber and SHALL require reauthentication of the subscriber from the IdP at FAL3.</p>
      </part>
      <part id="SUBPB-11_obj" name="objective">
        <p>Determine whether the RP terminates all active FAL3 sessions for the subscriber and requires IdP reauthentication at FAL3 when a bound authenticator is removed from the RP subscriber account.</p>
        <link href="#SUBPB-11_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-11_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test using a test subscriber account with at least one bound authenticator and an active FAL3 session by doing the following: (1) Establish one or more additional active FAL3 sessions for the test subscriber (e.g., multiple browser sessions or devices). (2) Remove a bound authenticator from the RP subscriber account. (3) Verify that all active FAL3 sessions for the subscriber are immediately terminated. (4) Attempt to access the RP at FAL3. Verify that the RP requires a new assertion from the IdP at FAL3 before granting access.</p>
      </part>
      <part id="SUBPB-11_gdn" name="guidance">
        <p>This control addresses the security response when a bound authenticator is removed, whether initiated by the subscriber (e.g., lost or compromised authenticator) or by the RP (e.g., authenticator no longer meets requirements). Terminating all FAL3 sessions and requiring reauthentication ensures that any sessions potentially established using the removed authenticator are invalidated.</p>
        <p>See SUBPB-12 for the related requirement that the RP not prompt for the removed authenticator during this process.</p>
      </part>
    </control>
    <control id="SUBPB-12">
      <title>Bound Authenticator Removal - No Prompt for Removed Authenticator</title>
      <prop name="label" class="index" value="3.16.2 L"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="SUBPB-12_smt" name="statement">
        <p>The RP SHALL NOT prompt the subscriber to authenticate with the authenticator being removed, since the subscriber will often not have access to the authenticator in question during the unbinding process, particularly if the authenticator is lost or compromised.</p>
      </part>
      <part id="SUBPB-12_obj" name="objective">
        <p>Determine whether the RP avoids prompting the subscriber to authenticate with the specific authenticator being removed during the unbinding process.</p>
        <link href="#SUBPB-12_smt" rel="assessment-for"/>
      </part>
      <part id="SUBPB-12_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test using a test subscriber account with at least one bound authenticator by initiating the removal of a bound authenticator from the RP subscriber account.  Verify that the RP does not prompt the subscriber to authenticate with the authenticator while the authenticator is being removed. (Note: If the account has multiple bound authenticators, the RP may prompt for a different bound authenticator, but never the one being removed.)</p>
      </part>
    </control>
    <control id="RPPHBA-1">
      <title>Bound Authenticator Verification</title>
      <prop name="label" class="index" value="3.17 #1"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="RPPHBA-1_smt" name="statement">
        <p>The subscriber SHALL prove possession of the bound authenticator to the RP, in addition to presenting the assertion itself.</p>
      </part>
      <part id="RPPHBA-1_obj" name="objective">
        <p>Determine whether the RP prompts the subscriber to prove possession of the expected authenticator and validates the authenticator output.</p>
        <link href="#RPPHBA-1_smt" rel="assessment-for"/>
      </part>
      <part id="RPPHBA-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by doing the following: (1) Initiate an FAL3 federation transaction. Verify the RP prompts the subscriber to prove possession of the authenticator in addition to presenting the assertion. (2) Authenticate with the correct authenticator. Verify FAL3 access is granted. (3) Authenticate with an incorrect authenticator. Verify rejection. (4) Present the assertion without any authenticator. Verify rejection.</p>
      </part>
      <part id="RPPHBA-1_gdn" name="guidance">
        <p>Assessment is required when: Authentication is required at both the IdP and the RP.</p>
        <p>Note: This control was intended to apply to both HoK and bound authenticator assertions. When the errata corrections are issued, this control will be updated to read: "The subscriber SHALL prove possession of the authenticator to the RP, in addition to presenting the assertion itself."</p>
      </part>
    </control>
    <control id="RPPHBA-2">
      <title>HoK Authenticator Reference Trust Level</title>
      <prop name="label" class="index" value="3.17 #2"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="RPPHBA-2_smt" name="statement">
        <p>For a holder-of-key assertion, a reference to a given authenticator that is found within an assertion SHALL be trusted at the same level as all other information within the assertion, as stipulated in the trust agreement.</p>
      </part>
      <part id="RPPHBA-2_obj" name="objective">
        <p>Determine whether the RP validates the complete HoK assertion and does not rely solely on verification of the referenced authenticator.</p>
        <link href="#RPPHBA-2_smt" rel="assessment-for"/>
      </part>
      <part id="RPPHBA-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by CFAL-2 (assertion validation), FAL1-2 (signature verification), SIGNA-2  (signed assertion validation), and SIGNA-3 (signature coverage).</p>
      </part>
      <part id="RPPHBA-2_gdn" name="guidance">
        <p>Assessment is required when: The assertion is a HoK assertion.</p>
        <p>Note: This control was intended to apply to HoK assertions only. When the errata corrections are issued, this control will be moved to section 3.15.</p>
      </part>
    </control>
    <control id="RPPHBA-3">
      <title>Assertion Validation with Bound Authenticator</title>
      <prop name="label" class="index" value="3.17 #3"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="RPPHBA-3_smt" name="statement">
        <p>The RP SHALL process and validate the assertion in addition to the bound authenticator.</p>
      </part>
      <part id="RPPHBA-3_obj" name="objective">
        <p>Determine whether the RP validates the assertion from the IdP when processing transactions that require RP authenticator validation.</p>
        <link href="#RPPHBA-3_smt" rel="assessment-for"/>
      </part>
      <part id="RPPHBA-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by CFAL-2.</p>
      </part>
      <part id="RPPHBA-3_gdn" name="guidance">
        <p>Assessment is required when: Authentication is required at both the IdP and the RP.</p>
        <p>Note: This control was intended to apply to both HoK and bound authenticator assertions. When the errata corrections are issued, this control will be updated to read: "The RP SHALL process and validate the assertion in addition to verifying the authenticator."</p>
      </part>
    </control>
    <control id="RPPHBA-4">
      <title>Bound Authenticator Failure Handling</title>
      <prop name="label" class="index" value="3.17 #4"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="RPPHBA-4_smt" name="statement">
        <p>Failure to authenticate with the bound authenticator SHALL result in an error at the RP and SHALL NOT create an authenticated session at the RP.</p>
      </part>
      <part id="RPPHBA-4_obj" name="objective">
        <p>Determine whether the RP rejects the transaction and prevents session creation when the subscriber fails to successfully authenticate at the RP.</p>
        <link href="#RPPHBA-4_smt" rel="assessment-for"/>
      </part>
      <part id="RPPHBA-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test, using a test subscriber account with a bound authenticator, by initiating an FAL3 federation transaction with a valid bound authenticator assertion. When prompted for the bound authenticator, fail authentication (e.g., cancel the prompt, provide an incorrect activation factor, or allow the request to timeout). Verify that the RP returns an error and does not create an authenticated session.</p>
      </part>
      <part id="RPPHBA-4_gdn" name="guidance">
        <p>Assessment is required when: Authentication is required at both the IdP and the RP.</p>
        <p>Note: This control was intended to apply to both HoK and bound authenticator assertions. When the errata corrections are issued, this control will be updated to read: "Failure to verify the authenticator SHALL result in an error at the RP and SHALL NOT create an authenticated session at the RP."</p>
      </part>
    </control>
    <control id="IDPAP-1">
      <title>Account Provisioning Disclosure</title>
      <prop name="label" class="index" value="4.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPAP-1_smt" name="statement">
        <p>In order to make subscriber accounts available through an IdP, the subscriber accounts need to be provisioned at the IdP. The means by which the subscriber account is provisioned to the IdP SHALL be disclosed in the trust agreement.</p>
      </part>
      <part id="IDPAP-1_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) disclose the means by which subscriber accounts are provisioned to the IdP.</p>
        <link href="#IDPAP-1_smt" rel="assessment-for"/>
      </part>
      <part id="IDPAP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to confirm that they include a description of the account provisioning method(s) used to make subscriber accounts available through the IdP.</p>
      </part>
      <part id="IDPAP-1_gdn" name="guidance">
        <p>RPs rely on this disclosure to understand the provenance and trustworthiness of identity assertions. Different provisioning methods carry different risk profiles and may affect RP decisions about accepting assertions from a given IdP.</p>
      </part>
    </control>
    <control id="IDPAP-2">
      <title>Attribute Bundle Signing</title>
      <prop name="label" class="index" value="4.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPAP-2_smt" name="statement">
        <p>If the CSP issues attribute bundles to the RP: The CSP SHALL sign attribute bundles issued to the IdP.</p>
      </part>
      <part id="IDPAP-2_obj" name="objective">
        <p>Determine whether the CSP signs attribute bundles before issuing them to the IdP.</p>
        <link href="#IDPAP-2_smt" rel="assessment-for"/>
      </part>
      <part id="IDPAP-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by obtaining an attribute bundle issued by the CSP to the IdP. Verify that the attribute bundle contains a valid cryptographic signature from the CSP.</p>
      </part>
      <part id="IDPAP-2_gdn" name="guidance">
        <p>The CSP can provide attributes from the subscriber account to the IdP as attribute values, derived attribute values, or attribute bundles.</p>
      </part>
    </control>
    <control id="TRUSTA-1">
      <title>Trust Agreement Establishment Method</title>
      <prop name="label" class="index" value="4.3 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TRUSTA-1_smt" name="statement">
        <p>Trust agreements for general-purpose IdPs SHALL be established either:</p>
        <p>(a) As the result of an agreement by the federated parties, prior to the federation transaction; or</p>
        <p>(b) As the result of decision or action by the subscriber, during the federation transaction.</p>
      </part>
      <part id="TRUSTA-1_obj" name="objective">
        <p>Determine whether the IdP uses one of the two trust agreement establishment methods.</p>
        <link href="#TRUSTA-1_smt" rel="assessment-for"/>
      </part>
      <part id="TRUSTA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to verify that the establishment method is either pre-established by the federated parties prior to the federation transaction, or subscriber-driven during the federation transaction.</p>
      </part>
      <part id="TRUSTA-1_gdn" name="guidance">
        <p>For pre-established trust agreement requirements, see PETA series (Sec. 4.3.1). For subscriber-driven trust agreement requirements, see SDTAE series (Sec. 4.3.2).</p>
      </part>
    </control>
    <control id="PETA-1">
      <title>Pre-Established Trust Agreement Terms</title>
      <prop name="label" class="index" value="4.3.1 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PETA-1_smt" name="statement">
        <p>When the trust agreement is established by the federated parties prior to the federation transaction, the trust agreement SHALL establish the following terms:</p>
        <p>(a) The set of subscriber attributes, derived attributes, and attribute bundles that the IdP can make available to the RP.</p>
        <p>(b) The attribute storage policy of the IdP for the subscriber account, including any available means for the subscriber to request deletion.</p>
        <p>(c) Any attribute sources from which the IdP receives applicable subscriber attributes, derived attributes, and attribute bundles, including the CSP.</p>
        <p>(d) Any identity APIs that are made available by the IdP, either directly or through an external provider, and which subscriber attributes are available at these APIs.</p>
        <p>(e) The population of subscriber accounts for which the IdP can create assertions.</p>
        <p>(f) Any additional uses of subscriber information beyond providing the identity service.</p>
        <p>(g) The set of subscriber attributes, derived attributes, and attribute bundles that the RP is allowed to request (i.e., a subset of the attributes made available).</p>
        <p>(h) The purpose for each attribute requested by the RP.</p>
        <p>(i) The provisioning models used by the RP for RP subscriber accounts.</p>
        <p>(j) The authorized party responsible for decisions regarding the release of subscriber attributes to the RP (e.g., the IdP organization, the subscriber).</p>
        <p>(k) The process and techniques used to inform subscribers about attribute sharing.</p>
        <p>(l) The process and techniques for collecting consent from the authorized party when necessary.</p>
        <p>(m) The xALs available from the IdP.</p>
        <p>(n) The xALs required by the RP.</p>
      </part>
      <part id="PETA-1_obj" name="objective">
        <p>Determine whether pre-established trust agreement artifact(s) document all required terms.</p>
        <link href="#PETA-1_smt" rel="assessment-for"/>
      </part>
      <part id="PETA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) and verify that each of the terms (a-n) is documented.</p>
      </part>
    </control>
    <control id="PETA-2">
      <title>Trust Agreement Availability to Operators</title>
      <prop name="label" class="index" value="4.3.1 B"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PETA-2_smt" name="statement">
        <p>The terms of the trust agreement SHALL be available to the operators of the RP and the IdP upon its establishment.</p>
      </part>
      <part id="PETA-2_obj" name="objective">
        <p>Determine whether trust agreement terms are made available to RP and IdP operators when the agreement is established.</p>
        <link href="#PETA-2_smt" rel="assessment-for"/>
      </part>
      <part id="PETA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) accessible to both the IdP and RP operators to ensure that all terms required by PETA-1 are available to them. Confirm that the terms became available to them prior to the initiation of operational federated transactions between the RP and IdP.</p>
      </part>
    </control>
    <control id="PETA-3">
      <title>Trust Agreement Availability to Subscribers</title>
      <prop name="label" class="index" value="4.3.1 C"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PETA-3_smt" name="statement">
        <p>The terms of the trust agreement SHALL be made available to subscribers upon request to the IdP or RP.</p>
      </part>
      <part id="PETA-3_obj" name="objective">
        <p>Determine whether subscribers can obtain trust agreement terms upon request to the IdP or RP.</p>
        <link href="#PETA-3_smt" rel="assessment-for"/>
      </part>
      <part id="PETA-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting the trust agreement terms documented in PETA-1, as a subscriber. Verify that the terms are provided.</p>
      </part>
    </control>
    <control id="PETA-4">
      <title>Redress Mechanism Assessment &amp; Disclosure</title>
      <prop name="label" class="index" value="4.3.1 D"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PETA-4_smt" name="statement">
        <p>The IdP and RP SHALL each assess their respective redress mechanisms for efficacy in resolving complaints or problems and disclose the results of this assessment as part of the trust agreement.</p>
      </part>
      <part id="PETA-4_obj" name="objective">
        <p>Determine whether the assessed party has evaluated its redress mechanisms and disclosed the assessment results in trust agreement artifact(s).</p>
        <link href="#PETA-4_smt" rel="assessment-for"/>
      </part>
      <part id="PETA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to verify that they include the results of the party's assessment of the efficacy of its redress mechanism, and that the information has been made available to the other party.</p>
      </part>
      <part id="PETA-4_gdn" name="guidance">
        <p>See Sec. 3.5.3 (RR-1 to RR-6) for additional requirements and considerations for redress mechanisms.</p>
      </part>
    </control>
    <control id="PETA-5">
      <title>FAL3 Trust Agreement Terms</title>
      <prop name="label" class="index" value="4.3.1 E"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="PETA-5_smt" name="statement">
        <p>If FAL3 is allowed within the trust agreement, the trust agreement SHALL stipulate the following terms regarding holder-of-key assertions (see Sec. 3.15) and bound authenticators (see Sec. 3.16):</p>
        <p>(a) The means by which holder-of-key assertions can be verified by the RP (such as a common trusted PKI system).</p>
        <p>(b) The means by which the RP can associate holder-of-key assertions with specific. RP subscriber accounts (such as attribute-based account resolution or pre-provisioning)</p>
        <p>(c) Whether bound authenticators are supplied by the RP or the subscriber.</p>
        <p>(d) Documentation of the binding ceremony used for any subscriber-provided bound authenticators.</p>
      </part>
      <part id="PETA-5_obj" name="objective">
        <p>Determine whether trust agreement artifact(s) document all required holder-of-key and bound authenticator terms when FAL 3 is permitted.</p>
        <link href="#PETA-5_smt" rel="assessment-for"/>
      </part>
      <part id="PETA-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) and verify the following: (1) If holder-of-key assertions are used, terms (a) and (b) are documented. (2) If bound authenticators are used, term (c) is documented. (3) If subscriber-provided bound authenticators are used, term (d) is documented.</p>
      </part>
    </control>
    <control id="PETA-6">
      <title>Shared Signaling Trust Agreement Terms</title>
      <prop name="label" class="index" value="4.3.1 F"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PETA-6_smt" name="statement">
        <p>If shared signaling is used by the IdP or RP (see Sec. 4.8), the terms of the trust agreement SHALL establish: the events that trigger a signal to be sent; which signals are sent for each trigger; the information included in each signal; and the expected behavior of the party receiving the signal.</p>
      </part>
      <part id="PETA-6_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) establish all four required elements for shared signaling.</p>
        <link href="#PETA-6_smt" rel="assessment-for"/>
      </part>
      <part id="PETA-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to verify documentation of each required element: (1) Triggering events: Identify and list each event that initiates a signal (e.g., account compromise detection, account termination, credential revocation). (2) Signal types per trigger: For each triggering event, verify that the specific signal(s) to be sent are identified.</p>
        <p>(3) Signal content: For each signal type, verify that the information included is specified (including whether personal information is included per SSIG-5).  (4) Receiver processing: For each signal type, verify that the expected behavior of the receiving party is defined.</p>
      </part>
      <part id="PETA-6_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
        <p>This control ensures operational clarity for shared signaling by requiring explicit documentation of the complete signal lifecycle: trigger -&gt; signal selection -&gt; content -&gt; response. SSIG-2 requires that this documentation be made available to authorized parties.</p>
      </part>
    </control>
    <control id="PETA-7">
      <title>Trust Agreement Periodic Review</title>
      <prop name="label" class="index" value="4.3.1 G"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PETA-7_smt" name="statement">
        <p>The trust agreement SHALL be reviewed periodically to ensure that it is still fit for purpose and to avoid unnecessary data exchange and the over-collection of subscriber data.</p>
      </part>
      <part id="PETA-7_obj" name="objective">
        <p>Determine whether the trust agreement is periodically reviewed, and that, as part of that review, subscriber data collection and data exchanges are assessed to determine whether they are still necessary.</p>
        <link href="#PETA-7_smt" rel="assessment-for"/>
      </part>
      <part id="PETA-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine relevant documentation to verify that the cadence of trust agreement reviews is documented and that clear ownership for the review is assigned. Determine whether the periodic reviews address whether the trust agreement remains fit for purpose and whether subscriber data exchange and collection remain necessary. For trust agreements that have been in effect long enough for a review cycle to have occurred, verify that reviews have been conducted as scheduled.</p>
      </part>
    </control>
    <control id="SDTAE-1">
      <title>Subscriber-Driven Trust Agreement Disclosure Terms</title>
      <prop name="label" class="index" value="4.3.2 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SDTAE-1_smt" name="statement">
        <p>In a subscriber-driven trust agreement, the trust agreement takes the form of a set of terms of use as opposed to a formal contract between parties. Consequently, the following terms SHALL be disclosed to the subscriber upon request:</p>
        <p>(a) Any attribute sources from which the IdP receives applicable subscriber attributes, including the CSP.</p>
        <p>(b) Any identity APIs that are made available by the IdP, either directly or through an external provider, and which subscriber attributes are available at these APIs.</p>
        <p>(c) The set of subscriber attributes, derived attributes, and attribute bundles that the IdP can make available to the RP.</p>
        <p>(d) The attribute storage policy of the IdP for the subscriber account, including any available means for the subscriber to request deletion; the use of any shared signaling between the IdP and RP.</p>
        <p>(e) The population of subscriber accounts for which the IdP can create assertions; any additional uses of subscriber information, beyond providing the identity service; the xALs available from the IdP.</p>
        <p>(f) The xALs required by the RP.</p>
      </part>
      <part id="SDTAE-1_obj" name="objective">
        <p>Determine whether the IdP discloses the required terms to subscribers upon request.</p>
        <link href="#SDTAE-1_smt" rel="assessment-for"/>
      </part>
      <part id="SDTAE-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting the trust agreement terms from the IdP, as a subscriber. Verify that all nine terms are provided.</p>
      </part>
      <part id="SDTAE-1_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is the authorized party.</p>
      </part>
    </control>
    <control id="SDTAE-2">
      <title>Subscriber-Driven Redress Assessment Disclosure</title>
      <prop name="label" class="index" value="4.3.2 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SDTAE-2_smt" name="statement">
        <p>The IdP SHALL assess its redress mechanisms for efficacy in resolving complaints or problems and disclose the results of this assessment to the subscriber.</p>
      </part>
      <part id="SDTAE-2_obj" name="objective">
        <p>Determine whether the IdP has assessed the efficacy of its redress mechanisms and discloses the results to subscribers.</p>
        <link href="#SDTAE-2_smt" rel="assessment-for"/>
      </part>
      <part id="SDTAE-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>The redress mechanism efficacy assessment is satisfied by PETA-4.</p>
        <p>Test for disclosure to the subscriber by requesting the results of the redress mechanism efficacy assessment, as a test subscriber. Verify that the results are provided.</p>
      </part>
      <part id="SDTAE-2_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is the authorized party.</p>
        <p>See Sec. 3.5.3 for additional requirements and considerations for redress mechanisms. (RR-1, RR-3, RR-4, RR-6)</p>
      </part>
    </control>
    <control id="SDTAE-3">
      <title>Subscriber-Driven Attribute Release</title>
      <prop name="label" class="index" value="4.3.2 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SDTAE-3_smt" name="statement">
        <p>The release of subscriber attributes SHALL be managed using a runtime decision at the IdP, as described in Sec. 4.6.1.3. The authorized party SHALL be the subscriber.</p>
      </part>
      <part id="SDTAE-3_obj" name="objective">
        <p>Determine whether the IdP manages attribute release using runtime decisions with the subscriber as the authorized party.</p>
        <link href="#SDTAE-3_smt" rel="assessment-for"/>
      </part>
      <part id="SDTAE-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by AAD-6.</p>
      </part>
      <part id="SDTAE-3_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is the authorized party.</p>
      </part>
    </control>
    <control id="SDTAE-4">
      <title>Runtime Decision Disclosure Terms</title>
      <prop name="label" class="index" value="4.3.2 D"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SDTAE-4_smt" name="statement">
        <p>The following terms of the trust agreement SHALL be disclosed to the subscriber during the runtime decision:</p>
        <p>(a) The set of subscriber attributes, derived attributes, and attribute bundles that the RP will request (i.e., a subset of the attributes made available by the IdP).</p>
        <p>(b) The purpose for each attribute requested by the RP.</p>
        <p>(c) The attribute storage policy of the RP for the RP subscriber account, including any available means for the subscriber to request deletion.</p>
      </part>
      <part id="SDTAE-4_obj" name="objective">
        <p>Determine whether the subscriber is informed of the requested attributes, their purpose, and the RP's storage policy prior to making the runtime attribute-release decision.</p>
        <link href="#SDTAE-4_smt" rel="assessment-for"/>
      </part>
      <part id="SDTAE-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction that triggers a runtime decision, as a test subscriber. Before making the attribute-release decision as the subscriber, verify that the following disclosures are presented to the subscriber across the IdP's and RP's combined interfaces: (1) the attributes the RP is requesting (see also IDPRD-3); (2) the purpose of the requested attributes; and (3) the RP's attribute storage policy, including deletion options.</p>
        <p>For each disclosure, record whether it was presented by the IdP, the RP, or both. If any disclosure is absent from both, the control is not satisfied.</p>
        <p>For RPs, repeat this test for each IdP (or wallet) supported by the RP.</p>
        <p>For IdPs, repeat this test for a representative sample of RPs that use the IdP.</p>
      </part>
      <part id="SDTAE-4_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is the authorized party.</p>
        <p>All information disclosed to the subscriber needs to be conveyed in a manner that is understandable and actionable, as discussed in Sec. 8.</p>
      </part>
    </control>
    <control id="DR-1">
      <title>IdP Identifier-Key Association</title>
      <prop name="label" class="index" value="4.4 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DR-1_smt" name="statement">
        <p>The RP SHALL associate the assertion validation keys and other relevant configuration information with the IdP's identifier, as stipulated by the trust agreement.</p>
      </part>
      <part id="DR-1_obj" name="objective">
        <p>Determine whether the RP associates the IdP's public signing key(s) and configuration information with the IdP's identifier per the trust agreement artifact(s).</p>
        <link href="#DR-1_smt" rel="assessment-for"/>
      </part>
      <part id="DR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's federation configuration and discovery/registration to determine that the RP associates the IdP's assertion validation key(s), and other relevant IdP-specific configuration information with the IdP's identifier, as stipulated by the trust agreement artifacts.</p>
      </part>
      <part id="DR-1_gdn" name="guidance">
        <p>See FAL3-4 for the related requirement that each party's identifier be uniquely associated with its verification keys.</p>
      </part>
    </control>
    <control id="DR-2">
      <title>Network Key Retrieval Protection</title>
      <prop name="label" class="index" value="4.4 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DR-2_smt" name="statement">
        <p>If the validation keys and configuration information are retrieved over a network connection, request and retrieval SHALL be made over an authenticated protected channel from a location that is associated with the IdP's identifier by the trust agreement.</p>
      </part>
      <part id="DR-2_obj" name="objective">
        <p>Determine whether the RP retrieves IdP keys and configuration information over an authenticated protected channel from a location specified in the trust agreement artifact(s).</p>
        <link href="#DR-2_smt" rel="assessment-for"/>
      </part>
      <part id="DR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to determine the location(s) associated with the IdP's identifier for retrieval of validation keys and configuration information. Examine the RP's federation configuration to verify that it retrieves keys and configuration information only from the specified location(s).</p>
        <p>The requirement that an authenticated protected channel be used is satisfied by ICKM-2.</p>
      </part>
      <part id="DR-2_gdn" name="guidance">
        <p>Assessment is required when: The validation keys and configuration information are retrieved over a network connection.</p>
        <p>In many federation protocols, this is accomplished by the RP fetching the public keys and configuration data from a URL specified in the trust agreement artifact(s) as controlled by the IdP or offered on the IdP's behalf. It is also possible for the RP to be configured directly with this information in a manual fashion, whereby the RP's system administrator enters the IdP information directly into the RP software's configuration.</p>
      </part>
    </control>
    <control id="DR-3">
      <title>RP Registration</title>
      <prop name="label" class="index" value="4.4 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DR-3_smt" name="statement">
        <p>The RP SHALL register its information with either the IdP or an authority that the IdP trusts, as stipulated by the trust agreement.</p>
      </part>
      <part id="DR-3_obj" name="objective">
        <p>Determine whether the RP has registered its information with the IdP or an IdP-trusted authority per the trust agreement artifact(s).</p>
        <link href="#DR-3_smt" rel="assessment-for"/>
      </part>
      <part id="DR-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to identify the required RP registration mechanism (direct with the IdP or via a federation authority). Verify that the RP has completed registration via the specified mechanism.</p>
      </part>
      <part id="DR-3_gdn" name="guidance">
        <p>In many federation protocols, the RP is assigned an identifier during this stage, which the RP will use in subsequent communication with the IdP.</p>
        <p>See also ICKM-1.</p>
      </part>
    </control>
    <control id="MR-1">
      <title>Automated Tooling for Manual Registration</title>
      <prop name="label" class="index" value="4.4.1 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="MR-1_smt" name="statement">
        <p>If [automated updates are utilized following manual registration], the trust agreement SHALL enumerate the allowable terms of the cryptographic key distribution and assignment, including allowable cache lifetimes.</p>
      </part>
      <part id="MR-1_obj" name="objective">
        <p>Determine whether trust agreement artifact(s) document the allowable terms for cryptographic key distribution and assignment, including allowable cache lifetimes, when automated updates are used following manual registration.</p>
        <link href="#MR-1_smt" rel="assessment-for"/>
      </part>
      <part id="MR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to verify that they include the allowable terms of cryptographic key distribution and assignment, and the allowable cache lifetimes.</p>
      </part>
      <part id="MR-1_gdn" name="guidance">
        <p>Assessment is required when: Automated updates are utilized following manual registration.</p>
        <p>Key updates following manual registration may be facilitated by automated tooling that points systems to a trusted source of information (e.g., a metadata URL) that can be updated over time. Cache lifetimes determine how long a party may use cached keys before re-fetching.</p>
      </part>
    </control>
    <control id="DYR-1">
      <title>Dynamic Registration Channel Protection</title>
      <prop name="label" class="index" value="4.4.2 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="FAL1/FAL2"/>
      <part id="DYR-1_smt" name="statement">
        <p>All transmission of configuration information SHALL be made over a secure protected channel to endpoints that are associated with the IdP's identifier by the trust agreement.</p>
      </part>
      <part id="DYR-1_obj" name="objective">
        <p>Determine whether configuration information transmitted during dynamic registration uses an authenticated protected channel to endpoints associated with the IdP per the trust agreement artifact(s).</p>
        <link href="#DYR-1_smt" rel="assessment-for"/>
      </part>
      <part id="DYR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant trust agreement artifact(s) to identify the endpoint(s) associated with the IdP's identifier for dynamic registration.  Verify the RP is configured to use the specified endpoint(s).</p>
      </part>
      <part id="DYR-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a dynamic registration from the RP and verify that configuration information is transmitted only to the endpoint(s) specified in the trust agreement artifact(s).</p>
        <p>The requirement that an authenticated protected channel be used is satisfied by ICKM-2.</p>
      </part>
      <part id="DYR-1_gdn" name="guidance">
        <p>Assessment is required when: Dynamic registration is used.</p>
        <p>At FAL1 and FAL2, the cryptographic keys and identifiers of the RP can be exchanged in a dynamic process, whereby the RP software presents its configuration to the IdP either directly or through a trusted third party and receives the identifier to use with that IdP. This process is specific to the federation protocol in use but requires machine-readable configuration data to be made available over the network.</p>
      </part>
    </control>
    <control id="SAI-1">
      <title>Subscriber Authentication Before IdP Actions</title>
      <prop name="label" class="index" value="4.5 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SAI-1_smt" name="statement">
        <p>The IdP SHALL require the subscriber to have an authenticated session before any of the following events:</p>
        <p>(a) Approval of attribute release.</p>
        <p>(b) Creation and issuance of an assertion.</p>
        <p>(c) Establishment of a subscriber-driven trust agreement.</p>
      </part>
      <part id="SAI-1_obj" name="objective">
        <p>Determine whether the IdP requires the subscriber to have an authenticated session before approving attribute release, creating/issuing assertions, or establishing subscriber-driven trust agreements.</p>
        <link href="#SAI-1_smt" rel="assessment-for"/>
      </part>
      <part id="SAI-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by (1) attempting to approve attribute release without an authenticated session. Verify that the IdP rejects the attempt. (2) Attempt to trigger assertion creation without an authenticated session. Verify that the IdP rejects the attempt. (3) If subscriber-driven trust agreements are supported, attempt to establish one without an authenticated session. Verify that the IdP rejects the attempt.</p>
      </part>
      <part id="SAI-1_gdn" name="guidance">
        <p>In a federation context, the IdP acts as the verifier for authenticators bound to the subscriber account, as described in [SP800-63B]. Verification of one or more authenticators creates an authentication event that begins the authenticated session at the IdP. This authentication event serves as the basis of the IdP's claim that the subscriber is present.</p>
      </part>
    </control>
    <control id="AUTHAD-1">
      <title>Authorized Party Decision</title>
      <prop name="label" class="index" value="4.6 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUTHAD-1_smt" name="statement">
        <p>The authorized party stipulated by the trust agreement SHALL decide whether a federation transaction proceeds and, therefore, whether an assertion is issued and attributes are released to the RP.</p>
      </part>
      <part id="AUTHAD-1_obj" name="objective">
        <p>Determine whether the authorized party identified in the trust agreement artifact(s) makes the decision on whether federation transactions proceed.</p>
        <link href="#AUTHAD-1_smt" rel="assessment-for"/>
      </part>
      <part id="AUTHAD-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to identify the designated authorized party or parties for the RPs supported by the IdP. Ensure that all covered cases are assessed by the authorized party identified in the trust agreement. If the subscriber is an authorized party, satisfied by IDPRD-1 through IDPRD-8.  If the organization is an authorized party satisfied by IALRP-1 through IALRP-6, and IDPBRP-1 and  IDPBRP-2.</p>
      </part>
      <part id="AUTHAD-1_gdn" name="guidance">
        <p>This decision can be calculated in a variety of ways, including:</p>
        <ul>
          <li>
            <p>An allowlist, which determines the circumstances under which the system can allow the federation transaction to proceed in an automated fashion;</p>
          </li>
          <li>
            <p>A blocklist, which determines the circumstances under which the system will not allow the federation transaction to proceed; and</p>
          </li>
          <li>
            <p>A runtime decision, which allows the authorized party (e.g., the subscriber) to decide whether the transaction can proceed and under what precise terms. A runtime decision can be stored and applied to future transactions.</p>
          </li>
        </ul>
        <p>The applicability of an allowlist, blocklist, or runtime decision can be influenced by aspects of the federation transaction, including the identity of the IdP and RP, the subscriber attributes requested, the xAL required, and other factors. These decisions can be facilitated by risk management systems, federation authorities, and local system policies. For a non-normative example of an RP that has been allowlisted at an IdP for a set of subscribers to facilitate single sign-on for an enterprise application, see Sec. 9.5.</p>
      </part>
    </control>
    <control id="AUTHAD-2">
      <title>IdP Redress Mechanisms</title>
      <prop name="label" class="index" value="4.6 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AUTHAD-2_smt" name="statement">
        <p>The IdP SHALL provide effective mechanisms for the redress of subscriber complaints or problems (e.g., subscriber identifies an inaccurate attribute value).</p>
      </part>
      <part id="AUTHAD-2_obj" name="objective">
        <p>Determine whether the IdP provides effective mechanisms for redress of subscriber complaints or problems.</p>
        <link href="#AUTHAD-2_smt" rel="assessment-for"/>
      </part>
      <part id="AUTHAD-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RR-3.</p>
      </part>
      <part id="AUTHAD-2_gdn" name="guidance">
        <p>IdPs need to provide effective mechanisms for redress of subscriber complaints or problems arising from the federation (e.g., subscriber identifies an inaccurate attribute value). The Privacy Act requires federal agencies that maintain a system of records to follow procedures to enable applicants to access and, if incorrect, amend their records. Any Privacy Act Statement should include a reference to the applicable SORN(s), which provide the subscriber with instructions on how to make a request for access or correction. Non-federal entities should have comparable procedures, including contact information for any third parties if they are the source of the information.</p>
      </part>
    </control>
    <control id="IALRP-1">
      <title>Allowlist: RP Conformance</title>
      <prop name="label" class="index" value="4.6.1.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IALRP-1_smt" name="statement">
        <p>When placing an RP on its allowlist, the IdP SHALL confirm that the RP abides by the terms of the trust agreement.</p>
      </part>
      <part id="IALRP-1_obj" name="objective">
        <p>Determine whether RPs in an IdP's allowlist are compliant with the terms of their trust agreement.</p>
        <link href="#IALRP-1_smt" rel="assessment-for"/>
      </part>
      <part id="IALRP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's policies and procedures for adding RPs to the allowlist to verify that a process exists to confirm RP compliance with the trust agreement artifact(s) before allowlisting. For a sample of allowlisted RPs, verify that evidence of compliance exists (e.g., review records, attestations, federation authority approval).</p>
      </part>
      <part id="IALRP-1_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes an allowlist for RPs.</p>
      </part>
    </control>
    <control id="IALRP-2">
      <title>Allowlist: IdP Attribute Determination for RPs</title>
      <prop name="label" class="index" value="4.6.1.1 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IALRP-2_smt" name="statement">
        <p>The IdP SHALL determine which identity attributes are passed to the allowlisted RP upon authentication.</p>
      </part>
      <part id="IALRP-2_obj" name="objective">
        <p>Determine whether the IdP controls which identity attributes are released to allowlisted RPs upon authentication.</p>
        <link href="#IALRP-2_smt" rel="assessment-for"/>
      </part>
      <part id="IALRP-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by IALRP-5 and IALRP-6.</p>
      </part>
      <part id="IALRP-2_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes an allowlist for RPs.</p>
      </part>
    </control>
    <control id="IALRP-3">
      <title>Allowlist: Subscriber Availability</title>
      <prop name="label" class="index" value="4.6.1.1 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IALRP-3_smt" name="statement">
        <p>IdPs SHALL make allowlists available to subscribers, as described in Sec. 7.2.</p>
      </part>
      <part id="IALRP-3_obj" name="objective">
        <p>Determine whether the list of allowlisted RPs is available to subscribers.</p>
        <link href="#IALRP-3_smt" rel="assessment-for"/>
      </part>
      <part id="IALRP-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's allowlist configuration to identify the full set of allowlisted RPs applicable to a test subscriber.</p>
      </part>
      <part id="IALRP-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting the allowlist from the IdP, as the same test subscriber above. Compare the returned list against the allowlist identified in the examine step and verify it is complete.</p>
      </part>
      <part id="IALRP-3_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes an allowlist for RPs.</p>
        <p>When an RP is allowlisted by an IdP, some subset of the subscriber's information is made available to the RP during the login process without the subscriber being prompted at runtime for additional consent or confirmation. The IdP needs to make the list of allowlisted RPs available to subscribers to allow subscribers to view which sites their information will be sent to during a federation transaction without the subscriber being specifically prompted.</p>
      </part>
    </control>
    <control id="IALRP-4">
      <title>Allowlist: RP Identification</title>
      <prop name="label" class="index" value="4.6.1.1 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IALRP-4_smt" name="statement">
        <p>IdP allowlists SHALL uniquely identify RPs through fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. Any entities that share an identifier SHALL be considered equivalent for the purposes of the allowlist. An allowlist entry for an RP SHALL NOT use a wildcard domain identifier.</p>
      </part>
      <part id="IALRP-4_obj" name="objective">
        <p>Determine whether IdP allowlist entries uniquely identify RPs using appropriate identifiers, and whether entities sharing an identifier are treated as equivalent.</p>
        <link href="#IALRP-4_smt" rel="assessment-for"/>
      </part>
      <part id="IALRP-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP allowlist entries and verify each RP is identified using fully qualified domain names, cryptographic keys, or other protocol-appropriate unique identifiers. Verify that no wildcard domain identifiers are used.</p>
      </part>
      <part id="IALRP-4_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes an allowlist for RPs.</p>
        <p>For blocklists, see IDPBRP-2.</p>
      </part>
    </control>
    <control id="IALRP-5">
      <title>Allowlist: Attribute Indication</title>
      <prop name="label" class="index" value="4.6.1.1 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IALRP-5_smt" name="statement">
        <p>IdP allowlist entries for an RP SHALL indicate which attributes are included as part of an allowlisted decision.</p>
      </part>
      <part id="IALRP-5_obj" name="objective">
        <p>Determine whether IdP allowlist entries specify which attributes can be released to each allowlisted RP.</p>
        <link href="#IALRP-5_smt" rel="assessment-for"/>
      </part>
      <part id="IALRP-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP allowlist entries and verify that each entry specifies the attributes that can be released to the RP.</p>
      </part>
      <part id="IALRP-5_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes an allowlist for RPs.</p>
        <p>Allowlist entries must not just identify the RP, but also define what attributes can be released. See IALRP-6 for handling of RP requests for additional attributes beyond the allowlist entry.</p>
      </part>
    </control>
    <control id="IALRP-6">
      <title>Allowlist: Additional Attribute Requests</title>
      <prop name="label" class="index" value="4.6.1.1 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IALRP-6_smt" name="statement">
        <p>If additional attributes are requested by the RP, the request SHALL be:</p>
        <p>(a) Subject to a runtime decision of the authorized party to approve the additional attributes requested.</p>
        <p>(b) Redacted to only the attributes in the allowlist entry, or</p>
        <p>(c) Denied outright by the IdP.</p>
      </part>
      <part id="IALRP-6_obj" name="objective">
        <p>Determine whether the IdP handles RP requests for attributes beyond the allowlist entry by either obtaining authorized party approval, redacting to allowlist attributes, or denying the request.</p>
        <link href="#IALRP-6_smt" rel="assessment-for"/>
      </part>
      <part id="IALRP-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by configuring an allowlist entry for a test RP with a defined set of attributes, then submitting a federation request from that RP that includes a request for additional attributes beyond those listed in the allowlist entry. Verify the IdP responds with one of the following: (a) Prompts the authorized party to approve the additional attributes (see IDPRD-1 through IDPRD-6), or (b) returns only the attributes specified in the allowlist entry, or (c) denies the request entirely.</p>
      </part>
      <part id="IALRP-6_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes an allowlist for RPs.</p>
        <p>This control ensures that allowlist entries are not simply bypassed by an RP requesting additional attributes. The IdP must have a policy for handling such requests and enforce it.</p>
      </part>
    </control>
    <control id="IDPBRP-1">
      <title>Blocklist Assertion Prohibition</title>
      <prop name="label" class="index" value="4.6.1.2 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPBRP-1_smt" name="statement">
        <p>If an RP is on an IdP's blocklist, the IdP SHALL NOT produce an assertion that targets the RP in question under any circumstances.</p>
      </part>
      <part id="IDPBRP-1_obj" name="objective">
        <p>Determine whether the IdP refuses to issue assertions to blocklisted RPs.</p>
        <link href="#IDPBRP-1_smt" rel="assessment-for"/>
      </part>
      <part id="IDPBRP-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by adding a test RP to the IdP's blocklist, then submitting a federation request as the blocklisted RP.  Verify the IdP refuses to produce an assertion.</p>
      </part>
      <part id="IDPBRP-1_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes a blocklist for RPs.</p>
      </part>
    </control>
    <control id="IDPBRP-2">
      <title>Blocklist: RP Identification</title>
      <prop name="label" class="index" value="4.6.1.2 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPBRP-2_smt" name="statement">
        <p>IdP blocklists SHALL identify RPs through the means of domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. Any entities that share an identifier SHALL be considered equivalent for the purposes of the blocklist.</p>
      </part>
      <part id="IDPBRP-2_obj" name="objective">
        <p>Determine whether IdP blocklist entries identify RPs using appropriate identifiers, and whether entities sharing an identifier are treated as equivalent.</p>
        <link href="#IDPBRP-2_smt" rel="assessment-for"/>
      </part>
      <part id="IDPBRP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP blocklist entries and verify that each RP is identified using domain names, cryptographic keys, or other protocol-applicable identifiers.</p>
      </part>
      <part id="IDPBRP-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by adding a wildcard entry (e.g., "*.example.com") to the IdP's blocklist, then submitting federation requests from multiple subdomains matching the wildcard (e.g., "www.example.com", "service.example.com"). Verify all matching requests are blocked.</p>
      </part>
      <part id="IDPBRP-2_gdn" name="guidance">
        <p>Assessment is required when: The IdP utilizes a blocklist for RPs.</p>
        <p>The Current text incorrectly states: IdP blocklists SHALL uniquely identify RPs through the means of fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. The text will be updated in the errata volume.</p>
      </part>
    </control>
    <control id="IDPRD-1">
      <title>RP Not on Allowlist: Runtime Authorization</title>
      <prop name="label" class="index" value="4.6.1.3 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-1_smt" name="statement">
        <p>Every RP that is in a trust agreement with an IdP but not on an allowlist with that IdP SHALL be governed by a default policy in which runtime authorization decisions will be made by an authorized party that is identified by the trust agreement.</p>
      </part>
      <part id="IDPRD-1_obj" name="objective">
        <p>Determine whether a request for information release by an RP that is not allowlisted triggers a runtime authorization decision by the authorized party.</p>
        <link href="#IDPRD-1_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP configuration to verify that a default policy exists requiring runtime authorization decisions for non-allowlisted RPs.</p>
      </part>
      <part id="IDPRD-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction from a non-allowlisted RP and verify that the IdP presents a runtime authorization decision to the authorized party, who can both approve and deny the request.</p>
      </part>
      <part id="IDPRD-1_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist.</p>
        <p>If a given RP is allowed to request a connection from an IdP, and that RP has not been allowlisted by the IdP, then the IdP must present a runtime authorization decision to the authorized party identified in the trust agreement. The purpose of this requirement is to allow authorized party-driven connection decisions where possible in addition to traditional pre-negotiated connections enabled by allowlists.</p>
      </part>
    </control>
    <control id="IDPRD-2">
      <title>RP Not on Allowlist: Attribute Release Consent</title>
      <prop name="label" class="index" value="4.6.1.3 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-2_smt" name="statement">
        <p>The IdP SHALL provide the authorized party with explicit notice and prompt them for positive confirmation before any attributes about the subscriber are transmitted to the RP.</p>
      </part>
      <part id="IDPRD-2_obj" name="objective">
        <p>Determine whether the IdP provides the authorized party with explicit notice and obtains positive confirmation before transmitting subscriber attributes to the RP.</p>
        <link href="#IDPRD-2_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction from a non-allowlisted RP. Verify that the IdP presents explicit notice and requires positive confirmation from the authorized party before transmitting any attributes. Verify that denying confirmation prevents attribute transmission.</p>
      </part>
      <part id="IDPRD-2_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist.</p>
      </part>
    </control>
    <control id="IDPRD-3">
      <title>RP Not on Allowlist: Attribute Disclosure Before Release</title>
      <prop name="label" class="index" value="4.6.1.3 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-3_smt" name="statement">
        <p>The IdP SHALL disclose which attributes will be released to the RP if the transaction is approved.</p>
      </part>
      <part id="IDPRD-3_obj" name="objective">
        <p>Determine whether the IdP discloses to the authorized party the specific attributes that will be released to the RP before the transaction is approved.</p>
        <link href="#IDPRD-3_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's runtime decision screens and related configurations to verify that a runtime decision prompt displays the list of attributes to be released prior to authorization.</p>
      </part>
      <part id="IDPRD-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction that triggers a runtime decision and verifying that the IdP presents the list of attributes to be released before the authorized party approves the transaction.</p>
      </part>
      <part id="IDPRD-3_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist.</p>
        <p>This control ensures informed decisions are made by requiring the IdP to show which attributes will be transmitted before the authorized party approves the transaction. Related Controls:</p>
        <ul>
          <li>
            <p>IDPRD-2 requires explicit notice and positive confirmation before attribute transmission.</p>
          </li>
          <li>
            <p>IDPRD-5 requires the IdP to provide mechanisms for viewing attribute values.</p>
          </li>
          <li>
            <p>IDPRD-4 addresses selective disclosure of optional attributes.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="IDPRD-4">
      <title>RP Not on Allowlist: Selective attribute disclosure</title>
      <prop name="label" class="index" value="4.6.1.3 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-4_smt" name="statement">
        <p>If the federation protocol in use allows for optional or selective attribute disclosure at runtime, the authorized party SHALL be given the option to decide whether to transmit specific attributes to the RP without terminating the federation transaction entirely.</p>
      </part>
      <part id="IDPRD-4_obj" name="objective">
        <p>Determine whether the authorized party can selectively approve or deny the RP access to any optional attributes without terminating the transaction.</p>
        <link href="#IDPRD-4_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's runtime decision interface to verify that optional attributes are clearly delineated from required attributes and that the authorized party is given the option to approve or deny individual optional attributes.</p>
      </part>
      <part id="IDPRD-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction that includes a request for optional attributes. Verify that: (1) The authorized party is presented with a clear distinction between required and optional attributes.  (2) The authorized party can deny optional attributes. (3) Denied optional attributes are not released to the RP. (4) The transaction continues after the denial of optional attributes.</p>
      </part>
      <part id="IDPRD-4_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist, and the federation protocol supports optional attributes in the request</p>
        <p>Some federation protocols allow for attributes to be requested for optional release. In such cases, the IdP must provide the authorized party with the opportunity to decide, during the process, whether to transmit those optional attributes to the RP. Optional attributes and the selection method need to be clearly delineated for the authorized party.</p>
      </part>
    </control>
    <control id="IDPRD-5">
      <title>RP Not on Allowlist: Attribute Value Viewing Mechanism</title>
      <prop name="label" class="index" value="4.6.1.3 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-5_smt" name="statement">
        <p>If the authorized party is the subscriber, the IdP SHALL provide mechanisms for the subscriber to view the attribute values and derived attribute values to be sent to the RP.</p>
      </part>
      <part id="IDPRD-5_obj" name="objective">
        <p>Determine whether the IdP provides the subscriber with a mechanism to view the actual attribute values and derived attribute values that will be transmitted to the RP.</p>
        <link href="#IDPRD-5_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the runtime decision screens to verify that mechanisms exist to display attribute and derived attribute values to the subscriber.</p>
      </part>
      <part id="IDPRD-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction as a subscriber that triggers a runtime decision. Verify that the subscriber can view the actual values of the attributes and derived attributes to be released.</p>
      </part>
      <part id="IDPRD-5_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist.</p>
        <p>This control goes beyond IDPRD-3 (which requires disclosure of which attributes will be released) by requiring the IdP to show the actual values of those attributes. This enables the subscriber to verify correctness and make an informed decision.</p>
        <p>Related Controls:</p>
        <ul>
          <li>
            <p>IDPRD-3 requires disclosure of which attributes will be released.</p>
          </li>
          <li>
            <p>IDPRD-6 requires masking of sensitive information by default.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="IDPRD-6">
      <title>RP Not on Allowlist: Sensitive Information Masking</title>
      <prop name="label" class="index" value="4.6.1.3 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-6_smt" name="statement">
        <p>To mitigate the risk of unauthorized exposure of sensitive information (e.g., shoulder surfing), the IdP SHALL, by default, mask sensitive information displayed to the subscriber.</p>
      </part>
      <part id="IDPRD-6_obj" name="objective">
        <p>Determine whether sensitive information is masked upon display by default.</p>
        <link href="#IDPRD-6_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-6_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction that triggers a runtime decision. Verify that all sensitive information displayed to the subscriber is masked by default.</p>
      </part>
      <part id="IDPRD-6_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist.</p>
        <p>The IdP is a trusted holder of information for the subscriber. When the subscriber interacts with the IdP, the IdP may need to display sensitive information to the subscriber to allow the subscriber to confirm and authorize its release to the RP. When doing so, the IdP must present that information so that the full value of the sensitive information is not displayed on the screen by default.</p>
      </part>
    </control>
    <control id="IDPRD-7">
      <title>RP Not on Allowlist: Remembered Decision Disclosure</title>
      <prop name="label" class="index" value="4.6.1.3 G"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-7_smt" name="statement">
        <p>The IdP SHALL disclose to the authorized party that the storage mechanism is in use.</p>
      </part>
      <part id="IDPRD-7_obj" name="objective">
        <p>Determine whether the IdP discloses to the authorized party that a mechanism is in use to remember their authorization decision.</p>
        <link href="#IDPRD-7_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the runtime decision screens and IdP documentation to verify that disclosure of the remembered decision mechanism is presented to the authorized party.</p>
      </part>
      <part id="IDPRD-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction that triggers a runtime decision and verify that the IdP either (a) gives the authorized party a choice whether or not the decision should be remembered for future transactions or (b) discloses that the authorization decision may be remembered for future transactions.</p>
      </part>
      <part id="IDPRD-7_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist, and the IdP employs a mechanism to remember the authorized party's decision.</p>
        <p>Related Control: IDPRD-8 requires the IdP to allow revocation of remembered decisions.</p>
      </part>
    </control>
    <control id="IDPRD-8">
      <title>RP Not on Allowlist: Remembered Decision Revocation</title>
      <prop name="label" class="index" value="4.6.1.3 H"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IDPRD-8_smt" name="statement">
        <p>[The IdP] SHALL allow the authorized party to revoke such remembered access at a future time.</p>
      </part>
      <part id="IDPRD-8_obj" name="objective">
        <p>Determine whether a previous runtime decision can be revoked by the authorized party.</p>
        <link href="#IDPRD-8_smt" rel="assessment-for"/>
      </part>
      <part id="IDPRD-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP interface to verify that the authorized party can view and revoke remembered authorization decisions.</p>
      </part>
      <part id="IDPRD-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by approving a non-allowlisted RP at runtime and have the IdP remember the decision. Then, initiate a new transaction with the same RP. Verify no runtime prompt appears.</p>
      </part>
      <part id="IDPRD-8_asm-test-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by revoking the above remembered decision using the IdP's revocation mechanism. Then, initiate another transaction with the same RP. Verify the runtime prompt reappears.</p>
      </part>
      <part id="IDPRD-8_gdn" name="guidance">
        <p>Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist, and the IdP employs a mechanism to remember the authorized party's decision.</p>
        <p>When the IdP remembers an authorized party's runtime decision, the IdP must provide a mechanism for the authorized party to revoke that decision so that future transactions with the same RP will trigger a new runtime authorization prompt. Related control: IDPRD-7 requires the IdP to disclose that the remembered decision mechanism is in use.</p>
      </part>
    </control>
    <control id="RPAIDP-1">
      <title>RP Allowlist: IdP Conformance</title>
      <prop name="label" class="index" value="4.6.2.1 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPAIDP-1_smt" name="statement">
        <p>When placing an IdP in its allowlist, the RP SHALL confirm that the IdP abides by the terms of the trust agreement. This confirmation can be facilitated by a federation authority or undertaken directly by the RP.</p>
      </part>
      <part id="RPAIDP-1_obj" name="objective">
        <p>Determine whether all IdPs in an RP's allowlist are compliant with the requirements of their trust agreement artifact(s).</p>
        <link href="#RPAIDP-1_smt" rel="assessment-for"/>
      </part>
      <part id="RPAIDP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP policies and procedures for adding IdPs to the allowlist to verify that a process exists for confirming IdP compliance with trust agreement artifact(s) before allowlisting. For a sample of allowlisted IdPs, verify that evidence of compliance confirmation exists (e.g., review records, attestation, federation authority approval).</p>
      </part>
      <part id="RPAIDP-1_gdn" name="guidance">
        <p>Assessment is required when: The RP maintains an IdP allowlist.</p>
        <p>Before adding an IdP to its allowlist, the RP must confirm that the IdP abides by the terms of the trust agreement artifact(s). This confirmation may be facilitated by a federation authority or undertaken directly by the RP.</p>
      </part>
    </control>
    <control id="RPAIDP-2">
      <title>RP Allowlist: IdP Identification</title>
      <prop name="label" class="index" value="4.6.2.1 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPAIDP-2_smt" name="statement">
        <p>RP allowlists SHALL uniquely identify IdPs through fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. An allowlist entry for an IdP SHALL NOT use a wildcard domain identifier.</p>
      </part>
      <part id="RPAIDP-2_obj" name="objective">
        <p>Determine whether the RP's allowlist uniquely identifies IdPs using appropriate identifiers for the federation protocol in use.</p>
        <link href="#RPAIDP-2_smt" rel="assessment-for"/>
      </part>
      <part id="RPAIDP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's allowlist configuration to verify that each IdP entry uses a unique identifier such as a fully qualified domain name, cryptographic key, or other protocol-appropriate identifier, and that no entries use wildcard domain identifiers.</p>
      </part>
      <part id="RPAIDP-2_gdn" name="guidance">
        <p>Assessment is required when: The RP maintains an IdP allowlist.</p>
        <p>Wildcard identifiers (e.g., "*.example.com") are prohibited because they could match unintended IdPs, undermining the security of the allowlist.</p>
      </part>
    </control>
    <control id="RPBIDP-1">
      <title>RP Blocklist: IdP Identification</title>
      <prop name="label" class="index" value="4.6.2.2 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPBIDP-1_smt" name="statement">
        <p>RP blocklists SHALL identify IdPs through domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. Any entities that share an identifier SHALL be considered equivalent for the purposes of the blocklist.</p>
      </part>
      <part id="RPBIDP-1_obj" name="objective">
        <p>Determine whether the RP's blocklist identifies IdPs using appropriate identifiers for the federation protocol in use and treats entities sharing an identifier as equivalent for blocking purposes.</p>
        <link href="#RPBIDP-1_smt" rel="assessment-for"/>
      </part>
      <part id="RPBIDP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP blocklist entries and verify that each IdP is identified using domain names, cryptographic keys, or other protocol-applicable identifiers.</p>
      </part>
      <part id="RPBIDP-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test with representative matching IdPs and determine that all matching entities are treated as equivalent for blocklist purposes, if the RP uses an identifier that can match multiple IdPs,</p>
      </part>
      <part id="RPBIDP-1_gdn" name="guidance">
        <p>Assessment is required when: The RP maintains an IdP blocklist.</p>
        <p>Unlike allowlists, blocklists may use wildcard domain identifiers to block multiple malicious or untrusted IdPs under a common domain.</p>
        <p>The Current text incorrectly states: "RP blocklists SHALL uniquely identify IdPs through fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use." The text will be updated in the errata volume.</p>
      </part>
    </control>
    <control id="RPRD-1">
      <title>RP Runtime Decision: IdP Acceptance</title>
      <prop name="label" class="index" value="4.6.2.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPRD-1_smt" name="statement">
        <p>Every IdP that is in a trust agreement with an RP but not on an allowlist with that RP SHALL be governed by a default policy in which runtime authorization decisions will be made by the authorized party indicated in the trust agreement.</p>
      </part>
      <part id="RPRD-1_obj" name="objective">
        <p>Determine whether non-allowlisted IdPs are governed by a default policy in which runtime authorization decisions are made by the authorized party identified in the trust agreement artifact(s).</p>
        <link href="#RPRD-1_smt" rel="assessment-for"/>
      </part>
      <part id="RPRD-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) and RP decision logic to determine which party is designated as the authorized party for non-allowlisted IdPs.</p>
      </part>
      <part id="RPRD-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction using an IdP that is in a trust agreement with the RP but is not allowlisted, and determine that the runtime decision is made by the authorized party identified in the trust agreement.</p>
      </part>
      <part id="RPRD-1_gdn" name="guidance">
        <p>Assessment is required when: The RP is in a trust agreement with an IdP, but does not include that IdP in an allowlist.</p>
        <p>For IdPs that are in a trust agreement with the RP but not allowlisted, the RP must present a runtime authorization decision to the authorized party. Common implementations include allowing the authorized party to type a directed identifier to facilitate discovery, or using an account chooser to select from available IdPs.</p>
      </part>
    </control>
    <control id="RPRD-2">
      <title>RP Runtime Decision: Remembered Decision Disclosure</title>
      <prop name="label" class="index" value="4.6.2.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPRD-2_smt" name="statement">
        <p>The RP SHALL disclose to the authorized party that the storage mechanism is in use.</p>
      </part>
      <part id="RPRD-2_obj" name="objective">
        <p>Determine whether the RP discloses to the authorized party that a mechanism is in use to remember their prior IdP authorization decision.</p>
        <link href="#RPRD-2_smt" rel="assessment-for"/>
      </part>
      <part id="RPRD-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine runtime decision screens and RP documentation to verify that the remembered IdP decision is disclosed to the authorized party.</p>
      </part>
      <part id="RPRD-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction that triggers a runtime IdP selection and verify that the RP either (a) gives the authorized party a choice whether the decision should be remembered for future transactions, or (b) discloses that the decision may be remembered for future transactions.</p>
      </part>
      <part id="RPRD-2_gdn" name="guidance">
        <p>Assessment is required when: The RP is in a trust agreement with an IdP, but does not include that IdP in an allowlist, and the RP employs a mechanism to remember the authorized party's decision.</p>
        <p>This is the RP-side equivalent of IDPRD-7. The RP's remembered decision concerns which IdP to contact, not which attributes to release. Since this mechanism operates prior to authentication (e.g., via a browser cookie outside the authenticated session), it is separate from the RP subscriber account. Related Controls: RPRD-3 requires the RP to allow revocation of remembered decisions.</p>
      </part>
    </control>
    <control id="RPRD-3">
      <title>RP Runtime Decision: Remembered Decision Revocation</title>
      <prop name="label" class="index" value="4.6.2.3 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPRD-3_smt" name="statement">
        <p>[The RP] SHALL allow the authorized party to revoke such remembered access at a future time.</p>
      </part>
      <part id="RPRD-3_obj" name="objective">
        <p>Determine whether a previous runtime decision can be revoked by the authorized party.</p>
        <link href="#RPRD-3_smt" rel="assessment-for"/>
      </part>
      <part id="RPRD-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP interface to verify a mechanism exists for the authorized party to view and revoke remembered IdP selection decisions.</p>
      </part>
      <part id="RPRD-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by selecting a non-allowlisted IdP at runtime and having the RP remember the decision. Then, initiate a new transaction and verify that no IdP selection prompt appears. Next, revoke the remembered decision using the RP's revocation mechanism. Initiate another transaction and verify that the IdP selection prompt reappears.</p>
      </part>
      <part id="RPRD-3_gdn" name="guidance">
        <p>Assessment is required when: The RP is in a trust agreement with an IdP, but does not include that IdP in an allowlist, and the RP employs a mechanism to remember the authorized party's decision.</p>
      </part>
    </control>
    <control id="PMRPSA-1">
      <title>RP Subscriber Account Provisioning Methods</title>
      <prop name="label" class="index" value="4.6.3 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PMRPSA-1_smt" name="statement">
        <p>The RP subscriber account SHALL be provisioned at the RP prior to the establishment of an authenticated session at the RP in one of the following ways:</p>
        <p>(a) Just-In-Time Provisioning</p>
        <p>(b) Pre-Provisioning</p>
        <p>(c) Ephemeral Provisioning</p>
        <p>(d) Other Provisioning Methods</p>
      </part>
      <part id="PMRPSA-1_obj" name="objective">
        <p>Determine whether the RP subscriber account is provisioned prior to session establishment using a documented provisioning method.</p>
        <link href="#PMRPSA-1_smt" rel="assessment-for"/>
      </part>
      <part id="PMRPSA-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>The underlying requirement that the RP subscriber account be provisioned through the method specified in the trust agreement artifact(s) before an authenticated session is created is satisfied by ASRP-1 and PMRPSA-7.</p>
        <p>If Just-In-Time Provisioning is used, this control is further satisfied by PMRPSA-2.</p>
        <p>If Pre-Provisioning is used, this control is further satisfied by PMRPSA-3 and PMRPSA-4.</p>
        <p>If Ephemeral Provisioning is used, this control is further satisfied by PMRPSA-5.</p>
        <p>If Alternative Provisioning Methods are used,  this control is further satisfied by PMRPSA-6.</p>
      </part>
    </control>
    <control id="PMRPSA-2">
      <title>Just-In-Time Provisioning Cached Attribute Management</title>
      <prop name="label" class="index" value="4.6.3 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PMRPSA-2_smt" name="statement">
        <p>The RP SHALL be responsible for managing any cached attributes it might have.</p>
      </part>
      <part id="PMRPSA-2_obj" name="objective">
        <p>Determine whether the RP manages cached subscriber attributes obtained through just-in-time provisioning.</p>
        <link href="#PMRPSA-2_smt" rel="assessment-for"/>
      </part>
      <part id="PMRPSA-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP policies and system documentation for attribute caching and lifecycle management, including retention periods, update procedures, and deletion processes.</p>
      </part>
      <part id="PMRPSA-2_gdn" name="guidance">
        <p>Assessment is required when: Just-In-Time Provisioning is used.</p>
        <p>In just-in-time provisioning, the RP subscriber account is created or updated at the time of the federation transaction based on attributes provided in the assertion. The RP may cache these attributes locally for use between federation transactions. This control ensures the RP has defined processes for managing the lifecycle of cached attributes.</p>
      </part>
    </control>
    <control id="PMRPSA-3">
      <title>Pre-Provisioned Account Access Method</title>
      <prop name="label" class="index" value="4.6.3 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PMRPSA-3_smt" name="statement">
        <p>Pre-provisioned accounts SHALL be bound to a federated identifier at the time of provisioning, unless an alternative means of access is defined by the trust agreement, such as an account linking policy (see Sec. 3.8.1), an account resolution policy (see Sec. 3.8.2), or alternative authentication mechanisms (see Sec. 3.8.3).</p>
      </part>
      <part id="PMRPSA-3_obj" name="objective">
        <p>Determine whether pre-provisioned RP subscriber accounts have a defined means of subscriber access, either through a federated identifier bound at the time of provisioning or through an alternative means of access defined in the trust agreement artifact(s).</p>
        <link href="#PMRPSA-3_smt" rel="assessment-for"/>
      </part>
      <part id="PMRPSA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the provisioning model documentation assessed under PMRPSA-7, and identify the means by which subscribers access pre-provisioned RP subscriber accounts. If a federated identifier is bound at provisioning time, verify that provisioning records include a federated identifier for each pre-provisioned account. If an alternative means of access is used, verify that the trust agreement artifact(s) define the alternative access method (e.g., account linking per Sec. 3.8.1, account resolution per Sec. 3.8.2, or alternative authentication per Sec. 3.8.3) and that the method is implemented.</p>
      </part>
      <part id="PMRPSA-3_gdn" name="guidance">
        <p>Assessment is required when: Pre-Provisioning is used.</p>
        <p>This requirement ensures that pre-provisioned RP subscriber accounts are not created without a defined path for subscribers to access them. The default mechanism is binding a federated identifier at provisioning time. If the trust agreement defines an alternative, such as account linking, account resolution, or direct authentication, that alternative must be documented and implemented.</p>
      </part>
    </control>
    <control id="PMRPSA-4">
      <title>Pre-Provisioning Privacy Considerations</title>
      <prop name="label" class="index" value="4.6.3 D"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PMRPSA-4_smt" name="statement">
        <p>The privacy considerations of the RP having access to this information prior to a federation transaction SHALL be accounted for in the trust agreement.</p>
      </part>
      <part id="PMRPSA-4_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) address the privacy considerations of the RP having access to subscriber information prior to a federation transaction.</p>
        <link href="#PMRPSA-4_smt" rel="assessment-for"/>
      </part>
      <part id="PMRPSA-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to verify that, when pre-provisioning is used, they account for the privacy considerations of the RP receiving subscriber information prior to a federation transaction. Verify that the trust agreement addresses, as applicable: (1) the categories of subscriber information the RP receives through pre-provisioning; (2) the fact that pre-provisioned data may include subscribers who may never interact with the RP; and (3) any privacy protections or limitations applicable to that pre-provisioned information, such as restrictions on collection, use, disclosure, retention, or synchronization.</p>
      </part>
      <part id="PMRPSA-4_gdn" name="guidance">
        <p>Assessment is required when: Pre-Provisioning is used.</p>
        <p>In this model, the RP also receives attributes about subscribers who have not yet interacted with the RP and who may never do so. This is in contrast to other models in which the RP only receives information about the subset of subscribers that use the RP, and then only after the subscriber uses the RP for the first time.</p>
      </part>
    </control>
    <control id="PMRPSA-5">
      <title>Ephemeral Provisioning Identifier Unlinking</title>
      <prop name="label" class="index" value="4.6.3 E"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PMRPSA-5_smt" name="statement">
        <p>If a federation identifier is supplied in the assertion, the RP SHALL remove any linkage of the federated identifier from an RP subscriber account.</p>
      </part>
      <part id="PMRPSA-5_obj" name="objective">
        <p>Determine whether the RP removes any linkage between the federated identifier and the RP subscriber account when using ephemeral provisioning.</p>
        <link href="#PMRPSA-5_smt" rel="assessment-for"/>
      </part>
      <part id="PMRPSA-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP system documentation and data retention policies to verify that federated identifiers are not persistently linked to ephemerally provisioned RP subscriber accounts.</p>
      </part>
      <part id="PMRPSA-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by conducting an ephemeral provisioning transaction and verifying that the federated identifier is not retained or linked to the RP subscriber account after the session ends.</p>
      </part>
      <part id="PMRPSA-5_gdn" name="guidance">
        <p>Assessment is required when: Ephemeral Provisioning is used, and a federation identifier is supplied in the assertion.</p>
        <p>When processing an assertion, the RP establishes a link between that assertion and a new or existing RP subscriber account but removes that link when the authenticated session ends. This process is similar to just-in-time provisioning, but the RP keeps no long-term record of the subscriber when the session is complete, in accordance with Sec. 3.11.3. This form of provisioning is useful for RPs that fully externalize access rights to the IdP, allowing the RP to be more simplified with less internal state. If this form of provisioning is used, the federated identifier is not required in the assertion.</p>
      </part>
    </control>
    <control id="PMRPSA-6">
      <title>Alternative Provisioning Privacy Assessment</title>
      <prop name="label" class="index" value="4.6.3 F"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PMRPSA-6_smt" name="statement">
        <p>The details of any alternative provisioning model SHALL be included in the privacy risk assessments of the IdP and RP.</p>
      </part>
      <part id="PMRPSA-6_obj" name="objective">
        <p>Determine whether the privacy risk assessments of the IdP and RP include the details of any alternative provisioning model in use.</p>
        <link href="#PMRPSA-6_smt" rel="assessment-for"/>
      </part>
      <part id="PMRPSA-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the privacy risk assessment to verify that it addresses the alternative provisioning model, including a description of the alternative provisioning model and the privacy risks specific to the model (e.g., data exposure, retention, minimization).</p>
      </part>
      <part id="PMRPSA-6_gdn" name="guidance">
        <p>Assessment is required when: An Alternative Provisioning Method is used.</p>
      </part>
    </control>
    <control id="PMRPSA-7">
      <title>Provisioning Model Documentation</title>
      <prop name="label" class="index" value="4.6.3 G"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PMRPSA-7_smt" name="statement">
        <p>All organizations SHALL document their provisioning models as part of their trust agreement.</p>
      </part>
      <part id="PMRPSA-7_obj" name="objective">
        <p>Determine whether the organization documents its provisioning model in the trust agreement artifact(s).</p>
        <link href="#PMRPSA-7_smt" rel="assessment-for"/>
      </part>
      <part id="PMRPSA-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the  trust agreement artifact(s) for documentation of the provisioning model(s) in use. Verify that each documented model is identifiable as one of the provisioning methods enumerated in Sec. 4.6.3: just-in-time, pre-provisioning, ephemeral, or an alternative method.</p>
      </part>
    </control>
    <control id="ATSYNC-1">
      <title>RP Processing of Termination Signal</title>
      <prop name="label" class="index" value="4.6.4 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ATSYNC-1_smt" name="statement">
        <p>Upon receiving such a signal, the RP SHALL process the RP subscriber account as stipulated in the trust agreement and in accordance with Sec. 3.11.3.</p>
      </part>
      <part id="ATSYNC-1_obj" name="objective">
        <p>Determine whether the RP processes the RP subscriber account in accordance with the trust agreement artifact(s) and Section 3.11.3 upon receiving a termination or revocation signal from the IdP.</p>
        <link href="#ATSYNC-1_smt" rel="assessment-for"/>
      </part>
      <part id="ATSYNC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to identify the stipulated processing requirements for termination and revocation signals. Review RP account termination procedures to verify alignment with those requirements, and with SSIN-1, SSIN-2, and SSIN-3.</p>
      </part>
      <part id="ATSYNC-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by sending a termination signal to the RP and verifying that the RP subscriber account is processed according to the requirements for termination and revocation signals stipulated in the trust agreement artifact(s), and in accordance with SSIN-1, SSIN-2, and SSIN-3.</p>
      </part>
      <part id="ATSYNC-1_gdn" name="guidance">
        <p>Assessment is required when: The RP may receive a signal from an IdP indicating that a subscriber account has been terminated or the subscriber's access to the RP has been revoked.</p>
      </part>
    </control>
    <control id="ATSYNC-2">
      <title>IdP Notification of Terminations due to Fraud or Suspicious Activity</title>
      <prop name="label" class="index" value="4.6.4 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ATSYNC-2_smt" name="statement">
        <p>If the reason for termination is suspicious or fraudulent activity, the IdP SHALL notify the RP of the termination and include the reason in its signal to the RP to allow the RP to review the associated RP subscriber account's activity for suspicious activity, if specified in the trust agreement with that RP.</p>
      </part>
      <part id="ATSYNC-2_obj" name="objective">
        <p>Determine whether the IdP notifies the RP and includes the reason when terminating a subscriber account due to suspicious or fraudulent activity, as specified in the trust agreement artifact(s).</p>
        <link href="#ATSYNC-2_smt" rel="assessment-for"/>
      </part>
      <part id="ATSYNC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to determine whether notification of termination due to suspicious or fraudulent activity is required. If required, review IdP procedures for signaling terminations to verify that the procedures include notifying the RP of the reason for termination.</p>
      </part>
      <part id="ATSYNC-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by simulating a termination due to suspicious activity and verify that the IdP's signal to the RP includes the reason for termination, if the trust agreement artifact(s) require notification of termination due to suspicious or fraudulent activity.</p>
      </part>
      <part id="ATSYNC-2_gdn" name="guidance">
        <p>Assessment is required when: The RP may receive a signal from an IdP indicating that a subscriber account has been terminated or the subscriber's access to the RP has been revoked.</p>
        <p>This notification enables the RP to review the associated RP subscriber account's activity for suspicious activity.</p>
      </part>
    </control>
    <control id="PAPI-1">
      <title>Provisioning API: Attributes Limited to RP Functions</title>
      <prop name="label" class="index" value="4.6.5 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-1_smt" name="statement">
        <p>The attributes in the provisioning API that are available to a given RP SHALL be limited to only those necessary for the RP to perform its functions, including any audit and security purposes, as discussed in Sec. 3.10.1.</p>
      </part>
      <part id="PAPI-1_obj" name="objective">
        <p>Determine whether the attributes available to the RP through the provisioning API are limited to those necessary for the RP to perform its functions.</p>
        <link href="#PAPI-1_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the provisioning API configuration to identify which attributes are available to each RP via the API. For each attribute, verify that it maps to a documented functional need of the RP (including audit and security purposes) as established in the trust agreement artifact(s). Verify that no attributes beyond those necessary are exposed through the API.</p>
      </part>
      <part id="PAPI-1_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
      </part>
    </control>
    <control id="PAPI-2">
      <title>Provisioning API: Documentation of Access Requirements</title>
      <prop name="label" class="index" value="4.6.5 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-2_smt" name="statement">
        <p>As part of establishing the trust agreement, the IdP SHALL document when an RP is given access to a provisioning API, including at least the following:</p>
        <p>(a) The purpose for the access using the provisioning model.</p>
        <p>(b) The set of attributes made available to the RP.</p>
        <p>(c) Whether the API functions as a push to the RP, a pull from the RP, or both.</p>
        <p>(d) The population of subscribers whose attributes are made available to the RP.</p>
      </part>
      <part id="PAPI-2_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) document the requirements for provisioning API access.</p>
        <link href="#PAPI-2_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to verify adequate documentation of the following: (1) the purpose for provisioning API access; (2) the set of attributes made available to the RP; (3) whether the API functions as push, pull, or both; and (4) the population of subscribers whose attributes are made available.</p>
      </part>
      <part id="PAPI-2_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
      </part>
    </control>
    <control id="PAPI-3">
      <title>Provisioning API Mutual Authentication</title>
      <prop name="label" class="index" value="4.6.5 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-3_smt" name="statement">
        <p>Access to the provisioning API SHALL occur over a mutually authenticated protected channel.</p>
      </part>
      <part id="PAPI-3_obj" name="objective">
        <p>Determine whether access to the provisioning API occurs over a mutually authenticated protected channel.</p>
        <link href="#PAPI-3_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the provisioning API configuration and documentation to verify that mutual authentication is required for all connections.</p>
      </part>
      <part id="PAPI-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to access the provisioning API without presenting RP credentials and verify that access is denied.</p>
      </part>
      <part id="PAPI-3_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
        <p>A mutually authenticated protected channel requires both parties (IdP and RP) to authenticate to each other, unlike a standard authenticated protected channel where only the server is authenticated.</p>
      </part>
    </control>
    <control id="PAPI-4">
      <title>Provisioning API Prohibition for Subscriber-Driven Trust Agreements</title>
      <prop name="label" class="index" value="4.6.5 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-4_smt" name="statement">
        <p>A provisioning API SHALL NOT be made available under a subscriber-driven trust agreement.</p>
      </part>
      <part id="PAPI-4_obj" name="objective">
        <p>Determine whether the IdP prohibits provisioning API access under subscriber-driven trust agreements.</p>
        <link href="#PAPI-4_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP policies and provisioning API access controls to verify that provisioning API access is not granted to RPs operating under subscriber-driven trust agreements.</p>
      </part>
      <part id="PAPI-4_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
        <p>Subscriber-driven trust agreements rely on runtime decisions by the subscriber rather than pre-established organizational agreements. Provisioning APIs provide bulk or out-of-band access to subscriber attributes, which is incompatible with the subscriber-controlled nature of subscriber-driven trust agreements.</p>
      </part>
    </control>
    <control id="PAPI-5">
      <title>Trust Agreement Required for Provisioning API</title>
      <prop name="label" class="index" value="4.6.5 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-5_smt" name="statement">
        <p>The IdP SHALL NOT make a provisioning API available to any RP outside of an established trust agreement.</p>
      </part>
      <part id="PAPI-5_obj" name="objective">
        <p>Determine whether the IdP restricts provisioning API access to RPs with established trust agreements.</p>
        <link href="#PAPI-5_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP provisioning API access control configuration to verify that each RP with API access has a corresponding established trust agreement with the IdP that allows provisioning API access (see PAPI-2).</p>
      </part>
      <part id="PAPI-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to access the provisioning API as an RP without an established trust agreement with the IdP. Verify that access is denied.</p>
      </part>
      <part id="PAPI-5_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
      </part>
    </control>
    <control id="PAPI-6">
      <title>Provisioning API Purpose Limitation</title>
      <prop name="label" class="index" value="4.6.5 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-6_smt" name="statement">
        <p>IdP SHALL provide access to a provisioning API only as part of a federated identity relationship with an RP to facilitate federation transactions with that RP and related functions, such as signaling revocation of the subscriber account.</p>
      </part>
      <part id="PAPI-6_obj" name="objective">
        <p>Determine whether the IdP limits provisioning API access to the purpose of facilitating federation transactions and related functions.</p>
        <link href="#PAPI-6_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>The purpose for provisioning API access is satisfied by PAPI-2(a).</p>
        <p>Examine the IdP's provisioning API capabilities to verify that API functionality is limited to facilitating federation transactions and related functions (e.g., account provisioning, attribute synchronization, account revocation signaling). Verify that no API capabilities serve purposes outside the federated identity relationship (e.g., general-purpose directory queries, marketing data access, analytics unrelated to federation).</p>
      </part>
      <part id="PAPI-6_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
      </part>
    </control>
    <control id="PAPI-7">
      <title>Provisioning API Access Revocation</title>
      <prop name="label" class="index" value="4.6.5 G"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-7_smt" name="statement">
        <p>The IdP SHALL revoke an RP's access to the provisioning API once access is no longer required by the RP for its functioning purposes or when the trust agreement is terminated.</p>
      </part>
      <part id="PAPI-7_obj" name="objective">
        <p>Determine whether the IdP revokes RP access to the provisioning API when no longer required or when the trust agreement is terminated</p>
        <link href="#PAPI-7_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP policies and procedures for provisioning API access lifecycle management to verify that access is terminated when the trust agreement is terminated or when the RP notifies the IdP that access is no longer needed.</p>
      </part>
      <part id="PAPI-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by revoking a test RP's provisioning API access and verifying that the RP can no longer access the API.</p>
      </part>
      <part id="PAPI-7_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
      </part>
    </control>
    <control id="PAPI-8">
      <title>Provisioning API Control and Jurisdiction</title>
      <prop name="label" class="index" value="4.6.5 H"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-8_smt" name="statement">
        <p>Any provisioning API provided to the RP SHALL be under the control and jurisdiction of the IdP.</p>
      </part>
      <part id="PAPI-8_obj" name="objective">
        <p>Determine whether the IdP is responsible for the content and accuracy of the provisioning API, including when the API infrastructure is operated by a third party.</p>
        <link href="#PAPI-8_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the system architecture documentation to determine whether the provisioning API is operated directly by the IdP or by a third party. If it is operated by a third party, examine the agreement between the IdP and the third party to verify that the IdP retains responsibility for the content and accuracy of the API's outputs. Verify that the agreement defines how the IdP enforces content and accuracy requirements (e.g., attribute validation, error correction, audit rights).</p>
      </part>
      <part id="PAPI-8_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
      </part>
    </control>
    <control id="PAPI-9">
      <title>Provisioning API Account State Change Signaling</title>
      <prop name="label" class="index" value="4.6.5 I"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-9_smt" name="statement">
        <p>When a provisioning API is in use, the IdP SHALL signal to the RP when the state of a subscriber account has been changed, such as when the account has been terminated or disabled.</p>
      </part>
      <part id="PAPI-9_obj" name="objective">
        <p>Determine whether the IdP signals the RP through the provisioning API when the state of a subscriber account changes.</p>
        <link href="#PAPI-9_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's provisioning API documentation and procedures to verify that account state changes (termination, disabling, etc.) trigger signals to the RP.</p>
      </part>
      <part id="PAPI-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by changing the state of a subscriber account (e.g., disable the account) and verifying that the IdP sends a signal to the RP indicating the state change.</p>
      </part>
      <part id="PAPI-9_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
        <p>PRIVR-9 addresses the specific requirement to deprovision terminated accounts via the provisioning API.</p>
      </part>
    </control>
    <control id="PAPI-10">
      <title>Federated Identifier Unbinding Upon Terminated/Disabled Signal</title>
      <prop name="label" class="index" value="4.6.5 J"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-10_smt" name="statement">
        <p>When receiving such a signal, the RP SHALL remove the binding of the federated identifier from the account.</p>
      </part>
      <part id="PAPI-10_obj" name="objective">
        <p>Determine whether the RP removes the federated identifier from the RP subscriber account upon receiving a signal that the subscriber account has been terminated or disabled.</p>
        <link href="#PAPI-10_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's design, configuration, and signal-processing logic for handling IdP signals indicating that a subscriber account has been terminated or disabled. Verify that receipt of such a signal causes the RP to remove the corresponding federated identifier from the affected RP subscriber account.</p>
      </part>
      <part id="PAPI-10_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by sending a signal indicating that a test subscriber account has been terminated or disabled. Verify that the RP removes the federated identifier associated with that IdP from the RP subscriber account.</p>
      </part>
      <part id="PAPI-10_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
        <p>In the errata publication, this control will be changed to: When receiving a signal indicating that the account has been terminated or disabled, the RP SHALL remove the federated identifier from the RP subscriber account.</p>
        <p>Related Controls:</p>
        <ul>
          <li>
            <p>PAPI-9 requires the IdP to signal account state changes.</p>
          </li>
          <li>
            <p>ACCL-2 prohibits access once a federated identifier is removed.</p>
          </li>
        </ul>
      </part>
    </control>
    <control id="PAPI-11">
      <title>Provisioning API: Personal Information Handling</title>
      <prop name="label" class="index" value="4.6.5 K"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="PAPI-11_smt" name="statement">
        <p>The RP SHALL treat all personal information sourced from the provisioning API in accordance with Sec. 3.11.3.</p>
      </part>
      <part id="PAPI-11_obj" name="objective">
        <p>Determine whether the RP treats personal information sourced from the provisioning API in accordance with Section 3.11.3 requirements.</p>
        <link href="#PAPI-11_smt" rel="assessment-for"/>
      </part>
      <part id="PAPI-11_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by CAARP-1.</p>
      </part>
      <part id="PAPI-11_gdn" name="guidance">
        <p>Assessment is required when: The IdP provides a provisioning API.</p>
      </part>
    </control>
    <control id="CAARP-1">
      <title>RP Subscriber Account Attribute Storage</title>
      <prop name="label" class="index" value="4.6.6 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CAARP-1_smt" name="statement">
        <p>All attributes in the RP subscriber account - regardless of source - SHALL be stored in accordance with Sec. 3.11.3.</p>
      </part>
      <part id="CAARP-1_obj" name="objective">
        <p>Determine whether the RP stores all attributes in the RP subscriber account in accordance with Section 3.11.3 requirements.</p>
        <link href="#CAARP-1_smt" rel="assessment-for"/>
      </part>
      <part id="CAARP-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by SSIN-1 through SSIN-3.</p>
      </part>
      <part id="CAARP-1_gdn" name="guidance">
        <p>This control applies to all attributes regardless of source (assertion, provisioning API, identity API, or other sources).</p>
      </part>
    </control>
    <control id="CAARP-2">
      <title>Disclosure of Purpose for Additional Attributes</title>
      <prop name="label" class="index" value="4.6.6 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CAARP-2_smt" name="statement">
        <p>The RP SHALL disclose to the subscriber the purpose for collecting any additional attributes.</p>
      </part>
      <part id="CAARP-2_obj" name="objective">
        <p>Determine whether the RP discloses to the subscriber the purpose for any additional attributes collected.</p>
        <link href="#CAARP-2_smt" rel="assessment-for"/>
      </part>
      <part id="CAARP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP subscriber-facing documentation, such as privacy notices and consent screens, to verify that the purpose for collecting additional attributes is disclosed to the subscriber.</p>
      </part>
      <part id="CAARP-2_gdn" name="guidance">
        <p>Assessment is required when: The RP collects additional attributes not provided by the IdP.</p>
      </part>
    </control>
    <control id="CAARP-3">
      <title>Additional Attribute Use Limitation</title>
      <prop name="label" class="index" value="4.6.6 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CAARP-3_smt" name="statement">
        <p>These attributes SHALL be used solely for the stated purposes of the RP's functionality.</p>
      </part>
      <part id="CAARP-3_obj" name="objective">
        <p>Determine whether the RP limits use of additional attributes to the stated purposes of its functionality.</p>
        <link href="#CAARP-3_smt" rel="assessment-for"/>
      </part>
      <part id="CAARP-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine RP policies and procedures for handling additional attributes to verify that use is limited to the purposes disclosed per CAARP-2.</p>
      </part>
      <part id="CAARP-3_gdn" name="guidance">
        <p>Assessment is required when: The RP collects additional attributes not provided by the IdP.</p>
        <p>This control requires the RP to adhere to the purpose disclosed under CAARP-2.</p>
      </part>
    </control>
    <control id="CAARP-4">
      <title>RP Attribute Transmission Limitations</title>
      <prop name="label" class="index" value="4.6.6 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CAARP-4_smt" name="statement">
        <p>The transmission of additionally collected attributes SHALL be handled in accordance with Sec. 3.10.1.</p>
      </part>
      <part id="CAARP-4_obj" name="objective">
        <p>Determine whether the RP handles the transmission of additionally collected attributes in accordance with the limitations in Sec. 3.10.1.</p>
        <link href="#CAARP-4_smt" rel="assessment-for"/>
      </part>
      <part id="CAARP-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Apply the assessment methods from TSI-1, TSI-2, and TSI-3 to the RP's transmission of additionally collected attributes, substituting the RP for the IdP in each assessment.</p>
      </part>
      <part id="CAARP-4_gdn" name="guidance">
        <p>Assessment is required when: The RP collects additional attributes not provided by the IdP.</p>
        <p>Section 3.10.1 establishes limitations on transmitting subscriber information, directed at the IdP (TSI-1 through TSI-3). This control extends those same limitations to the RP when transmitting additionally collected attributes - attributes the RP gathered independently, not through the federation transaction.</p>
      </part>
    </control>
    <control id="CAARP-5">
      <title>Redress for Additionally Collected Attributes</title>
      <prop name="label" class="index" value="4.6.6 E"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CAARP-5_smt" name="statement">
        <p>The RP SHALL provide a secure and effective means of redress for the subscriber to update and remove these additionally collected attributes from the RP subscriber account.</p>
      </part>
      <part id="CAARP-5_obj" name="objective">
        <p>Determine whether the RP provides a secure and effective means of redress for subscribers to request updates to or removal of additionally collected attributes.</p>
        <link href="#CAARP-5_smt" rel="assessment-for"/>
      </part>
      <part id="CAARP-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's subscriber-facing interfaces and account management capabilities to verify that subscribers can request updates to, and removal of, any additionally collected attributes from their RP subscriber account.</p>
      </part>
      <part id="CAARP-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting an update to an attribute value and requesting the removal of an attribute, as a test subscriber who has additionally collected attributes in their RP subscriber account. Verify that both requests are processed.</p>
      </part>
      <part id="CAARP-5_gdn" name="guidance">
        <p>Assessment is required when: The RP collects additional attributes not provided by the IdP.</p>
      </part>
    </control>
    <control id="CAARP-6">
      <title>Federal RP SORN Disclosure for Additional Attributes</title>
      <prop name="label" class="index" value="4.6.6 F"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CAARP-6_smt" name="statement">
        <p>An RP SHALL disclose any additional attributes collected and their use as part of its System of Records Notice (SORN).</p>
      </part>
      <part id="CAARP-6_obj" name="objective">
        <p>Determine whether the federal agency RP discloses additionally collected attributes and their use in its SORN.</p>
        <link href="#CAARP-6_smt" rel="assessment-for"/>
      </part>
      <part id="CAARP-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's System of Records Notice (SORN) to verify that additionally collected attributes and their uses are disclosed.</p>
      </part>
      <part id="CAARP-6_gdn" name="guidance">
        <p>Assessment is required when: The RP is a federal agency and collects additional attributes not provided by the IdP.</p>
        <p>This control applies only to RPs that are federal agencies. SORN requirements derive from the Privacy Act of 1974 (5 U.S.C. 552a).</p>
      </part>
    </control>
    <control id="TBRRP-1">
      <title>Time-Based Termination Notice and Reactivation</title>
      <prop name="label" class="index" value="4.6.7 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TBRRP-1_smt" name="statement">
        <p>When processing an inactive account, the RP SHALL provide sufficient notice to the subscriber about the pending termination of the account and provide the subscriber with an option to re-activate the account prior to its scheduled termination.</p>
      </part>
      <part id="TBRRP-1_obj" name="objective">
        <p>Determine whether the RP provides sufficient notice to subscribers about pending account termination and an option to reactivate the account prior to scheduled termination, when processing inactive accounts for time-based removal.</p>
        <link href="#TBRRP-1_smt" rel="assessment-for"/>
      </part>
      <part id="TBRRP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's policies and procedures for time-based account termination, including notice timelines and reactivation processes. Also, examine sample termination notices to verify they inform subscribers of pending termination and provide a reactivation option.</p>
      </part>
      <part id="TBRRP-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by triggering a time-based termination process for a test account and verifying that notice is provided, and reactivation is available prior to termination.</p>
      </part>
      <part id="TBRRP-1_gdn" name="guidance">
        <p>Assessment is required when: The RP uses time-based removal of RP subscriber accounts.</p>
        <p>"Sufficient notice" should be tailored to expected usage patterns at the RP. For example, an RP that expects weekly access might provide 30 days' notice, while an RP that expects monthly access might provide 90 days or more.</p>
      </part>
    </control>
    <control id="TBRRP-2">
      <title>Personal Information Removal Upon Time-Based Termination</title>
      <prop name="label" class="index" value="4.6.7 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TBRRP-2_smt" name="statement">
        <p>Upon termination, the RP SHALL remove all personal information associated with the RP subscriber account in accordance with Sec. 3.11.3.</p>
      </part>
      <part id="TBRRP-2_obj" name="objective">
        <p>Determine whether the RP removes all personal information associated with the RP subscriber account upon termination in accordance with Sec. 3.11.3.</p>
        <link href="#TBRRP-2_smt" rel="assessment-for"/>
      </part>
      <part id="TBRRP-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RPSA-1.</p>
      </part>
      <part id="TBRRP-2_gdn" name="guidance">
        <p>Assessment is required when: The RP uses time-based removal of RP subscriber accounts.</p>
      </part>
    </control>
    <control id="RASR-1">
      <title>Communication of Authentication Recency</title>
      <prop name="label" class="index" value="4.7 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RASR-1_smt" name="statement">
        <p>The IdP SHALL communicate to the RP any information that the IdP has regarding the recency of the subscriber's latest authentication event at the IdP, and the RP MAY use this information to make authorization and access decisions.</p>
      </part>
      <part id="RASR-1_obj" name="objective">
        <p>Determine whether the IdP communicates information regarding the recency of the subscriber's latest authentication event to the RP.</p>
        <link href="#RASR-1_smt" rel="assessment-for"/>
      </part>
      <part id="RASR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP assertion structure and documentation to verify that recency information for the subscriber's latest authentication event is included in assertions.</p>
      </part>
      <part id="RASR-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by having the IdP generate a test assertion and verify the authentication timestamp is present. Next, trigger a new authentication event at the IdP to generate a second assertion. Verify the second assertion reflects the updated authentication time.</p>
      </part>
      <part id="RASR-1_gdn" name="guidance">
        <p>A federated assertion is generated in the context of an active authentication event for the subscriber at the IdP. When communicating the authentication state of the subscriber to the RP in an assertion, the IdP has to communicate the timing of that authentication event to the RP. This information can help the RP make access decisions, such as requesting the subscriber to re-authenticate at the IdP directly before being allowed to access highly sensitive information.</p>
      </part>
    </control>
    <control id="RASR-2">
      <title>Identity API Access Insufficient for Session Extension</title>
      <prop name="label" class="index" value="4.7 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RASR-2_smt" name="statement">
        <p>The RP's ability to successfully fetch additional attributes through an identity API SHALL NOT be used to establish or extend a session at the RP.</p>
      </part>
      <part id="RASR-2_obj" name="objective">
        <p>Determine whether the RP refrains from using successful identity API attribute fetches to extend an existing authenticated session.</p>
        <link href="#RASR-2_smt" rel="assessment-for"/>
      </part>
      <part id="RASR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>The prohibition on session establishment via identity API access, is satisfied by IDAP-3.</p>
        <p>For the session extension prohibition: Examine the RP session-management logic, session renewal/extension code, and timeout handling to verify that successful identity API calls do not trigger session extension or reset the overall or inactivity timeout.</p>
      </part>
      <part id="RASR-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by establishing an authenticated session at the RP and allowing it to approach an overall or inactivity timeout threshold. Successfully fetch attributes via the identity API. Verify that the session is not extended or refreshed solely as a result of the API call.</p>
      </part>
      <part id="RASR-2_gdn" name="guidance">
        <p>Assessment is required when: An identity API is available to the RP.</p>
        <p>The lifetime of the access to the identity API is independent of the lifetime of the assertion.</p>
      </part>
    </control>
    <control id="SSIG-1">
      <title>Shared Signaling Purpose Limitations</title>
      <prop name="label" class="index" value="4.8 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-1_smt" name="statement">
        <p>Shared signaling SHALL be limited to the allowable functions of the identity process, as discussed in Sec. 3.10.1.</p>
      </part>
      <part id="SSIG-1_obj" name="objective">
        <p>Determine whether all shared signals serve one of the allowable identity process functions defined in Section 3.10.1.</p>
        <link href="#SSIG-1_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the shared signals documentation (see SSIG-2 and SSIG-3). For each signal type, verify that the stated purpose maps to one of the allowable functions: (1) identity service (identity proofing, authentication, or attribute assertions), (2) a specific subscriber request, (3) fraud mitigation related to the identity service, or (4) security incident response related to the identity service. Flag any signal that serves a purpose outside these four categories.</p>
      </part>
      <part id="SSIG-1_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
        <p>Shared signals are communications between the IdP and RP that occur outside of the federation transaction to alert federation partner(s) of important changes in state that would not otherwise be known, such as suspected fraud or an account status change.</p>
        <p>This control gates all shared signaling to the same purpose limitations that govern other subscriber information transmissions under Section 3.10.1. SSIG-2 and SSIG-3 require documentation of signal purposes; this control verifies those purposes are permissible.</p>
      </part>
    </control>
    <control id="SSIG-2">
      <title>Shared Signaling Documentation and Disclosure</title>
      <prop name="label" class="index" value="4.8 B"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-2_smt" name="statement">
        <p>All uses of shared signaling SHALL be documented in the trust agreement and made available to the authorized party stipulated by the trust agreement.</p>
      </part>
      <part id="SSIG-2_obj" name="objective">
        <p>Determine whether (1) all uses of shared signaling are documented in the trust agreement artifact(s), and (2) that this documentation is made available to the authorized party.</p>
        <link href="#SSIG-2_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to verify that all shared signaling uses are documented. Identify the authorized party designated to receive this documentation. Verify the documentation has been made available to that party (e.g., through disclosure records, acknowledgment of receipt, or accessibility via published terms).</p>
      </part>
      <part id="SSIG-2_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
        <p>For documentation content requirements, see SSIG-3.</p>
        <p>The "authorized party" varies by trust agreement type. In subscriber-driven agreements, this is typically the subscriber (see SDTAE-1, which includes shared signaling in required disclosures). In pre-established agreements, this may be the federation parties or a federation authority. SSIG-3 specifies the required content of this documentation; PETA-6 establishes trust agreement terms for shared signaling.</p>
      </part>
    </control>
    <control id="SSIG-3">
      <title>Shared Signaling Documentation Content</title>
      <prop name="label" class="index" value="4.8 C"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-3_smt" name="statement">
        <p>[The Trust Agreement artifact(s)] SHALL include the events under which a signal is sent, the type of information included in such a signal (including any personal information), any additional parameters sent with the signal, and the expected processing of a received signal.</p>
      </part>
      <part id="SSIG-3_obj" name="objective">
        <p>Determine whether the trust agreement artifact(s) document the required shared signaling content elements.</p>
        <link href="#SSIG-3_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by PETA-6.</p>
      </part>
      <part id="SSIG-3_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
      </part>
    </control>
    <control id="SSIG-4">
      <title>Shared Signaling Privacy Review</title>
      <prop name="label" class="index" value="4.8 D"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-4_smt" name="statement">
        <p>The use of shared signaling SHALL be subject to privacy review under the trust agreement.</p>
      </part>
      <part id="SSIG-4_obj" name="objective">
        <p>Determine whether shared signaling has been subject to privacy review under the trust agreement.</p>
        <link href="#SSIG-4_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine each party's privacy risk assessment (or equivalent privacy review documentation) to verify that shared signaling is addressed, including the events that trigger signals, any personal information transmitted, and the expected processing by the receiving party. Refer to SSIG-2 and PETA-6 for the documented signaling terms that should be covered by the privacy review.</p>
      </part>
      <part id="SSIG-4_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
      </part>
    </control>
    <control id="SSIG-5">
      <title>Shared Signal Personal Information Minimization</title>
      <prop name="label" class="index" value="4.8 E"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-5_smt" name="statement">
        <p>Shared signals SHALL NOT include personal information except what is necessary to identify the subscriber account in question (e.g., an account identifier or attributes that can be correlated by the receiving party).</p>
      </part>
      <part id="SSIG-5_obj" name="objective">
        <p>Determine whether shared signals limit personal information to only what is necessary to identify the subscriber account.</p>
        <link href="#SSIG-5_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the shared signal documentation (per PETA-6) to identify any personal information included. Verify that each personal information element is necessary for subscriber account identification by the receiving party. Flag any personal information that serves purposes beyond account identification.</p>
      </part>
      <part id="SSIG-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by capturing sample shared signals and verifying that the actual content matches the documented content and contains no personal information beyond what is required for identification.</p>
      </part>
      <part id="SSIG-5_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
        <p>This control applies data minimization principles to shared signaling. The permitted personal information is limited to what enables the receiving party to match the signal to the correct subscriber account - typically an opaque identifier or correlation handle already known to both parties.</p>
      </part>
    </control>
    <control id="SSIG-6">
      <title>IdP-to-RP Signaling: Pre-Established Trust Agreement Required</title>
      <prop name="label" class="index" value="4.8 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-6_smt" name="statement">
        <p>Signaling from the IdP to the RP SHALL require a pre-established trust agreement.</p>
      </part>
      <part id="SSIG-6_obj" name="objective">
        <p>Determine whether IdP-to-RP shared signaling occurs only under a pre-established trust agreement.</p>
        <link href="#SSIG-6_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP shared signaling configuration to verify that outbound signals to RPs are sent only to RPs whose pre-established trust agreement artifact(s) explicitly authorize shared signaling (see PETA-6). Verify that no IdP-to-RP signaling is configured for RPs operating under subscriber-driven trust agreements or for RPs whose trust agreement artifact(s) do not include shared signaling terms.</p>
      </part>
      <part id="SSIG-6_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
        <p>In a subscriber-driven trust agreement, the IdP has no pre-existing relationship with the RP and therefore no established channel for signaling. Per Sec. 4.8, signaling from the RP to the IdP MAY be used in both pre-established and subscriber-driven trust agreements; only IdP-to-RP signaling requires a pre-established trust agreement.</p>
      </part>
    </control>
    <control id="SSIG-7">
      <title>IdP Compromise Signal Review</title>
      <prop name="label" class="index" value="4.8 G"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-7_smt" name="statement">
        <p>If the IdP receives a signal that a subscriber account is suspected of compromise, the IdP SHALL review actions taken by that account at the IdP for suspicious activity.</p>
      </part>
      <part id="SSIG-7_obj" name="objective">
        <p>Determine whether the IdP reviews subscriber account activity upon receiving a compromise signal.</p>
        <link href="#SSIG-7_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP incident response procedures for documented processes triggered by receipt of a subscriber account compromise signal, including the scope of activity review (e.g., authentication events, attribute changes, federation transactions).</p>
      </part>
      <part id="SSIG-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by simulating a compromise signal for a test subscriber account and verifying that the IdP initiates a review of that account's activity.</p>
      </part>
      <part id="SSIG-7_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
        <p>Related: SSIG-8 (4.8 H) requires the IdP to signal additional RPs if suspicious activity is confirmed.</p>
      </part>
    </control>
    <control id="SSIG-8">
      <title>IdP Compromise Notification to Affected RPs</title>
      <prop name="label" class="index" value="4.8 H"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-8_smt" name="statement">
        <p>If suspicious activity is confirmed at the IdP, the IdP SHALL signal any additional RPs that the subscriber account was used for during the suspected time frame.</p>
      </part>
      <part id="SSIG-8_obj" name="objective">
        <p>Determine whether the IdP signals all RPs that the compromised subscriber account was used for during the suspected time frame when suspicious activity is confirmed.</p>
        <link href="#SSIG-8_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's incident response procedures to identify a documented process for signaling RPs when suspicious activity is confirmed on a subscriber account. Determine whether the IdP retains federation transaction records sufficient to identify which RPs the subscriber account interacted with during the suspected time frame.  If yes, verify the process signals the RPs identified from those federation transaction records for the suspected time frame. If no, verify the process signals all RPs with which the IdP has a pre-established trust agreement authorizing shared signaling that could have been impacted for the relevant subscriber population or transaction context.</p>
      </part>
      <part id="SSIG-8_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
        <p>The IdP is not required to retain records of which RPs a subscriber account interacted with. However, the obligation to signal affected RPs remains. If the IdP cannot scope the notification to RPs the account actually used during the suspected time frame, the IdP must signal all RPs that could have been impacted. In practice, this means all RPs with pre-established trust agreement artifact(s) that authorize shared signaling (see SSIG-6, PETA-6).</p>
        <p>Prerequisite: SSIG-7 (IdP review upon receiving compromise signal).</p>
      </part>
    </control>
    <control id="SSIG-9">
      <title>Security and Privacy Reviews of Additional Signals</title>
      <prop name="label" class="index" value="4.8 I"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-9_smt" name="statement">
        <p>Additional signals from both the IdP and RP SHALL be subject to a security review, included in the privacy risk assessment, and addressed in the trust agreement.</p>
      </part>
      <part id="SSIG-9_obj" name="objective">
        <p>Determine whether signals beyond those recommended in Sec. 4.8 have undergone a security review, been included in the privacy risk assessment, and are addressed in the trust agreement artifact(s).</p>
        <link href="#SSIG-9_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine all shared signals implemented by the assessed party. Identify any signals not in the following recommended sets:</p>
        <p>(1) IdP-to-RP recommended signals: account terminated/suspended/disabled; account suspected of being compromised; attributes changed (including non-federated identifiers such as email address or certificate common name); possible range of IAL, AAL, or FAL for the account has changed; authenticators have been updated.  (2) RP-to-IdP recommended signals: account terminated/suspended/disabled; suspected of being compromised; bound authenticator added; bound authenticator removed.</p>
        <p>For each additional signal identified, verify that it has been subject to a security review, included in the privacy risk assessment, and addressed in the applicable trust agreement artifact(s), including the event that triggers the signal, the information included in the signal, any additional parameters, and the expected processing by the receiving party.</p>
      </part>
      <part id="SSIG-9_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used.</p>
      </part>
    </control>
    <control id="SSIG-10">
      <title>Linked Account Signal Handling Documentation</title>
      <prop name="label" class="index" value="4.8 J"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-10_smt" name="statement">
        <p>If the RP allows for account linking to multiple IdPs, the RP SHALL document their practices regarding signals for linked accounts.</p>
      </part>
      <part id="SSIG-10_obj" name="objective">
        <p>Determine whether the RP documents its practices for handling shared signals that affect RP subscriber accounts linked to multiple IdPs.</p>
        <link href="#SSIG-10_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP policy documentation for practices governing how signals received from one IdP are applied to an RP subscriber account that is also linked to one or more other IdPs (e.g., whether a compromise signal from one IdP triggers suspension of the entire RP subscriber account or only the affected federated identifier).</p>
      </part>
      <part id="SSIG-10_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used and the RP allows account linking to multiple IdPs.</p>
        <p>This control addresses the ambiguity that arises when a signal pertains to one IdP's subscriber account, but the RP subscriber account is also accessible via other IdPs. Without documented practices, signal handling for linked accounts is ad hoc and potentially inconsistent. Related: SSIG-11 constrains these practices by requiring that shared signals not reveal the identity of a subscriber's linked IdPs</p>
      </part>
    </control>
    <control id="SSIG-11">
      <title>Linked IdP Identity Protection in Shared Signals</title>
      <prop name="label" class="index" value="4.8 K"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="SSIG-11_smt" name="statement">
        <p>The RP SHALL ensure that the shared signals do not reveal the identity of a subscriber's linked IdPs.</p>
      </part>
      <part id="SSIG-11_obj" name="objective">
        <p>Determine whether the RP's shared signals are constructed so as not to reveal the identity of any other IdPs linked to the subscriber's RP subscriber account.</p>
        <link href="#SSIG-11_smt" rel="assessment-for"/>
      </part>
      <part id="SSIG-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP shared signal message content and structure to verify that no signal includes or implies the identity of other IdPs linked to the subscriber's RP subscriber account (e.g., IdP identifiers, IdP-specific federated identifiers, or attributes uniquely associated with a particular IdP).</p>
      </part>
      <part id="SSIG-11_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating one or more shared signals for a test RP subscriber account linked to multiple IdPs and verifying that the outbound signal content does not directly or indirectly reveal the identity of any other linked IdP.</p>
      </part>
      <part id="SSIG-11_gdn" name="guidance">
        <p>Assessment is required when: Shared signaling is used and the RP allows account linking to multiple IdPs.</p>
        <p>Companion to SSIG-10, which requires the RP to document its signal-handling practices for linked accounts. This control constrains what those signals may contain. Revealing linked IdP identities could enable profiling of a subscriber's identity provider relationships, undermining federation privacy goals.</p>
      </part>
    </control>
    <control id="ARTC-1">
      <title>Assertions represent Discrete Authentication Events</title>
      <prop name="label" class="index" value="4.9 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-1_smt" name="statement">
        <p>Assertions SHALL represent a discrete authentication event of the subscriber at the IdP.</p>
      </part>
      <part id="ARTC-1_obj" name="objective">
        <p>Determine whether each assertion issued by the IdP represents a single, discrete authentication event of the subscriber.</p>
        <link href="#ARTC-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP assertion issuance process to verify that each assertion is generated in response to a specific authentication event and does not represent a standing authorization, batch of events, or ongoing session state.</p>
      </part>
      <part id="ARTC-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sample assertions to verify that each contains a unique authentication time corresponding to a single event.</p>
      </part>
      <part id="ARTC-1_gdn" name="guidance">
        <p>SAI-1 (4.5 A) is a prerequisite: the subscriber must have an authenticated session before assertion issuance. ARTC-3 (4.9 C) reinforces this requirement by requiring an authentication time timestamp in every assertion.</p>
      </part>
    </control>
    <control id="ARTC-2">
      <title>RP Assertion Processing as Discrete Event</title>
      <prop name="label" class="index" value="4.9 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-2_smt" name="statement">
        <p>Assertions...SHALL be processed as a discrete authentication event at the RP.</p>
      </part>
      <part id="ARTC-2_obj" name="objective">
        <p>Determine whether the RP processes each assertion as a discrete authentication event.</p>
        <link href="#ARTC-2_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP assertion processing procedures to verify that each received assertion is treated as a discrete event rather than being merged with, appended to, or treated as a continuation of a prior assertion.</p>
      </part>
      <part id="ARTC-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP session management practices to verify that a new assertion does not automatically extend or refresh an existing authenticated session established by a prior assertion.</p>
      </part>
    </control>
    <control id="ARTC-3">
      <title>Assertion Attribute Requirements</title>
      <prop name="label" class="index" value="4.9 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-3_smt" name="statement">
        <p>All assertions SHALL include the following attributes:</p>
        <p>(1) Issuer identifier: An identifier for the issuer of the assertion (i.e., the IdP).</p>
        <p>(2) Audience identifier: An identifier for the party intended to consume the assertion (i.e., the RP). An assertion can contain more than one audience identifier at FAL1.</p>
        <p>(3) Issuance time: A timestamp that indicates when the IdP issued the assertion.</p>
        <p>(4) Validity time window: A period of time outside of which the assertion SHALL NOT be accepted as valid by the RP for the purposes of authenticating the subscriber and starting an authenticated session at the RP. This is usually communicated by means of an expiration timestamp for the assertion in addition to the issuance timestamp.</p>
        <p>(5) Assertion identifier: A value that uniquely identifies this assertion and is used to prevent attackers from replaying prior assertions.</p>
        <p>(6) Authentication time: A timestamp that indicates when the IdP last verified the presence of the subscriber at the IdP through a primary authentication event.</p>
        <p>(7) Signature: Digital signature or MAC, including verification key identifier, that covers the entire assertion.</p>
      </part>
      <part id="ARTC-3_obj" name="objective">
        <p>Determine whether assertions generated contain at least this list of required fields with appropriate values and that the assertion's contents are covered by the signature.</p>
        <link href="#ARTC-3_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating a test assertion for a test RP. Examine the assertion for all required fields and verify their contents.</p>
      </part>
      <part id="ARTC-3_gdn" name="guidance">
        <p>This criterion presents all of the elements required in every assertion. Each element provides a different and vital piece of information for the secure conveyance of the identity information. Assertions can contain additional information, whether about the subscriber or about the authentication event itself, but these fields are all required at all FALs.</p>
      </part>
    </control>
    <control id="ARTC-4">
      <title>Subscriber Identification in Non-Ephemeral Assertions</title>
      <prop name="label" class="index" value="4.9 D"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-4_smt" name="statement">
        <p>If the RP subscriber account does not use an ephemeral provisioning process, the subscriber SHALL be identified in the assertion using a federated identifier (see Sec. 3.4) or through an account resolution process (see Sec. 3.8.2).</p>
      </part>
      <part id="ARTC-4_obj" name="objective">
        <p>Determine whether the subscriber is identified in the assertion using a federated identifier or through attributes sufficient for account resolution, when the RP subscriber account does not use ephemeral provisioning.</p>
        <link href="#ARTC-4_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sample assertions to determine which subscriber identification information they include for IdPs. If a federated identifier is used, satisfied by ARTC-5 (subject identifier) and FEDID-1. If account resolution is used, examine the trust agreement artifact(s) for the agreed-upon attributes used for resolution, then examine a sample of assertions to confirm that those attributes are present.</p>
        <p>For RPs, if a federated identifier is used, satisfied by FEDID-2. If account resolution is used, satisfied by ACCR-1.</p>
      </part>
      <part id="ARTC-4_gdn" name="guidance">
        <p>Assessment is required when: The RP subscriber account does not use an ephemeral provisioning process.</p>
      </part>
    </control>
    <control id="ARTC-5">
      <title>Subject Identifier in Assertion</title>
      <prop name="label" class="index" value="4.9 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-5_smt" name="statement">
        <p>If the subscriber is identified using a federated identifier, the assertion SHALL include: Subject Identifier: An identifier for the party to which the assertion applies (i.e., the subscriber).</p>
      </part>
      <part id="ARTC-5_obj" name="objective">
        <p>Determine whether the assertion includes a subject identifier when the subscriber is identified using a federated identifier.</p>
        <link href="#ARTC-5_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion generation configuration to verify that a subject identifier is included in assertions when federated identifiers are the subscriber identification method.</p>
      </part>
      <part id="ARTC-5_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is identified using a federated identifier.</p>
        <p>The subject identifier is separated from the unconditional assertion requirements in ARTC-3 because subscriber-controlled wallets acting as IdPs may not include a subject identifier in their assertions. For example, mobile driver's licenses may identify the subscriber through the driver's license number and issuer rather than a subject identifier. This control ensures a subject identifier is present when federated identifiers are the identification method.</p>
      </part>
    </control>
    <control id="ARTC-6">
      <title>xAL Information in Assertion or Trust Agreement</title>
      <prop name="label" class="index" value="4.9 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-6_smt" name="statement">
        <p>The following aspects of the federation transaction SHALL be provided through information contained in the assertion contents or the applicable trust agreement:</p>
        <p>(1) The IAL as well as the type of verification used during the identity proofing process (e.g., biometric, address verification), an indication of the identity proofing processes used to establish the subscriber account, or an indication that no IAL is asserted.</p>
        <p>(2) The AAL used when the subscriber authenticated to the IdP or an indication that no AAL is asserted.</p>
        <p>(3) The IdP's intended FAL of the federation process represented by the assertion.</p>
      </part>
      <part id="ARTC-6_obj" name="objective">
        <p>Determine whether all required xAL information is conveyed through the assertion contents or trust agreement artifact(s).</p>
        <link href="#ARTC-6_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sample assertions where IAL and AAL are asserted. For IAL, verify that the verification method used during identity proofing (e.g., biometric, home address verification, cell phone verification) is provided. Also verify that the proofing process(es) used to establish the subscriber account are indicated. Where multiple proofing pathways are possible at a given IAL, the information provided must be sufficient for the RP to determine which process was used. The conveyance of the IAL is satisfied by RXAL-3.</p>
        <p>For AAL, satisfied by RXAL-4.</p>
        <p>For FAL, satisfied by RXAL-5</p>
      </part>
      <part id="ARTC-6_gdn" name="guidance">
        <p>The IAL alone tells the RP the level of identity proofing, but not how it was achieved. SP 800-63A-4 defines multiple proofing pathways at each IAL, each with a different risk profile. Without the verification type and proofing pathway, the RP cannot make fine-grained, risk-informed access decisions; it can only make a binary accept/reject decision based on the IAL number. This control ensures the IdP provides that granularity.</p>
      </part>
    </control>
    <control id="ARTC-7">
      <title>Cryptographic Nonce</title>
      <prop name="label" class="index" value="4.9 G"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="ARTC-7_smt" name="statement">
        <p>At FAL2 and above, the assertion SHALL include:</p>
        <ol>
          <li>
            <p>Nonce: A cryptographic nonce from the RP's federation request.</p>
          </li>
        </ol>
      </part>
      <part id="ARTC-7_obj" name="objective">
        <p>Determine whether FAL2 and FAL3 assertions include a cryptographic nonce from the RP's federation request.</p>
        <link href="#ARTC-7_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the sample assertions to verify that each contains a cryptographic nonce. Verify that the nonce in the assertion corresponds to the nonce provided in the RP's federation request (see ARTRQ-1).</p>
      </part>
      <part id="ARTC-7_gdn" name="guidance">
        <p>The nonce is a mechanism by which FAL2 achieves its defining security property: assertion injection protection (see FAL2-1). It cryptographically binds the RP's specific federation request to the resulting assertion, preventing an attacker from injecting a captured or manufactured assertion into a different transaction. The requirement operates as a three-part chain: the RP sends a nonce in its request (ARTRQ-1, Sec. 4.10 A), the IdP echoes it in the assertion (this control), and the RP validates its presence (ARTC-10 item 5).</p>
        <p>In the errata publication, this control will be changed to: At FAL2 and above, the assertion SHALL include the cryptographic nonce from the RP's federation request.</p>
      </part>
    </control>
    <control id="ARTC-8">
      <title>FAL3 Assertion Mechanism</title>
      <prop name="label" class="index" value="4.9 H"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="ARTC-8_smt" name="statement">
        <p>At FAL3, the assertion SHALL include one of the following:</p>
        <p>(1) The public key, key identifier, or other identifier for a holder-of-key assertion; or</p>
        <p>(2) An indicator that the verification of a bound authenticator is required to process this assertion</p>
      </part>
      <part id="ARTC-8_obj" name="objective">
        <p>Determine whether FAL3 assertions meet holder-of-key or bound authenticator requirements.</p>
        <link href="#ARTC-8_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-8_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Holder-of-key assertions: Satisfied by HKA-1.</p>
        <p>Bound authenticators: Satisfied by BAUTH-1.</p>
      </part>
      <part id="ARTC-8_gdn" name="guidance">
        <p>FAL3 achieves its defining security property, subscriber authentication at the RP as well as at the IdP, through one of two mechanisms: holder-of-key assertions or bound authenticators. The assertion must signal which mechanism is in use so the RP knows which verification path to execute.</p>
      </part>
    </control>
    <control id="ARTC-9">
      <title>Prohibition of Authentication Secrets in Assertions</title>
      <prop name="label" class="index" value="4.9 I"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-9_smt" name="statement">
        <p>Assertions SHALL NOT contain subscriber authentication secrets (e.g., passwords).</p>
      </part>
      <part id="ARTC-9_obj" name="objective">
        <p>Determine whether the IdP's assertions exclude subscriber authentication secrets.</p>
        <link href="#ARTC-9_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sample assertions to verify that no subscriber authentication secrets are present, including but not limited to passwords, shared secrets, or other authenticator values. Verify that the IdP's assertion generation process has no mechanism or configuration that would embed authentication secrets in assertion payloads.</p>
      </part>
      <part id="ARTC-9_gdn" name="guidance">
        <p>Assertions are an identity conveyance mechanism, not an authentication credential. Including authentication secrets in an assertion would expose them to the RP and any intermediary that processes the assertion, creating a direct credential compromise vector. HKA-5 (Sec. 3.15) addresses the narrower case of prohibiting unencrypted private or symmetric keys in holder-of-key assertions. This control covers the general case across all assertion types and all categories of authentication secrets.</p>
      </part>
    </control>
    <control id="ARTC-10">
      <title>RP Assertion Validation Checklist</title>
      <prop name="label" class="index" value="4.9 J"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-10_smt" name="statement">
        <p>The RP SHALL validate the assertion by checking that all of the following are true:</p>
        <p>(1) Signature validation: Ensure that the signature of the assertion is valid and corresponds to a verification key that belongs to the IdP sending the assertion.</p>
        <p>(2) Issuer verification: Ensure that the assertion was issued by the expected IdP.</p>
        <p>(3) Time validation: Ensure that the validity time window is within acceptable limits of the current timestamp.</p>
        <p>(4) Audience restriction: Ensure that this RP is the intended recipient of the assertion.</p>
        <p>(5) Nonce: Ensure that the cryptographic nonce included in the RP's request (if applicable) is included in the presentation.</p>
        <p>(6) Transaction terms: Ensure that the IAL, AAL, and FAL represented by the assertion are allowable under the applicable trust agreement and are suitable for the RP's needs.</p>
        <p>(7) Assertion identifier: Ensure that the assertion has not been replayed within its validity time window at this RP.</p>
      </part>
      <part id="ARTC-10_obj" name="objective">
        <p>Determine whether the RP validates all required elements of an assertion before accepting it.</p>
        <link href="#ARTC-10_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-10_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Verify that the RP's assertion validation process includes all of the following checks: (1) Signature validation, satisfied by FAL1-2. (2) Issuer verification, satisfied by ASRP-1 (b). (3) Time validation:  Examine the RP's assertion processing logic to confirm it compares the assertion's issuance time and expiration against the current timestamp and rejects assertions outside the validity window. (4) Audience restriction, satisfied by AUDR-2.</p>
        <p>(5) Nonce validation (required at FAL2 &amp; FAL3): Test by doing the following: (a) Generate a test federation transaction at FAL2 or above and capture the nonce sent in the RP's federation request. (b) Verify the RP accepts an assertion containing the matching nonce. (c) Present an otherwise valid assertion containing a different nonce value - verify rejection. (d) Present an otherwise valid assertion with the nonce omitted - verify rejection. (6) Transaction terms: Examine the xAL terms established in the trust agreement artifact(s) (see TRUST-7) and ensure that the RP is configured to only accept those xALs. Suitability terms are satisfied by RXAL-8. (7) Assertion identifier: satisfied by FAL1-5.</p>
      </part>
      <part id="ARTC-10_gdn" name="guidance">
        <p>This control consolidates the RP's assertion validation obligations into a single checklist. Items 1, 2, 4, 6b, and 7 defer to dedicated controls; the unique assessment work here is time validation (item 3), nonce validation (item 5), and trust agreement xAL conformance (item 6a).</p>
      </part>
    </control>
    <control id="ARTC-11">
      <title>Subject ID Uniqueness</title>
      <prop name="label" class="index" value="4.9 K"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-11_smt" name="statement">
        <p>An RP that uses the federated identifier to identify the subscriber SHALL NOT treat subject identifiers as inherently globally unique across IdPs.</p>
      </part>
      <part id="ARTC-11_obj" name="objective">
        <p>Determine whether an RP treats the same subject identifier from different IdPs as different accounts.</p>
        <link href="#ARTC-11_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's code, configuration, and documentation to verify that subject identifiers are always interpreted in the context of the IdP that asserted them.</p>
      </part>
      <part id="ARTC-11_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by configuring two test IdPs to assert the same subject identifier. Submit an assertion from each IdP to the RP. Verify that the RP creates two distinct subscriber accounts and does not associate them.</p>
      </part>
      <part id="ARTC-11_gdn" name="guidance">
        <p>Assessment is required when: The RP uses the federated identifier to identify the subscriber.</p>
        <p>Even if an IdP uses a collision-resistant namespace such as a UUID for its subscriber identifiers, the tying of a specific identifier to a particular subscriber is still under the control of the IdP making the assertion. An RP's internal processing of an assertion needs to take this into account by processing the combination of the subject identifier along with the IdP that issued the assertion. If the RP does not account for the source IdP when determining the identity of the subscriber, a rogue or compromised IdP could impersonate subscribers from another IdP at a susceptible RP by mimicking the valid IdP's subject identifiers.</p>
      </part>
    </control>
    <control id="ARTC-12">
      <title>RP Session Time Independent of Assertion</title>
      <prop name="label" class="index" value="4.9 L"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTC-12_smt" name="statement">
        <p>Assertion validity time windows SHALL NOT be used to limit the session at the RP. See Sec. 4.7 for more information.</p>
      </part>
      <part id="ARTC-12_obj" name="objective">
        <p>Determine whether the RP manages its session lifetime independently of the assertion validity time window.</p>
        <link href="#ARTC-12_smt" rel="assessment-for"/>
      </part>
      <part id="ARTC-12_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's session management configuration to confirm the session timeout is set by RP policy, and is not the same as the assertion's expiration timestamp.</p>
      </part>
      <part id="ARTC-12_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by authenticating via federation and establishing an RP session. Confirm that the RP session remains valid after the assertion's validity window has expired.</p>
      </part>
      <part id="ARTC-12_gdn" name="guidance">
        <p>The assertion validity window exists solely for the RP to process the assertion and create a local session; it is not a session duration directive from the IdP. Section 4.7 establishes that assertion validity, IdP session lifetime, and RP session lifetime are three independent time periods. An RP that terminates sessions when the assertion expires would force unnecessary reauthentication and effectively let the IdP dictate RP session policy. RP session management requirements are governed by SP 800-63B Section 5 (Session Management).</p>
      </part>
    </control>
    <control id="ARTRQ-1">
      <title>Assertion Request Requirements</title>
      <prop name="label" class="index" value="4.10 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTRQ-1_smt" name="statement">
        <p>When the federation transaction is initiated by the RP, the RP's request for an assertion SHALL contain:</p>
        <p>(1) An identifier for the RP.</p>
        <p>(2) A cryptographic nonce to be returned in the assertion.</p>
      </part>
      <part id="ARTRQ-1_obj" name="objective">
        <p>Determine if the RP includes the required identifier and cryptographic nonce in requests for an assertion.</p>
        <link href="#ARTRQ-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARTRQ-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's federation configuration to confirm that it sends its identifier and a cryptographic nonce in all assertion requests.</p>
      </part>
      <part id="ARTRQ-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a request for an assertion.  Examine the request and verify that the request contains a unique identifier for the RP and a cryptographic nonce.</p>
      </part>
      <part id="ARTRQ-1_gdn" name="guidance">
        <p>The cryptographic nonce binds the assertion to the specific request, preventing replay and injection attacks. The RP's request should also contain the set of requested attributes and their purpose, and the authentication event requirements.</p>
      </part>
    </control>
    <control id="BCP-1">
      <title>Tamper &amp; Fabrication Resistant Assertion References</title>
      <prop name="label" class="index" value="4.11.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-1_smt" name="statement">
        <p>The assertion reference itself contains no information about the subscriber and SHALL be resistant to tampering and fabrication by an attacker.</p>
      </part>
      <part id="BCP-1_obj" name="objective">
        <p>Determine whether the IdP generates and manages assertion references such that they are resistant to tampering and fabrication by an attacker.</p>
        <link href="#BCP-1_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion reference design and generation process to verify that the assertion reference contains no subscriber information. Verify the reference is generated and managed in a way that resists tampering and fabrication by an attacker (e.g., cryptographic randomness with sufficient entropy, or cryptographic integrity protection).</p>
      </part>
      <part id="BCP-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by obtaining a valid assertion reference, modifying it, and presenting the modified value to the IdP. Verify rejection. Present a fabricated reference not issued by the IdP. Verify rejection.</p>
      </part>
      <part id="BCP-1_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>Assertion references are used to limit the information that is exposed to different parties within the federation transaction, such as the user's browser. As a consequence, it is counterproductive to put any information about the subscriber in the assertion reference itself. Additionally, since the RP will trade the assertion reference for the actual assertion, the assertion reference needs to be something that an attacker can neither guess nor manipulate in order to alter the assertion received. It is recommended that assertion references be cryptographically random values.</p>
      </part>
    </control>
    <control id="BCP-2">
      <title>RP-Specific Assertion Reference</title>
      <prop name="label" class="index" value="4.11.1 #1"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-2_smt" name="statement">
        <p>The assertion reference:</p>
        <ol>
          <li>
            <p>SHALL be limited to use by a single RP.</p>
          </li>
        </ol>
      </part>
      <part id="BCP-2_obj" name="objective">
        <p>Determine whether the IdP enforces a binding between each issued assertion reference and exactly one designated Relying Party, ensuring that the reference can only be used by a single RP.</p>
        <link href="#BCP-2_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by BCP-10.</p>
      </part>
      <part id="BCP-2_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>Since assertion references are traded for assertions, the IdP needs to ensure that the assertion reference is presented only by the specific RP to which it was issued. Otherwise, an attacker could capture an assertion reference and inject it into a different RP to fake a log in. This requirement applies even if the RPs are logistically related, such as being configured to receive a common identifier. If assertion references are not used, this requirement does not apply.</p>
      </part>
    </control>
    <control id="BCP-3">
      <title>Single-use Assertion Reference</title>
      <prop name="label" class="index" value="4.11.1 #2"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-3_smt" name="statement">
        <p>The assertion reference:</p>
        <ol>
          <li>
            <p>SHALL be single-use.</p>
          </li>
        </ol>
      </part>
      <part id="BCP-3_obj" name="objective">
        <p>Determine whether assertion references can be successfully used only once.</p>
        <link href="#BCP-3_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion reference lifecycle configuration to confirm that the IdP maintains a state record for each issued reference. Verify that references are invalidated (e.g., flagged or deleted) upon first successful redemption.</p>
      </part>
      <part id="BCP-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by obtaining a valid assertion reference and redeeming it once through the IdP's assertion-resolution endpoint. Attempt a second redemption of the same reference; verify that the IdP rejects the request (e.g., returns an error such as "invalid_reference," "expired," or "already_used").</p>
      </part>
      <part id="BCP-3_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>The IdP is responsible for ensuring that once an assertion reference has been redeemed (i.e., used by the designated Relying Party to obtain the assertion), it cannot be used again. This control prevents replay attacks and the unauthorized reuse of valid assertion references by an attacker or another RP session.</p>
      </part>
    </control>
    <control id="BCP-4">
      <title>Assertion Reference Time Limitation</title>
      <prop name="label" class="index" value="4.11.1 #3"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-4_smt" name="statement">
        <p>The assertion reference:</p>
        <ol>
          <li>
            <p>SHALL be time-limited.</p>
          </li>
        </ol>
      </part>
      <part id="BCP-4_obj" name="objective">
        <p>Determine whether assertion references are time-limited.</p>
        <link href="#BCP-4_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's federation protocol configuration (e.g., authorization code lifetime in OIDC, artifact validity window in SAML) to identify the configured assertion reference lifetime.</p>
      </part>
      <part id="BCP-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by completing a back-channel federation transaction up to the point where the test RP receives the assertion reference, but do not immediately redeem it. Wait beyond the configured lifetime, then have the test RP present the reference to the IdP. Confirm that the IdP rejects the expired reference.</p>
      </part>
      <part id="BCP-4_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>The assertion reference is a temporary artifact whose sole purpose is to allow the RP to retrieve the full assertion from the IdP. A short lifetime limits the window for interception, replay, or misuse. The guidelines recommend (SHOULD) a validity window of no more than five minutes.</p>
      </part>
    </control>
    <control id="BCP-5">
      <title>RP Authentication at Assertion Reference Redemption</title>
      <prop name="label" class="index" value="4.11.1 #4"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-5_smt" name="statement">
        <p>The assertion reference:</p>
        <ol>
          <li>
            <p>SHALL be presented along with authentication of the RP to the IdP.</p>
          </li>
        </ol>
      </part>
      <part id="BCP-5_obj" name="objective">
        <p>Determine whether the RP authenticates itself to the IdP when presenting the assertion reference.</p>
        <link href="#BCP-5_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-5_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's federation configuration to confirm that the RP authenticates to the IdP when redeeming assertion references.</p>
      </part>
      <part id="BCP-5_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>RP authentication at the point of assertion reference redemption prevents an attacker who intercepts or steals an assertion reference from redeeming it at the IdP. Without RP authentication, possession of the reference alone would be sufficient to obtain the full assertion.</p>
      </part>
    </control>
    <control id="BCP-6">
      <title>Assertion Reference Security</title>
      <prop name="label" class="index" value="4.11.1 #5"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-6_smt" name="statement">
        <p>The assertion reference:</p>
        <ol>
          <li>
            <p>SHALL NOT be predictable or guessable by an attacker.</p>
          </li>
        </ol>
      </part>
      <part id="BCP-6_obj" name="objective">
        <p>Determine whether assertion references are generated in a manner that prevents prediction or guessing by an attacker.</p>
        <link href="#BCP-6_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-6_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP documentation describing the assertion reference generation mechanism to confirm it uses an approved random bit generator or equivalent method that produces values with at least 112 bits of security strength per SP 800-131A.</p>
      </part>
      <part id="BCP-6_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>This control complements BCP-1, which requires tamper and fabrication resistance. BCP-1 addresses integrity protection of assertion references; this control addresses the unpredictability of their values. Together they ensure an attacker can neither guess a valid reference nor modify an intercepted one.</p>
      </part>
    </control>
    <control id="BCP-7">
      <title>Subscriber Back-Channel Protection</title>
      <prop name="label" class="index" value="4.11.1 B"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-7_smt" name="statement">
        <p>Conveyance of the assertion reference from the IdP to the subscriber and from the subscriber to the RP SHALL be made over an authenticated protected channel.</p>
      </part>
      <part id="BCP-7_obj" name="objective">
        <p>Determine whether the delivery of the assertion reference occurs over authenticated protected channels, across all connections.</p>
        <link href="#BCP-7_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-7_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the endpoint configuration to confirm that assertion reference exchange occurs only over authenticated protected channels. (e.g., HTTPS/TLS).</p>
      </part>
      <part id="BCP-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to convey the assertion reference from the IdP to the subscriber and from the subscriber to the RP over an unprotected channel (e.g., plain HTTP) and verify that each attempt fails, is rejected, or the connection is refused. A protocol-specific error is not required if the endpoints refuse unprotected connections entirely.</p>
      </part>
      <part id="BCP-7_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>In this model, the assertion reference is passed through the front channel using the subscriber's browser. This process consists of two separate network connections over which information flows, from the subscriber to the IdP and the subscriber to the RP. Both legs of this connection have to be protected from attackers by using authenticated protected channels, such as HTTPS over TLS connections.</p>
      </part>
    </control>
    <control id="BCP-8">
      <title>RP-IdP Back-Channel Protection</title>
      <prop name="label" class="index" value="4.11.1 C"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-8_smt" name="statement">
        <p>Conveyance of the assertion reference from the RP to the IdP and vice versa SHALL be made over an authenticated protected channel.</p>
      </part>
      <part id="BCP-8_obj" name="objective">
        <p>Determine whether the connection between the RP and IdP takes place over an authenticated protected channel.</p>
        <link href="#BCP-8_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-8_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the relevant federation configuration to verify that assertion references are conveyed between the RP and IdP only over authenticated protected channels.</p>
      </part>
      <part id="BCP-8_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by attempting to convey the assertion reference between the RP and IdP over an unprotected channel (e.g., plain HTTP) and verify that the attempt fails, is rejected, or the connection is refused.</p>
      </part>
      <part id="BCP-8_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>In this model, the assertion reference is traded for the assertion by the RP making a direct call to the IdP. This call, which carries both the assertion reference and the assertion itself, needs to be protected from attackers by using an authenticated protected channel, such as HTTPS over TLS connections.</p>
      </part>
    </control>
    <control id="BCP-9">
      <title>Assertion Reference Injection Prevention</title>
      <prop name="label" class="index" value="4.11.1 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-9_smt" name="statement">
        <p>The RP SHALL protect itself against the injection of manufactured or captured assertion references by using cross-site scripting (XSS) and cross-site request forgery (CSRF) protection, rejecting assertion references outside of the correct stage of a federation transaction, or other accepted techniques discussed in Sec. 3.11.1.</p>
      </part>
      <part id="BCP-9_obj" name="objective">
        <p>Determine whether the RP employs best practices for its platform to protect against injection of assertion references.</p>
        <link href="#BCP-9_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-9_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's federation implementation to verify that it protects against assertion reference injection through XSS and CSRF protections, rejection of assertion references outside the correct stage of the federation transaction, and other RP-side countermeasures such as request correlation, nonce use, and transaction state tracking.</p>
      </part>
      <part id="BCP-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction in one RP session, capturing the resulting assertion reference, and submitting that assertion reference in a different RP session that has a different session identifier and unrelated transaction state. Verify that the RP rejects the assertion reference and does not complete the federation transaction.</p>
      </part>
      <part id="BCP-9_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>The assertion reference needs to be delivered to the RP in some fashion, and for many protocols this happens through a front-channel redirect through the subscriber's browser. The RP needs to ensure that any assertion references presented to it are legitimate by protecting itself against common injection attacks. The techniques for protection vary depending on the type of RP application and its deployment model, but there are many resources and documented best practices for different applications and platforms. For example, ensuring that the assertion reference is returned in the same browser session that was used to request the assertion reference in the front channel. Without these protections, an attacker could convince an RP to trade an injected (but otherwise valid) assertion reference and therefore get a fraudulent assertion and give the attacker access to the RP.</p>
      </part>
    </control>
    <control id="BCP-10">
      <title>RP-Assertion Reference Binding</title>
      <prop name="label" class="index" value="4.11.1 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="BCP-10_smt" name="statement">
        <p>When assertion references are presented to the IdP, the IdP SHALL verify that the RP presenting the assertion reference is the same RP that made the assertion request that resulted in the assertion reference.</p>
      </part>
      <part id="BCP-10_obj" name="objective">
        <p>Determine whether an assertion reference is bound to a single RP identified by the IdP.</p>
        <link href="#BCP-10_smt" rel="assessment-for"/>
      </part>
      <part id="BCP-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine IdP documentation to ensure the IdP verifies the RP presenting the assertion reference using client credentials, PKCE, or alternative mechanism providing equivalent protections.</p>
      </part>
      <part id="BCP-10_gdn" name="guidance">
        <p>Assessment is required when: A back-channel presentation is used.</p>
        <p>Before issuing an assertion to the RP in exchange for the assertion reference, the IdP needs to ensure that the RP making the exchange request is the same RP that the assertion reference was intended for. Otherwise, an attacker could substitute an assertion reference for one RP in order to get an assertion for a different RP, or trick the subscriber into authorizing one RP only to authorize the attacker's RP. The IdP can do this by associating a specific RP with the assertion reference when the reference is created.</p>
      </part>
    </control>
    <control id="FCP-1">
      <title>Front-Channel Assertion Replay Protection</title>
      <prop name="label" class="index" value="4.11.2 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FCP-1_smt" name="statement">
        <p>The RP SHALL use the assertion identifier to ensure that a given assertion is presented at most once during the assertion's validity time window.</p>
      </part>
      <part id="FCP-1_obj" name="objective">
        <p>Determine whether the RP uses the assertion identifier to prevent replay within the assertion's validity time window.</p>
        <link href="#FCP-1_smt" rel="assessment-for"/>
      </part>
      <part id="FCP-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by FAL1-5.</p>
      </part>
      <part id="FCP-1_gdn" name="guidance">
        <p>Assessment is required when: Front-channel presentation is used.</p>
        <p>Front-channel presentation passes the full assertion through the subscriber's browser (user agent), increasing the risk of capture and replay. This requirement mandates that the RP track assertion identifiers to ensure each assertion is accepted at most once within its validity window.</p>
      </part>
    </control>
    <control id="FCP-2">
      <title>RP Front-Channel Injection Protection</title>
      <prop name="label" class="index" value="4.11.2 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FCP-2_smt" name="statement">
        <p>The RP SHALL protect itself against the injection of manufactured or captured assertions by using XSS and CSRF protection, rejecting assertions outside of the correct stage of a federation transaction, or other accepted techniques discussed in Sec. 3.11.1.</p>
      </part>
      <part id="FCP-2_obj" name="objective">
        <p>Determine whether the RP employs best practices for its platform to protect against the injection of assertions.</p>
        <link href="#FCP-2_smt" rel="assessment-for"/>
      </part>
      <part id="FCP-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's federation implementation for XSS and CSRF protections, session-binding of federation transactions, and other injection countermeasures appropriate to the platform</p>
      </part>
      <part id="FCP-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by capturing an assertion for the RP and injecting it into an unrelated active session at the RP. Ensure that the RP does not accept the injected assertion.</p>
      </part>
      <part id="FCP-2_gdn" name="guidance">
        <p>Assessment is required when: Front-channel presentation is used.</p>
        <p>The assertion needs to be delivered to the RP in some fashion, and for many protocols, this happens through a front-channel redirect through the subscriber's browser. The RP needs to ensure that any assertions presented to it are legitimate by protecting itself against common injection attacks. The techniques for protection vary by RP application and deployment model, but there are many resources and documented best practices for different applications and platforms. Without these protections, an attacker could convince an RP to accept an injected (but otherwise valid) assertion and gain access to the subscriber's account at an RP.</p>
      </part>
    </control>
    <control id="FCP-3">
      <title>Subscriber Front-Channel Protection</title>
      <prop name="label" class="index" value="4.11.2 C"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FCP-3_smt" name="statement">
        <p>Conveyance of the assertion from the IdP to the subscriber and from the subscriber to the RP SHALL be made over an authenticated protected channel.</p>
      </part>
      <part id="FCP-3_obj" name="objective">
        <p>Determine whether the connections between the subscriber and the RP as well as the subscriber and IdP take place over an authenticated protected channel.</p>
        <link href="#FCP-3_smt" rel="assessment-for"/>
      </part>
      <part id="FCP-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the assessed party's front-channel federation endpoints to confirm they require authenticated protected channels (e.g., HTTPS/TLS) and that connections over non-protected channels are refused.</p>
      </part>
      <part id="FCP-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a front-channel federation transaction targeting the assessed party's endpoints. Verify the connection uses an authenticated protected channel. Attempt to connect to the assessed party's front-channel endpoints over a non-protected channel (e.g., plain HTTP) and verify the request is rejected, or the connection is refused.</p>
      </part>
      <part id="FCP-3_gdn" name="guidance">
        <p>Assessment is required when: Front-channel presentation is used.</p>
      </part>
    </control>
    <control id="FCP-4">
      <title>Front-Channel Personal Information Protection</title>
      <prop name="label" class="index" value="4.11.2 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="FCP-4_smt" name="statement">
        <p>As a consequence, an IdP that uses HTTP redirects for the front-channel presentation of assertions SHALL encrypt all personal information in the assertion, as discussed in Sec. 3.13.3.</p>
      </part>
      <part id="FCP-4_obj" name="objective">
        <p>Determine whether any personal information in assertions that is passed through the front channel is encrypted.</p>
        <link href="#FCP-4_smt" rel="assessment-for"/>
      </part>
      <part id="FCP-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the IdP's assertion generation configuration to confirm that assertions delivered via front-channel presentation encrypt all personal information. For encryption mechanism requirements, see ENCA-1.</p>
      </part>
      <part id="FCP-4_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by generating a test assertion containing personal information via a front-channel presentation mechanism. Examine the assertion payload as transmitted through the front channel and verify that all personal information is encrypted.</p>
      </part>
      <part id="FCP-4_gdn" name="guidance">
        <p>Assessment is required when: Front-channel presentation is used.</p>
        <p>Front-channel presentation passes the assertion through the subscriber's browser, exposing it to intermediaries. Encryption ensures that even if the assertion is intercepted, personal information remains protected. ENCA-1 assesses the encryption mechanism; this control verifies that encryption is applied when front-channel delivery is used.</p>
      </part>
    </control>
    <control id="IABSCW-1">
      <title>Wallet Attribute Bundle Issuance Process</title>
      <prop name="label" class="index" value="5.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IABSCW-1_smt" name="statement">
        <p>When the CSP issues attribute bundles to the subscriber-controlled wallet, the process SHALL include the following steps:</p>
        <p>(1) The subscriber proves their identity to the CSP's issuance functionality using the CSP's identity proofing process or by authenticating to the subscriber account.</p>
        <p>(2) The subscriber activates the wallet using an activation factor, which might entail authenticating to a hosted wallet service.</p>
        <p>(3) The wallet generates or chooses a signing key and corresponding verification key. The wallet proves possession of its signing key to the CSP.</p>
        <p>(4) The CSP creates one or more attribute bundles that include subscriber attributes and the wallet's verification key (or a reference to that key).</p>
        <p>(5) The wallet stores the attribute bundle for later presentation to RPs.</p>
      </part>
      <part id="IABSCW-1_obj" name="objective">
        <p>Determine whether the CSP's issuance process requires the subscriber to prove their identity and prove possession of a wallet-generated key before an attribute bundle is issued.</p>
        <link href="#IABSCW-1_smt" rel="assessment-for"/>
      </part>
      <part id="IABSCW-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the following: (1) The CSP's issuance process to confirm it requires subscriber identity verification (via identity proofing or authentication) before bundle creation. Identity proofing requirements are assessed under SP 800-63A; authentication requirements are assessed under SP 800-63B. (2) The CSP's documentation to confirm that the CSP has evaluated that the target wallet platform enforces activation factor requirements before permitting signing key operations. Wallet activation requirements are assessed separately under Section 5.4 controls. (3) The CSP's issuance protocol to confirm it requires and validates proof of possession of the wallet's signing key before creating the attribute bundle. (4) The CSP's bundle creation process to confirm the resulting attribute bundle includes subscriber attributes and the wallet's verification key or a reference to it. Attribute bundle content requirements are assessed under the ABUN series (Section 3.12.1). (5) The CSP's delivery mechanism to confirm the bundle is transmitted to the requesting wallet.</p>
      </part>
      <part id="IABSCW-1_gdn" name="guidance">
        <p>This is a process-level control covering the end-to-end issuance process from the CSP's perspective.</p>
        <p>SP 800-63C-4 uses the terms "signing key" and "verification key" throughout Section 5 rather than the "private key" and "public key" terminology used in other NIST cryptographic standards. The signing key is the wallet's private key used to sign assertions; the verification key is the corresponding public key.</p>
        <p>The CSP cannot observe wallet activation at runtime but can control which wallet platforms it issues to. Before issuing attribute bundles to a given wallet platform, the CSP should verify that the platform enforces activation requirements. This may involve reviewing wallet platform documentation, security certifications, or independent security evaluations.</p>
      </part>
    </control>
    <control id="IABSCW-2">
      <title>Attribute Bundle Uniqueness</title>
      <prop name="label" class="index" value="5.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IABSCW-2_smt" name="statement">
        <p>The CSP SHALL create a unique attribute bundle for each requesting wallet.</p>
      </part>
      <part id="IABSCW-2_obj" name="objective">
        <p>Determine whether the CSP creates a unique attribute bundle for each requesting wallet.</p>
        <link href="#IABSCW-2_smt" rel="assessment-for"/>
      </part>
      <part id="IABSCW-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's attribute bundle issuance process to verify that each bundle is uniquely bound to the requesting wallet (e.g., by including the wallet's verification key per IABSCW-1 #4).</p>
      </part>
      <part id="IABSCW-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting attribute bundles from the CSP using two different wallets for the same subscriber. Compare the bundles and verify they are distinct.</p>
      </part>
    </control>
    <control id="IABSCW-3">
      <title>Multi-CSP Attribute Bundle Assertion Conformance</title>
      <prop name="label" class="index" value="5.1 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="IABSCW-3_smt" name="statement">
        <p>The simultaneous presentation of attribute bundles from multiple CSPs in a single assertion is possible with some technologies. When this occurs, the assertion of multiple attribute bundles SHALL conform to the assertion requirements in this guideline.</p>
      </part>
      <part id="IABSCW-3_obj" name="objective">
        <p>Determine whether assertions containing attribute bundles from multiple CSPs conform to assertion requirements.</p>
        <link href="#IABSCW-3_smt" rel="assessment-for"/>
      </part>
      <part id="IABSCW-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>When an assertion contains attribute bundles from multiple CSPs, satisfied by the IdP-directed requirements in ARTCN-1 to ARTCN-6 and ARTCN-12 (Sec. 5.8).</p>
      </part>
      <part id="IABSCW-3_gdn" name="guidance">
        <p>Assessment is required when: The wallet presents attribute bundles from multiple CSPs in a single assertion.</p>
        <p>If a wallet allows combining attribute bundles from different CSPs into a single assertion (e.g., a driver's license from one CSP and professional credentials from another), each bundle must be individually validated per the assertion requirements, regardless of how many are combined.</p>
      </part>
    </control>
    <control id="INVABSCW-1">
      <title>Attribute Bundle Invalidation Capability</title>
      <prop name="label" class="index" value="5.1.1 A"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="INVABSCW-1_smt" name="statement">
        <p>The CSP SHALL provide a means of invalidating attribute bundles that are issued to a subscriber-controlled wallet.</p>
      </part>
      <part id="INVABSCW-1_obj" name="objective">
        <p>Determine whether the CSP provides a means of invalidating attribute bundles issued to subscriber-controlled wallets.</p>
        <link href="#INVABSCW-1_smt" rel="assessment-for"/>
      </part>
      <part id="INVABSCW-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine CSP documentation for a defined invalidation process covering at minimum the three scenarios identified in Sec. 5.1.1: subscriber account termination, wallet termination due to loss/theft/compromise, and attribute bundle compromise or disclosure to an attacker.</p>
      </part>
      <part id="INVABSCW-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by issuing an attribute bundle to a test wallet. Next, invoke the CSP's invalidation process for that bundle. Verify that the CSP's systems reflect the bundle as invalidated (e.g., marked as invalid in the CSP's status registry or list, removed from active bundle records, or otherwise flagged as invalid).</p>
      </part>
      <part id="INVABSCW-1_gdn" name="guidance">
        <p>Attribute bundle invalidation is used when: -The subscriber account is terminated, thereby rendering downstream federation actions invalid; -The wallet needs to be terminated due to the device being lost, stolen, or compromised; or -The attribute bundle is disclosed to an attacker or otherwise compromised.</p>
      </part>
    </control>
    <control id="INVABSCW-2">
      <title>Attribute Bundle Status Verification Privacy</title>
      <prop name="label" class="index" value="5.1.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="INVABSCW-2_smt" name="statement">
        <p>The CSP SHOULD provide a means to independently verify the status of attribute bundles (i.e., whether a specific bundle has been revoked by the CSP). If such a service is offered, the service SHALL be deployed in a privacy-preserving way such that the CSP is not alerted to the use of a specific attribute bundle at a specific RP.</p>
      </part>
      <part id="INVABSCW-2_obj" name="objective">
        <p>Determine whether the CSP's attribute bundle status verification service is deployed in a privacy-preserving manner that does not alert the CSP to the use of a specific attribute bundle at a specific RP.</p>
        <link href="#INVABSCW-2_smt" rel="assessment-for"/>
      </part>
      <part id="INVABSCW-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the architecture and design documentation for the status verification service. Verify that the service design does not enable the CSP to correlate a specific attribute bundle with a specific RP. Identify the privacy-preserving mechanism in use (e.g., status lists, batch download of revocation data).</p>
      </part>
      <part id="INVABSCW-2_gdn" name="guidance">
        <p>Assessment is required when: The CSP offers an attribute bundle status verification service.</p>
        <p>Status verification mechanisms where the RP queries the CSP directly with a specific bundle identifier (e.g., standard OCSP) would fail this requirement because the CSP can correlate the querying RP's network identity with the specific bundle being checked, revealing which RP the subscriber visited. Privacy-preserving alternatives include mechanisms where the RP downloads a complete status dataset and checks bundle status locally, preventing the CSP from learning which specific bundle was checked. One example is the W3C Bitstring Status List.</p>
      </part>
    </control>
    <control id="TAGREE-1">
      <title>Wallet Runtime Attribute Release</title>
      <prop name="label" class="index" value="5.3 #1"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TAGREE-1_smt" name="statement">
        <ol>
          <li>
            <p>The release of subscriber attributes SHALL be managed using a runtime decision managed by the wallet, as described in Sec. 4.6.1.3.</p>
          </li>
        </ol>
      </part>
      <part id="TAGREE-1_obj" name="objective">
        <p>Determine whether the wallet manages attribute release using runtime decisions as described in Sec. 4.6.1.3.</p>
        <link href="#TAGREE-1_smt" rel="assessment-for"/>
      </part>
      <part id="TAGREE-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by  IDPRD-1 through IDPRD-8, treating the wallet as the IdP. These controls apply unconditionally in the wallet context, regardless of whether the RP is on an allowlist.</p>
      </part>
      <part id="TAGREE-1_gdn" name="guidance">
        <p>Due to the architectures and design of subscriber-controlled wallets, the trust agreements that support federated transactions are less direct than with general-purpose IdPs. To maintain privacy outcomes and prevent the tracking of user transactions, CSPs and RPs do not typically have direct communication with each other.</p>
        <p>Unlike the general IdP case (Sec. 4.6.1.3), where allowlisting an RP can bypass the runtime decision, wallet attribute release always requires a runtime decision regardless of whether an allowlist is used. An allowlist in the wallet context may constrain which RPs can request attributes, but the subscriber still approves release at transaction time. TAGREE-2 establishes that the authorized party for this decision is the subscriber.</p>
      </part>
    </control>
    <control id="TAGREE-2">
      <title>Wallet Authorized Party</title>
      <prop name="label" class="index" value="5.3 #2"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TAGREE-2_smt" name="statement">
        <ol>
          <li>
            <p>The authorized party SHALL be the subscriber.</p>
          </li>
        </ol>
      </part>
      <part id="TAGREE-2_obj" name="objective">
        <p>Determine whether the wallet designates the subscriber as the authorized party for attribute release decisions.</p>
        <link href="#TAGREE-2_smt" rel="assessment-for"/>
      </part>
      <part id="TAGREE-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the wallet documentation to verify that the subscriber is the party making the attribute release decisions.</p>
      </part>
      <part id="TAGREE-2_gdn" name="guidance">
        <p>In the general IdP case, the trust agreement identifies the authorized party, which may be the subscriber, an administrator, or another surrogate. For subscriber-controlled wallets, the authorized party is always the subscriber.</p>
      </part>
    </control>
    <control id="TAGREE-3">
      <title>Wallet Runtime Decision Disclosure Terms</title>
      <prop name="label" class="index" value="5.3 #3"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="TAGREE-3_smt" name="statement">
        <ol>
          <li>
            <p>The following terms SHALL be disclosed to the subscriber during the runtime decision:</p>
          </li>
        </ol>
        <p>(a) The set of subscriber attributes, derived attributes, and attribute bundles that the RP will request (a subset of the attributes made available).</p>
        <p>(b) The purpose of each attribute requested by the RP.</p>
      </part>
      <part id="TAGREE-3_obj" name="objective">
        <p>Determine whether the wallet discloses the required terms to the subscriber during the runtime decision.</p>
        <link href="#TAGREE-3_smt" rel="assessment-for"/>
      </part>
      <part id="TAGREE-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the runtime decision screen(s) to verify that it is designed to display the required disclosure terms.</p>
      </part>
      <part id="TAGREE-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a transaction that triggers a runtime decision. Verify that the following information is disclosed to the subscriber: (1) the attributes the RP will request (see also IDPRD-3), and (2) the purpose of the requested attributes</p>
      </part>
      <part id="TAGREE-3_gdn" name="guidance">
        <p>All information disclosed to the subscriber needs to be conveyed in a manner that is understandable and actionable, as discussed in Sec. 8.</p>
      </part>
    </control>
    <control id="CR-1">
      <title>Federation Authority Wallet Ecosystem Trust Agreement Contents</title>
      <prop name="label" class="index" value="5.3.1 A"/>
      <prop name="marking" class="target" value="Federation Authority"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CR-1_smt" name="statement">
        <p>Such trust agreements SHALL contain:</p>
        <p>(a) The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles.</p>
        <p>(b) The set of subscriber attributes and derived attributes that the wallet can make available to the RP.</p>
        <p>(c) The population of subscriber accounts that the CSP can represent.</p>
        <p>(d) The IALs or issuance processes of subscriber accounts that are associated with the attribute bundles from the CSP.</p>
        <p>(e) The issuance process related to CSP attribute bundles.</p>
        <p>(f) The FALs supported by subscriber-controlled wallets.</p>
        <p>(g) The allowable purposes for each attribute RPs may request.</p>
        <p>(h) Expectations of RPs for the protection and management of subscriber data provided through attribute bundles.</p>
      </part>
      <part id="CR-1_obj" name="objective">
        <p>Determine whether the federation authority's trust agreement artifacts for a subscriber-controlled wallet ecosystem contains the required terms.</p>
        <link href="#CR-1_smt" rel="assessment-for"/>
      </part>
      <part id="CR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the federation authority trust agreement artifact(s) to verify all required terms are present.</p>
      </part>
      <part id="CR-1_gdn" name="guidance">
        <p>Assessment is required when: The trust relationship between the RP and CSP is facilitated by a federation authority.</p>
        <p>In subscriber-controlled wallet ecosystems, the CSP and RP typically do not communicate directly. A federation authority can bridge this gap by defining ecosystem-wide trust agreement artifact(s) that govern the relationships among RPs, CSPs, and wallets.</p>
      </part>
    </control>
    <control id="CR-2">
      <title>CSP Publication of Wallet Ecosystem Information</title>
      <prop name="label" class="index" value="5.3.1 B"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CR-2_smt" name="statement">
        <p>CSPs SHALL publish the following information to a trusted location for RPs to evaluate:</p>
        <p>(a) The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles.</p>
        <p>(b) The set of subscriber attributes and derived attributes that the wallet can make available to the RP.</p>
        <p>(c) The population of subscriber accounts that the CSP can represent.</p>
        <p>(d) The IALs or issuance processes of subscriber accounts associated with the attribute bundles from the CSP.</p>
      </part>
      <part id="CR-2_obj" name="objective">
        <p>Determine whether the CSP publishes the required information to a location accessible to RPs for evaluation.</p>
        <link href="#CR-2_smt" rel="assessment-for"/>
      </part>
      <part id="CR-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP-published information at the identified location to verify all required information is present. The assessor should verify the location is accessible to RPs and that the information is current.</p>
      </part>
      <part id="CR-2_gdn" name="guidance">
        <p>Assessment is required when: Trust is established unilaterally by RP evaluation of publicly available CSP information (i.e., no federation authority facilitates the trust relationship).</p>
        <p>The CSP defines the boundaries of attribute disclosure through its trust agreement artifact(s) with the wallet (see Sec. 5.3.2). The bundle may contain more attributes than any single RP is authorized to receive; selective disclosure technology allows the wallet to reveal different subsets to different RPs without reissuance. "The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles" reflects the full set issued by the CSP, while "The set of subscriber attributes and derived attributes that the wallet can make available to the RP" reflects the subset the wallet is authorized to disclose. This information may also be published through a federation authority's discovery service (see Sec. 5.3.1).</p>
      </part>
    </control>
    <control id="CSCW-1">
      <title>CSP-Wallet Trust Agreement</title>
      <prop name="label" class="index" value="5.3.2 A"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CSCW-1_smt" name="statement">
        <p>There SHALL be a trust agreement between the CSP and the subscriber-controlled wallets into which they issue attribute bundles.</p>
      </part>
      <part id="CSCW-1_obj" name="objective">
        <p>Determine whether a trust agreement exists between the CSP and the subscriber-controlled wallets to which it issues attribute bundles.</p>
        <link href="#CSCW-1_smt" rel="assessment-for"/>
      </part>
      <part id="CSCW-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>For CSPs: Examine documentation to identify trust agreement artifact(s) governing the relationship with subscriber-controlled wallets. Verify the agreement exists prior to issuance of attribute bundles.</p>
      </part>
      <part id="CSCW-1_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>For wallets (IdPs): Examine documentation to identify trust agreement artifact(s) governing the relationship with the CSP(s) from which it receives attribute bundles.</p>
      </part>
      <part id="CSCW-1_gdn" name="guidance">
        <p>CSCW-2 specifies the minimum required contents of this trust agreement.</p>
      </part>
    </control>
    <control id="CSCW-2">
      <title>CSP-Wallet Trust Agreement Requirements</title>
      <prop name="label" class="index" value="5.3.2 B"/>
      <prop name="marking" class="target" value="CSP/IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="CSCW-2_smt" name="statement">
        <p>At a minimum, this trust agreement SHALL include the following:</p>
        <p>(1) The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles.</p>
        <p>(2) The set of subscriber attributes and derived attributes that the wallet can make available to the RP.</p>
        <p>(3) Any processes the subscriber-controlled wallet needs to implement to support the issuance of attribute bundles (e.g., PAD, data collection, risk scoring).</p>
        <p>(4) Data storage and security practices for the wallet service.</p>
        <p>(5) The activation factors or AALs that subscribers use to access the wallet service prior to the generation of any assertion.</p>
        <p>(6) The FALs supported by subscriber-controlled wallets.</p>
        <p>(7) The allowable purposes or any restrictions that the wallets need to enforce related to the release of attributes to RP.</p>
      </part>
      <part id="CSCW-2_obj" name="objective">
        <p>Determine whether the trust agreement between the CSP and subscriber-controlled wallets contains the minimum required terms.</p>
        <link href="#CSCW-2_smt" rel="assessment-for"/>
      </part>
      <part id="CSCW-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>For CSPs: Examine CSP-published information to verify that terms (1), (3), and (7) are present.</p>
      </part>
      <part id="CSCW-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>For wallets (IdPs): Examine wallet-published information to verify terms (2), (4), (5), and (6) are present.</p>
      </part>
      <part id="CSCW-2_gdn" name="guidance">
        <p>The trust agreement may be composed of information published independently by each party. The CSP publishes what it issues and the constraints it imposes on wallets. The wallet publishes its own capabilities and security practices. Together these constitute the trust agreement.</p>
      </part>
    </control>
    <control id="RSCW-1">
      <title>Wallet Disclosure to RPs</title>
      <prop name="label" class="index" value="5.3.3 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RSCW-1_smt" name="statement">
        <p>Subscriber-controlled wallets SHALL disclose to RPs:</p>
        <p>(1) Activation or authentication methods they use to authenticate subscribers prior to presentation of an assertion.</p>
        <p>(2) Security features of how the wallet protects the attribute bundles.</p>
        <p>(3) Key management information.</p>
        <p>(4) Indications of the integrity of the subscriber-controlled wallet's software.</p>
      </part>
      <part id="RSCW-1_obj" name="objective">
        <p>Determine whether the wallet discloses all required information to RPs.</p>
        <link href="#RSCW-1_smt" rel="assessment-for"/>
      </part>
      <part id="RSCW-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine wallet-published documentation, metadata, or runtime disclosures to verify all four required items are disclosed to RPs. Items (1) and (2) may already be documented under CSCW-2 terms (5) and (4) respectively. Verify that the same information is made available to RPs, not only to the CSP. Items (3) and (4) are unique to this control.</p>
      </part>
      <part id="RSCW-1_gdn" name="guidance">
        <p>The RP needs this information to make trust decisions about the wallet presenting attribute bundles. Software integrity indications can be provided through platform-specific attestation mechanisms.</p>
      </part>
    </control>
    <control id="FAL3SCW-1">
      <title>FAL3 Hosted Wallet: HoK or Bound Authenticator</title>
      <prop name="label" class="index" value="5.3.4 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="FAL3SCW-1_smt" name="statement">
        <p>To reach FAL3, federation transactions with a subscriber-controlled wallet on a hosted service SHALL use either a holder-of-key assertion (see Sec. 3.15) or a bound authenticator (see Sec. 3.16).</p>
      </part>
      <part id="FAL3SCW-1_obj" name="objective">
        <p>Determine whether federation transactions with a hosted subscriber-controlled wallet at FAL3 use either a holder-of-key assertion or a bound authenticator.</p>
        <link href="#FAL3SCW-1_smt" rel="assessment-for"/>
      </part>
      <part id="FAL3SCW-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>For holder-of-key assertions, satisfied by HKA-1 through HKA-5.</p>
        <p>For assertions that use bound authenticators, satisfied by BAUTH-1 through BAUTH-8.</p>
      </part>
      <part id="FAL3SCW-1_gdn" name="guidance">
        <p>Assessment is required when: A subscriber-controlled wallet on a hosted service is used at FAL3.</p>
        <p>Device-based subscriber-controlled wallets inherently hold signing keys that can satisfy HoK requirements. Hosted wallets do not, because the subscriber does not directly control the key material. This control requires hosted wallets to bridge that gap through either an additional HoK authenticator separate from the wallet's signing key, or a bound authenticator at the RP.</p>
        <p>FAL3SCW-2 requires all other FAL3 requirements (Sec. 2.4) to also be met.</p>
      </part>
    </control>
    <control id="FAL3SCW-2">
      <title>Wallet FAL3 Compliance</title>
      <prop name="label" class="index" value="5.3.4 B"/>
      <prop name="marking" class="target" value="CSP/IdP/RP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="FAL3SCW-2_smt" name="statement">
        <p>All requirements for FAL3 in Sec. 2.4 SHALL be met.</p>
      </part>
      <part id="FAL3SCW-2_obj" name="objective">
        <p>Determine whether federation transactions involving a subscriber-controlled wallet meet all FAL3 requirements specified in Sec. 2.4.</p>
        <link href="#FAL3SCW-2_smt" rel="assessment-for"/>
      </part>
      <part id="FAL3SCW-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by FAL3-1 through FAL3-5.</p>
      </part>
    </control>
    <control id="WACT-1">
      <title>Wallet Activation for Signing Operations</title>
      <prop name="label" class="index" value="5.4 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WACT-1_smt" name="statement">
        <p>The subscriber-controlled wallet SHALL require the presentation of an activation factor from the subscriber for the following actions that result in the creation of a signed artifact from the wallet's signing keys: providing proof of possession of the wallet's signing key to the CSP during the issuance process; and signing the assertion for presentation to the RP.</p>
      </part>
      <part id="WACT-1_obj" name="objective">
        <p>Determine whether the subscriber-controlled wallet requires presentation of an activation factor from the subscriber before performing signing operations with the wallet's signing keys.</p>
        <link href="#WACT-1_smt" rel="assessment-for"/>
      </part>
      <part id="WACT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the wallet platform's security architecture documentation to confirm that signing-key operations are gated behind the presentation of an activation factor. Confirm that the architecture does not allow access to the signing key without activation.</p>
      </part>
      <part id="WACT-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by doing the following: (1) During an attribute bundle issuance flow with a CSP, observe that the wallet prompts the subscriber for an activation factor before completing proof-of-possession of the signing key. (2) During a federation transaction with an RP, observe that the wallet prompts the subscriber for an activation factor before signing the assertion for presentation. (3) For each operation above, dismiss or cancel the activation prompt and confirm that the signing operation does not proceed.</p>
      </part>
      <part id="WACT-1_gdn" name="guidance">
        <p>The activation factor ensures the subscriber is present and consenting before any signing operation occurs. If the activation factor is a secret (e.g., PIN or password), it must meet the activation secret requirements in SP 800-63B Sec. 3.2.10. If the activation factor is biometric, it must meet the requirements in SP 800-63B Sec. 3.2.3. WACT-2 addresses the requirement that wallet activation be separate from device unlock for device-based wallets.</p>
      </part>
    </control>
    <control id="WACT-2">
      <title>Wallet Activation Separation from Device Unlock</title>
      <prop name="label" class="index" value="5.4 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WACT-2_smt" name="statement">
        <p>For subscriber-controlled wallets that run on a device that the subscriber controls, the submission of the activation factor SHALL be a separate operation from the unlocking of the host device (e.g., smartphone), although the same activation factor used to unlock the host device MAY be used in the activation operation. Organizations MAY relax this requirement for subscriber-controlled wallets managed by or on behalf of the CSP (e.g., via mobile device management) and that are constrained to have short, organization-determined inactivity timeouts and device activation factors that meet the above requirements.</p>
      </part>
      <part id="WACT-2_obj" name="objective">
        <p>Determine whether the subscriber-controlled wallet requires a separate activation operation from host device unlock, or whether the organization qualifies for the MDM relaxation.</p>
        <link href="#WACT-2_smt" rel="assessment-for"/>
      </part>
      <part id="WACT-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the wallet's security architecture documentation to confirm that wallet activation is implemented as an operation distinct from host device unlock.</p>
      </part>
      <part id="WACT-2_asm-examine-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine documentation to verify that: (1) The wallet is managed by or on behalf of the CSP (e.g., via MDM); (2) The device is constrained to short, organization-determined inactivity timeouts; and (3) The device activation factors meet the requirements in Sec. 3.2.10 of SP 800-63B-4, if the organization claims the MDM relaxation.</p>
        <p>If all three conditions are met, device-level controls satisfy the separation requirement. If any condition is not met, the relaxation does not apply, and the base requirement must be assessed.</p>
      </part>
      <part id="WACT-2_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by unlocking the host device (e.g., smartphone) using the device unlock mechanism if the MDM relaxation is not claimed or applicable.</p>
      </part>
      <part id="WACT-2_asm-test-2" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by Immediately initiate a wallet signing operation (issuance or assertion presentation per WACT-1) if the MDM relaxation is not claimed or applicable.</p>
      </part>
      <part id="WACT-2_asm-test-3" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by confirming the wallet requires a separate activation prompt before proceeding - device unlock alone does not satisfy the wallet activation requirement if the MDM relaxation is not claimed or applicable.</p>
      </part>
      <part id="WACT-2_gdn" name="guidance">
        <p>Assessment is required when: The subscriber-controlled wallet runs on a device controlled by the subscriber (i.e., not a hosted wallet).</p>
        <p>The requirement permits the same activation factor (e.g., the same fingerprint or PIN) to be used for both device unlock and wallet activation, provided the wallet requires its own distinct activation event. Activation factor requirements for authenticators are discussed in Sec. 3.2.10 of SP 800-63B-4.</p>
        <p>The MDM relaxation applies to enterprise or government scenarios where the CSP controls both the identity credential and the device environment. In such cases, device management policies can enforce equivalent security properties at the device level, making a separate wallet activation event redundant. This relaxation does not apply to consumer scenarios where the CSP has no management authority over the subscriber's device.</p>
      </part>
    </control>
    <control id="KS-1">
      <title>Wallet Signing Key Sync and Sharing Prohibition</title>
      <prop name="label" class="index" value="5.4.1 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="KS-1_smt" name="statement">
        <p>Keys used for signing assertions SHALL NOT be synced or shared across devices.</p>
      </part>
      <part id="KS-1_obj" name="objective">
        <p>Determine whether wallet signing keys used for assertions are prohibited from being synced or shared across devices.</p>
        <link href="#KS-1_smt" rel="assessment-for"/>
      </part>
      <part id="KS-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the wallet's key management architecture, configuration, and subscriber-facing key management features to confirm that signing keys are generated and stored per-device and that no mechanism exists to sync, replicate, or share signing keys across devices (e.g., cloud key sync, cross-device backup, or key export functionality).</p>
      </part>
      <part id="KS-1_gdn" name="guidance">
        <p>CKS-1 covers general secure key storage requirements under FIPS 140; this control adds the wallet-specific prohibition on key syncing across devices. Non-exportable key storage becomes a SHALL for wallets whose signing key is used as a holder-of-key authenticator at FAL3 (see KS-2). The definition of non-exportable key storage is established in CKS-2.</p>
      </part>
    </control>
    <control id="KS-2">
      <title>Wallet HoK Signing Key Non-Exportable Storage</title>
      <prop name="label" class="index" value="5.4.1 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="KS-2_smt" name="statement">
        <p>If the wallet's signing key is used as a holder-of-key authenticator for FAL3, the key SHALL be stored in non-exportable key storage, as discussed in Sec. 3.6.2.</p>
      </part>
      <part id="KS-2_obj" name="objective">
        <p>Determine whether the wallet's signing key, when used as a holder-of-key authenticator for FAL3, is stored in non-exportable key storage.</p>
        <link href="#KS-2_smt" rel="assessment-for"/>
      </part>
      <part id="KS-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>This is a summative control. Compliance is demonstrated when the requirements of the following controls have been met:</p>
        <p>(a) CKS-2: Non-Exportable Key Storage Definition</p>
        <p>(b) CKS-3: Non-Exportable Key Isolation</p>
        <p>(c) CKS-4: Non-Exportable Storage Immutability</p>
      </part>
      <part id="KS-2_gdn" name="guidance">
        <p>Assessment is required when: The wallet's signing key is used as a holder-of-key authenticator for FAL3.</p>
        <p>KS-1 prohibits key syncing across devices for all wallet signing keys. This control elevates the storage requirement to non-exportable for the specific case of HoK at FAL3.</p>
      </part>
    </control>
    <control id="DISCR-1">
      <title>CSP Verification Key Determination</title>
      <prop name="label" class="index" value="5.5 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="DISCR-1_smt" name="statement">
        <p>To perform a federation transaction with a subscriber-controlled wallet, the RP SHALL first determine the attribute bundle verification key of the CSP through a secure process as stated by the trust agreement.</p>
      </part>
      <part id="DISCR-1_obj" name="objective">
        <p>Determine whether the RP obtains the CSP's attribute bundle verification key through a secure process defined in the trust agreement artifact(s) prior to performing federation transactions with a subscriber-controlled wallet.</p>
        <link href="#DISCR-1_smt" rel="assessment-for"/>
      </part>
      <part id="DISCR-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to identify the process specified for the RP to obtain the CSP's attribute bundle verification key (e.g., retrieval from a URL controlled by the CSP, manual configuration, or retrieval through a federation authority). Review the RP's configuration to confirm that the CSP's verification key was obtained through the specified process. Confirm that the process used to obtain the key provides authentication of the source (e.g., authenticated protected channel, manual out-of-band verification, or federation authority trust chain).</p>
      </part>
      <part id="DISCR-1_gdn" name="guidance">
        <p>This control is the wallet-specific counterpart to DR-1, which covers the RP's association of assertion validation keys with the IdP's identifier. In the wallet model, the trust anchor is the CSP's signature on the attribute bundle rather than the IdP's assertion signature. Sec. 5.5 describes several mechanisms: retrieval from a URL known to be controlled by the CSP, manual configuration before deployment, or facilitation by a third-party discovery and registration service (such as a federation authority) in multi-lateral trust agreement artifact(s). ARTVL-1 covers the RP's validation of the attribute bundle signature and depends on this control being satisfied. For network-based key retrieval, DR-2 requirements for authenticated protected channels also apply.</p>
      </part>
    </control>
    <control id="WAAD-1">
      <title>Wallet Subscriber Transaction Authorization</title>
      <prop name="label" class="index" value="5.6 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WAAD-1_smt" name="statement">
        <p>The decision of whether a federation transaction proceeds and, therefore, an assertion is issued and attributes are released to the RP SHALL be determined by the subscriber acting in the role of the authorized party.</p>
      </part>
      <part id="WAAD-1_obj" name="objective">
        <p>Determine whether the subscriber-controlled wallet ensures that the subscriber, acting as the authorized party, controls the decision of whether a federation transaction proceeds and attributes are released to the RP.</p>
        <link href="#WAAD-1_smt" rel="assessment-for"/>
      </part>
      <part id="WAAD-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by TAGREE-1 and TAGREE-2.</p>
      </part>
    </control>
    <control id="WAAD-2">
      <title>Wallet Remembered Decision Disclosure</title>
      <prop name="label" class="index" value="5.6 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WAAD-2_smt" name="statement">
        <p>If [the subscriber-controlled wallet provides a mechanism to remember a disclosure decision by the authorized party (i.e., the subscriber) to apply to future requests from the same RP], the subscriber-controlled wallet SHALL disclose to the authorized party that the storage mechanism is in use.</p>
      </part>
      <part id="WAAD-2_obj" name="objective">
        <p>Determine whether the subscriber-controlled wallet discloses to the subscriber that a mechanism to remember their authorization decision is in use.</p>
        <link href="#WAAD-2_smt" rel="assessment-for"/>
      </part>
      <part id="WAAD-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by IDPRD-7, applied to the wallet as the party implementing the runtime decision.</p>
      </part>
      <part id="WAAD-2_gdn" name="guidance">
        <p>Assessment is required when: The subscriber-controlled wallet provides a mechanism to remember a subscriber's disclosure decision for future requests from the same RP.</p>
      </part>
    </control>
    <control id="WAAD-3">
      <title>Wallet Remembered Decision Revocation</title>
      <prop name="label" class="index" value="5.6 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WAAD-3_smt" name="statement">
        <p>If [the subscriber-controlled wallet provides a mechanism to remember a disclosure decision by the authorized party (i.e., the subscriber) to apply to future requests from the same RP], the subscriber-controlled wallet... SHALL allow the authorized party to revoke such remembered access at a future time.</p>
      </part>
      <part id="WAAD-3_obj" name="objective">
        <p>Determine whether the subscriber-controlled wallet allows the subscriber to revoke a previously remembered authorization decision.</p>
        <link href="#WAAD-3_smt" rel="assessment-for"/>
      </part>
      <part id="WAAD-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by IDPRD-8, applied to the wallet as the party implementing the runtime decision.</p>
      </part>
      <part id="WAAD-3_gdn" name="guidance">
        <p>Assessment is required when: The subscriber-controlled wallet provides a mechanism to remember a subscriber's disclosure decision for future requests from the same RP.</p>
      </part>
    </control>
    <control id="WAAD-4">
      <title>CSP Wallet Subscriber Redress</title>
      <prop name="label" class="index" value="5.6 D"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="WAAD-4_smt" name="statement">
        <p>The CSP SHALL provide secure and effective means of redress of subscriber complaints or problems (e.g., subscriber identifies an inaccurate attribute value, the need to invalidate attribute bundles that were previously issued to a subscriber-controlled wallet).</p>
      </part>
      <part id="WAAD-4_obj" name="objective">
        <p>Determine whether the CSP provides secure and effective means of redress for subscriber complaints or problems related to attribute bundles issued to a subscriber-controlled wallet.</p>
        <link href="#WAAD-4_smt" rel="assessment-for"/>
      </part>
      <part id="WAAD-4_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>The base CSP redress mechanism is satisfied by RR-6.</p>
        <p>Examine the CSP's redress documentation and procedures for coverage of wallet-specific scenarios, including correction of inaccurate attribute values in issued bundles and invalidation of previously issued attribute bundles (e.g., due to compromise, account termination, or subscriber request).  Verify that these redress mechanisms protect the integrity of the redress process (e.g., authenticating the subscriber before modifying or invalidating bundles) and produce effective outcomes for the subscriber.</p>
      </part>
    </control>
    <control id="AREQ-1">
      <title>Wallet Assertion Request Contents</title>
      <prop name="label" class="index" value="5.7 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="AREQ-1_smt" name="statement">
        <p>When federation transactions are initiated by the RP, the RP's request for an assertion SHALL contain:</p>
        <p>(1) An identifier for the RP</p>
        <p>(2) A cryptographic nonce</p>
        <p>(3) The set of identity attributes, derived attributes, and attribute bundles requested by the RP and their purpose of use at the RP.</p>
      </part>
      <part id="AREQ-1_obj" name="objective">
        <p>Determine whether the RP's requests for assertions from subscriber-controlled wallets contain all required elements.</p>
        <link href="#AREQ-1_smt" rel="assessment-for"/>
      </part>
      <part id="AREQ-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's wallet federation configuration to confirm it includes its identifier, a cryptographic nonce, and the set of requested attributes, with the purpose of use, in all assertion requests to subscriber-controlled wallets.</p>
      </part>
      <part id="AREQ-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction between an RP and a subscriber-controlled wallet and capturing the RP's assertion request. Verify that it contains: (1) a unique identifier for the RP; (2) b. a cryptographic nonce; (3)the set of identity attributes, derived attributes, and attribute bundles requested by the RP and their purpose of use at the RP.</p>
      </part>
    </control>
    <control id="ARTCN-1">
      <title>Wallet Assertion Contents</title>
      <prop name="label" class="index" value="5.8 A"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-1_smt" name="statement">
        <p>Assertions from a subscriber-controlled wallet SHALL contain:</p>
        <p>(1) A signed attribute bundle from the CSP.</p>
        <p>(2) Audience identifier: An identifier for the party that is intended to consume the assertion (i.e., the RP).</p>
        <p>(3) Issuance time: A timestamp that indicates when the wallet issued the assertion.</p>
        <p>(4) Validity time window: A period of time outside of which the assertion SHALL NOT be accepted as valid by the RP for the purposes of authenticating the subscriber and starting an authenticated session at the RP. This is usually communicated by means of an expiration timestamp for the assertion in addition to the issuance timestamp.</p>
        <p>(5) Assertion identifier: A value that uniquely identifies this assertion and is used to prevent attackers from replaying prior assertions. For example, this can be a unique nonce generated by the wallet and included in the assertion.</p>
        <p>(6) Signature: A digital signature that uses asymmetric cryptography and covers the entire assertion.</p>
      </part>
      <part id="ARTCN-1_obj" name="objective">
        <p>Determine whether assertions from a subscriber-controlled wallet contain all required elements.</p>
        <link href="#ARTCN-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-1_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction and capture the wallet's assertion. Verify the assertion contains all required elements.</p>
      </part>
      <part id="ARTCN-1_gdn" name="guidance">
        <p>RP enforcement of the validity time window is assessed under ARTVL-3 item 3.</p>
      </part>
    </control>
    <control id="ARTCN-2">
      <title>Wallet Assertion xAL and Activation Information</title>
      <prop name="label" class="index" value="5.8 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-2_smt" name="statement">
        <p>The following aspects of the federation transaction SHALL be provided through information contained in the assertion contents or the applicable trust agreement:</p>
        <p>(1) The IAL of the subscriber account being represented in the assertion, an indication of the issuance processes, or an indication that no IAL is asserted.</p>
        <p>(2) The nature of the activation method used to activate the wallet.</p>
        <p>(3) The wallet's intended FAL of the federation process that is represented by the assertion.</p>
      </part>
      <part id="ARTCN-2_obj" name="objective">
        <p>Determine whether the required IAL, activation method, and FAL information is conveyed through the wallet assertion contents or the applicable trust agreement artifact(s).</p>
        <link href="#ARTCN-2_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-2_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sample assertions and/or trust agreement artifact(s) to confirm they convey all required information.</p>
      </part>
    </control>
    <control id="ARTCN-3">
      <title>Hosted Wallet AAL Reporting</title>
      <prop name="label" class="index" value="5.8 C"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-3_smt" name="statement">
        <p>If a subscriber-controlled wallet is hosted as a remote service, the AAL of the subscriber's current session at the hosted wallet service SHALL be provided through information contained in the assertion contents or the applicable trust agreement.</p>
      </part>
      <part id="ARTCN-3_obj" name="objective">
        <p>Determine whether the AAL of the subscriber's current session at the hosted wallet service is conveyed through the assertion contents or the applicable trust agreement artifact(s).</p>
        <link href="#ARTCN-3_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine sample assertions and/or trust agreement artifact(s) to confirm the AAL of the subscriber's session at the hosted wallet service is conveyed.</p>
      </part>
      <part id="ARTCN-3_gdn" name="guidance">
        <p>Assessment is required when: The subscriber-controlled wallet is hosted as a remote service.</p>
      </part>
    </control>
    <control id="ARTCN-4">
      <title>Wallet Assertion Nonce Inclusion</title>
      <prop name="label" class="index" value="5.8 D"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL2/FAL3"/>
      <part id="ARTCN-4_smt" name="statement">
        <p>At FAL2 and above, the assertion SHALL include:</p>
        <ol>
          <li>
            <p>Nonce: A cryptographic nonce from the RP's federation request.</p>
          </li>
        </ol>
      </part>
      <part id="ARTCN-4_obj" name="objective">
        <p>Determine whether the wallet's assertion includes the cryptographic nonce from the RP's federation request at FAL2 and above.</p>
        <link href="#ARTCN-4_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ARTC-7.</p>
      </part>
      <part id="ARTCN-4_gdn" name="guidance">
        <p>In the errata publication, this control will be changed to: At FAL2 and above, the assertion SHALL include the cryptographic nonce from the RP's federation request.</p>
      </part>
    </control>
    <control id="ARTCN-5">
      <title>Wallet FAL3 Assertion Mechanism Indicator</title>
      <prop name="label" class="index" value="5.8 E"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="FAL3"/>
      <part id="ARTCN-5_smt" name="statement">
        <p>At FAL3, the assertion SHALL include one of the following: the public key, key identifier, or other identifier for a holder-of-key assertion. This MAY be the same key that the subscriber-controlled wallet uses to sign the assertion; or, an indicator that the verification of a bound authenticator is required to process this assertion.</p>
      </part>
      <part id="ARTCN-5_obj" name="objective">
        <p>Determine whether the wallet's assertion at FAL3 includes either a holder-of-key identifier or a bound authenticator indicator.</p>
        <link href="#ARTCN-5_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-5_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction at FAL3 with a subscriber-controlled wallet. Capture the assertion and verify it contains either:</p>
        <p>(a) a public key, key identifier, or other identifier for a holder-of-key assertion, or (b) an indicator that verification of a bound authenticator is required.</p>
      </part>
      <part id="ARTCN-5_gdn" name="guidance">
        <p>ARTC-8 establishes the equivalent requirement for traditional federation (Sec. 4.9 H). In the wallet model, the wallet's own signing key may also serve as the holder-of-key authenticator, since the attribute bundle from the CSP already binds that key to the subscriber.</p>
      </part>
    </control>
    <control id="ARTCN-6">
      <title>Wallet Assertion Authentication Secret Prohibition</title>
      <prop name="label" class="index" value="5.8 F"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-6_smt" name="statement">
        <p>Assertions SHALL NOT contain subscriber authentication secrets (e.g., passwords).</p>
      </part>
      <part id="ARTCN-6_obj" name="objective">
        <p>Determine whether wallet assertions are free of subscriber authentication secrets.</p>
        <link href="#ARTCN-6_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-6_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ARTC-9.</p>
      </part>
    </control>
    <control id="ARTCN-7">
      <title>Attribute Bundle Contents</title>
      <prop name="label" class="index" value="5.8 G"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-7_smt" name="statement">
        <p>The signed attribute bundle from the CSP SHALL contain:</p>
        <p>(1) Keys: A verification key or key identifier for the key used by the subscriber controlled wallet to sign assertions.</p>
        <p>(2) Issuer identifier: An identifier for the issuer of the attribute bundle (i.e., the CSP).</p>
        <p>(3) Issuance time: A timestamp that indicates when the CSP issued the attribute bundle.</p>
        <p>(4) IAL: Indicator of the IAL of the subscriber account being represented in the attribute bundle or an indication that no IAL is asserted.</p>
        <p>(5) Signature: A digital signature that uses asymmetric cryptography and covers the entire attribute bundle.</p>
        <p>(6) Attribute values and derived attribute values: Information about the subscriber.</p>
      </part>
      <part id="ARTCN-7_obj" name="objective">
        <p>Determine whether signed attribute bundles from the CSP contain all required elements.</p>
        <link href="#ARTCN-7_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-7_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by obtaining a signed attribute bundle issued by the CSP to a subscriber-controlled wallet. Verify the bundle contains all required elements.</p>
      </part>
    </control>
    <control id="ARTCN-8">
      <title>Wallet Assertion Subscriber Identification</title>
      <prop name="label" class="index" value="5.8 H"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-8_smt" name="statement">
        <p>If the RP subscriber account does not use an ephemeral provisioning process (see Sec. 4.6.5) or an account resolution process (see Sec. 3.8.2), the subscriber SHALL be identified in the assertion using a federated identifier (see Sec. 3.4).</p>
      </part>
      <part id="ARTCN-8_obj" name="objective">
        <p>Determine whether the subscriber is identified in the wallet assertion using a federated identifier when neither ephemeral provisioning nor account resolution is used.</p>
        <link href="#ARTCN-8_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-8_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>This is a functional requirement describing when a federated identifier is used. Assessment of federated identifier handling is covered under the RP subscriber account controls in Sec. 3.8.</p>
      </part>
      <part id="ARTCN-8_gdn" name="guidance">
        <p>Assessment is required when: The RP subscriber account does not use an ephemeral provisioning process or an account resolution process.</p>
      </part>
    </control>
    <control id="ARTCN-9">
      <title>Wallet Federated Identifier Issuer</title>
      <prop name="label" class="index" value="5.8 I"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-9_smt" name="statement">
        <p>The issuer identifier SHALL be of the CSP that issued the signed attribute bundle.</p>
      </part>
      <part id="ARTCN-9_obj" name="objective">
        <p>Determine whether the RP uses the CSP's issuer identifier as the issuer component of the federated identifier.</p>
        <link href="#ARTCN-9_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-9_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting a wallet assertion where the wallet's issuer identifier in the outer assertion differs from the CSP's issuer identifier in the signed attribute bundle. Confirm that the RP constructs the federated identifier using the CSP's issuer identifier.</p>
      </part>
      <part id="ARTCN-9_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is identified in the assertion using a federated identifier.</p>
        <p>When wallets act as an IdP, the assertion has two issuers: the wallet (outer assertion) and the CSP (signed attribute bundle). The federated identifier must use the CSP as the issuer component because the CSP is the authority over the subscriber account and the subject identifier.</p>
      </part>
    </control>
    <control id="ARTCN-10">
      <title>Wallet Subject Identifier in Signed Attribute Bundle</title>
      <prop name="label" class="index" value="5.8 J"/>
      <prop name="marking" class="target" value="CSP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-10_smt" name="statement">
        <p>The subject identifier SHALL be contained in the signed attribute bundle.</p>
      </part>
      <part id="ARTCN-10_obj" name="objective">
        <p>Determine whether the CSP includes the subject identifier within the signed attribute bundle issued to the wallet.</p>
        <link href="#ARTCN-10_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-10_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the CSP's attribute bundle issuance process and configuration to confirm that the subject identifier is included as a field within the signed attribute bundle.</p>
      </part>
      <part id="ARTCN-10_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by requesting issuance of an attribute bundle from the CSP and inspect its signed contents to confirm the subject identifier is present inside the bundle (rather than in the outer wallet assertion).</p>
      </part>
      <part id="ARTCN-10_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is identified in the assertion using a federated identifier.</p>
      </part>
    </control>
    <control id="ARTCN-11">
      <title>Wallet Subject Identifier Namespace Processing</title>
      <prop name="label" class="index" value="5.8 K"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-11_smt" name="statement">
        <p>The subject identifier SHALL be... processed in the namespace of the CSP that issued the attribute bundle.</p>
      </part>
      <part id="ARTCN-11_obj" name="objective">
        <p>Determine whether the RP scopes the subject identifier to the namespace of the CSP that issued the signed attribute bundle.</p>
        <link href="#ARTCN-11_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-11_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's assertion processing logic to confirm that subject identifiers extracted from CSP-signed attribute bundles are paired with the CSP's issuer identifier when resolving to an RP subscriber account.</p>
      </part>
      <part id="ARTCN-11_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting assertions from two different CSPs containing attribute bundles with the same subject identifier value. Confirm the RP treats them as different subscribers.</p>
      </part>
      <part id="ARTCN-11_gdn" name="guidance">
        <p>Assessment is required when: The subscriber is identified in the assertion using a federated identifier.</p>
        <p>See ARTC-11 for the equivalent requirement for non-wallet federation.</p>
      </part>
    </control>
    <control id="ARTCN-12">
      <title>Attribute Bundle Validity Window Enforcement</title>
      <prop name="label" class="index" value="5.8 L"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-12_smt" name="statement">
        <p>The signed attribute bundle from the CSP SHOULD contain a validity time window, which is defined as a period of time outside of which the attribute bundle SHALL NOT be accepted as valid by the RP for the purposes of authenticating the subscriber and starting an authenticated session at the RP.</p>
      </part>
      <part id="ARTCN-12_obj" name="objective">
        <p>Determine whether the RP rejects signed attribute bundles presented outside their validity time window.</p>
        <link href="#ARTCN-12_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-12_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by presenting an assertion from a wallet that contains an attribute bundle with an expired validity time window to the RP. Confirm the RP rejects it and does not establish an authenticated session.</p>
      </part>
      <part id="ARTCN-12_gdn" name="guidance">
        <p>Assessment is required when: The signed attribute bundle contains a validity time window.</p>
      </part>
    </control>
    <control id="ARTCN-13">
      <title>Wallet Selective Disclosure</title>
      <prop name="label" class="index" value="5.8 M"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-13_smt" name="statement">
        <p>Attributes SHALL be made available to the RP using a selective disclosure method if such a method is made available by the underlying attribute bundle. In selective disclosure, a subset of attributes is revealed rather than the entire set.</p>
      </part>
      <part id="ARTCN-13_obj" name="objective">
        <p>Determine whether the wallet uses selective disclosure when presenting attributes to the RP, when the attribute bundle supports it.</p>
        <link href="#ARTCN-13_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-13_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the wallet's assertion presentation logic to confirm that when the underlying attribute bundle supports selective disclosure, the wallet uses it to present only the attributes requested by the RP rather than the full bundle contents.</p>
      </part>
      <part id="ARTCN-13_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test by initiating a federation transaction where the RP requests a subset of the attributes available in the attribute bundle. Confirm the wallet presents only the requested subset.</p>
      </part>
      <part id="ARTCN-13_gdn" name="guidance">
        <p>Assessment is required when: The underlying attribute bundle supports selective disclosure.</p>
        <p>This requirement ensures that the wallet does not over-disclose attributes to the RP.</p>
      </part>
    </control>
    <control id="ARTCN-14">
      <title>Unsigned Attributes as Self-Asserted</title>
      <prop name="label" class="index" value="5.8 N"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTCN-14_smt" name="statement">
        <p>Identity attributes that are in the assertion but outside of a signed attribute bundle SHALL be considered self-asserted.</p>
      </part>
      <part id="ARTCN-14_obj" name="objective">
        <p>Determine whether the RP treats identity attributes present in the assertion but outside of a signed attribute bundle as self-asserted.</p>
        <link href="#ARTCN-14_smt" rel="assessment-for"/>
      </part>
      <part id="ARTCN-14_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP's assertion processing logic or documentation to confirm that attributes outside a signed attribute bundle are classified as self-asserted and not treated as CSP-verified for access or trust decisions.</p>
      </part>
      <part id="ARTCN-14_gdn" name="guidance">
        <p>The RP may validate these additional attributes using its own validation process.</p>
      </part>
    </control>
    <control id="ARTPT-1">
      <title>Wallet Assertion Presentation Channel Protection</title>
      <prop name="label" class="index" value="5.9 A"/>
      <prop name="marking" class="target" value="IdP/RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTPT-1_smt" name="statement">
        <p>Assertions SHALL be presented to the RP through an authenticated protected channel.</p>
      </part>
      <part id="ARTPT-1_obj" name="objective">
        <p>Determine whether assertions from a subscriber-controlled wallet are presented to the RP over an authenticated protected channel.</p>
        <link href="#ARTPT-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARTPT-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>For network-based assertion presentations, this control is satisfied by PSI-1.</p>
        <p>Examine the presentation protocol specification and implementation documentation  to confirm that the protocol establishes an authenticated protected channel for assertion presentation, for each wallet and non-network presentation method that will be utilized.</p>
      </part>
    </control>
    <control id="ARTPT-2">
      <title>Wallet Presentation Nonce Inclusion</title>
      <prop name="label" class="index" value="5.9 B"/>
      <prop name="marking" class="target" value="IdP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTPT-2_smt" name="statement">
        <p>The presentation SHALL include the cryptographic nonce from the RP's request, if present (this is required at FAL2 and above).</p>
      </part>
      <part id="ARTPT-2_obj" name="objective">
        <p>Determine whether the wallet includes the RP's cryptographic nonce in the assertion presentation.</p>
        <link href="#ARTPT-2_smt" rel="assessment-for"/>
      </part>
      <part id="ARTPT-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ARTCN-4.</p>
      </part>
      <part id="ARTPT-2_gdn" name="guidance">
        <p>Assessment is required when: The RP sends a cryptographic nonce in its federation request (required at FAL2 and above).</p>
      </part>
    </control>
    <control id="ARTPT-3">
      <title>Wallet Presentation Nonce Verification</title>
      <prop name="label" class="index" value="5.9 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTPT-3_smt" name="statement">
        <p>The RP SHALL verify the nonce in accordance with the federation protocol.</p>
      </part>
      <part id="ARTPT-3_obj" name="objective">
        <p>Determine whether the RP verifies the cryptographic nonce in the wallet's presentation.</p>
        <link href="#ARTPT-3_smt" rel="assessment-for"/>
      </part>
      <part id="ARTPT-3_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ARTVL-3, item 5.</p>
      </part>
      <part id="ARTPT-3_gdn" name="guidance">
        <p>Assessment is required when: The RP sends a cryptographic nonce in its federation request (required at FAL2 and above).</p>
      </part>
    </control>
    <control id="ARTPT-4">
      <title>Wallet Assertion Injection Protection</title>
      <prop name="label" class="index" value="5.9 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTPT-4_smt" name="statement">
        <p>The RP SHALL protect itself against the injection of manufactured or captured assertions by using XSS and CSRF protection, rejecting assertions outside of the correct stage of a federation transaction, or other accepted techniques discussed in Sec. 3.11.1.</p>
      </part>
      <part id="ARTPT-4_obj" name="objective">
        <p>Determine whether the RP protects itself against injection of manufactured or captured wallet assertions.</p>
        <link href="#ARTPT-4_smt" rel="assessment-for"/>
      </part>
      <part id="ARTPT-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by FCP-2.</p>
      </part>
    </control>
    <control id="ARTVL-1">
      <title>Wallet Attribute Bundle Signature Validation</title>
      <prop name="label" class="index" value="5.10 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTVL-1_smt" name="statement">
        <p>The RP SHALL validate the signature on all signed attribute bundles in the assertion using the verification key from the CSP that issued the signed attribute bundle.</p>
      </part>
      <part id="ARTVL-1_obj" name="objective">
        <p>Determine whether the RP validates the signature on all signed attribute bundles in the assertion using the verification key from the CSP that issued the bundle.</p>
        <link href="#ARTVL-1_smt" rel="assessment-for"/>
      </part>
      <part id="ARTVL-1_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ABUN-2.</p>
      </part>
      <part id="ARTVL-1_gdn" name="guidance">
        <p>ABUN-2 establishes the requirement for RPs to validate CSP signatures on attribute bundles. This control applies that requirement to subscriber-controlled wallet scenarios.</p>
      </part>
    </control>
    <control id="ARTVL-2">
      <title>Wallet Assertion Signature Validation</title>
      <prop name="label" class="index" value="5.10 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTVL-2_smt" name="statement">
        <p>The RP SHALL validate the signature of the assertion using the verification key of the subscriber controlled wallet contained in the signed attribute bundle.</p>
      </part>
      <part id="ARTVL-2_obj" name="objective">
        <p>Determine whether the RP validates the wallet's assertion signature using the wallet's verification key contained in the signed attribute bundle.</p>
        <link href="#ARTVL-2_smt" rel="assessment-for"/>
      </part>
      <part id="ARTVL-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ABUN-3.</p>
      </part>
    </control>
    <control id="ARTVL-3">
      <title>Wallet Assertion Validation Checklist</title>
      <prop name="label" class="index" value="5.10 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="ARTVL-3_smt" name="statement">
        <p>The RP SHALL validate the assertion by checking that all the following are true:</p>
        <p>(1) Bundle verification: Ensure that the bundle was issued to the wallet that is presenting the assertion to the RP.</p>
        <p>(2) Issuer verification: If a specific wallet was requested by the RP, ensure that the assertion was issued by the requested wallet.</p>
        <p>(3) Time validation: Ensure that the validity time window is within acceptable limits of the current timestamp.</p>
        <p>(4) Audience restriction: Ensure that this RP is the intended recipient of the assertion.</p>
        <p>(5) Nonce: Ensure that the cryptographic nonce included in the RP's request is also included in the presentation.</p>
        <p>(6) Transaction terms: Ensure that the IAL, AAL, and FAL represented by the assertion are allowable under the applicable trust agreement and are suitable for the RP's needs.</p>
        <p>(7) Assertion identifier: Ensure that the assertion has not been replayed within its validity time window at this RP by validating a transaction specific assertion identifier, such as a wallet-provided nonce.</p>
      </part>
      <part id="ARTVL-3_obj" name="objective">
        <p>Determine whether the RP validates all required elements of a wallet assertion before accepting it.</p>
        <link href="#ARTVL-3_smt" rel="assessment-for"/>
      </part>
      <part id="ARTVL-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the RP assertion validation documentation to confirm that all requirements are checked.</p>
      </part>
      <part id="ARTVL-3_asm-test" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="TEST"/>
        <p>Test the RP system to validate all assertions are checked for the required elements and reject if they are not present.</p>
      </part>
    </control>
    <control id="RPSUBA-1">
      <title>Wallet Account Resolution Attribute Minimization</title>
      <prop name="label" class="index" value="5.11 A"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSUBA-1_smt" name="statement">
        <p>If a federated identifier is not present (e.g., in the case of mDL), the RP will need to request the necessary attributes to resolve the subscriber to the RP subscriber account for each federated transaction. This attribute set SHALL be the minimum necessary to achieve accurate resolution.</p>
      </part>
      <part id="RPSUBA-1_obj" name="objective">
        <p>Determine whether the RP requests only the minimum attributes necessary for accurate account resolution when a federated identifier is not present.</p>
        <link href="#RPSUBA-1_smt" rel="assessment-for"/>
      </part>
      <part id="RPSUBA-1_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the set of attributes that the RP requests from the wallet for account resolution. Confirm that each requested attribute is necessary for accurate resolution and that no extraneous attributes are included.</p>
      </part>
      <part id="RPSUBA-1_gdn" name="guidance">
        <p>Assessment is required when: A federated identifier is not present in the wallet assertion and account resolution is used.</p>
        <p>ACCR-1 requires that the requested attributes are sufficient for unique resolution; this control requires that they are no more than necessary. Together they establish the bound: request enough to resolve accurately, but nothing beyond that. This supports the data minimization principles in Sec. 7.</p>
      </part>
    </control>
    <control id="RPSUBA-2">
      <title>Wallet Federated Identifier Linking</title>
      <prop name="label" class="index" value="5.11 B"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSUBA-2_smt" name="statement">
        <p>Linking to multiple federated identifiers SHALL be managed as discussed in Sec. 3.8.1.</p>
      </part>
      <part id="RPSUBA-2_obj" name="objective">
        <p>Determine whether linking to multiple federated identifiers in the wallet context is managed in accordance with Sec. 3.8.1.</p>
        <link href="#RPSUBA-2_smt" rel="assessment-for"/>
      </part>
      <part id="RPSUBA-2_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by ACCL-1 and ACCL-2.</p>
      </part>
    </control>
    <control id="RPSUBA-3">
      <title>RP Subscriber Information Management Disclosure</title>
      <prop name="label" class="index" value="5.11 C"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSUBA-3_smt" name="statement">
        <p>The RP SHALL disclose its practices for managing subscriber information as part of the trust agreement.</p>
      </part>
      <part id="RPSUBA-3_obj" name="objective">
        <p>Determine whether the RP discloses its practices for managing subscriber information as part of the trust agreement artifact(s).</p>
        <link href="#RPSUBA-3_smt" rel="assessment-for"/>
      </part>
      <part id="RPSUBA-3_asm-examine" name="assessment-method">
        <prop ns="http://csrc.nist.gov/ns/rmf" name="method" value="EXAMINE"/>
        <p>Examine the trust agreement artifact(s) to confirm the RP's practices for managing subscriber information are disclosed, including how subscriber data is collected, stored, used, and disposed of.</p>
      </part>
    </control>
    <control id="RPSUBA-4">
      <title>Wallet RP Subscriber Account Redress</title>
      <prop name="label" class="index" value="5.11 D"/>
      <prop name="marking" class="target" value="RP"/>
      <prop name="marking" class="xal-level" value="ALL"/>
      <part id="RPSUBA-4_smt" name="statement">
        <p>The RP SHALL provide effective means of redress to the subscriber for correcting information in the RP subscriber account. See Sec. 3.5.3 for additional requirements and considerations for redress mechanisms.</p>
      </part>
      <part id="RPSUBA-4_obj" name="objective">
        <p>Determine whether the RP provides effective means of redress to the subscriber for correcting information in the RP subscriber account.</p>
        <link href="#RPSUBA-4_smt" rel="assessment-for"/>
      </part>
      <part id="RPSUBA-4_asm-summary" name="assessment-method" class="assessment-summary">
        <title>Assessment Method</title>
        <prop name="method" value="EXAMINE"/>
        <p>Satisfied by RR-1.</p>
      </part>
    </control>
  </group>
</catalog>