--- catalog: uuid: 11d5ade2-d32b-42c0-971e-3d72d49ad33d groups: - class: revision id: revision-63Base title: 63Base controls: - id: DIRM-1 title: Digital Identity Risk Management - RP Process Implementation props: - value: "3.0 #1" class: index name: label - value: RP class: target name: marking - value: DIRM class: xal-level name: marking parts: - id: DIRM-1_smt name: statement prose: Federal RPs SHALL implement the DIRM process for all online services. - id: DIRM-1_obj links: - rel: assessment-for href: "#DIRM-1_smt" name: objective prose: Determine if all online services of the Federal RP are identified and ensure the DIRM process is implemented for those online services. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIRM-1_asm-examine name: assessment-method prose: "Examine DIRM policy to determine that it is intended to cover all organizational applications. If available, review the list of online services to ensure all services are identified and that DIRM documentation for each online service exists." - id: DIRM-1_gdn name: guidance prose: "For relying parties, the intent of [the DIRM] process is to determine the assurance levels and any tailoring required to protect all online services and the applications, transactions, and systems that comprise or are impacted by those services. This directly contributes to the selection, development, and procurement of CSP services." - id: DIRM-2 title: Digital Identity Risk Management - CSP/IdP Communication of Normative Deviations props: - value: "3.0 #2" class: index name: label - value: CSP/IdP class: target name: marking - value: DIRM class: xal-level name: marking parts: - id: DIRM-2_smt name: statement prose: "Whenever a service offering deviates from normative guidance, those deviations SHALL be clearly communicated to the RPs that utilize the service." - id: DIRM-2_obj links: - rel: assessment-for href: "#DIRM-2_smt" name: objective prose: Ensure that the CSP/IdP has a documented process for communicating when their services deviate from the established normative guidance of the applicable NIST SP 900-63 requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIRM-2_asm-examine name: assessment-method prose: Examine the CSP/IdP policy for communicating deviations from normative guidance. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: DIRM-2_asm-interview name: assessment-method prose: Interview relying party customers to confirm they are familiar with the policy and process for communication and determine if the process is being used. - id: DIRM-2_gdn name: guidance prose: "For credential service providers and identity providers, the intent of [the DIRM] process is to design service offerings that meet the requirements of the defined assurance levels, continuously guard against compromises to the identity system, and meet the needs of RPs." - id: DIRM-3 title: Digital Identity Risk Management - Documentation props: - value: 3.0 A class: index name: label - value: Organization class: target name: marking - value: DIRM class: xal-level name: marking parts: - id: DIRM-3_smt name: statement prose: "At a minimum, organizations SHALL execute and document each step and complete and document the normative mandates and outcomes of each step, regardless of any organization-specific processes or tools used in the overall DIRM process." - id: DIRM-3_obj links: - rel: assessment-for href: "#DIRM-3_smt" name: objective prose: Determine that each step of the DIRM process is executed and documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIRM-3_asm-examine name: assessment-method prose: Examine the DIRM process documentation to ensure the outcomes of each step are completed as applicable. - id: DIRM-3_gdn name: guidance prose: "This requirement is agnostic to any organization-specific processes or tools used in the overall DIRM process.(Ref. Sec. 3.0 #A)" - id: DOS-1a title: Define Online Services - Mission and Business props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1a_smt name: statement prose: RPs SHALL develop a description of the online service that includes the organizational mission and business objectives supported by the online service. - id: DOS-1a_obj links: - rel: assessment-for href: "#DOS-1a_smt" name: objective prose: Determine if a description of the online service has been developed that includes the organizational mission and business objectives that are supported by the online service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1a_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it includes a description of its organizational mission and business objectives. - id: DOS-1a_gdn name: guidance prose: "The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process." - id: DOS-1b title: Define Online Services - Dependencies props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1b_smt name: statement prose: RPs SHALL develop a description of the online service that includes the mission and business partner dependencies associated with the online service. - id: DOS-1b_obj links: - rel: assessment-for href: "#DOS-1b_smt" name: objective prose: Determine if a description of the online service has been developed that includes the mission and business partner dependencies associated with the online service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1b_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it includes its associated mission and business partner dependencies. - id: DOS-1b_gdn name: guidance prose: "The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process." - id: DOS-1c title: "Define Online Services - Legal, Regulatory, Contractual" props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1c_smt name: statement prose: "RPs SHALL develop a description of the online service that includes legal, regulatory, and contractual requirements, including privacy obligations that apply to the online service." - id: DOS-1c_obj links: - rel: assessment-for href: "#DOS-1c_smt" name: objective prose: "Determine if a description of the online service has been developed that includes the legal, regulatory, and contractual requirements, including obligations that apply to the online service." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1c_asm-examine name: assessment-method prose: "Examine the organization's DIRM documentation for each online service to ensure it includes its legal, regulatory, and contractual requirements, including obligations that apply to the online service." - id: DOS-1c_gdn name: guidance prose: "The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process." - id: DOS-1d title: Define Online Services - Functionality and Data Processing props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1d_smt name: statement prose: RPs SHALL develop a description of the online service that includes the functionality of the online service and the data that it is expected to process. - id: DOS-1d_obj links: - rel: assessment-for href: "#DOS-1d_smt" name: objective prose: Determine if a description of the online service has been developed that includes the functionality of the online service and the data that it is expected to process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1d_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it includes its functionality and the data that it is expected to process. - id: DOS-1d_gdn name: guidance prose: "The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process." - id: DOS-1e title: Define Online Services - User Groups Transactions & Access Privileges props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1e_smt name: statement prose: RPs SHALL develop a description of the online service that includes user groups that need to have access to the online service as well as the types of online transactions and access privileges available to each user group. - id: DOS-1e_obj links: - rel: assessment-for href: "#DOS-1e_smt" name: objective prose: Determine if a description of the online service has been developed that includes the user groups that need to have access to the online service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1e_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it identifies user groups and the transaction types and access privileges associated with each group. - id: DOS-1e_gdn name: guidance prose: |- The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process. The set of entities includes users of the online service, organizations, and populations served. It is crucial to differentiate between user groups and impacted entities. (a) User groups are users who are partitioned based on the specific functionality or access privileges offered to them (e.g., citizens checking tax status vs. tax preparers filing returns). (b) Impacted entities include everyone who could face negative consequences if the identity system fails. This group includes members of the user groups but also potentially those who never directly use the system. - id: DOS-1f title: Define Online Services - Impacted Entities and Business Processes props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1f_smt name: statement prose: "RPs SHALL develop a description of the online service that includes the set of entities (to include users of the online service, organizations, and populations served) that will be impacted by the online service and the broader business process of which it is a part." - id: DOS-1f_obj links: - rel: assessment-for href: "#DOS-1f_smt" name: objective prose: Determine if a description of the online service has been developed that includes the set of entities that will be impacted by the online service and the broader business process of which it is a part. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1f_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it includes the set of entities that will be impacted by the online service and the broader business process of which it is a part. - id: DOS-1f_gdn name: guidance prose: |- The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process. The set of entities includes users of the online service, organizations, and populations served. - id: DOS-1g title: Define Online Services - Previous Assessment Results and Technologies props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1g_smt name: statement prose: "RPs SHALL develop a description of the online service that includes the results of any preexisting DIRM assessments (as an input) and the current state of any preexisting identity technologies (i.e., proofing, authentication, or federation)." - id: DOS-1g_obj links: - rel: assessment-for href: "#DOS-1g_smt" name: objective prose: Determine if a description of the online service has been developed that includes the results of any preexisting DIRM assessments and the current state of any preexisting identity technologies. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1g_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it includes the results of any preexisting DIRM assessments and/or a description of the current state of any preexisting identity technologies. - id: DOS-1g_gdn name: guidance prose: "The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process." - id: DOS-1h title: Define Online Services - Identity Evidence Availability props: - value: 3.1 A class: index name: label - value: RP class: target name: marking - value: DIRM Step 1 class: xal-level name: marking parts: - id: DOS-1h_smt name: statement prose: RPs SHALL develop a description of the online service that includes the estimated availability of the types of identity evidence required for identity proofing across all user groups served. - id: DOS-1h_obj links: - rel: assessment-for href: "#DOS-1h_smt" name: objective prose: Determine if a description of the online service has been developed that includes the estimated availability of the types of identity evidence required for identity proofing across all user groups served. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-1h_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it includes the estimated availability of the types of identity evidence required for identity proofing across all user groups served. - id: DOS-1h_gdn name: guidance prose: "The purpose of this initial step is to establish a common understanding of the online service's context and functionality, which is essential for informing the subsequent risk assessment steps of the DIRM process." - id: DOS-2 title: Define Online Services - Impact Assessment Scope - Users and Organization props: - value: 3.1 B class: index name: label - value: Organization class: target name: marking - value: "DIRM Step 1, Impact assessment" class: xal-level name: marking parts: - id: DOS-2_smt name: statement prose: The scope of impact assessments SHALL include individuals who use the online service as well as the organization itself. - id: DOS-2_obj links: - rel: assessment-for href: "#DOS-2_smt" name: objective prose: Determine if the scope of impact assessments includes impacts to individuals who use the online service and impacts to the organization. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-2_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure the impact assessments address impacts to the individuals who use the online service and impacts to the organization. - id: DOS-2_gdn name: guidance prose: "Note: \"online application\" is the same as \"online service\"." - id: DOS-3 title: Define Online Services - Impact Assessment Scope - Entities included in Mission and Business Needs props: - value: 3.1 C class: index name: label - value: Organization class: target name: marking - value: "DIRM Step 1, Impact assessment" class: xal-level name: marking parts: - id: DOS-3_smt name: statement prose: "The scope of impact assessments for organizations SHALL identify other entities (e.g., mission partners, communities, and those identified in [SP800-30]) that need to be specifically included based on mission and business needs." - id: DOS-3_obj links: - rel: assessment-for href: "#DOS-3_smt" name: objective prose: Determine if the scope of impact assessments for organizations identify other entities that need to be specifically included based on mission and business needs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-3_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure the impact assessments address mission partners and other external organizations that may be impacted by the online service. - id: DOS-3_gdn name: guidance prose: DOS-3 deals with user groups. - id: DOS-4 title: Define Online Services - Impact Assessment Scope - Impacted Entities props: - value: 3.1 D class: index name: label - value: Organization class: target name: marking - value: "DIRM Step 1, Impact assessment" class: xal-level name: marking parts: - id: DOS-4_smt name: statement prose: "At a minimum, organizations SHALL document all impacted entities (both internal and external to the organization) when conducting their impact assessments." - id: DOS-4_obj links: - rel: assessment-for href: "#DOS-4_smt" name: objective prose: Determine if the scope of impact assessments for organizations identify all internal and external impacted entities. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DOS-4_asm-examine name: assessment-method prose: Examine the organization's DIRM documentation for each online service to ensure it includes a description of the scope of impact assessments for organizations that identifies all internal and external impacted entities. - id: DOS-4_gdn name: guidance prose: DOS-4 deals with impacted entities. - id: CIA-1a title: Impact Assessment - Potential Harms for Impact Categories props: - value: 3.2 A class: index name: label - value: Organization class: target name: marking - value: "DIRM Step 2, Impact assessment" class: xal-level name: marking parts: - id: CIA-1a_smt name: statement prose: The impact assessment SHALL include a set of impact categories and the potential harms for each impact category. - id: CIA-1a_obj links: - rel: assessment-for href: "#CIA-1a_smt" name: objective prose: Determine that the impact assessment includes a set of impact categories and the potential harms for each impact category. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CIA-1a_asm-examine name: assessment-method prose: Examine the organization's DIRM impact assessment documentation to establish that the impact assessment includes a set of impact categories and the potential harms for each impact category. - id: CIA-1b title: Impact Assessment - Levels of Impact Identification props: - value: 3.2 A class: index name: label - value: Organization class: target name: marking - value: "DIRM Step 2, Impact assessment" class: xal-level name: marking parts: - id: CIA-1b_smt name: statement prose: The impact assessment SHALL include identifying the levels of impact. - id: CIA-1b_obj links: - rel: assessment-for href: "#CIA-1b_smt" name: objective prose: Determine that the impact assessment includes the levels of impact. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CIA-1b_asm-examine name: assessment-method prose: Examine the organization's DIRM impact assessment documentation to establish that the impact assessment includes the levels of impact. - id: CIA-1c title: Impact Assessment - Levels of Impact - User Groups props: - value: 3.2 A class: index name: label - value: Organization class: target name: marking - value: "DIRM Step 2, Impact assessment" class: xal-level name: marking parts: - id: CIA-1c_smt name: statement prose: The impact assessment SHALL include assessing the level of impact for each user group. - id: CIA-1c_obj links: - rel: assessment-for href: "#CIA-1c_smt" name: objective prose: Determine that the impact assessment includes an assessment of the level of impact for each user group. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CIA-1c_asm-examine name: assessment-method prose: Examine the organization's DIRM impact assessment documentation to establish that the impact assessment includes an assessment for the level of impact for each user group. - id: CIA-2 title: Impact Assessment - Levels of Impact - Transactions props: - value: 3.2 B class: index name: label - value: Organization class: target name: marking - value: "DIRM Step 2, Impact assessment" class: xal-level name: marking parts: - id: CIA-2_smt name: statement prose: The level of impact for each user group identified in Sec. 3.1 SHALL be considered separately based on the transactions available to that user group. - id: CIA-2_obj links: - rel: assessment-for href: "#CIA-2_smt" name: objective prose: Determine if the levels of impact for each user group is considered separately based on the transactions available to that user group. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CIA-2_asm-examine name: assessment-method prose: Examine the organization's DIRM impact assessment documentation to establish that the levels of impact for each user group is considered separately based on the transactions available to that user group. - id: IC-1 title: Impact Categories props: - value: 3.2.1 A class: index name: label - value: Organization class: target name: marking - value: "Impact categories, Potential harms" class: xal-level name: marking parts: - id: IC-1_smt name: statement prose: |- At a minimum, organizations SHALL include the following impact categories in their impact assessments: (a) Degradation of mission delivery. (b) Damage to trust, standing, or reputation. (c) Unauthorized access to information. (d) Financial loss or liability. (e) Loss of life or danger to human safety, human health, or environmental health. - id: IC-1_obj links: - rel: assessment-for href: "#IC-1_smt" name: objective prose: "Determine if the impact categories in the impact assessments include degradation of mission delivery, damage to trust, standing, or reputation, unauthorized access to information, financial loss or liability, and loss of life or danger to human safety, human health, or environmental health." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IC-1_asm-examine name: assessment-method prose: "Examine the organization's DIRM impact assessment documentation to establish that the impact categories include degradation of mission delivery, damage to trust, standing, or reputation, unauthorized access to information, financial loss or liability, and loss of life or danger to human safety, human health, or environmental health." - id: IC-2 title: Impact Categories - Documentation and Application props: - value: 3.2.1 B class: index name: label - value: Organization class: target name: marking - value: "Impact categories, Potential harms" class: xal-level name: marking parts: - id: IC-2_smt name: statement prose: Each impact category SHALL be documented and consistently applied when implementing the DIRM process across different online services offered by the organization. - id: IC-2_obj links: - rel: assessment-for href: "#IC-2_smt" name: objective prose: "Determine if, for each online service offered by the organization, each impact category is documented and applied as part of the DIRM process." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IC-2_asm-examine name: assessment-method prose: "Examine the organization's DIRM impact assessment documentation to establish that, for each online service, each impact category is documented and applied." - id: IC-3 title: Impact Categories - Potential Harms props: - value: 3.2.1 C class: index name: label - value: Organization class: target name: marking - value: "Impact categories, Potential harms" class: xal-level name: marking parts: - id: IC-3_smt name: statement prose: "For each impact category, organizations SHALL consider potential harms for each of the impacted entities identified in Sec. 3.1" - id: IC-3_obj links: - rel: assessment-for href: "#IC-3_smt" name: objective prose: Determine if potential harms are identified for each impact category and each of the impacted entities. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IC-3_asm-examine name: assessment-method prose: Examine the organization's DIRM impact assessment documentation to establish that potential harms are identified for each impact category and each of the impacted entities. - id: PIL-1 title: "Potential Impact Levels - Threshold Development, Examples, and Documentation" props: - value: 3.2.2 A class: index name: label - value: Organization class: target name: marking - value: Impact levels class: xal-level name: marking parts: - id: PIL-1_smt name: statement prose: "To provide a more objective basis for impact level assignments, organizations SHOULD develop thresholds and examples for the impact levels for each impact category. Where this is done, particularly with specifically defined quantifiable values, these thresholds SHALL be documented and used consistently in the DIRM assessments across an organization to allow for a common understanding of risks." - id: PIL-1_obj links: - rel: assessment-for href: "#PIL-1_smt" name: objective prose: |- PIL-1Obj1: Determine if thresholds and examples for the impact levels for each impact category have been developed. (0ptional) PIL-1Obj2: Determine if PIL-1Obj1 is documented and used consistently in the DIRM assessments. (conditional) - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PIL-1_asm-examine name: assessment-method prose: "Examine the DIRM impact assessment documentation to verify that they are documented, including any specifically defined quantifiable values, and look for evidence of consistent use in the DIRM assessments." - id: PIL-1_gdn name: guidance prose: "Assessment is required when: thresholds and examples for the impact levels were developed." - id: IA-1 title: Impact Analysis - Impacts from Unauthorized Access props: - value: 3.2.3 A class: index name: label - value: Organization class: target name: marking - value: Impact analysis class: xal-level name: marking parts: - id: IA-1_smt name: statement prose: The impact analysis SHALL consider the level of impact for each impact category for each type of impacted entity if an intruder obtains unauthorized access as a member of each user group. - id: IA-1_obj links: - rel: assessment-for href: "#IA-1_smt" name: objective prose: "Determine if the impact analysis considers the level of impact resulting from unauthorized access, for each impact category for each type of impacted entity." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IA-1_asm-examine name: assessment-method prose: "Examine the analysis of the organization's DIRM impact assessment to establish that it considers impacts from unauthorized access for each type of impacted entity," - id: IA-2 title: Impact Analysis - User Groups props: - value: 3.2.3 B class: index name: label - value: Organization class: target name: marking - value: Impact analysis class: xal-level name: marking parts: - id: IA-2_smt name: statement prose: The impact analysis SHALL be performed for each user group that has access to the online service. - id: IA-2_obj links: - rel: assessment-for href: "#IA-2_smt" name: objective prose: Determine if the impact analysis is performed for each user group that has access to the online service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IA-2_asm-examine name: assessment-method prose: Examine documentation for the impact analyses performed to determine that one exists for each user group that has access to the online service. - id: IA-3 title: Impact Analysis - Output Documentation props: - value: 3.2.3 C class: index name: label - value: Organization class: target name: marking - value: Impact analysis class: xal-level name: marking parts: - id: IA-3_smt name: statement prose: The output of this impact analysis is a set of impact levels for each user group that SHALL be documented for further analysis in accordance with Sec. 3.4. - id: IA-3_obj links: - rel: assessment-for href: "#IA-3_smt" name: objective prose: Determine if the output of the impact analysis includes a documented set of impact levels. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IA-3_asm-examine name: assessment-method prose: Examine the output of the impact analysis to verify that it includes a documented set of impact levels. - id: CIL-1 title: Combined Impact - Overall Impact Level and Application props: - value: 3.2.4 A class: index name: label - value: Organization class: target name: marking - value: "Impact levels, User groups" class: xal-level name: marking parts: - id: CIL-1_smt name: statement prose: Organizations SHALL document the approach they use to combine their impact assessment into an overall impact level for each of their defined user groups and SHALL apply it consistently across all of its online services. - parts: - id: CIL-1_obj-1 links: - rel: assessment-for href: "#CIL-1_smt" name: objective prose: Determine if the approach used to combine the impact assessment into an overall impact level for each defined user group has been documented. - id: CIL-1_obj-2 links: - rel: assessment-for href: "#CIL-1_smt" name: objective prose: Determine if the approach used to combine the impact assessment into an overall impact level for each defined user group is applied consistently across all online services. id: CIL-1_obj links: - rel: assessment-for href: "#CIL-1_smt" name: objective - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CIL-1_asm-examine name: assessment-method prose: Examine the DIRM process documentation to ensure that the approach used to combine the impact assessment into an overall impact level for each defined user group has been documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: CIL-1_asm-interview name: assessment-method prose: Interview the person/people responsible for implementing this approach to ensure they understand the approach and are implementing it consistently. - id: CIL-2 title: Combined Impact Level - Impact Documentation props: - value: 3.2.4 B class: index name: label - value: Organization class: target name: marking - value: "Impact levels, User groups" class: xal-level name: marking parts: - id: CIL-2_smt name: statement prose: "At the conclusion of the combinatorial analysis, organizations SHALL document the impact for each user group." - id: CIL-2_obj links: - rel: assessment-for href: "#CIL-2_smt" name: objective prose: Determine if the overall impact levels for each user group have been documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CIL-2_asm-examine name: assessment-method prose: Examine the completed combined impact assessments to ensure the approach and results for each user group have been documented. - id: AL-1 title: Assurance Levels - xAL Need Determination props: - value: 3.3.1 A class: index name: label - value: RP class: target name: marking - value: "IAL, AAL, FAL" class: xal-level name: marking parts: - id: AL-1_smt name: statement prose: |- The RP SHALL identify the types of assurance levels that apply to their online service from the following: (a) IAL: The robustness of the identity proofing process to determine the identity of an individual. The IAL is selected to mitigate risks that result from potential identity proofing failures. (b) AAL: The robustness of the authentication process itself and the binding between an authenticator and a specific individual's identifier. The AAL is selected to mitigate risks that result from potential authentication failures. (c) FAL: The robustness of the federation process used to communicate authentication and attribute information to an RP from an IdP. The FAL is selected to mitigate risks that result from potential federation failures. - id: AL-1_obj links: - rel: assessment-for href: "#AL-1_smt" name: objective prose: "Determine if the online service needs an IAL, AAL, or FAL." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AL-1_asm-examine name: assessment-method prose: "Examine the documented needs of the identity service, the results of the DIRM documentation completed to date, and the IAL requirements from 800-63A, to determine if identity proofing is necessary." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AL-1_asm-examine-2 name: assessment-method prose: "Examine the documented needs of the identity service, the results of the DIRM documentation completed to date, and the IAL requirements from 800-63B, to determine if authentication is needed." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AL-1_asm-examine-3 name: assessment-method prose: "Examine the documented needs of the identity service, the results of the DIRM documentation completed to date, and the IAL requirements from 800-63C, to determine if federation is needed." - id: IALS-1 title: Initial Assurance Level Selection - Process and Governance Documentation props: - value: 3.3.3 A class: index name: label - value: Organization class: target name: marking - value: Assurance levels class: xal-level name: marking parts: - id: IALS-1_smt name: statement prose: Organizations SHALL develop and document a process and governance model for selecting initial assurance levels and controls based on the potential impacts of failures in the digital identity system. - id: IALS-1_obj links: - rel: assessment-for href: "#IALS-1_smt" name: objective prose: Determine if the process and governance model for selecting initial assurance levels and controls has been developed based on the potential impacts of failures in the digital identity system and has been documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IALS-1_asm-examine name: assessment-method prose: Examine the DIRM documentation to verify that the process and governance model for selecting initial assurance levels and controls has been developed and documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IALS-1_asm-examine-2 name: assessment-method prose: Examine the process and governance model documentation and identify the potential impacts of failures that the process and governance model were based on. - id: IIAL-1a title: Initial IAL - Decision Documentation props: - value: 3.3.3.1 A class: index name: label - value: Organization class: target name: marking - value: IAL class: xal-level name: marking parts: - id: IIAL-1a_smt name: statement prose: The organization SHALL document whether identity proofing is required for their application. - id: IIAL-1a_obj links: - rel: assessment-for href: "#IIAL-1a_smt" name: objective prose: Determine if the question of whether identity proofing is required for the online service has been documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IIAL-1a_asm-examine name: assessment-method prose: Examine the online service documentation to verify that the results of the analysis to determine the need for identity proofing has been documented. - id: IIAL-1a_gdn name: guidance prose: This documents the results of control AL-1. - id: IIAL-1b title: Initial IAL - Selection props: - value: 3.3.3.1 A class: index name: label - value: Organization class: target name: marking - value: IAL class: xal-level name: marking parts: - id: IIAL-1b_smt name: statement prose: "If identity proofing is required for their application, the organization SHALL select an initial IAL for each user group based on the effective impact level determination from Sec. 3.2.4." - id: IIAL-1b_obj links: - rel: assessment-for href: "#IIAL-1b_smt" name: objective prose: Determine if an initial IAL for each user group was determined and is based on the impact level determination (see CIL requirements) - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IIAL-1b_asm-examine name: assessment-method prose: Examine the documentation to verify that the initial IAL has been determined for each user group and is based on the effective impact level determination (See CIL controls). - id: IIAL-1b_gdn name: guidance prose: |- Assessment is required when: the online service requires identity proofing for their user groups. See AL-1. If identity proofing is required, see CIL controls for impact levels. - id: IAAL-1a title: Initial AAL - Decision Documentation props: - value: 3.3.3.2 A class: index name: label - value: Organization class: target name: marking - value: AAL class: xal-level name: marking parts: - id: IAAL-1a_smt name: statement prose: The organization SHALL document whether authentication is required for their application. - id: IAAL-1a_obj links: - rel: assessment-for href: "#IAAL-1a_smt" name: objective prose: Determine if the question of whether authentication is required for the online service has been documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAAL-1a_asm-examine name: assessment-method prose: Examine the online service documentation to verify that the results of the analysis to determine the need for authentication has been documented. - id: IAAL-1a_gdn name: guidance prose: This documents the results of requirement AL-1. - id: IAAL-1b title: Initial AAL - Selection props: - value: 3.3.3.2 A class: index name: label - value: Organization class: target name: marking - value: AAL class: xal-level name: marking parts: - id: IAAL-1b_smt name: statement prose: "If authentication is required for their application, the organization SHALL select an initial AAL for each user group based on the effective impact level determination from Sec. 3.2.4." - id: IAAL-1b_obj links: - rel: assessment-for href: "#IAAL-1b_smt" name: objective prose: Determine if an initial AAL for each user group was determined and is based on the impact level determination (see CIL requirements) - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAAL-1b_asm-examine name: assessment-method prose: Examine the documentation to verify that the initial AAL has been determined for each user group and is based on the effective impact level determination (See CIL controls). - id: IAAL-1b_gdn name: guidance prose: |- Assessment is required when: the online service requires authentication. See AL-1. If authentication is required, see CIL controls for impact levels. - id: IFAL-1a title: Initial FAL - Decision Documentation props: - value: 3.3.3.3 A class: index name: label - value: Organization class: target name: marking - value: FAL class: xal-level name: marking parts: - id: IFAL-1a_smt name: statement prose: The organization SHALL document whether federation is required for their application. - id: IFAL-1a_obj links: - rel: assessment-for href: "#IFAL-1a_smt" name: objective prose: Determine if the question of whether federation is required for the online service has been documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IFAL-1a_asm-examine name: assessment-method prose: Examine the online service documentation to verify that the results of the analysis to determine the need for federation has been documented. - id: IFAL-1a_gdn name: guidance prose: "This documents the results of the FAL assessment in control AL-1. Assessment is required when: the organization will use federation." - id: IFAL-1b title: Initial FAL - Selection props: - value: 3.3.3.3 A class: index name: label - value: Organization class: target name: marking - value: FAL class: xal-level name: marking parts: - id: IFAL-1b_smt name: statement prose: "If federation is required for their application, the organization SHALL select an initial FAL for each user group based on the effective impact level determination from Sec. 3.2.4." - id: IFAL-1b_obj links: - rel: assessment-for href: "#IFAL-1b_smt" name: objective prose: Determine if an initial FAL for each user group was determined and is based on the impact level determination (see CIL requirements) - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IFAL-1b_asm-examine name: assessment-method prose: Examine the documentation to verify that the initial FAL has been determined for each user group and is based on the effective impact level determination (See CIL controls). - id: IFAL-1b_gdn name: guidance prose: |- Assessment is required when: the online service requires federation. See AL-1. If federation will be used, see CIL controls for impact levels. - id: IFAL-2 title: Initial FAL - FAL2 or FAL3 Assessment props: - value: 3.3.3.3 B class: index name: label - value: Organization class: target name: marking - value: FAL class: xal-level name: marking parts: - id: IFAL-2_smt name: statement prose: "For online services that are assessed to be high impact, organizations SHALL conduct a further assessment to evaluate the risk of a compromised IdP to determine whether FAL2 or FAL3 is more appropriate for their use case." - id: IFAL-2_obj links: - rel: assessment-for href: "#IFAL-2_smt" name: objective prose: "If the online service is \"high impact,\" determine if further assessment has been done to evaluate the risk of a compromised IdP and if FAL2 or FAL3 is more appropriate." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IFAL-2_asm-examine name: assessment-method prose: Examine the documentation for additional assessments that evaluate if FAL2 or FAL3 is more appropriate. - id: IFAL-2_gdn name: guidance prose: |- Dependent on the results from controls AL-1 and IFAL-1a. Assessment is required when: the online service is assessed to be "high-impact." - id: BC-1a title: Baseline Controls - IAL Controls props: - value: 3.3.3 A class: index name: label - value: Organization class: target name: marking - value: Baseline Controls class: xal-level name: marking parts: - id: BC-1a_smt name: statement prose: "Using the initial xALs selected in Sec. 3.3.3, the organization SHALL identify the applicable baseline controls for each user group for the Initial IAL and related technical and process controls from [SP800-63A]." - id: BC-1a_obj links: - rel: assessment-for href: "#BC-1a_smt" name: objective prose: Determine if the applicable baseline controls for the initial IAL and related technical and process controls have been identified for each user group in alignment with SP 800-63A. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BC-1a_asm-examine name: assessment-method prose: Examine the initial IAL baseline controls and related technical and process controls to determine that they are in alignment with SP 800-63A for each user group. - id: BC-1a_gdn name: guidance prose: See IIAL controls. - id: BC-1b title: Baseline Controls - AAL Controls props: - value: 3.3.3 A class: index name: label - value: Organization class: target name: marking - value: Baseline Controls class: xal-level name: marking parts: - id: BC-1b_smt name: statement prose: "Using the initial xALs selected in Sec. 3.3.3, the organization SHALL identify the applicable baseline controls for each user group for the Initial AAL and related technical and process controls from [SP800-63B]." - id: BC-1b_obj links: - rel: assessment-for href: "#BC-1b_smt" name: objective prose: Determine if the applicable baseline controls for the initial AAL and related technical and process controls have been identified for each user group in alignment with SP 800-63B. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BC-1b_asm-examine name: assessment-method prose: Examine the initial AAL baseline controls and related technical and process controls to determine that they are in alignment with SP 800-63B for each user group. - id: BC-1b_gdn name: guidance prose: See IAAL controls. - id: BC-1c title: Baseline Controls - FAL Controls props: - value: 3.3.3 A class: index name: label - value: Organization class: target name: marking - value: Baseline Controls class: xal-level name: marking parts: - id: BC-1c_smt name: statement prose: "Using the initial xALs selected in Sec. 3.3.3, the organization SHALL identify the applicable baseline controls for each user group for the Initial FAL and related technical and process controls from [SP800-63C]." - id: BC-1c_obj links: - rel: assessment-for href: "#BC-1c_smt" name: objective prose: Determine if the applicable baseline controls for the initial FAL and related technical and process controls have been identified for each user group in alignment with SP 800-63C. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BC-1c_asm-examine name: assessment-method prose: Examine the initial FAL baseline controls and related technical and process controls to determine that they are in alignment with SP 800-63C for each user group - id: BC-1c_gdn name: guidance prose: See IFAL controls. - id: TAL-1 title: Tailor Assurance Levels - Mission Impacts props: - value: 3.4 A class: index name: label - value: Organization class: target name: marking - value: Tailoring class: xal-level name: marking parts: - id: TAL-1_smt name: statement prose: "Within the tailoring step, organizations SHALL focus on impacts to mission delivery due to the implementation of identity management controls." - id: TAL-1_obj links: - rel: assessment-for href: "#TAL-1_smt" name: objective prose: Determine if the impacts to mission delivery are used as a focus for the tailoring step. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAL-1_asm-examine name: assessment-method prose: Examine the tailoring documentation to ensure impacts to mission are used as a focus. - id: TAL-1_gdn name: guidance prose: Impacts include the possibility of legitimate users who are unable to access desired online services or experience sufficient friction or frustration with the identity system (and technology selection) that they abandon attempts to access the online service.(Ref. Sec. 3.4 A) - id: TAL-2 title: Tailor Assurance Levels - DIAS Review props: - value: 3.4 B class: index name: label - value: Organization class: target name: marking - value: Tailoring class: xal-level name: marking parts: - id: TAL-2_smt name: statement prose: "As a part of the tailoring process, organizations SHALL review the Digital Identity Acceptance Statements (DIAS) and practice statements from CSPs and IdPs that they use or intend to use." - id: TAL-2_obj links: - rel: assessment-for href: "#TAL-2_smt" name: objective prose: Determine if the DIAS and practice statements from CSPs and IdPs have been reviewed as part of the tailoring process. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: TAL-2_asm-interview name: assessment-method prose: Interview the person/team responsible for completing the tailoring step to ensure they reviewed the DIAS and practice statements. - id: TAL-3 title: Tailor Assurance Levels - Analysis props: - value: 3.4 C class: index name: label - value: Organization class: target name: marking - value: Tailoring class: xal-level name: marking parts: - id: TAL-3_smt name: statement prose: Organizations SHALL also conduct their own analysis to ensure that their specific mission and the communities being served by the online service are given due consideration for tailoring purposes. - id: TAL-3_obj links: - rel: assessment-for href: "#TAL-3_smt" name: objective prose: Determine if the tailoring process includes organizations' own analysis to ensure that their mission and communities served by the online services are given due consideration. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAL-3_asm-examine name: assessment-method prose: "Examine the tailoring documentation to ensure analysis was done, and due consideration given, to the organization specific mission and the communities being served by the online service." - id: TAL-4 title: Tailor Assurance Levels - Tailoring Process props: - value: 3.4 D class: index name: label - value: Organization class: target name: marking - value: Tailoring class: xal-level name: marking parts: - id: TAL-4_smt name: statement prose: Organizations SHALL establish and document their xAL tailoring process. - id: TAL-4_obj links: - rel: assessment-for href: "#TAL-4_smt" name: objective prose: |- (1) Determine if the xAL tailoring process has been documented. (2) Determine if the xAL tailoring process has been implemented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAL-4_asm-examine name: assessment-method prose: Examine the tailoring process documentation for each xAL to verify its existence and completeness. - id: TAL-5 title: Tailor Assurance Levels - Governance Approach props: - value: 3.4 E class: index name: label - value: Organization class: target name: marking - value: Tailoring class: xal-level name: marking parts: - id: TAL-5_smt name: statement prose: "At a minimum, [the tailoring] process SHALL follow a documented governance approach to allow for decision-making." - id: TAL-5_obj links: - rel: assessment-for href: "#TAL-5_smt" name: objective prose: Determine if the tailoring process follows a documented governance approach that allows for decision-making. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAL-5_asm-examine name: assessment-method prose: Examine the tailoring process documentation for information on the governance approach that allows for decision-making. - id: TAL-6 title: Tailor Assurance Levels - Document Decisions props: - value: 3.4 F class: index name: label - value: Organization class: target name: marking - value: Tailoring class: xal-level name: marking parts: - id: TAL-6_smt name: statement prose: "At a minimum, [the tailoring] process SHALL document all decisions in the tailoring process (see Sec. 3.4.4)." - id: TAL-6_obj links: - rel: assessment-for href: "#TAL-6_smt" name: objective prose: Determine if the tailoring process documents all decisions made during the tailoring process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAL-6_asm-examine name: assessment-method prose: Examine the tailoring process documentation to determine that all decisions made during the tailoring process have been documented. - id: TAL-6_gdn name: guidance prose: "Examples of decisions include the assessed xALs, modified xALs, and supplemental and compensating controls in the Digital Identity Acceptance Statement" - id: TAL-7 title: Tailor Assurance Levels - Document Risk-Based Decisions props: - value: 3.4 G class: index name: label - value: Organization class: target name: marking - value: Tailoring class: xal-level name: marking parts: - id: TAL-7_smt name: statement prose: "At a minimum, the [tailoring] process SHALL justify and document all risk-based decisions or modifications to the initially assessed xALs in the Digital Identity Acceptance Statement (DIAS) (see Sec. 3.4.4)." - id: TAL-7_obj links: - rel: assessment-for href: "#TAL-7_smt" name: objective prose: Determine if the tailoring process justifies and documents all risk-based decisions or modifications to the initially selected xALs in the DIAS. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAL-7_asm-examine name: assessment-method prose: Examine the tailoring process documentation to ensure justifications are included in the documented risk-based decisions or modifications that apply to the initially selected xALs in the DIAS. - id: PCT-1 title: "Privacy, Customer Experience, Threat Resistance - Identify Impacts" props: - value: 3.4.1 A class: index name: label - value: Organization class: target name: marking - value: "Privacy, Customer Experience, Threat Resistance" class: xal-level name: marking parts: - id: PCT-1_smt name: statement prose: "When progressing from the initial assurance level selection in [the Baseline Controls requirements] (Sec. 3.3.4) to the final xAL selection and implementation, organizations SHALL conduct detailed assessments of the controls defined for the initially selected xALs to identify potential impacts in the operational environment." - id: PCT-1_obj links: - rel: assessment-for href: "#PCT-1_smt" name: objective prose: "As part of the selection of the final xALs, determine if a detailed assessment of the initial xAL controls was conducted and identified potential impacts in the operational environment." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PCT-1_asm-examine name: assessment-method prose: Examine the DIRM documentation indicating the final xAL selection to ensure it includes a detailed assessment of the initial xAL controls and identifies potential impacts in the operational environment. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PCT-1_asm-interview name: assessment-method prose: Interview the person(s) responsible for conducting the assessment of the initial xAL controls for how they identified the potential impacts in the operational environment. - id: PCT-2a title: "Privacy, Customer Experience, Threat Resistance - Privacy Impact Assessment" props: - value: 3.4.1 B class: index name: label - value: Organization class: target name: marking - value: Privacy class: xal-level name: marking parts: - id: PCT-2a_smt name: statement prose: "At a minimum, organizations SHALL assess the impacts and potential unintended consequences related to Privacy - Identify unintended consequences to the privacy of individuals who will be subject to the controls at an assessed xAL and of individuals affected by organizational or third-party practices related to the establishment, management, or federation of a digital identity. A privacy assessment SHOULD leverage an existing Privacy Threshold Analysis (PTA) or Privacy Impact Assessment (PIA) as inputs during the privacy assessment process." - id: PCT-2a_obj links: - rel: assessment-for href: "#PCT-2a_smt" name: objective prose: Determine if the organization assessed the impacts and potential unintended consequences related to privacy. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PCT-2a_asm-examine name: assessment-method prose: Examine the DIRM documentation indicating the final xAL selection to ensure it includes an assessment of the impacts and potential unintended consequences related to privacy. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PCT-2a_asm-interview name: assessment-method prose: Interview the person(s) responsible for assessing the impacts and potential consequences related to privacy to determine if they leveraged a PTA or PIA as part of their process. (optional) - id: PCT-2a_gdn name: guidance prose: "As the goal of the privacy assessment is to identify privacy risks that arise from the initial assurance level selection, additional assessments and evaluations that are specific to the baseline controls for the assurance levels may be required for the underlying information system. Leveraging an existing PTA or PIA is recommended." - id: PCT-1b title: "Privacy, Customer Experience, Threat Resistance - Customer Experience Impact Assessment" props: - value: 3.4.1 B class: index name: label - value: Organization class: target name: marking - value: Customer Experience class: xal-level name: marking parts: - id: PCT-1b_smt name: statement prose: "At a minimum, organizations SHALL assess the impacts and potential unintended consequences related to Customer Experience - Determine whether implementation of the initial assurance levels may create substantial or unacceptable barriers to individuals seeking to access services. Customer experience assessments SHALL consider impacts that result from the identity management controls to ensure that they do not cause undue burdens, frustrations, or frictions for individuals and that there are pathways to provide service to users of all capabilities, resources, technology access, and economic statuses." - id: PCT-1b_obj links: - rel: assessment-for href: "#PCT-1b_smt" name: objective prose: Determine if the organization assessed the impacts and potential unintended consequences related to customer experience. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PCT-1b_asm-examine name: assessment-method prose: "Examine the DIRM documentation indicating the final xAL selection to ensure it includes an assessment of the impacts and potential unintended consequences related to customer experience, such as undue burdens, frustrations, or frictions for individuals, as well as pathways to provide service to users of all capabilities, resources, technology access, and economic statuses." - id: PCT-1b_gdn name: guidance prose: Determine whether implementation of the initial assurance levels may create substantial or unacceptable barriers to individuals seeking to access services. - id: PCT-1c title: "Privacy, Customer Experience, Threat Resistance - Threat Resistance Impact Assessment" props: - value: 3.4.1 B class: index name: label - value: Organization class: target name: marking - value: Threat Resistance class: xal-level name: marking parts: - id: PCT-1c_smt name: statement prose: "At a minimum, organizations SHALL assess the impacts and potential unintended consequences related to Threat Resistance - Determine whether the defined assurance level and related controls will address specific threats to the online service based on the operational environment, its threat actors, and known tactics, techniques, and procedures (TTPs). Threat assessments SHALL consider specific known and potential threats, threat actors, and TTPs within the implementation environment for the identity management functions." - id: PCT-1c_obj links: - rel: assessment-for href: "#PCT-1c_smt" name: objective prose: Determine if the organization assessed the impacts and potential unintended consequences related to threat resistance. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PCT-1c_asm-examine name: assessment-method prose: "Examine the DIRM documentation indicating the final xAL selection to ensure there is an assessment of the impacts and potential unintended consequences related to threat resistance showing that the defined assurance level and related controls address: 1) specific threats to the online service based on the operation environment, 2) the threat actors of those specific threats and known TTPs." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PCT-1c_asm-interview name: assessment-method prose: "Interview the person(s) responsible for assessing the impacts and potential consequences related to privacy to determine if and how they considered specific known and potential threats, threat actors, and TTPs within the implementation environment for the identity management functions." - id: PCT-1c_gdn name: guidance prose: "For example, certain benefits programs may be more subject to familial threats or collusion. Based on their assessments, organizations MAY implement supplemental controls specific to the communities served by their online service. Conversely, organizations MAY tailor their assessed xAL down or modify their baseline controls if their threat assessment indicates that a reduced threat posture is appropriate based on their environment." - id: PCT-3 title: "Privacy, Customer Experience, Threat Resistance - Compensating and Supplemental Controls" props: - value: 3.4.1 C class: index name: label - value: Organization class: target name: marking - value: "Privacy, Customer Experience, Threat Resistance" class: xal-level name: marking parts: - id: PCT-3_smt name: statement prose: "All assessments applied during the tailoring phase SHALL be extended to any compensating or supplemental controls, as defined in Sec. 3.4.2 and Sec. 3.4.3." - id: PCT-3_obj links: - rel: assessment-for href: "#PCT-3_smt" name: objective prose: Determine if all assessments applied during the tailoring phase were extended to any identified compensating or supplemental controls. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PCT-3_asm-examine name: assessment-method prose: Examine the DIRM documentation indicating the final xAL selection to ensure all assessments applied during the tailoring phase were extended to any compensating or supplemental controls identified in ICC-1 and ISC-1. - id: PCT-3_gdn name: guidance prose: |- A compensating control is a management, operational, or technical control employed by an organization in lieu of a normative control (i.e., SHALL statements) in the defined xALs. (Ref. Sec. 3.4.2. A) The purpose of this requirement is to allow the RP to assess and determine the acceptability of the compensating controls for their use cases.(Ref. Sec. 3.4.2. C) Assessment is required when: compensating controls are implemented. Per section 3.4.2, "Organizations MAY choose to implement a compensating control if they are unable to implement a baseline control or when a risk assessment indicates that a compensating control sufficiently mitigates risk in alignment with organizational risk tolerance. This control MAY be a modification to the normative statements defined in these guidelines or MAY be applied elsewhere in an online service, digital transaction, or service life cycle." - id: PCT-4 title: "Privacy, Customer Experience, Threat Resistance - Cost-based Decision Documentation" props: - value: 3.4.1 D class: index name: label - value: Organization class: target name: marking - value: "Privacy, Customer Experience, Threat Resistance" class: xal-level name: marking parts: - id: PCT-4_smt name: statement prose: Any cost-based decisions that result in modifications to assessed xALs or baseline controls SHALL be documented in the Digital Identity Acceptance Statement (see Sec. 3.4.4). - id: PCT-4_obj links: - rel: assessment-for href: "#PCT-4_smt" name: objective prose: Determine if cost-based decisions that result in modification to assessed xALs or baseline controls are documented in the Digital Identity Acceptance Statement (DIAS). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PCT-4_asm-examine name: assessment-method prose: Examine the DIAS to ensure cost-based decisions that resulted in modification to the assessed xALs or baseline controls are documented. - id: ICC-1 title: Identify Compensating Controls - Documentation props: - value: 3.4.2 B class: index name: label - value: Organization class: target name: marking - value: "Compensating controls, Conditional" class: xal-level name: marking parts: - id: ICC-1_smt name: statement prose: "Where compensating controls are implemented, organizations SHALL document the compensating control, the rationale for the deviation, comparability of the chosen alternative, and any resulting residual risks." - id: ICC-1_obj links: - rel: assessment-for href: "#ICC-1_smt" name: objective prose: "Determine if implemented compensating controls are documented, including the rationale for the deviation, comparability of the chosen alternative, and any resulting residual risks." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ICC-1_asm-examine name: assessment-method prose: "Examine the tailoring documentation to ensure implemented compensating controls are fully documented, including the rationale for the deviation, comparability of the chosen alternative, and any resulting residual risks." - id: ICC-1_gdn name: guidance prose: |- A compensating control is a management, operational, or technical control employed by an organization in lieu of a normative control (i.e., SHALL statements) in the defined xALs. (Ref. Sec. 3.4.2. A) The purpose of this requirement is to allow the RP to assess and determine the acceptability of the compensating controls for their use cases.(Ref. Sec. 3.4.2. C) Assessment is required when: compensating controls are implemented. Per section 3.4.2, "Organizations MAY choose to implement a compensating control if they are unable to implement a baseline control or when a risk assessment indicates that a compensating control sufficiently mitigates risk in alignment with organizational risk tolerance. This control MAY be a modification to the normative statements defined in these guidelines or MAY be applied elsewhere in an online service, digital transaction, or service life cycle." - id: ICC-2 title: Identify Compensating Controls - Communication props: - value: 3.4.2 C class: index name: label - value: CSP/IdP class: target name: marking - value: "Compensating controls, Conditional" class: xal-level name: marking parts: - id: ICC-2_smt name: statement prose: CSPs and IdPs that implement compensating controls SHALL communicate this information to all potential RPs prior to integration. - id: ICC-2_obj links: - rel: assessment-for href: "#ICC-2_smt" name: objective prose: Determine if CSPs and IdPs that implement compensating controls have communicated this information to all potential RPs prior to integration. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ICC-2_asm-examine name: assessment-method prose: Examine CSP/IdP communications with all RPs and potential RPs to ensure the information regarding the implementation of those compensating controls was done prior to their integration. - id: ICC-2_gdn name: guidance prose: |- A compensating control is a management, operational, or technical control employed by an organization in lieu of a normative control (i.e., SHALL statements) in the defined xALs. (Ref. Sec. 3.4.2. A) The purpose of this requirement is to allow the RP to assess and determine the acceptability of the compensating controls for their use cases.(Ref. Sec. 3.4.2. C) Assessment is required when: compensating controls are implemented. Per section 3.4.2, "Organizations MAY choose to implement a compensating control if they are unable to implement a baseline control or when a risk assessment indicates that a compensating control sufficiently mitigates risk in alignment with organizational risk tolerance. This control MAY be a modification to the normative statements defined in these guidelines or MAY be applied elsewhere in an online service, digital transaction, or service life cycle." - id: ISC-1 title: Identify Supplemental Controls - Impact Assessment props: - value: 3.4.3 A class: index name: label - value: Organization class: target name: marking - value: Supplemental controls class: xal-level name: marking parts: - id: ISC-1_smt name: statement prose: Any supplemental controls SHALL be assessed for impacts based on the same factors used to tailor the organization's assurance level. - id: ISC-1_obj links: - rel: assessment-for href: "#ISC-1_smt" name: objective prose: Determine if supplemental controls are assessed for impacts based on the same factors used to tailor the organization's assurance level. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISC-1_asm-examine name: assessment-method prose: Examine the tailoring documentation to ensure any implemented supplemental controls have been assessed for impacts based on the same factors used to tailor the initial xALs. See TAL and PCT requirements. - id: ISC-1_gdn name: guidance prose: "Assessment is required when: supplemental controls are identified and implemented." - id: ISC-2 title: Identify Supplemental Controls - Documentation props: - value: 3.4.3 A class: index name: label - value: Organization class: target name: marking - value: Supplemental controls class: xal-level name: marking parts: - id: ISC-2_smt name: statement prose: Any supplemental controls SHALL be documented. - id: ISC-2_obj links: - rel: assessment-for href: "#ISC-2_smt" name: objective prose: Determine if supplemental controls are documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISC-2_asm-examine name: assessment-method prose: Examine the tailoring documentation to ensure implemented supplemental controls are fully documented. - id: ISC-2_gdn name: guidance prose: "Assessment is required when: supplemental controls are identified and implemented." - id: DIAS-1a title: Digital Identity Acceptance Statement - Documentation - Managed Online Services props: - value: 3.4.4 Aa class: index name: label - value: RP class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-1a_smt name: statement prose: Organizations SHALL develop a Digital Identity Acceptance Statement (DIAS) to document the results of the DIRM process for each online service managed by the organization. - id: DIAS-1a_obj links: - rel: assessment-for href: "#DIAS-1a_smt" name: objective prose: Determine if a DIAS was developed that documents the results of the DIRM process for each online service managed by the organization. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-1a_asm-examine name: assessment-method prose: Examine the DIAS to verify documentation of the DIRM process results for each online service managed by the organization. - id: DIAS-1a_gdn name: guidance prose: See DIRM-1. - id: DIAS-1b title: Digital Identity Acceptance Statement - Documentation - External Online Services props: - value: 3.4.4 Ab class: index name: label - value: RP class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-1b_smt name: statement prose: Organizations SHALL develop a Digital Identity Acceptance Statement (DIAS) to document the results of the DIRM process for each external online service used to support the mission of the organization. - id: DIAS-1b_obj links: - rel: assessment-for href: "#DIAS-1b_smt" name: objective prose: Determine if a DIAS was developed that documents the results of the DIRM process for each external online service used to support the mission of the organization. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-1b_asm-examine name: assessment-method prose: Examine the DIAS to verify documentation of the DIRM process results for each external online service used to support the mission of the organization. - id: DIAS-1b_gdn name: guidance prose: |- External online services include software-as-a-service offerings (e.g., social media platforms, email services, online marketing services). (Ref. Sec. 3.4.4.A) See DIRM-1 - id: DIAS-2 title: Digital Identity Acceptance Statement - Incorporating External DIAS Information props: - value: 3.4.4 B class: index name: label - value: RP class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-2_smt name: statement prose: RPs who intend to use a particular CSP/IdP SHALL review the latter's DIAS and incorporate relevant information into the organization's DIAS for each online service. - id: DIAS-2_obj links: - rel: assessment-for href: "#DIAS-2_smt" name: objective prose: Determine if the RP reviewed the CSP/IdP's DIAS and incorporated relevant information into the RP's DIAS for each online service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-2_asm-examine name: assessment-method prose: Examine each RP online service's DIAS for relevant information from the DIAS of the CSP/IdP the RP intends to use. - id: DIAS-2_gdn name: guidance prose: "Assessment is required when: the CSP/IdP used by the RP has created a DIAS." - id: DIAS-3 title: Digital Identity Acceptance Statement - Online Service DIAS contents props: - value: 3.4.4 C class: index name: label - value: "RP, CSP/IdP" class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-3_smt name: statement prose: |- Organizations SHALL prepare a DIAS for their online service that includes, at a minimum: (a) Initial impact assessment results; initially assessed xALs. (b) Tailored xALs and rationale if the tailored xALs differs from the initially assessed xALs. (c) All compensating controls with their comparability or residual risks. (d) All supplemental controls. - id: DIAS-3_obj links: - rel: assessment-for href: "#DIAS-3_smt" name: objective prose: "Determine if the organization's online service DIAS includes, at a minimum, initial impact assessment results, initially assessed xALs, tailored xALs and rationale if the tailored xALs differs from the initially assessed xALs, all compensating controls with their comparability or residual risks, and all supplemental controls." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-3_asm-examine name: assessment-method prose: "Examine each DIAS to ensure it includes the initial impact assessment results, initially assessed xALs, tailored xALs and rationale if the tailored xALs differs from the initially assessed xALs, all compensating controls with their comparability or residual risks, and all supplemental controls." - id: DIAS-3_gdn name: guidance prose: "Assessment is required for a CS{/IdP when: the CSP/IdP deviates from normative guidance and creates a DIAS." - id: DIAS-4 title: Digital Identity Acceptance Statement - CSP DIAS Implementation props: - value: 3.4.4 D class: index name: label - value: CSP/IdP class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-4_smt name: statement prose: "CSPs/IdPs SHALL implement the DIRM process and develop a DIAS for the services they offer if they deviate from the normative guidance in these guidelines, including when supplemental or compensating controls are added." - id: DIAS-4_obj links: - rel: assessment-for href: "#DIAS-4_smt" name: objective prose: "For CSP/IdPs that deviate from normative guidance, determine if the CSP/IdP has implemented the DIRM process and developed a DIAS for the services they offer." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-4_asm-examine name: assessment-method prose: Examine the documentation to ensure the DIRM process was implemented and a DIAS developed for their offered services. - id: DIAS-4_gdn name: guidance prose: |- Assessment is required when: the CSP/IdP deviates from normative guidance, including when supplemental or compensating controls are added. To complete a DIRM of their offered assurance levels and controls, CSPs/IdPs MAY base their assessment on anticipated or representative digital identity services that they wish to support. - id: DIAS-5 title: Digital Identity Acceptance Statement - CSP DIAS Elements props: - value: 3.4.4 E class: index name: label - value: CSP/IdP class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-5_smt name: statement prose: |- The DIAS prepared by a CSP SHALL include, at a minimum: (a) Claimed xAL, related controls, and rationale for any deviations from normative guidance; (b) All compensating controls with their comparability or residual risks; and (c) All supplemental controls. - id: DIAS-5_obj links: - rel: assessment-for href: "#DIAS-5_smt" name: objective prose: "Determine if the CSP's DIAS includes the claimed xAL, related controls, and rationale for any deviations from normative guidance, all compensating controls with their comparability or residual risks, and all supplemental controls." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-5_asm-examine name: assessment-method prose: "Examine the CSP's DIAS to ensure it includes claimed xAL, related controls, and rationale for any deviations from normative guidance, all compensating controls with their comparability or residual risks, and all supplemental controls." - id: DIAS-5_gdn name: guidance prose: "Assessment is required when: the CSP/IdP has created a DIAS (see DIAS-4)." - id: DIAS-6 title: Digital Identity Acceptance Statement - Documentation of Relevant Inputs props: - value: 3.4.4 F class: index name: label - value: "RP, CSP/IdP" class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-6_smt name: statement prose: The DIRM process for external online services used by the organization SHALL consider relevant inputs from the provider of the service and document the results in a DIAS. - id: DIAS-6_obj links: - rel: assessment-for href: "#DIAS-6_smt" name: objective prose: Determine if the DIRM process for external online services includes the results of inputs from the provider of the service are documented in a DIAS. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-6_asm-examine name: assessment-method prose: Examine the DIAS containing the results of the DIRM process for external online services used by the organization includes and documents relevant inputs from the provider of the service. - id: DIAS-6_gdn name: guidance prose: CSP's trying to meet this requirement should coordinate with the RP for the documentation. - id: DIAS-7 title: Digital Identity Acceptance Statement - External Online Services DIAS props: - value: 3.4.4 G class: index name: label - value: "RP, CSP/IdP" class: target name: marking - value: Acceptance supplement class: xal-level name: marking parts: - id: DIAS-7_smt name: statement prose: |- The DIAS prepared by the organization for external online services SHALL include, at a minimum: (a) Assessed xAL, related controls, and rationale for any deviations from normative guidance; (b) All compensating controls with their comparability or residual risks; and (c) All supplemental controls. - id: DIAS-7_obj links: - rel: assessment-for href: "#DIAS-7_smt" name: objective prose: "Determine if the DIAS for external online services includes assessed xALs, related controls, and rationale for any deviations from normative guidance, all compensating controls with their comparability or residual risks, and all supplemental controls." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIAS-7_asm-examine name: assessment-method prose: "Examine the DIAS prepared for each external online services to ensure they include assessed xALs, related controls, and rationale for any deviations from normative guidance, all compensating controls with their comparability or residual risks, and all supplemental controls." - id: DIAS-7_gdn name: guidance prose: "Assessment is required when: the CSP/IdP created a DIAS (see DIAS-4)" - id: CEI-1 title: Continuously Evaluate and Improve - Implementation props: - value: 3.5 A class: index name: label - value: "CSP/IdP, RP" class: target name: marking - value: Continuous evaluation and improvement class: xal-level name: marking parts: - id: CEI-1_smt name: statement prose: Organizations SHALL implement a continuous evaluation and improvement program that leverages input from end users who have interacted with the identity management system as well as performance metrics for the online service. - id: CEI-1_obj links: - rel: assessment-for href: "#CEI-1_smt" name: objective prose: Determine if the organization has implemented a continuous evaluation and improvement program that leverages input from end users who have interacted with the identity management system and performance metrics for the online service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CEI-1_asm-examine name: assessment-method prose: Examine documentation that describes the continuous evaluation and improvement program to ensure it leverages input from end users who have interacted with the identity management system. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CEI-1_asm-examine-2 name: assessment-method prose: Examine documentation that describes the continuous evaluation and improvement program to ensure it leverages input from performance metrics for the online service. - id: CEI-1_gdn name: guidance prose: The purpose of this control is to address the shifting environment in which they operate and more rapidly address service capability gaps. - id: CEI-2 title: Continuously Evaluate and Improve - Documentation props: - value: 3.5 B class: index name: label - value: "CSP/IdP, RP" class: target name: marking - value: Continuous evaluation and improvement class: xal-level name: marking parts: - id: CEI-2_smt name: statement prose: "This program SHALL be documented, including the metrics that are collected, the sources of data required to enable performance evaluation, and the processes in place for taking timely actions based on the continuous improvement process." - id: CEI-2_obj links: - rel: assessment-for href: "#CEI-2_smt" name: objective prose: |- Determine if the documentation includes: (a) the metrics that are collected, (b) the sources of data required to enable performance evaluation, and (c) the processes in place for taking timely actions based on the continuous improvement process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CEI-2_asm-examine name: assessment-method prose: Examine the continuous evaluation and improvement program documentation to ensure it includes all collected metrics. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CEI-2_asm-examine-2 name: assessment-method prose: Examine the continuous evaluation and improvement program documentation to ensure it includes the sources of data required to enable performance evaluation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CEI-2_asm-examine-3 name: assessment-method prose: Examine the continuous evaluation and improvement program documentation to ensure it includes the processes in place for taking timely actions based on the continuous improvement process. - id: CEI-3 title: Continuously Evaluate and Improve - Monitoring props: - value: 3.5 C class: index name: label - value: "CSP/IdP, RP" class: target name: marking - value: Continuous evaluation and improvement class: xal-level name: marking parts: - id: CEI-3_smt name: statement prose: Organizations SHALL monitor the evolving threat landscape. - id: CEI-3_obj links: - rel: assessment-for href: "#CEI-3_smt" name: objective prose: Determine if the organization is monitoring the evolving threat landscape. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CEI-3_asm-examine name: assessment-method prose: Examine the continuous evaluation and improvement program documentation to ensure it includes policies and procedures for monitoring the evolving threat landscape. - id: CEI-3_gdn name: guidance prose: The purpose of monitoring the evolving threat landscape is to stay informed of the latest threats and fraud tactics. - id: CEI-4 title: Continuously Evaluate and Improve - Assessing props: - value: 3.5 D class: index name: label - value: "CSP/IdP, RP" class: target name: marking - value: Continuous evaluation and improvement class: xal-level name: marking parts: - id: CEI-4_smt name: statement prose: Organizations SHALL regularly assess the effectiveness of current security measures and fraud detection capabilities against the latest threats and fraud tactics. - id: CEI-4_obj links: - rel: assessment-for href: "#CEI-4_smt" name: objective prose: Determine if the organization regularly assesses the effectiveness of current security measures and fraud detection capabilities against the latest threats and fraud tactics. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CEI-4_asm-examine name: assessment-method prose: Examine the continuous evaluation and improvement program documentation (policy and logs) for evidence that the effectiveness of current security measures and fraud detection capabilities against the latest threats and fraud tactics is being assessed regularly. - id: EI-1 title: Evaluation Inputs props: - value: 3.5.1 A class: index name: label - value: "CSP/IdP, RP" class: target name: marking - value: Continuous evaluation and improvement class: xal-level name: marking parts: - id: EI-1_smt name: statement prose: |- At a minimum, evaluation inputs SHALL include: (a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate; (b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups); (c) Threat analysis, threat reporting, and threat intelligence feeds that are available; (d) Fraud trends, fraud investigation results, and fraud metrics as available; and (e) The results of ongoing customer experience assessments and privacy assessments. - id: EI-1_obj links: - rel: assessment-for href: "#EI-1_smt" name: objective prose: |- Determine if the evaluation inputs include: (a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate; (b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups); (c)Threat analysis, threat reporting, and threat intelligence feeds that are available; (d) Fraud trends, fraud investigation results, and fraud metrics as available; and (e) The results of ongoing customer experience assessments and privacy assessments. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EI-1_asm-examine name: assessment-method prose: |- Examine the continuous evaluation and improvement program documentation evaluation inputs to ensure they include: (a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate; (b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups); (c) Threat analysis, threat reporting, and threat intelligence feeds that are available; (d)Fraud trends, fraud investigation results, and fraud metrics as available; and (e) The results of ongoing customer experience assessments and privacy assessments. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: EI-1_asm-test name: assessment-method prose: |- Test the continuous evaluation and improvement program to ensure it can use all the following evaluation inputs: (a) Integrated CSP, IdP, and authentication functions as well as validation, verification, and fraud management systems, as appropriate; (b) Customer feedback mechanisms, such as complaint processes, helpdesk statistics, and other user feedback (e.g., surveys, interviews, or focus groups); (c) Threat analysis, threat reporting, and threat intelligence feeds that are available; (d) Fraud trends, fraud investigation results, and fraud metrics as available; and (e) The results of ongoing customer experience assessments and privacy assessments. - id: EI-1_gdn name: guidance prose: "The purpose of control EI-1 is to fully understand the performance of their identity system, organizations will need to identify critical inputs to their continuous evaluation process." - id: EI-2 title: Evaluation Inputs - Documentation props: - value: 3.5.1 B class: index name: label - value: "CSP/IdP, RP" class: target name: marking - value: Continuous evaluation and improvement class: xal-level name: marking parts: - id: EI-2_smt name: statement prose: "RPs SHALL document their metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service to ensure that expectations are appropriately communicated to partners and vendors." - id: EI-2_obj links: - rel: assessment-for href: "#EI-2_smt" name: objective prose: "Determine if the RP has documented their metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EI-2_asm-examine name: assessment-method prose: "Examine the documents for the continuous evaluation and improvement process to ensure they include the RPs metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service." - id: EI-2_gdn name: guidance prose: "The documentation of metrics, reporting requirements, and data inputs for any CSP, IdP, or other integrated identity service is to ensure that expectations are appropriately communicated to partners and vendors." - id: RED-1 title: Redress - Issue Handling Process props: - value: 3.6 A class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-1_smt name: statement prose: "RPs and CSPs SHALL enable individuals to convey grievances and seek redress through an issue handling process that is documented, accessible, trackable, and usable by all individuals and whose instructions are easy to find on a public-facing website." - id: RED-1_obj links: - rel: assessment-for href: "#RED-1_smt" name: objective prose: |- (1) Determine if the RPs and CSPs issues handline process is: (a) Documented, (b) Accessible, (c) Trackable, (e) Usable by all individuals, and has instructions on an easy-to-find, public-facing website. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RED-1_asm-test name: assessment-method prose: "Test the issues handling process public-facing website to ensure the instructions are easy to find and follow, and the issues are documented, accessible, trackable, and usable (i.e., 508 compliant)." - id: RED-2 title: Redress - Governance Model props: - value: 3.6 B class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-2_smt name: statement prose: "RPs and CSPs SHALL institute a governance model for implementing this issue handling process, including documented roles and responsibilities." - id: RED-2_obj links: - rel: assessment-for href: "#RED-2_smt" name: objective prose: Determine if the RPs and CSPs instituted a governance model for implementing the issue handling process that includes documented roles and responsibilities. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-2_asm-examine name: assessment-method prose: Examine the issuance handling governance model documentation to ensure it includes documented roles and responsibilities. - id: RED-3a title: Redress - Issue Handling Function - Evidence Review props: - value: 3.6 C class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-3a_smt name: statement prose: The issue handling process SHALL be implemented as a dedicated function that includes procedures for impartially reviewing pertinent evidence. - id: RED-3a_obj links: - rel: assessment-for href: "#RED-3a_smt" name: objective prose: Determine if the issue handling process is implemented as a dedicated function with procedures for impartially reviewing pertinent evidence. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-3a_asm-examine name: assessment-method prose: Examine the issuance handling documentation for descriptions of how it is implemented to ensure it is implemented as a dedicated function that includes procedures for impartially reviewing pertinent evidence. - id: RED-3b title: Redress - Issue Handling Function - Additional Evidence props: - value: 3.6 C class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-3b_smt name: statement prose: The issue handling process SHALL be implemented as a dedicated function that includes procedures for requesting and collecting additional evidence that informs the issues. - id: RED-3b_obj links: - rel: assessment-for href: "#RED-3b_smt" name: objective prose: Determine if the issue handling process is implemented as a dedicated function with procedures for requesting and collecting additional evidence that informs the issues. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-3b_asm-examine name: assessment-method prose: Examine the issuance handling documentation for descriptions of how it is implemented to ensure it is implemented as a dedicated function that includes procedures for requesting and collecting additional evidence that informs the issues. - id: RED-3c title: Redress - Issue Handling Function - Resolution props: - value: 3.6 C class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-3c_smt name: statement prose: The issue handling process SHALL be implemented as a dedicated function that includes procedures for expeditiously resolving issues and determining corrective action. - id: RED-3c_obj links: - rel: assessment-for href: "#RED-3c_smt" name: objective prose: Determine if the issue handling process is implemented as a dedicated function with procedures for expeditiously resolving issues and determining corrective action. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-3c_asm-examine name: assessment-method prose: Examine the issuance handling documentation for descriptions of how it is implemented to ensure it is implemented as a dedicated function that includes procedures for expeditiously resolving issues and determining corrective action. - id: RED-4 title: Redress - Support Personnel props: - value: 3.6 D class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-4_smt name: statement prose: RPs and CSPs SHALL make human support personnel available to intervene and override issue adjudication outputs generated by algorithmic support mechanisms. - id: RED-4_obj links: - rel: assessment-for href: "#RED-4_smt" name: objective prose: Determine if RPs and CSPs have made human support personnel available to intervene and override issue adjudication outputs generated by algorithmic support mechanisms. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: RED-4_asm-interview name: assessment-method prose: Interview the human support personnel whose role is to intervene and override issue adjudication outputs generated by algorithmic support mechanisms to ensure they are available. - id: RED-5a title: Redress - Support Personnel Education - Issue Handling props: - value: 3.6 E class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-5a_smt name: statement prose: RPs and CSPs SHALL educate support personnel on issue handling procedures for the digital identity management system. - id: RED-5a_obj links: - rel: assessment-for href: "#RED-5a_smt" name: objective prose: Determine if RPs and CSPs have educated support personnel on issue handling procedures for the digital identity management system. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: RED-5a_asm-interview name: assessment-method prose: Interview the support personnel to ensure they are educated on issue handling procedures for the digital identity management system. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-5a_asm-examine name: assessment-method prose: Examine the training materials used to train the support personnel in issue handling procedures for the digital identity management system. - id: RED-5b title: Redress - Support Personnel Education - Redress props: - value: 3.6 E class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-5b_smt name: statement prose: RPs and CSPs SHALL educate support personnel on the avenues for redress. - id: RED-5b_obj links: - rel: assessment-for href: "#RED-5b_smt" name: objective prose: Determine if RPs and CSPs have educated support personnel on the avenues for redress. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: RED-5b_asm-interview name: assessment-method prose: Interview the support personnel to ensure they are educated on the avenues for redress. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-5b_asm-examine name: assessment-method prose: Examine the training materials used to train the support personnel on the avenues for redress. - id: RED-5c title: Redress - Support Personnel Education - Access Alternatives props: - value: 3.6 E class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-5c_smt name: statement prose: RPs and CSPs SHALL educate support personnel on the alternatives available to gain access to services. - id: RED-5c_obj links: - rel: assessment-for href: "#RED-5c_smt" name: objective prose: Determine if RPs and CSPs have educated support personnel on the alternatives available to gain access to services. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: RED-5c_asm-interview name: assessment-method prose: Interview the support personnel to ensure they are educated on the alternatives available to gain access to services. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-5c_asm-examine name: assessment-method prose: Examine the training materials used to train the support personnel on the alternatives available to gain access to services. - id: RED-6 title: Redress - Support Functions props: - value: 3.6 F class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-6_smt name: statement prose: RPs and CSPs SHALL implement a process for personnel and technologies that provides support functions to report and address major barriers that end users face and grievances they may have. - id: RED-6_obj links: - rel: assessment-for href: "#RED-6_smt" name: objective prose: Determine if the RP/CSP has implemented a process for personnel and technologies that provides support functions to report and address major barriers that end users face and grievances they may have. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-6_asm-examine name: assessment-method prose: Examine the issues handling process documentation to ensure it includes processes for personnel and technologies that support functions to report and address major barriers that end users face and grievances they may have. - id: RED-7 title: Redress - Continuous Evaluation and Improvement props: - value: 3.6 G class: index name: label - value: "RP, CSP" class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-7_smt name: statement prose: RPs and CSPs SHALL incorporate findings derived from the issue handling process into continuous evaluation and improvement activities. - id: RED-7_obj links: - rel: assessment-for href: "#RED-7_smt" name: objective prose: Determine if the RP/CSP has incorporated findings derived from the issue handling process into continuous evaluation and improvement activities. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-7_asm-examine name: assessment-method prose: Examine the evaluation inputs for the continuous evaluation and improvement program to ensure they incorporate findings derived from the issue handline process. - id: RED-8a title: Redress - Integrity and Performance props: - value: 3.6 Ha class: index name: label - value: Organization class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-8a_smt name: statement prose: Organizations SHALL assess the integrity and performance of their redress mechanisms. - id: RED-8a_obj links: - rel: assessment-for href: "#RED-8a_smt" name: objective prose: Determine if the integrity and performance of their redress mechanisms are being assessed. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-8a_asm-examine name: assessment-method prose: Examine the issues handling process documentation for policies and practices that describe how to assess the integrity and performance of their redress mechanisms. - id: RED-8b title: Redress - Fraud Detection props: - value: 3.6 Hb class: index name: label - value: Organization class: target name: marking - value: Redress class: xal-level name: marking parts: - id: RED-8b_smt name: statement prose: "Organizations SHALL implement controls to prevent, detect, and remediate attempted identity fraud involving those mechanisms." - id: RED-8b_obj links: - rel: assessment-for href: "#RED-8b_smt" name: objective prose: "Determine if controls to prevent, detect, and remediate attempted identity fraud involving the redress mechanisms have been implemented." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RED-8b_asm-examine name: assessment-method prose: "Examine the issues handling process documentation for policies and practices that describe the controls they implement to prevent, detect, and remediate attempted identity fraud involving those mechanisms." - id: CFI-1 title: "Cybersecurity, Fraud, and Identity Program Integrity - Information Exchange" props: - value: 3.7 A class: index name: label - value: Organization class: target name: marking - value: Program Integrity class: xal-level name: marking parts: - id: CFI-1_smt name: statement prose: Organizations SHALL establish consistent mechanisms for the exchange of information between stakeholders that are responsible for critical internal security and fraud prevention. - id: CFI-1_obj links: - rel: assessment-for href: "#CFI-1_smt" name: objective prose: Determine if consistent mechanisms for the exchange of information between stakeholders that are responsible for critical internal security and fraud prevention have been established. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CFI-1_asm-examine name: assessment-method prose: Examine mechanisms used for the exchange of information between stakeholders that are responsible for critical internal security and fraud prevention. - id: CFI-2 title: "Cybersecurity, Fraud, and Identity Program Integrity - Privacy Assessment" props: - value: 3.7 B class: index name: label - value: CSP/IdP class: target name: marking - value: Program Integrity class: xal-level name: marking parts: - id: CFI-2_smt name: statement prose: "All data collected, transmitted, or shared by the identity service provider SHALL be subject to a detailed privacy and legal assessment by either the entity generating the data (e.g., a CSP) or the related RP for whom the service is provided." - id: CFI-2_obj links: - rel: assessment-for href: "#CFI-2_smt" name: objective prose: "Determine if all data collected, transmitted, or shared by the identity service provider is subject to a detailed privacy and legal assessment." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CFI-2_asm-examine name: assessment-method prose: "Examine privacy and legal assessments to ensure one exists for all data collected, transmitted, or shared by the identity service provider," - id: CFI-2_gdn name: guidance prose: "The privacy and legal assessment can be done by either the entity generating the data (e.g., a CSP) or the related RP for whom the service is provided." - id: AIML-1a title: Artificial Intelligence and Machine Learning in Identity Systems - Documentation props: - value: 3.8 A class: index name: label - value: Organization class: target name: marking - value: "AI, ML, Artificial Intelligence, Machine Learning" class: xal-level name: marking parts: - id: AIML-1a_smt name: statement prose: "All uses of AI/ML [in the identity system] SHALL be documented." - id: AIML-1a_obj links: - rel: assessment-for href: "#AIML-1a_smt" name: objective prose: Determine if all uses of AI/ML in the identity system have been documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AIML-1a_asm-examine name: assessment-method prose: Examine documentation describing all uses of AI/ML. - id: AIML-1b title: Artificial Intelligence and Machine Learning in Identity Systems - Communication props: - value: 3.8 A class: index name: label - value: Organization class: target name: marking - value: "AI, ML, Artificial Intelligence, Machine Learning" class: xal-level name: marking parts: - id: AIML-1b_smt name: statement prose: "All uses of AI/ML [in the identity system] SHALL be communicated to organizations that rely on these systems." - id: AIML-1b_obj links: - rel: assessment-for href: "#AIML-1b_smt" name: objective prose: Determine if all uses of AI/ML in the identity system have been communicated to organizations that rely on these systems. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AIML-1b_asm-examine name: assessment-method prose: Examine communications to ensure all uses of AI/ML in the identity system have been communicated to organizations that rely on them. - id: AIML-2 title: Artificial Intelligence and Machine Learning in Identity Systems - Disclosure to RPs props: - value: 3.8 B class: index name: label - value: "CSP, IdP, Verifier" class: target name: marking - value: "AI, ML, Artificial Intelligence, Machine Learning" class: xal-level name: marking parts: - id: AIML-2_smt name: statement prose: "The use of integrated technologies that leverage AI/ML by CSPs, IdPs, or verifiers SHALL be disclosed to all RPs that make access decisions based on information from these systems." - id: AIML-2_obj links: - rel: assessment-for href: "#AIML-2_smt" name: objective prose: Determine if the use of integrated technologies that leverage AI/ML is disclosed to all RPs that make access decisions based on information from these systems. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AIML-2_asm-examine name: assessment-method prose: Examine communications from CSP/IdPs to RPs that make access decisions based on information from systems to ensure disclosure of any use of integrated technologies that leverage AI/ML. - id: AIML-3a title: Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information - Training Methods props: - value: 3.8 C class: index name: label - value: Organization class: target name: marking - value: "AI, ML, Artificial Intelligence, Machine Learning" class: xal-level name: marking parts: - id: AIML-3a_smt name: statement prose: "All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] the methods and techniques used for training their models." - id: AIML-3a_obj links: - rel: assessment-for href: "#AIML-3a_smt" name: objective prose: Determine if methods and techniques used for training AI/ML models have been provided to the entities using the AI/ML technology. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AIML-3a_asm-examine name: assessment-method prose: Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes the methods and techniques used for training their AI/ML models. - id: AIML-3b title: Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information - Training Data Sets props: - value: 3.8 C class: index name: label - value: Organization class: target name: marking - value: "AI, ML, Artificial Intelligence, Machine Learning" class: xal-level name: marking parts: - id: AIML-3b_smt name: statement prose: "All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] a description of the data sets used in training." - id: AIML-3b_obj links: - rel: assessment-for href: "#AIML-3b_smt" name: objective prose: Determine if a description of the data sets used in training the AI/ML models have been provided to the entities using the AI/ML technology. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AIML-3b_asm-examine name: assessment-method prose: Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes a description of the data sets used in training. - id: AIML-3c title: Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information - Updates props: - value: 3.8 C class: index name: label - value: Organization class: target name: marking - value: "AI, ML, Artificial Intelligence, Machine Learning" class: xal-level name: marking parts: - id: AIML-3c_smt name: statement prose: "All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] the frequency of model updates." - id: AIML-3c_obj links: - rel: assessment-for href: "#AIML-3c_smt" name: objective prose: Determine if the frequency of AI/ML model updates have been provided to the entities using the AI/ML technology. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AIML-3c_asm-examine name: assessment-method prose: Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes the frequency of model updates. - id: AIMLIS-3d title: Artificial Intelligence and Machine Learning in Identity Systems - AI/ML Model Information - Algorithm Testing props: - value: 3.8 C class: index name: label - value: Organization class: target name: marking - value: "AI, ML, Artificial Intelligence, Machine Learning" class: xal-level name: marking parts: - id: AIMLIS-3d_smt name: statement prose: "All organizations that use AI/ML SHALL provide information to any entities that use their technology [including] the results of all testing completed on their algorithms." - id: AIMLIS-3d_obj links: - rel: assessment-for href: "#AIMLIS-3d_smt" name: objective prose: Determine if the results of all testing completed on their AI/ML algorithms have been provided to the entities using the AI/ML technology. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AIMLIS-3d_asm-examine name: assessment-method prose: Examine AI/ML documentation that is shared with entities that use their technology to ensure it includes the results of all testing completed on their algorithms. - class: revision id: revision-63A title: 63A controls: - id: IDPRF-1 title: Risk Evaluation props: - value: 2.0 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-1_smt name: statement prose: "CSPs SHALL evaluate the risks associated with each identity proofing option offered (e.g., identity proofing types, validation sources, assistance mechanisms) and implement mitigating fraud controls, as appropriate." - id: IDPRF-1_obj links: - rel: assessment-for href: "#IDPRF-1_smt" name: objective prose: Confirm that the CSP has assessed the risks associated with each identity proofing option offered and that they have employed appropriate mitigations to address those risks. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-1_asm-examine name: assessment-method prose: "Examine the CSP's risk assessment results and confirm it has assessed the risks associated with each identity proofing option offered and has implemented mitigating fraud controls, as appropriate." - id: IDPRF-1_gdn name: guidance prose: CSPs are likely to provide different options for how applicants can complete the identity proofing process. This control ensures a risk assessment process is in place to evaluate these options and identify and address unique risks. It can be done as part of the DIRM process defined in NIST SP 800-63-4 or an organizational specific risk management process. - id: IDPRF-2 title: Design Options props: - value: 2.0 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-2_smt name: statement prose: "At a minimum, CSPs SHALL design each option such that the options provide comparable assurance in aggregate." - id: IDPRF-2_obj links: - rel: assessment-for href: "#IDPRF-2_smt" name: objective prose: Confirm that the CSP has designed its identity services so that no identity proofing pathway (sequence of actions) results in a lower level of assurance than another. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-2_asm-examine name: assessment-method prose: Examine the CSP's documentation to confirm that the risk assessment identifies the risks unique to each identity proofing option and that the risks have been mitigated sufficiently to provide comparable assurance. - id: IDPRF-3 title: Identify Roles props: - value: 2.1.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-3_smt name: statement prose: CSPs SHALL identify which roles are applicable to their identity service. - id: IDPRF-3_obj links: - rel: assessment-for href: "#IDPRF-3_smt" name: objective prose: Confirm that the CSP has identified the roles that are employed as part of its identity proofing service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the roles it employs in its identity service. - id: IDPRF-3_gdn name: guidance prose: "Identity proofing roles are proofing agent, trusted referee, applicant reference, and process assistant." - id: IDPRF-4 title: Training props: - value: 2.1.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-4_smt name: statement prose: CSPs SHALL provide training and support resources consistent with the requirements and expectations provided in Sec. 3. - id: IDPRF-4_obj links: - rel: assessment-for href: "#IDPRF-4_smt" name: objective prose: Confirm that individuals with defined identity proofing roles are properly trained and provided with the resources they need to be effective in performing their identity proofing roles. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-4_asm-examine name: assessment-method prose: "Examine the CSP's documentation to confirm the CSP provides appropriate training and resources to persons performing identity proofing roles, consistent with the summary and references in SP 800-63A-4, Appendix B, Table 7." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IDPRF-4_asm-interview name: assessment-method prose: "Interview persons performing identity proofing roles for the CSP to identify what training and resources have been provided, and verify they satisfy the summary and references in SP 800-63A-4, Appendix B, Table 7." - id: IDPRF-5 title: Government Identifier props: - value: 2.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-5_smt name: statement prose: CSPs SHALL include a government identifier as a part of its core attributes. - id: IDPRF-5_obj links: - rel: assessment-for href: "#IDPRF-5_smt" name: objective prose: Determine that CSPs require the collection of a government identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-5_asm-examine name: assessment-method prose: Examine the CSPs documentation to confirm their set of core attributes includes a unique identifier that is associated with the applicant in government records. - id: IDPRF-5_gdn name: guidance prose: "A government identifier is a unique identifier that is associated with the applicant in government records (e.g., Social Security number, driver's license number, passport number)." - id: IDPRF-6 title: Document props: - value: 2.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-6_smt name: statement prose: The CSP and RP SHALL document all core attributes in trust agreements and practice statements. - id: IDPRF-6_obj links: - rel: assessment-for href: "#IDPRF-6_smt" name: objective prose: Confirm that agreements between CSPs and RPs include the CSP's set of core attributes so that an RP can make risk-based decisions about using a CSP's identity service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-6_asm-examine name: assessment-method prose: "Examine trust agreements, contracts, or practices statements to confirm they include the list of attributes a CSP considers as it core attributes." - id: IDPRF-7 title: FAIR Evidence props: - value: 2.4.1.1 class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-7_smt name: statement prose: "To be considered FAIR, identity evidence SHALL meet all the requirements in Sec. 2.4.1.1." - id: IDPRF-7_obj links: - rel: assessment-for href: "#IDPRF-7_smt" name: objective prose: Confirm that the CSP has documented the types of FAIR evidence it considers acceptable and provided justifications for each based on defined requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP only accepts types of FAIR evidence that meet the requirements provided in Sec. 2.4.1.1. - id: IDPRF-8 title: STRONG Evidence props: - value: 2.4.1.2 class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-8_smt name: statement prose: "To be considered STRONG, identity evidence SHALL meet all the requirements in Sec. 2.4.1.2." - id: IDPRF-8_obj links: - rel: assessment-for href: "#IDPRF-8_smt" name: objective prose: Determine that the CSP has documented the types of STRONG evidence it considers acceptable and provided justifications for each based on defined requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP only accepts types of STRONG evidence that meet the requirements provided in Sec. 2.4.1.2. - id: IDPRF-9 title: SUPERIOR Evidence props: - value: 2.4.1.3 class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-9_smt name: statement prose: "To be considered SUPERIOR, identity evidence SHALL meet all the requirements in Sec. 2.4.1.3." - id: IDPRF-9_obj links: - rel: assessment-for href: "#IDPRF-9_smt" name: objective prose: Determine that the CSP has documented the types of SUPERIOR evidence it considers acceptable and provided justifications for each based on defined requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP only accepts types of SUPERIOR evidence that meet the requirements provided in Sec. 2.4.1.3. - id: IDPRF-10 title: Evidence Validation props: - value: 2.4.2.1 class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-10_smt name: statement prose: "The CSP SHALL validate the authenticity, accuracy, and validity of presented evidence by confirming that: the evidence is in the correct format and includes complete information for the identity evidence type; the evidence does not show signs of being counterfeit or tampered with; the evidence contains physical or digital security features; and the core attributes and data fields necessary to determine authenticity on the evidence are accurate." - id: IDPRF-10_obj links: - rel: assessment-for href: "#IDPRF-10_smt" name: objective prose: "Determine that the CSP validates all collected evidence according to a systematic and repeatable process that ensures its authenticity, accuracy, and validity." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to confirm that its process for validating identity evidence meets all the criteria provided in Sec. 2.4.2.1. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IDPRF-10_asm-interview name: assessment-method prose: Interview appropriate agents of the CSP to determine how presented identity evidence is validated. - id: IDPRF-11 title: Attribute Validation props: - value: 2.4.2.3 class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-11_smt name: statement prose: "The CSP SHALL validate all core attributes, whether obtained from identity evidence or self-asserted by the applicant, with an authoritative or credible source." - id: IDPRF-11_obj links: - rel: assessment-for href: "#IDPRF-11_smt" name: objective prose: All core attributes are validated against authoritative or credible sources to confirm they are accurate. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-11_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its processes and sources for validating the different types of core attributes. - id: IDPRF-12 title: Validation Sources props: - value: 2.4.2.4 class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-12_smt name: statement prose: "The CSP SHALL use authoritative or credible sources that meet [the criteria provided in Sec. 2.4.2.4]." - id: IDPRF-12_obj links: - rel: assessment-for href: "#IDPRF-12_smt" name: objective prose: CSPs use appropriate sources to validate core attributes and identity evidence. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-12_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to confirm all authoritative and credible sources meet the criteria provided in Sect. 2.4.2.4. - id: IDPRF-12_gdn name: guidance prose: "An authoritative source is the issuing source of identity evidence or attributes or has direct access to the information maintained by issuing sources. A credible source has access to attribute information that can be traced to an authoritative source or maintains identity attribute information obtained from multiple sources that is correlated for accuracy, consistency, and currency." - id: IDPRF-13 title: ID Verification Methods props: - value: 2.5.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-13_smt name: statement prose: "The CSP SHALL verify the linkage between the claimed identity to the applicant engaged in the identity proofing process through one or more of the [methods provided in Sec. 2.5.1]." - id: IDPRF-13_obj links: - rel: assessment-for href: "#IDPRF-13_smt" name: objective prose: CSPs employ proven methods to perform identity verification. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-13_asm-examine name: assessment-method prose: Examine the CSP's documentation to determine the method or methods it uses to perform identity verification. - id: IDPRF-13_gdn name: guidance prose: "Acceptable identity verification methods include, Confirmation code verification, Authentication and federation protocols, Transaction verification, Visual facial image comparison for on-site attended, and Visual facial image comparison for remote attended or remote unattended. Additional requirements on acceptable methods are addressed per assurance level." - id: IDPRF-14 title: KBV props: - value: 2.5.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRF-14_smt name: statement prose: Knowledge-based verification (KBV) or knowledge-based authentication SHALL NOT be used for identity verification. - id: IDPRF-14_obj links: - rel: assessment-for href: "#IDPRF-14_smt" name: objective prose: Confirm that the CSP does not employ KBV or KBA as part of its identity verification process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRF-14_asm-examine name: assessment-method prose: Examine the CSP's documentation to determine it does not employ KBV or KBA during the identity verification process. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRF-14_asm-test name: assessment-method prose: Test the identity proofing workflow to confirm KBV or KBA is not employed for identity verification. - id: IDPRF-14_gdn name: guidance prose: "Because KBV can be easily subverted, it is not a suitable method for identity verification. However, CSPs may employ KBV as part of fraud management processes. Note that applicants may provide self-asserted attributes during the identity proofing process. Provided the CSP validates these self-asserted attributes with an authoritative or credible source, they may be used by the CSP as core attributes for identity resolution and communication with RPs. However, the CSP may not use the applicant's knowledge of these attributes as evidence the applicant is who they claim to be." - id: ISDR-1 title: Documented Procedures Policy props: - value: 3.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-1_smt name: statement prose: The CSP SHALL conduct its operations according to documented procedures or a practice statement that details all identity proofing processes as they are implemented to achieve the defined IAL. - id: ISDR-1_obj links: - rel: assessment-for href: "#ISDR-1_smt" name: objective prose: Confirm that the CSP has documented its procedures to achieve the defined IALs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the processes it employs to achieve a defined IAL. - id: ISDR-2 title: Service Description Policy props: - value: "3.1 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-2_smt name: statement prose: The CSP's documented procedures SHALL include a complete service description including the particular steps that it follows to identity-proof applicants at each offered assurance level. - id: ISDR-2_obj links: - rel: assessment-for href: "#ISDR-2_smt" name: objective prose: Confirm that the CSP has documented the particular steps it employs to identity proof applicants at each offered assurance level. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it has documented the steps it follows to identity proof applicants at a specified assurance level. - id: ISDR-2_gdn name: guidance prose: Documentation of the complete service description allows CSPs to communicate to RPs and others the scope and components of their services and how they achieve specific IALs. - id: ISDR-3 title: Notice Policy props: - value: "3.1 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-3_smt name: statement prose: "The CSP's documented procedures SHALL include its policy for providing notice to applicants about the types of identity proofing processes available, the evidence and attribute collection requirements for the IALs offered by the CSP, the purpose for collecting personal information, and the purposes for collecting, using, and retaining biometrics." - id: ISDR-3_obj links: - rel: assessment-for href: "#ISDR-3_smt" name: objective prose: "Confirm that the CSP has documented its procedures for providing notice to applicants, as specified in item #2 of Sec. 3.1." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its applicant notice policies. - id: ISDR-3_gdn name: guidance prose: "Notice is essential to promoting informed decision-making while conducting identity proofing processes. Since CSPs collect sensitive information, documented set of policies supports informed consent from applicants before engaging with the service." - id: ISDR-4 title: Timeliness Policy props: - value: "3.1 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-4_smt name: statement prose: The CSP's documented procedures SHALL include its policy for ensuring that the identity proofing process concludes in a timely manner once the applicant has met all of the requirements. - id: ISDR-4_obj links: - rel: assessment-for href: "#ISDR-4_smt" name: objective prose: Confirm that the CSP has a documented policy for ensuring the identity proofing process concludes in a timely manner. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for the timely conclusion of the identity proofing process. - id: ISDR-4_gdn name: guidance prose: Lack of timeliness results in the degradation of mission delivery as it affects the ability of the organization to perform mission functions and increases burden on applicants seeking services. Providing policies for the timely completion of identity proofing services sets expectations for RPs and enables communication to applicants about the anticipated timing of the process. - id: ISDR-5 title: Evidence Policy props: - value: "3.1 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-5_smt name: statement prose: The CSP's documented procedures SHALL include the types of evidence that it accepts and the justification for how the evidence fulfills the strength requirements of the level at which it will be accepted by the CSP. - id: ISDR-5_obj links: - rel: assessment-for href: "#ISDR-5_smt" name: objective prose: Confirm that the CSP has documented the types of evidence it accepts and the justification for how the evidence fulfills the strength requirements of the specified IAL. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the types of evidence it accepts and the justification for how the types fulfill the strength requirements for the specified IAL. - id: ISDR-5_gdn name: guidance prose: "The policy for identity evidence collection and classification of evidence acceptance allows open communication between the CSP and the RP, which can then be communicated to the applicant to build trust between the applicant and RP as the identity evidence collection is a sensitive process." - id: ISDR-6 title: Verification Policy props: - value: "3.1 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-6_smt name: statement prose: "The CSP's documented procedures SHALL include its policy and process for validating and verifying identity evidence, including training and qualification requirements for personnel who serve in identity proofing roles." - id: ISDR-6_obj links: - rel: assessment-for href: "#ISDR-6_smt" name: objective prose: "Confirm that the CSP has documented its policy and process for validating and verifying evidence, including any training and qualification requirements for proofing agents." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-6_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its evidence validation and verification policies, and polices for training and qualifying proofing agents or other personnel." - id: ISDR-6_gdn name: guidance prose: The CSP documenting policy and process for validating and verifying identity evidence offers knowledge for the RP that may be employed for communication to the applicant. - id: ISDR-7 title: Technology Policy props: - value: "3.1 #6" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-7_smt name: statement prose: The CSP's documented procedures SHALL include the specific technologies that the CSP employs for evidence validation and verification. - id: ISDR-7_obj links: - rel: assessment-for href: "#ISDR-7_smt" name: objective prose: Confirm that the CSP documents the technologies it uses for evidence validation and verification. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the technologies it uses for evidence validation and verification. - id: ISDR-7_gdn name: guidance prose: Documenting the details of specific technologies that the CSP uses opens the doors for the RP to determine if they are adequate for them as well as communicating to the end-user what technology and services will have access to their identity evidence. - id: ISDR-8 title: Exception Handling Policy props: - value: "3.1 #7" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-8_smt name: statement prose: The CSP's documented procedures SHALL include its policy and processes for supporting applicants who lack sufficient identity evidence for the required IAL and for addressing identity proofing exceptions and errors. - id: ISDR-8_obj links: - rel: assessment-for href: "#ISDR-8_smt" name: objective prose: "Confirm that the CSP has documented procedures for exception handling and identity proofing errors, including for the identity proofing of applicants who lack the required identity evidence." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-8_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its procedures for exception handling and identity proofing errors, including for the identity proofing of applicants who lack the required identity evidence." - id: ISDR-8_gdn name: guidance prose: The CSPs outlining support mechanisms for applicants that lack evidence or have exceptions or errors allow the RPs to serve the end-user while ensuring that the identity is valid and informs them of what is required of them. - id: ISDR-9 title: Attributes Validation Policy props: - value: "3.1 #8" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-9_smt name: statement prose: The CSP's documented procedures SHALL include the attributes that it considers to be core attributes and the authoritative and credible sources it uses for validating those attributes. - id: ISDR-9_obj links: - rel: assessment-for href: "#ISDR-9_smt" name: objective prose: Confirm that the CSP has documented the attributes it considers to be core attributes and the validation sources it uses to validate those attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the attributes it considers to be core attributes and the validation sources it uses to validate those attributes - id: ISDR-9_gdn name: guidance prose: The CSPs outlining support mechanisms for applicants that lack evidence or have exceptions or errors allow the RPs to serve the end-user while ensuring that the identity is valid and informs them of what is required of them. - id: ISDR-10 title: Service Change Policy props: - value: "3.1 #9" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-10_smt name: statement prose: "The CSP's documented procedures SHALL include the CSP's policy for managing and communicating service changes to RPs, such as changes in data sources, integrated vendors, or biometric algorithms." - id: ISDR-10_obj links: - rel: assessment-for href: "#ISDR-10_smt" name: objective prose: Confirm that the CSP has documented policies for managing and communicating service changes to the RPs that use its service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for managing and communicating changes to its service to its RPs. - id: ISDR-10_gdn name: guidance prose: The CSPs outlining support mechanisms for applicants that lack evidence or have exceptions or errors allows the RPs to serve the end-user while ensuring that the identity is valid and informing them of what is required of them. - id: ISDR-11 title: Fraud Management Policy props: - value: "3.1 #10" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-11_smt name: statement prose: "The CSP's documented procedures SHALL include its approach to fraud management, including its policy and process for identifying and remediating suspected or confirmed fraudulent accounts and communicating such information to RPs and affected individuals." - id: ISDR-11_obj links: - rel: assessment-for href: "#ISDR-11_smt" name: objective prose: "Confirm the CSP has documented its fraud management procedures, including its policy and process for identifying and remediating suspected or confirmed fraudulent accounts and communicating such information to RPs and affected individuals." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-11_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its fraud management procedures, including its remediation and communication policies and processes." - id: ISDR-11_gdn name: guidance prose: "CSP documentation of the fraud management approach allows the RP to be informed on the status of its end users and policies that determine the state of its users' accounts, as well as allowing them to be informed and communicative of any effects that the fraud management process has on the end users' account." - id: ISDR-12 title: Reverification Policy props: - value: "3.1 #11" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-12_smt name: statement prose: The CSP's documented procedures SHALL include its policy for any conditions that would require reverification of the user. - id: ISDR-12_obj links: - rel: assessment-for href: "#ISDR-12_smt" name: objective prose: Confirm that the CSP has documented policies on any conditions that require the reverification of the subscriber already enrolled in its identity service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-12_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policies on subscriber reverification. - id: ISDR-12_gdn name: guidance prose: "Examples of reverification include account recovery, account abandonment, and regulatory \"recertification\" requirements. Documentation of this allows RPs to inform end-users of these processes, the status of the accounts, what triggers them, and enables the RP to communicate any changes desired to the CSP." - id: ISDR-13 title: Privacy Risk Policy props: - value: "3.1 #12" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-13_smt name: statement prose: "The CSP's documented procedures SHALL include its policy for conducting privacy risk assessments, including the timing of its periodic reviews and specific conditions that will trigger an updated privacy risk assessment." - id: ISDR-13_obj links: - rel: assessment-for href: "#ISDR-13_smt" name: objective prose: "Confirm the CSP has documented its policy for conducting risk assessments, including the timing of its periodic reviews and specific conditions that will trigger an updated privacy risk assessment." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-13_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its risk assessment policies. - id: ISDR-13_gdn name: guidance prose: "Communicating this policy ensures that the RPs are aware of the privacy risks that could affect end-users, potentially communicate to them those results, and allows the RPs and CSP to work together on changes based on the results." - id: ISDR-14 title: Customer Experience Assessment Policy props: - value: "3.1 #13" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-14_smt name: statement prose: "The CSP's documented procedures SHALL include its policy for assessing customer experience, including the testing methods employed, timing of its periodic reviews, and any specific conditions that will trigger an out-of-cycle review." - id: ISDR-14_obj links: - rel: assessment-for href: "#ISDR-14_smt" name: objective prose: "Confirm the CSP has a documented policy for assessing customer experience, including the testing methods employed, timing of its periodic reviews, and any specific conditions that will trigger an out-of-cycle review." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-14_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policies for assessing customer experience. - id: ISDR-14_gdn name: guidance prose: "These procedures and the results of them can be used by the RP to determine if any changes need to be made to promote continuous improvement and address concerns, which ultimately improves the end-user experience." - id: ISDR-15 title: Data Deletion Policy props: - value: "3.1 #14" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-15_smt name: statement prose: "The CSP's documented procedures SHALL include its policy for the retention, protection, and deletion of all personal, sensitive, and biometric data, including the treatment of all such data if the CSP ceases operation or merges or transfers operations to another CSP." - id: ISDR-15_obj links: - rel: assessment-for href: "#ISDR-15_smt" name: objective prose: "Confirm the CSP has documented policies for the retention, protection, and deletion of all personal, sensitive, and biometric data, including the treatment of all such data if the CSP ceases operation or merges or transfers operations to another CSP." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-15_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its data management policies. - id: ISDR-16 title: Continuous Assessment Policy props: - value: "3.1 #15" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-16_smt name: statement prose: The CSP's documented procedures SHALL include its policy for reporting and updating performance metrics. - id: ISDR-16_obj links: - rel: assessment-for href: "#ISDR-16_smt" name: objective prose: Confirm that the CSP has documented policies for reporting and updating performance metrics. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-16_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policies for reporting and updating performance metrics. - id: ISDR-16_gdn name: guidance prose: "Meeting performance metrics starts with standardizing how it is reported and updated, as it is critical to RPs in being able to provide an adequate system and interface to the end-user, and communicate any changes as a result." - id: ISDR-17 title: Digital Estate Policy props: - value: "3.1 #16" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-17_smt name: statement prose: The CSP's documented procedures SHALL include its policy for accessing or removing a subscriber's account in the event of their death or incapacitation. - id: ISDR-17_obj links: - rel: assessment-for href: "#ISDR-17_smt" name: objective prose: Confirm that the CSP has documented policies for the access or removal of a subscriber's account in the event of their death or incapacitation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-17_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its digital estate policies. - id: ISDR-18 title: Documentation Availability props: - value: 3.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ISDR-18_smt name: statement prose: CSPs SHALL make their documented procedures or practice statements available to RPs that use their identity service. - id: ISDR-18_obj links: - rel: assessment-for href: "#ISDR-18_smt" name: objective prose: Confirm that the CSP makes its practices statement or other documentation available to the RPs that use its services. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ISDR-18_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy on communicating its procedures with the RPs that use its service. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: ISDR-18_asm-interview name: assessment-method prose: Interview RPs to determine if the appropriate documentation has been made available. - id: ISDR-18_gdn name: guidance prose: CSPs maintaining the transparency and availability of their statements and procedures creates a proactive environment between CSPs and RPs where the end-users are served. - id: FRAUD-1 title: Fraud Mgmt Program props: - value: "3.2.1 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-1_smt name: statement prose: "CSPs SHALL establish and maintain a fraud management program that provides fraud identification, detection, investigation, reporting, and resolution capabilities. The specific capabilities and details of this program SHALL be documented within their CSP practice statement." - id: FRAUD-1_obj links: - rel: assessment-for href: "#FRAUD-1_smt" name: objective prose: Determine that CSPs proactively manage risks associated with fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation for details about its fraud management program. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-1_asm-interview name: assessment-method prose: Interview appropriate personnel to obtain details about the CSP's fraud management program. - id: FRAUD-1_gdn name: guidance prose: "A critical aspect of the identity proofing process is to mitigate fraudulent attempts to gain access to benefits, services, data, or assets that are protected by identity management systems. Resolution, validation, and verification processes are designed to mitigate many types of attacks. However, with the constantly changing threat environment, layering additional checks and controls can provide increased confidence in proofing identities and additional protections against advanced and emerging types of attacks. The ability to identify, detect, and resolve instances of potential fraud is a critical functionality for CSPs and RPs." - id: FRAUD-2 title: Fraud Privacy Risk Assessment props: - value: "3.2.1 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-2_smt name: statement prose: CSPs SHALL conduct a privacy risk assessment of all fraud checks and fraud mitigation technologies prior to implementation. - id: FRAUD-2_obj links: - rel: assessment-for href: "#FRAUD-2_smt" name: objective prose: Determine that the CSP assesses the privacy risks associated with employing fraud management mechanisms. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-2_asm-examine name: assessment-method prose: Examine the documented results of CSP's privacy risk assessment of the fraud checks and mitigation technologies it employs as part of its identity service. - id: FRAUD-3 title: Fraud Self-Reporting props: - value: "3.2.1 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-3_smt name: statement prose: The CSP SHALL establish a self-reporting mechanism and investigation capability for subjects who believe they have been the victim of fraud or an attempt to compromise their involvement in the identity proofing processes. - id: FRAUD-3_obj links: - rel: assessment-for href: "#FRAUD-3_smt" name: objective prose: Confirm that the CSP provides a mechanism for users to self-report if they believe they have been a victim of fraud or an attempt to compromise their involvement in the identity proofing process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-3_asm-examine name: assessment-method prose: Examine the CSP's design document or documented procedures for details about how users can self-report potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-3_asm-interview name: assessment-method prose: Interview appropriate personnel to obtain details about the CSP's fraud self-reporting mechanisms. - id: FRAUD-4 title: High Risk Channels props: - value: "3.2.1 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-4_smt name: statement prose: "CSPs SHALL analyze all remote proofing communication channels to look for high-risk indicators (e.g., blocklisted proxies and IP addresses)." - id: FRAUD-4_obj links: - rel: assessment-for href: "#FRAUD-4_smt" name: objective prose: Confirm that the CSP monitors ID proofing communication channels for indicators of fraud or attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-4_asm-examine name: assessment-method prose: Examine the CSP's design documentation or its documented procedures to determine that it monitors and analyzes all remote ID proofing communication channels for evidence of fraudulent activity or attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-4_asm-interview name: assessment-method prose: Interview appropriate personnel to determine how the CSP monitors its remote ID proofing channels for indicators of fraud or attacks. - id: FRAUD-5 title: Data Washing props: - value: "3.2.1 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-5_smt name: statement prose: The CSP SHALL take measures to prevent unsuccessful applicants from inferring the accuracy of any self-asserted information with that confirmed by authoritative or credible sources. - id: FRAUD-5_obj links: - rel: assessment-for href: "#FRAUD-5_smt" name: objective prose: Determine the measures a CSP takes to prevent attackers from determining the accuracy of self-asserted information that has been compared to authoritative or credible sources as part of the validation step. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-5_asm-examine name: assessment-method prose: Examine the CSP's design documentation or practices statement to determine the measures a CSP employs to prevent attackers from determining the accuracy of self-asserted information that has been compared to authoritative or credible sources as part of the validation step. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FRAUD-5_asm-test name: assessment-method prose: Test by initiating an identity proofing session and self-asserting attributes. Confirm that no information is revealed that can aid in determining the accuracy of submitted attributes. - id: FRAUD-5_gdn name: guidance prose: "This is often called \"data washing\" and typically occurs when an attacker manipulates or cleans up stolen attribute information to make it appear legitimate by removing inconsistencies or red flags that might trigger fraud detection systems. Data washing can be prevented through a number of methods, depending on the interfaces deployed by a CSP. As such, these guidelines do not dictate specific mechanisms to prevent this practice." - id: FRAUD-6 title: Fraud Check Monitoring props: - value: "3.2.1 #6" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-6_smt name: statement prose: CSPs SHALL monitor the performance of their fraud checks and fraud mitigation technologies to ensure continued effectiveness in mitigating fraud risks. - id: FRAUD-6_obj links: - rel: assessment-for href: "#FRAUD-6_smt" name: objective prose: Determine that the CSP monitors the effectiveness of their fraud mitigation measures in addressing new and changing types of fraud and attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-6_asm-examine name: assessment-method prose: Examine the CSP's design documentation or other documentation to determine that the CSP monitors the performance of its fraud management measures. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-6_asm-interview name: assessment-method prose: Interview appropriate personnel to determine the CSP's approach to monitoring the effectiveness of its fraud management measures. - id: FRAUD-7 title: Fraud Communication props: - value: "3.2.1 #7" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-7_smt name: statement prose: CSPs SHALL establish a technical or process-based mechanism to communicate suspected and confirmed fraudulent events to RPs. - id: FRAUD-7_obj links: - rel: assessment-for href: "#FRAUD-7_smt" name: objective prose: Determine that the CSP has a process for communicating incidents of suspected or confirmed fraud to its RPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the CSP's process for communicating instances of suspected or confirmed fraud to its RPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-7_asm-interview name: assessment-method prose: Interview appropriate personnel to determine the CSP's process for communicating instances of suspected or confirmed fraud to its RPs. - id: FRAUD-8 title: Death Records Check props: - value: "3.2.1 #8" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-8_smt name: statement prose: "CSPs SHALL implement a death records check for all identity proofing processes by confirming with a credible, authoritative, or issuing source that the applicant is not deceased." - id: FRAUD-8_obj links: - rel: assessment-for href: "#FRAUD-8_smt" name: objective prose: Determine that the CSP checks against a death record repository to confirm that an applicant is not claiming to be someone who has died. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine how the CSP conducts its death records check. - id: FRAUD-8_gdn name: guidance prose: |- Death records are typically maintained by state and local vital records offices. The Social Security Administration (SSA) also collects and manages death information for its programs, but it does not hold comprehensive records of all deaths in the country. Checking against these repositories can aid in preventing synthetic identity fraud, the use of stolen identity information, and exploitation by a close associate or relative. - id: FRAUD-9 title: Detect Fraud Indicators props: - value: "3.2.1 #12" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-9_smt name: statement prose: "For attended proofing processes, CSPs SHALL train proofing agents to detect indicators of fraud and SHALL provide proofing agents and trusted referees with tools to flag suspected fraudulent events for further treatment and investigation." - id: FRAUD-9_obj links: - rel: assessment-for href: "#FRAUD-9_smt" name: objective prose: "[If a CSP provides an attended identity proofing process,] confirm that its agents are trained to detect potential fraud and are provided with mechanisms to flag incidents of suspected fraud." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP trains its agents to identify potential fraud and provides them with a way to flag suspected fraud for further investigation and treatment. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-9_asm-interview name: assessment-method prose: Interview appropriate personnel to determine how the CSP trains its agents to identify potential fraud and how it provides them with a way to flag suspected fraud for further investigation and treatment. - id: FRAUD-10 title: Insider Threat Controls props: - value: "3.2.1 #13" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-10_smt name: statement prose: CSPs SHALL implement insider threat controls to detect and prevent collusion involving CSP representatives that are directly involved with or can intervene in proofing processes or decisions. - id: FRAUD-10_obj links: - rel: assessment-for href: "#FRAUD-10_smt" name: objective prose: Determine that the CSP has implemented appropriate insider threat controls to help detect and prevent collusion. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine if the CSP employs insider threat controls to prevent collusion. - id: FRAUD-10_gdn name: guidance prose: Collusion is possible whenever CSP representatives are directly involved in proofing processes or decisions. - id: FRAUD-11 title: Compensating Controls props: - value: "3.2.1 #16" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-11_smt name: statement prose: "If fraud mitigation measures are employed as compensating controls, they SHALL be documented as deviations from the normative guidance of these guidelines and SHALL be conveyed to all RPs through a Digital Identity Acceptance Statement (DIAS) prior to integration." - id: FRAUD-11_obj links: - rel: assessment-for href: "#FRAUD-11_smt" name: objective prose: "Determine if a CSP employs fraud mitigation measures as compensating controls, and if it does, determine that the CSP has documented these controls as deviations from the normative guidance of these guidelines and conveys this information to its RPs through a Digital Identity Acceptance Statement (DIAS)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-11_asm-examine name: assessment-method prose: Examine the CSP's practices statement or Digital Identity Acceptance Statement to determine that the CSP has documented any compensating controls and has a process for communicating these deviations to its CSPs through DIASs. - id: FRAUD-11_gdn name: guidance prose: "See SP 800-63-4, section 3.4.4, for more information about DIAS." - id: FRAUD-12 title: AI and ML props: - value: 3.2.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-12_smt name: statement prose: "CSPs that employ artificial intelligence (AI) or machine learning (ML) as part of their identity service SHALL adhere to the requirements provided in Sec. 3.8 of [SP800-63], as applicable." - id: FRAUD-12_obj links: - rel: assessment-for href: "#FRAUD-12_smt" name: objective prose: "Determine if the CSP employs AI or ML as part of its identity service and if it does, confirm that it adheres to all the requirements provided in Section 8 of NIST SP 800-63-4." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-12_asm-examine name: assessment-method prose: Examine the CSP's design documentation or other documentation to determine that any AI or ML it employs adheres to the requirements provided in Section 8 of NIST SP 800-63-4. - id: FRAUD-13 title: Fraud POC props: - value: "3.2.2 #1" class: index name: label - value: RPs class: target name: marking - value: RPs class: xal-level name: marking parts: - id: FRAUD-13_smt name: statement prose: RPs SHALL establish a point of contact with whom CSPs can interact and communicate fraud data. - id: FRAUD-13_obj links: - rel: assessment-for href: "#FRAUD-13_smt" name: objective prose: Confirm the RP has established a point of contact to receive fraud and other information from its CSPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-13_asm-examine name: assessment-method prose: Examine an example agreement or contract to determine that the RP has an identified point of contact (POC) to interact with and receive fraud and other information for CSPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-13_asm-interview name: assessment-method prose: Interview appropriate personnel to determine that the RP has an identified POC to interact with and receive fraud and other information for CSPs. - id: FRAUD-14 title: Fraud PRA props: - value: "3.2.2 #2a" class: index name: label - value: RPs class: target name: marking - value: RPs class: xal-level name: marking parts: - id: FRAUD-14_smt name: statement prose: RPs SHALL conduct a privacy risk assessment (see Sec. 3.3.1) of any CSP fraud checks and mitigation technologies to identify potential privacy risks or unintended harms. - id: FRAUD-14_obj links: - rel: assessment-for href: "#FRAUD-14_smt" name: objective prose: Determine that the RP has conducted a privacy risk assessment of all fraud checks or mitigations used by CSPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-14_asm-examine name: assessment-method prose: Examine the results of the privacy risk assessment the RP conducted of all fraud checks and mitigations used by its CSPs. - id: FRAUD-15 title: Fed Fraud PRA props: - value: "3.2.2 #2b" class: index name: label - value: Federal Agency class: target name: marking - value: FedAgen class: xal-level name: marking parts: - id: FRAUD-15_smt name: statement prose: Federal agency RPs SHALL implement the privacy risk assessment consistent with the requirements contained in Sec. 3.7. - id: FRAUD-15_obj links: - rel: assessment-for href: "#FRAUD-15_smt" name: objective prose: Determine that the Federal agency RP has conducted a privacy risk assessment for all fraud checks and mitigations used by its CSPs in accordance with the requirements provided in section 3.7 of SP 800-63A-4. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-15_asm-examine name: assessment-method prose: Examine the documented results of any privacy risk assessments conducted for fraud checks and mitigations used by its CSPs. - id: FRAUD-16 title: Fraud Reviews props: - value: "3.2.2 #4" class: index name: label - value: RPs class: target name: marking - value: RPs class: xal-level name: marking parts: - id: FRAUD-16_smt name: statement prose: "RPs SHALL conduct periodic reviews of their CSP's fraud management program, fraud checks, and fraud technologies to adjust thresholds, review investigations into fraud events, and evaluate the effectiveness and efficacy of fraud controls." - id: FRAUD-16_obj links: - rel: assessment-for href: "#FRAUD-16_smt" name: objective prose: Confirm the RP conducts periodic re-reviews of its fraud management program activities to ensure its ongoing effectiveness against existing and emerging risks and threats. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-16_asm-examine name: assessment-method prose: Examine the documented process and results of any periodic reviews and assessments of the RPs' fraud management program and activities. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-16_asm-interview name: assessment-method prose: Interview appropriate personnel for information about the RPs' ongoing reviews and assessments of its fraud management program activities. - id: FRAUD-17 title: Risk Tolerance props: - value: "3.2.2 #5a" class: index name: label - value: RPs class: target name: marking - value: RPs class: xal-level name: marking parts: - id: FRAUD-17_smt name: statement prose: RPs SHALL review all fraud mitigation measures that have been deployed as compensating or supplemental controls by CSPs to align with their internal risk tolerance and acceptance. - id: FRAUD-17_obj links: - rel: assessment-for href: "#FRAUD-17_smt" name: objective prose: Determine that the RP has reviewed and accepted all risks associated with fraud mitigation measures employed by its CSP as compensating controls and confirmed they align with the RP's own risk acceptance profile. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-17_asm-examine name: assessment-method prose: Examine the documented results of any reviews of the risks associated with any fraud mitigation measures used as compensating controls by its CSPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-17_asm-interview name: assessment-method prose: Interview appropriate personnel to determine that the RP has reviewed and accepted the risks associated with any fraud mitigation measures used as compensating controls by its CSPs. - id: FRAUD-18 title: RP DIAS props: - value: "3.2.2 #5b" class: index name: label - value: RPs class: target name: marking - value: RPs class: xal-level name: marking parts: - id: FRAUD-18_smt name: statement prose: The RP SHALL record the CSP's compensating controls in their own DIAS prior to integration. - id: FRAUD-18_obj links: - rel: assessment-for href: "#FRAUD-18_smt" name: objective prose: "Determine if the CSP employs any compensating controls and, if so, determine that the RP as included the controls from the CSP's DIAS into its own DIAS." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-18_asm-examine name: assessment-method prose: Examine the RP's DIAS to determine if it has integrated compensating controls from the CSP's DIAS into its own DIAS. - id: FRAUD-18_gdn name: guidance prose: "From NIST SP 800-63-4: Organizations SHALL develop a Digital Identity Acceptance Statement (DIAS) to document the results of the DIRM process for (i) each online service managed by the organization, and (ii) each external online service used to support the mission of the organization, including software-as-a-service offerings (e.g., social media platforms, email services, online marketing services). RPs who intend to use a particular CSP/IdP SHALL review the latter's DIAS and incorporate relevant information into the organization's DIAS for each online service." - id: FRAUD-19 title: Fraud Check Practices props: - value: "3.2.3 #1" class: index name: label - value: RPs class: target name: marking - value: RPs class: xal-level name: marking parts: - id: FRAUD-19_smt name: statement prose: CSPs SHALL establish and document actions and practices related to each of their fraud checks and provide these actions and practices to RPs. - id: FRAUD-19_obj links: - rel: assessment-for href: "#FRAUD-19_smt" name: objective prose: "Confirm that the CSP has established and documented actions and practices associated with its fraud checks, and that it communicates this information to its RPs." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-19_asm-examine name: assessment-method prose: "Examine the CSP's practice statements and/or other documentation to determine that the CSP has established and documented actions and practices associated with its fraud checks, and that it communicates this information to its RPs." - id: FRAUD-20 title: Redress props: - value: "3.2.3 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-20_smt name: statement prose: CSPs SHALL establish procedures for redress to allow applicants to resolve issues associated with fraud checks and mitigation technologies. - id: FRAUD-20_obj links: - rel: assessment-for href: "#FRAUD-20_smt" name: objective prose: Determine that the CSP has established redress procedures specific to issues associated with its fraud checks and mitigation measures. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-20_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to confirm it provides a way for applicants to seek redress to resolve issues associated with the CSP's fraud checks or other fraud mitigation measures. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-20_asm-interview name: assessment-method prose: Interview appropriate personnel to determine how the CSP provides a way for applicants to seek redress to resolve issues associated with the CSP's fraud checks or other fraud mitigation measures. - id: FRAUD-20_gdn name: guidance prose: "See Sec. 3.6 of [SP800-63] for more information about redress." - id: FRAUD-21 title: Failed Fraud Checks props: - value: "3.2.3 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FRAUD-21_smt name: statement prose: "If trusted referees are offered to applicants who fail fraud checks in unattended remote processes, the trusted referees SHALL be provided with a summary of the results of the fraud failures to inform their risk-based decision-making processes." - id: FRAUD-21_obj links: - rel: assessment-for href: "#FRAUD-21_smt" name: objective prose: "Determine if the CSP offers Trusted Referee services to applicants who fail fraud checks and, if it does, confirm that these Trusted Referees are provided with the results of the fraud checks." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FRAUD-21_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it provides the results of any failed fraud checks for an applicant to Trusted Referees. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FRAUD-21_asm-interview name: assessment-method prose: Interview Trusted Referees to confirm that they are provided with the results of any failed fraud checks for an applicant. - id: FRAUD-21_gdn name: guidance prose: The CSP SHOULD offer trusted referee services to applicants who fail fraud checks in unattended remote processes. - id: PRIVACY-1 title: Privacy Risk Assessment props: - value: "3.3 #1a" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-1_smt name: statement prose: The CSP SHALL conduct and document a privacy risk assessment for the processes used for identity proofing and enrollment. - id: PRIVACY-1_obj links: - rel: assessment-for href: "#PRIVACY-1_smt" name: objective prose: Determine that the CSP has conducted a privacy risk assessment of its identity service processes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-1_asm-examine name: assessment-method prose: Examine the results of the CSP's privacy risk assessment. - id: PRIVACY-1_gdn name: guidance prose: "For more information about privacy risk assessments, refer to the NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management at https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.01162020.pdf." - id: PRIVACY-2 title: Min Privacy Risk Assessment Requirements props: - value: "3.3.1 #1b" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-2_smt name: statement prose: |- At a minimum, the privacy risk assessment SHALL assess the risks associated with: (a) Processing personal information for the purposes of identity proofing, enrollment, or fraud management, including identity attributes, biometrics, images, video, scans, or copies of identity evidence. (b) Additional steps that the CSP takes to verify the identity of an applicant beyond the mandatory requirements specified herein. (c) Processing of personal information for purposes outside of the scope of identity proofing and enrollment, except to comply with law or legal processes. (d) The retention schedule for identity records and personal information. (e) Processing non-personal information that could be used to identify a person when aggregated or processed by an algorithm. (f) Personal information that is processed by a third-party service on behalf of the CSP. - id: PRIVACY-2_obj links: - rel: assessment-for href: "#PRIVACY-2_smt" name: objective prose: "Determine that the CSP has assessed the privacy risks associated with all the aspects of its identity service, as specified in item #1 of section 3.3.1." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-2_asm-examine name: assessment-method prose: Examine the results of the CSP's privacy risk assessment. - id: PRIVACY-3 title: Privacy Mgmt props: - value: "3.3.1 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-3_smt name: statement prose: "Based on the results of its privacy risk assessment, the CSP SHALL document the measures it takes to maintain the disassociability, predictability, manageability, confidentiality, integrity, and availability of any personal information it collects or processes." - id: PRIVACY-3_obj links: - rel: assessment-for href: "#PRIVACY-3_smt" name: objective prose: "Determine that the CSP has documented the measures it takes to manage its privacy risks, as identified by the CSP's privacy risk assessment." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-3_asm-examine name: assessment-method prose: Examine the CSP's privacy risk or other documentation to determine what measures it takes to manage its privacy risks. - id: PRIVACY-3_gdn name: guidance prose: "NIST IR 8062 provides an overview of predictability, manageability, and disassociability, including examples of how these objectives can be met." - id: PRIVACY-4 title: Reassess Privacy Risks props: - value: "3.3.1 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-4_smt name: statement prose: The CSP SHALL reassess privacy risks and update its privacy risk assessment any time it makes changes to its identity service that affect the processing of personal information. - id: PRIVACY-4_obj links: - rel: assessment-for href: "#PRIVACY-4_smt" name: objective prose: Determine that the CSP has a policy and/or procedure for reassessing its associated privacy risks anytime changes to its identity service affect the processing of personal information. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it has a policy and/or procedure for reassessing its associated privacy risks anytime changes to its identity service affect the processing of personal information. - id: PRIVACY-5 title: PIA Review props: - value: "3.3.1 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-5_smt name: statement prose: "The CSP SHALL review its privacy risk assessment periodically, as documented in its practice statement, to ensure that it accurately reflects the current risks associated with the collection and processing of personal information." - id: PRIVACY-5_obj links: - rel: assessment-for href: "#PRIVACY-5_smt" name: objective prose: Determine that the CSP reviews its privacy risk assessment process and/or results to ensure that it accurately reflects the current privacy risks associated with operating its identity service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other document to determine that it has a policy or procedure for periodically reviewing its privacy risk assessment process and/or results. - id: PRIVACY-6 title: PIA Summary props: - value: "3.3.1 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-6_smt name: statement prose: The CSP SHALL make a summary of its privacy risk assessment available to any RPs that use its services. The summary SHALL be in sufficient detail to enable such RPs to make reasonable determinations about privacy risks associated with the CSP's services and to complete their own privacy risk assessments. - id: PRIVACY-6_obj links: - rel: assessment-for href: "#PRIVACY-6_smt" name: objective prose: Determine that the CSP has a process for communicating summarized results of its privacy risk assessment to its RPs and that such summaries are in sufficient detail to allow those RPs to determine if the risks of using the CSP's identity services are acceptable. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-6_asm-examine name: assessment-method prose: "Examine the CSP's privacy risk or other documentation, such as agreements or contracts, to determine how it communicates the results of its risk assessment to the RPs that use its services." - id: PRIVACY-7 title: Sub Account PIA props: - value: "3.3.1 #6" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-7_smt name: statement prose: The CSP SHALL perform a privacy risk assessment for the processing of any personal information maintained in subscriber accounts. - id: PRIVACY-7_obj links: - rel: assessment-for href: "#PRIVACY-7_smt" name: objective prose: Determine that the CSP performed a privacy risk assessment of its subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-7_asm-examine name: assessment-method prose: Examine the CSP's privacy risk or other documentation to determine it has conducted a privacy risk assessment of its subscriber accounts. - id: PRIVACY-8 title: Min Personal Info props: - value: "3.3.2 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-8_smt name: statement prose: "The processing of personal information SHALL be limited to the minimum necessary to validate the existence of the claimed identity, associate the claimed identity with the applicant, mitigate fraud, and provide RPs with attributes that they may use to make authorization decisions." - id: PRIVACY-8_obj links: - rel: assessment-for href: "#PRIVACY-8_smt" name: objective prose: Determine that the CSP applies the privacy-protecting principle of data minimization. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-8_asm-examine name: assessment-method prose: "Examine the CSP's practices statement, privacy risk documentation, or other documentation to determine that the CSP limits the personal information it collects to the minimum necessary." - id: PRIVACY-9 title: Privacy Training props: - value: "3.3.2 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-9_smt name: statement prose: The CSP SHALL provide privacy training to all personnel and any third-party service providers who have access to sensitive information associated with the CSP's identity service. - id: PRIVACY-9_obj links: - rel: assessment-for href: "#PRIVACY-9_smt" name: objective prose: Determine that the CSP provides privacy training to all its personnel and to those third-party service providers who have access to any personal or sensitive information associated with the CSP's identity service operations. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-9_asm-examine name: assessment-method prose: Examine the CSP's applicable documentation to determine that it provides privacy training to all its personnel and to any third-parties that have access to personal information processed by the CSP's identity service. - id: PRIVACY-10 title: SSN Collection props: - value: "3.3.2 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-10_smt name: statement prose: "[If the SSN is collected on behalf of a federal, state, or local government agency,] the CSP SHALL provide notice to the applicant for the collection in accordance with applicable laws." - id: PRIVACY-10_obj links: - rel: assessment-for href: "#PRIVACY-10_smt" name: objective prose: "Determine if the CSP collects SSNs, and if it does, confirm that it provides notice to the applicant for the collection." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it provides notice to applicants for the collection in accordance with applicable laws if the CSP collects a social security number (SSN) from applicants. - id: PRIVACY-10_gdn name: guidance prose: "The CSP MAY collect a Social Security number (SSN) as an attribute when necessary for identity resolution. Knowledge of an SSN is not sufficient to act as evidence of identity, nor is it considered an acceptable method of verifying possession of the Social Security card when used as evidence." - id: PRIVACY-11 title: Explicit Notice props: - value: "3.3.2 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVACY-11_smt name: statement prose: "At the time of collection, the CSP SHALL provide explicit notice to the applicant regarding the purpose for collecting any attributes and personal information. Such a notice SHALL include whether the personal information and attributes are voluntary or mandatory to complete the identity proofing process; the specific attributes and other sensitive data that the CSP intends to store in the applicant's subsequent subscriber account; the consequences of not providing the attributes; and the details of any records retention requirement if one is in place, including an applicant's right to request data deletion or engage in other forms of redress." - id: PRIVACY-11_obj links: - rel: assessment-for href: "#PRIVACY-11_smt" name: objective prose: "Determine that the CSP provides explicit notice to the applicant for the collection of attributes and personal information and that such notice includes all the elements provided in item #4 of section 3.3.2." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVACY-11_asm-examine name: assessment-method prose: Examine a sample of the notice the CSP provides to applicants for the collection of personal information. - id: CUSTOMER-1 title: CX Challenges props: - value: "3.4 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CUSTOMER-1_smt name: statement prose: "The CSP SHALL assess the elements of its identity proofing processes to identify processes or technologies that can result in customer experience challenges, particularly if those challenges prevent the CSP from consistently delivering identity proofing services to all users served by an RP." - id: CUSTOMER-1_obj links: - rel: assessment-for href: "#CUSTOMER-1_smt" name: objective prose: Determine that the CSP has assessed its identity proofing process and identified any potential customer experience challenges. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CUSTOMER-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP has assessed its identity service for potential customer experience challenges. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: CUSTOMER-1_asm-interview name: assessment-method prose: Interview appropriate personnel to determine that the CSP has assessed its identity service for potential customer experience challenges. - id: CUSTOMER-1_gdn name: guidance prose: "CSPs assess the elements of their identity services to identify processes and technologies that may result in customer experience challenges for the populations they serve. If risks to customer experience are identified, CSPs proactively employ mitigations that will reduce or eliminate these issues consistent with their assurance levels and risk posture." - id: CUSTOMER-2 title: CX Assessments props: - value: "3.4 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CUSTOMER-2_smt name: statement prose: CSPs SHALL provide RPs with a summary of their customer experience assessments that includes information about common challenges or issues faced by users. - id: CUSTOMER-2_obj links: - rel: assessment-for href: "#CUSTOMER-2_smt" name: objective prose: Determine that the CSP has a process for communicating the results of its customer experience assessments to the RPs that use its service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CUSTOMER-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine how the CSP communicates the results of its customer experience assessment to its RPs. - id: CUSTOMER-3 title: CX Mitigations props: - value: "3.4 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CUSTOMER-3_smt name: statement prose: "Based on the results of its assessment, the CSP SHALL document any measures it takes to mitigate the possible access challenges." - id: CUSTOMER-3_obj links: - rel: assessment-for href: "#CUSTOMER-3_smt" name: objective prose: Determine that the CSP has documented any measures it takes to mitigate the potential customer experience challenges it identified through its customer experience assessment. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CUSTOMER-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine any measures it takes to mitigate the potential customer experience challenges it identified through its customer experience assessment. - id: CUSTOMER-4 title: Periodic CX Reassessment props: - value: "3.4 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CUSTOMER-4_smt name: statement prose: The CSP SHALL reassess the customer experience risks periodically and any time the CSP makes changes to its identity service that affect the processes or technologies that impact customer experience. - id: CUSTOMER-4_obj links: - rel: assessment-for href: "#CUSTOMER-4_smt" name: objective prose: Determine that the CSP periodically reassesses its customer experience risks (challenges) and any time it makes changes to its identity service that could impact the customer experience. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CUSTOMER-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its stated policy or practice of reassessing customer experience challenges and risks associated with its identity services. - id: CUSTOMER-5 title: Applicant Participation props: - value: "3.4 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CUSTOMER-5_smt name: statement prose: The CSP SHALL NOT make applicant participation in these risk assessments mandatory. - id: CUSTOMER-5_obj links: - rel: assessment-for href: "#CUSTOMER-5_smt" name: objective prose: Confirm that the CSP does not make applicant participation in customer experience risk assessments mandatory. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CUSTOMER-5_asm-examine name: assessment-method prose: |- Examine the CSP's practices statement or other documentation to confirm its policy on applicant participation in customer experience risk assessments. Test the customer experience risk assessment workflow. - id: SECURITY-1 title: Protected Channel props: - value: "3.5 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECURITY-1_smt name: statement prose: "Each online transaction within the identity proofing process, including transactions that involve third parties, SHALL occur over an authenticated, protected channel." - id: SECURITY-1_obj links: - rel: assessment-for href: "#SECURITY-1_smt" name: objective prose: Determine that all communications are protected by approved cryptography. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECURITY-1_asm-examine name: assessment-method prose: "Examine the CSP's identity service design document or other documentation, to determine that all communications occur via authenticated, protected channels." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SECURITY-1_asm-test name: assessment-method prose: Test identity service transactions to determine that they are protected by approved cryptography. - id: SECURITY-1_gdn name: guidance prose: "An authenticated protected channel is an encrypted communication channel that uses approved cryptography in which the connection initiator (client) has authenticated the recipient (server). Authenticated protected channels are encrypted to provide confidentiality and protection against active intermediaries and are frequently used in the user authentication process. Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) [RFC9325] are examples of authenticated protected channels in which the certificate presented by the recipient is verified by the initiator. Unless otherwise specified, authenticated protected channels do not require the server to authenticate the client. Authentication of the server is often accomplished through a certificate chain that leads to a trusted root rather than individually with each server." - id: SECURITY-2 title: Auto Attack Protections props: - value: "3.5 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECURITY-2_smt name: statement prose: "The CSP SHALL implement automated attack protections for the identity proofing process, such as bot detection, mitigation, and management solutions; behavioral analytics; web application firewall settings; and network traffic analysis." - id: SECURITY-2_obj links: - rel: assessment-for href: "#SECURITY-2_smt" name: objective prose: Confirm that the CSP has identified which automated attacks its identity service is vulnerable to and has implemented appropriate attack detection mechanisms. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECURITY-2_asm-examine name: assessment-method prose: "Examine the CSP's identity service design document, or other documentation, to determine that it employs appropriate automated attack detection mechanisms." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SECURITY-2_asm-test name: assessment-method prose: Test whether the identity service is able to detect automated attacks. - id: SECURITY-2_gdn name: guidance prose: Behavioral analytics in this context is used to determine whether an interaction is indicative of an automated attack and not an effort to identify or authenticate a specific user based on a captured reference template for that user. - id: SECURITY-3 title: Data Protection props: - value: "3.5 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECURITY-3_smt name: statement prose: "All personal information that is collected as part of the identity proofing process SHALL be protected to maintain the confidentiality and integrity of the information, including the encryption of data at rest and the exchange of information using authenticated, protected channels." - id: SECURITY-3_obj links: - rel: assessment-for href: "#SECURITY-3_smt" name: objective prose: Determine that the CSP protects all identity service data. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECURITY-3_asm-examine name: assessment-method prose: "Examine the CSP's identity service design document, certification information, or other documentation, to determine that it employs data protection mechanisms for data at rest and during transmission." - id: SECURITY-4 title: Risk Assessment props: - value: "3.5 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECURITY-4_smt name: statement prose: "The CSP SHALL assess the information security and privacy risks associated with operating its identity service, according to the NIST Risk Management Framework or equivalent risk management guidelines. At a minimum, the CSP SHALL apply appropriate controls consistent with the NIST SP 800-53 moderate baseline, regardless of IAL." - id: SECURITY-4_obj links: - rel: assessment-for href: "#SECURITY-4_smt" name: objective prose: Determine that the CSP has conducted a risk assessment and that it employs appropriate security controls consistent with the NIST SP 800-53 MODERATE baseline or greater. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECURITY-4_asm-examine name: assessment-method prose: "Examine the CSP's risk assessment results document, or other documentation, to confirm it has conducted a security risk assessment." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECURITY-4_asm-examine-2 name: assessment-method prose: "Examine the CSP's identity service design document, certification information, or other documentation, to determine if it employs MODERATE baseline controls or greater." - id: SECURITY-5 title: Third-Party Risk props: - value: "3.5 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECURITY-5_smt name: statement prose: "The CSP SHALL assess risks associated with its use of third-party services and apply appropriate controls, as provided in the Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations." - id: SECURITY-5_obj links: - rel: assessment-for href: "#SECURITY-5_smt" name: objective prose: Determine that the CSP has assessed the risks associated with its user of third-party services and has applied appropriate controls. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECURITY-5_asm-examine name: assessment-method prose: Examine the results of the CSP's supply chain risk assessment. - id: REDIP-1 title: Redress Mechanisms props: - value: "3.6 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REDIP-1_smt name: statement prose: "The CSP SHALL provide mechanisms for the redress of applicant complaints and problems that arise from the identity proofing process, including proofing failures; delays; difficulties; and the recovery of a compromised subscriber account (e.g., as a result of a scam or fraud)." - id: REDIP-1_obj links: - rel: assessment-for href: "#REDIP-1_smt" name: objective prose: Determine that the CSP provides a mechanism for applicants to seek redress for errors or harms associated with their use of the CSP's identity service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REDIP-1_asm-examine name: assessment-method prose: "Examine the CSP's practices statement, or other documentation, to determine its redress mechanism(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: REDIP-1_asm-interview name: assessment-method prose: Interview appropriate personnel to determine the CSP's redress mechanism(s). - id: REDIP-1_gdn name: guidance prose: See section 3.6 of NIST SP 800-63-4 for more information about redress. - id: REDIP-2 title: Easy Redress props: - value: "3.6 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REDIP-2_smt name: statement prose: These redress mechanisms SHALL be easy for applicants to find and use. - id: REDIP-2_obj links: - rel: assessment-for href: "#REDIP-2_smt" name: objective prose: Determine that the CSP's redress mechanisms are easy to find and use. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REDIP-2_asm-examine name: assessment-method prose: Examine the CSP's website to determine how easy it is to find information about its redress process. - id: REDIP-3 title: Redress Efficacy props: - value: "3.6 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REDIP-3_smt name: statement prose: The CSP SHALL assess the mechanisms for their efficacy in achieving a resolution of complaints or problems. - id: REDIP-3_obj links: - rel: assessment-for href: "#REDIP-3_smt" name: objective prose: Determine that the CSP assesses its redress process and mechanisms to confirm they are effective. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REDIP-3_asm-examine name: assessment-method prose: "Examine the CSP's practices statement, or other documentation, to determine that it assesses the efficacy of its redress process." - id: FED-1 title: SAOP Consult props: - value: "3.7 #1" class: index name: label - value: Federal Agency class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FED-1_smt name: statement prose: "The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) to determine whether the collection of personal information, including biometrics, to conduct identity proofing triggers Privacy Act requirements." - id: FED-1_obj links: - rel: assessment-for href: "#FED-1_smt" name: objective prose: Confirm that the Federal Agency has consulted with its SAOP to determine if the collection of personal information in association with the use of the identity service triggers Privacy Act requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FED-1_asm-examine name: assessment-method prose: Examine the Federal Agency's documentation to determine if it has consulted with its SAOP whether its use of an identity service triggers requirements under the Privacy Act. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FED-1_asm-interview name: assessment-method prose: Interview appropriate personnel to determine whether the Federal Agency has consulted with is SAOP whether its use of an identity service triggers requirements under the Privacy Act. - id: FED-2 title: E-Gov Act props: - value: "3.7 #2" class: index name: label - value: Federal Agency class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FED-2_smt name: statement prose: "The agency SHALL consult with their SAOP to determine whether the collection of personal information, including biometrics, to conduct identity proofing triggers E-Government Act of 2002 requirements." - id: FED-2_obj links: - rel: assessment-for href: "#FED-2_smt" name: objective prose: Confirm that the Federal Agency has consulted with its SAOP to determine if the collection of personal information in association with the use of the identity service triggers E-Government Act of 2002 requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FED-2_asm-examine name: assessment-method prose: Examine the Federal Agency's documentation to determine if it has consulted with its SAOP whether its use of an identity service triggers requirements under the E-Government Act of 2002. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FED-2_asm-interview name: assessment-method prose: Interview appropriate personnel to determine whether the Federal Agency has consulted with is SAOP and whether its use of an identity service triggers requirements under the E-Government Act of 2002. - id: FED-3 title: SORN props: - value: "3.7 #3" class: index name: label - value: Federal Agency class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FED-3_smt name: statement prose: "The agency SHALL publish a System of Records Notice (SORN) to cover such collections, as applicable." - id: FED-3_obj links: - rel: assessment-for href: "#FED-3_smt" name: objective prose: "Determine that the Federal Agency has published a SORN, as applicable, for its use of an identity service." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FED-3_asm-examine name: assessment-method prose: Examine the Federal Agency's documentation to determine that it has published a SORN for its identity service(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: FED-3_asm-interview name: assessment-method prose: Interview appropriate personnel to determine that it has published a SORN for its identity service(s). - id: FED-3_gdn name: guidance prose: "For more information about SORNs, see OPM's System of Records Notice (SORN) Guide(https://www.opm.gov/information-management/privacy-policy/privacy-references/sornguide.pdf)." - id: FED-4 title: Fed PIA props: - value: "3.7 #4" class: index name: label - value: Federal Agency class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FED-4_smt name: statement prose: "The agency SHALL publish a Privacy Impact Assessment (PIA) to cover such collections, as applicable." - id: FED-4_obj links: - rel: assessment-for href: "#FED-4_smt" name: objective prose: Determine that the Federal Agency has conducted a PIA for its identity service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FED-4_asm-examine name: assessment-method prose: Examine the Federal Agency's PIA document to determine if it has conducted a privacy assessment of its identity service(s). - id: FED-5 title: PIA Input props: - value: "3.7 #6" class: index name: label - value: Federal Agency class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FED-5_smt name: statement prose: "If the agency uses a third-party CSP, the agency SHALL conduct its own PIA and use the CSP's privacy risk assessment as input." - id: FED-5_obj links: - rel: assessment-for href: "#FED-5_smt" name: objective prose: "Determine if the Federal Agency uses a third-party CSP and, if it does, confirm it has conducted a PIA and included the CSP's PIA as an input." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FED-5_asm-examine name: assessment-method prose: Examine the agency PIA documentation to determine it has included the results of the CSP's privacy assessment into its own PIA. - id: CONFIRM-1 title: Confirm Codes props: - value: 3.8 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONFIRM-1_smt name: statement prose: Confirmation codes SHALL include at least 6 decimal digits (or equivalent) from an approved random bit generator (see Sec. 3.2.12 of SP800-63B). - id: CONFIRM-1_obj links: - rel: assessment-for href: "#CONFIRM-1_smt" name: objective prose: "Determine if the CSP uses confirmation codes and, if it does, confirm that these codes are comprised of at least 6 digits (or equivalent) from a random bit generator." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONFIRM-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its confirmation codes include at least 6 decimal digits (or equivalent) from an approved random bit generator. - id: CONFIRM-1_gdn name: guidance prose: |- Confirmation codes are used to confirm that an applicant has access to a postal address, email address, or phone number for the purposes of future communications. A random bit generator (RGB) is a device or algorithm that can produce a sequence of bits that appear to be both statistically independent and unbiased. - id: CONFIRM-2 title: Confirm Code Validity props: - value: 3.8 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONFIRM-2_smt name: statement prose: Confirmation codes SHALL be valid for at most 21 days when sent to a validated postal address within the contiguous United States; 30 days when sent to a validated postal address outside of the contiguous United States; 10 minutes when sent to a validated telephone number (SMS or voice); and 24 hours when sent to a validated email address. - id: CONFIRM-2_obj links: - rel: assessment-for href: "#CONFIRM-2_smt" name: objective prose: "Determine if the CSP uses confirmation codes and, if it does, confirm that they meet the validity requirements specified in section 3.8." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONFIRM-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its confirmation codes meet the validity requirements specified in Section 3.8. - id: CONFIRM-3 title: Invalidate Confirm Code props: - value: 3.8 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONFIRM-3_smt name: statement prose: "Upon its use, the CSP SHALL invalidate the confirmation code." - id: CONFIRM-3_obj links: - rel: assessment-for href: "#CONFIRM-3_smt" name: objective prose: "Determine if the CSP uses confirmation codes and, if it does, confirm the codes are invalidated upon use." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONFIRM-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine confirmation codes are invalidated upon use. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CONFIRM-3_asm-test name: assessment-method prose: Test by requesting confirmation codes and attempting to use them after their validity period has expired. - id: CONTINUE-1 title: Continue Codes props: - value: "3.9 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONTINUE-1_smt name: statement prose: "Continuation codes SHALL include at least 64 bits from an approved random bit generator (see Sec. 3.2.12 of [SP800-63B])." - id: CONTINUE-1_obj links: - rel: assessment-for href: "#CONTINUE-1_smt" name: objective prose: "Determine if the CSP uses continuation codes and, if it does, confirm that these codes are comprised of at least 64 bits from a random bit generator." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONTINUE-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its confirmation codes include at least 64 bits from an approved random bit generator. - id: CONTINUE-1_gdn name: guidance prose: |- Continuation codes are used to reestablish an applicant's linkage to an incomplete identity proofing or enrollment process. The continuation code provides a temporary secret that can connect one session to another. A random bit generator (RGB) is a device or algorithm that can produce a sequence of bits that appear to be both statistically independent and unbiased. - id: CONTINUE-2 title: Continue Code Throttling props: - value: "3.9 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONTINUE-2_smt name: statement prose: "The verification of continuation codes SHALL be subject to throttling requirements, as provided in Sec. 3.2.2 of [SP800-63B]." - id: CONTINUE-2_obj links: - rel: assessment-for href: "#CONTINUE-2_smt" name: objective prose: "Determine if the CSP uses continuation codes and, if it does, confirm that the use of these codes is subject to throttling requirements provided in NIST SP 800-63B-4, Sec. 3.2.2." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONTINUE-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the use of continuation codes is subject to the throttling requirements provided in NIST SP 9800-63B-4 Sec. 3.2.2. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CONTINUE-2_asm-test name: assessment-method prose: Test by attempting to submit invalid continuation codes at a rate that would trigger throttling requirements. - id: CONTINUE-2_gdn name: guidance prose: "In the case of continuation codes, throttling is a mechanism that limits the number of failed attempts at entering a continuation code." - id: CONTINUE-3 title: Hashed Continue Codes props: - value: "3.9 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONTINUE-3_smt name: statement prose: Continuation codes SHALL be stored in hashed form using a Federal Information Processing Standards (FIPS)-approved or NIST-recommended one-way function. - id: CONTINUE-3_obj links: - rel: assessment-for href: "#CONTINUE-3_smt" name: objective prose: "Determine if the CSP uses continuation codes and, if it does, confirm that these codes are stored in hashed form, as specified in item #5 of Sec. 3.9." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONTINUE-3_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that these codes are stored in hashed form, as specified in item #5 of Sec. 3.9." - id: CONTINUE-4 title: Invalidate Continue Code props: - value: "3.9 #6" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONTINUE-4_smt name: statement prose: "Upon its use, the CSP SHALL invalidate the continuation code." - id: CONTINUE-4_obj links: - rel: assessment-for href: "#CONTINUE-4_smt" name: objective prose: "Determine if the CSP uses continuation codes and, if it does, confirm that the codes are invalidated upon use." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONTINUE-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that these codes are invalidated upon use. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CONTINUE-4_asm-test name: assessment-method prose: Test by requesting several continuation codes and attempting to use them after their validity period has expired. - id: CONTINUE-4_gdn name: guidance prose: "Since substantial time may elapse between when an applicant receives their continuation code and when they are able to complete the proofing process, expiry is not defined in these guidelines. Expiry will need to be defined by the CSP based on their processes, technologies, and partnerships." - id: NOTIFS-1 title: Validated Addresses props: - value: "3.10 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: NOTIFS-1_smt name: statement prose: Notifications of proofing SHALL be sent to a validated postal address or phone number at all IALs or MAY be sent to a validated email address at IAL1. - id: NOTIFS-1_obj links: - rel: assessment-for href: "#NOTIFS-1_smt" name: objective prose: Confirm that the CSP sends notifications of proofing at IALs 2 and 3 to validated postal addresses or phone numbers. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: NOTIFS-1_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that, for IALs 2 or 3, it only sends notifications of proofing to validated postal addresses and/or phone numbers." - id: NOTIFS-1_gdn name: guidance prose: |- Notifications of proofing are sent to the applicant's validated address to inform them that they have been successfully identity-proofed and provide them with information about the identity proofing event and subsequent enrollment. Additionally, the notification explains how the recipient can dispute their involvement in the identity proofing events. Per Sec. 2.4.2.3, validated postal addresses or phone numbers are those that have been confirmed (validated) with an authoritative source or credible source, such as a mobile network operator or AAMVA. - id: NOTIFS-2 title: ID Proofing Details props: - value: "3.10 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: NOTIFS-2_smt name: statement prose: "Notifications of proofing SHALL include details about the identity proofing event, including the name of the identity service and the date on which the identity proofing was completed." - id: NOTIFS-2_obj links: - rel: assessment-for href: "#NOTIFS-2_smt" name: objective prose: Confirm that the CSP includes appropriate details about the identity proofing event in its notifications of proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: NOTIFS-2_asm-examine name: assessment-method prose: Examine an example of the CSP's notification of proofing to determine it includes adequate details about the identity proofing event. - id: NOTIFS-3 title: Repudiation Instructions props: - value: "3.10 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: NOTIFS-3_smt name: statement prose: "Notifications of proofing SHALL provide clear instructions, including contact information, on actions for the recipient to take if they repudiate their participation in the identity proofing event." - id: NOTIFS-3_obj links: - rel: assessment-for href: "#NOTIFS-3_smt" name: objective prose: Confirm that the CSP's notifications of proofing include clear instructions for how recipients can deny their participation in an identity proofing event with the CSP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: NOTIFS-3_asm-examine name: assessment-method prose: Examine an example of the CSP's notification of proofing to determine it includes clear and easy-to-follow instructions to the recipient for repudiating their participation in the identity proofing event with the CSP. - id: NOTIFS-4 title: Security Protections props: - value: "3.10 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: NOTIFS-4_smt name: statement prose: Notifications of proofing SHALL provide information about how the organization or CSP protects the security and confidentiality of the information it collects. - id: NOTIFS-4_obj links: - rel: assessment-for href: "#NOTIFS-4_smt" name: objective prose: Confirm that the CSP's notifications of proofing include information about how it protects the security and confidentiality of the recipient's personal information. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: NOTIFS-4_asm-examine name: assessment-method prose: Examine an example of the CSP's notification of proofing to determine it includes information about how the CSP protects the security and confidentiality of the information it collects and processes. - id: NOTIFS-5 title: Subscriber Responsibilities props: - value: "3.10 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: NOTIFS-5_smt name: statement prose: Notifications of proofing SHALL provide information about any responsibilities that the recipient has as a subscriber of the identity service. - id: NOTIFS-5_obj links: - rel: assessment-for href: "#NOTIFS-5_smt" name: objective prose: Confirm that the CSP's notifications of proofing include information about any responsibilities that the recipient has as a subscriber of the identity service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: NOTIFS-5_asm-examine name: assessment-method prose: Examine an example of the CSP's notification of proofing to determine it includes information about any responsibilities that the recipient has as a subscriber of the identity service. - id: NOTIFS-5_gdn name: guidance prose: Examples of subscriber responsibilities may be to not share their account information with anyone else or to report any suspected fraud associated with their account to the CSP as soon as possible. - id: NOTIFS-6 title: Subscriber Repudiation Response props: - value: 3.10 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: NOTIFS-6_smt name: statement prose: "If a subscriber repudiates having been identity-proofed by the identity service, the CSP or RP SHALL respond in accordance with its established fraud management and redress policies." - id: NOTIFS-6_obj links: - rel: assessment-for href: "#NOTIFS-6_smt" name: objective prose: Confirm that the CSP or RP has a defined policy for responding to subscriber repudiations. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: NOTIFS-6_asm-examine name: assessment-method prose: Examine the CSP's or RP's policies or other documentation to determine if it has a defined policy for responding to situations where a subscriber repudiates having been identity proofed by the CSP. - id: BIO-1 title: Bio Disclosure props: - value: "3.11 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-1_smt name: statement prose: "CSPs SHALL provide clear, publicly available information about all uses of biometrics, including what biometric data is collected, how it is stored and protected, and how to remove biometric data consistent with applicable laws and regulations." - id: BIO-1_obj links: - rel: assessment-for href: "#BIO-1_smt" name: objective prose: Confirm that the CSP discloses complete information about its uses of biometrics in a way that is clear and understandable to the general public. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy about publicly disclosing information about its uses of biometrics. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-1_asm-examine-2 name: assessment-method prose: Examine the CSP's website and user facing privacy policies to confirm biometric disclosure is addressed. - id: BIO-2 title: Bio Consent props: - value: "3.11 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-2_smt name: statement prose: CSPs SHALL obtain explicit informed consent to collect and use biometrics from all applicants. - id: BIO-2_obj links: - rel: assessment-for href: "#BIO-2_smt" name: objective prose: Confirm that the CSP obtains informed consent from applicants prior to the collection and use of their biometric attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy about obtaining consent from applicants prior to collecting and using biometrics. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BIO-2_asm-test name: assessment-method prose: Test the CSP's identity proofing workflow to determine how it obtains consent from applicants prior to collecting and using biometrics. - id: BIO-3 title: Stored Consent props: - value: "3.11 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-3_smt name: statement prose: CSPs SHALL store a record of the subscriber's consent for biometric use and associate it with the subscriber's account. - id: BIO-3_obj links: - rel: assessment-for href: "#BIO-3_smt" name: objective prose: Confirm that the CSP stores a record of the subscriber's consent for biometric use and that it is associated with the subscriber's account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for associating a record of the subscriber's consent for biometric use with their account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-3_asm-examine-2 name: assessment-method prose: Examine and test the subscriber account to determine that it includes a record of the subscriber's consent for biometric use. - id: BIO-4 title: BIO Deletion Process props: - value: "3.11 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-4_smt name: statement prose: "CSPs SHALL have a documented and publicly available deletion process and default retention period for all biometric information. Retention periods SHALL be consistent with applicable regulations, policies, and statutes for the regions and sectors that the CSP serves." - id: BIO-4_obj links: - rel: assessment-for href: "#BIO-4_smt" name: objective prose: "Determine the applicable biometric retention regulations, policies, and statutes applicable to the CSP's identity service and confirm that the CSP has documented and made publicly available its process and default retention period(s) for all biometric information, in accordance with these requirements." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-4_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine 1) which regulations, policies, and statutes are applicable to its identity service and 2) that it has documented and made publicly available its deletion process and default retention period(s) for all biometric information." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-4_asm-examine-2 name: assessment-method prose: Examine the CSP's website to confirm that information about the availability of deletion processes are available to the public. - id: BIO-5 title: Non-Deletion Justification props: - value: "3.11 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-5_smt name: statement prose: "If a CSP does not support biometric deletion requests, it SHALL publicly document the regulatory, statutory, or risk-based justification for their policy." - id: BIO-5_obj links: - rel: assessment-for href: "#BIO-5_smt" name: objective prose: "If the CSP DOES NOT support biometric deletion request, confirm that it has publicly disclosed the regulatory, statutory, and risk-based justification for their policy." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-5_asm-examine name: assessment-method prose: Examine the CSP's public notice justifying why it does not support biometric deletion requests. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-5_asm-examine-2 name: assessment-method prose: Examine the CSP's website to confirm it includes an explanation as to why it does not support biometric deletion requests. - id: BIO-5_gdn name: guidance prose: "CSPs SHOULD support the deletion of all of a subscriber's biometric information upon the subscriber's request, except where otherwise restricted by regulation, law, or policy." - id: BIO-6 title: Biometric Algorithm Testing props: - value: "3.11 #6" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-6_smt name: statement prose: "CSPs SHALL have their biometric recognition and attack detection algorithms periodically tested by independent entities for their performance characteristics, including performance across demographic groups." - id: BIO-6_obj links: - rel: assessment-for href: "#BIO-6_smt" name: objective prose: "Confirm that the CSP periodically employs independent organizations to test its biometric algorithms testing for their performance characteristics, including performance across demographic groups." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-6_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine: 1) that it employs independent organizations to test its biometric algorithms, and 2) how often or under what conditions it employs these organizations." - id: BIO-6_gdn name: guidance prose: "In addition, the CSP SHOULD conduct internal testing on biometric algorithms based on the update schedule of the provider.(Ref.Sec.3.11 #6A)" - id: BIO-7 title: Demographic Impacts props: - value: "3.11 #7A" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-7_smt name: statement prose: CSPs SHALL assess the performance and demographic impacts of employed biometric technologies in conditions that are substantially similar to the operational environment and user base of the system. - id: BIO-7_obj links: - rel: assessment-for href: "#BIO-7_smt" name: objective prose: Confirm that the CSP assesses the performance of any employed biometric technologies under conditions that are substantially similar to the operational environment and the user base(s) of the identity service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the conditions under which it assesses the performance of its employed biometric technologies. - id: BIO-7_gdn name: guidance prose: The user base is defined by both the expected users and the devices they are expected to use. - id: BIO-8 title: Voluntary Participation props: - value: "3.11 #7B" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-8_smt name: statement prose: "When biometric performance assessments include real-world users, participation by users SHALL be voluntary." - id: BIO-8_obj links: - rel: assessment-for href: "#BIO-8_smt" name: objective prose: "Determine if the CSP's biometric performance assessments include real-world users and, if so, confirm that participation by these users is entirely voluntary." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for assessing biometric performance using real-world users. - id: BIO-9 title: 1:1 Comparison Performance props: - value: "3.11 #8" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-9_smt name: statement prose: "CSPs SHALL meet the following performance thresholds if one-to-one (1:1) comparison algorithms are used for verification against a claimed identity: false match rate: 1:10,000 or better; and false non-match rate: 1:100 or better." - id: BIO-9_obj links: - rel: assessment-for href: "#BIO-9_smt" name: objective prose: "Determine if the CSP employs 1:1 comparison algorithms as part of the identity verification process and, if it does, confirm the algorithms meet the required performance thresholds." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-9_asm-examine name: assessment-method prose: Examine the CSP's biometric testing results to determine that the performance of 1:1 biometric comparison algorithms meet or surpass the required thresholds. - id: BIO-10 title: 1:N Minimum Performance props: - value: "3.11 #9" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-10_smt name: statement prose: "If a CSP uses one-to-many (1:N) scenarios, it SHALL meet a minimum performance threshold for false positive identification of 1:1,000 or better." - id: BIO-10_obj links: - rel: assessment-for href: "#BIO-10_smt" name: objective prose: "Determine if the CSP employs 1:N identification and, if it does, confirm the algorithms meet or surpass the stated performance threshold." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-10_asm-examine name: assessment-method prose: Examine the CSP's biometric testing results to determine that use of any 1:N scenarios meet or surpass the stated performance threshold. - id: BIO-10_gdn name: guidance prose: "CSPs MAY use one-to-many (1:N) identification in support of resolution or deduplication, pursuant to a privacy risk assessment." - id: BIO-11 title: FPIR Test Gallery props: - value: "3.11 #10" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-11_smt name: statement prose: Tests that demonstrate this requirement SHALL employ a gallery no smaller than 90% of the current or intended operational size (N). - id: BIO-11_obj links: - rel: assessment-for href: "#BIO-11_smt" name: objective prose: Confirm that the tests the CSP uses to test FPIR for 1:N comparisons employs a gallery of at least 90% of the current intended operational size (N). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-11_asm-examine name: assessment-method prose: Examine the CSP's biometric testing procedures and results to determine that the tests to determine the FPIR for 1:N comparisons employs a gallery of at least 90% of the current intended operational size (N). - id: BIO-11_gdn name: guidance prose: "A 1:N search of an applicant's collected biometric characteristics against a database is done to determine whether the applicant is already present in the database, possibly under a different name. The false positive identification rate (FPIR) refers to the proportion of 1:N searches in which a biometric system incorrectly identifies another person as a match, which is a false positive result. The performance metric of 1:1,000 means that a false positive outcome occurs for no more than 1 in every 1,000 searches." - id: BIO-12 title: 1:N Manual Review props: - value: "3.11 #11" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-12_smt name: statement prose: "CSPs that make use of 1:N biometric identification for resolution, deduplication, or fraud detection purposes SHALL NOT decline a user's enrollment without a manual review to confirm the automated search results and confirm that the results are not a false positive identification." - id: BIO-12_obj links: - rel: assessment-for href: "#BIO-12_smt" name: objective prose: "If a CSP employs 1:N biometric identification, confirm that it does not decline a user's enrollment into an identity service based on a positive 1:N comparison match." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-12_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP employs a manual review of any positive 1:N matches. - id: BIO-12_gdn name: guidance prose: One possible reason for a false positive result is twins submitting face photographs for different accounts with the same CSP. - id: BIO-13 title: Demographic Performance props: - value: "3.11 #12A" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-13_smt name: statement prose: Biometric verification technologies SHALL provide performance for applicants of different demographic types that is no more than 25% worse than the performance for the overall population. - id: BIO-13_obj links: - rel: assessment-for href: "#BIO-13_smt" name: objective prose: Confirm that the CSP employs biometric verification technologies that have been tested across different demographic groups and whose demonstrated performance differences do not exceed 25%. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-13_asm-examine name: assessment-method prose: Examine the CSP's biometric testing results to determine the performance characteristics of any biometric verification technologies across demographic groups. - id: BIO-13_gdn name: guidance prose: "For example, if the measured false nonmatch rate (FNMR) for the overall population is 0.006, the FNMR for a specific demographic group cannot exceed 0.0075. Similarly, if the false match rate (FMR) for the overall population is 0.0001, the FMR for each demographic group cannot exceed 0.000125." - id: BIO-14 title: Biometric Threshold props: - value: "3.11 #12B" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-14_smt name: statement prose: The biometric system SHALL be configured with a fixed threshold; it is not feasible to change the threshold for each demographic group. - id: BIO-14_obj links: - rel: assessment-for href: "#BIO-14_smt" name: objective prose: Confirm that the CSP employs a biometric threshold that is consistent across all demographic groups. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-14_asm-examine name: assessment-method prose: Examine the CSP's design or other documentation to determine that the biometric threshold is fixed and consistent across all demographic groups. - id: BIO-15 title: Demographic Categories props: - value: "3.11 #12C" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-15_smt name: statement prose: "Demographic categories to be considered SHALL include sex, age, and skin tone when these factors affect biometric performance." - id: BIO-15_obj links: - rel: assessment-for href: "#BIO-15_smt" name: objective prose: "Confirm that the CSP considers sex, age, and skin tone as demographic categories for its biometric performance testing." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-15_asm-examine name: assessment-method prose: "Examine the CSP's design or other documentation to determine that its biometric performance testing includes categories for sex, age, and skin tone." - id: BIO-16 title: Biometric Testing Standards props: - value: "3.11 #13A" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-16_smt name: statement prose: "All biometric performance tests SHALL be conformant to ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024, including demographics testing." - id: BIO-16_obj links: - rel: assessment-for href: "#BIO-16_smt" name: objective prose: "Confirm that all biometric performance testing, including demographics testing, employed by the CSP adheres to ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-16_asm-examine name: assessment-method prose: Examine the CSP's biometric test procedures to determine all its biometric performance testing adheres to ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024. - id: BIO-17 title: Testing Results Availability props: - value: "3.11 #14" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-17_smt name: statement prose: CSPs SHALL make the results of their biometric algorithm performance and biometric system operational test results publicly available. - id: BIO-17_obj links: - rel: assessment-for href: "#BIO-17_smt" name: objective prose: Confirm that the CSP makes the results of its biometric algorithm performance and biometric system operational test publicly available. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-17_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it makes the results of all its biometric systems testing publicly available. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-17_asm-examine-2 name: assessment-method prose: Examine a public website or other platform where the CSP has made the results of all biometric systems testing available. - id: BIO-17_gdn name: guidance prose: The CSP MAY provide these test results in summary form if the results indicate performance against the defined metrics in these guidelines and across the tested demographic groups. - id: BIO-18 title: Reasonable Assurance props: - value: "3.11 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-18_smt name: statement prose: "If a CSP collects biometric samples from applicants, it SHALL collect them in a way that provides reasonable assurance that the biometric characteristic is collected from the applicant and not another subject." - id: BIO-18_obj links: - rel: assessment-for href: "#BIO-18_smt" name: objective prose: "Determine if the CSP collects biometric samples from applicants and, if it does, confirm that it has employed mechanisms to increase the assurance that the sample is being collected from the applicant and not a different subject." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-18_asm-examine name: assessment-method prose: "Examine the CSP's design or other documentation to determine that it employs mechanisms, such as liveness detection and presentation attack detection, to increase the assurance that the sample being collected is from the applicant and not another subject." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BIO-18_asm-test name: assessment-method prose: Test the biometric collection system by employing a spoofing attack. - id: BIO-18_gdn name: guidance prose: "Mechanisms that mitigate risks associated with biometric collection fraud include liveness detection, and digital injection and other types of presentation attack detection (such as mechanisms to detect the presence of a foreign object)." - id: BIO-19 title: Remote Biometric Collection props: - value: "3.11 #2a" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-19_smt name: statement prose: "When collecting and comparing biometric characteristics remotely, the CSP SHALL implement presentation attack detection (PAD) capabilities that meet the impostor attack presentation accept rate (IAPAR) performance metric of <0.07 to confirm the genuine presence of a live human being and to mitigate spoofing and impersonation attempts." - id: BIO-19_obj links: - rel: assessment-for href: "#BIO-19_smt" name: objective prose: Confirm that the CSP has employed PAD capabilities that meet the specified IAPAR performance metric for its remote biometric collection or comparison functions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-19_asm-examine name: assessment-method prose: Examine the CSP's PAD testing results to determine that any remote biometric collection and comparison functions meet the specific IAPAR performance metric. - id: BIO-20 title: PAD Tests props: - value: "3.11 #2b" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-20_smt name: statement prose: All biometric presentation attack detection tests SHALL be conformant to ISO/IEC 30107-3:2023. - id: BIO-20_obj links: - rel: assessment-for href: "#BIO-20_smt" name: objective prose: Confirm that all biometric PAD tests employed by the CSP conform to ISO/IEC 30107-3:2023. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-20_asm-examine name: assessment-method prose: Examine the CSP's PAD testing procedures to determine that its biometric PAD tests conform to ISO/IEC 30107-3:2023. - id: BIO-21 title: On-Site Biometric Collection props: - value: "3.11 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BIO-21_smt name: statement prose: "When collecting biometric characteristics on-site, the CSP SHALL have the operator view the biometric source (e.g., fingers, face) for the presence of unexpected non-natural materials and perform such inspections as part of the proofing process." - id: BIO-21_obj links: - rel: assessment-for href: "#BIO-21_smt" name: objective prose: "Confirm that, for on-site biometric collection as part of the identity proofing process, human agents of the CSP examine the source of the biometric (e.g., fingers, face) for the presence of any unexpected, non-natural materials." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BIO-21_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that, for during on-site identity proofing processes, it has human operators view the source of any collected biometrics for the source of unexpected foreign materials." - id: VISUAL-1 title: Image Comparison Training props: - value: "3.12 #1A" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-1_smt name: statement prose: Proofing agents and trusted referees SHALL be trained to conduct visual facial image comparison. - id: VISUAL-1_obj links: - rel: assessment-for href: "#VISUAL-1_smt" name: objective prose: Confirm that the CSP trains its proofing agents and trusted referees in how to effectively conduct visual comparisons of facial images. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the training it provides to its agents that conduct visual comparison of facial images. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: VISUAL-1_asm-interview name: assessment-method prose: Interview one or more proofing agents or trusted referees to determine the training they received on the visual comparison of facial images. - id: VISUAL-2 title: Visual Match Training props: - value: "3.12 #1B" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-2_smt name: statement prose: "This training SHALL include techniques and methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence." - id: VISUAL-2_obj links: - rel: assessment-for href: "#VISUAL-2_smt" name: objective prose: "Confirm that the training the CSP provides for its proofing agents and trusted referees includes methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-2_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that its proofing agents and trusted referees have been trained in methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: VISUAL-2_asm-interview name: assessment-method prose: "Interview one or more proofing agents or trusted referees to determine that they have been trained in methods for identifying facial characteristics, unique traits, and other indicators of matches or non-matches between an applicant and their presented evidence." - id: VISUAL-3 title: Agent Assessment props: - value: "3.12 #2A" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-3_smt name: statement prose: Proofing agents and trusted referees SHALL be assessed on their ability to conduct visual facial image comparisons. - id: VISUAL-3_obj links: - rel: assessment-for href: "#VISUAL-3_smt" name: objective prose: Confirm that the CSP assesses its proofing agents and trusted referees on their ability to conduct visual facial image comparisons. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it assesses its proofing agents and/or trusted referees on their ability to conduct visual facial image comparisons. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: VISUAL-3_asm-interview name: assessment-method prose: Interview one or more proofing agents or trusted referees to determine that they have been assessed on their ability to conduct visual facial image comparisons. - id: VISUAL-4 title: Annual Reassessment props: - value: "3.12 #2B" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-4_smt name: statement prose: "Additionally, proofing agents and trusted referees SHALL be reassessed on an annual basis and remedially trained, if needed." - id: VISUAL-4_obj links: - rel: assessment-for href: "#VISUAL-4_smt" name: objective prose: "Confirm that the CSP annually reassesses its proofing agents and trusted referees on their ability to conduct visual facial image comparisons and provides remedial training, if needed." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-4_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policy for annually reassessing, and remedially training if needed, its proofing agents and/or trusted referees on their ability to conduct visual facial image comparisons." - id: VISUAL-5 title: Attack Training props: - value: "3.12 #2C" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-5_smt name: statement prose: "Training SHALL be designed to reflect potential real-world attack scenarios, such as comparing applicants to images of relatives, twins, and individuals with a similar appearance." - id: VISUAL-5_obj links: - rel: assessment-for href: "#VISUAL-5_smt" name: objective prose: Confirm that the CSP designs its visual image comparison training to address real-world scenarios that might result in incorrect visual comparison determinations. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-5_asm-examine name: assessment-method prose: Examine the CSP's design or other documentation to determine that it has designed its visual image comparison training to reflect potential real-world scenarios. - id: VISUAL-6 title: Visual Comparison Resources props: - value: "3.12 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-6_smt name: statement prose: "CSPs SHALL provide proofing agents and trusted referees that conduct visual facial comparisons during remote attended transactions with resources that support accurate comparisons, such as high-quality image feeds, high-definition monitors, and image analysis software." - id: VISUAL-6_obj links: - rel: assessment-for href: "#VISUAL-6_smt" name: objective prose: Confirm that the CSP provides its proofing agents and trusted referees that conduct visual facial comparisons during remote transactions with resources that support the accuracy of those comparisons. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-6_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it provides its agents with resources that support the accurate visual comparison of facial images during remote transactions. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: VISUAL-6_asm-interview name: assessment-method prose: Interview one or more proofing agents or trusted referees to determine that the CSP has provided them with resources that support the accurate visual comparison of facial images during remote transactions. - id: VISUAL-7 title: Documented Training Procedures props: - value: "3.12 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-7_smt name: statement prose: CSPs SHALL document their training and assessment procedures for visual image comparisons and make them available to RPs upon request. - id: VISUAL-7_obj links: - rel: assessment-for href: "#VISUAL-7_smt" name: objective prose: Confirm that the CSP has documented its visual image comparison training and assessment procedures and makes them available to their RPs upon request. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it has documented its training and assessment procedures for its agents that perform visual image comparisons AND its policy for providing this information to its RPs if requested. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-7_asm-examine-2 name: assessment-method prose: Examine an example of the information it provides to RPs about its visual image comparison training and assessment procedures. - id: VISUAL-8 title: Manual Review Training props: - value: "3.12 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VISUAL-8_smt name: statement prose: "These requirements SHALL apply for visual facial image comparisons done as manual reviews for failures of automated biometric comparisons (e.g., failure of 1:N checks conducted for resolution or deduplication)." - id: VISUAL-8_obj links: - rel: assessment-for href: "#VISUAL-8_smt" name: objective prose: "Confirm that the CSP trains and assesses its proofing agents and trusted referees who conduct manual reviews for failures of automated biometric comparisons, in accordance with the requirements provided in Sec. 3.12." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VISUAL-8_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that it trains and assesses its proofing agents and trusted referees who conduct manual reviews for failures of automated biometric comparisons, in accordance with the requirements provided in Sec. 3.12." - id: VISUAL-8_gdn name: guidance prose: "Also see Sec. 3.11 #11 and Sec. 3.15.2 #2." - id: PHYS-1 title: Auto Evidence Validation props: - value: "3.13 A #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-1_smt name: statement prose: "Automated evidence validation technology SHALL meet the following performance measures: document false acceptance rate (DFAR) of 0.1 or less; and document false rejection rate (DFRR) of 0.1 or less." - id: PHYS-1_obj links: - rel: assessment-for href: "#PHYS-1_smt" name: objective prose: "If the CSP employs automated evidence validation technology, confirm that it meets the specified performance metrics." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-1_asm-examine name: assessment-method prose: "Examine the CSP's evidence validation technology testing results to confirm that any automated evidence validation technology it employs meets the following performance metrics: document false acceptance rate (DFAR) of 0.1 or less; and document false rejection rate (DFRR) of 0.1 or less." - id: PHYS-1_gdn name: guidance prose: |- For the purposes of this document, the DFAR is the proportion of processed, fraudulent documents that the document validation system determined to be valid divided by the number of processed fraudulent documents. For the purposes of this document, DFRR is the proportion of processed, genuine documents that the document validation system determined to be invalid divided by the number of processed genuine documents. - id: PHYS-2 title: MRZ Data props: - value: "3.13 A #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-2_smt name: statement prose: "If a Machine Readable Zone (MRZ) or barcode is present on the evidence, the optical capture and inspection SHALL compare the MRZ data to the printed data on the evidence for consistency." - id: PHYS-2_obj links: - rel: assessment-for href: "#PHYS-2_smt" name: objective prose: "For evidence with MRZs or barcodes, confirm that the CSP employs optical capture and inspection capabilities that compare the MRZ data with the printed data on the evidence." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-2_asm-examine name: assessment-method prose: Examine the CSP's design or other documentation to determine that it employs optical capture and inspection capabilities that are able to compare evidence MRZ data to printed data. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PHYS-2_asm-test name: assessment-method prose: Test the CSPs implemented evidence validation technology to confirm it compares the MRZ to the printed data. - id: PHYS-3 title: Live Document Capture props: - value: "3.13 A #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-3_smt name: statement prose: CSPs SHALL implement live capture of documents during the validation process and SHALL implement passive or active document presence checks (also called document liveness). - id: PHYS-3_obj links: - rel: assessment-for href: "#PHYS-3_smt" name: objective prose: Confirm that the CSP employs live capture of documents during its validation process and that the live capture capabilities include document presence checks. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-3_asm-examine name: assessment-method prose: "Examine the CSP's design or other documentation to determine that it employs the live capture capabilities, including document presence checks." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PHYS-3_asm-test name: assessment-method prose: Test the CSPs evidence validation technologies to confirm that only live capture of documents is used and that images cannot be directly uploaded to the service. - id: PHYS-3_gdn name: guidance prose: "Live capture techniques confirm that the document is physically present and that the image captured during the identity proofing session is not a manipulated digital copy. For additional requirements to prevent the injection of modified media (i.e., digitally generated video or images of evidence), see Sec. 3.14." - id: PHYS-4 title: Optical Capture Peformance 1 props: - value: "3.13 A #4a" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-4_smt name: statement prose: CSPs SHALL assess the performance of employed optical capture and inspection technologies in conditions that are substantially similar to the operational environment and the types of evidence presented by the user base of the system. - id: PHYS-4_obj links: - rel: assessment-for href: "#PHYS-4_smt" name: objective prose: Confirm that the CSP assesses the performance of any employed optical capture and inspection technologies under conditions that are substantially similar to the operational environment and the types of evidence presented by the user base of the system. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the conditions under which it assesses the performance of any employed optical capture and inspection technologies. - id: PHYS-5 title: Optical Capture Peformance 2 props: - value: "3.13 A #4b" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-5_smt name: statement prose: These tests SHALL account for all available identity evidence types that the CSPs allow to be validated using optical capture and inspection technology. - id: PHYS-5_obj links: - rel: assessment-for href: "#PHYS-5_smt" name: objective prose: Confirm that the CSP's optical capture and inspection performance testing incorporates all the types of evidence it accepts to be validated using optical capture and inspection capabilities. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the types of evidence it includes in its performance assessments of optical capture and inspection technologies. - id: PHYS-6 title: Optical Capture Peformance 3 props: - value: "3.13 A #4c" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-6_smt name: statement prose: "If subscribers' documents, personal information, or images are used as part of the testing, it SHALL be on a voluntary basis and with subscriber notification and consent." - id: PHYS-6_obj links: - rel: assessment-for href: "#PHYS-6_smt" name: objective prose: "If the CSP uses documents, personal information, or images belonging to real users as part of its image capture performance testing, confirm that participation by the user is entirely voluntary and that the CSP first provides notification to the user and obtains their consent." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-6_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policy on using documents, personal information, and/or images from real users as part of its image capture performance testing." - id: PHYS-6_gdn name: guidance prose: These requirements apply to technologies that capture and validate images of physical identity evidence. They do not apply to validation techniques that rely on PKI or other cryptographic technologies that are embedded in the evidence itself. - id: PHYS-7 title: Capture Assessment Results props: - value: "3.13 A #6" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-7_smt name: statement prose: CSPs SHALL make the results of their testing publicly available. - id: PHYS-7_obj links: - rel: assessment-for href: "#PHYS-7_smt" name: objective prose: Confirm that the CSP makes publicly available the results of any performance assessments it conducts on its image capture and validation technologies. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it makes publicly available the results of any performance assessments it conducts on its image capture and validation technologies. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-7_asm-examine-2 name: assessment-method prose: Examine the CSP's performance assessment results on a publicly available website or platform. - id: PHYS-7_gdn name: guidance prose: "CSPs SHOULD have their evidence validation technology periodically tested by independent entities (e.g., accredited laboratories or research institutions) for their performance characteristic." - id: PHYS-8 title: Visual Inspection Training props: - value: "3.13 B #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-8_smt name: statement prose: "Proofing agents and trusted referees SHALL be trained and provided with the resources to visually inspect all forms of evidence supported by the CSP. This training SHALL include: authentic layouts and topography of evidence types; physical security features (e.g., raised letters, holographic features, microprinting); techniques for assessing features (e.g., tools to be used, where tactile inspection is needed, manipulation required to view specific features); and common indications of tampering (e.g., damage to the lamination, image modification)." - id: PHYS-8_obj links: - rel: assessment-for href: "#PHYS-8_smt" name: objective prose: Confirm that the CSP trains its proofing agents and trusted referees and provides them with the resources they need to visually inspect all forms of evidence supported by the CSP and confirm that this training includes all the specified elements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it trains its proofing agents and trusted referees and provides them with the resources they need to effectively visually inspect all forms of supported evidence. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PHYS-8_asm-interview name: assessment-method prose: Interview one or more proofing agents or trusted referees to determine what training and resources the CSP has provided to them on visually inspecting all forms of supported evidence. - id: PHYS-9 title: Visual Inspection Assessment props: - value: "3.13 B #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-9_smt name: statement prose: "Proofing agents and trusted referees SHALL be assessed regarding their ability to visually inspect evidence based on their training. Additionally, proofing agents and trusted referees SHALL be reassessed on an annual basis or whenever significant new threats to the evidence validation process are identified and remedially trained as needed." - id: PHYS-9_obj links: - rel: assessment-for href: "#PHYS-9_smt" name: objective prose: "Confirm that the CSP (1) assesses the ability of its trained proofing agents and trusted referees to visually inspect all types of supported evidence, (2) re-assesses these agents on an annual basis, and (3) provides remedial training as needed." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for assessing and annually reassessing its proofing agents and trusted referees on their ability to visually inspect all types of supported evidence. - id: PHYS-10 title: Visual Inspection Tools props: - value: "3.13 B #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-10_smt name: statement prose: Proofing agents and trusted referees SHALL be provided with specialized tools and equipment to support the visual inspection of evidence as appropriate for the identity evidence type. - id: PHYS-10_obj links: - rel: assessment-for href: "#PHYS-10_smt" name: objective prose: Confirm that the CSP provides its proofing agents and trusted referees with specialized tools that support the visual inspection of supported evidence types. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the types of tools it provides to its proofing agents and trusted referees to support the visual inspection of supported evidence types. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PHYS-10_asm-interview name: assessment-method prose: Interview one or more of the CSP's proofing agents and/or trusted referee to determine that they are provided with the specialized tools they need to effectively conduct visual inspection of supported evidence types. - id: PHYS-10_gdn name: guidance prose: "Specialized tools may include magnifiers, ultraviolet lights, barcode readers, etc." - id: PHYS-11 title: Remote Visual Inspections props: - value: "3.13 B #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-11_smt name: statement prose: Proofing agents and trusted referees who conduct visual inspections via remote means SHALL be provided with devices and internet connections that support sufficiently high-quality imagery to be able to effectively inspect presented evidence. - id: PHYS-11_obj links: - rel: assessment-for href: "#PHYS-11_smt" name: objective prose: Confirm that the CSP provides its proofing agents and trusted referees who conduct visual inspections in remote scenarios with devices and internet connections that support sufficiently high-quality imagery. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-11_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it provides its proofing agents and trusted referees who conduct visual inspection in remote scenarios with devices and internet connections that support high-quality imagery. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PHYS-11_asm-interview name: assessment-method prose: Interview one or more of the CSP's proofing agents and/or trusted referee who conduct visual inspection in remote scenarios to determine the types of devices and internet connections the CSP has provided them with. - id: PHYS-12 title: Documented Inspection Training props: - value: "3.13 B #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PHYS-12_smt name: statement prose: CSPs SHALL document their training and assessment procedures for visual inspections of evidence and make them available to RPs upon request. - id: PHYS-12_obj links: - rel: assessment-for href: "#PHYS-12_smt" name: objective prose: Confirm the CSP has documented its training and assessment procedures for visual inspections of evidence and makes them available to its RPs upon request. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-12_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it has documented its training and assessment procedures for visual inspection of evidence AND its policy for providing this information to its RPs if requested. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHYS-12_asm-examine-2 name: assessment-method prose: Examine an example of the information it provides to RPs about its evidence visual inspection training and assessment procedures. - id: DIGINJ-1 title: Media Technical Controls props: - value: "3.14 A #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DIGINJ-1_smt name: statement prose: CSPs SHALL implement technical controls to increase confidence that digital media is being produced by a genuine sensor during the proofing process. - id: DIGINJ-1_obj links: - rel: assessment-for href: "#DIGINJ-1_smt" name: objective prose: Confirm that the CSP has implemented technical controls that check for the use of genuine sensors during the identity proofing process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-1_asm-examine name: assessment-method prose: Examine the CSP's design or other documentation to determine the types of checks it employs to determine that sensors used during the identity proofing process are genuine. - id: DIGINJ-1_gdn name: guidance prose: "Many emerging attacks on both attended and unattended remote identity proofing processes pair digital injection attacks with increasingly effective and available generative AI tools. These AI tools are used to create or modify media that contain images or videos of applicants and evidence (i.e., deepfakes) to defeat automated document validation processes, biometric operations, and visual comparisons done by proofing agents. Injection attacks insert modified or forged media between the capture point (e.g., a device) and the element conducting the comparison or other operation (e.g., a server running the algorithms, a workstation used by a proofing agent)." - id: DIGINJ-2 title: Analyze Digital Media props: - value: "3.14 A #2a" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DIGINJ-2_smt name: statement prose: "CSPs SHALL analyze all digital media submitted during the identity proofing process for artifacts and indicators of potential modification, manipulation, tampering, or forgery." - id: DIGINJ-2_obj links: - rel: assessment-for href: "#DIGINJ-2_smt" name: objective prose: Confirm that the CSP employs a mechanism to analyze whether submitted digital media contains artifacts or other indicators of having been modified or forged. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-2_asm-examine name: assessment-method prose: Examine the CSP's design or other documentation to determine that it employs mechanisms for detecting indicators of digital media tampering or forgery. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: DIGINJ-2_asm-test name: assessment-method prose: Test the CSP's identity proofing workflow by attempting to submit an image or other type of media that has been digitally modified or forged. - id: DIGINJ-3 title: Image Analysis Algorithms props: - value: "3.14 A #2b" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DIGINJ-3_smt name: statement prose: Automated image analysis algorithms SHALL be tested against available attack artifacts and genuine media to provide a baseline of performance and to determine the expected rate of false positives and false negatives generated by the system. - id: DIGINJ-3_obj links: - rel: assessment-for href: "#DIGINJ-3_smt" name: objective prose: "If a CSP employs automated image analysis algorithms, confirm that these algorithms has been tested against available attack artifacts and genuine media and that expected rates of false positives and false negatives have been determined." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that any automated image analysis algorithms have been tested and the expected rates of false positives and false negatives have been determined. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-3_asm-examine-2 name: assessment-method prose: Examine the results of automated image analysis testing. - id: DIGINJ-4 title: Attack Artifact Testing props: - value: "3.14 A #2c" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DIGINJ-4_smt name: statement prose: The kinds of available attack artifacts that were tested and the corresponding false negative rates SHALL be documented and made available to RPs upon request. - id: DIGINJ-4_obj links: - rel: assessment-for href: "#DIGINJ-4_smt" name: objective prose: "If a CSP employs automated image analysis algorithms, confirm that is has documented the types of attack artifacts that were tested and the corresponding false negatives and that this information has been made available to any of its RPs that request it." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-4_asm-examine name: assessment-method prose: Examine the CSP's testing procedures and results to determine which attack artifacts were tested and the corresponding false negative rates. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-4_asm-examine-2 name: assessment-method prose: Examine an example contract for an RP to determine it includes the option for RPs to request this information. - id: DIGINJ-5 title: Authenticated Protected Channels props: - value: "3.14 A #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DIGINJ-5_smt name: statement prose: CSPs SHALL only use authenticated protected channels for the exchange of data during remote identity proofing processes. - id: DIGINJ-5_obj links: - rel: assessment-for href: "#DIGINJ-5_smt" name: objective prose: Confirm that the CSP always employs authenticated protected channels for the exchange of date during remote identity proofing processes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-5_asm-examine name: assessment-method prose: Examine the CSP's design or other documentation to determine that it uses authenticated protected channels for all exchanges of data. - id: DIGINJ-6 title: Manipulated Media Detection props: - value: "3.14 B #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DIGINJ-6_smt name: statement prose: "For remote attended scenarios, CSPs SHALL train proofing agents and trusted referees to look for indications of manipulated media." - id: DIGINJ-6_obj links: - rel: assessment-for href: "#DIGINJ-6_smt" name: objective prose: Confirm that the CSP trains its proofing agents and trusted referees how to look for indications of digital media fraud in remote attended scenarios. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-6_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it trains its proofing agents and trusted referees on how to look for indications that digital media has been manipulated. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: DIGINJ-6_asm-interview name: assessment-method prose: Interview one or more proofing agents and/or trusted referees to determine they have been trained how to look for manipulated digital media during attended remote scenarios. - id: DIGINJ-7 title: Human In The Loop props: - value: "3.14 B #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DIGINJ-7_smt name: statement prose: "For remote attended scenarios, CSPs SHALL introduce random \"human-in-the-loop\" cues into their capture processes to increase the possibility of forged or manipulated media being detected." - id: DIGINJ-7_obj links: - rel: assessment-for href: "#DIGINJ-7_smt" name: objective prose: Confirm that the CSP introduces random "human-in-the-loop" cues into its capture processes during remote attended scenarios - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DIGINJ-7_asm-examine name: assessment-method prose: Examine the CSP's design or other documentation to determine that it incorporates random "human-in-the-loop" cues into its digital media capture processes in remote attended scenarios. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: DIGINJ-7_asm-interview name: assessment-method prose: Interview one or more proofing agents or other personnel to determine that the CSP incorporates random "human-in-the-loop" cues into its digital media capture processes. - id: DIGINJ-7_gdn name: guidance prose: Examples of "human-in-the-loop" cues include requesting user movements or requesting that the user move objects between the capture sensor and their face. - id: EXCEPT-1 title: Documented Exception Handling props: - value: 3.15 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-1_smt name: statement prose: CSPs SHALL document their operational processes for dealing with errors and handling exceptions. - id: EXCEPT-1_obj links: - rel: assessment-for href: "#EXCEPT-1_smt" name: objective prose: Confirm that the CSP has documented its error and exception handling processes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its operational processes for dealing with errors and handling exceptions. - id: EXCEPT-1_gdn name: guidance prose: |- Throughout the identity proofing process, there are many points at which errors or failures may occur. Such exceptions to a standard identity proofing workflow include process failures (e.g., when a user does not possess the required evidence), technical failures (e.g., when an integrated service is not available), and failures due to user error (e.g., when an applicant is unable to capture a clear image of their identity evidence using remote validation tools). These documented processes SHOULD include providing trusted referees to support applicants who are otherwise unable to meet the requirements of IALs 1 and 2. Additionally, CSPs SHOULD support the use of applicant references who can vouch for an applicant's attributes, conditions, or identity. - id: EXCEPT-2 title: Trusted Referee Notification props: - value: "3.15.1 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-2_smt name: statement prose: The CSP SHALL notify the public of the availability of trusted referee services and how such services are obtained. - id: EXCEPT-2_obj links: - rel: assessment-for href: "#EXCEPT-2_smt" name: objective prose: "[If the CSP provides trusted referees], confirm that it notifies the public of their availability and how to obtain their services." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine how it notifies the public about the availability of trusted referee services. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-2_asm-examine-2 name: assessment-method prose: Examine the information about the availability and use of trusted referees on the CSPs website or identity system. - id: EXCEPT-2_gdn name: guidance prose: "Trusted referees are used to increase access to online services by facilitating the identity proofing and enrollment of individuals who are otherwise unable to prove their identities using the usual identity proofing process for a specific IAL. A non-exhaustive list of examples of individuals who may need the assistance of trusted referees includes those who do not possess and cannot obtain the required identity evidence, persons with disabilities, older individuals, persons experiencing homelessness, individuals with limited access to online services or computing devices, persons without a bank account or with limited credit history, victims of identity theft, individuals displaced or affected by natural disasters, and children under 18. Trusted referees can be provided by the CSP, a third party, or an RP." - id: EXCEPT-3 title: Trusted Referee Policies props: - value: "3.15.1 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-3_smt name: statement prose: "The CSP SHALL establish written policies and procedures for the use of trusted referees as part of its practice statement, as specified in Sec. 3.1." - id: EXCEPT-3_obj links: - rel: assessment-for href: "#EXCEPT-3_smt" name: objective prose: Confirm that the CSP has established written policies and procedures for the use of trusted referees. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine is has established written procedures for the use of trusted referees. - id: EXCEPT-4 title: Trusted Referee Training props: - value: "3.15.1 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-4_smt name: statement prose: |- The CSP SHALL train and certify its trusted referees to make risk-based decisions that allow applicants to be successfully identity-proofed based on their unique circumstances. At a minimum, such training SHALL include: (a) Document identification and validation, such as common templates, security features, layouts, and topography (see Sec. 3.13). (b) Indicators of fraudulent documents, such as damage, tampering, modification, fabrication, or forgery (see Sec. 3.13). (c) Facial image comparisons to verify applicants against presented documents (see Sec. 3.12). (d) Indicators of social engineering exhibited by an applicant, such as distress, confusion, or coercion. (e) An annual review of the trusted referee's abilities to visually inspect evidence and make visual facial image comparisons (see Sec. 3.12). - id: EXCEPT-4_obj links: - rel: assessment-for href: "#EXCEPT-4_smt" name: objective prose: Confirm that the CSP trains and certifies its trusted referees in accordance to the specified requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the training and certification it provides to its trusted referees. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: EXCEPT-4_asm-interview name: assessment-method prose: Interview one or more of the CSP's trusted referees to determine that they were certified by the CSP and received the specified training. - id: EXCEPT-5 title: TR Usage Record props: - value: "3.15.1 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-5_smt name: statement prose: "The CSP SHALL establish a record of any identity proofing session that involves a trusted referee, including the reasons why a trusted referee was used (e.g., automated process failure, applicant request, established exception policy), the identity of the trusted referee, what evidence was presented, which processes were completed (e.g., validation or verification), and the trusted referee's decision and, if negative, their rationale." - id: EXCEPT-5_obj links: - rel: assessment-for href: "#EXCEPT-5_smt" name: objective prose: "Confirm that the CSP establishes a record whenever a trusted referee is involved in the identity proofing of an applicant, and that this record includes, at the minimum, the details specified in this requirement." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it establishes detailed records of identity proofing transactions that involve a trusted referee. - id: EXCEPT-5_gdn name: guidance prose: "While the details of trusted referee usage will necessarily be associated with the subject being identity proofed, it is expected that some or all of this information will not be visible to the subject through in subscriber account." - id: EXCEPT-6 title: ALL Applicable Requirements props: - value: "3.15.1 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-6_smt name: statement prose: These sessions SHALL be consistent with the requirements of these proofing types based on the IAL of the proofing event. - id: EXCEPT-6_obj links: - rel: assessment-for href: "#EXCEPT-6_smt" name: objective prose: "Confirm the CSP's policy on meeting all applicable requirements for identity proofing transactions, regardless of whether or not a trusted referee is involved." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-6_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that all applicable requirements for identity proofing transactions, regardless of whether or not a trusted referee is involved." - id: EXCEPT-6_gdn name: guidance prose: "All applicable requirements must be met, regardless of the use of trusted referees." - id: EXCEPT-7 title: Trusted Referee Use props: - value: "3.15.2 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-7_smt name: statement prose: CSPs SHALL document which types of exceptions and failures are eligible for the use of a trusted referee. - id: EXCEPT-7_obj links: - rel: assessment-for href: "#EXCEPT-7_smt" name: objective prose: Confirm the CSP has documented the scenarios that are eligible for trusted referee involvement in an identity proofing transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine which scenarios are eligible for the use of a trusted referee. - id: EXCEPT-8 title: Automated Validation Failures props: - value: "3.15.2 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-8_smt name: statement prose: |- If a CSP offers trusted referees [are offered for failures in completing automated validation processes], the following requirements apply: (a) CSPs SHALL provide a policy for additional evidence types that may be used to corroborate core attributes or changes in core attributes. (b) Trusted referees SHALL review additional evidence types for authenticity to the greatest degree allowed by the evidence. (c) If no authoritative or credible records are available to support validation, the trusted referee MAY compare the attributes on additional pieces of evidence with the strongest piece of evidence available to corroborate the consistency of core attributes. (d) If there is a partial mismatch of core attributes to authoritative records, the trusted referee SHALL review evidence that supports the legitimacy of the asserted attribute value (e.g., recent move or change of name). - id: EXCEPT-8_obj links: - rel: assessment-for href: "#EXCEPT-8_smt" name: objective prose: "Determine if the CSP offers trusted referees to assist with automated validation failures and, if it does, confirm that their involvement in these scenarios adheres to the specified requirements." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy on trusted referee involvement in automated validation failures. - id: EXCEPT-8_gdn name: guidance prose: "CSPs SHOULD offer trusted referee services for failures in completing automated validation processes, such as mismatched core attributes or the absence of the applicant in a record source." - id: EXCEPT-9 title: Applicant Reference Notification props: - value: "3.15.3 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-9_smt name: statement prose: The CSP SHALL notify the public of the allowability of applicant references and any requirements for the relationship between the reference and an applicant. - id: EXCEPT-9_obj links: - rel: assessment-for href: "#EXCEPT-9_smt" name: objective prose: Confirm if the CSP provides a notice to the public about the allowability of applicant references to assist in identity proofing transactions along with any requirements for their use. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it notifies the public about the allowability of applicant references and the requirements for their use. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-9_asm-examine-2 name: assessment-method prose: Examine the information about the allowability of and requirements for applicant reference use on the CSP's public website or identity system. - id: EXCEPT-9_gdn name: guidance prose: |- Applicant references are individuals who participate in the identity proofing of an applicant in order to vouch for the applicant's identity, attributes, or circumstances related to the applicant's ability to complete identity proofing. Applicant references are not agents of the CSP, but rather representatives of the applicant who have sufficient knowledge to aid in the completion of identity proofing when other forms of evidence, validation, and verification are not available. Applicant references are permissible at IAL 1 and IAL 2 only. - id: EXCEPT-10 title: Applicant Reference Policy props: - value: "3.15.3 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-10_smt name: statement prose: "The CSP SHALL establish written policies and procedures for the use of applicant references as part of its practice statement, as specified in Sec. 3.1." - id: EXCEPT-10_obj links: - rel: assessment-for href: "#EXCEPT-10_smt" name: objective prose: Confirm that the CSP has written policies and procedures for the use of applicant references. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it has written policies for the use of applicant references. - id: EXCEPT-11 title: Applicant Reference Proofing props: - value: "3.15.3 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-11_smt name: statement prose: The CSP SHALL identity-proof an applicant reference to the same or higher IAL intended for the applicant. - id: EXCEPT-11_obj links: - rel: assessment-for href: "#EXCEPT-11_smt" name: objective prose: "Determine if the CSP allows the use of applicant references and, if it does, confirm that all applicant references are identity-proofed to the same or higher IAL as the applicant or applicants they are supporting." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-11_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it identity proofs applicant reference to the same or higher IAL as the applicants. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-11_asm-examine-2 name: assessment-method prose: Examine one or more sample records of subscribers who were identity proofed using an applicant reference and determine the IAL associated with both the subscriber and their reference. - id: EXCEPT-12 title: AR Privacy Assessment props: - value: "3.15.3 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-12_smt name: statement prose: "The CSP SHALL include the information collected, recorded, and retained for identity proofing the applicant references in its privacy risk assessment, as required in section Sec. 3.3.1." - id: EXCEPT-12_obj links: - rel: assessment-for href: "#EXCEPT-12_smt" name: objective prose: Confirm that the CSP included all personal data associated with the use of applicant references in its privacy risk assessment. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-12_asm-examine name: assessment-method prose: Examine the CSP's privacy risk assessment documentation to determine it has included data associated with the use of applicant references. - id: EXCEPT-13 title: Applicant Reference Record props: - value: "3.15.3 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-13_smt name: statement prose: The CSP SHALL record the use of an applicant reference in the subscriber account and maintain a record of the applicant reference and their relationship to the applicant. - id: EXCEPT-13_obj links: - rel: assessment-for href: "#EXCEPT-13_smt" name: objective prose: "Confirm that the CSP records the use of applicant references in the associated subscriber accounts, including their relationship to the applicant." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-13_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine how it records the use of applicant references. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-13_asm-examine-2 name: assessment-method prose: Examine one or more subscriber accounts to determine how it records the use of an applicant reference. - id: EXCEPT-14 title: RP Risk Assessment props: - value: "3.15.3 #5" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-14_smt name: statement prose: "The RP SHALL conduct a risk assessment to determine the applicability, business requirements, and potential risks associated with excluding or including applicant references for proofing events." - id: EXCEPT-14_obj links: - rel: assessment-for href: "#EXCEPT-14_smt" name: objective prose: Confirm that the RP has conducted a risk assessment that considers the impacts of both allowing and not allowing the use of applicant references. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-14_asm-examine name: assessment-method prose: Examine the results of the RP's risk assessment to determine it has thoroughly considered whether or not to allow the acceptance of users whose identity proofing process was supported by applicant references. - id: EXCEPT-15 title: Acceptable AR Uses props: - value: 3.15.4 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-15_smt name: statement prose: "If CSPs allow the use of applicant references, the CSPs and the RPs that use their services SHALL document all acceptable uses for applicant references in their contracts or trust agreements." - id: EXCEPT-15_obj links: - rel: assessment-for href: "#EXCEPT-15_smt" name: objective prose: "If CSPs allow for the use of applicant references, confirm that acceptable uses of their services are documented in any contacts or trust agreements with RPs." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-15_asm-examine name: assessment-method prose: "Examine a sample RP contract or trust agreement and determine that the CSP has included acceptable uses, if any, for applicant references." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: EXCEPT-15_asm-interview name: assessment-method prose: Interview appropriate personnel to determine that the CSP includes information about the acceptable uses of applicant references in its contracts or trust agreements with the RPs that use its service. - id: EXCEPT-16 title: AR Legal Requirements props: - value: 3.15.4 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-16_smt name: statement prose: "In all instances, the CSP SHALL establish a record of the role that the applicant reference played in the process and document these actions sufficient to support any applicable legal and regulatory requirements." - id: EXCEPT-16_obj links: - rel: assessment-for href: "#EXCEPT-16_smt" name: objective prose: "Determine that the CSP has identified any legal or regulatory requirements associated with the use of applicant references, and confirm that it records sufficient details about the use of an applicant reference to support those requirements." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-16_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine any legal or regulatory requirements that apply to the use of applicant references, and determine that the CSP records sufficient details about each use of an applicant reference to meet these requirements." - id: EXCEPT-17 title: Applicant Reference Liability props: - value: 3.15.4 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-17_smt name: statement prose: CSPs SHALL make available to the applicant reference clear and understandable information relative to the legal and liability impacts that may result from their participation as an applicant reference. - id: EXCEPT-17_obj links: - rel: assessment-for href: "#EXCEPT-17_smt" name: objective prose: Confirm that the CSP makes information available to potential applicant references about any legal or liability implications associated with their participation in the identity proofing of an applicant. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-17_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the information it provides to potential applicant references. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-17_asm-examine-2 name: assessment-method prose: Examine the actual information it provides to applicant references. - id: EXCEPT-18 title: AR Relationship Requirements props: - value: "3.15.5 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-18_smt name: statement prose: The CSP and RP SHALL establish requirements for applicant reference relationship confirmation processes and document them in any contracts or trust agreements. - id: EXCEPT-18_obj links: - rel: assessment-for href: "#EXCEPT-18_smt" name: objective prose: Confirm that the requirements and process for confirming the relationship between an applicant and their applicant reference is documented in any contracts or trust agreements between CSPs and RPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-18_asm-examine name: assessment-method prose: Examine a sample contract or trust agreement to determine that it includes information about the requirements and process for confirming the relationship between an applicant and their applicant reference. - id: EXCEPT-19 title: Applicant Reference Evidence props: - value: "3.15.5 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-19_smt name: statement prose: The CSP SHALL make a list of acceptable evidence of relationship available to the applicant reference prior to initiating the relationship confirmation process. - id: EXCEPT-19_obj links: - rel: assessment-for href: "#EXCEPT-19_smt" name: objective prose: Confirm that the CSP provides a list of acceptable evidence of the relationship between an applicant and their applicant reference prior to initiating the relationship confirmation process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-19_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP provides a list of acceptable evidence of the relationship between an applicant and their applicant reference prior to initiating the relationship confirmation process. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: EXCEPT-19_asm-test name: assessment-method prose: Test the applicant reference workflow to determine that the CSP provides a list of acceptable evidence of the relationship between an applicant and their reference prior to initiating the relationship confirmation process. - id: EXCEPT-20 title: AR Relationship Evidence props: - value: "3.15.5 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-20_smt name: statement prose: "The CSP SHALL request evidence of the applicant's relationship (e.g., notarized power of attorney, a professional certification)." - id: EXCEPT-20_obj links: - rel: assessment-for href: "#EXCEPT-20_smt" name: objective prose: Confirm that the CSP collects evidence supporting the relationship between an applicant and their applicant reference. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-20_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that the CSP collects evidence supporting the relationship between an applicant and their applicant reference. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: EXCEPT-20_asm-test name: assessment-method prose: Test the applicant reference workflow to determine that the CSP collects evidence supporting the relationship between an applicant and their applicant reference. - id: EXCEPT-21 title: Record Relationship Evidence props: - value: "3.15.5 #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-21_smt name: statement prose: "Upon successfully identity proofing an applicant, the CSP SHALL record the evidence used to confirm the applicant reference's relationship to the applicant in the subscriber account." - id: EXCEPT-21_obj links: - rel: assessment-for href: "#EXCEPT-21_smt" name: objective prose: Confirm that the CSP records the evidence used to confirm the relationship between an applicant and their applicant reference and associates it with the subscriber's account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-21_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that records the evidence used to confirm the relationship between an applicant and their applicant reference in the subscriber's account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-21_asm-examine-2 name: assessment-method prose: Examine one or more sample records of subscribers who were identity proofed using an applicant reference and determine that it includes information about the type(s) of evidence used to confirm the relationship between the applicant and their applicant reference. - id: EXCEPT-22 title: Minors Evidence Policy props: - value: "3.15.6 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-22_smt name: statement prose: The CSP SHALL establish a written policy and procedures as part of its practice statement for identity proofing minors who may not be able to meet the evidence requirements for a given IAL. - id: EXCEPT-22_obj links: - rel: assessment-for href: "#EXCEPT-22_smt" name: objective prose: Confirm that the CSP has documented its policy and procedures for the identity proofing of minors who are unable to meet the evidence requirements for a given IAL. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-22_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and procedures for identity proofing minors who are unable to meet the IAL evidence requirements. - id: EXCEPT-23 title: COPPA props: - value: "3.15.6 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-23_smt name: statement prose: "When interacting with persons under the age of 13, the CSP SHALL ensure compliance with the Children's Online Privacy Protection Act of 1998 [COPPA] or other laws and regulations that deal with the protection of minors, as applicable." - id: EXCEPT-23_obj links: - rel: assessment-for href: "#EXCEPT-23_smt" name: objective prose: Confirm that the CSP complies with COPPA and any other laws and regulations that deal with the protection of minors. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-23_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for complying with COPPA and any other applicable laws and regulations that deal with the protection of minors. - id: EXCEPT-24 title: Minors' Applicant References props: - value: "3.15.6 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXCEPT-24_smt name: statement prose: CSPs SHALL support the use of applicant references when interacting with individuals under the age of 18. - id: EXCEPT-24_obj links: - rel: assessment-for href: "#EXCEPT-24_smt" name: objective prose: Confirm that the CSP allows for the use of applicant references for the identity proofing of individuals under the age of 18. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXCEPT-24_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for complying for supporting the use of applicant references for the identity proofing of individuals under the age of 18. - id: ELEVATE-1 title: Elevating Assurance Levels props: - value: "3.16 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ELEVATE-1_smt name: statement prose: CSPs SHALL document their approved approaches for elevating assurance levels in their practice statements. - id: ELEVATE-1_obj links: - rel: assessment-for href: "#ELEVATE-1_smt" name: objective prose: "If the CSP supports the elevation of subscriber assurance levels, confirm that the CSP has documented its policy and approved approaches for this process." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ELEVATE-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and approaches for elevating subscriber assurance levels. - id: ELEVATE-1_gdn name: guidance prose: CSPs SHOULD allow subscribers to elevate IALs related to their subscriber accounts to support higher assurance transactions with RPs. - id: ELEVATE-2 title: Account Upgrade Authentication props: - value: "3.16 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ELEVATE-2_smt name: statement prose: CSPs SHALL require subscribers to authenticate at the highest authentication assurance level (AAL) available on their account prior to initiating the upgrade process. - id: ELEVATE-2_obj links: - rel: assessment-for href: "#ELEVATE-2_smt" name: objective prose: "If the CSP supports the elevation of subscriber assurance levels, confirm that it requires subscribers to authenticate at the highest AAL available on their account prior to initiating the upgrade process." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ELEVATE-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it subscribers to authenticate at the highest AAL available on their account prior to initiating the upgrade process. - id: ELEVATE-3 title: Additional Evidence Requirements props: - value: "3.16 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ELEVATE-3_smt name: statement prose: "CSPs SHALL collect, validate, and verify additional evidence, as mandated to achieve the higher IAL." - id: ELEVATE-3_obj links: - rel: assessment-for href: "#ELEVATE-3_smt" name: objective prose: "If the CSP supports the elevation of subscriber assurance levels, confirm that it collects, validates, and verifies additional evidence, as needed to meet the requirements of the higher IAL." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ELEVATE-3_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that it collects, validates, and verifies additional evidence, as needed to meet the requirements of the higher IAL." - id: IAL1-1 title: IAL1 Documented Process props: - value: "4.1.1 #2" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-1_smt name: statement prose: CSPs that combine elements of different proofing types SHALL document their hybrid process and state how the applicable requirements for each of the employed proofing types are met. - id: IAL1-1_obj links: - rel: assessment-for href: "#IAL1-1_smt" name: objective prose: "If the CSP employs a hybrid process, confirm that it is documented, and such documentation includes details about how the applicable requirements for each proofing type are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine how its hybrid identity proofing process meets the applicable requirements. - id: IAL1-1_gdn name: guidance prose: "IAL1 identity proofing MAY be delivered through any proofing type, as described in Sec. 2.1.3. CSPs MAY combine proofing types and their stated requirements to create hybrid processes. For example, a CSP might leverage remote unattended identity proofing validation processes in advance of a remote attended session where the verification will take place." - id: IAL1-2 title: IAL1 Evidence Collection props: - value: 4.1.2 class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-2_smt name: statement prose: "For identity proofing at IAL1, the CSP SHALL collect: one piece of FAIR evidence that can be digitally validated or that includes a facial portrait or other biometric; OR, one piece of STRONG evidence; OR, one piece of SUPERIOR evidence." - id: IAL1-2_obj links: - rel: assessment-for href: "#IAL1-2_smt" name: objective prose: Confirm that the CSP collects the specified evidence for identity proofing at IAL 1. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-2_asm-examine name: assessment-method prose: Examine the CSP's practice statement or other documentation to determine its evidence collection requirements for IAL 1. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-2_asm-test name: assessment-method prose: Test the CSP's identity proofing workflow to determine that documented evidence collection processes are followed. - id: IAL1-3 title: IAL1 Attribute Collection props: - value: 4.1.3 class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-3_smt name: statement prose: "The CSP SHALL collect all core attributes, including at least one government identifier." - id: IAL1-3_obj links: - rel: assessment-for href: "#IAL1-3_smt" name: objective prose: "Confirm that the CSP collects all core attributes, including at least one government identifier." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for collecting core attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-3_asm-test name: assessment-method prose: Test the CSP's identity proofing workflow to determine that all documented core attribute collection processes are followed. - id: IAL1-3_gdn name: guidance prose: "Validated evidence is the preferred source of identity attributes. If the presented identity evidence does not provide all of the attributes that the CSP considers to be core attributes, it MAY collect attributes that are self-asserted by the applicant." - id: IAL1-4 title: IAL1 Evidence Validation props: - value: 4.1.4 class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-4_smt name: statement prose: "Each piece of evidence presented SHALL be validated using one of the methods [provided in Sec. 4.1.4]." - id: IAL1-4_obj links: - rel: assessment-for href: "#IAL1-4_smt" name: objective prose: Confirm that the CSP validates all collected evidence as specified. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its evidence validation policy and processes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-4_asm-test name: assessment-method prose: Test the CSP's identity proofing workflow to determine that all documented validation processes are followed. - id: IAL1-5 title: IAL1 Attribute Validation props: - value: "4.1.5 #1" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-5_smt name: statement prose: The CSP SHALL validate all core attributes and the government identifier against an authoritative or credible source to determine accuracy. - id: IAL1-5_obj links: - rel: assessment-for href: "#IAL1-5_smt" name: objective prose: Confirm that the CSP validates all collected core attributes as specified. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its core attribute validation policy and processes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-5_asm-test name: assessment-method prose: Test the CSP's identity proofing workflow to determine that all core attribute validation processes are followed. - id: IAL1-5_gdn name: guidance prose: |- CSPs SHOULD evaluate attributes obtained from different sources (e.g., presented evidence, self-asserted, authoritative or credible sources) for consistency. CSPs SHOULD validate any reference numbers on the presented identity evidence, if available. - id: IAL1-6 title: IAL1 Verification Requirements props: - value: 4.1.6 A class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-6_smt name: statement prose: "The CSP SHALL verify the applicant's ownership of one piece of evidence using one of the methods [provided in 4.1.6]." - id: IAL1-6_obj links: - rel: assessment-for href: "#IAL1-6_smt" name: objective prose: Confirm that the CSP verifies the applicant's ownership of at least one piece of collected evidence using one of the specified methods. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-6_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and processes for performing verification. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-6_asm-test name: assessment-method prose: Test the CSP's identity proofing workflow to determine that all documented verification processes are followed. - id: IAL1-7 title: Async Visual Comparison props: - value: 4.1.6 B class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-7_smt name: statement prose: "If the visual comparison is performed asynchronously at a later time, the CSP SHALL implement PAD and passive or active document presence checks to increase confidence that both the live applicant and physical documents are present during the submission or capture event." - id: IAL1-7_obj links: - rel: assessment-for href: "#IAL1-7_smt" name: objective prose: Confirm that the CSP has implemented PAD and passive and active document liveness checks for the asynchronous visual comparison of an applicant to their identity evidence. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it has implemented PAD and passive and active document liveness checks for the asynchronous visual comparison of an applicant to their identity evidence. - id: IAL1-8 title: IAL1 Video Session props: - value: "4.1.8 #1" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-8_smt name: statement prose: "For Remote Attended identity proofing, the applicant SHALL remain in view of the proofing agent during each step of the proofing process." - id: IAL1-8_obj links: - rel: assessment-for href: "#IAL1-8_smt" name: objective prose: "For remote attended video sessions, confirm the CSP requires that the applicant is visible to the proofing agent for each step of the identity proofing process." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its requirements for applicant visibility during remote attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL1-8_asm-interview name: assessment-method prose: Interview appropriate personnel to determine the process for viewing applicants during each step of remote attended identity proofing sessions. - id: IAL1-9 title: IAL1 Video Quality props: - value: "4.1.8 #2" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-9_smt name: statement prose: "For Remote Attended identity proofing, the video quality SHALL be sufficient to support the necessary steps in the validation and verification processes, such as inspecting evidence and comparing the applicant to the evidence." - id: IAL1-9_obj links: - rel: assessment-for href: "#IAL1-9_smt" name: objective prose: "For remote attended video sessions, confirm the video quality is sufficient to support the needs of the identity proofing process." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it employs video technologies of sufficient quality to support the identity proofing processes. - id: IAL1-10 title: IAL1 Remote Attended Coercion Training props: - value: "4.1.8 #3" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-10_smt name: statement prose: "For Remote Attended identity proofing, the proofing agent SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the session." - id: IAL1-10_obj links: - rel: assessment-for href: "#IAL1-10_smt" name: objective prose: Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-10_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL1-10_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the training they've received to identify these signs. - id: IAL1-11 title: IAL1 Remote Attended Recorded Video props: - value: "4.1.8 #4" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-11_smt name: statement prose: |- For Remote Attended identity proofing, if the CSP records a video session, the following further requirements apply: (a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session. (b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session. (c) The CSP SHALL publish their retention schedule and deletion processes for all video records. - id: IAL1-11_obj links: - rel: assessment-for href: "#IAL1-11_smt" name: objective prose: "If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-11_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording remote attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-11_asm-test name: assessment-method prose: Test the remote attended identity proofing process and determine that all the specified requirements for recording remote attended identity proofing sessions are met. - id: IAL1-12 title: IAL1 Injection Protection props: - value: "4.1.8 #5" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-12_smt name: statement prose: "For Remote Attended identity proofing, the CSP SHALL implement injection protection and modified media controls, as defined in Sec. 3.14." - id: IAL1-12_obj links: - rel: assessment-for href: "#IAL1-12_smt" name: objective prose: Confirm that the CSP employs injection protection and controls against modified media. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-12_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it has implemented injection project and modified media controls. - id: IAL1-13 title: IAL1 Remote Attended Fraud Flags props: - value: "4.1.8 #6" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-13_smt name: statement prose: "For Remote Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to flag events for potential fraud." - id: IAL1-13_obj links: - rel: assessment-for href: "#IAL1-13_smt" name: objective prose: Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-13_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL1-13_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud. - id: IAL1-14 title: IAL1 On-Site Attended Physical Setting props: - value: "4.1.9 #1" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-14_smt name: statement prose: "For On-site Attended identity proofing, the CSP SHALL provide a physical setting in which on-site identity proofing sessions are conducted." - id: IAL1-14_obj links: - rel: assessment-for href: "#IAL1-14_smt" name: objective prose: Confirm the CSP provides physical location in for on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-14_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that is provides a physical setting for on-site attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-14_asm-examine-2 name: assessment-method prose: Examine a location where the CSPs conducts on-site identity proofing. - id: IAL1-15 title: IAL1 On-Site Attended Security Controls props: - value: "4.1.9 #2" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-15_smt name: statement prose: "For On-site Attended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes." - id: IAL1-15_obj links: - rel: assessment-for href: "#IAL1-15_smt" name: objective prose: Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-15_asm-examine name: assessment-method prose: "Examine the CSP's practices statement, certification information, or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher." - id: IAL1-16 title: IAL1 On-Site Attended Coercion Training props: - value: "4.1.9 #3" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-16_smt name: statement prose: "For On-site Attended identity proofing, CSP proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the on-site session." - id: IAL1-16_obj links: - rel: assessment-for href: "#IAL1-16_smt" name: objective prose: Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-16_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL1-16_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the training they've received to identify these signs. - id: IAL1-17 title: IAL1 On-Site Attended Recorded Video props: - value: "4.1.9 #4" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-17_smt name: statement prose: |- For On-site Attended identity proofing, if the CSP records a video session, the following additional requirements apply: (a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session. (b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session. (c) The CSP SHALL publish their retention schedule and deletion processes for all video records. - id: IAL1-17_obj links: - rel: assessment-for href: "#IAL1-17_smt" name: objective prose: "If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-17_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-17_asm-test name: assessment-method prose: Test the on-site attended identity proofing process to determine that all the requirements for recording video sessions are met. - id: IAL1-18 title: IAL1 On-Site Attended Fraud Flags props: - value: "4.1.9 #5" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-18_smt name: statement prose: "For On-site Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to covertly flag events for potential fraud." - id: IAL1-18_obj links: - rel: assessment-for href: "#IAL1-18_smt" name: objective prose: Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-18_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL1-18_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud. - id: IAL1-19 title: IAL1 On-Site Unattended Physical Setting props: - value: "4.1.10 #1" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-19_smt name: statement prose: "For On-site Unattended identity proofing, the CSP SHALL provide a physical setting in which on-site identity proofing sessions are conducted." - id: IAL1-19_obj links: - rel: assessment-for href: "#IAL1-19_smt" name: objective prose: Confirm the CSP provides physical location in for on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-19_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that is provides a physical setting for on-site attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-19_asm-examine-2 name: assessment-method prose: Examine a location where the CSPs conducts on-site identity proofing. - id: IAL1-20 title: IAL1 On-Site Unattended Security Controls props: - value: "4.1.10 #2" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-20_smt name: statement prose: "For On-site Unattended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes." - id: IAL1-20_obj links: - rel: assessment-for href: "#IAL1-20_smt" name: objective prose: Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-20_asm-examine name: assessment-method prose: "Examine the CSP's practices statement, certification information, or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher." - id: IAL1-21 title: IAL1 Device Inspection props: - value: "4.1.10 #3" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-21_smt name: statement prose: "For On-site Unattended identity proofing, all devices SHALL be inspected periodically by trained technicians to deter tampering, modification, or damage." - id: IAL1-21_obj links: - rel: assessment-for href: "#IAL1-21_smt" name: objective prose: "Confirm that the CSP has a policy for ensuring that all equipment used for on-site attended identity proofing is periodically inspected by technicians who are trained to detect tampering, modification, and damage." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-21_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for inspecting equipment used for on-site attended identity proofing. - id: IAL1-22 title: IAL1 On-Site Unattended Recorded Video props: - value: "4.1.10 #4" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-22_smt name: statement prose: |- For On-site Unattended identity proofing, if the CSP records a video session, the following additional requirements apply: (a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session. (b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session. (c) The CSP SHALL publish their retention schedule and deletion processes for all video records. - id: IAL1-22_obj links: - rel: assessment-for href: "#IAL1-22_smt" name: objective prose: "If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-22_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site unattended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-22_asm-test name: assessment-method prose: Test the on-site unattended identity proofing process to determine that all the requirements for recording video sessions are met. - id: IAL1-23 title: IAL1 Proofing Notification props: - value: 4.1.11 class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-23_smt name: statement prose: "Upon the successful completion of identity proofing at IAL1, the CSP SHALL send a notification of proofing to a validated address for the applicant, as specified in Sec. 3.10." - id: IAL1-23_obj links: - rel: assessment-for href: "#IAL1-23_smt" name: objective prose: Confirm that the CSP sends notifications of proofing to validated addresses for applicants after they have successfully complete identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-23_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that it sends notifications of proofing to applicant's validated addresses, upon successful completion of identity proofing." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-23_asm-test name: assessment-method prose: Test the identity proofing workflow to confirm that appropriate notifications are delivered to a validated address. - id: IAL1-23_gdn name: guidance prose: Notifications can be delivered to test accounts and addresses as appropriate based on the capabilities of the assessor or the testing environment available to them and any privacy restrictions on the use of legitimate addresses. - id: IAL1-24 title: IAL1 Authenticator Binding props: - value: "4.1.12 #1" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-24_smt name: statement prose: |- The CSP SHALL provide the ability for the applicant to bind an authenticator using one of the following methods: (a) Remote enrollment of a subscriber-provided authenticator consistent with the requirements for the authenticator type, as defined in Sec. 4.1.3 of [SP800-63B]. (b) Distribution of a physical authenticator to a validated address. (c) Distribution or on-site enrollment of an authenticator. - id: IAL1-24_obj links: - rel: assessment-for href: "#IAL1-24_smt" name: objective prose: Confirm that the CSP provides the ability for an applicant to bind an authenticator using one of the specified methods. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-24_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and process for allowing an applicant to bind one or more authenticators to their subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-24_asm-test name: assessment-method prose: Test the identity proofing workflow to confirm that the applicants are able to bind authenticators using one or more of the specified methods. - id: IAL1-25 title: IAL1 Subscriber Verification props: - value: "4.1.12 #2" class: index name: label - value: CSP class: target name: marking - value: IAL1 class: xal-level name: marking parts: - id: IAL1-25_smt name: statement prose: |- If authenticators are bound outside of a single protected session with the user, the CSP SHALL confirm the presence of the intended subscriber through one of the following methods: (a) Return of a continuation code. (b) Comparison against a biometric collected at the time of proofing. - id: IAL1-25_obj links: - rel: assessment-for href: "#IAL1-25_smt" name: objective prose: "For authenticators that are bound outside of a single, protection session, confirm that the CSP validates the presence of the intended subscriber through using one of the specified methods." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL1-25_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its process for confirming the presence of the intended subscriber prior to binding authenticators that were issued after the identity proofing session. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL1-25_asm-test name: assessment-method prose: Test the identity proofing workflow to confirm that the CSP employs its documented processes for using continuation codes or biometrics for confirming the presence of the intended subscriber prior to binding authenticators that were issued outside of the original identity proofing session. - id: IAL2-1 title: IAL2 Documented Process props: - value: "4.2.1 #2" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-1_smt name: statement prose: "If such steps are combined, CSPs SHALL document their hybrid process and state how the applicable requirements for each of the employed proofing types are met." - id: IAL2-1_obj links: - rel: assessment-for href: "#IAL2-1_smt" name: objective prose: "[If the CSP employs a hybrid process], confirm that it is documented, and such documentation includes details about how the applicable requirements for each proofing type are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine how its hybrid identity proofing process meets the applicable requirements. - id: IAL2-1_gdn name: guidance prose: "IAL2 identity proofing MAY be delivered through any proofing type, as described in Sec. 2.1.3. CSPs MAY combine proofing types and their stated requirements to create hybrid processes. For example, a CSP might leverage remote unattended identity proofing validation processes in advance of a remote attended session where the verification will take place." - id: IAL2-2 title: IAL2 Evidence Collection props: - value: 4.2.2 class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-2_smt name: statement prose: "For identity proofing at IAL2, the CSP SHALL collect: one piece of FAIR evidence and one piece of STRONG evidence; OR, two pieces of STRONG evidence; OR, one piece of SUPERIOR evidence." - id: IAL2-2_obj links: - rel: assessment-for href: "#IAL2-2_smt" name: objective prose: Confirm that the CSP collects the specified evidence for identity proofing at IAL 2. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its evidence collection requirements for IAL 2. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-2_asm-test name: assessment-method prose: Test the CSP's IAL2 identity proofing workflow to determine that documented evidence collection processes are followed. - id: IAL2-3 title: IAL2 Attribute Collection props: - value: 4.2.3 class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-3_smt name: statement prose: "The CSP SHALL collect all core attributes, including at least one government identifier. Validated evidence is the preferred source of identity attributes." - id: IAL2-3_obj links: - rel: assessment-for href: "#IAL2-3_smt" name: objective prose: "Confirm that the CSP collects all core attributes, including at least one government identifier." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for collecting core attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-3_asm-test name: assessment-method prose: Test the CSP's IAL2 identity proofing workflow to determine that all documented core attribute collection processes are followed. - id: IAL2-3_gdn name: guidance prose: "If the presented identity evidence does not provide all of the attributes that the CSP considers to be core attributes, it MAY collect attributes that are self-asserted by the applicant." - id: IAL2-4 title: IAL2 Fair/Strong Validation props: - value: "4.2.4 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-4_smt name: statement prose: |- Each piece of FAIR or STRONG evidence that is presented SHALL be validated using one of the following techniques: (a) Confirming the authenticity of the digital evidence by interrogating the digital security features (e.g., signatures on assertions or data). (b) Confirming the authenticity of the physical evidence using automated scanning technology that can detect physical security features. (c) Confirming the integrity of any physical security features through a visual inspection by a proofing agent using a real-time or asynchronous process (e.g., offline manual review). (d) Confirming the integrity of any physical security features through physical and tactile inspection by a proofing agent at an on-site location. - id: IAL2-4_obj links: - rel: assessment-for href: "#IAL2-4_smt" name: objective prose: Confirm that the CSP validates each piece of FAIR and STRONG evidence as specified. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its process for validating FAIR and STRONG evidence. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-4_asm-test name: assessment-method prose: Test the CSP's IAL2 identity proofing workflow to determine that all documented validation processes for FAIR and STRONG evidence are followed. - id: IAL2-5 title: IAL2 Superior Validation props: - value: "4.2.4 #2" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-5_smt name: statement prose: "Each piece of SUPERIOR evidence SHALL be validated through the cryptographic verification of the evidence contents and the issuing source, including digital signature verification and the validation of any trust chain back to a trust anchor." - id: IAL2-5_obj links: - rel: assessment-for href: "#IAL2-5_smt" name: objective prose: Confirm that the CSP validates each piece of SUPERIOR evidence as specified. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its process for validating SUPERIOR evidence. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-5_asm-test name: assessment-method prose: Test the CSP's IAL2 identity proofing workflow to determine that all documented validation processes for SUPERIOR evidence are followed. - id: IAL2-6 title: IAL2 Attribute Validation props: - value: "4.2.5 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-6_smt name: statement prose: |- The CSP SHALL validate all core attributes by either: (a) Comparing the government identifier and other core attributes against an authoritative or credible source to determine accuracy. (b) Validating the accuracy of digitally signed attributes that are contained on SUPERIOR evidence through the public key of the issuing source. - id: IAL2-6_obj links: - rel: assessment-for href: "#IAL2-6_smt" name: objective prose: Confirm that the CSP validates all collected core attributes as specified. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-6_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its core attribute validation policy and processes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-6_asm-test name: assessment-method prose: Test the CSP's IAL2 identity proofing workflow to determine that all core attribute validation processes are followed. - id: IAL2-6_gdn name: guidance prose: |- CSPs SHOULD evaluate attributes obtained from different sources (e.g., presented evidence, self-asserted, authoritative or credible sources) for consistency. CSPs SHOULD validate any reference numbers on the presented identity evidence, if available. - id: IAL2-7 title: IAL2 Pathway Record props: - value: 4.2.6 A class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-7_smt name: statement prose: "CSPs that offer multiple verification pathways SHALL record in the subscriber record which pathways were followed to achieve IAL2 and SHALL make that information available to RPs in the assertion, API, or as part of their trust agreement." - id: IAL2-7_obj links: - rel: assessment-for href: "#IAL2-7_smt" name: objective prose: "If the CSP offers more than one verification pathway at IAL2, confirm that it records the employed pathway in its subscriber accounts." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it records which verification pathway was followed in its subscriber accounts. - id: IAL2-8 title: IAL2 Pathway Assertion props: - value: 4.2.6 B class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-8_smt name: statement prose: "CSPs that offer multiple verification pathways SHALL make that information available to RPs in the assertion, API, or as part of their trust agreement." - id: IAL2-8_obj links: - rel: assessment-for href: "#IAL2-8_smt" name: objective prose: "If the CSP offers more than one verification pathway at IAL2, confirm that it makes this information available to RPs that use its service." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it makes information about what verification pathway was followed by a subscriber to RPs that use its service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-8_asm-examine-2 name: assessment-method prose: Examine a sample trust agreement or service contract to determine it makes this information available to its RPs. - id: IAL2-9 title: IAL2 Non-Bio Pathway props: - value: 4.2.6 C class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-9_smt name: statement prose: "When the Non-Biometric Pathway is used, the CSP SHALL additionally record whether a mailed confirmation code or a visual comparison of the applicant against evidence was used for verification." - id: IAL2-9_obj links: - rel: assessment-for href: "#IAL2-9_smt" name: objective prose: "When the Non-Biometric Pathway is used, confirm the CSP records whether verification was accomplished through a mailed confirmation code or a visual comparison of the applicant against evidence." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it records the method used to perform verification. - id: IAL2-10 title: IAL2 Non-Bio Communication props: - value: 4.2.6.1 A class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-10_smt name: statement prose: "If provided as an option at IAL2, CSPs SHALL communicate their use of the Non-Biometric Pathway to all RPs that use their identity service." - id: IAL2-10_obj links: - rel: assessment-for href: "#IAL2-10_smt" name: objective prose: Confirm that the CSP communicates its use of the Non-Biometric Pathway to all RPs that use its service. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it communicates its use of the Non-Biometric Pathway for verification to the RPs that use its service. - id: IAL2-10_gdn name: guidance prose: "The IAL2 Non-Biometric Pathway provides verification methods that do not use an automated comparison of biometric samples provided by the applicant. This pathway can still involve the collection and verification of biometric data (e.g., visual comparison to a facial image contained on identity evidence performed by a proofing agent), but such comparisons are done through manual rather than automated means. Additional verification methods that do not require the use of automated biometric comparison are also included in the Digital Evidence Pathway requirements specified in Sec. 4.2.6.2." - id: IAL2-11 title: IAL2 Non-Bio Evidence props: - value: "4.2.6.1 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-11_smt name: statement prose: "For remote attended, remote unattended, and on-site unattended identity proofing, the CSP SHALL verify the applicant's ownership of all pieces of presented identity evidence. For on-site attended identity proofing, the CSP SHALL verify the applicant's ownership of the strongest piece of presented identity evidence." - id: IAL2-11_obj links: - rel: assessment-for href: "#IAL2-11_smt" name: objective prose: "For the Non-Biometric Pathway, confirm that the CSP meets the evidence ownership verification requirements associated with the identity proofing type." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-11_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policies for verifying ownership of identity evidence when using the Non-Biometric Pathway based on the identity proofing type (i.e., remote attended, remote unattended, on-site unattended, on-site attended)." - id: IAL2-11_gdn name: guidance prose: |- Approved non-biometric methods for verifying FAIR evidence at IAL2 include: (a) Confirming the applicant's ability to return a confirmation code delivered to a validated address associated with the evidence (e.g., postal address, phone number). (b) Visually comparing the applicant's facial image to a facial portrait on the presented evidence (e.g., student or employee ID card) or in records associated with the evidence during an on-site attended session (i.e., in-person with a proofing agent), a remote attended session (i.e., live video with a proofing agent), or an asynchronous process (i.e., visual comparison made by a proofing agent at a different time). Approved non-biometric methods for verifying STRONG and SUPERIOR evidence at IAL2 include: (b) Visually comparing the applicant's facial image to a facial portrait on the presented evidence or in records associated with the evidence during an on-site attended session (i.e., in-person with a proofing agent), a remote attended session (i.e., live video with a proofing agent), or an asynchronous process (i.e., visual comparison made by a proofing agent at a different time). If the comparison is performed asynchronously at a later time, the CSP SHALL implement PAD and passive or active document presence checks to increase confidence that both the live applicant and physical documents are present during the captured identity proofing event. - id: IAL2-12 title: IAL2 Digital Evidence props: - value: "4.2.6.2 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-12_smt name: statement prose: "For remote attended, remote unattended, and on-site unattended identity proofing, the CSP SHALL verify the applicant's ownership of all pieces of presented identity evidence. For on-site attended identity proofing, the CSP SHALL verify the applicant's ownership of the strongest piece of presented identity evidence." - id: IAL2-12_obj links: - rel: assessment-for href: "#IAL2-12_smt" name: objective prose: "For the Digital Evidence Pathway, confirm that the CSP meets the evidence ownership verification requirements associated with the identity proofing type." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-12_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policies for verifying ownership of identity evidence when using the Digital Evidence Pathway based on the identity proofing type (i.e., remote attended, remote unattended, on-site unattended, on-site attended)." - id: IAL2-12_gdn name: guidance prose: |- Approved digital evidence verification methods for FAIR evidence at IAL2 include: (a Confirming the applicant's ability to return a microtransaction value delivered to a validated account (e.g., checking account owned by the applicant that has been validated by an authoritative or credible source). (b) Confirming the applicant's ability to return a confirmation code delivered to a validated digital address associated with the digital evidence (e.g., MNO/phone account). (c) Confirming the applicant's ability to successfully complete an authentication and federation protocol equivalent to AAL2/FAL2 to access an account related to the identity evidence. Approved digital evidence verification methods for STRONG evidence at IAL2 involve confirming the applicant's ability to successfully complete an authentication and federation protocol equivalent to AAL2/FAL2 or higher to access an account related to the identity evidence. Approved digital evidence verification methods for SUPERIOR evidence at IAL2 include confirming the applicant's possession of the evidence through the use of a local activation factor and the presentation of a cryptographically verifiable attribute bundle. - id: IAL2-13 title: IAL2 Biometric Pathway props: - value: "4.2.6.3 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-13_smt name: statement prose: "For remote attended, remote unattended, and on-site unattended identity proofing, the CSP SHALL verify the applicant's ownership of all pieces of presented identity evidence. For on-site attended identity proofing, the CSP SHALL verify the applicant's ownership of the strongest piece of presented identity evidence." - id: IAL2-13_obj links: - rel: assessment-for href: "#IAL2-13_smt" name: objective prose: "For the Biometric Pathway, confirm that the CSP meets the evidence ownership verification requirements associated with the identity proofing type." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-13_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policies for verifying ownership of identity evidence when using the Biometric Pathway based on the identity proofing type (i.e., remote attended, remote unattended, on-site unattended, on-site attended)." - id: IAL2-13_gdn name: guidance prose: |- Approved methods for verifying FAIR, STRONG, and SUPERIOR evidence for use in the IAL2 Biometric Pathway include: (a) Using automated means to compare a facial image represented on or stored in the identity evidence or in records associated with the evidence to a live sample provided by the applicant. (b) Using automated means to compare a biometric characteristic other than a facial image stored on the identity evidence or in records associated with the evidence to a live sample provided by the applicant. - id: IAL2-14 title: IAL2 Video Session props: - value: "4.2.8 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-14_smt name: statement prose: "For Remote Attended identity proofing, during the video session, the applicant SHALL remain in view of the proofing agent during each step of the proofing process." - id: IAL2-14_obj links: - rel: assessment-for href: "#IAL2-14_smt" name: objective prose: "For remote attended video sessions, confirm the CSP requires that the applicant is visible to the proofing agent for each step of the identity proofing process." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-14_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its requirements for applicant visibility during remote attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL2-14_asm-interview name: assessment-method prose: Interview appropriate personnel to determine the process for viewing applicants during each step of remote attended identity proofing sessions. - id: IAL2-15 title: IAL2 Video Quality props: - value: "4.2.8 #2" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-15_smt name: statement prose: "For Remote Attended identity proofing, the video quality SHALL be sufficient to support the necessary steps in the validation and verification processes, such as inspecting evidence and comparing the applicant to the evidence." - id: IAL2-15_obj links: - rel: assessment-for href: "#IAL2-15_smt" name: objective prose: "For remote attended video sessions, confirm the video quality is sufficient to support the needs of the identity proofing process." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-15_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it employs video technologies of sufficient quality to support the identity proofing processes. - id: IAL2-16 title: IAL2 Remote Attended Coercion Training props: - value: "4.2.8 #3" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-16_smt name: statement prose: "For Remote Attended identity proofing, proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the session." - id: IAL2-16_obj links: - rel: assessment-for href: "#IAL2-16_smt" name: objective prose: Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-16_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL2-16_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the training they've received to identify these signs. - id: IAL2-17 title: IAL2 Remote Attended Recorded Video props: - value: "4.2.8 #4" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-17_smt name: statement prose: |- For Remote Attended identity proofing, if the CSP records a video session, the following additional requirements apply: (a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session. (b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session. (c) The CSP SHALL publish their retention schedule and deletion processes for all video records. - id: IAL2-17_obj links: - rel: assessment-for href: "#IAL2-17_smt" name: objective prose: "If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-17_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording remote attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-17_asm-test name: assessment-method prose: Test the remote attended identity proofing process and determine that all the specified requirements for recording remote attended identity proofing sessions are met. - id: IAL2-17_gdn name: guidance prose: "CSPs MAY record and maintain video sessions for fraud prevention and prosecution purposes pursuant to a privacy risk assessment, as defined in Sec. 3.3.1." - id: IAL2-18 title: IAL2 Injection Protection props: - value: "4.2.8 #5" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-18_smt name: statement prose: "For Remote Attended identity proofing, the CSP SHALL implement injection protection and modified media controls, as defined in Sec. 3.14." - id: IAL2-18_obj links: - rel: assessment-for href: "#IAL2-18_smt" name: objective prose: Confirm that the CSP employs injection protection and controls against modified media. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-18_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it has implemented injection project and modified media controls. - id: IAL2-19 title: IAL2 Remote Attended Fraud Flags props: - value: "4.2.8 #6" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-19_smt name: statement prose: "For Remote Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to flag events for potential fraud." - id: IAL2-19_obj links: - rel: assessment-for href: "#IAL2-19_smt" name: objective prose: Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-19_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL2-19_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud. - id: IAL2-20 title: IAL2 Physical Setting props: - value: "4.2.9 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-20_smt name: statement prose: "For On-site Attended identity proofing, the CSP SHALL provide a physical setting in which on-site identity proofing sessions are conducted." - id: IAL2-20_obj links: - rel: assessment-for href: "#IAL2-20_smt" name: objective prose: Confirm the CSP provides physical location in for on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-20_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that is provides a physical setting for on-site attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-20_asm-examine-2 name: assessment-method prose: Examine a location where the CSPs conducts on-site identity proofing. - id: IAL2-21 title: IAL2 On-Site Attended Security Controls props: - value: "4.2.9 #2" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-21_smt name: statement prose: "For On-site Attended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes." - id: IAL2-21_obj links: - rel: assessment-for href: "#IAL2-21_smt" name: objective prose: Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-21_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher. - id: IAL2-22 title: IAL2 On-Site Attended Coercion Training props: - value: "4.2.9 #3" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-22_smt name: statement prose: "For On-site Attended identity proofing, CSP proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the on-site session." - id: IAL2-22_obj links: - rel: assessment-for href: "#IAL2-22_smt" name: objective prose: Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-22_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL2-22_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the training they've received to identify these signs. - id: IAL2-23 title: IAL2 On-Site Attended Recorded Video props: - value: "4.2.9 #4" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-23_smt name: statement prose: |- For On-site Attended identity proofing, if the CSP records a video session, the following additional requirements apply: (a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session. (b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session. (c) The CSP SHALL publish their retention schedule and deletion processes for all video records. - id: IAL2-23_obj links: - rel: assessment-for href: "#IAL2-23_smt" name: objective prose: "If the CSP records on-site attended video identity proofing sessions, confirm that the specified requirements are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-23_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site attended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-23_asm-test name: assessment-method prose: Test the on-site attended identity proofing process to determine that all the requirements for recording video sessions are met. - id: IAL2-23_gdn name: guidance prose: "CSPs MAY record and maintain video sessions for fraud prevention and prosecution purposes pursuant to a privacy risk assessment, as defined in Sec. 3.3.1." - id: IAL2-24 title: IAL2 On-Site Attended Fraud Flags props: - value: "4.2.9 #5" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-24_smt name: statement prose: "For On-site Attended identity proofing, the CSP SHALL provide proofing agents with a method or mechanism to covertly flag events for potential fraud." - id: IAL2-24_obj links: - rel: assessment-for href: "#IAL2-24_smt" name: objective prose: Confirm the CSP provides its proofing agents with a mechanism to flag potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-24_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL2-24_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud. - id: IAL2-25 title: IAL2 Tamper Prevention props: - value: "4.2.10 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-25_smt name: statement prose: "For On-site Unattended identity proofing, all devices SHALL be safeguarded from tampering through observation by CSP representatives and/or physical and digital tamper prevention features." - id: IAL2-25_obj links: - rel: assessment-for href: "#IAL2-25_smt" name: objective prose: Confirm that the CSP safeguards all devices and equipment used for on-site unattended identity proofing at IAL2 are safeguarded from tampering. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-25_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it safeguards the devices it uses for on-site attended identity proofing from tampering. - id: IAL2-26 title: IAL2 On-Site Unattended Security Controls props: - value: "4.2.10 #2" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-26_smt name: statement prose: "For On-site Unattended identity proofing, all devices SHALL be protected by appropriate baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes." - id: IAL2-26_obj links: - rel: assessment-for href: "#IAL2-26_smt" name: objective prose: Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all equipment used for on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-26_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to confirm it protects the equipment used in on-site attended identity proofing by security controls comparable to FISMA moderate or higher. - id: IAL2-27 title: IAL2 Device Inspection props: - value: "4.2.10 #3" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-27_smt name: statement prose: "For On-site Unattended identity proofing, all devices SHALL be inspected periodically by trained technicians to deter tampering, modification, or damage." - id: IAL2-27_obj links: - rel: assessment-for href: "#IAL2-27_smt" name: objective prose: "Confirm that the CSP has a policy for ensuring that all equipment used for on-site attended identity proofing is periodically inspected by technicians who are trained to detect tampering, modification, and damage." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-27_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for inspecting equipment used for on-site attended identity proofing. - id: IAL2-28 title: IAL2 On-Site Unattended Recorded Video props: - value: "4.2.10 #4" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-28_smt name: statement prose: |- For On-site Unattended identity proofing, if the CSP records a video session, the following additional requirements apply: (a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session. (b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session. (c) The CSP SHALL publish their retention schedule and deletion processes for all video records. - id: IAL2-28_obj links: - rel: assessment-for href: "#IAL2-28_smt" name: objective prose: "If the CSP records remote attended video identity proofing sessions, confirm that the specified requirements are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-28_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site unattended identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-28_asm-test name: assessment-method prose: Test the on-site unattended identity proofing process to determine that all the requirements for recording video sessions are met. - id: IAL2-29 title: IAL2 Proofing Notification props: - value: 4.2.11 class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-29_smt name: statement prose: "Upon the successful completion of identity proofing at IAL2, the CSP SHALL send a notification of proofing to a validated address for the applicant, as specified in Sec. 3.10." - id: IAL2-29_obj links: - rel: assessment-for href: "#IAL2-29_smt" name: objective prose: Confirm that the CSP sends notifications of proofing to validated addresses for applicants after they have successfully complete identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-29_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that it sends notifications of proofing to applicant's validated addresses, upon successful completion of identity proofing." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-29_asm-test name: assessment-method prose: Test the identity proofing workflow to confirm that appropriate notifications are delivered to a validated address. - id: IAL2-29_gdn name: guidance prose: |- CSPs SHOULD send the notification of proofing to the applicant's postal address. Note to assessors: Notifications can be delivered to test accounts and addresses as appropriate based on the capabilities of the assessor or the testing environment available to them and any privacy restrictions on the use of legitimate addresses. - id: IAL2-30 title: IAL2 Authenticator Binding props: - value: "4.2.12 #1" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-30_smt name: statement prose: |- The CSP SHALL provide the ability for the applicant to bind an authenticator using one of the following methods: (a) Remote enrollment of a subscriber-provided authenticator consistent with the requirements for the authenticator type, as defined in Sec. 4.1.3 of [SP800-63B]. (b) Distribution of a physical authenticator to a validated address. (c) Distribution or on-site enrollment of an authenticator. - id: IAL2-30_obj links: - rel: assessment-for href: "#IAL2-30_smt" name: objective prose: Confirm that the CSP provides the ability for an applicant to bind an authenticator using one of the specified methods. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-30_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and process for allowing an applicant to bind one or more authenticators to their subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-30_asm-test name: assessment-method prose: Test the identity proofing workflow to confirm that the applicants are able to bind authenticators using one or more of the specified methods. - id: IAL2-31 title: IAL2 Subscriber Verification props: - value: "4.2.12 #2" class: index name: label - value: CSP class: target name: marking - value: IAL2 class: xal-level name: marking parts: - id: IAL2-31_smt name: statement prose: |- If authenticators are bound outside of a single protected session with the user, the CSP SHALL confirm the presence of the intended subscriber through one of the following methods: (a) Return of a continuation code. (b) Comparison against a biometric collected at the time of proofing. - id: IAL2-31_obj links: - rel: assessment-for href: "#IAL2-31_smt" name: objective prose: "For authenticators that are bound outside of a single, protection session, confirm that the CSP validates the presence of the intended subscriber through using one of the specified methods." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL2-31_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its process for verifying subscribers prior to binding authenticators outside of a single protected session. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL2-31_asm-test name: assessment-method prose: Test the authenticator binding workflow to confirm that the CSP employs its documented processes for using continuation codes or biometrics to confirm the presence of the intended subscriber prior to binding authenticators that were issued outside of the original identity proofing session. - id: IAL3-1 title: IAL3 On-Site Attended props: - value: 4.3.1 A class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-1_smt name: statement prose: IAL3 identity proofing SHALL only be delivered as on-site attended. - id: IAL3-1_obj links: - rel: assessment-for href: "#IAL3-1_smt" name: objective prose: Confirm that the CSP only offers on-site attended (Collocated Agent or Kiosk-based) identity proofing for IAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that all IAL3 identity proofing is conducted via on-site attended processes. - id: IAL3-1_gdn name: guidance prose: The proofing agent MAY be co-located with the applicant or attend the identity proofing session via a CSP-controlled kiosk or device. - id: IAL3-2 title: IAL3 Evidence Collection props: - value: 4.3.2 A class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-2_smt name: statement prose: "For identity proofing at IAL3, the CSP SHALL collect: one piece of FAIR evidence and one piece of STRONG evidence; OR, two pieces of STRONG evidence; OR one piece of SUPERIOR evidence." - id: IAL3-2_obj links: - rel: assessment-for href: "#IAL3-2_smt" name: objective prose: Confirm that the CSP collects the specified evidence for identity proofing at IAL . - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its evidence collection requirements for IAL 3. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-2_asm-test name: assessment-method prose: Test the CSP's IAL3 identity proofing workflow to determine that documented evidence collection processes are followed. - id: IAL3-3 title: IAL3 Attribute Collection props: - value: "4.3.3 #1" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-3_smt name: statement prose: "The CSP SHALL collect all core attributes, including at least one government identifier." - id: IAL3-3_obj links: - rel: assessment-for href: "#IAL3-3_smt" name: objective prose: "Confirm that the CSP collects all core attributes, including at least one government identifier." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for collecting core attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-3_asm-test name: assessment-method prose: Test the CSP's IAL3 identity proofing workflow to determine that all documented core attribute collection processes are followed. - id: IAL3-3_gdn name: guidance prose: "Validated evidence is the preferred source of identity attributes. If the presented identity evidence does not provide all of the attributes that a CSP considers to be core attributes, the CSP MAY collect attributes that are self asserted by the applicant." - id: IAL3-4 title: IAL3 Fair Strong props: - value: "4.3.4 #1" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-4_smt name: statement prose: |- Each piece of FAIR or STRONG evidence that is presented SHALL be validated using one of the following techniques: (a) Confirming the authenticity of the digital evidence by interrogating the digital security features (e.g., signatures on assertions or data). (b) Confirming the authenticity of the physical evidence using automated scanning technology that can detect physical security features. (c) Confirming the integrity of any physical security features through a visual inspection by a proofing agent using a real-time or asynchronous process (e.g., offline manual review). - id: IAL3-4_obj links: - rel: assessment-for href: "#IAL3-4_smt" name: objective prose: "Confirm that the CSP validates each piece of FAIR or STRONG evidence using the one of the techniques provided in item #1 of Sec. 4.3.4." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and process for validating FAIR and STRONG evidence at IAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-4_asm-test name: assessment-method prose: Test the CSP's IAL3 identity proofing workflow to determine that all documented validation processes for FAIR and STRONG evidence are followed. - id: IAL3-5 title: IAL3 Superior Evidence props: - value: "4.3.4 #2" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-5_smt name: statement prose: "Each piece of SUPERIOR evidence SHALL be validated through the cryptographic verification of the evidence contents and the issuing source, including digital signature verification and the validation of any trust chain back to a trust anchor." - id: IAL3-5_obj links: - rel: assessment-for href: "#IAL3-5_smt" name: objective prose: Confirm that the CSP validates each piece of presented SUPERIOR evidence through the cryptographic verification of the evidence contents and the issuing source. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and process for validating SUPERIOR evidence at IAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-5_asm-test name: assessment-method prose: Test the CSP's IAL3 identity proofing workflow to determine that all documented validation processes for SUPERIOR evidence are followed. - id: IAL3-6 title: IAL3 ID Verification props: - value: "4.3.6 #1" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-6_smt name: statement prose: |- The CSP SHALL verify the applicant's ownership of the strongest piece of evidence (STRONG or SUPERIOR) by one of the following methods: (a) Confirming the applicant's ability to successfully authenticate to a physical device or application (e.g., a mobile driver's license) and comparing a digitally protected and transmitted facial portrait to the applicant. (b) Comparing the applicant's facial image to the facial portrait on the presented evidence via an automated comparison. (c) Visually comparing the applicant's facial image to the facial portrait on the presented evidence during an on-site attended session or a remote attended session. (d) Performing an automated comparison of a stored biometric on the identity evidence or in the authoritative records associated with the evidence to a sample provided by the applicant. - id: IAL3-6_obj links: - rel: assessment-for href: "#IAL3-6_smt" name: objective prose: Confirm that the CSP verifies the applicant's ownership of the strongest piece of evidence by one of the methods provided in Sec 4.3.6. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-6_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine how it verifies an applicant's ownership of the strongest piece of presented evidence. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-6_asm-test name: assessment-method prose: Test the CSP's IAL3 identity proofing workflow to determine that all documented verification processes for evidence are followed. - id: IAL3-7 title: IAL3 Secure Setting props: - value: "4.3.7 #1" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-7_smt name: statement prose: "For on-site attended identity proofing with collocated agents, the CSP SHALL provide a secure, physical setting in which on-site identity proofing sessions are conducted." - id: IAL3-7_obj links: - rel: assessment-for href: "#IAL3-7_smt" name: objective prose: "Confirm that the CSP provides a secure, physical setting for on-site attended identity proofing sessions with collocated agents." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-7_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine it provides a secure, physical setting for on-site attended identity proofing sessions with collocated agents to determine the setting is secure." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-7_asm-examine-2 name: assessment-method prose: Examine one or more locations where the CSP conducts on-site attended identity proofing with collocated agents. - id: IAL3-8 title: IAL3 Biometric Capture props: - value: "4.3.7 #2" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-8_smt name: statement prose: "For on-site attended identity proofing with collocated agents, the CSP SHALL provide sensors and capture devices for the collection of biometrics from the applicant." - id: IAL3-8_obj links: - rel: assessment-for href: "#IAL3-8_smt" name: objective prose: Confirm that the workstations the CSP employs for on-site identity proofing at IAL3 include devices for the secure collection of biometric samples. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the workstations it employs for on-site identity proofing include sensors and capture devices for the secure collection of biometric samples. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-8_asm-examine-2 name: assessment-method prose: Examine one or more identity proofing sites to determine the CSP provides sensors and capture devices for the collection of biometrics. - id: IAL3-9 title: View Biometric Source props: - value: "4.3.7 #3" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-9_smt name: statement prose: "For on-site attended identity proofing with collocated agents, the CSP SHALL have the proofing agent view the source of the collected biometric for the presence of any non-natural materials (e.g., putty, glue)." - id: IAL3-9_obj links: - rel: assessment-for href: "#IAL3-9_smt" name: objective prose: "Confirm that the CSP requires its IAL3 proofing agents to view the source of the biometric (applicant's face, fingers, etc.) for the presence of any non-natural materials." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it requires its collocated proofing agents to view the source of biometric samples. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL3-9_asm-interview name: assessment-method prose: Interview one or more proofing agents to determine that they are required and understand how to view the source(s) of biometric samples for the presences of non-natural materials. - id: IAL3-10 title: Biometric Collection Source props: - value: "4.3.7 #4" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-10_smt name: statement prose: "For on-site attended identity proofing with collocated agents, the CSP SHALL have the proofing agent collect the biometric samples in such a way that ensures the sample was collected from the applicant and no other source." - id: IAL3-10_obj links: - rel: assessment-for href: "#IAL3-10_smt" name: objective prose: Confirm that the CSP employs practices and mechanisms that ensure that all biometric samples are collected from the intended applicant. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it employs practices and mechanisms to ensure that all biometric samples are collected from the intended applicants. - id: IAL3-11 title: IAL3 Colocated Agent Security Controls props: - value: "4.3.7 #5" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-11_smt name: statement prose: "For on-site attended identity proofing with collocated agents, the CSP SHALL ensure that all information systems and technology leveraged by proofing agents and trusted referees are protected consistent with at least FISMA moderate or comparable levels of controls, including physical controls for the proofing facility." - id: IAL3-11_obj links: - rel: assessment-for href: "#IAL3-11_smt" name: objective prose: Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all information systems and equipment used for on-site attended identity proofing with collocated agents. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-11_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to confirm it protects all information systems and equipment used in on-site attended identity proofing with collocated agents by security controls comparable to FISMA moderate or higher. - id: IAL3-12 title: IAL3 Coercion Training props: - value: "4.3.7 #6" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-12_smt name: statement prose: "For on-site attended identity proofing with collocated agents, CSP proofing agents SHALL be trained to identify signs of manipulation, coercion, or social engineering occurring during the on-site session." - id: IAL3-12_obj links: - rel: assessment-for href: "#IAL3-12_smt" name: objective prose: Confirm the CSP trains its agents to identify signs that an applicant has been coerced or manipulated into participating in the identity proofing process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-12_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its policy for training its agents to identify signs of coercion, manipulation, or social engineering." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL3-12_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the training they've received to identify these signs. - id: IAL3-13 title: IAL3 Recorded Video props: - value: "4.3.7 #7" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-13_smt name: statement prose: |- For on-site attended identity proofing with collocated agents, if the CSP records a session, the following additional requirements apply: (a) The CSP SHALL notify the applicant of the recording prior to initiating a recorded session. (b) The CSP SHALL gain consent from the applicant prior to initiating a recorded session. (c) The CSP SHALL publish their retention schedule and deletion processes for all video records. - id: IAL3-13_obj links: - rel: assessment-for href: "#IAL3-13_smt" name: objective prose: "If the CSP records video sessions of on-site attended identity proofing with collocated agents at IAL3, confirm that the requirements specified in Sec. 4.3.7 #7 are met." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-13_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it meets all the specified requirements for recording on-site attended with collocated agent identity proofing sessions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-13_asm-test name: assessment-method prose: Test the on-site attended with collocated agent identity proofing process and determine that all the specified requirements for recording remote attended identity proofing sessions are met. - id: IAL3-13_gdn name: guidance prose: "CSPs MAY record and maintain video sessions for fraud prevention and prosecution purposes pursuant to a privacy risk assessment, as defined in Sec. 3.3.1." - id: IAL3-14 title: IAL3 Fraud Flags props: - value: "4.3.7 #8" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-14_smt name: statement prose: "For on-site attended identity proofing with collocated agents, the CSP SHALL provide proofing agents with a method or mechanism to discretely flag events or actions as potential fraud." - id: IAL3-14_obj links: - rel: assessment-for href: "#IAL3-14_smt" name: objective prose: Confirm the CSP provides its collocated proofing agents with a mechanism to flag potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-14_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it provides its proofing agents with a mechanism to flag incidents of potential fraud. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL3-14_asm-interview name: assessment-method prose: Interview one or more agents of the CSP to determine the mechanism they use to flag incidents of potential fraud. - id: IAL3-15 title: Kiosk Video Transmission props: - value: "4.3.8 #1" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-15_smt name: statement prose: "For kiosk-based on-site attended identity proofing, the CSP SHALL monitor the entire identity proofing session through a high-resolution video transmission with the applicant." - id: IAL3-15_obj links: - rel: assessment-for href: "#IAL3-15_smt" name: objective prose: Confirm that all workstations and kiosks employed by the CSP for kiosk-based on-site attended identity proofing at IAL3 include video cameras that support high-resolution video transmission. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-15_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it employs high-resolution video cameras in the kiosk used for kiosk-based on-site attended identity proofing at IAL3. - id: IAL3-16 title: Live Agent Participation props: - value: "4.3.8 #2" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-16_smt name: statement prose: "For kiosk-based on-site attended identity proofing, the CSP SHALL have a live proofing agent participate remotely with the applicant for the evidence collection, evidence validation, and verification steps of the identity proofing process." - id: IAL3-16_obj links: - rel: assessment-for href: "#IAL3-16_smt" name: objective prose: "Confirm that the CSP's proofing agents participate remotely in the evidence collection, evidence validation, and identity verification steps of kiosk-based on-site attended identity proofing at IAL3." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-16_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine its agents participate remotely in the evidence collection, evidence validation, and identity verification steps for kiosk-based on-site attended identity proofing at IAL3." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL3-16_asm-interview name: assessment-method prose: "Interview one or more proofing agents of the CSP to determine that, for kiosk-based on-site attended identity proofing, they are required to participate remotely, at a minimum, in the evidence collection, evidence validation, and identity verification steps of the identity proofing process for IAL3." - id: IAL3-17 title: Clearly Visible Actions props: - value: "4.3.8 #3" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-17_smt name: statement prose: "For kiosk-based on-site attended identity proofing, the CSP SHALL require all actions taken by the applicant during the evidence collection, evidence validation, and verification steps to be clearly visible to the remote proofing agent." - id: IAL3-17_obj links: - rel: assessment-for href: "#IAL3-17_smt" name: objective prose: Confirm that the CSP designs the workstations used for kiosk-based on-site attended identity proofing at IAL3 so that all specified actions taken by the applicants are clearly visible to proofing agents who are participating remotely. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-17_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that all specified actions taken by the applicant in kiosk-based on-site attended identity proofing at IAL3 are visible to the remote proofing agent. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL3-17_asm-interview name: assessment-method prose: "Interview one or more proofing agents of the CSP to determine that, for kiosk-based on-site attended identity proofing, all specified actions taken by the applicant are visible to the remote proofing agent." - id: IAL3-18 title: IAL3 Integrated Sensors props: - value: "4.3.8 #4" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-18_smt name: statement prose: "For kiosk-based on-site attended identity proofing, the CSP SHALL require that all digital validation and verification of evidence be performed by integrated scanners and sensors." - id: IAL3-18_obj links: - rel: assessment-for href: "#IAL3-18_smt" name: objective prose: Confirm that the CSP's kiosk-based identity proofing stations employ integrated scanners and sensors. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-18_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that kiosk-based identity proofing stations employ integrated scanners and sensors. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-18_asm-examine-2 name: assessment-method prose: Examine one or more stations used for kiosk-based on-site attended identity proofing to determine it includes integrated scanners and sensors. - id: IAL3-18_gdn name: guidance prose: Scanners and sensors that are built into the - id: IAL3-19 title: Kiosk Tamper Prevention props: - value: "4.3.8 #5" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-19_smt name: statement prose: "For kiosk-based on-site attended identity proofing, all devices used to support interaction between the proofing agent and the applicant SHALL be safeguarded from tampering through observation by CSP representatives or monitoring devices (e.g., cameras) and through physical and digital tamper prevention features." - id: IAL3-19_obj links: - rel: assessment-for href: "#IAL3-19_smt" name: objective prose: Confirm that the CSP employs mechanisms to safeguard the equipment and devices used for kiosk-based on-site attended identity proofing from tampering. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-19_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the safeguards it employs to protect its kiosk-based on-site attended identity proofing stations from tampering. - id: IAL3-20 title: IAL3 Kiosk-Based Security Controls props: - value: "4.3.8 #6" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-20_smt name: statement prose: "For kiosk-based on-site attended identity proofing, all devices used to support interaction between the proofing agent and the applicant SHALL be protected by appropriate baseline security features that are comparable to at least FISMA moderate controls, including malware protection, administrator-specific access controls, and software update processes." - id: IAL3-20_obj links: - rel: assessment-for href: "#IAL3-20_smt" name: objective prose: Confirm that the CSP employs security controls comparable to FISMA moderate or higher for all information systems and equipment used for kiosk-based on-site attended identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-20_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to confirm it protects all information systems and equipment used in kiosk-based on-site attended identity proofing by security controls comparable to FISMA moderate or higher. - id: IAL3-21 title: IAL3 Device Inspection props: - value: "4.3.8 #7" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-21_smt name: statement prose: "For kiosk-based on-site attended identity proofing, all devices used to support interaction between the proofing agent and the applicant SHALL be inspected periodically by trained technicians to deter tampering, modification, or damage." - id: IAL3-21_obj links: - rel: assessment-for href: "#IAL3-21_smt" name: objective prose: Confirm that the CSP ensures that the devices and stations used for kiosk-based on-site attended identity proofing are inspected periodically by trained technicians. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-21_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine it employs trained technicians to periodically inspect the equipment and area used for kiosk-based on-site attended identity proofing for evidence of tampering, modification, or damage." - id: IAL3-22 title: IAL3 Proofing Notification props: - value: 4.3.9 A class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-22_smt name: statement prose: "Upon the successful completion of identity proofing at IAL3, the CSP SHALL send a notification of proofing to a validated address for the applicant, as specified in Sec. 3.10." - id: IAL3-22_obj links: - rel: assessment-for href: "#IAL3-22_smt" name: objective prose: Confirm that the CSP sends notifications of proofing to validated addresses for applicants after they have successfully complete identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-22_asm-examine name: assessment-method prose: "Examine the CSP's practices statement or other documentation to determine that it sends notifications of proofing to applicant's validated addresses, upon successful completion of identity proofing." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-22_asm-test name: assessment-method prose: Test the identity proofing workflow to confirm that appropriate notifications are delivered to a validated address. - id: IAL3-22_gdn name: guidance prose: |- CSPs SHOULD send the notification of proofing to the applicant's postal address. Note to assessors: Notifications can be delivered to test accounts and addresses as appropriate based on the capabilities of the assessor or the testing environment available. - id: IAL3-23 title: IAL3 Authenticator Binding props: - value: "4.3.10 #1" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-23_smt name: statement prose: The CSP SHALL distribute or enroll the subscriber's initial authenticator during an on-site attended interaction with a proofing agent. - id: IAL3-23_obj links: - rel: assessment-for href: "#IAL3-23_smt" name: objective prose: Confirm that the CSP distributes and/or enrolls the subscriber's initial authenticator during an on-site attended session with a proofing agent. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-23_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and process for distributing and/or enrolling the subscriber's initial authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: IAL3-23_asm-interview name: assessment-method prose: Interview one or more proofing agents to determine that the CSP distributes and enrolls initial authenticators during on-site attended identity proofing sessions. - id: IAL3-24 title: IAL3 Subscriber Verification props: - value: "4.3.10 #2" class: index name: label - value: CSP class: target name: marking - value: IAL3 class: xal-level name: marking parts: - id: IAL3-24_smt name: statement prose: "If the CSP distributes or enrolls the initial authenticator outside of a single authenticated protected session with the subscriber, the CSP SHALL compare a biometric sample collected from the subscriber to the one collected at the time of proofing prior to registration of the authenticator." - id: IAL3-24_obj links: - rel: assessment-for href: "#IAL3-24_smt" name: objective prose: "For initial authenticators that are distributed or enrolled outside a single authenticated protected session with the subscriber, confirm that the CSP compares a biometric sample collected from the subscriber to the one collected at the time of proofing prior to registration of the authenticator." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAL3-24_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its process for verifying subscribers prior to binding authenticators outside of a single protected session. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAL3-24_asm-test name: assessment-method prose: Test the authenticator binding workflow to confirm that the CSP employs biometric comparison to confirm the presence of the intended subscriber prior to binding authenticators that were issued outside of the original identity proofing session. - id: IAL3-24_gdn name: guidance prose: The CSP MAY request that the subscriber bring the identity evidence used during the proofing process to further strengthen the process of binding the authenticator to the subscriber. - id: SUB-1 title: Unique Subscriber Account props: - value: 5.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-1_smt name: statement prose: The CSP SHALL establish and maintain a unique subscriber account for each active subscriber in its identity system from the time of enrollment to the time of account closure. - id: SUB-1_obj links: - rel: assessment-for href: "#SUB-1_smt" name: objective prose: Confirm that the CSP establishes and maintains subscriber accounts for all its active subscribers. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-1_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it establishes and maintains unique accounts for its active subscribers. - id: SUB-1_gdn name: guidance prose: The CSP establishes a subscriber account to record each subscriber as a unique identity within its identity service and to maintain a record of all authenticators associated with that account. - id: SUB-2 title: Subscriber Identifier props: - value: 5.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-2_smt name: statement prose: The CSP SHALL assign a unique identifier to each subscriber account. - id: SUB-2_obj links: - rel: assessment-for href: "#SUB-2_smt" name: objective prose: Confirm that the CSP assigns a unique identifier to each subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-2_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it assigns a unique identifier to each subscriber account. - id: SUB-2_gdn name: guidance prose: "The identifier SHOULD be randomly generated by the CSP's system and of sufficient length and entropy to ensure uniqueness within its user population and to support federation with RPs, where applicable. The identifier MAY be used as a subject identifier in the generation of assertions, consistent with [SP800-63C]." - id: SUB-3 title: Subscriber Account Information props: - value: 5.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-3_smt name: statement prose: "At a minimum, the CSP SHALL include the following information in each subscriber account: the unique identifier associated with the subscriber account; any subject identifiers established for the subscriber, including any RP-specific subject identifiers; a record of the identity proofing steps completed for the subscriber;* maximum IAL successfully achieved for the identity proofing of the subscriber; records of any applicant consent agreements related to the collection and processing of information about the applicant throughout the subscriber account life cycle, including biometrics; all authenticators currently bound to the subscriber account, whether registered at enrollment or subsequent to enrollment; and attributes that were validated during the identity proofing process or in subsequent transactions to support RP access." - id: SUB-3_obj links: - rel: assessment-for href: "#SUB-3_smt" name: objective prose: Confirm that CSP's subscriber accounts include all the specified information. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-3_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine what information it stores in its subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-3_asm-examine-2 name: assessment-method prose: "Examine one or more example subscriber accounts to determine it includes, at a minimum, the specified information." - id: SUB-3_gdn name: guidance prose: |- - Required details about the identity proofing steps completed for the subscriber include: - The type and issuer of identity evidence. - The type of proofing (i.e., remote unattended, remote attended, on-site attended, on-site unattended). - The validation and verification methods used. - The use of a trusted referee or other exception handling process. - The use of an applicant reference, including a unique identifier for the applicant reference. - id: SUB-4 title: Subscriber Account Access props: - value: 5.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-4_smt name: statement prose: The CSP SHALL provide the capability for subscribers to authenticate and access information in their subscriber account. - id: SUB-4_obj links: - rel: assessment-for href: "#SUB-4_smt" name: objective prose: Confirm that the CSP provides subscribers with the ability to access their subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-4_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it provides subscribers with the ability to access their accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUB-4_asm-test name: assessment-method prose: Test to determine that appropriately authenticated subscribers can access their subscriber account information. - id: SUB-5 title: Subscriber Account AAL props: - value: 5.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-5_smt name: statement prose: "For subscriber accounts that contain personal information, this capability SHALL be accomplished through AAL2 or AAL3 authentication processes using authenticators that are registered to the subscriber account." - id: SUB-5_obj links: - rel: assessment-for href: "#SUB-5_smt" name: objective prose: Confirm that the CSP requires subscribers to authenticate to their accounts using registered authenticators and AAL2 or AAL3 processes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-5_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the authentication processes associated with accessing subscriber accounts that contain personal information. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUB-5_asm-test name: assessment-method prose: Test to determine that a subscriber account with PII requires at least AAL2 authentication. - id: SUB-6 title: SA Update Requests props: - value: 5.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-6_smt name: statement prose: The CSP SHALL provide the capability for a subscriber to request that information be updated in their subscriber account. - id: SUB-6_obj links: - rel: assessment-for href: "#SUB-6_smt" name: objective prose: Confirm that the CSP provides the ability for subscribers to request updates to the information contained in their accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-6_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and process for subscribers to request information be updated in their subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUB-6_asm-test name: assessment-method prose: Test to determine that subscribers can request changes to their subscriber information. - id: SUB-7 title: Core Attribute Updates props: - value: 5.3 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-7_smt name: statement prose: "With the exception of physical addresses, the CSP SHALL validate any changes to core attribute information maintained in the subscriber account." - id: SUB-7_obj links: - rel: assessment-for href: "#SUB-7_smt" name: objective prose: "Confirm that the CSP validates any updated core attribute information maintained in a subscriber's account, with the exception of physical address." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-7_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for validating updated core attribute information stored in a subscriber's account. - id: SUB-8 title: SA Update Notifications props: - value: 5.3 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-8_smt name: statement prose: The CSP SHALL notify the subscriber of any updates made to information in the subscriber account. - id: SUB-8_obj links: - rel: assessment-for href: "#SUB-8_smt" name: objective prose: Confirm that the CSP notifies its subscribers anytime information in their subscriber accounts changes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-8_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy or process for notifying subscribers when information in their accounts is updated. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUB-8_asm-test name: assessment-method prose: Test to determine that subscribers can request changes to their subscriber information. - id: SUB-9 title: Subscriber Account Compromise props: - value: 5.3 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-9_smt name: statement prose: The CSP SHALL provide the capability for the subscriber to report any unauthorized access or potential compromise to information in their subscriber account. - id: SUB-9_obj links: - rel: assessment-for href: "#SUB-9_smt" name: objective prose: Confirm that the CSP provides a mechanism for subscribers to report suspected or confirmed incidents of fraud associated with their accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-9_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine it provides the capability for subscribers to report any unauthorized access or suspect incidence of fraud in association with their subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUB-9_asm-test name: assessment-method prose: Test this capability. - id: SUB-10 title: Subscriber Account Termination props: - value: 5.4 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-10_smt name: statement prose: "The CSP SHALL promptly suspend or terminate the subscriber account when [any of events listed in Sec. 5.4 occurs]." - id: SUB-10_obj links: - rel: assessment-for href: "#SUB-10_smt" name: objective prose: Confirm that the CSP suspends or terminates subscriber accounts when any of the specified conditions occurs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-10_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy and process for suspending or terminating subscriber accounts based on the specified conditions. - id: SUB-11 title: Account Status Notification props: - value: 5.4 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-11_smt name: statement prose: The CSP SHALL notify the subscriber if their account has been suspended or terminated. - id: SUB-11_obj links: - rel: assessment-for href: "#SUB-11_smt" name: objective prose: Confirm that the CSP notifies subscribers if their subscriber account has been suspended or terminated. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-11_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for notifying a subscriber if their account has been suspended or terminated. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-11_asm-examine-2 name: assessment-method prose: Examine an example of such a notice. - id: SUB-12 title: SA Notification Details props: - value: 5.4 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-12_smt name: statement prose: "Such notices SHALL include information about why the account was suspended or terminated, reactivation or renewal options, and any options for redress if the subscriber thinks the account was suspended or terminated in error." - id: SUB-12_obj links: - rel: assessment-for href: "#SUB-12_smt" name: objective prose: Confirm that the CSP's account suspension or termination notices include sufficient details about the action and options for redress in the case of error. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-12_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine what information is included in its account suspension or termination notices. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-12_asm-examine-2 name: assessment-method prose: Examine an example of such a notice. - id: SUB-13 title: SA Information Deletion props: - value: 5.4 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-13_smt name: statement prose: "The CSP SHALL delete all personal information from the subscriber account records following account termination in accordance with the record retention and disposal requirements, as documented in its practices statement (see Sec. 3.1)." - id: SUB-13_obj links: - rel: assessment-for href: "#SUB-13_smt" name: objective prose: "Confirm that the CSP has a documented records retention and disposal policy, and that it deletes all personal information upon subscriber account determination in accordance with this policy." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-13_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for deleting all personal information from subscriber accounts following account termination. - id: SUB-14 title: Data Breach Notification props: - value: 5.5 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-14_smt name: statement prose: "In the event of a data breach of CSP records, the CSP SHALL provide notification to subscribers whose personal information may have been exposed to unauthorized access." - id: SUB-14_obj links: - rel: assessment-for href: "#SUB-14_smt" name: objective prose: Confirm that the CSP has a documented policy and process for data breach notifications. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-14_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its data breach notification policy. - id: SUB-15 title: Breach Notification Details props: - value: 5.5 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-15_smt name: statement prose: Such notification SHALL include information about the breach and actions for subscribers to take to recover or maintain access to their accounts and to protect against any unauthorized disclosure of their personal information. - id: SUB-15_obj links: - rel: assessment-for href: "#SUB-15_smt" name: objective prose: "Confirm that the CSP's data breach notifications include, at a minimum, information about the breach and any actions the subscriber needs to take with regard to their subscriber account." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-15_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine the information it includes in its data breach notifications. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-15_asm-examine-2 name: assessment-method prose: Examine an example data breach notification. - id: SUB-16 title: Expeditious Breach Notification props: - value: 5.5 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-16_smt name: statement prose: The CSP SHALL send such notifications as expeditiously as possible to the subscribers' validated address. - id: SUB-16_obj links: - rel: assessment-for href: "#SUB-16_smt" name: objective prose: "Confirm that the CSP sends its data breach notifications as soon as reasonably possible, and that such notifications are sent to validated addresses for its subscribers." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-16_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that its policy for sending data breach notifications. - id: SUB-17 title: Multiple Account Reviews props: - value: "5.6 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-17_smt name: statement prose: The CSP SHALL develop and document their process for reviewing and assessing subscribers with multiple accounts to identify possible fraud. - id: SUB-17_obj links: - rel: assessment-for href: "#SUB-17_smt" name: objective prose: Confirm that the CSP has a policy and process for assessing fraud associated with multiple accounts for a single subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-17_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its policy for dealing with multiple accounts associated with a single subscriber. - id: SUB-17_gdn name: guidance prose: "Some CSPs need to support a single user's ability to interact with the CSP while fulfilling different roles or personas. To limit fraud and avoid redundant costs and processes, CSPs SHOULD provide users with a means to manage multiple user personas without having to create multiple subscriber accounts. If this is not possible, and multiple subscriber accounts are supported for a single subscriber, the CSP SHOULD implement its subscriber accounts in a manner that avoids unnecessary re-proofing of the same subscriber (e.g., linking accounts via a common identifier or through biometric or attribute resolution)." - id: SUB-18 title: Multiple Accounts Tracking props: - value: "5.6 #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-18_smt name: statement prose: The CSP SHALL maintain a mapping of all accounts associated with a unique government identifier or common core attributes. - id: SUB-18_obj links: - rel: assessment-for href: "#SUB-18_smt" name: objective prose: Confirm the CSP has a mechanism for tracking all subscriber accounts associated with an individual. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-18_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine its approach for mapping all subscriber accounts associated with a subscriber. - id: SUB-19 title: Multiple Accounts Visibility props: - value: "5.6 #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SUB-19_smt name: statement prose: The CSP SHALL provide individuals with visibility into the full list of subscriber accounts associated with their identity. - id: SUB-19_obj links: - rel: assessment-for href: "#SUB-19_smt" name: objective prose: Confirm that the CSP provides a mechanism for subscribers to view a list of all subscriber accounts associated with their identity. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUB-19_asm-examine name: assessment-method prose: Examine the CSP's practices statement or other documentation to determine that it allows subscribers to view and track all subscriber accounts associated with their identity. - class: revision id: revision-63B title: 63B controls: - id: AAL-1 title: AAL Minimum Requirements props: - value: 2.0 A class: index name: label - value: CSP/Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAL-1_smt name: statement prose: "To satisfy the requirements of a given AAL and be recognized as a subscriber, a claimant SHALL authenticate to an RP (or IdP, as described in [SP800-63C]) with a process whose strength is equal to or greater than the requirements at that level." - id: AAL-1_obj links: - rel: assessment-for href: "#AAL-1_smt" name: objective prose: Authentication requirements meet the requirements of assessed AALs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL-1_asm-examine name: assessment-method prose: Examine CSP documentation to determine that authentication requirements for supported assurance levels address requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL-1_asm-test name: assessment-method prose: Test online processes to ensure that authentication is required whenever identification as a subscriber is required. - id: AAL-2 title: Personal Information AAL props: - value: 2.0 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAL-2_smt name: statement prose: Federal agencies SHALL select a minimum of AAL2 when personal information is made available online. - id: AAL-2_obj links: - rel: assessment-for href: "#AAL-2_smt" name: objective prose: Comply with Section 3 of Executive Order 13681 requiring multifactor authentication - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL-2_asm-examine name: assessment-method prose: |- For federal agency relying parties, where personal information is made available online, Examine policies defining accepted authentication methods to determine that all meet a minimum of AAL2. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL-2_asm-test name: assessment-method prose: Test online authentication processes for identified applications that handle personal information to confirm AAL2 authentication policies are enforced. - id: AAL-2_gdn name: guidance prose: Applies to federal agencies only. - id: AAL-3 title: Fraud Indications props: - value: 2.0 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAL-3_smt name: statement prose: CSPs or verifiers SHALL assess their use of indicators of potential fraud for efficacy and to identify and mitigate potential negative impacts on their user populations. - id: AAL-3_obj links: - rel: assessment-for href: "#AAL-3_smt" name: objective prose: Minimize fraud and potential negative impacts on authentication where possible. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: AAL-3_asm-interview name: assessment-method prose: Interview CSPs and verifier operators to determine that they have evaluated potential fraud indicators. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL-3_asm-examine name: assessment-method prose: Examine CSP UX testing procedures and results to confirm that processes are in place to identify and address UX challenges for user populations. - id: AAL-4 title: Privacy Fraud Indications props: - value: 2.0 D class: index name: label - value: CSP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAL-4_smt name: statement prose: CSPs or verifiers SHALL include fraud indicators in the authentication privacy risk assessment. - id: AAL-4_obj links: - rel: assessment-for href: "#AAL-4_smt" name: objective prose: Minimize potential privacy impacts stemming from use of fraud indicators. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL-4_asm-examine name: assessment-method prose: Examine privacy risk assessment to confirm that it includes any identified uses of fraud indicators. - id: AAL1PAT-1 title: AAL1 Authenticator Types props: - value: 2.1.1 A class: index name: label - value: Verifier class: target name: marking - value: AAL1 class: xal-level name: marking parts: - id: AAL1PAT-1_smt name: statement prose: |- AAL1 authentication SHALL use any of the following authentication types, which are further defined in Sec. 3: (a) Password (Sec. 3.1.1): A memorizable secret typically chosen by the subscriber. (b) Look-up secret (Sec. 3.1.2): A secret determined by the claimant by looking up a prompted value in a list held by the subscriber. (c) Out-of-band device (Sec. 3.1.3): A secret sent or received through a separate communication channel with the subscriber. (d) Single-factor one-time password (OTP) (Sec. 3.1.4): A one-time secret obtained from a device or application held by the subscriber. (e) Multi-factor OTP (Sec. 3.1.5): A one-time secret obtained from a device or application held by the subscriber that requires activation by a second authentication factor. (f) Single-factor cryptographic authentication (Sec. 3.1.6): Proof of possession and control via an authentication protocol of a cryptographic key held by the subscriber. (g) Multi-factor cryptographic authentication (Sec. 3.1.7): Proof of possession and control via an authentication protocol of a cryptographic key held by the subscriber that requires activation by a second authentication factor. - id: AAL1PAT-1_obj links: - rel: assessment-for href: "#AAL1PAT-1_smt" name: objective prose: Identify acceptable authenticator types at AAL1. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL1PAT-1_asm-examine name: assessment-method prose: Examine documentation defining authentication interactions to determine that all authentication methods meet the requirements of one of the defined authenticator types. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL1PAT-1_asm-test name: assessment-method prose: Test authentication events at AAL1 to confirm that implemented processes meet the requirement one of the defined authenticator types. - id: AAL1AVR-1 title: AAL1 Approved Cryptography props: - value: 2.1.2 A class: index name: label - value: Verifier class: target name: marking - value: AAL1 class: xal-level name: marking parts: - id: AAL1AVR-1_smt name: statement prose: Authenticators used at AAL1 SHALL use approved cryptography. - id: AAL1AVR-1_obj links: - rel: assessment-for href: "#AAL1AVR-1_smt" name: objective prose: Use secure cryptographic algorithms. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL1AVR-1_asm-examine name: assessment-method prose: Examine documented policies or practices to determine that only cryptographic algorithms specified in NIST cryptographic guidelines are used. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL1AVR-1_asm-test name: assessment-method prose: Test the system's functionality to observe the cryptographic algorithm(s) being accepted and determine whether the algorithms are specified in NIST cryptographic guidelines. - id: AAL1AVR-2 title: AAL1 Authenticated Protected Channels props: - value: 2.1.2 B class: index name: label - value: Verifier class: target name: marking - value: AAL1 class: xal-level name: marking parts: - id: AAL1AVR-2_smt name: statement prose: Communication between the claimant and verifier SHALL occur via one or more authenticated protected channels. - id: AAL1AVR-2_obj links: - rel: assessment-for href: "#AAL1AVR-2_smt" name: objective prose: Protect the exchange of authenticator information between the verifier and the claimant. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL1AVR-2_asm-examine name: assessment-method prose: Examine the verifier's documentation to ensure that TLS or a similarly secure protocol is used in conjunction with an approved encryption protocol. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL1AVR-2_asm-test name: assessment-method prose: Test the verifier's interactions and observe that TLS or similarly secure protocol is used in conjunction with an approved encryption protocol. - id: AAL1AVR-3 title: AAL1 FIPS140 Validation props: - value: 2.1.2 C class: index name: label - value: Verifier class: target name: marking - value: AAL1 class: xal-level name: marking parts: - id: AAL1AVR-3_smt name: statement prose: "Cryptography used by verifiers operated by or on behalf of federal agencies at AAL1 SHALL be validated to meet the requirements of [FIPS140] Level 1." - id: AAL1AVR-3_obj links: - rel: assessment-for href: "#AAL1AVR-3_smt" name: objective prose: Use validated cryptographic modules and components. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL1AVR-3_asm-examine name: assessment-method prose: Examine system documentation or software information to identify the cryptographic modules used by the verifiers and verify associated CMVP validation certificates. - id: AAL1AVR-3_gdn name: guidance prose: "Applies to federal agencies and those acting on their behalf (e.g., contractors) only." - id: AAL1REA-1 title: AAL1 Reauthentication props: - value: 2.1.3 A class: index name: label - value: RP class: target name: marking - value: AAL1 class: xal-level name: marking parts: - id: AAL1REA-1_smt name: statement prose: "Periodic reauthentication of subscriber sessions SHALL be performed, as described in Sec. 5.2." - id: AAL1REA-1_obj links: - rel: assessment-for href: "#AAL1REA-1_smt" name: objective prose: "Mitigate theft of session secrets, session hijacking, and unauthorized use of open session." - props: - value: EXAMINE name: method class: assessment-summary id: AAL1REA-1_asm-summary title: Assessment Method name: assessment-method prose: See REAUTH 1 - 5 - id: AAL1REA-2 title: AAL1 Overall Timeout props: - value: 2.1.3 B class: index name: label - value: RP class: target name: marking - value: AAL1 class: xal-level name: marking parts: - id: AAL1REA-2_smt name: statement prose: "A definite reauthentication overall timeout SHALL be established, which SHOULD be no more than 30 days at AAL1." - id: AAL1REA-2_obj links: - rel: assessment-for href: "#AAL1REA-2_smt" name: objective prose: "Mitigate theft of session secrets, session hijacking, and unauthorized use of open session." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL1REA-2_asm-examine name: assessment-method prose: Examine documentation for defined reauthentication intervals. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL1REA-2_asm-test name: assessment-method prose: Test implemented controls to confirm reauthentication behavior is consistent with documented AAL1 reauthentication intervals. - id: AAL2PAT-1 title: AAL2 Multiple Factors props: - value: 2.2.1 A class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2PAT-1_smt name: statement prose: "At AAL2, authentication SHALL use either a multi-factor authenticator (MFA) or a combination of two separate authentication factors." - id: AAL2PAT-1_obj links: - rel: assessment-for href: "#AAL2PAT-1_smt" name: objective prose: Enforce MFA at AAL2. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2PAT-1_asm-examine name: assessment-method prose: Examine documentation defining authentication interactions to determine that all authentication methods meet the requirements of AAL2 authenticator types and combinations. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL2PAT-1_asm-test name: assessment-method prose: Test authentication events at AAL2 to confirm that implemented processes meet the requirements of the defined authenticator types and combinations. - id: AAL2PAT-2 title: AAL2 Authenticator Combinations props: - value: 2.2.1 B class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2PAT-2_smt name: statement prose: |- When a combination of two single-factor authenticators is used, the combination SHALL include one physical authenticator (i.e., "something you have") from the following list in conjunction with either a password (Sec. 3.1.1) or a biometric comparison: (a) Look-up secret (Sec. 3.1.2) (b) Out-of-band device (Sec. 3.1.3) (c) Single-factor OTP (Sec. 3.1.4) (d) Single-factor cryptographic authentication (Sec. 3.1.6) - id: AAL2PAT-2_obj links: - rel: assessment-for href: "#AAL2PAT-2_smt" name: objective prose: Enforce MFA at AAL2. - props: - value: EXAMINE name: method class: assessment-summary id: AAL2PAT-2_asm-summary title: Assessment Method name: assessment-method prose: See AAL2PAT-1 - id: AAL2PAT-2_gdn name: guidance prose: Applies when multiple authenticators are used to achieve AAL2. - id: AAL2AVR-1 title: AAL2 Approved Cryptography props: - value: 2.2.2 A class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2AVR-1_smt name: statement prose: Authenticators used at AAL2 SHALL use approved cryptography. - id: AAL2AVR-1_obj links: - rel: assessment-for href: "#AAL2AVR-1_smt" name: objective prose: Use secure cryptographic algorithms. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2AVR-1_asm-examine name: assessment-method prose: Examine documented policies or practices to determine that only cryptographic algorithms specified in NIST cryptographic guidelines are used. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL2AVR-1_asm-test name: assessment-method prose: Test the system's functionality to observe the cryptographic algorithm(s) being accepted and determine whether the algorithms are specified in NIST cryptographic guidelines. - id: AAL2AVR-2 title: AAL2 FIPS140 Authenticators props: - value: 2.2.2 B class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2AVR-2_smt name: statement prose: "Cryptographic authenticators procured by federal agencies SHALL be validated to meet the requirements of [FIPS140] Level 1." - id: AAL2AVR-2_obj links: - rel: assessment-for href: "#AAL2AVR-2_smt" name: objective prose: Authenticators procured by or on behalf of government agencies use validated cryptographic modules and components. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2AVR-2_asm-examine name: assessment-method prose: Examine system documentation or vendor documentation to identify the cryptographic modules used by authenticators and verify associated CMVP validation certificates. - id: AAL2AVR-2_gdn name: guidance prose: Applies to authenticators procured by federal agencies only. - id: AAL2AVR-3 title: AAL2 Replay Resistance props: - value: 2.2.2 C class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2AVR-3_smt name: statement prose: "At least one authenticator used at AAL2 SHALL be replay-resistant, as described in Sec. 3.2.7." - id: AAL2AVR-3_obj links: - rel: assessment-for href: "#AAL2AVR-3_smt" name: objective prose: Prevent attackers from reusing stolen or observed authentication data to hijack accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2AVR-3_asm-examine name: assessment-method prose: "Examine the combinations of authenticators that can be used at AAL2 and verify that for each combination, at least one authenticator is replay-resistant. OTP authenticators, cryptographic authenticators, and look-up secrets are considered replay resistant." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL2AVR-3_asm-test name: assessment-method prose: "Test if verifying a physical authenticator that does not implement a cryptographic challenge/response protocol, attempt to authenticate more than once using the same authenticator output (during its validity period, if time-based). If a subsequent authentication succeeds, the test of replay resistance has failed." - id: AAL2AVR-4 title: AAL2 Authenticated Protected Channels props: - value: 2.2.2 D class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2AVR-4_smt name: statement prose: Communication between the claimant and verifier SHALL occur via one or more authenticated protected channels. - id: AAL2AVR-4_obj links: - rel: assessment-for href: "#AAL2AVR-4_smt" name: objective prose: Determine that the communication channel meets the requirements of an authenticated protected channel as defined in SP 800-63B-4 Appendix D. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2AVR-4_asm-examine name: assessment-method prose: Examine the verifier's documentation to ensure that TLS or a similarly secure protocol is used in conjunction with an approved encryption protocol. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL2AVR-4_asm-test name: assessment-method prose: Test the verifier's interactions and observe that TLS or similarly secure protocol is used in conjunction with an approved encryption protocol. - id: AAL2AVR-5 title: AAL2 FIPS140 Verifiers props: - value: 2.2.2 E class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2AVR-5_smt name: statement prose: "Cryptography used by verifiers operated by or on behalf of federal agencies at AAL2 SHALL be validated to meet the requirements of [FIPS140] Level 1 unless otherwise specified." - id: AAL2AVR-5_obj links: - rel: assessment-for href: "#AAL2AVR-5_smt" name: objective prose: Verifiers operated by or on behalf of government agencies are required to be validated to meet FIPS 140 requirements. The FIPS 140 requirements generally apply to cryptographic modules (both hardware and software). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2AVR-5_asm-examine name: assessment-method prose: Examine system documentation or software information to identify the cryptographic modules used by the verifiers and verify associated CMVP validation certificates. - id: AAL2AVR-5_gdn name: guidance prose: "Applies to federal agencies and those acting on their behalf (e.g., contractors) only." - id: AAL2AVR-6 title: AAL2 Phishing Resistance Offer props: - value: 2.2.2 F class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2AVR-6_smt name: statement prose: "Verifiers SHALL offer at least one phishing-resistant authentication option at AAL2, as described in Sec. 3.2.5." - id: AAL2AVR-6_obj links: - rel: assessment-for href: "#AAL2AVR-6_smt" name: objective prose: Ensure that phishing-resistant authentication methods are available to subscribers who wish to use them. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2AVR-6_asm-examine name: assessment-method prose: Examine documentation to determine that authentication at AAL2 always includes a phishing-resistant option. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL2AVR-6_asm-test name: assessment-method prose: Test authentication selection screens at AAL2 to confirm that a phishing resistant authentication options is presented to users. - id: AAL2AVR-7 title: AAL2 Phishing Resistance Requirement props: - value: 2.2.2 G class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2AVR-7_smt name: statement prose: "Federal agencies SHALL require their staff, contractors, and partners to use phishing-resistant authentication to access federal information systems." - id: AAL2AVR-7_obj links: - rel: assessment-for href: "#AAL2AVR-7_smt" name: objective prose: "Ensure phishing resistance for applications used by federal staff, contractors, and partners." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2AVR-7_asm-examine name: assessment-method prose: Examine documentation to determine that authentication of internal applications at AAL2 requires use of a phishing-resistant authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL2AVR-7_asm-test name: assessment-method prose: Test authentication to determine that authentication at AAL2 requires use of a phishing-resistant authenticator. - id: AAL2AVR-7_gdn name: guidance prose: Applies to federal agencies only. - id: AAL2REA-1 title: AAL2 Reauthentication props: - value: 2.2.3 A class: index name: label - value: RP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: AAL2REA-1_smt name: statement prose: "Periodic reauthentication of subscriber sessions SHALL be performed, as described in Sec. 5.2." - id: AAL2REA-1_obj links: - rel: assessment-for href: "#AAL2REA-1_smt" name: objective prose: Determine that appropriate expiration of sessions occurs to mitigate theft of session secrets or use of a forgotten session. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL2REA-1_asm-examine name: assessment-method prose: Examine documentation to determine that required reauthentication requirements are enforced. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL2REA-1_asm-test name: assessment-method prose: "Test by authenticating, then idle for documented inactivity timeout and determine that reauthentication is required. Maintain a session for at least the overall timeout period and observe that reauthentication is required." - id: AAL3PAT-1 title: AAL3 Authenticator Combinations props: - value: 2.3.1 A class: index name: label - value: Verifier class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3PAT-1_smt name: statement prose: AAL3 authentication SHALL require an authenticator combination consisting of either multi-factor cryptographic authentication (Sec. 3.1.7); or single-factor cryptographic authentication (Sec. 3.1.6) used in conjunction with either a password (Sec. 3.1.1) or a biometric comparison. - id: AAL3PAT-1_obj links: - rel: assessment-for href: "#AAL3PAT-1_smt" name: objective prose: Require use of highest security authenticators at AAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3PAT-1_asm-examine name: assessment-method prose: Examine documented policies or practices to determine authenticator types that can be used. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL3PAT-1_asm-test name: assessment-method prose: Test the system's functionality to observe the authenticator types being made available to users and accepted. - id: AAL3AVR-1 title: AAL3 Approved Cryptography props: - value: 2.3.2 A class: index name: label - value: Verifier class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-1_smt name: statement prose: Authenticators used at AAL3 SHALL use approved cryptography. - id: AAL3AVR-1_obj links: - rel: assessment-for href: "#AAL3AVR-1_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-1_asm-examine name: assessment-method prose: Examine documented policies or practices to determine that only approved cryptographic algorithms can be used. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-1_asm-examine-2 name: assessment-method prose: Examine the system's functionality to observe the cryptographic algorithm(s) being accepted and determine whether the algorithms are approved. - id: AAL3AVR-2 title: AAL3 Authenticated Protected Channels props: - value: 2.3.2 B class: index name: label - value: Verifier class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-2_smt name: statement prose: Communication between the claimant and verifier SHALL occur via one or more authenticated protected channels. - id: AAL3AVR-2_obj links: - rel: assessment-for href: "#AAL3AVR-2_smt" name: objective prose: Determine that the communication channel meets the requirements of an authenticated protected channel as defined in SP 800-63B-4 Appendix D. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-2_asm-examine name: assessment-method prose: Examine the verifier's documentation to ensure that TLS or a similarly secure protocol is used in conjunction with an approved encryption protocol. - id: AAL3AVR-3 title: AAL3 Non-Exportable Key props: - value: 2.3.2 C class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-3_smt name: statement prose: The cryptographic authenticator used at AAL3 SHALL have a non-exportable private key. - id: AAL3AVR-3_obj links: - rel: assessment-for href: "#AAL3AVR-3_smt" name: objective prose: Require use of high-security authenticators at AAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-3_asm-examine name: assessment-method prose: Examine the authenticators and their associated architecture/documentation offered by the CSP to determine how keys are protected and that they meet non-exportability requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-3_asm-examine-2 name: assessment-method prose: Examine signed authenticator attestations (if available) to determine key protection characteristics and that they meet non-exportability requirements. - id: AAL3AVR-3.5 title: AAL3 Phishing Resistance props: - value: 2.3.2 C class: index name: label - value: Verifier class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-3.5_smt name: statement prose: "The cryptographic authenticator used at AAL3 SHALL provide phishing resistance, as described in Sec. 3.2.5." - id: AAL3AVR-3.5_obj links: - rel: assessment-for href: "#AAL3AVR-3.5_smt" name: objective prose: Require use of phishing resistant authenticators at AAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-3.5_asm-examine name: assessment-method prose: Examine documentation to determine that authentication at AAL3 requires use of a phishing-resistant authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL3AVR-3.5_asm-test name: assessment-method prose: Test authentication to determine that authentication at AAL3 requires use of a phishing-resistant authenticator. - id: AAL3AVR-3.7 title: AAL3 Replay Resistance props: - value: 2.3.2 D class: index name: label - value: Verifier class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-3.7_smt name: statement prose: The cryptographic authentication protocol SHALL be replay-resistant. - id: AAL3AVR-3.7_obj links: - rel: assessment-for href: "#AAL3AVR-3.7_smt" name: objective prose: Ensure that the authentication transaction cannot be replayed by an attacker. - props: - value: EXAMINE name: method class: assessment-summary id: AAL3AVR-3.7_asm-summary title: Assessment Method name: assessment-method prose: Requirement is met by satisfying requirement to use a cryptographic authenticator (AAL3PAT-1). - id: AAL3AVR-4 title: AAL3 Intent props: - value: 2.3.2 E class: index name: label - value: Verifier class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-4_smt name: statement prose: "All authentication and reauthentication processes at AAL3 SHALL demonstrate authentication intent from at least one authenticator, as described in Sec. 3.2.8." - id: AAL3AVR-4_obj links: - rel: assessment-for href: "#AAL3AVR-4_smt" name: objective prose: "Ensure that authentication is actively requested, and not accidental." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-4_asm-examine name: assessment-method prose: Examine CSP documentation to determine the acceptable combinations of authenticators that are available to subscribers authenticating at AAL3. - id: AAL3AVR-5 title: AAL3 Public-Key Cryptography props: - value: 2.3.2 F class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-5_smt name: statement prose: Cryptographic authenticators used at AAL3 SHALL use public-key cryptography to protect the authentication secrets from compromise of the verifier. - id: AAL3AVR-5_obj links: - rel: assessment-for href: "#AAL3AVR-5_smt" name: objective prose: Avoid the use of shared authentication secrets that could be compromised by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-5_asm-examine name: assessment-method prose: Examine documentation of verifiers to determine that they only store public keys for cryptographic authenticators used at AAL3. - id: AAL3AVR-6 title: AAL3 FIPS140 Authenticators props: - value: 2.3.2 G class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-6_smt name: statement prose: "Single-factor and multi-factor authenticators used at AAL3 SHALL be validated to meet the requirements of [FIPS140] Level 1 or higher overall." - id: AAL3AVR-6_obj links: - rel: assessment-for href: "#AAL3AVR-6_smt" name: objective prose: Cryptographic authenticators at AAL3 are required to be validated to meet FIPS 140 requirements. The FIPS 140 requirements generally apply to cryptographic modules (both hardware and software). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-6_asm-examine name: assessment-method prose: Examine system documentation or software information to identify the cryptographic modules used by the authenticators and verify associated CMVP validation certificates. - id: AAL3AVR-7 title: AAL3 Unsyncability props: - value: 2.3.2 H class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-7_smt name: statement prose: Syncable authenticators SHALL NOT be used at AAL3. - id: AAL3AVR-7_obj links: - rel: assessment-for href: "#AAL3AVR-7_smt" name: objective prose: "Ensure that syncable authenticators, which have exportable authentication keys, are not used." - props: - value: EXAMINE name: method class: assessment-summary id: AAL3AVR-7_asm-summary title: Assessment Method name: assessment-method prose: Requirement is met by authenticators meeting AAL3AVR-3. - id: AAL3AVR-8 title: AAL3 FIPS140 Verifiers props: - value: 2.3.2 I class: index name: label - value: Verifier class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3AVR-8_smt name: statement prose: "Cryptography used by verifiers at AAL3 SHALL be validated at [FIPS140] Level 1 or higher." - id: AAL3AVR-8_obj links: - rel: assessment-for href: "#AAL3AVR-8_smt" name: objective prose: Verifiers operated by or on behalf of government agencies are required to be validated to meet FIPS 140 requirements. The FIPS 140 requirements generally apply to cryptographic modules (both hardware and software). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3AVR-8_asm-examine name: assessment-method prose: Examine system documentation or software information to identify the cryptographic modules used by the verifiers and verify associated CMVP validation certificates. - id: AAL3REA-1 title: AAL3 Reauthentication props: - value: 2.3.3 A class: index name: label - value: RP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3REA-1_smt name: statement prose: "Periodic reauthentication of subscriber sessions SHALL be performed, as described in Sec. 5.2." - id: AAL3REA-1_obj links: - rel: assessment-for href: "#AAL3REA-1_smt" name: objective prose: Determine that appropriate expiration of sessions occurs to mitigate theft of session secrets or use of a forgotten session. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AAL3REA-1_asm-test name: assessment-method prose: "Test to authenticate, then idle for documented inactivity timeout and determine that reauthentication is required. Maintain a session for at least the overall timeout period and observe that reauthentication is required." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3REA-1_asm-examine name: assessment-method prose: Examine verifier or CSP documentation to determine that required reauthentication requirements are enforced. - id: AAL3REA-2 title: AAL3 Reauthentication Limit props: - value: 2.3.3 B class: index name: label - value: RP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: AAL3REA-2_smt name: statement prose: "At AAL3, the overall timeout for reauthentication SHALL be no more than 12 hours." - id: AAL3REA-2_obj links: - rel: assessment-for href: "#AAL3REA-2_smt" name: objective prose: Establish upper bound on session lifetime. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAL3REA-2_asm-examine name: assessment-method prose: Examine CSP documentation to see that maximum overall session timeout is less than or equal to 12 hours. - id: SC-1 title: Security Controls props: - value: 2.4.1 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SC-1_smt name: statement prose: "The verifier SHALL employ appropriately tailored security controls from the moderate baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard that the organization has chosen for the information systems, applications, and online services that these guidelines are used to protect." - id: SC-1_obj links: - rel: assessment-for href: "#SC-1_smt" name: objective prose: Determine compliance with relevant overall security controls. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SC-1_asm-examine name: assessment-method prose: "Examine the CSP's documentation to determine it employs appropriately tailored security controls to include control enhancements, from the medium baseline of security controls defined in SP 800-53 or equivalent federal (e.g., FEDRAMP) or industry standard." - id: RRP-1 title: Records Retention props: - value: 2.4.2 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RRP-1_smt name: statement prose: "The verifier SHALL comply with its respective records retention policies in accordance with applicable laws, regulations, and policies, including any National Archives and Records Administration (NARA) records retention schedules that may apply." - id: RRP-1_obj links: - rel: assessment-for href: "#RRP-1_smt" name: objective prose: Determine compliance with records retention policy requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RRP-1_asm-examine name: assessment-method prose: "Examine the CSP's records retention policy and evaluate its applicability with laws and regulations. Where applicable, audit a sample of retained records to ensure that their retention is consistent with policy." - id: RRP-2 title: Records Retention Risk props: - value: 2.4.2 B class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RRP-2_smt name: statement prose: "If the verifier opts to retain records in the absence of mandatory requirements, the verifier or the CSP or IdP of which it is a part SHALL conduct a risk management process [NISTRMF], including assessments of privacy and security risks, to determine how long records should be retained and SHALL inform the subscriber of that retention policy." - id: RRP-2_obj links: - rel: assessment-for href: "#RRP-2_smt" name: objective prose: Verify justification for records retention not covered by mandatory requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RRP-2_asm-examine name: assessment-method prose: "Examine evidence to determine risk-based decision for records retention was used, and that notice to subscribers is provided." - id: RRP-2_gdn name: guidance prose: Non-mandatory records retention. - id: PR-1 title: Privacy Controls props: - value: 2.4.3 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PR-1_smt name: statement prose: "The verifier SHALL employ appropriately tailored privacy controls defined in [SP800-53] or an equivalent industry standard." - id: PR-1_obj links: - rel: assessment-for href: "#PR-1_smt" name: objective prose: Determine compliance with relevant overall privacy requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PR-1_asm-examine name: assessment-method prose: "Examine the CSP's operating procedure documentation and, as applicable, authority-to-operate (ATO) for consistency with SP 800-53 or equivalent standard." - id: PR-2 title: Attribute Privacy Management props: - value: 2.4.3 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PR-2_smt name: statement prose: "If CSPs or IdPs process attributes for purposes other than identity services (i.e., identity proofing, authentication, or attribute assertions), related fraud mitigation, or compliance with laws or legal processes, they SHALL implement measures to maintain predictability and manageability commensurate with the privacy risks that arise from the additional processing." - id: PR-2_obj links: - rel: assessment-for href: "#PR-2_smt" name: objective prose: Determine compliance with relevant privacy requirements for supplemental services. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PR-2_asm-examine name: assessment-method prose: "Examine the CSP's documented policies or practices to determine which predictability and manageability measures it employs, (e.g., notice, consent, selective disclosure)." - id: PR-2_gdn name: guidance prose: Applies when there is non-identity use of identity attributes. - id: PR-3 title: Consent Non-Mandatory props: - value: 2.4.3 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PR-3_smt name: statement prose: "When CSPs or IdPs use consent measures, they SHALL NOT make consent for the additional processing a condition of the identity service." - id: PR-3_obj links: - rel: assessment-for href: "#PR-3_smt" name: objective prose: Ensure that consent measures are voluntary. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PR-3_asm-examine name: assessment-method prose: Examine terms of use to ensure that additional consent is not a requirement. - id: PR-3_gdn name: guidance prose: Applies when consent is requested from subscriber. - id: PR-4 title: Privacy Act Consultation props: - value: "2.4.3 #1" class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PR-4_smt name: statement prose: "The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) and conduct an analysis to determine whether the collection of personal information to issue or maintain authenticators triggers the requirements of the Privacy Act of 1974 [Privacy Act] (see Sec. 7.4)." - id: PR-4_obj links: - rel: assessment-for href: "#PR-4_smt" name: objective prose: Determine when Privacy Act requirements are triggered. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PR-4_asm-examine name: assessment-method prose: Examine documentation to determine that consultation with the SAOP occurred and that all determinations of whether the service is subject to the privacy act of 1974 have been recorded. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PR-4_asm-interview name: assessment-method prose: Interview to confirm that the agency has consulted with its SAOP to determine if the service is subject to the Privacy Act of 1974. - id: PR-4_gdn name: guidance prose: Applies to federal agencies and others acting on their behalf. - id: PR-5 title: SORN Publication props: - value: "2.4.3 #2" class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PR-5_smt name: statement prose: "The agency SHALL publish a System of Records Notice (SORN) to cover such collections, as applicable." - id: PR-5_obj links: - rel: assessment-for href: "#PR-5_smt" name: objective prose: Determine that a SORN is published when required. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PR-5_asm-examine name: assessment-method prose: "Examine the agency's System of Records Notice, as applicable." - id: PR-5_gdn name: guidance prose: Applies to federal agencies only. - id: PR-6 title: E-Government Consultation props: - value: "2.4.3 #3" class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PR-6_smt name: statement prose: "The agency SHALL consult with its SAOP and conduct an analysis to determine whether the collection of personal information to issue or maintain authenticators triggers the requirements of the E-Government Act of 2002 [E-Gov]." - id: PR-6_obj links: - rel: assessment-for href: "#PR-6_smt" name: objective prose: Determine when E-Government Act requirements are triggered. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PR-6_asm-interview name: assessment-method prose: Interview to confirm that the agency offering or using the identity proofing service has consulted with its SAOP to determine if the service is subject to the E-Government Act of 2002. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PR-6_asm-examine name: assessment-method prose: Examine documentation of the SAOP assessment. - id: PR-6_gdn name: guidance prose: Applies to federal agencies only. - id: PR-7 title: Privacy Impact Assessment Publication props: - value: "2.4.3 #4" class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PR-7_smt name: statement prose: "The agency SHALL publish a Privacy Impact Assessment (PIA) to cover such collection, as applicable." - id: PR-7_obj links: - rel: assessment-for href: "#PR-7_smt" name: objective prose: Determine that a PIA is published when required. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PR-7_asm-examine name: assessment-method prose: "Examine the agency's Privacy Impact Assessment, as applicable." - id: PR-7_gdn name: guidance prose: Applies to federal agencies and others providing services to federal agencies. - id: REDAUTH-1 title: Redress Provision props: - value: 2.4.4 A class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REDAUTH-1_smt name: statement prose: "The verifier and associated CSP or IdP SHALL provide mechanisms for the redress of subscriber complaints and problems that arise from subscriber authentication processes, as described in Sec. 5.6 of [SP800-63]." - id: REDAUTH-1_obj links: - rel: assessment-for href: "#REDAUTH-1_smt" name: objective prose: Determine that useful redress for authentication problems is provided. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: REDAUTH-1_asm-test name: assessment-method prose: Test redress mechanisms from the viewpoint of the claimant. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REDAUTH-1_asm-examine name: assessment-method prose: Examine redress mechanisms from the viewpoint of the claimant. - id: REDAUTH-2 title: Redress Usability props: - value: 2.4.4 B class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REDAUTH-2_smt name: statement prose: These mechanisms SHALL be easy for subscribers to find and use. - id: REDAUTH-2_obj links: - rel: assessment-for href: "#REDAUTH-2_smt" name: objective prose: Ensure that redress mechanisms are usable by the population of subscribers. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: REDAUTH-2_asm-test name: assessment-method prose: Test redress mechanisms to determine their ease of use. - id: REDAUTH-3 title: Redress Efficacy props: - value: 2.4.4 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REDAUTH-3_smt name: statement prose: The CSP or IdP SHALL assess the mechanisms for efficacy in resolving complaints or problems. - id: REDAUTH-3_obj links: - rel: assessment-for href: "#REDAUTH-3_smt" name: objective prose: Ensure that redress mechanisms are sufficient to resolve expected authentication problems. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: REDAUTH-3_asm-interview name: assessment-method prose: Interview CSP or IdP operator to determine the results of their assessment. - id: PASSAUTH-1 title: Password Choice props: - value: 3.1.1.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PASSAUTH-1_smt name: statement prose: Passwords SHALL either be chosen by the subscriber or assigned randomly by the CSP. - id: PASSAUTH-1_obj links: - rel: assessment-for href: "#PASSAUTH-1_smt" name: objective prose: "Establish acceptable methods of password creation (e.g., no default passwords)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PASSAUTH-1_asm-test name: assessment-method prose: Test by creating a new account or changing a password to determine how password is chosen. If the password is not chosen by the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PASSAUTH-1_asm-interview name: assessment-method prose: Interview CSP to establish that the password is assigned randomly. - id: PASSAUTH-2 title: Password Blocklist props: - value: 3.1.1.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PASSAUTH-2_smt name: statement prose: "If the CSP disallows a chosen password because it is on a blocklist of commonly used, expected, or compromised values (see Sec. 3.1.1.2), the subscriber SHALL be required to choose a different password." - id: PASSAUTH-2_obj links: - rel: assessment-for href: "#PASSAUTH-2_smt" name: objective prose: Prohibit use of passwords expected to be commonly chosen. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PASSAUTH-2_asm-test name: assessment-method prose: Test by attempting to set an account to use a memorized secret that is on the blocklist. The attempt should fail. - id: PASSAUTH-3 title: Password Composition props: - value: 3.1.1.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PASSAUTH-3_smt name: statement prose: Other composition requirements for passwords SHALL NOT be imposed. - id: PASSAUTH-3_obj links: - rel: assessment-for href: "#PASSAUTH-3_smt" name: objective prose: "Prohibit composition rules (e.g., requirement for specific character types)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PASSAUTH-3_asm-test name: assessment-method prose: "Test by attempting to create an unusual password that does not meet usual composition requirements (e.g., all lower case letters) and determine that it is accepted." - id: PV-1 title: Password Length props: - value: "3.1.1.2 #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-1_smt name: statement prose: Verifiers and CSPs SHALL require passwords that are used as a single-factor authentication mechanism to be a minimum of 15 characters in length. Verifiers and CSPs MAY allow passwords that are only used as part of multi-factor authentication processes to be shorter but SHALL require them to be a minimum of eight characters in length. - id: PV-1_obj links: - rel: assessment-for href: "#PV-1_smt" name: objective prose: Require passwords to be long enough to provide baseline security. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-1_asm-test name: assessment-method prose: Test by trying to create a password that does not meet the minimum length requirements and verify that it is not accepted. - id: PV-2 title: Unicode Passwords props: - value: "3.1.1.2 #4" class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-2_smt name: statement prose: "Verifiers and CSPs SHOULD accept Unicode [ISO/IEC 10646] characters in passwords. Each Unicode code point SHALL be counted as a single character when evaluating password length." - id: PV-2_obj links: - rel: assessment-for href: "#PV-2_smt" name: objective prose: "Allow use of characters memorable to the subscriber, even if they use a language not represented by ASCII." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-2_asm-test name: assessment-method prose: "Test by creating a password containing a Unicode character such as an accented vowel and determine that it is accepted, and that the unaccented version of the same character does not allow successful authentication." - id: PV-3 title: Password Verifier Composition props: - value: "3.1.1.2 #5" class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-3_smt name: statement prose: "Verifiers and CSPs SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords." - id: PV-3_obj links: - rel: assessment-for href: "#PV-3_smt" name: objective prose: "Prohibit composition rules (e.g., requirement for specific character types)" - props: - value: EXAMINE name: method class: assessment-summary id: PV-3_asm-summary title: Assessment Method name: assessment-method prose: See PASSAUTH-3 - id: PV-4 title: Password Non-Expiration props: - value: "3.1.1.2 #6" class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-4_smt name: statement prose: "Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically. However, verifiers SHALL force a change if there is evidence that the authenticator has been compromised." - id: PV-4_obj links: - rel: assessment-for href: "#PV-4_smt" name: objective prose: "Prohibit password rotation, which has been shown to cause selection of weaker passwords." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PV-4_asm-interview name: assessment-method prose: "Interview to determine from CSP that periodic password changes are not required, but that a mechanism is in place to force password changes for affected subscribers after a breach." - id: PV-5 title: Password Hints props: - value: "3.1.1.2 #7" class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-5_smt name: statement prose: "Verifiers and CSPs SHALL NOT permit the subscriber to store a hint (e.g., a reminder of how the password was created) that is accessible to an unauthenticated claimant." - id: PV-5_obj links: - rel: assessment-for href: "#PV-5_smt" name: objective prose: "Prohibit use of password hints, which greatly weaken security." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-5_asm-test name: assessment-method prose: Test to ensure that there is no provision for a password hint to be displayed to unauthenticated claimants and that there is no provision for storing a hint in subscribers' account management. - id: PV-6 title: Passwords Not KBA props: - value: "3.1.1.2 #8" class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-6_smt name: statement prose: "Verifiers and CSPs SHALL NOT prompt subscribers to use knowledge-based authentication (KBA) (e.g., \"What was the name of your first pet?\") or security questions when choosing passwords." - id: PV-6_obj links: - rel: assessment-for href: "#PV-6_smt" name: objective prose: "Prohibit use of KBA, which greatly weakens security." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-6_asm-test name: assessment-method prose: Test to ensure that there is no authentication flow that involves the use of KBA and that there is no provision for storing authentication questions and answers in subscribers' account management. - id: PV-7 title: Password Full Verification props: - value: "3.1.1.2 #9" class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-7_smt name: statement prose: "Verifiers SHALL request the password to be provided in full (not a subset of it) and SHALL verify the entire submitted password (e.g., not truncate it)." - id: PV-7_obj links: - rel: assessment-for href: "#PV-7_smt" name: objective prose: Require use of the entire password for authentication to maximize the security benefit of the whole password. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PV-7_asm-examine name: assessment-method prose: Examine verification code to ensure that entire password is verified. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-7_asm-test name: assessment-method prose: Test by creating long passwords and attempting to authenticate with truncated passwords. - id: PV-8 title: Password Verifier Blocklist props: - value: 3.1.1.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-8_smt name: statement prose: "When processing a request to establish or change a password, verifiers SHALL compare the prospective secret against a blocklist that contains known commonly used, expected, or compromised passwords." - id: PV-8_obj links: - rel: assessment-for href: "#PV-8_smt" name: objective prose: Require use of a blocklist to prevent selection of excessively weak passwords. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PV-8_asm-interview name: assessment-method prose: Interview CSP to determine contents of the blocklist. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-8_asm-test name: assessment-method prose: Test to ensure that it is not possible to change a password to a blocklist entry. - id: PV-9 title: Verifier Blocklist Substrings props: - value: 3.1.1.2 B class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-9_smt name: statement prose: "The entire password SHALL be subject to comparison, not substrings or words that might be contained therein." - id: PV-9_obj links: - rel: assessment-for href: "#PV-9_smt" name: objective prose: Ensure that the entire password is verified so that the full security benefit of long passwords is realized. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-9_asm-test name: assessment-method prose: Test to ensure that a long password containing a blocklist entry is accepted. - id: PV-10 title: Verifier Blocklist Response props: - value: 3.1.1.2 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-10_smt name: statement prose: "If the chosen password is found on the blocklist, the CSP SHALL require the subscriber to select a different secret and SHALL provide the reason for rejection." - id: PV-10_obj links: - rel: assessment-for href: "#PV-10_smt" name: objective prose: Require selection of a different password if a weak one is chosen. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-10_asm-test name: assessment-method prose: Test to ensure that a substitute for a blocklisted password is requested. - id: PV-11 title: Strong Password Guidance props: - value: 3.1.1.2 D class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-11_smt name: statement prose: "Verifiers SHALL offer guidance to the subscriber to help the subscriber choose a strong password. This is particularly important following the rejection of a password on the blocklist as it discourages trivial modifications of listed weak passwords [Blocklists]." - id: PV-11_obj links: - rel: assessment-for href: "#PV-11_smt" name: objective prose: Require coaching of the subscriber on selection of better passwords if a weak one is initially chosen. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-11_asm-test name: assessment-method prose: Test to determine that helpful advice on choosing strong passwords is offered. - id: PV-12 title: Password Rate-Limiting props: - value: 3.1.1.2 E class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-12_smt name: statement prose: "Verifiers SHALL implement a rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on the subscriber account, as described in Sec. 3.2.2." - id: PV-12_obj links: - rel: assessment-for href: "#PV-12_smt" name: objective prose: Strengthen verifier against online password guessing attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-12_asm-test name: assessment-method prose: Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited. - id: PV-13 title: Password Manager Use props: - value: 3.1.1.2 F class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-13_smt name: statement prose: Verifiers SHALL allow the use of password managers and autofill functionality. - id: PV-13_obj links: - rel: assessment-for href: "#PV-13_smt" name: objective prose: "Allow subscriber to use a password manager, which aids in the use of strong and unguessable passwords." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-13_asm-test name: assessment-method prose: Test by attempting to authenticate using one or more popular password managers and verify that a password stored in the manager can be filled in. - id: PV-14 title: Password Authenticated Protected Channels props: - value: 3.1.1.2 G class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-14_smt name: statement prose: Verifiers and CSPs SHALL use approved encryption and an authenticated protected channel when requesting passwords. - id: PV-14_obj links: - rel: assessment-for href: "#PV-14_smt" name: objective prose: Ensure that the communication channel to the verifier is secure against eavesdropping. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PV-14_asm-test name: assessment-method prose: Test password transmission to verify that an authenticated protected channel such as TLS is used. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PV-14_asm-examine name: assessment-method prose: Examine encryption algorithms used to verify that they are approved. - id: PV-15 title: Password Offline Attack Resistance props: - value: 3.1.1.2 H class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-15_smt name: statement prose: Verifiers SHALL store passwords in a form that is resistant to offline attacks. - id: PV-15_obj links: - rel: assessment-for href: "#PV-15_smt" name: objective prose: Require strong storage to protect against offline attacks. - props: - value: EXAMINE name: method class: assessment-summary id: PV-15_asm-summary title: Assessment Method name: assessment-method prose: Requirement is satisfied by PV-16 through PV-18. - id: PV-16 title: Password Salted Hashing props: - value: 3.1.1.2 I class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-16_smt name: statement prose: Passwords SHALL be salted and hashed using a suitable password hashing scheme. - id: PV-16_obj links: - rel: assessment-for href: "#PV-16_smt" name: objective prose: "At a minimum, require salting and hashing of passwords as protection against offline attacks should the verifier be breached." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PV-16_asm-examine name: assessment-method prose: Examine password verification storage to determine evidence of password hashing and salt storage. - id: PV-17 title: Salt Requirements props: - value: 3.1.1.2 J class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-17_smt name: statement prose: "The salt SHALL be at least 32 bits in length and chosen to minimize salt value collisions among stored hashes (i.e., to prevent multiple subscriber accounts from having the same hashed password)." - id: PV-17_obj links: - rel: assessment-for href: "#PV-17_smt" name: objective prose: Require use of a salt sufficient to ensure that two subscribers with the same password do not hash to the same value in the verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PV-17_asm-examine name: assessment-method prose: Examine stored salt values to ensure that they are at least 32 bits in length. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PV-17_asm-interview name: assessment-method prose: Interview CSP personnel to determine that salt is chosen to avoid collisions. - id: PV-18 title: Salt Storage props: - value: 3.1.1.2 K class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-18_smt name: statement prose: Both the salt value and the resulting hash SHALL be stored for each password. - id: PV-18_obj links: - rel: assessment-for href: "#PV-18_smt" name: objective prose: Describes the use of a salt. - props: - value: EXAMINE name: method class: assessment-summary id: PV-18_asm-summary title: Assessment Method name: assessment-method prose: Requirement is satisfied by verification method of PV-16. - id: PV-19 title: Hashing Key Generation props: - value: 3.1.1.2 L class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-19_smt name: statement prose: "If used, this key value SHALL be generated by an approved random bit generator, as described in Sec. 3.2.1.2." - id: PV-19_obj links: - rel: assessment-for href: "#PV-19_smt" name: objective prose: "For keyed hashing, require appropriate selection of the key." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PV-19_asm-interview name: assessment-method prose: Interview CSP personnel to determine how the key value is generated. - id: PV-19_gdn name: guidance prose: Applies when keyed hashing is used. - id: PV-20 title: Hashing Key Storage props: - value: 3.1.1.2 M class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PV-20_smt name: statement prose: The secret key value SHALL be stored separately from the hashed passwords. - id: PV-20_obj links: - rel: assessment-for href: "#PV-20_smt" name: objective prose: Require separate storage for a keyed hash key so it is not also breached if the hashed passwords are. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: PV-20_asm-interview name: assessment-method prose: Interview CSP personnel to determine how the key value is stored. - id: PV-20_gdn name: guidance prose: Applies when keyed hashing is used. - id: LSA-1 title: Look-Up Secret Generation props: - value: 3.1.2.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSA-1_smt name: statement prose: "CSPs that create look-up secret authenticators SHALL use an approved random bit generator, as described in Sec. 3.2.12, to generate the list of secrets." - id: LSA-1_obj links: - rel: assessment-for href: "#LSA-1_smt" name: objective prose: Require selection of sufficiently random look-up secrets - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: LSA-1_asm-examine name: assessment-method prose: Examine code used to generate look-up secrets. - id: LSA-1.5 title: Look-Up Secret Delivery props: - value: 3.1.2.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSA-1.5_smt name: statement prose: "CSPs that create look-up secret authenticators SHALL deliver the authenticator list securely to the subscriber (e.g., in an in-person session, via an online session, through the postal mail to a contact address)." - id: LSA-1.5_obj links: - rel: assessment-for href: "#LSA-1.5_smt" name: objective prose: Ensure that eavesdroppers and other intermediaries do not have access to look-up secrets being delivered to the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: LSA-1.5_asm-interview name: assessment-method prose: Interview CSP to determine the possible methods for delivering look-up secrets to subscribers. - id: LSA-2 title: Online Look-Up Secret Delivery props: - value: 3.1.2.1 B class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSA-2_smt name: statement prose: "If delivered via an online session, the session SHALL be authenticated by the subscriber at AAL2 or higher and SHALL deliver the secrets through an authenticated protected channel and in accordance with the post-enrollment binding requirements in Sec. 4.1.2." - id: LSA-2_obj links: - rel: assessment-for href: "#LSA-2_smt" name: objective prose: Ensure that online delivery of look-up secrets is sufficiently secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: LSA-2_asm-test name: assessment-method prose: "Test by requesting delivery of look-up secrets online, and ensure that a minimum of AAL2 authentication is required and that an authenticated protected channel such as TLS is used." - id: LSA-2_gdn name: guidance prose: Applies when look-up secrets are delivered online. - id: LSA-3 title: Look-Up Secret Length props: - value: 3.1.2.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSA-3_smt name: statement prose: "Look-up secrets SHALL be at least six decimal digits (or equivalent) in length. Additional requirements described in Sec. 3.1.2.2 may also apply, depending on their length." - id: LSA-3_obj links: - rel: assessment-for href: "#LSA-3_smt" name: objective prose: Verify that look-up secrets are sufficiently long to provide adequate security. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: LSA-3_asm-examine name: assessment-method prose: Examine look-up secrets received in response to a request and verify that they are at least six decimal digits or equivalent in length. - id: LSV-1 title: Look-Up Secret Prompt props: - value: 3.1.2.2 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-1_smt name: statement prose: Verifiers of look-up secrets SHALL prompt the claimant for a secret from their authenticator. - id: LSV-1_obj links: - rel: assessment-for href: "#LSV-1_smt" name: objective prose: Verify appropriate authentication flow. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: LSV-1_asm-test name: assessment-method prose: Test by authenticating with a look-up secret authenticator and verify the prompt. - id: LSV-2 title: Look-Up Secret Reuse props: - value: 3.1.2.2 B class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-2_smt name: statement prose: A secret from a look-up secret authenticator SHALL be used successfully only once. - id: LSV-2_obj links: - rel: assessment-for href: "#LSV-2_smt" name: objective prose: Ensure that look-up secrets are replay resistant. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: LSV-2_asm-test name: assessment-method prose: Test by attempting to authenticate using the same look-up secret more than once and verify that subsequent attempts are unsuccessful. - id: LSV-3 title: Look-Up Secret Offline Attack Resistance props: - value: 3.1.2.2 C class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-3_smt name: statement prose: Verifiers SHALL store look-up secrets in a form that is resistant to offline attacks. - id: LSV-3_obj links: - rel: assessment-for href: "#LSV-3_smt" name: objective prose: Require strong storage to protect against offline attacks. - props: - value: EXAMINE name: method class: assessment-summary id: LSV-3_asm-summary title: Assessment Method name: assessment-method prose: Requirement is satisfied by LSV-4 and LSV-6 through LSV-8. - id: LSV-4 title: Look-Up Secret Storage props: - value: 3.1.2.2 D class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-4_smt name: statement prose: All lookup secrets SHALL be stored in a hashed form using an approved hashing function. - id: LSV-4_obj links: - rel: assessment-for href: "#LSV-4_smt" name: objective prose: Require use of a hashing function known to be sufficiently secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: LSV-4_asm-examine name: assessment-method prose: Examine code to determine hashing function used. - id: LSV-5 title: Look-Up Secret Verifier Length props: - value: 3.1.2.2 E class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-5_smt name: statement prose: "Look-up secrets SHALL be at least six decimal digits (or equivalent) in length, as specified in Sec. 3.1.2.1." - id: LSV-5_obj links: - rel: assessment-for href: "#LSV-5_smt" name: objective prose: Verify that look-up secrets are sufficiently long to provide adequate security. - props: - value: EXAMINE name: method class: assessment-summary id: LSV-5_asm-summary title: Assessment Method name: assessment-method prose: See LSA-3. - id: LSV-6 title: Look-Up Secret Salted Hashing props: - value: 3.1.2.2 F class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-6_smt name: statement prose: "Look-up secrets that are shorter than the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication) SHALL be stored in a salted and hashed form using a suitable password hashing scheme, as described in Sec. 3.1.1.2." - id: LSV-6_obj links: - rel: assessment-for href: "#LSV-6_smt" name: objective prose: Require salting for look-up secrets that are at risk of collision with other secrets. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: LSV-6_asm-examine name: assessment-method prose: Examine look-up secret verification storage to determine evidence of password hashing and salt storage. - id: LSV-6_gdn name: guidance prose: Applies to look-up secrets shorter than 112 bits. - id: LSV-7 title: Look-Up Secret Salt Length props: - value: 3.1.2.2 G class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-7_smt name: statement prose: The salt value SHALL be at least 32 bits in length and arbitrarily chosen to minimize salt value collisions among stored hashes. - id: LSV-7_obj links: - rel: assessment-for href: "#LSV-7_smt" name: objective prose: Require use of a salt sufficient to ensure that two subscribers with the same look-up secrets do not hash to the same value in the verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: LSV-7_asm-examine name: assessment-method prose: Examine stored salt values to ensure that they are at least 32 bits in length. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: LSV-7_asm-interview name: assessment-method prose: Interview CSP personnel to determine that salt is chosen to avoid collisions. - id: LSV-7_gdn name: guidance prose: Applies to look-up secrets shorter than 112 bits. - id: LSV-8 title: Look-Up Secret Salt Storage props: - value: 3.1.2.2 H class: index name: label - value: Verifier/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-8_smt name: statement prose: Both the salt value and the resulting hash SHALL be stored for each lookup secret. - id: LSV-8_obj links: - rel: assessment-for href: "#LSV-8_smt" name: objective prose: Describes the use of a salt. - props: - value: EXAMINE name: method class: assessment-summary id: LSV-8_asm-summary title: Assessment Method name: assessment-method prose: Requirement is satisfied by verification method of LSV-6. - id: LSV-8_gdn name: guidance prose: Applies to look-up secrets shorter than 112 bits. - id: LSV-9 title: Look-Up Secret Rate Limiting props: - value: 3.1.2.2 I class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-9_smt name: statement prose: "The verifier SHALL implement a rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on the subscriber account, as described in Sec. 3.2.2." - id: LSV-9_obj links: - rel: assessment-for href: "#LSV-9_smt" name: objective prose: Strengthen verifier against online look-up secret guessing attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: LSV-9_asm-test name: assessment-method prose: Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited. - id: LSV-10 title: Look-Up Secret Authenticated Protected Channel props: - value: 3.1.2.2 J class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LSV-10_smt name: statement prose: The verifier SHALL use approved encryption and an authenticated protected channel when requesting look-up secrets. - id: LSV-10_obj links: - rel: assessment-for href: "#LSV-10_smt" name: objective prose: Ensure that online delivery of look-up secrets is sufficiently secure. - props: - value: EXAMINE name: method class: assessment-summary id: LSV-10_asm-summary title: Assessment Method name: assessment-method prose: Requirement is satisfied by LSA-2. - id: OBA-1 title: Out-Of-Band Channel Independence props: - value: 3.1.3.1 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBA-1_smt name: statement prose: The out-of-band authenticator SHALL establish a separate channel with the verifier to retrieve the out-of-band secret or authentication request. - id: OBA-1_obj links: - rel: assessment-for href: "#OBA-1_smt" name: objective prose: Verify that a separate channel is used to communicate with the verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBA-1_asm-test name: assessment-method prose: Test to verify that the secondary channel is established with a separate device or that it is established with an independent application on the authenticating device. - id: OBA-2 title: Out-Of-Band Approved Encryption props: - value: 3.1.3.1 B class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBA-2_smt name: statement prose: Communication over the secondary channel SHALL use approved encryption unless sent via the public switched telephone network (PSTN). - id: OBA-2_obj links: - rel: assessment-for href: "#OBA-2_smt" name: objective prose: Establish that delivery of the out-of-band secret is delivered securely. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBA-2_asm-test name: assessment-method prose: Test by requesting an out-of-band secret and verify that an authenticated protected channel such as TLS is used or that is it delivered via the PSTN. - id: OBA-3 title: Out-Of-Band Email Prohibition props: - value: 3.1.3.1 C class: index name: label - value: CSP/Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBA-3_smt name: statement prose: |- Email SHALL NOT be used for out-of-band authentication because it may be vulnerable to: (a) Access using only a password. (b) Interception in transit or at intermediate mail servers. (c) Rerouting attacks, such as those caused by Domain Name System (DNS) spoofing. - id: OBA-3_obj links: - rel: assessment-for href: "#OBA-3_smt" name: objective prose: Prohibit the use of email for delivery of out-of-band secrets because of multiple security vulnerabilities. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBA-3_asm-test name: assessment-method prose: Test by attempting to authenticate and verify that there is no option to use email for out-of-band authentication. - id: OBA-4 title: Out-Of-Band Communication Methods props: - value: 3.1.3.1 D class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBA-4_smt name: statement prose: |- The out-of-band authenticator SHALL uniquely authenticate itself in one of the following ways when communicating with the verifier: (a) Using approved cryptography, establish a mutually authenticated protected channel (e.g., client-authenticated transport layer security (TLS) [RFC8446]) with the verifier. Communication between the out-of-band authenticator and the verifier MAY use a trusted intermediary service to which each authenticates. The key used to establish the channel SHALL be provisioned in a mutually authenticated session during authenticator binding, as described in Sec. 4.1. (b) Authenticate to a public mobile telephone network using a SIM card or equivalent secret that uniquely identifies the subscriber. This method SHALL only be used if a secret is sent from the verifier to the out-of-band device via the PSTN (i.e., SMS or voice) or an encrypted instant messaging service; use a wired connection to the PSTN that the verifier can call and dictate the out-of-band secret. For the purposes of this definition, "wired connection" includes services such as cable providers that offer PSTN services through other wired media and fiber via analog telephone adapters. - id: OBA-4_obj links: - rel: assessment-for href: "#OBA-4_smt" name: objective prose: Confirm that out-of-band secrets are delivered only to authenticated devices. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: OBA-4_asm-examine name: assessment-method prose: Examine code to verify that one of the specified methods is used to authenticate the device receiving an out-of-band secret. - id: OBA-5 title: Out-Of-Band Secondary Approval props: - value: 3.1.3.1 E class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBA-5_smt name: statement prose: "If the out-of-band authenticator requests approval over the secondary communication channel rather than by presenting a secret that the claimant transfers to the primary communication channel, it SHALL accept a transfer of the secret from the primary channel and send it to the verifier over the secondary channel to associate the approval with the authentication transaction." - id: OBA-5_obj links: - rel: assessment-for href: "#OBA-5_smt" name: objective prose: Ensure that authentication approval over the secondary channel requires transfer of a secret from the primary channel to avoid approval fatigue attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBA-5_asm-test name: assessment-method prose: "Test, if present, secondary channel approval to verify that it requires entry of a secret obtained from the primary channel." - id: OBV-1 title: Out-Of-Band Key Verification props: - value: 3.1.3.2 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-1_smt name: statement prose: "The verifier SHALL NOT store the identifying key itself but SHALL use a verification method (e.g., an approved hash function or proof of possession of the identifying key) to uniquely identify the authenticator." - id: OBV-1_obj links: - rel: assessment-for href: "#OBV-1_smt" name: objective prose: "Ensure that, should the verifier be compromised, any active out-of-band secrets are protected from disclosure." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: OBV-1_asm-examine name: assessment-method prose: Examine verifier storage of out-of-band secrets to verify that they are protected from compromise. - id: OBV-2 title: Out-Of-Band Transfer Methods props: - value: 3.1.3.2 B class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-2_smt name: statement prose: |- Depending on the type of out-of-band authenticator, one of the following SHALL take place: (a) Transfer of the secret from the secondary to the primary channel. As shown in Fig. 1, the verifier MAY signal the device that contains the subscriber's authenticator to indicate a readiness to authenticate. It SHALL then transmit a random secret to the out-of-band authenticator and wait for the secret to be returned via the primary communication channel. (b) Transfer of the secret from the primary to the secondary channel. As shown in Fig. 2, the verifier SHALL transmit a random authentication secret to the claimant via the primary channel. It SHALL then wait for the secret to be returned via the secondary channel from the claimant's out-of-band authenticator. The verifier MAY additionally display an address, such as a phone number or VoIP address, for the claimant to use in addressing its response to the verifier. - id: OBV-2_obj links: - rel: assessment-for href: "#OBV-2_smt" name: objective prose: Ensure that one of the approved authentication flows involving the transfer of a secret from one device or application to another is used. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBV-2_asm-test name: assessment-method prose: Test out-of-band authentication to verify that one of the given authentication flows is used. - id: OBV-3 title: Out-Of-Band Time Limit props: - value: 3.1.3.2 C class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-3_smt name: statement prose: "In all cases, the authentication SHALL be considered invalid unless completed within 10 minutes." - id: OBV-3_obj links: - rel: assessment-for href: "#OBV-3_smt" name: objective prose: Make sure that out-of-band secrets are only valid for the short term. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBV-3_asm-test name: assessment-method prose: Test out-of-band authentication by delaying slightly more than 10 minutes before transferring the secret and verify that authentication is unsuccessful. - id: OBV-4 title: Out-Of-Band Replay Resistance props: - value: 3.1.3.2 D class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-4_smt name: statement prose: "Verifiers SHALL accept a given authentication secret as valid only once during the validity period to provide replay resistance, as described in Sec. 3.2.7." - id: OBV-4_obj links: - rel: assessment-for href: "#OBV-4_smt" name: objective prose: Verify that out-of-band secrets are replay resistant. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBV-4_asm-test name: assessment-method prose: Test by attempting to authenticate and ensure that a given out-of-band secret can be used only once. - id: OBV-5 title: Out-Of-Band Secret Length props: - value: 3.1.3.2 E class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-5_smt name: statement prose: The verifier SHALL generate random authentication secrets that are at least six decimal digits (or equivalent) in length. - id: OBV-5_obj links: - rel: assessment-for href: "#OBV-5_smt" name: objective prose: Verify that out-of-band secrets are sufficiently long to provide adequate security. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: OBV-5_asm-examine name: assessment-method prose: Examine look-up secrets received in response to a request and verify that they are at least six decimal digits or equivalent in length. - id: OBV-5.5 title: Out-Of-Band Secret Generation props: - value: 3.1.3.2 E class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-5.5_smt name: statement prose: The verifier SHALL generate random authentication secrets using an approved random bit generator as described in Sec. 3.2.12. - id: OBV-5.5_obj links: - rel: assessment-for href: "#OBV-5.5_smt" name: objective prose: Require selection of sufficiently random look-up secrets. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: OBV-5.5_asm-examine name: assessment-method prose: Examine code used to generate look-up secrets. - id: OBV-6 title: Out-Of-Band Rate Limiting props: - value: 3.1.3.2 F class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-6_smt name: statement prose: "If the authentication secret is less than 64 bits long, the verifier SHALL implement a rate-limiting mechanism that effectively limits the total number of consecutive failed authentication attempts that can be made on the subscriber account as described in Sec. 3.2.2." - id: OBV-6_obj links: - rel: assessment-for href: "#OBV-6_smt" name: objective prose: Ensure that out-of-band authentication is sufficiently protected against online guessing attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBV-6_asm-test name: assessment-method prose: Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited. - id: OBV-7 title: Out-Of-Band Failure Count props: - value: 3.1.3.2 G class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: OBV-7_smt name: statement prose: Generating a new authentication secret SHALL NOT reset the failed authentication count. - id: OBV-7_obj links: - rel: assessment-for href: "#OBV-7_smt" name: objective prose: Ensure that obtaining a new out-of-band secret does not bypass the rate limiting mechanism. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: OBV-7_asm-test name: assessment-method prose: Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited even if a new authentication secret is obtained. - id: AUPSTN-1 title: Pstn Restricted props: - value: 3.1.3.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUPSTN-1_smt name: statement prose: Use of the PSTN for out-of-band verification is restricted as described in this section and SHALL satisfy the requirements of Sec. 3.2.9. - id: AUPSTN-1_obj links: - rel: assessment-for href: "#AUPSTN-1_smt" name: objective prose: Invoke restricted authenticator provisions. - props: - value: EXAMINE name: method class: assessment-summary id: AUPSTN-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RESTA-1 and RESTA-2. - id: AUPSTN-2 title: Pstn Modification Binding props: - value: 3.1.3.3 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUPSTN-2_smt name: statement prose: Setting or changing the pre-registered telephone number is considered to be the binding of a new authenticator and SHALL only occur as described in Sec. 4.1.2. - id: AUPSTN-2_obj links: - rel: assessment-for href: "#AUPSTN-2_smt" name: objective prose: Defend against attackers who attempt to change the pre-registered telephone number. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AUPSTN-2_asm-test name: assessment-method prose: Test by changing pre-registered telephone number and verify that requirements BAA-2 and BAA-3 are satisfied. - id: AUPSTN-3 title: Pstn Alternatives props: - value: 3.1.3.3 C class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUPSTN-3_smt name: statement prose: Verifiers SHALL ensure that alternative authenticator types are available to all subscribers and SHOULD remind subscribers of this limitation of PSTN out-of-band authenticators before binding one or more devices controlled by the subscriber. - id: AUPSTN-3_obj links: - rel: assessment-for href: "#AUPSTN-3_smt" name: objective prose: Ensure that subscribers understand the risks associated with PSTN out-of-band authentication. - props: - value: EXAMINE name: method class: assessment-summary id: AUPSTN-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RESTA-2. - id: MFOBA-1 title: MF-OOB Activation props: - value: 3.1.3.4 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MFOBA-1_smt name: statement prose: Each use of the authenticator SHALL require the presentation of the activation factor. - id: MFOBA-1_obj links: - rel: assessment-for href: "#MFOBA-1_smt" name: objective prose: Ensure that a previously activated authenticator cannot be coopted by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: MFOBA-1_asm-test name: assessment-method prose: Test by authenticating more than once with the same authenticator and verify that the activation factor is required each time. Also satisfied by MFOBA-4. - id: MFOBA-2 title: MF-OOB Activation Secrets props: - value: 3.1.3.4 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MFOBA-2_smt name: statement prose: Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10. - id: MFOBA-2_obj links: - rel: assessment-for href: "#MFOBA-2_smt" name: objective prose: Invoke requirements for activation secrets. - props: - value: EXAMINE name: method class: assessment-summary id: MFOBA-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AS-1 through AS-8. - id: MFOBA-3 title: MF-OOB Biometric Requirements props: - value: 3.1.3.4 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MFOBA-3_smt name: statement prose: "A biometric activation factor SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures." - id: MFOBA-3_obj links: - rel: assessment-for href: "#MFOBA-3_smt" name: objective prose: Invoke requirements for biometric authentication factors. - props: - value: EXAMINE name: method class: assessment-summary id: MFOBA-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by UB-1 through UB-4. - id: MFOBA-4 title: MF-OOB Activation Erasure props: - value: 3.1.3.4 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MFOBA-4_smt name: statement prose: "The password or biometric sample used for activation and any biometric data derived from the biometric sample (e.g., a fingerprint image and feature locations produced by a fingerprint feature extractor) SHALL be erased immediately after an authentication operation." - id: MFOBA-4_obj links: - rel: assessment-for href: "#MFOBA-4_smt" name: objective prose: Ensure that the activation factor cannot be used or extracted following an authentication operation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOBA-4_asm-examine name: assessment-method prose: Examine code to establish that activation factor is erased as required. - id: SFOA-1 title: OTP Generation Key Strength props: - value: 3.1.4.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOA-1_smt name: statement prose: "The secret key and its algorithm SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication)." - id: SFOA-1_obj links: - rel: assessment-for href: "#SFOA-1_smt" name: objective prose: Ensure that the key used to generate the OTP is of sufficient size to be secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFOA-1_asm-examine name: assessment-method prose: Examine code to determine the security strength of the key used to generate the OTP. - id: SFOA-2 title: OTP Nonce Length props: - value: 3.1.4.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOA-2_smt name: statement prose: The nonce SHALL be of sufficient length to ensure that it is unique for each operation of the authenticator over its lifetime. - id: SFOA-2_obj links: - rel: assessment-for href: "#SFOA-2_smt" name: objective prose: Ensure that the nonce is large enough that the OTP sequence doesn't repeat. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFOA-2_asm-examine name: assessment-method prose: Examine code to determine if the nonce is sufficiently long to not repeat during the expected lifetime of the authenticator. - id: SFOA-3 title: TOTP Change Frequency props: - value: 3.1.4.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOA-3_smt name: statement prose: "If the nonce used to generate the authenticator output is based on a real-time clock, the nonce SHALL be changed at least once every two minutes." - id: SFOA-3_obj links: - rel: assessment-for href: "#SFOA-3_smt" name: objective prose: Ensure that the nonce of a time-based OTP changes frequently enough. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SFOA-3_asm-test name: assessment-method prose: Test to determine that the OTP changes at least once every two minutes. - id: SFOA-3_gdn name: guidance prose: Applies to time-based OTP authenticators. - id: SFOV-1 title: OTP Verifier Key Protection props: - value: 3.1.3.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOV-1_smt name: statement prose: The symmetric keys used by authenticators are also present in the verifier and SHALL be strongly protected against unauthorized disclosure by access controls that limit access to the keys to only those software components that require access. - id: SFOV-1_obj links: - rel: assessment-for href: "#SFOV-1_smt" name: objective prose: Protect against attacks on verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFOV-1_asm-examine name: assessment-method prose: Examine storage of OTP generation keys to determine whether they are strongly protected. - id: SFOV-2 title: OTP Key Establishment props: - value: 3.1.4.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOV-2_smt name: statement prose: "When binding a single-factor OTP authenticator to a subscriber account, the verifier or associated CSP SHALL use approved cryptography for key establishment to generate and exchange keys or to obtain the secrets required to duplicate the authenticator output." - id: SFOV-2_obj links: - rel: assessment-for href: "#SFOV-2_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFOV-2_asm-examine name: assessment-method prose: Examine code or documentation showing the algorithms being used and verify that they are NIST approved. - id: SFOV-3 title: OTP Authenticated Protected Channels props: - value: 3.1.4.2 C class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOV-3_smt name: statement prose: The verifier SHALL use approved encryption and an authenticated protected channel when collecting the OTP. - id: SFOV-3_obj links: - rel: assessment-for href: "#SFOV-3_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms and protocols are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFOV-3_asm-examine name: assessment-method prose: Examine documented policies or code to determine that only approved cryptographic algorithms can be used. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFOV-3_asm-examine-2 name: assessment-method prose: Examine secure use of a protocol such as TLS for communication with the claimant. - id: SFOV-4 title: OTP Replay Protection props: - value: 3.1.4.2 D class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOV-4_smt name: statement prose: "Verifiers SHALL accept a given OTP only once while it is valid to provide replay resistance, as described in Sec. 3.2.7." - id: SFOV-4_obj links: - rel: assessment-for href: "#SFOV-4_smt" name: objective prose: Ensure that OTP use is replay resistant. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SFOV-4_asm-test name: assessment-method prose: Test to ensure that it is not possible to successfully use the same OTP value for two different authentication transactions while it is valid. - id: SFOV-5 title: TOTP Key Lifetime props: - value: 3.1.4.2 E class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOV-5_smt name: statement prose: "Time-based OTPs [TOTP] SHALL have a defined lifetime that is determined by the expected clock drift in either direction of the authenticator over its lifetime plus an allowance for network delay and claimant entry of the OTP." - id: SFOV-5_obj links: - rel: assessment-for href: "#SFOV-5_smt" name: objective prose: Ensure that OTP will not fail prematurely due to clock drift. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFOV-5_asm-examine name: assessment-method prose: Examine specifications for authenticator clock drift and planned lifetime and ensure that time tolerance of OTP entry is sufficiently long. - id: SFOV-5_gdn name: guidance prose: Applies to time-based OTP authenticators. - id: SFOV-6 title: OTP Rate Limiting props: - value: 3.1.4.2 F class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFOV-6_smt name: statement prose: "The verifier SHOULD implement or, if the authenticator output is less than 64 bits in length, SHALL implement a rate-limiting mechanism that effectively limits the number of failed authentication attempts that can be made on the subscriber account, as described in Sec. 3.2.2." - id: SFOV-6_obj links: - rel: assessment-for href: "#SFOV-6_smt" name: objective prose: Protect against OTP guessing attacks - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SFOV-6_asm-test name: assessment-method prose: Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited. - id: SFOV-6_gdn name: guidance prose: Applies when authenticator output if less than 64 bits in length. - id: MFOA-1 title: MF-OTP Activation props: - value: 3.1.5.1 A class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOA-1_smt name: statement prose: Each use of the authenticator SHALL require the input of the activation factor. - id: MFOA-1_obj links: - rel: assessment-for href: "#MFOA-1_smt" name: objective prose: Ensure that all use of the authenticator is protected by the activation factor. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: MFOA-1_asm-test name: assessment-method prose: Test by attempting to authenticate and verify that the activation factor is needed for each authentication. - id: MFOA-2 title: MF-OTP Generation Key Strength props: - value: 3.1.5.1 B class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOA-2_smt name: statement prose: "The secret key and its algorithm SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication)." - id: MFOA-2_obj links: - rel: assessment-for href: "#MFOA-2_smt" name: objective prose: Ensure that the key used to generate the OTP is of sufficient size to be secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOA-2_asm-examine name: assessment-method prose: Examine code to determine the security strength of the key used to generate the OTP. - id: MFOA-3 title: MF-OTP Nonce Length props: - value: 3.1.5.1 C class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOA-3_smt name: statement prose: The nonce SHALL be of sufficient length to ensure that it is unique for each operation of the authenticator over its lifetime. - id: MFOA-3_obj links: - rel: assessment-for href: "#MFOA-3_smt" name: objective prose: Ensure that the nonce is large enough that the OTP sequence doesn't repeat. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOA-3_asm-examine name: assessment-method prose: Examine code to determine if the nonce is sufficiently long to not repeat during the expected lifetime of the authenticator. - id: MFOA-4 title: MF-TOTP Change Frequency props: - value: 3.1.5.1 D class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOA-4_smt name: statement prose: "If the nonce used to generate the authenticator output is based on a real-time clock, the nonce SHALL be changed at least once every two minutes." - id: MFOA-4_obj links: - rel: assessment-for href: "#MFOA-4_smt" name: objective prose: Ensure that the nonce of a time-based OTP changes frequently enough. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: MFOA-4_asm-test name: assessment-method prose: Test to determine that the OTP changes at least once every two minutes. - id: MFOA-4_gdn name: guidance prose: Applies to time-based OTP authenticators. - id: MFOA-5 title: MF-OTP Activation Secrets props: - value: 3.1.5.1 E class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOA-5_smt name: statement prose: Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10. - id: MFOA-5_obj links: - rel: assessment-for href: "#MFOA-5_smt" name: objective prose: Invoke requirements for activation secrets. - props: - value: EXAMINE name: method class: assessment-summary id: MFOA-5_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AS-1 through AS-8. - id: MFOA-5_gdn name: guidance prose: Authenticator uses activation secrets. - id: MFOA-6 title: MF-OTP Biometric Requirements props: - value: 3.1.5.1 F class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOA-6_smt name: statement prose: "A biometric activation factor SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures." - id: MFOA-6_obj links: - rel: assessment-for href: "#MFOA-6_smt" name: objective prose: Invoke requirements for biometric authentication factors. - props: - value: EXAMINE name: method class: assessment-summary id: MFOA-6_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by UB-1 through UB-4. - id: MFOA-6_gdn name: guidance prose: Authenticator uses biometric activation. - id: MFOA-7 title: MF-OTP Activation Erasure props: - value: 3.1.5.1 G class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOA-7_smt name: statement prose: "The unencrypted key and activation secret or biometric sample and any biometric data derived from the biometric sample (e.g., a fingerprint image and feature locations produced by a fingerprint feature extractor) SHALL be erased immediately after an OTP has been generated." - id: MFOA-7_obj links: - rel: assessment-for href: "#MFOA-7_smt" name: objective prose: Ensure that the activation factor cannot be used or extracted following an authentication operation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOA-7_asm-examine name: assessment-method prose: Examine code to establish that activation factor is erased as required. - id: MFOV-1 title: MF-OTP Verifier Key Protection props: - value: 3.1.5.2 A class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOV-1_smt name: statement prose: The symmetric keys used by authenticators SHALL be strongly protected against unauthorized disclosure by access controls that limit access to the keys to only those software components that require access. - id: MFOV-1_obj links: - rel: assessment-for href: "#MFOV-1_smt" name: objective prose: Protect against attacks on verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOV-1_asm-examine name: assessment-method prose: Examine storage of OTP generation keys to determine whether they are strongly protected. - id: MFOV-2 title: MF-OTP Key Establishment props: - value: 3.1.5.2 B class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOV-2_smt name: statement prose: "When binding a multi-factor OTP authenticator to a subscriber account, the verifier or associated CSP SHALL use approved cryptography for key establishment to generate and exchange keys or to obtain the secrets required to duplicate the authenticator output." - id: MFOV-2_obj links: - rel: assessment-for href: "#MFOV-2_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOV-2_asm-examine name: assessment-method prose: Examine code or documentation showing the algorithms being used and verify that they are NIST approved. - id: MFOV-3 title: MF-OTP Authenticated Protected Channels props: - value: 3.1.5.2 C class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOV-3_smt name: statement prose: The verifier SHALL use approved encryption and an authenticated protected channel when collecting the OTP. - id: MFOV-3_obj links: - rel: assessment-for href: "#MFOV-3_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms and protocols are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOV-3_asm-examine name: assessment-method prose: Examine documented policies or code to determine that only approved cryptographic algorithms can be used. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOV-3_asm-examine-2 name: assessment-method prose: Examine secure use of a protocol such as TLS for communication with the claimant. - id: MFOV-4 title: MF-OTP Replay Protection props: - value: 3.1.5.2 D class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOV-4_smt name: statement prose: "Verifiers SHALL accept a given OTP only once while it is valid to provide replay resistance, as described in Sec. 3.2.7." - id: MFOV-4_obj links: - rel: assessment-for href: "#MFOV-4_smt" name: objective prose: Ensure that OTP use is replay resistant. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: MFOV-4_asm-test name: assessment-method prose: Test to ensure that it is not possible to successfully use the same OTP value for two different authentication transactions while it is valid. - id: MFOV-5 title: MF-TOTP Key Lifetime props: - value: 3.1.5.2 E class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOV-5_smt name: statement prose: "Time-based OTPs [TOTP] SHALL have a defined lifetime that is determined by the expected clock drift in either direction of the authenticator over its lifetime plus an allowance for network delay and claimant entry of the OTP." - id: MFOV-5_obj links: - rel: assessment-for href: "#MFOV-5_smt" name: objective prose: Ensure that OTP will not fail prematurely due to clock drift. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFOV-5_asm-examine name: assessment-method prose: Examine specifications for authenticator clock drift and planned lifetime and ensure that time tolerance of OTP entry is sufficiently long. - id: MFOV-6 title: MF-OTP Rate Limiting props: - value: 3.1.5.2 F class: index name: label - value: Verifier class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFOV-6_smt name: statement prose: "The verifier SHALL implement a rate-limiting mechanism that effectively limits the number of consecutive failed authentication attempts that can be made on the subscriber account, as required by Sec. 3.2.10." - id: MFOV-6_obj links: - rel: assessment-for href: "#MFOV-6_smt" name: objective prose: Protect against OTP guessing attacks - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: MFOV-6_asm-test name: assessment-method prose: Test by making a large number of incorrect authentication attempts and ensure that number and/or rate of attempts is limited. - id: SFCATION-1 title: SF Crypto Public Key props: - value: 3.1.6 A class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: SFCATION-1_smt name: statement prose: Single-factor cryptographic authenticators used at AAL3 SHALL use public-key cryptography to protect the authentication secrets from compromise of the verifier. - id: SFCATION-1_obj links: - rel: assessment-for href: "#SFCATION-1_smt" name: objective prose: Avoid the use of shared authentication secrets that could be compromised by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFCATION-1_asm-examine name: assessment-method prose: Examine documentation of verifiers to determine that they only store public keys for cryptographic authenticators - id: SFCATORS-1 title: SF Exportable Authentication Key Protection props: - value: 3.1.6.1 A class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: SFCATORS-1_smt name: statement prose: "If they are accessible to the endpoint being authenticated, exportable authentication keys SHALL be strongly protected against unauthorized disclosure with access controls that limit access to the key to only those software components that require access." - id: SFCATORS-1_obj links: - rel: assessment-for href: "#SFCATORS-1_smt" name: objective prose: Protect against attacks on authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFCATORS-1_asm-examine name: assessment-method prose: Examine storage of authentication keys to determine whether they are strongly protected. - id: SFCATORS-1_gdn name: guidance prose: Applies to exportable authentication keys. - id: SFCATORS-2 title: SF Non-Exportable Authentication Key Storage props: - value: 3.1.6.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFCATORS-2_smt name: statement prose: Nonexportable authentication keys (usable at AAL3 or below) SHALL be stored in an isolated execution environment that is protected by hardware or in a separate processor with a controlled interface to the central processing unit of the user endpoint. - id: SFCATORS-2_obj links: - rel: assessment-for href: "#SFCATORS-2_smt" name: objective prose: Protect against attacks on authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFCATORS-2_asm-examine name: assessment-method prose: Examine storage of authentication keys to determine whether they are stored in an isolated execution environment. - id: SFCATORS-2_gdn name: guidance prose: Applies to non-exportable authentication keys. - id: SFCATORS-3 title: SF External Authentication Key Requirements props: - value: 3.1.6.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFCATORS-3_smt name: statement prose: "External (i.e., non-embedded) cryptographic authenticators SHALL meet the requirements for connected authenticators in Sec. 3.2.11." - id: SFCATORS-3_obj links: - rel: assessment-for href: "#SFCATORS-3_smt" name: objective prose: Ensure integrity of endpoint-authenticator connection. - props: - value: EXAMINE name: method class: assessment-summary id: SFCATORS-3_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by CONNAUTH-1 through CONNAUTH-3, and if wireless, WC-1 through WC-7." - id: SFCATORS-3_gdn name: guidance prose: Applies to non-embedded cryptographic authenticators. - id: SFCVER-1 title: Cryptographic Verifier Symmetric Key Protection props: - value: 3.1.6.2 A class: index name: label - value: CSP/Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFCVER-1_smt name: statement prose: "While both types of keys SHALL be protected against modification, symmetric keys SHALL additionally be protected against unauthorized disclosure by access controls that limit access to the key to only those software components that require access." - id: SFCVER-1_obj links: - rel: assessment-for href: "#SFCVER-1_smt" name: objective prose: Protect against attacks on verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFCVER-1_asm-examine name: assessment-method prose: Examine storage of authentication keys to determine whether they are strongly protected. - id: SFCVER-1_gdn name: guidance prose: Applies when symmetric authentication keys are used. - id: SFCVER-2 title: Cryptographic Authentication Key Strength props: - value: 3.1.6.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFCVER-2_smt name: statement prose: "The authentication key and its algorithm SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication)." - id: SFCVER-2_obj links: - rel: assessment-for href: "#SFCVER-2_smt" name: objective prose: Ensure that the authentication key is of sufficient size to be secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFCVER-2_asm-examine name: assessment-method prose: Examine code to determine the security strength of the authentication key. - id: SFCVER-3 title: Cryptographic Nonce Length props: - value: 3.1.6.2 C class: index name: label - value: CSP/Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFCVER-3_smt name: statement prose: "The challenge nonce SHALL be at least 64 bits in length and SHALL either be unique over the authenticator's lifetime or statistically unique (i.e., generated using an approved random bit generator, as described in Sec. 3.2.12)." - id: SFCVER-3_obj links: - rel: assessment-for href: "#SFCVER-3_smt" name: objective prose: Provide strong protection against replay attacks. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFCVER-3_asm-examine name: assessment-method prose: Examine code used to generate the authentication nonce. - id: SFCVER-4 title: Cryptographic Verifier Approved Cryptography props: - value: 3.1.6.2 D class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SFCVER-4_smt name: statement prose: The verification operation SHALL use approved cryptography. - id: SFCVER-4_obj links: - rel: assessment-for href: "#SFCVER-4_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms and protocols are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SFCVER-4_asm-examine name: assessment-method prose: Examine documented policies or code to determine that only approved cryptographic algorithms can be used. - id: MFCTION-1 title: MF Crypto Public Key props: - value: 3.1.7 A class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: MFCTION-1_smt name: statement prose: Multi-factor cryptographic authenticators used at AAL3 SHALL use public-key cryptography to protect the authentication secrets from compromise of the verifier. - id: MFCTION-1_obj links: - rel: assessment-for href: "#MFCTION-1_smt" name: objective prose: Avoid the use of shared authentication secrets that could be compromised by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFCTION-1_asm-examine name: assessment-method prose: Examine documentation of verifiers to determine that they only store public keys for cryptographic authenticators. - id: MFCTORS-1 title: MF Crypto Authenticator Activation Required props: - value: 3.1.7.1 A class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: MFCTORS-1_smt name: statement prose: "Multi-factor cryptographic authenticators encapsulate one or more authentication keys that SHALL only be accessible through the presentation and verification of an activation factor (i.e., a password or a biometric characteristic)." - id: MFCTORS-1_obj links: - rel: assessment-for href: "#MFCTORS-1_smt" name: objective prose: Ensure that authenticator enforces use of an activation factor. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFCTORS-1_asm-examine name: assessment-method prose: Examine storage of authentication secret to determine that the secret is only accessible upon presentation of a valid activation factor. - id: MFCTORS-2 title: MF Non-Exportable Authentication Key Storage props: - value: 3.1.7.1 B class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: MFCTORS-2_smt name: statement prose: "Non-exportable authentication keys, suitable for use at AAL3, SHALL be stored in an isolated execution environment that is protected by hardware or in a separate processor with a controlled interface to the central processing unit of the user endpoint." - id: MFCTORS-2_obj links: - rel: assessment-for href: "#MFCTORS-2_smt" name: objective prose: Protect against attacks on authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFCTORS-2_asm-examine name: assessment-method prose: Examine storage of authentication keys to determine whether they are stored in an isolated execution environment. - id: MFCTORS-2_gdn name: guidance prose: Applies to non-exportable authentication keys. - id: MFCTORS-3 title: MF Exportable Authentication Key Protection props: - value: 3.1.7.1 C class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: MFCTORS-3_smt name: statement prose: "If accessible to the endpoint being authenticated, authentication keys SHALL be strongly protected against unauthorized disclosure by using access controls that limit access to the authentication keys to only those software components that require access." - id: MFCTORS-3_obj links: - rel: assessment-for href: "#MFCTORS-3_smt" name: objective prose: Protect against attacks on authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFCTORS-3_asm-examine name: assessment-method prose: Examine storage of authentication keys to determine whether they are strongly protected. - id: MFCTORS-3_gdn name: guidance prose: Applies to exportable authentication keys. - id: MFCTORS-4 title: MF External Authentication Key Requirements props: - value: 3.1.7.1 D class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: MFCTORS-4_smt name: statement prose: External (non-embedded) cryptographic authenticators SHALL meet the requirements for connected authenticators in Sec. 3.2.11. - id: MFCTORS-4_obj links: - rel: assessment-for href: "#MFCTORS-4_smt" name: objective prose: Ensure integrity of endpoint-authenticator connection. - props: - value: EXAMINE name: method class: assessment-summary id: MFCTORS-4_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by CONNAUTH-1 through CONNAUTH-3, and if wireless, WC-1 through WC-7." - id: MFCTORS-4_gdn name: guidance prose: Applies to non-embedded cryptographic authenticators. - id: MFCTORS-5 title: MF Crypto Activation props: - value: 3.1.7.1 E class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: MFCTORS-5_smt name: statement prose: Each authentication event SHALL require input and verification of the local activation factor. - id: MFCTORS-5_obj links: - rel: assessment-for href: "#MFCTORS-5_smt" name: objective prose: Ensure that a previously activated authenticator cannot be coopted by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: MFCTORS-5_asm-test name: assessment-method prose: Test by authenticating more than once with the same authenticator and verify that the activation factor is required each time. - id: MFCTORS-6 title: MF Crypto Activation Secrets props: - value: 3.1.7.1 F class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: MFCTORS-6_smt name: statement prose: Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10. - id: MFCTORS-6_obj links: - rel: assessment-for href: "#MFCTORS-6_smt" name: objective prose: Invoke requirements for activation secrets. - props: - value: EXAMINE name: method class: assessment-summary id: MFCTORS-6_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AS-1 through AS-8. - id: MFCTORS-6_gdn name: guidance prose: Authenticator uses activation secrets. - id: MFCTORS-7 title: MF Crypto Biometric Requirements props: - value: 3.1.7.1 G class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: MFCTORS-7_smt name: statement prose: "A biometric activation factor SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures." - id: MFCTORS-7_obj links: - rel: assessment-for href: "#MFCTORS-7_smt" name: objective prose: Invoke requirements for biometric authentication factors. - props: - value: EXAMINE name: method class: assessment-summary id: MFCTORS-7_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by UB-1 through UB-4. - id: MFCTORS-7_gdn name: guidance prose: Authenticator uses biometric activation. - id: MFCTORS-8 title: MF Crypto Activation Erasure props: - value: 3.1.7.1 H class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: MFCTORS-8_smt name: statement prose: "The activation secret or biometric sample and any biometric data derived from the biometric sample (e.g., a fingerprint image and feature locations produced by a fingerprint feature extractor) SHALL be erased after an authentication transaction." - id: MFCTORS-8_obj links: - rel: assessment-for href: "#MFCTORS-8_smt" name: objective prose: Ensure that the activation factor cannot be used or extracted following an authentication operation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFCTORS-8_asm-examine name: assessment-method prose: Examine code to establish that activation factor is erased as required. - id: MFCFIERS-0.5 title: MF Crypto Verifier Requirements props: - value: 3.1.7.2 class: index name: label - value: CSP/Verifier class: target name: marking - value: AAL2/AAl3 class: xal-level name: marking parts: - id: MFCFIERS-0.5_smt name: statement prose: Requirements for a multi-factor cryptographic verifier are identical to those for a single-factor cryptographic verifier. - id: MFCFIERS-0.5_obj links: - rel: assessment-for href: "#MFCFIERS-0.5_smt" name: objective prose: Ensure baseline requirements for cryptographic verifiers are met. - props: - value: EXAMINE name: method class: assessment-summary id: MFCFIERS-0.5_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SFCVER-1 through SFCVER-4 - id: MFCFIERS-1 title: MF Crypto Activation Flag props: - value: 3.1.7.2 A class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: MFCFIERS-1_smt name: statement prose: "If a flag indicating use of an activation factor is present and indicates that an activation factor was not used, the authentication SHALL be treated as single-factor." - id: MFCFIERS-1_obj links: - rel: assessment-for href: "#MFCFIERS-1_smt" name: objective prose: Ensure that an activation factor was used if indication was provided. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MFCFIERS-1_asm-examine name: assessment-method prose: "Examine code to determine if the activation factor flag is checked and heeded, if provided." - id: UWSCW-1 title: Wallet Activation Required props: - value: 3.1.7.3 A class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UWSCW-1_smt name: statement prose: Access to the private key SHALL require an activation factor. - id: UWSCW-1_obj links: - rel: assessment-for href: "#UWSCW-1_smt" name: objective prose: Ensure that authenticator enforces use of an activation factor. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UWSCW-1_asm-examine name: assessment-method prose: Examine storage of authentication secret to determine that the secret is only accessible upon presentation of a valid activation factor. - id: UWSCW-2 title: Wallet Activation Secrets props: - value: 3.1.7.3 B class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UWSCW-2_smt name: statement prose: Authenticator activation secrets SHALL meet the requirements of Sec. 3.2.10. - id: UWSCW-2_obj links: - rel: assessment-for href: "#UWSCW-2_smt" name: objective prose: Invoke requirements for activation secrets. - props: - value: EXAMINE name: method class: assessment-summary id: UWSCW-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AS-1 through AS-8. - id: UWSCW-2_gdn name: guidance prose: Authenticator uses activation secrets. - id: UWSCW-3 title: Wallet Biometric Requirements props: - value: 3.1.7.3 C class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UWSCW-3_smt name: statement prose: "Biometric activation factors SHALL meet the requirements of Sec. 3.2.3, including limits on the number of consecutive authentication failures." - id: UWSCW-3_obj links: - rel: assessment-for href: "#UWSCW-3_smt" name: objective prose: Invoke requirements for biometric authentication factors. - props: - value: EXAMINE name: method class: assessment-summary id: UWSCW-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by UB-1 through UB-4. - id: UWSCW-3_gdn name: guidance prose: Authenticator uses biometric activation. - id: UWSCW-4 title: Wallet Activation Erasure props: - value: 3.1.7.3 D class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UWSCW-4_smt name: statement prose: The password or biometric sample used for activation and any biometric data derived from the biometric sample SHALL be erased immediately after an authentication transaction. - id: UWSCW-4_obj links: - rel: assessment-for href: "#UWSCW-4_smt" name: objective prose: Ensure that the activation factor cannot be used or extracted following an authentication operation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UWSCW-4_asm-examine name: assessment-method prose: Examine code to establish that activation factor is erased as required. - id: UWSCW-5 title: Wallet Federation props: - value: 3.1.7.3 E class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UWSCW-5_smt name: statement prose: "Authentication processes using subscriber-controlled wallets SHALL be used with a federation process as detailed in Sec. 5 of [SP800-63C]." - id: UWSCW-5_obj links: - rel: assessment-for href: "#UWSCW-5_smt" name: objective prose: Ensure that subscriber-controlled wallets are used in connection with federation requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UWSCW-5_asm-examine name: assessment-method prose: Examine federation process and verify compliance with requirements in Section 5 of SP 800-63C - id: UWSCW-6 title: Wallet Phishing-Resistance Conditions props: - value: 3.1.7.3 F class: index name: label - value: RP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UWSCW-6_smt name: statement prose: Assertions that lack a valid signature from the wallet or an audience restriction SHALL NOT be considered phishing-resistant. - id: UWSCW-6_obj links: - rel: assessment-for href: "#UWSCW-6_smt" name: objective prose: Ensure that wallets satisfy applications requiring phishing resistance. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UWSCW-6_asm-examine name: assessment-method prose: Examine assertions or code generating them to determine if valid signatures or audience restrictions are present. - id: UWSCW-7 title: Wallet Activation Information props: - value: 3.1.7.3 G class: index name: label - value: IdP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UWSCW-7_smt name: statement prose: Assertions SHALL also include sufficient information to determine the nature of the activation method used to activate the wallet. - id: UWSCW-7_obj links: - rel: assessment-for href: "#UWSCW-7_smt" name: objective prose: Ensure that activation information is provided to relying parties. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UWSCW-7_asm-examine name: assessment-method prose: Examine assertions or code generating them to determine if the activation method is included. - id: PHYSA-1 title: Physical Authenticator Instructions props: - value: 3.2.1 A class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: PHYSA-1_smt name: statement prose: CSPs SHALL provide subscriber instructions for appropriately protecting the authenticator against theft or loss. - id: PHYSA-1_obj links: - rel: assessment-for href: "#PHYSA-1_smt" name: objective prose: Ensure that subscribers understand their responsibilities for protecting authenticators. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PHYSA-1_asm-test name: assessment-method prose: Test by establishing a new subscriber account and observe whether sufficient instructions are provided. - id: PHYSA-2 title: Physical Authenticator Invalidation props: - value: 3.2.1 B class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: PHYSA-2_smt name: statement prose: "The CSP SHALL provide a mechanism to invalidate the authenticator immediately upon notification from a subscriber that the authenticator's loss, theft, or compromise is suspected." - id: PHYSA-2_obj links: - rel: assessment-for href: "#PHYSA-2_smt" name: objective prose: Ensure that subscribers have a meaningful way to report authenticator issues and that appropriate action is taken. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PHYSA-2_asm-test name: assessment-method prose: Test by simulating the loss of an authenticator and determine whether instructions are provided to the subscriber to handle this situation and that appropriate action is taken when reported. - id: RL-1 title: Rate Limiting Requirement props: - value: 3.2.2 A class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: RL-1_smt name: statement prose: "When required by the authenticator type descriptions in Sec. 3.1, the verifier SHALL implement controls to protect against online guessing attacks." - id: RL-1_obj links: - rel: assessment-for href: "#RL-1_smt" name: objective prose: Control online guessing attacks. - props: - value: EXAMINE name: method class: assessment-summary id: RL-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RL-2 through RL-6 - id: RL-2 title: Rate Limiting Upper Bound props: - value: 3.2.2 B class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: RL-2_smt name: statement prose: "Unless otherwise specified in the description of a given authenticator, the verifier SHALL limit consecutive failed authentication attempts using a specific authenticator on a single subscriber account to no more than 100 by disabling that authenticator." - id: RL-2_obj links: - rel: assessment-for href: "#RL-2_smt" name: objective prose: Set overall upper limit on consecutive failed authentication attempts. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RL-2_asm-test name: assessment-method prose: Test by making 101 authentication failures with an authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RL-2_asm-examine name: assessment-method prose: Examine subscriber account to verify that the authenticator has been disabled. - id: RL-3 title: Rate Limiting Authenticator Association props: - value: 3.2.2 C class: index name: label - value: CSP/Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: RL-3_smt name: statement prose: "If more than one authenticator is involved with an excessive number of authentication attempts (e.g., single-factor cryptographic authenticator and centrally verified password), both authenticators SHALL be disabled." - id: RL-3_obj links: - rel: assessment-for href: "#RL-3_smt" name: objective prose: Address excessive authentication failures involving more than one authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RL-3_asm-test name: assessment-method prose: Test by making excessive authentication failures with two authenticators. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RL-3_asm-examine name: assessment-method prose: Examine subscriber account to verify that both authenticators have been disabled. - id: RL-4 title: Rate Limiting Rebinding props: - value: 3.2.2 D class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: RL-4_smt name: statement prose: "Authenticators that have been disabled SHALL be required to rebind to the subscriber account, as described in Sec. 4.1, to be usable in the future." - id: RL-4_obj links: - rel: assessment-for href: "#RL-4_smt" name: objective prose: Ensure that disabled authenticators are treated as unbound to the subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RL-4_asm-test name: assessment-method prose: Test by causing an authenticator to be disabled due to excessive authentication failures and verify that there is no way to successfully use the authenticator other than to go through the authenticator binding procedure. - id: RL-5 title: Rate Limiting AAL Limitation props: - value: 3.2.2 E class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: RL-5_smt name: statement prose: "If the retry count of an authenticator is reset following a successful authentication, the maximum AAL of the authenticator being reset SHALL not exceed the AAL of the session from which it is being reset." - id: RL-5_obj links: - rel: assessment-for href: "#RL-5_smt" name: objective prose: Prevent AAL escalation due to authenticator retry count reset. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RL-5_asm-test name: assessment-method prose: Test by authenticating unsuccessfully and then successfully with a given authenticator and examine the maximum AAL at which it can be used to verify that it does not increase. - id: RL-5_gdn name: guidance prose: Applies to verifiers that reset the unsuccessful authentication count after successful authentication. - id: RL-6 title: Rate Limiting Recovery Requirement props: - value: 3.2.2 F class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: RL-6_smt name: statement prose: "If the subscriber cannot authenticate at the required AAL, the account recovery procedures in Sec. 4.2 SHALL be used." - id: RL-6_obj links: - rel: assessment-for href: "#RL-6_smt" name: objective prose: Require account recovery in the event that authenticator rebinding is unavailable. - props: - value: EXAMINE name: method class: assessment-summary id: RL-6_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by section 4.2 compliance - id: UB-1 title: Biometrics Applicability props: - value: 3.2.3 A class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UB-1_smt name: statement prose: "Biometrics SHALL only be used as part of multi-factor authentication with a physical authenticator (i.e., \"something you have\")." - id: UB-1_obj links: - rel: assessment-for href: "#UB-1_smt" name: objective prose: Block use of biometric comparison as a single factor or with only a password. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: UB-1_asm-test name: assessment-method prose: Test available authentication methods to ensure that all require a physical authenticator. - id: UB-2 title: Biometrics Not Cached props: - value: 3.2.3 B class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UB-2_smt name: statement prose: The biometric characteristic SHALL be presented and compared for each authentication operation. - id: UB-2_obj links: - rel: assessment-for href: "#UB-2_smt" name: objective prose: Do not allow biometric characteristics to be cached. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: UB-2_asm-test name: assessment-method prose: Test by making multiple authentications using biometric comparison and verify that the biometric characteristic is required to be presented each time. - id: UB-3 title: Biometrics Alternatives props: - value: 3.2.3 C class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UB-3_smt name: statement prose: An alternative nonbiometric authentication option SHALL always be provided to the subscriber. - id: UB-3_obj links: - rel: assessment-for href: "#UB-3_smt" name: objective prose: Require alternatives in the event that a biometric characteristic cannot be presented for some reason. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: UB-3_asm-test name: assessment-method prose: Test available authentication methods to ensure that an alternative to biometric comparison is always available. - id: UB-4 title: Biometrics Sensitivity props: - value: 3.2.3 D class: index name: label - value: Verifier/CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UB-4_smt name: statement prose: Biometric data SHALL be treated and secured as sensitive personal information. - id: UB-4_obj links: - rel: assessment-for href: "#UB-4_smt" name: objective prose: Ensure that biometric data is sufficiently protected. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UB-4_asm-examine name: assessment-method prose: Examine storage of biometric data and evaluate access controls for that data. - id: BA-1 title: Biometric FMR props: - value: 3.2.3.1 A class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: BA-1_smt name: statement prose: "The biometric system SHALL operate with an FMR [ISO/IEC2382-37] of one in 10000 or better for all demographic groups." - id: BA-1_obj links: - rel: assessment-for href: "#BA-1_smt" name: objective prose: Ensure biometric comparison is sufficiently secure against false matches. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BA-1_asm-examine name: assessment-method prose: Examine test results or certifications for biometric system - id: BA-2 title: Biometric Demographic Categories props: - value: 3.2.3.1 B class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: BA-2_smt name: statement prose: Demographic categories to be considered SHALL include sex and skin tone when these factors affect biometric performance. - id: BA-2_obj links: - rel: assessment-for href: "#BA-2_smt" name: objective prose: Ensure biometric comparison works for a wide demographic range. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BA-2_asm-examine name: assessment-method prose: Examine test procedure for biometric system to verify that a wide demographic range was included. - id: BA-3 title: Biometric Test Conditions props: - value: 3.2.3.1 C class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: BA-3_smt name: statement prose: "This FMR SHALL be achieved under the conditions of a conformant attack (i.e., zero-effort impostor attempt), as defined in [ISO/IEC30107-1]." - id: BA-3_obj links: - rel: assessment-for href: "#BA-3_smt" name: objective prose: Define test conditions for false match rate test. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BA-3_asm-examine name: assessment-method prose: Examine test procedure to determine test conditions. - id: BA-4 title: Biometric Test Procedure props: - value: 3.2.3.1 D class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: BA-4_smt name: statement prose: "Biometric performance SHALL be tested in accordance with [ISO/IEC19795-1]." - id: BA-4_obj links: - rel: assessment-for href: "#BA-4_smt" name: objective prose: Define test conditions for false match rate test. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BA-4_asm-examine name: assessment-method prose: Examine test procedure to determine test conditions. - id: BA-5 title: Biometric Threshold props: - value: 3.2.3.1 E class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: BA-5_smt name: statement prose: The biometric system SHALL be configured with a fixed threshold; it is not feasible to change the threshold for each demographic. - id: BA-5_obj links: - rel: assessment-for href: "#BA-5_smt" name: objective prose: Require consistent match criteria for all demographic groups. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BA-5_asm-examine name: assessment-method prose: Examine comparison algorithm to verify that it uses a single threshold. - id: PAD-1 title: Biometric Pad props: - value: 3.2.3.2 A class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: PAD-1_smt name: statement prose: The biometric system SHOULD implement PAD for iris and fingerprint modalities and SHALL implement PAD for facial recognition. - id: PAD-1_obj links: - rel: assessment-for href: "#PAD-1_smt" name: objective prose: Require PAD for facial recognition to counter deepfakes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PAD-1_asm-test name: assessment-method prose: Test facial recognition with a synthetic image to verify use of presentation attack detection. - id: PAD-1_gdn name: guidance prose: Applies to facial recognition modality. - id: PAD-2 title: Biometric Voice Prohibition props: - value: 3.2.3.2 B class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: PAD-2_smt name: statement prose: Biometric comparison based on voice SHALL NOT be used. - id: PAD-2_obj links: - rel: assessment-for href: "#PAD-2_smt" name: objective prose: Prohibit use of voice recognition due to ease in spoofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PAD-2_asm-test name: assessment-method prose: Test available authentication methods to verify that voice recognition is not available. - id: PAD-2_gdn name: guidance prose: Applies to voice recognition modality. - id: IAD-1 title: Biometric Failure Threshold props: - value: 3.2.3.3 A class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: IAD-1_smt name: statement prose: The biometric system SHALL allow no more than five consecutive failed authentication attempts or 10 consecutive failed attempts if PAD is implemented and meets the above requirements. - id: IAD-1_obj links: - rel: assessment-for href: "#IAD-1_smt" name: objective prose: Limit opportunity to spoof biometric comparison. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAD-1_asm-test name: assessment-method prose: Test by creating unsuccessful comparisons and verify that requests are throttled after the specified limit is reached. - id: IAD-2 title: Biometric Failure Delay props: - value: 3.2.3.3 B class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: IAD-2_smt name: statement prose: "Once that limit has been reached, the biometric authenticator SHALL impose a delay of at least 30 seconds before each subsequent attempt with an overall limit of no more than 50 consecutive failed authentication attempts or 100 if PAD is implemented due to the mitigation of presentation attacks." - id: IAD-2_obj links: - rel: assessment-for href: "#IAD-2_smt" name: objective prose: Limit opportunity to spoof biometric comparison. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAD-2_asm-test name: assessment-method prose: Test by creating unsuccessful comparisons and verify that requests are throttled after the specified limit is reached. - id: IAD-3 title: Biometric Failure Limit props: - value: 3.2.3.3 C class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: IAD-3_smt name: statement prose: "Once the overall limit is reached, the biometric system SHALL disable biometric authentication and offer another factor (e.g., a different biometric modality or an activation secret if it is not a required factor) if such an alternative method is already available." - id: IAD-3_obj links: - rel: assessment-for href: "#IAD-3_smt" name: objective prose: Limit opportunity to spoof biometric comparison. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAD-3_asm-test name: assessment-method prose: Test by creating unsuccessful comparisons and verify that biometric comparison is disabled when the specified limit is reached. - id: IAD-4 title: Biometric Unlocking Independence props: - value: 3.2.3.3 D class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: IAD-4_smt name: statement prose: "The presentation of a biometric factor for authenticator activation SHALL be a separate operation from unlocking the host device (e.g., smartphone)." - id: IAD-4_obj links: - rel: assessment-for href: "#IAD-4_smt" name: objective prose: Minimize opportunity for an attacker to authenticate on an already unlocked device. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IAD-4_asm-test name: assessment-method prose: Test by attempting to authenticate on an already unlocked device and verify that an additional biometric comparison is required. - id: IAD-5 title: Biometric Endpoint Authentication props: - value: 3.2.3.3 E class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: IAD-5_smt name: statement prose: "If the comparison is performed centrally, the sender or endpoint SHALL be authenticated before capturing the biometric sample from the claimant." - id: IAD-5_obj links: - rel: assessment-for href: "#IAD-5_smt" name: objective prose: Protect against injection attacks from rogue hardware devices. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAD-5_asm-examine name: assessment-method prose: Examine method for authenticating sensor or endpoint and evaluate its security - id: IAD-5_gdn name: guidance prose: Central biometric comparison. - id: IAD-5.1 title: Biometric Central Protection props: - value: 3.2.3.3 F class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: IAD-5.1_smt name: statement prose: "If the comparison is performed centrally, appropriate controls (e.g., encryption and access controls) for sensitive personal information SHALL be implemented." - id: IAD-5.1_obj links: - rel: assessment-for href: "#IAD-5.1_smt" name: objective prose: Ensure that centrally stored biometric data is sufficiently secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAD-5.1_asm-examine name: assessment-method prose: Examine storage of biometric data and evaluate access controls for that data. - id: IAD-5.1_gdn name: guidance prose: Central biometric comparison. - id: IAD-5.2 title: Biometric Authenticated Protected Channel props: - value: 3.2.3.3 G class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: IAD-5.2_smt name: statement prose: "If the comparison is performed centrally, an authenticated protected channel between the sensor (or an endpoint containing a sensor that resists sensor replacement) and the verifier SHALL be established. All transmission of biometric information SHALL be conducted over that authenticated protected channel." - id: IAD-5.2_obj links: - rel: assessment-for href: "#IAD-5.2_smt" name: objective prose: Ensure that biometric data is transmitted securely for central comparison. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IAD-5.2_asm-examine name: assessment-method prose: Examine code or communications protocol to verify that all biometric data is transmitted over an authenticated protected channel. - id: IAD-5.2_gdn name: guidance prose: Central biometric comparison. - id: UBS-1 title: Biometric Sample Erasure props: - value: 3.2.3.4 A class: index name: label - value: CSP/Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UBS-1_smt name: statement prose: The biometric samples and any other biometric data derived from them SHALL be erased immediately after any adaptation or research data has been derived. - id: UBS-1_obj links: - rel: assessment-for href: "#UBS-1_smt" name: objective prose: Ensure that biometric samples are securely erased as soon as they are no longer needed. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UBS-1_asm-examine name: assessment-method prose: Examine code to verify erasure of biometric samples. - id: UBS-2 title: Biometric Sample Storage Limit props: - value: 3.2.3.4 B class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: UBS-2_smt name: statement prose: A limit on the allowable time for adaptation SHALL be established and enforced by the authenticator or the CSP. - id: UBS-2_obj links: - rel: assessment-for href: "#UBS-2_smt" name: objective prose: Establish reasonable limits on adaptation time to limit persistence of biometric samples. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UBS-2_asm-examine name: assessment-method prose: Examine documentation to determine adaptation time limit. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: UBS-2_asm-examine-2 name: assessment-method prose: Examine code to verify that biometric samples are erased at or before that time limit. - id: ATT-1 title: Attestation Signature Requirements props: - value: 3.2.4 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ATT-1_smt name: statement prose: "Attestations SHALL be signed using a digital signature that provides at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication)." - id: ATT-1_obj links: - rel: assessment-for href: "#ATT-1_smt" name: objective prose: Ensure that the key used to sign the attestation is of sufficient size to be secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ATT-1_asm-examine name: assessment-method prose: Examine code to determine the security strength of the attestation key. - id: PHIRES-1 title: Phishing Resistance Approved Algorithms props: - value: 3.2.5 A class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: PHIRES-1_smt name: statement prose: Approved cryptographic algorithms SHALL be used to establish phishing resistance where required. - id: PHIRES-1_obj links: - rel: assessment-for href: "#PHIRES-1_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms and protocols are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHIRES-1_asm-examine name: assessment-method prose: Examine documented policies or code to determine that only approved cryptographic algorithms can be used. - id: PHIRES-2 title: Phishing Resistance Key Strength props: - value: 3.2.5 B class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: PHIRES-2_smt name: statement prose: "Keys used for phishing resistance SHALL provide at least the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication)." - id: PHIRES-2_obj links: - rel: assessment-for href: "#PHIRES-2_smt" name: objective prose: Ensure that the authentication key is of sufficient size to be secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PHIRES-2_asm-examine name: assessment-method prose: Examine code to determine the security strength of the authentication key. - id: PHIRES-3 title: Phishing Resistance Manual Prohibition props: - value: 3.2.5 C class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: PHIRES-3_smt name: statement prose: "Authenticators that involve the manual entry of an authenticator output (e.g., out-of-band and OTP authenticators) SHALL NOT be considered phishing-resistant because the manual entry does not bind the authenticator output to the specific session being authenticated." - id: PHIRES-3_obj links: - rel: assessment-for href: "#PHIRES-3_smt" name: objective prose: "Ensure that manual intervention, which can be socially engineered, is not part of phishing-resistant authentication." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PHIRES-3_asm-test name: assessment-method prose: Test available authentication methods to ensure that phishing -resistant authentication methods do not use manual entry. - id: CB-1 title: Channel Binding Authenticated Protected Channel props: - value: 3.2.5.1 A class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: CB-1_smt name: statement prose: An authentication protocol with channel binding SHALL establish an authenticated protected channel with the verifier. - id: CB-1_obj links: - rel: assessment-for href: "#CB-1_smt" name: objective prose: Ensure that phishing-resistant authentication uses a secure channel that authenticates the verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CB-1_asm-test name: assessment-method prose: Test by to verify that authenticated protected channel such as TLS is used. - id: CB-2 title: Channel Binding Identifier props: - value: 3.2.5.1 B class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: CB-2_smt name: statement prose: "The protocol SHALL then strongly and irreversibly bind a channel identifier negotiated in establishing the authenticated protected channel to the authenticator output (e.g., by signing the two values together using a private key controlled by the claimant for which the public key is known to the verifier)." - id: CB-2_obj links: - rel: assessment-for href: "#CB-2_smt" name: objective prose: Ensure that the authentication protocol is bound to the communications channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CB-2_asm-test name: assessment-method prose: Test to determine if client-authenticated TLS is being used or analyze protocol to verify channel binding. - id: CB-3 title: Channel Binding Validation props: - value: 3.2.5.1 C class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: CB-3_smt name: statement prose: The verifier SHALL validate the signature or other information used to prove phishing resistance. - id: CB-3_obj links: - rel: assessment-for href: "#CB-3_smt" name: objective prose: Ensure that authentication requires a valid signature. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CB-3_asm-test name: assessment-method prose: Test to verify that invalid signatures are not accepted. - id: VNB-1 title: Name Binding Authenticated Protected Channel props: - value: 3.2.5.2 A class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: VNB-1_smt name: statement prose: An authentication protocol with verifier name binding SHALL establish an authenticated protected channel with the verifier. - id: VNB-1_obj links: - rel: assessment-for href: "#VNB-1_smt" name: objective prose: Ensure that phishing-resistant authentication uses a secure channel that authenticates the verifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: VNB-1_asm-test name: assessment-method prose: Test by to verify that authenticated protected channel such as TLS is used. - id: VNB-2 title: Name Binding Authenticated Verifier props: - value: 3.2.5.2 B class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: VNB-2_smt name: statement prose: The protocol SHALL generate an authenticator output that is cryptographically bound to a verifier identifier that is authenticated as part of the protocol. - id: VNB-2_obj links: - rel: assessment-for href: "#VNB-2_smt" name: objective prose: Ensure that the authentication transaction can only succeed when connected to a specific host or domain. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: VNB-2_asm-test name: assessment-method prose: Test by simulating connection to a different host or domain and verify that the transaction does not succeed. - id: VNB-3 title: Name Binding Hostname props: - value: 3.2.5.2 C class: index name: label - value: Verifier class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: VNB-3_smt name: statement prose: "In the case of DNS identifiers, the verifier identifier SHALL be either the authenticated hostname of the verifier or a parent domain that is at least one level below the public suffix [PSL] associated with that hostname." - id: VNB-3_obj links: - rel: assessment-for href: "#VNB-3_smt" name: objective prose: Ensure the correct relationship between the transaction hostname and the bound verifier name. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VNB-3_asm-examine name: assessment-method prose: Examine code to determine that the correct comparison is made between the bound host/domain and the hostname of the authenticated protected channel. - id: VCIC-1 title: Separate Verifier Mutually Authenticated Channel props: - value: 3.2.6 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: VCIC-1_smt name: statement prose: "If the verifier and CSP or IdP are separate entities (as shown by the dotted line in Fig. 3 of [SP800-63]), communications between the verifier and CSP or IdP SHALL occur through a mutually authenticated protected channel (e.g., a client-authenticated TLS connection) using approved cryptography." - id: VCIC-1_obj links: - rel: assessment-for href: "#VCIC-1_smt" name: objective prose: Ensure a secure relationship between verifier and CSP/IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: VCIC-1_asm-examine name: assessment-method prose: Examine communications channel between verifier and CSP/IdP and verify that client-authenticated TLS or equivalent is used. - id: VCIC-1_gdn name: guidance prose: Applies when verifier and CSP/IdP are separate entities. - id: AI-1 title: Intent Requirement props: - value: 3.2.8 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AI-1_smt name: statement prose: The authenticator itself SHALL establish authentication intent. - id: AI-1_obj links: - rel: assessment-for href: "#AI-1_smt" name: objective prose: Ensure that authentication only occurs when intended by the claimant. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AI-1_asm-test name: assessment-method prose: Test available authentication methods to ensure that all require some action on the part of the claimant. - id: AI-2 title: Intent Explicit props: - value: 3.2.8 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AI-2_smt name: statement prose: "In scenarios involving biometric authentication not requiring claimant action, an explicit mechanism (e.g., tapping a software or physical button) SHALL be provided to establish authentication intent." - id: AI-2_obj links: - rel: assessment-for href: "#AI-2_smt" name: objective prose: Ensure that "passive" biometric authentication is not sufficient to establish intent. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AI-2_asm-test name: assessment-method prose: Test available authentication methods using biometrics to ensure that all require some action on the part of the claimant. - id: AI-2_gdn name: guidance prose: Applies to authentication methods using biometric comparison. - id: RESTA-1 title: Restricted Authenticator Risk Determination props: - value: 3.2.9 A class: index name: label - value: Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RESTA-1_smt name: statement prose: "If the RP determines that the risk to any party is unacceptable, the restricted authenticator SHALL NOT be used, and an alternative authenticator type SHALL be used." - id: RESTA-1_obj links: - rel: assessment-for href: "#RESTA-1_smt" name: objective prose: Ensure that restricted authenticators are not used in high-risk situations. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RESTA-1_asm-examine name: assessment-method prose: Examine risk assessment for evaluation and acceptability of risks. - id: RESTA-2 title: Non-Restricted Authenticator Requirement props: - value: "3.2.9 B #1" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RESTA-2_smt name: statement prose: The CSP SHALL offer subscribers at least one alternative authenticator that is not restricted and can be used to authenticate at the required AAL. - id: RESTA-2_obj links: - rel: assessment-for href: "#RESTA-2_smt" name: objective prose: Ensure that alternative authentication methods not using restricted authenticators are provided. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RESTA-2_asm-examine name: assessment-method prose: Examine available authentication methods to verify that one or more non-restricted authenticators can be used. - id: RESTA-3 title: Restricted Authenticator Risk Notice props: - value: "3.2.9 B #2" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RESTA-3_smt name: statement prose: The CSP SHALL provide subscribers with meaningful notice regarding the restricted authenticator's security risks and the availability of unrestricted alternatives. - id: RESTA-3_obj links: - rel: assessment-for href: "#RESTA-3_smt" name: objective prose: Ensure that subscribers are aware of the risks and alternatives. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RESTA-3_asm-examine name: assessment-method prose: Examine text displayed to subscriber when binding a restricted authenticator to make sure meaningful notice is displayed. - id: RESTA-4 title: Restricted Authenticator Risk Documentation props: - value: "3.2.9 B #3" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RESTA-4_smt name: statement prose: The CSP SHALL address any additional risks to subscribers and RPs in its risk assessment. - id: RESTA-4_obj links: - rel: assessment-for href: "#RESTA-4_smt" name: objective prose: Ensure that risks are documented. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RESTA-4_asm-examine name: assessment-method prose: Examine risk assessment for documentation of any additional risks. - id: RESTA-5 title: Restricted Authenticator Migration Plan props: - value: "3.2.9 B #4" class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RESTA-5_smt name: statement prose: "The CSP SHALL develop a migration plan for the possibility that the restricted authenticator will not be acceptable in the future and include this migration plan in its Digital Identity Acceptance Statement (see Sec. 3.4.4 of [SP800-63])." - id: RESTA-5_obj links: - rel: assessment-for href: "#RESTA-5_smt" name: objective prose: Plan for the likelihood that restricted authenticators will be non-compliant in the future. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RESTA-5_asm-examine name: assessment-method prose: Examine migration plan to verify a plan for deprecation/removal of restricted authenticator. - id: AS-1 title: Activation Secret Non-Transferable props: - value: 3.2.10 A class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-1_smt name: statement prose: "In all cases, the activation secret SHALL remain within the authenticator and its associated user endpoint." - id: AS-1_obj links: - rel: assessment-for href: "#AS-1_smt" name: objective prose: Ensure that activation secret remains secure. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AS-1_asm-examine name: assessment-method prose: Examine protocol between authenticator or endpoint and verifier and confirm that activation secret is not transmitted. - id: AS-2 title: Activation Secret Minimum Length props: - value: 3.2.10 B class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-2_smt name: statement prose: Authenticators that use activation secrets SHALL require the secrets to be at least four characters in length and SHOULD require the secrets to be at least six characters in length. - id: AS-2_obj links: - rel: assessment-for href: "#AS-2_smt" name: objective prose: Ensure that activation secret is not too easy to guess. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AS-2_asm-test name: assessment-method prose: Test by attempting to establish an activation secret that is three characters or less and verify that it is not accepted. - id: AS-3 title: Activation Secret Retry Limit props: - value: 3.2.10 C class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-3_smt name: statement prose: The authenticator or verifier SHALL implement a retry-limiting mechanism that limits the number of consecutive failed activation attempts using the authenticator to no more than 10. - id: AS-3_obj links: - rel: assessment-for href: "#AS-3_smt" name: objective prose: Ensure that the verification process limits excessive retries that would indicate a brute force attack. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AS-3_asm-test name: assessment-method prose: Test by making more than 10 consecutive incorrect activation secret entries followed by a successful one and verify that authentication does not succeed. - id: AS-4 title: Retry Limit Authenticator Implementation props: - value: 3.2.10 D class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-4_smt name: statement prose: "Unless the authenticator generates an invalid output when an incorrect activation secret is provided, retry limiting SHALL be implemented in the authenticator." - id: AS-4_obj links: - rel: assessment-for href: "#AS-4_smt" name: objective prose: Ensure that it is not possible to do an offline activation attack by observing the authenticator output. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AS-4_asm-test name: assessment-method prose: Test by attempting to activate the authenticator offline and ensure that it is locally throttled. - id: AS-4_gdn name: guidance prose: "Does not apply when the authenticator provides an output, but a wrong one, when an activation secret is provided." - id: AS-5 title: Retry Limit Exceeded Disables props: - value: 3.2.10 E class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-5_smt name: statement prose: "Once the limit of attempts is reached, the authenticator SHALL be disabled, and a different authenticator SHALL be required for authentication." - id: AS-5_obj links: - rel: assessment-for href: "#AS-5_smt" name: objective prose: Ensure that an authenticator that has reached its limit of activation attempts cannot be easily reactivated. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AS-5_asm-examine name: assessment-method prose: Examine procedures for use of an authenticator that has reached its activation attempts limit and verify that rebinding of the authenticator to the subscriber account is required. - id: AS-6 title: AAL3 Hardware-Protected Authentication Secret Verification props: - value: 3.2.10 F class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-6_smt name: statement prose: "For authenticators that are usable at AAL3, verification of activation secrets SHALL be performed in a hardware-protected environment (e.g., a secure element, TPM, or TEE)." - id: AS-6_obj links: - rel: assessment-for href: "#AS-6_smt" name: objective prose: Ensure that authenticator protects activation secrets sufficiently for use at AAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AS-6_asm-examine name: assessment-method prose: Examine implementation of authenticator to verify that activation secret verification is hardware-protected. - id: AS-7 title: AAL2 Activation Secret Derivation props: - value: 3.2.10 G class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-7_smt name: statement prose: "At AAL2, if a hardware-protected environment is not used, the authenticator SHALL use the activation secret to derive a key used to decrypt the authentication key." - id: AS-7_obj links: - rel: assessment-for href: "#AS-7_smt" name: objective prose: Ensure that the authentication key is protected by knowledge of the activation secret. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AS-7_asm-examine name: assessment-method prose: Examine storage of the authentication key and verify it is the result of a decrypting the stored key with a key derived from the activation secret. - id: AS-7_gdn name: guidance prose: Applies when authentication key is stored in a software protected environment. - id: AS-8 title: Activation Secret Independence props: - value: 3.2.10 H class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: AS-8_smt name: statement prose: "Submitting the activation factor SHALL be a separate operation from unlocking the host device (e.g., smartphone)." - id: AS-8_obj links: - rel: assessment-for href: "#AS-8_smt" name: objective prose: Minimize opportunity for an attacker to authenticate on an already unlocked device. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AS-8_asm-test name: assessment-method prose: Test by attempting to authenticate on an already unlocked device and verify that a separate entry of the activation secret is required. - id: CONNAUTH-1 title: Authenticator Connection Types props: - value: 3.2.11 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONNAUTH-1_smt name: statement prose: "This connection SHALL be made using a wired connection (e.g., USB or direct connection with a smartcard), a wireless technology, or a hybrid of those technologies, including network connections." - id: CONNAUTH-1_obj links: - rel: assessment-for href: "#CONNAUTH-1_smt" name: objective prose: Ensure that connection to the authenticator meets an accepted model. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONNAUTH-1_asm-examine name: assessment-method prose: Examine ways that a connected authenticator can be used and verify that it meets one of the three models for connection. - id: CONNAUTH-2 title: Connected Authenticator Approved Cryptography props: - value: 3.2.11 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONNAUTH-2_smt name: statement prose: Approved cryptography SHALL be used for all cases in which cryptographic operations are required. - id: CONNAUTH-2_obj links: - rel: assessment-for href: "#CONNAUTH-2_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms and protocols are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONNAUTH-2_asm-examine name: assessment-method prose: Examine documented policies or code to determine that only approved cryptographic algorithms can be used. - id: CONNAUTH-3 title: Connected Authenticator Authenticated Protected Channel props: - value: 3.2.11 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CONNAUTH-3_smt name: statement prose: All communication of authentication data between authenticators and endpoints SHALL occur directly between those devices or through an authenticated protected channel between the authenticator and endpoint. - id: CONNAUTH-3_obj links: - rel: assessment-for href: "#CONNAUTH-3_smt" name: objective prose: Require secure communications between authenticator and endpoint. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CONNAUTH-3_asm-examine name: assessment-method prose: Examine protocol for any communications between authenticator and endpoint that may be indirect (through intermediaries). - id: CONNAUTH-3_gdn name: guidance prose: Applies when communication between authenticator and endpoint is not point-to-point. - id: WC-1 title: Wireless Authenticator Physical Proximity Requirement props: - value: 3.2.11.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-1_smt name: statement prose: "To minimize the attack surface for threats to the authenticator-endpoint connection, the authentication process SHALL require physical proximity between the authenticator and endpoint by establishing a wireless connection with a range of no more than 240 meters." - id: WC-1_obj links: - rel: assessment-for href: "#WC-1_smt" name: objective prose: Limit opportunity for attack by remotely located attackers. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WC-1_asm-test name: assessment-method prose: Test authentication process with a remotely located authenticator and verify that it fails. - id: WC-2 title: Wireless Authenticator Key Establishment props: - value: 3.2.11.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-2_smt name: statement prose: |- Wireless connections SHALL establish a key for encrypted communication between the authenticator and endpoint in one of the following ways: (1) Through a temporary wired connection between the devices. (2) Through an association process that is similar to a pairing process but does not require a persistent relationship between devices to establish a key for encrypted communication between the authenticator and endpoint. - id: WC-2_obj links: - rel: assessment-for href: "#WC-2_smt" name: objective prose: Define acceptable methods for associating authenticator and endpoint. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WC-2_asm-test name: assessment-method prose: Test key establishment between endpoint and authenticator and verify that it is done in an acceptable way. - id: WC-2.1 title: Wireless Authenticator Pairing Code props: - value: 3.2.11.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-2.1_smt name: statement prose: "If an association process is used, it SHALL employ a pairing code or other shared secret between the devices." - id: WC-2.1_obj links: - rel: assessment-for href: "#WC-2.1_smt" name: objective prose: Require use of a shared secret to identify the parties to the association. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WC-2.1_asm-test name: assessment-method prose: Test association process and verify that a pairing code or shared secret is required. - id: WC-2.1_gdn name: guidance prose: Applies when an association process is used instead of a temporary wired connection. - id: WC-2.2 title: Wireless Authenticator Pairing Code Length props: - value: 3.2.11.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-2.2_smt name: statement prose: "If an association process is used, either the authenticator or endpoint SHALL have a pairing code that is at least six decimal digits (or equivalent) in length that MAY be printed on the device." - id: WC-2.2_obj links: - rel: assessment-for href: "#WC-2.2_smt" name: objective prose: Require that the pairing code be long enough to provide appropriate security. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WC-2.2_asm-test name: assessment-method prose: Test association process and verify that the pairing code or shared secret is long enough. - id: WC-2.2_gdn name: guidance prose: Applies when an association process is used instead of a temporary wired connection. - id: WC-2.3 title: Wireless Authenticator Association Methods props: - value: 3.2.11.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-2.3_smt name: statement prose: "If an association process is used, the pairing code SHALL be conveyed between the devices by manual entry or using a QR code or similar representation that is optically communicated." - id: WC-2.3_obj links: - rel: assessment-for href: "#WC-2.3_smt" name: objective prose: Allow use of manual or optically-assisted entry of pairing code. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WC-2.3_asm-test name: assessment-method prose: Test association process to verify that the pairing code is manually entered or optically communicated. - id: WC-2.3_gdn name: guidance prose: Applies when an association process is used instead of a temporary wired connection. - id: WC-3 title: Wireless Authenticator Proximate Activation Secret props: - value: 3.2.11.2 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-3_smt name: statement prose: "When using a wireless technology with an effective range of less than 1 meter (e.g., NFC), any activation secret transmitted from the endpoint to the authenticator SHALL be encrypted using a key that is established between the devices." - id: WC-3_obj links: - rel: assessment-for href: "#WC-3_smt" name: objective prose: Ensure secure transmission of the activation secret from the endpoint to the authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: WC-3_asm-examine name: assessment-method prose: Examine implementation to verify that transmission of the activation secret is encrypted using a key established between the devices. - id: WC-3_gdn name: guidance prose: Applies when very short range (<1 m) wireless technologies are used. - id: WC-4 title: Wireless Authenticator Pairing Code Use props: - value: 3.2.11.2 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-4_smt name: statement prose: A pairing code SHALL be used if the authenticator is configured to require authenticated pairing. - id: WC-4_obj links: - rel: assessment-for href: "#WC-4_smt" name: objective prose: Use pairing processes appropriate for the authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WC-4_asm-test name: assessment-method prose: Test to verify that a pairing code is used when authenticated pairing is required. - id: WC-4_gdn name: guidance prose: Applies when authenticator uses authenticated pairing. - id: WC-5 title: Wireless Authenticator Non-Proximate Authenticated Protected Channel props: - value: 3.2.11.2 F class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-5_smt name: statement prose: "Network connections and wireless technologies with an effective range of 1 meter or more (e.g., Bluetooth Low Energy [BLE]) SHALL use an authenticated protected channel between the authenticator and endpoint." - id: WC-5_obj links: - rel: assessment-for href: "#WC-5_smt" name: objective prose: Require stronger protections for wireless connections with longer range. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: WC-5_asm-examine name: assessment-method prose: Examine implementation to verify that an authenticated protected channel such as TLS is used. - id: WC-5_gdn name: guidance prose: Applies when longer range (>=1 m) wireless technologies are used. - id: WC-6 title: Wireless Authenticator Encryption props: - value: 3.2.11.2 G class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-6_smt name: statement prose: The entire authentication transaction SHALL be encrypted. - id: WC-6_obj links: - rel: assessment-for href: "#WC-6_smt" name: objective prose: Protect authentication transaction in transit between devices. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: WC-6_asm-examine name: assessment-method prose: Examine implementation to verify that the entire transaction is authenticated. - id: WC-7 title: Wireless Authenticator Persistent Key Removal props: - value: 3.2.11.2 H class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WC-7_smt name: statement prose: A mechanism for endpoints to remove persistent keys SHALL be provided. - id: WC-7_obj links: - rel: assessment-for href: "#WC-7_smt" name: objective prose: Require removal of associations between authenticator and endpoint when no longer needed. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WC-7_asm-test name: assessment-method prose: Test authenticator and/or endpoint to verify that a mechanism to remove persistent keys exists. - id: HYBC-1 title: Hybrid Connection Establishment props: - value: 3.2.11.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: HYBC-1_smt name: statement prose: |- Hybrid connections (e.g., hybrid transports specified by the CTAP2.2 protocol) SHALL be established between authenticators and endpoints in one of the following ways: (1) By communicating initial keying information and the identity of the tunnel service to be used via a displayed QR code or similar visual representation coupled with the receipt by the endpoint of wireless data containing the additional information required to establish the tunnel connection. (2) Through cached keying and tunnel information retained by the authenticator and endpoint from a previous authentication transaction. - id: HYBC-1_obj links: - rel: assessment-for href: "#HYBC-1_smt" name: objective prose: Require hybrid connections to be established securely or to be based on cached information. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: HYBC-1_asm-test name: assessment-method prose: Test establishment of hybrid connections between authenticators and endpoints to verify that they are established in one of the permitted methods. - id: HYBC-1.1 title: Hybrid Connection Proximity props: - value: 3.2.11.3 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: HYBC-1.1_smt name: statement prose: The wireless data SHALL be conveyed over a technology with a maximum effective range of no more than 240 meters. - id: HYBC-1.1_obj links: - rel: assessment-for href: "#HYBC-1.1_smt" name: objective prose: Limit opportunity for attack by remotely located attackers. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: HYBC-1.1_asm-test name: assessment-method prose: Test authentication process with a remotely located authenticator and verify that it fails. - id: HYBC-1.1_gdn name: guidance prose: Applies when initial keying information is being established. - id: HYBC-2 title: Hybrid Connection Association Removal props: - value: 3.2.11.3 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: HYBC-2_smt name: statement prose: A mechanism for endpoints to remove cached associations with authenticators SHALL be provided. - id: HYBC-2_obj links: - rel: assessment-for href: "#HYBC-2_smt" name: objective prose: Require removal of associations between authenticator and endpoint when no longer needed. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: HYBC-2_asm-test name: assessment-method prose: Test authenticator and/or endpoint to verify that a mechanism to remove persistent keys exists. - id: RANV-1 title: Random Value Generation Requirements props: - value: 3.2.12 A class: index name: label - value: CSP/Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RANV-1_smt name: statement prose: "Unless otherwise specified, random values that reference this section SHALL be generated by an approved random bit generator that provides at least the minimum security strength specified in the latest revision of SP800-131A (i.e., 112 bits as of the date of this publication)." - id: RANV-1_obj links: - rel: assessment-for href: "#RANV-1_smt" name: objective prose: Require use of sufficiently secure random values. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RANV-1_asm-examine name: assessment-method prose: Examine implementation of random bit generator to verify that it meets SP 800-131A requirements. - id: EXPO-1 title: Non-Exportability Hardware Requirements props: - value: 3.2.13 A class: index name: label - value: CSP class: target name: marking - value: AAL1/AAL2 class: xal-level name: marking parts: - id: EXPO-1_smt name: statement prose: "To be considered non-exportable, an authenticator SHALL either be a separate piece of hardware or an embedded processor or execution environment (e.g., secure element, TEE, TPM)." - id: EXPO-1_obj links: - rel: assessment-for href: "#EXPO-1_smt" name: objective prose: Require that non-exportable keys not be directly accessible to the endpoint. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXPO-1_asm-examine name: assessment-method prose: "Examine implementation, including APIs, to ensure that authentication keys are not sent or accessible outside the authenticator." - id: EXPO-2 title: Non-Exportable Authentication Key Protection props: - value: 3.2.13 B class: index name: label - value: CSP class: target name: marking - value: AAL1/AAL2 class: xal-level name: marking parts: - id: EXPO-2_smt name: statement prose: A non-exportable authenticator SHALL be designed to prohibit the export of the authentication secret to the host processor and SHALL NOT be capable of being reprogrammed by the host processor to allow the secret to be extracted. - id: EXPO-2_obj links: - rel: assessment-for href: "#EXPO-2_smt" name: objective prose: Ensure that reprogramming of the secure environment is not possible as a back door to obtain access to authentication secrets. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXPO-2_asm-examine name: assessment-method prose: Examine APIs between the endpoint and authenticator to verify that it is not possible for the endpoint to reprogram the authenticator. - id: AUTHB-1 title: Authenticator Binding Requirements props: - value: 4.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUTHB-1_smt name: statement prose: "Authenticators SHALL be bound to subscriber accounts by either: being issued by the CSP as part of enrollment; or using a subscriber-provided authenticator that is acceptable to the CSP." - id: AUTHB-1_obj links: - rel: assessment-for href: "#AUTHB-1_smt" name: objective prose: Allow CSP to verify that all authenticators bound to subscriber accounts meet their requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUTHB-1_asm-examine name: assessment-method prose: Examine procedures for binding authenticators and verify that they provide an opportunity for the CSP to verify the authenticator's security. - id: AUTHB-2 title: Authenticator Record-Keeping props: - value: 4.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUTHB-2_smt name: statement prose: "Throughout the lifetime of a digital identity, CSPs SHALL maintain a record of all authenticators that are bound to each subscriber account." - id: AUTHB-2_obj links: - rel: assessment-for href: "#AUTHB-2_smt" name: objective prose: Maintain the ability to audit authenticators that are or have been bound to subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUTHB-2_asm-examine name: assessment-method prose: Examine CSP records to verify that records of current and past bound authenticators are maintained. - id: AUTHB-3 title: CSP Authenticator Characteristics Determination props: - value: 4.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUTHB-3_smt name: statement prose: "The CSP SHALL determine the characteristics of the authenticator being bound (e.g., single-factor versus multifactor, phishing-resistant or not) so that verifiers can assess compliance with the requirements at each AAL." - id: AUTHB-3_obj links: - rel: assessment-for href: "#AUTHB-3_smt" name: objective prose: Ensure that authenticators bound to subscriber accounts meet requirements for the AALs at which they will be used. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: AUTHB-3_asm-interview name: assessment-method prose: Interview CSP to determine the sufficiency of procedures for approving authenticators. - id: AUTHB-4 title: CSP Authenticator State Storage props: - value: 4.1 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUTHB-4_smt name: statement prose: The CSP SHALL also maintain other state information that is required to meet the authenticator verification requirements. - id: AUTHB-4_obj links: - rel: assessment-for href: "#AUTHB-4_smt" name: objective prose: Ensure that the CSP is equipped to maintain other state information such as that required for throttling. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUTHB-4_asm-examine name: assessment-method prose: Examine CSP records to verify that required state information is maintained. - id: AUTHB-5 title: CSP Authenticator Lifecycle Logging props: - value: 4.1 E class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUTHB-5_smt name: statement prose: "The record created by the CSP SHALL contain the date and time of significant authenticator life cycle events (e.g., binding to the subscriber account, renewal, update, expiration)." - id: AUTHB-5_obj links: - rel: assessment-for href: "#AUTHB-5_smt" name: objective prose: Maintain the ability to audit authenticator life cycle events. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUTHB-5_asm-examine name: assessment-method prose: Examine CSP records to verify that authenticator life cycle events are documented. - id: BAA-1 title: Multiple Authenticator Binding props: - value: 4.1.2.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BAA-1_smt name: statement prose: "Accordingly, CSPs SHALL permit the binding of multiple authenticators to a subscriber account." - id: BAA-1_obj links: - rel: assessment-for href: "#BAA-1_smt" name: objective prose: Allow subscribers to bind multiple authenticators to guard against loss or failure of a given authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAA-1_asm-test name: assessment-method prose: Test by attempting to bind multiple authenticators and verify that it is successful. - id: BAA-2 title: Binding Authentication Requirement props: - value: 4.1.2.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BAA-2_smt name: statement prose: "When any new authenticator is bound to a subscriber account, the CSP SHALL ensure that the process requires authentication at either the maximum AAL currently available in the subscriber account or the maximum AAL at which the new authenticator will be used, whichever is lower." - id: BAA-2_obj links: - rel: assessment-for href: "#BAA-2_smt" name: objective prose: Ensure that it is not possible to increase authenticated AAL by binding a new authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAA-2_asm-test name: assessment-method prose: Test by binding a new authenticator for use at AAL2 or AAL3 and verify that it requires authentication at the corresponding AAL. - id: BAA-3 title: Binding Notification Requirement props: - value: 4.1.2.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BAA-3_smt name: statement prose: "When an authenticator is added, the CSP SHALL notify the subscriber via a mechanism independent of the transaction binding the new authenticator, as described in Sec. 4.6." - id: BAA-3_obj links: - rel: assessment-for href: "#BAA-3_smt" name: objective prose: Warn subscriber in case an authenticator is bound without their knowledge. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAA-3_asm-test name: assessment-method prose: Test by binding an additional authenticator and verify that the subscriber receives a notification as described. - id: BINAE-1 title: External Authenticator Binding props: - value: 4.1.2.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-1_smt name: statement prose: |- The binding process SHALL proceed in one of the following ways: (1) An endpoint that has authenticated to the CSP requests a binding code from the CSP. The binding code is input into the endpoint associated with the new authenticator and sent to the CSP. (2) The endpoint associated with the new authenticator obtains a binding code from the CSP. The binding code is input to an authenticated endpoint and sent to the CSP. - id: BINAE-1_obj links: - rel: assessment-for href: "#BINAE-1_smt" name: objective prose: Ensure that the binding of authenticators not directly connected to an authenticated session uses a secure process. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-1_asm-test name: assessment-method prose: "Test by binding an authenticator that is not connected to the authenticated endpoint, and ensure that it uses one of the described processes." - id: BINAE-2 title: External Authenticator Authenticated Protected Channel props: - value: 4.1.2.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-2_smt name: statement prose: "When binding an external authenticator, an authenticated protected channel SHALL be established by the endpoint associated with the new authenticator and the CSP." - id: BINAE-2_obj links: - rel: assessment-for href: "#BINAE-2_smt" name: objective prose: Ensure that channel between authenticator and endpoint are protected against eavesdropping and intermediaries. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BINAE-2_asm-examine name: assessment-method prose: Examine implementation to verify that an authenticated protected channel such as TLS is used. - id: BINAE-3 title: External Authenticator Binding Code props: - value: 4.1.2.2 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-3_smt name: statement prose: "When binding an external authenticator, the CSP SHALL generate a binding code using an approved random bit generator as described in Sec. 3.2.12 and send it to either the new authenticator endpoint or the authenticated endpoint approving the binding." - id: BINAE-3_obj links: - rel: assessment-for href: "#BINAE-3_smt" name: objective prose: Ensure that a sufficiently random binding code is used and transmitted to the endpoint or authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BINAE-3_asm-examine name: assessment-method prose: Examine implementation to see how the binding code is generated. - id: BINAE-4 title: External Authenticator Identifier Binding Code Length props: - value: 4.1.2.2 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-4_smt name: statement prose: The binding code SHALL be at least 40 bits in length if it is used with an identifier entered by the subscriber on the new authenticator. - id: BINAE-4_obj links: - rel: assessment-for href: "#BINAE-4_smt" name: objective prose: Ensure that the binding code is sufficiently large to provide the required level of security. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-4_asm-test name: assessment-method prose: Test by binding an external authenticator and verify that the binding code is sufficiently long. - id: BINAE-4_gdn name: guidance prose: Applies when an identifier is entered by the subscriber on the new authenticator. - id: BINAE-5 title: External Authenticator Non-Identifier Binding Code Length props: - value: 4.1.2.2 E class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-5_smt name: statement prose: The binding code SHALL be at least 112 bits in length if it is not used with an identifier entered by the subscriber on the new authenticator. - id: BINAE-5_obj links: - rel: assessment-for href: "#BINAE-5_smt" name: objective prose: Ensure that the binding code is sufficiently large to provide the required level of security. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-5_asm-test name: assessment-method prose: Test by binding an external authenticator and verify that the binding code is sufficiently long. - id: BINAE-5_gdn name: guidance prose: Applies when no identifier is entered by the subscriber on the new authenticator. - id: BINAE-6 title: External Authenticator Association Methods props: - value: 4.1.2.2 F class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-6_smt name: statement prose: "When binding an external authenticator, the subscriber SHALL transfer the binding code to the other endpoint manually or via a local out-of-band method such as a QR code." - id: BINAE-6_obj links: - rel: assessment-for href: "#BINAE-6_smt" name: objective prose: Ensure that the binding code is transferred through action by the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-6_asm-test name: assessment-method prose: Test all supported methods for binding an external authenticator and verify that manual or local out-of-band action is required. - id: BINAE-7 title: External Authenticator Binding Code Security props: - value: 4.1.2.2 G class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-7_smt name: statement prose: The binding code SHALL NOT be communicated over an insecure channel. - id: BINAE-7_obj links: - rel: assessment-for href: "#BINAE-7_smt" name: objective prose: Ensure that the binding code is not available to an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-7_asm-test name: assessment-method prose: Test all supported methods for binding an external authenticator and verify that no insecure channels are used. - id: BINAE-8 title: External Authenticator Binding Code Replay props: - value: 4.1.2.2 H class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-8_smt name: statement prose: "When binding an external authenticator, the binding code SHALL be usable only once." - id: BINAE-8_obj links: - rel: assessment-for href: "#BINAE-8_smt" name: objective prose: Guard against replay of the binding code. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-8_asm-test name: assessment-method prose: Test by attempting to use the same binding code more than once and verify that it fails. - id: BINAE-9 title: External Authenticator Binding Code Lifetime props: - value: 4.1.2.2 I class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-9_smt name: statement prose: The binding code SHALL be valid for a maximum of 10 minutes. - id: BINAE-9_obj links: - rel: assessment-for href: "#BINAE-9_smt" name: objective prose: Limit usability of a binding code that may have been part of an incomplete binding transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-9_asm-test name: assessment-method prose: "Test by attempting to bind an external authenticator while delaying transfer of the binding code for more than 10 minutes, and verify that it fails." - id: BINAE-10 title: External Authenticator Binding Instructions props: - value: 4.1.2.2 J class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BINAE-10_smt name: statement prose: The CSP SHALL provide clear instructions on what the subscriber should do in the event of an authenticator binding mishap. - id: BINAE-10_obj links: - rel: assessment-for href: "#BINAE-10_smt" name: objective prose: Provide recourse for binding transactions that do not occur normally. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BINAE-10_asm-test name: assessment-method prose: Test by attempting to bind an external authenticator and verify that suitable guidance to the subscriber is provided. - id: BSPA-1 title: Subscriber Provided Authenticator Procedure props: - value: 4.1.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BSPA-1_smt name: statement prose: The binding of subscriber-provided authenticators SHALL be done as described in Sec. 4.1.2. - id: BSPA-1_obj links: - rel: assessment-for href: "#BSPA-1_smt" name: objective prose: Ensure that subscriber-provided authenticators are bound in a secure manner. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BSPA-1_asm-examine name: assessment-method prose: Examine procedures for binding subscriber-controlled authenticators and verify that they meet BAA-1 through BAA-3 and BINAE-1 through BINAE-9 as applicable. - id: BSPA-2 title: Authenticator Type Documentation props: - value: 4.1.3 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BSPA-2_smt name: statement prose: The types of authenticators accepted by the CSP SHALL be documented in the CSP practice statement. - id: BSPA-2_obj links: - rel: assessment-for href: "#BSPA-2_smt" name: objective prose: Make sure clear guidelines for subscriber acceptability are published. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BSPA-2_asm-examine name: assessment-method prose: Examine CSP practice statement to verify that acceptable types of subscriber-provided authenticators are documented. - id: ARM-1 title: Account Recovery Requirement props: - value: 4.2.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARM-1_smt name: statement prose: CSPs SHALL support one or more of the four account recovery mechanisms described. - id: ARM-1_obj links: - rel: assessment-for href: "#ARM-1_smt" name: objective prose: Ensure that secure account recovery mechanisms are provided. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARM-1_asm-examine name: assessment-method prose: Examine available recovery procedures to verify that at least one of the described account recovery mechanisms is supported. - id: ARM-2 title: Account Recovery Alternatives props: - value: 4.2.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARM-2_smt name: statement prose: The use of alternative methods SHALL be based on a risk analysis and documented by the CSP. - id: ARM-2_obj links: - rel: assessment-for href: "#ARM-2_smt" name: objective prose: Require that alternative recovery mechanisms by documented and accompanied by a valid risk analysis. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARM-2_asm-examine name: assessment-method prose: Examine risk analysis for any alternative account recovery mechanisms that are supported. - id: SRC-1 title: Saved Recovery Code Generation props: - value: 4.2.1.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SRC-1_smt name: statement prose: The recovery code SHALL include at least 64 bits from an approved random bit generator. - id: SRC-1_obj links: - rel: assessment-for href: "#SRC-1_smt" name: objective prose: Ensure that a sufficiently random recovery code is used. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SRC-1_asm-examine name: assessment-method prose: Examine implementation to see how the recovery code is generated. - id: SRC-2 title: Saved Recovery Code Issuance Notification props: - value: 4.2.1.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SRC-2_smt name: statement prose: "The issuance of a replacement recovery code SHALL result in an account recovery notification, as described in Sec. 4.6." - id: SRC-2_obj links: - rel: assessment-for href: "#SRC-2_smt" name: objective prose: Confirm that subscriber is notified of account recovery events. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SRC-2_asm-test name: assessment-method prose: Test by performing a recovery using a saved recovery code and verify that the subscriber is notified in one of the ways described. - id: SRC-3 title: Saved Recovery Code Rate Limitation props: - value: 4.2.1.1 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SRC-3_smt name: statement prose: The verification of saved recovery codes SHALL be subject to the throttling requirements in Sec. 3.2.2. - id: SRC-3_obj links: - rel: assessment-for href: "#SRC-3_smt" name: objective prose: Limit ability to guess recovery codes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SRC-3_asm-test name: assessment-method prose: Test by performing a recovery using a number of invalid recovery codes followed by a correct code and confirm that throttling has occurred. - id: SRC-4 title: Saved Recovery Code Storage props: - value: 4.2.1.1 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SRC-4_smt name: statement prose: "Saved recovery codes SHALL be stored in the subscriber account in hashed form using an approved one-way function, as described in Sec. 3.1.1.2." - id: SRC-4_obj links: - rel: assessment-for href: "#SRC-4_smt" name: objective prose: "At a minimum, require salting and hashing of recovery codes as protection against offline attacks should the verifier be breached." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SRC-4_asm-examine name: assessment-method prose: Examine recovery code verification storage to determine evidence of hashing. - id: SRC-5 title: Saved Recovery Code Replay props: - value: 4.2.1.1 E class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SRC-5_smt name: statement prose: "Following the use of a saved recovery code, the CSP SHALL invalidate that recovery code and SHALL issue a new saved recovery code to the subscriber." - id: SRC-5_obj links: - rel: assessment-for href: "#SRC-5_smt" name: objective prose: Prevent replay of recovery codes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SRC-5_asm-test name: assessment-method prose: Test by attempting a second recovery using a saved recovery code and verify that it is unsuccessful. - id: IRC-1 title: Issued Recovery Code Generation props: - value: 4.2.1.2 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IRC-1_smt name: statement prose: "The issued recovery code SHALL include at least six decimal digits (or equivalent) from an approved random bit generator, as described in Sec. 3.2.12." - id: IRC-1_obj links: - rel: assessment-for href: "#IRC-1_smt" name: objective prose: Ensure that a sufficiently random recovery code is used. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IRC-1_asm-examine name: assessment-method prose: Examine implementation to see how the recovery code is generated. - id: IRC-2 title: Issued Recovery Code Validity props: - value: 4.2.1.2 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IRC-2_smt name: statement prose: |- Issued recovery codes SHALL be valid for at most: (a) 21 days when sent to a postal address within the contiguous United States. (b) 30 days when sent to a postal address outside of the contiguous United States. (c) 10 minutes when sent via text message or voice. (d) 24 hours when sent to an email address. - id: IRC-2_obj links: - rel: assessment-for href: "#IRC-2_smt" name: objective prose: Limit lifetimes of issued recovery codes based on expected delivery times. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IRC-2_asm-examine name: assessment-method prose: Examine methods for issued recovery code delivery and verify that implementation limits their validity to within the specified timeframes. - id: IRC-3 title: Issued Recovery Code Rate Limitation props: - value: 4.2.1.2 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IRC-3_smt name: statement prose: The verification of issued recovery codes SHALL be subject to the throttling requirements in Sec. 3.2.2. - id: IRC-3_obj links: - rel: assessment-for href: "#IRC-3_smt" name: objective prose: Limit ability to guess recovery codes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IRC-3_asm-test name: assessment-method prose: Test by performing a recovery using a number of invalid recovery codes followed by a correct code and confirm that throttling has occurred. - id: IRC-4 title: Issued Recovery Code Address Verification props: - value: 4.2.1.2 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IRC-4_smt name: statement prose: "When establishing recovery addresses other than those validated or verified as part of the identity proofing process, the address SHALL be verified." - id: IRC-4_obj links: - rel: assessment-for href: "#IRC-4_smt" name: objective prose: Confirm reliability of recovery addresses. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IRC-4_asm-examine name: assessment-method prose: Examine metadata associated with recovery addresses and verify that a confirmation flag is present and is required in order to be used for recovery. - id: IRC-5 title: Issued Recovery Code Address Verification Procedure props: - value: 4.2.1.2 E class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IRC-5_smt name: statement prose: "To verify an address, the CSP SHALL send a confirmation code with the same characteristics as a recovery code to the newly established recovery address and require that the subscriber return the same confirmation code to the CSP." - id: IRC-5_obj links: - rel: assessment-for href: "#IRC-5_smt" name: objective prose: Specify procedure for address confirmation. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IRC-5_asm-test name: assessment-method prose: Test by establishing a new recovery address and verify that it is only usable for recovery after having been confirmed. - id: IRC-6 title: Issued Recovery Code Multiple Address Requirement props: - value: 4.2.1.2 H class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IRC-6_smt name: statement prose: CSPs SHALL allow the subscriber to establish at least two recovery addresses. - id: IRC-6_obj links: - rel: assessment-for href: "#IRC-6_smt" name: objective prose: Provide backup in case subscriber loses control of a recovery address. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IRC-6_asm-test name: assessment-method prose: Test by verifying that it is possible to establish more than one recovery address. - id: RECC-1 title: Recovery Contact Addresses props: - value: 4.2.1.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RECC-1_smt name: statement prose: CSPs that support the use of recovery contacts SHALL allow the subscriber to specify one or more addresses of trusted associates to receive issued recovery codes. - id: RECC-1_obj links: - rel: assessment-for href: "#RECC-1_smt" name: objective prose: Define recovery contacts mechanism. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RECC-1_asm-test name: assessment-method prose: Test by establishing a recovery contact and performing account recovery to verify that associate received recovery code and instructions on what to do with it. - id: RECC-2 title: Recovery Contact Management props: - value: 4.2.1.3 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RECC-2_smt name: statement prose: "If the CSP supports the use of recovery contacts, the CSP SHALL provide methods for subscribers to view and manage recovery contacts." - id: RECC-2_obj links: - rel: assessment-for href: "#RECC-2_smt" name: objective prose: "Allow subscriber to manage recovery contacts (e.g., to change them)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RECC-2_asm-test name: assessment-method prose: Test by changing and deleting recovery contacts and verify that it is possible to do so. - id: RIP-1 title: Repeated Proofing Account Recovery props: - value: 4.2.1.4 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RIP-1_smt name: statement prose: The CSP SHALL repeat the necessary steps of identity proofing consistent with the level of initial identity proofing and SHALL confirm that the claimant's identity is consistent with the previously established account. - id: RIP-1_obj links: - rel: assessment-for href: "#RIP-1_smt" name: objective prose: Define requirements for recovery via repeated identity proofing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RIP-1_asm-examine name: assessment-method prose: Examine procedures for recovery via identity proofing to verify their usability and security. - id: RWIP-1 title: Non-Proofing Recovery props: - value: 4.2.2.1 A class: index name: label - value: CSP class: target name: marking - value: AAL1 class: xal-level name: marking parts: - id: RWIP-1_smt name: statement prose: "The recovery of such subscriber accounts SHALL require the successful use of a saved recovery code, issued recovery code, or recovery contact." - id: RWIP-1_obj links: - rel: assessment-for href: "#RWIP-1_smt" name: objective prose: Define non-proofing recovery. - props: - value: EXAMINE name: method class: assessment-summary id: RWIP-1_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by ARM, IRC, and RECC controls" - id: RAAL2-1 title: AAL2 Recovery Requirements props: - value: 4.2.2.2 A class: index name: label - value: CSP class: target name: marking - value: AAL2 class: xal-level name: marking parts: - id: RAAL2-1_smt name: statement prose: |- To recover an account that can authenticate at a maximum of AAL2, the CSP SHALL require the subscriber to complete one of the following: (1) Two recovery codes obtained using different methods from the set (i.e., saved, issued, and recovery contacts). (2) One recovery code from the set (i.e., saved, issued, and recovery contacts) plus authentication with a single-factor authenticator that is bound to the subscriber account. (3) Repeated identity proofing (provided that the subscriber account has been identity-proofed). - id: RAAL2-1_obj links: - rel: assessment-for href: "#RAAL2-1_smt" name: objective prose: Specify methods of account recovery at AAL2. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RAAL2-1_asm-test name: assessment-method prose: "Test to verify that one recovery method is required to recover a single authentication factor, two methods are required to recover two authentication factors, or repeated identity proofing is required at AAL2." - id: RAAL3-1 title: AAL3/IAL3 Recovery Requirements props: - value: 4.2.2.3 A class: index name: label - value: CSP class: target name: marking - value: AAL3 class: xal-level name: marking parts: - id: RAAL3-1_smt name: statement prose: "If an account that can authenticate at AAL3 has been identity-proofed at IAL3, the CSP SHALL successfully perform a successful biometric comparison against the biometric characteristic collected during an initial on-site attended identity proofing session, as described in [SP800-63A]." - id: RAAL3-1_obj links: - rel: assessment-for href: "#RAAL3-1_smt" name: objective prose: Require biometric comparison for subscriber accounts to meet AAL3/IAL3 security requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RAAL3-1_asm-examine name: assessment-method prose: Examine procedures for account recovery at AAL3/IAL3 and verify that a successful biometric comparison is required. - id: ACCRN-1 title: Account Recovery Notification props: - value: 4.2.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ACCRN-1_smt name: statement prose: "In all cases, account recovery SHALL cause a notification to be sent to the subscriber or their designee, as described in Sec. 4.6." - id: ACCRN-1_obj links: - rel: assessment-for href: "#ACCRN-1_smt" name: objective prose: Confirm that subscriber is notified of account recovery events. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ACCRN-1_asm-test name: assessment-method prose: Test by performing a recovery and verify that the subscriber is notified in one of the ways described. - id: LTDC-1 title: Compromise Suspension Requirement props: - value: 4.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LTDC-1_smt name: statement prose: "The CSP SHALL suspend, invalidate, or destroy compromised authenticators from the subscriber's account promptly following compromise detection." - id: LTDC-1_obj links: - rel: assessment-for href: "#LTDC-1_smt" name: objective prose: Require processes for rendering compromised authenticators inoperative. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: LTDC-1_asm-examine name: assessment-method prose: Examine procedures for handling compromised authenticators and verify that such authenticators are disabled. - id: LTDC-2 title: Compromise Reporting Authenticators props: - value: 4.3 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: LTDC-2_smt name: statement prose: Backup authenticators used for secure reporting of compromise SHALL be a password or a physical authenticator. - id: LTDC-2_obj links: - rel: assessment-for href: "#LTDC-2_smt" name: objective prose: Establish requirements for authenticators reporting compromise. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: LTDC-2_asm-examine name: assessment-method prose: Examine procedures for issuing backup authenticators for reporting. - id: LTDC-2_gdn name: guidance prose: Applies if CSP issues an authenticator for reporting. - id: EXP-1 title: Expired Authenticators Unusable props: - value: 4.4 A class: index name: label - value: CSP/Verifier class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXP-1_smt name: statement prose: "When an authenticator expires, it SHALL NOT be usable for authentication." - id: EXP-1_obj links: - rel: assessment-for href: "#EXP-1_smt" name: objective prose: Ensure that expired authenticators are not usable. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: EXP-1_asm-test name: assessment-method prose: Test by trying to authenticate with an expired authenticator and verify that it is unsuccessful. - id: EXP-1_gdn name: guidance prose: Applies if authenticators that expire are used. - id: EXP-2 title: Expired Authenticator Replacement props: - value: 4.4 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EXP-2_smt name: statement prose: "The replacement of expired authenticators SHALL conform to the binding process for an additional authenticator, as described in Sec. 4.1.2." - id: EXP-2_obj links: - rel: assessment-for href: "#EXP-2_smt" name: objective prose: Require standard issuance process for issuance of replacements for expired authenticators. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EXP-2_asm-examine name: assessment-method prose: Examine CSP procedures for issuing replacements for expired authenticators and verify that the full issuance process is used. - id: EXP-2_gdn name: guidance prose: Applies if authenticators that expire are used. - id: INVAL-1 title: Authenticator Invalidation props: - value: 4.5 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: INVAL-1_smt name: statement prose: "CSPs SHALL promptly invalidate authenticators when a subscriber account ceases to exist (e.g., subscriber's death, the discovery of a fraudulent subscriber), when requested by the subscriber, when the authenticator is compromised, or when the CSP determines that the subscriber no longer meets its eligibility requirements." - id: INVAL-1_obj links: - rel: assessment-for href: "#INVAL-1_smt" name: objective prose: Require a process for invalidating authenticators when required. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: INVAL-1_asm-examine name: assessment-method prose: Examine process for receiving and processing invalidation requests from subscriber and other appropriate sources. - id: INVAL-2 title: Authenticator Invalidation Reporting Risk props: - value: 4.5 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: INVAL-2_smt name: statement prose: The CSP SHALL make a risk-based determination of the authenticity of invalidation requests from the subscriber. - id: INVAL-2_obj links: - rel: assessment-for href: "#INVAL-2_smt" name: objective prose: Guard against denial-of-service attacks from spurious invalidation requests. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: INVAL-2_asm-examine name: assessment-method prose: Examine process for evaluating invalidation requests that are received. - id: ANOT-1 title: Notification Addresses props: - value: 4.6 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ANOT-1_smt name: statement prose: "Events that require notification SHALL cause a notification to be sent to the notification addresses stored in the subscriber account. Notification addresses may be any means by which the subscriber can be reliably contacted, such as: postal address; email address; address (e.g., telephone number) to which a text message or voice message may be sent; and reference to the subscriber in a push notification service." - id: ANOT-1_obj links: - rel: assessment-for href: "#ANOT-1_smt" name: objective prose: Define overall requirement for notification. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ANOT-1_asm-examine name: assessment-method prose: Examine implementation to verify that notification infrastructure exists. - id: ANOT-2 title: Notification Multiple Address Support props: - value: 4.6 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ANOT-2_smt name: statement prose: CSPs SHALL support at least two notification addresses per subscriber account. - id: ANOT-2_obj links: - rel: assessment-for href: "#ANOT-2_smt" name: objective prose: Require ability to establish multiple notification addresses for redundancy. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ANOT-2_asm-test name: assessment-method prose: Test establishment of multiple notification addresses and verify that it is possible to establish at least two. - id: ANOT-3 title: Notification Address Validation props: - value: 4.6 C class: index name: label - value: CSP class: target name: marking - value: AAL2/AAL3 class: xal-level name: marking parts: - id: ANOT-3_smt name: statement prose: "For subscriber accounts that have undergone identity proofing, at least one address SHALL have been validated during the identity proofing process." - id: ANOT-3_obj links: - rel: assessment-for href: "#ANOT-3_smt" name: objective prose: Require use of an identity proofed address for reliability. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ANOT-3_asm-test name: assessment-method prose: Test with an identity proofed subscriber account to verify that an identity proofed address is already used. - id: ANOT-3_gdn name: guidance prose: Applies when subscriber account has been identity proofed. - id: ANOT-4 title: Notification Multiplicity props: - value: 4.6 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ANOT-4_smt name: statement prose: Notifications SHALL be sent to all notification addresses except postal addresses. - id: ANOT-4_obj links: - rel: assessment-for href: "#ANOT-4_smt" name: objective prose: Require transmission to multiple addresses except postal addresses due to cost considerations. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ANOT-4_asm-test name: assessment-method prose: "Test by generating a notification to a subscriber account with multiple non-postal notification addresses, and verify that the notification is sent to all of them." - id: ANOT-5 title: Postal Notification props: - value: 4.6 E class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ANOT-5_smt name: statement prose: "However, notifications SHALL be sent to postal addresses if no other form of notification address is stored in the subscriber account or if the notification is for account recovery at AAL3." - id: ANOT-5_obj links: - rel: assessment-for href: "#ANOT-5_smt" name: objective prose: Require notifications to postal addresses when they are the only notification address or for high assurance account recovery. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ANOT-5_asm-test name: assessment-method prose: Test by generating a notification to subscriber accounts with only a postal address and by performing AAL3 account recovery and verify that a postal notification would be sent. - id: ANOT-5_gdn name: guidance prose: Applies when the only notification address is a postal address or AAL3 recovery. - id: ANOT-6 title: Postal Recovery Notification props: - value: 4.6 F class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ANOT-6_smt name: statement prose: Account recovery notifications SHALL also be sent to a postal address if the only other notification address in the subscriber account is the address to which an issued recovery code was sent. - id: ANOT-6_obj links: - rel: assessment-for href: "#ANOT-6_smt" name: objective prose: Provide postal notification when needed to provide notification independent of account recovery. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ANOT-6_asm-test name: assessment-method prose: Test by using an issued recovery code and verify that a postal notification would be sent if no other notification address exists. - id: ANOT-6_gdn name: guidance prose: Applies when using issued recovery codes and the only other notification address is postal. - id: ANOT-7 title: Notification Repudiation Instructions props: - value: 4.6 G class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ANOT-7_smt name: statement prose: "The notification SHALL provide clear instructions, including contact information, in case the recipient repudiates the event associated with the notification." - id: ANOT-7_obj links: - rel: assessment-for href: "#ANOT-7_smt" name: objective prose: Provide recourse for account holders receiving notification of events they did not authorize. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ANOT-7_asm-examine name: assessment-method prose: Examine notification and verify presence of instructions and contact information. - id: SB-1 title: Session Secret Requirement props: - value: 5.1 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-1_smt name: statement prose: A session secret SHALL be shared between the subscriber's software and the accessed service. - id: SB-1_obj links: - rel: assessment-for href: "#SB-1_smt" name: objective prose: Require that a session establishment be based on a shared secret. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-1_asm-examine name: assessment-method prose: Examine implementation to verify that a session secret is shared when a session is established based on authentication. - id: SB-2 title: Session Secret Presentation props: - value: 5.1 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-2_smt name: statement prose: "The secret SHALL be directly presented by the subscriber's software, or possession of the secret SHALL be proven using a cryptographic mechanism." - id: SB-2_obj links: - rel: assessment-for href: "#SB-2_smt" name: objective prose: Allow verification of the secret to be either direct or cryptographic - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-2_asm-examine name: assessment-method prose: Examine process for verifying the shared secret to verify how it is verified. - id: SB-3 title: Session Continuity Secrets props: - value: 5.1 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-3_smt name: statement prose: "The continuity of authenticated sessions SHALL be based on the possession of a session secret that is issued by the session host at the time of authentication and optionally refreshed during the session. The nature of a session depends on the application, such as: a web browser session with a \"session\" cookie; and an instance of a mobile application that retains a session secret." - id: SB-3_obj links: - rel: assessment-for href: "#SB-3_smt" name: objective prose: Provide examples of session verification methods. - props: - value: EXAMINE name: method class: assessment-summary id: SB-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SB-1 and SB-2. - id: SB-4 title: Session Secrets Not Replace Authentication props: - value: 5.1 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-4_smt name: statement prose: Cookies and similar "remember my browser" features SHALL NOT be used instead of authentication except as provided for reauthentication at AAL2 in Sec. 2.2.3 when the inactivity limit has been exceeded but the time limit has not. - id: SB-4_obj links: - rel: assessment-for href: "#SB-4_smt" name: objective prose: Emphasize that secrets may not be used to bypass multifactor authentication requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-4_asm-examine name: assessment-method prose: Examine implementation to verify that multifactor authentication requirements are enforced regardless of session secrets. - id: SB-5 title: Session Lifetime Limits props: - value: 5.1 E class: index name: label - value: RP/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-5_smt name: statement prose: "However, RPs and CSPs SHALL ensure that the session lifetime limits described in Sec. 2.2.3 are enforced even when a knowledge of the session secret is demonstrated." - id: SB-5_obj links: - rel: assessment-for href: "#SB-5_smt" name: objective prose: Emphasize that secrets may not be used to bypass reauthentication time limits. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-5_asm-examine name: assessment-method prose: Examine implementation to verify that reauthentication requirements are enforced regardless of session secrets. - id: SB-6 title: Session Secret Generation props: - value: 5.1 F class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-6_smt name: statement prose: The secret used for session binding SHALL be generated by the session host in direct response to an authentication event. - id: SB-6_obj links: - rel: assessment-for href: "#SB-6_smt" name: objective prose: Specify party generating session secret. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-6_asm-examine name: assessment-method prose: Examine protocol to verify that session secret is generated by host upon authentication. - id: SB-7 title: Session AAL Limitation props: - value: 5.1 G class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-7_smt name: statement prose: A session MAY be considered at a lower AAL than the authentication event but SHALL NOT be considered at a higher AAL than the authentication event. - id: SB-7_obj links: - rel: assessment-for href: "#SB-7_smt" name: objective prose: Allow sessions to be used at lower AALs than authenticated. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SB-7_asm-test name: assessment-method prose: Test to verify that it is possible to use a session at a lower AAL than was authenticated but not a higher AAL. - id: SB-7_gdn name: guidance prose: Applies to relying parties that support applications at multiple AALs. - id: SB-8 title: Session Secrets Result From Authentication props: - value: "5.1 #1" class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-8_smt name: statement prose: Secrets used for session binding SHALL be established during or immediately following authentication. - id: SB-8_obj links: - rel: assessment-for href: "#SB-8_smt" name: objective prose: Require tight relationship between authentication and session binding. - props: - value: EXAMINE name: method class: assessment-summary id: SB-8_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SB-6. - id: SB-8.1 title: Session Secret Generation Requirements props: - value: "5.1 #2" class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-8.1_smt name: statement prose: "Secrets used for session binding SHALL be established using input from an approved random bit generator, as described in Sec. 3.2.12, and are at least 64 bits in length." - id: SB-8.1_obj links: - rel: assessment-for href: "#SB-8.1_smt" name: objective prose: Ensure that a sufficiently random session secret is used. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-8.1_asm-examine name: assessment-method prose: Examine implementation to see how the session secret is generated and verify that it uses an approved random bit generator and is of sufficient length. - id: SB-8.2 title: Session Secret Logout Invalidation props: - value: "5.1 #3" class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-8.2_smt name: statement prose: Secrets used for session binding SHALL be erased or invalidated by the session subject when the subscriber logs out. - id: SB-8.2_obj links: - rel: assessment-for href: "#SB-8.2_smt" name: objective prose: Ensure that sessions are no longer usable following logout. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-8.2_asm-examine name: assessment-method prose: Examine implementation to verify that session secrets are no longer valid following logout. - id: SB-8.3 title: Session Secret Establishment props: - value: "5.1 #4" class: index name: label - value: RP/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-8.3_smt name: statement prose: "Secrets used for session binding SHALL be either transferred from the session host to the RP or CSP via an authenticated protected channel or derived from keys that are established as part of establishing a valid, mutually authenticated protected channel." - id: SB-8.3_obj links: - rel: assessment-for href: "#SB-8.3_smt" name: objective prose: Define secure methods of establishing the session secret. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-8.3_asm-examine name: assessment-method prose: Examine implementation to verify that the session secret is transferred or derived as described. - id: SB-8.4 title: Session Secret Time Limits props: - value: "5.1 #5" class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-8.4_smt name: statement prose: "Secrets used for session binding SHALL time out and not be accepted after the times specified in Sec. 2.1.3, Sec. 2.2.3, and Sec. 2.3.3, as appropriate for the AAL." - id: SB-8.4_obj links: - rel: assessment-for href: "#SB-8.4_smt" name: objective prose: Ensure that session secrets are invalidated when time out times are met. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-8.4_asm-examine name: assessment-method prose: Examine implementation to verify that necessary timers are in place and used to invalidate session secrets. - id: SB-8.5 title: Session Secret Intermediary Protection props: - value: "5.1 #6" class: index name: label - value: RP/CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-8.5_smt name: statement prose: Secrets used for session binding SHALL be unavailable to intermediaries between the host and the subscriber's endpoint. - id: SB-8.5_obj links: - rel: assessment-for href: "#SB-8.5_smt" name: objective prose: Prevent intermediaries and eavesdroppers from accessing session secrets - props: - value: EXAMINE name: method class: assessment-summary id: SB-8.5_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SB-8.3. - id: SB-9 title: Session Transport Security Maintenance props: - value: 5.1 I class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-9_smt name: statement prose: "Following authentication, authenticated sessions SHALL NOT fall back to an insecure transport (e.g., from https to http)." - id: SB-9_obj links: - rel: assessment-for href: "#SB-9_smt" name: objective prose: Prevent sessions from falling back to an insecure state - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SB-9_asm-test name: assessment-method prose: "Test, if insecure transport is supported at all, by attempting to substitute an insecure transport and verify that it is unsuccessful." - id: SB-10 title: CSRF Protection Requirement props: - value: 5.1 J class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SB-10_smt name: statement prose: POST/PUT content SHALL contain a session identifier that the RP SHALL verify to protect against cross-site request forgery (CSRF). - id: SB-10_obj links: - rel: assessment-for href: "#SB-10_smt" name: objective prose: Protect against cross-site request forgery. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SB-10_asm-examine name: assessment-method prose: "Examine content (e.g., with browser developer tools) to verify that session identifiers are present." - id: AT-1 title: Access Tokens Not Presence props: - value: 5.1.2 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AT-1_smt name: statement prose: The RP SHALL NOT interpret the presence of an access token as an indicator of the subscriber's presence in the absence of other signals. - id: AT-1_obj links: - rel: assessment-for href: "#AT-1_smt" name: objective prose: Ensure that session secrets rather than access/refresh tokens define validity of a session. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AT-1_asm-test name: assessment-method prose: Test by logging out of a federated session while a valid access token exists and verify that the session has been terminated. - id: AT-1_gdn name: guidance prose: "Applies to sessions established through federation. Note: last sentence of 5.1.2, \"authentication session\" -> \"authenticated session\"" - id: REAUTH-1 title: Periodic Reauthentication Requirement props: - value: 5.2 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REAUTH-1_smt name: statement prose: "The periodic reauthentication of sessions SHALL be performed to confirm the subscriber's continued presence at an authenticated session (e.g., that the subscriber has not walked away without logging out)." - id: REAUTH-1_obj links: - rel: assessment-for href: "#REAUTH-1_smt" name: objective prose: Ensure that a reauthentication process exists. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REAUTH-1_asm-examine name: assessment-method prose: Examine implementation to verify use of a reauthentication process following session time out. - id: REAUTH-2 title: Reauthentication Timeout Terminates Session props: - value: 5.2 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REAUTH-2_smt name: statement prose: "When either the overall or inactivity timeout expires, the session SHALL be terminated." - id: REAUTH-2_obj links: - rel: assessment-for href: "#REAUTH-2_smt" name: objective prose: Ensure that time out results in process termination. - props: - value: EXAMINE name: method class: assessment-summary id: REAUTH-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SB-8.4. - id: REAUTH-3 title: Reauthentication Timeout Reset props: - value: 5.2 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REAUTH-3_smt name: statement prose: "Session activity SHALL reset the inactivity timeout, and successful reauthentication during a session SHALL reset both timeouts." - id: REAUTH-3_obj links: - rel: assessment-for href: "#REAUTH-3_smt" name: objective prose: Define criteria for resetting timeouts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REAUTH-3_asm-examine name: assessment-method prose: Examine implementation of timeouts to verify that they are reset under these circumstances. - id: REAUTH-4 title: Reauthentication Documentation props: - value: 5.2 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REAUTH-4_smt name: statement prose: "Agencies SHALL establish and document the inactivity and overall time limits being enforced in a system security plan, such as that described in [SP800-39]." - id: REAUTH-4_obj links: - rel: assessment-for href: "#REAUTH-4_smt" name: objective prose: Verify documentation of timeouts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REAUTH-4_asm-examine name: assessment-method prose: Examine system security plan to verify that timeouts are described. - id: REAUTH-5 title: Reauthentication RP Authoritative props: - value: 5.2 E class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: REAUTH-5_smt name: statement prose: "The IdP can communicate the time and details of the authentication event to the RP, but the RP SHALL be authoritative as to whether the reauthentication requirements have been met." - id: REAUTH-5_obj links: - rel: assessment-for href: "#REAUTH-5_smt" name: objective prose: Establish precedence for control of session timing. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: REAUTH-5_asm-examine name: assessment-method prose: Examine implementation of timeouts at the RP to verify that it is not over-dependent on timing from the IdP. - id: REAUTH-5_gdn name: guidance prose: Applies to sessions established through federation. - id: SESSM-1 title: Session Monitoring Documentation props: - value: 5.3 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SESSM-1_smt name: statement prose: "Collection, the storage of expected subscriber characteristics, and the processing of session characteristics SHALL be included in the privacy risk assessment described in Sec. 7." - id: SESSM-1_obj links: - rel: assessment-for href: "#SESSM-1_smt" name: objective prose: Verify documentation of session monitoring. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SESSM-1_asm-examine name: assessment-method prose: Examine privacy risk assessment to verify that any use of session monitoring is included. - id: USEL-1 title: Consent Measures Voluntary props: - value: 7.3 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: USEL-1_smt name: statement prose: "Therefore, as stated in Sec. 2.4.3, when CSPs use consent measures, the subscriber's acceptance of additional uses SHALL NOT be a condition of providing authentication services." - id: USEL-1_obj links: - rel: assessment-for href: "#USEL-1_smt" name: objective prose: Ensure that consent measures are voluntary. - props: - value: EXAMINE name: method class: assessment-summary id: USEL-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by PR-3. - id: CAK-1 title: Syncable Authentication Key Generation props: - value: "B.2 #1" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-1_smt name: statement prose: All keys SHALL be generated using approved cryptography. - id: CAK-1_obj links: - rel: assessment-for href: "#CAK-1_smt" name: objective prose: "Determine that only secure, well-vetted cryptographic algorithms are being used." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-1_asm-examine name: assessment-method prose: Examine documented policies or practices to determine that only approved cryptographic algorithms can be used. - id: CAK-2 title: Syncable Authentication Key Fabric Requirements props: - value: "B.2 #2" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-2_smt name: statement prose: "Authentication keys that are cloned or exported from a device to a sync fabric SHALL only be stored in an encrypted form using a key with the minimum security strength specified in the latest revision of [SP800-131A] (i.e., 112 bits as of the date of this publication)." - id: CAK-2_obj links: - rel: assessment-for href: "#CAK-2_smt" name: objective prose: Protection of authentication keys in the sync fabric. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-2_asm-examine name: assessment-method prose: Examine sync fabric implementation(s) to verify that keys are stored in encrypted form with sufficient strength. - id: CAK-3 title: Syncable Private-Key Operations Local props: - value: "B.2 #3" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-3_smt name: statement prose: All authentication transactions SHALL perform private-key operations on the local device using cryptographic keys that are generated on-device or recovered from the sync fabric. - id: CAK-3_obj links: - rel: assessment-for href: "#CAK-3_smt" name: objective prose: Require cryptographic operations to be performed locally. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-3_asm-examine name: assessment-method prose: Examine implementation to verify that the source of private keys is local or from the sync fabric. - id: CAK-4 title: Syncable Key Fabric Access Control props: - value: "B.2 #4" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-4_smt name: statement prose: Authentication keys stored in the sync fabric SHALL be protected by access control mechanisms such that only the authenticated user can access their authentication keys in the sync fabric. - id: CAK-4_obj links: - rel: assessment-for href: "#CAK-4_smt" name: objective prose: Control access to keys in the sync fabric. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-4_asm-examine name: assessment-method prose: Examine implementation to verify that authentication keys are only available to the subscriber. - id: CAK-5 title: Syncable Key Fabric MFA props: - value: "B.2 #5" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-5_smt name: statement prose: User access to authentication keys in the sync fabric SHALL be protected by AAL2-equivalent MFA to preserve the integrity of the authentication protocols using the synced keys. - id: CAK-5_obj links: - rel: assessment-for href: "#CAK-5_smt" name: objective prose: Require sufficient authentication to access keys in the sync fabric. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-5_asm-examine name: assessment-method prose: Examine sync fabric implementation(s) to verify that at least AAL2 authentication is required to access authentication keys. - id: CAK-6 title: Syncable Authenticator Documentation props: - value: "B.2 #6" class: index name: label - value: CSP/Verifier class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-6_smt name: statement prose: "These general requirements and any other agency-specific requirements for using syncable authenticators SHALL be documented and communicated, including on public-facing websites and digital service policies, where applicable." - id: CAK-6_obj links: - rel: assessment-for href: "#CAK-6_smt" name: objective prose: Clearly document controls on use of syncable authenticators. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-6_asm-examine name: assessment-method prose: "Examine documentation, including on websites, of syncable authenticator guidelines." - id: CAK-7 title: Syncable Key Management props: - value: "B.2 #7" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-7_smt name: statement prose: "Authenticators that enable the use of syncable authentication keys SHOULD provide a user interface (UI) that allows subscribers to view the services for which they have created a syncable authentication key, whether that key has been synced, and where that key has been synced. The UI SHALL NOT expose the authentication key itself." - id: CAK-7_obj links: - rel: assessment-for href: "#CAK-7_smt" name: objective prose: Require manageability of syncable authentication keys by the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CAK-7_asm-test name: assessment-method prose: "Test to verify the ability of the subscriber to obtain information about their syncable keys, but not the key itself." - id: CAK-8 title: Syncable Key Fabric FISMA props: - value: "B.2 #8" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-8_smt name: statement prose: "Federal enterprise authentication keys SHALL be stored in sync fabrics that have achieved Federal Information Security Modernization Act (FISMA) [FISMA] moderate protections or equivalent." - id: CAK-8_obj links: - rel: assessment-for href: "#CAK-8_smt" name: objective prose: Require FISMA compliance for federal enterprise authentication keys. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-8_asm-examine name: assessment-method prose: Examine FISMA certification of sync fabric to verify that it meets provides moderate protection. - id: CAK-8_gdn name: guidance prose: Applies to federal enterprise use cases only. - id: CAK-9 title: Syncable Key Device Management props: - value: "B.2 #9" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-9_smt name: statement prose: "Devices (e.g., mobile phones, laptops, tablets) that generate, store, and sync authenticators containing federal enterprise authentication keys SHALL be protected by mobile device management software or other device configuration controls that prevent the syncing or sharing of keys to unauthorized devices or sync fabrics." - id: CAK-9_obj links: - rel: assessment-for href: "#CAK-9_smt" name: objective prose: Restrict choices of sync fabric to those approved by the agency. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-9_asm-examine name: assessment-method prose: Examine acceptance of authentication using syncable authenticators to verify that authentication requires appropriate device configuration management. - id: CAK-9_gdn name: guidance prose: Applies to federal enterprise use cases only. - id: CAK-10 title: Syncable Key Fabric Management props: - value: "B.2 #10" class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: CAK-10_smt name: statement prose: "Access to the sync fabric SHALL be controlled by agency-managed accounts (e.g., a central identity and access management solution, platform-based managed account) to maintain federal enterprise control over the authentication key's life cycle." - id: CAK-10_obj links: - rel: assessment-for href: "#CAK-10_smt" name: objective prose: Maintain federal control over authentication keys throughout their life cycle. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAK-10_asm-examine name: assessment-method prose: Examine choices of sync fabric approved by the agency to verify that it manages access to the fabric. - id: CAK-10_gdn name: guidance prose: Applies to federal enterprise use cases only. - id: IMPR-1 title: Syncable Key User Verification props: - value: B.3 A class: index name: label - value: Verifier class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: IMPR-1_smt name: statement prose: Verifiers SHALL indicate that user verification (UV) is preferred and SHALL inspect responses to confirm the value of the UV flag. - id: IMPR-1_obj links: - rel: assessment-for href: "#IMPR-1_smt" name: objective prose: Prefer syncable authenticators providing multi-factor authentication. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IMPR-1_asm-examine name: assessment-method prose: Examine implementation to verify that the value of the UV flag is observed. - id: IMPR-2 title: Syncable Non-UV Key SF props: - value: B.3 B class: index name: label - value: Verifier class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: IMPR-2_smt name: statement prose: "If the user is not verified, agencies SHALL treat the authenticator as a single-factor cryptographic authenticator." - id: IMPR-2_obj links: - rel: assessment-for href: "#IMPR-2_smt" name: objective prose: Authentication without user verification is single-factor. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IMPR-2_asm-examine name: assessment-method prose: Examine implementation to verify that authentication without user verification requires an additional password or biometric factor. - id: IMPR-3 title: Syncable Key Flag Trust props: - value: B.3 C class: index name: label - value: CSP class: target name: marking - value: Syncable class: xal-level name: marking parts: - id: IMPR-3_smt name: statement prose: Agencies SHALL evaluate the use cases for syncable authenticators and determine the appropriate access policy decisions that they intend to make based on returned information including flags and attestation. - id: IMPR-3_obj links: - rel: assessment-for href: "#IMPR-3_smt" name: objective prose: Provide basis for trusting information such as flags received from the authenticator. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IMPR-3_asm-examine name: assessment-method prose: Examine procedures and their basis to determine that appropriate attention has been paid to reliability of information received from syncable authenticators. - class: revision id: revision-63C title: 63C controls: - id: FAL-1 title: FAL Compliance props: - value: 2.0 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FAL-1_smt name: statement prose: "In order to fulfill the requirements for a given FAL, the federation transaction SHALL meet or exceed all requirements listed for that FAL." - id: FAL-1_obj links: - rel: assessment-for href: "#FAL-1_smt" name: objective prose: Determine that the IdP and RP each enforce all requirements associated with the applicable FAL and that every federation transaction meets or exceeds the criteria defined for that FAL. - props: - value: EXAMINE name: method class: assessment-summary id: FAL-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied when all controls applicable to the asserted FAL are satisfied. - id: FAL-1_gdn name: guidance prose: |- This requirement ensures that the assurance level claimed in a federation transaction reflects the actual technical protections in use. Each FAL defines minimum requirements for audience restriction, replay protection, assertion injection protection, trust agreement establishment, identifier and key establishment, and presentation. Both the IdP and RP must enforce those requirements so that no transaction is represented as operating at a higher FAL than the implemented controls support. See also SECC-4, which is a summative control for xAL baseline compliance. - id: CFAL-1 title: Federation Requirements props: - value: 2.1 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CFAL-1_smt name: statement prose: "At all FALs, all federation transactions SHALL comply with the requirements in Sec. 3 to deliver an assertion to the RP and create an authenticated session at the RP." - id: CFAL-1_obj links: - rel: assessment-for href: "#CFAL-1_smt" name: objective prose: Determine whether all federation transactions comply with the requirements in Section 3 for assertion delivery and RP session establishment. - props: - value: EXAMINE name: method class: assessment-summary id: CFAL-1_asm-summary title: Assessment Method name: assessment-method prose: |- For IdPs, satisfied by AAD-1, AAD-4, AAD-6, TSI-1, IDA-1 through IDA-3, ARTP-1, ARTI-1, SIGNA-1, SIGNA-3, SIGNA-4, and AUDR-1; also by PROXY-1, PROXY-3 if proxied federation is used; PPI-1, PPI-4 through PPI-8, PPI-10 if PPIs are used; DAV-1 if derived attribute values are used; and ENCA-1 if encrypted assertions are used. If FAL3, satisfied by HKA-1, HKA-3, HKA-5 when HoK assertions are used, and BAUTH-1 when the bound-authenticators are used. For RPs, satisfied by ASRP-1, SIGNA-2, and AUDR-2; also by FEDID-1, FEDID-2 when federated identifiers are used or ACCR-1 when account resolution is used; ABUN-2 and ABUN-3 if attribute bundles are used; and IDAP-3 if identity APIs are used. If FAL3, satisfied by ASRP-2; also HKA-2, RPPHBA-1, RPPHBA-3, RPPHBA-4 when HoK assertions are used; and BAUTH-5, BAUTH-7, RPPHBA-1, RPPHBA-3, and RPPHBA-4 when the bound-authenticators are used. - id: CFAL-1_gdn name: guidance prose: This is a summative control based on the outcomes of all controls governing assertion delivery and RP session creation. Compliance is demonstrated when all applicable Section 3 requirements are met. - id: CFAL-2 title: Assertion Validation props: - value: 2.1 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CFAL-2_smt name: statement prose: "At all FALs, the RP SHALL validate the assertion from the IdP, since the RP needs to trust the IdP to provide valid assertions representing the subscriber's authentication event." - id: CFAL-2_obj links: - rel: assessment-for href: "#CFAL-2_smt" name: objective prose: "Determine whether the RP validates each assertion received from the IdP to ensure its authenticity, integrity, and origin before establishing a session." - props: - value: EXAMINE name: method class: assessment-summary id: CFAL-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ARTC-10 and ARTVL-3. - id: CFAL-2_gdn name: guidance prose: This is a summative control. Assertion validation is assessed under ARTC-10 (traditional federation) and ARTVL-3 (subscriber-controlled wallets). - id: CFAL-3 title: Security Control Requirements props: - value: 2.1 C class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CFAL-3_smt name: statement prose: "All parties in the federation SHALL employ security controls, as discussed in Sec. 3.11." - id: CFAL-3_obj links: - rel: assessment-for href: "#CFAL-3_smt" name: objective prose: Determine whether the party undergoing assessment employs the security controls required in Section 3.11. - props: - value: EXAMINE name: method class: assessment-summary id: CFAL-3_asm-summary title: Assessment Method name: assessment-method prose: |- For IdPs/CSPs, satisfied by SECC-1, SECC-4, PSI-1 through PSI-3, and SSIN-2. For RPs, satisfied by SECC-2 through SECC-4, PSI-1 through PSI-3, and SSIN-1 through SSIN-3. - id: CFAL-3_gdn name: guidance prose: |- Section 3.11 establishes a tiered security controls baseline for federation participants. CSPs and IdPs must implement appropriately tailored controls from at least the SP 800-53 moderate baseline (or equivalent federal or industry standard such as FedRAMP). RPs must implement at least the low baseline, but RPs that request or process personal information must step up to the moderate baseline. All parties must also satisfy the minimum assurance-related controls for their systems. This is a summative control that relies on the conclusions of all applicable assessments related to Section 3.11 in this catalog. Compliance is demonstrated when all Section 3.11 requirements applicable to the assessed party are met. - id: FAL1-1 title: "Approved Cryptography: Assertion Signatures" props: - value: 2.2 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FAL1-1_smt name: statement prose: "At FAL1, the IdP SHALL sign the assertion using approved cryptography." - id: FAL1-1_obj links: - rel: assessment-for href: "#FAL1-1_smt" name: objective prose: Determine whether approved cryptography is used for the assertion signature. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL1-1_asm-examine name: assessment-method prose: Examine the IdP's assertion signing configuration to confirm that all assertions are cryptographically signed using approved algorithms and key sizes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FAL1-1_asm-test name: assessment-method prose: Test by generating an assertion from the IdP and verifying the presence of a cryptographic signature using approved cryptography. See SIGNA-4 for assessment of the specific signature mechanism and key type. - id: FAL1-1_gdn name: guidance prose: |- SP 800-63-4 defines approved cryptography as any algorithm, hash function, random bit generator, or similar technique that is FIPS-approved or NIST-recommended. For assertion signatures, the relevant standards are FIPS 186-5 (Digital Signature Standard, covering RSA, ECDSA, and EdDSA) and SP 800-131A (algorithm and key length transition schedules). Assessors should verify the IdP's signing algorithm and key size against these references. - id: FAL1-2 title: Signature Verification props: - value: 2.2 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FAL1-2_smt name: statement prose: The RP SHALL validate the signature using the verification key associated with the expected IdP. - id: FAL1-2_obj links: - rel: assessment-for href: "#FAL1-2_smt" name: objective prose: Determine whether the RP validates the assertion signature using the verification key associated with the expected IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL1-2_asm-examine name: assessment-method prose: "Examine the RP's signature-validation logic, configuration, and key-establishment documentation to verify that the RP selects the verification key based on the expected IdP identifier and validates assertion signatures only with the verification key associated with that IdP." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL1-2_asm-examine-2 name: assessment-method prose: "Examine the documented results of conformance testing to the IdP/RP implemented standards, protocols, and profiles if available (e.g., OIDC federation OP test)" - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FAL1-2_asm-test name: assessment-method prose: Test by setting up a test IdP and (1) Presenting a valid assertion signed by the expected IdP's key. Verify acceptance. (2) Presenting an assertion signed by a different trusted IdP's valid key. Verify rejection. (3) Presenting an assertion claiming the expected IdP as issuer but signed with a different IdP's key. Verify rejection. (4) Presenting an assertion signed with an unknown or untrusted key. Verify rejection. (5) Presenting an assertion with no signature. Verify rejection. - id: FAL1-2_gdn name: guidance prose: "This requirement ensures that the RP verifies the cryptographic signature on assertions to confirm their authenticity and integrity. The RP must use the verification key specifically associated with the expected IdP. For assessment of how the RP obtains and establishes that key through trusted mechanisms (discovery, registration, manual exchange, or federation authorities), see ICKM-1 and ICKM-2. For assessment of the specific signature mechanism type, see SIGNA-4." - id: FAL1-3 title: FAL1 Audience Restriction props: - value: 2.2 C class: index name: label - value: IdP class: target name: marking - value: FAL1 class: xal-level name: marking parts: - id: FAL1-3_smt name: statement prose: "At FAL1, the assertion SHALL be audience-restricted to a specific RP or set of RPs." - id: FAL1-3_obj links: - rel: assessment-for href: "#FAL1-3_smt" name: objective prose: Determine whether the IdP includes audience restrictions in all FAL1 assertions targeting specific RP(s). - props: - value: EXAMINE name: method class: assessment-summary id: FAL1-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AUDR-1. - id: FAL1-3_gdn name: guidance prose: "At all FALs, the IdP must include audience restrictions identifying the intended recipient(s). FAL1 allows multiple RPs per assertion, but the assertion must explicitly list all intended recipients. This prevents unscoped assertions that could be accepted by any RP. To reduce the risk of assertion replay, IdPs SHOULD issue assertions designated for a single audience whenever possible. Restriction to a single audience becomes mandatory at FAL2 and higher." - id: FAL1-4 title: FAL1 RP Audience Validation props: - value: 2.2 D class: index name: label - value: RP class: target name: marking - value: FAL1 class: xal-level name: marking parts: - id: FAL1-4_smt name: statement prose: "At FAL1, the RP SHALL validate that it is one of the targeted RPs for the given assertion." - id: FAL1-4_obj links: - rel: assessment-for href: "#FAL1-4_smt" name: objective prose: Verify that the RP validates each received assertion to ensure its own identifier appears in the audience restriction and rejects any assertion not explicitly targeted to it. - props: - value: EXAMINE name: method class: assessment-summary id: FAL1-4_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AUDR-2. - id: FAL1-4_gdn name: guidance prose: "The RP must check that its identifier appears in the assertion's audience field. This prevents replay attacks where assertions intended for other RPs are injected at an unintended RP. If the RP utilizes an IdP that lists multiple RPs in a single assertion at FAL1, confirm that the RP correctly handles assertions containing multiple RP identifiers." - id: FAL1-5 title: FAL1 RP Assertion Replay Protection props: - value: 2.2 E class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FAL1-5_smt name: statement prose: "Each RP in the [assertion] audience SHALL enforce replay protection mechanisms in the assertion to ensure that the same assertion is not accepted by a given RP multiple times." - id: FAL1-5_obj links: - rel: assessment-for href: "#FAL1-5_smt" name: objective prose: "Verify that the RP enforces replay protection by detecting and rejecting any assertion that has already been accepted, ensuring the same assertion cannot be used more than once." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL1-5_asm-examine name: assessment-method prose: "Examine RP documentation, federation configuration, code, and test results to confirm that replay detection mechanisms exist (e.g., nonce validation, assertion ID, and timestamp) and that repeated assertions are rejected." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL1-5_asm-examine-2 name: assessment-method prose: "Examine documented results of conformance testing to the standards, protocols, and profiles implemented by the RP, if available." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FAL1-5_asm-test name: assessment-method prose: "Test the RP configuration by replaying a previously accepted, valid assertion. Confirm rejection." - id: FAL1-5_gdn name: guidance prose: "Replay protection ensures that a given RP does not accept the same assertion more than once within its validity time window. At FAL1, where multi-audience assertions are permitted, each RP in the audience may accept the assertion once - but no individual RP may accept it a second time. Common replay detection mechanisms include tracking assertion identifiers, validating nonces, and enforcing timestamp-based expiration windows." - id: FAL2-1 title: Assertion Injection Protection props: - value: 2.3 A class: index name: label - value: RP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL2-1_smt name: statement prose: "At FAL2, the assertion SHALL be strongly protected from assertion injection attacks, as discussed in Sec. 3.11.1." - id: FAL2-1_obj links: - rel: assessment-for href: "#FAL2-1_smt" name: objective prose: Determine whether the RP implements strong protections against assertion injection attacks consistent with Sec. 3.11.1. - props: - value: EXAMINE name: method class: assessment-summary id: FAL2-1_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by implementing all of the following: FAL1-1, FAL1-2, FAL1-5, FAL2-2, ARTRQ-1, AUDR-1, ARTC-7, ARTC-10 items 3 and 5, AUDR-2, BCP-1 through BCP-10, FCP-1 through FCP-3." - id: FAL2-1_gdn name: guidance prose: |- An assertion injection attack in the context of a federated protocol consists of an attacker attempting to force an RP to accept or process an assertion or assertion reference in order to gain access to the RP or deny a legitimate subscriber access to the RP. The attacker does this by taking an assertion or assertion reference and injecting it into a vulnerable RP. A successful attacker can trick an RP into binding the attacker's session to the federated identifier in the assertion. The attacker's assertion could be either stolen from a legitimate subscriber or manufactured to perpetrate the attack. Protection from assertion injection attacks is recommended at all FALs and required at FAL2 and above. In all cases, the RP needs to take reasonable steps to prevent an attacker from presenting an injected assertion or assertion reference based on the nature of the RP software, the capabilities of the federation protocol in use, and the needs of the overall system. - id: FAL2-2 title: RP-Initiated Transactions props: - value: 2.3 B class: index name: label - value: RP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL2-2_smt name: statement prose: The federation transaction SHALL be initiated by the RP. - id: FAL2-2_obj links: - rel: assessment-for href: "#FAL2-2_smt" name: objective prose: "Verify that, at FAL2 and above, all federation transactions are initiated by the RP rather than the IdP." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL2-2_asm-examine name: assessment-method prose: Examine the RP's federation implementation and protocol configuration to confirm that all authentication requests originate from the RP. Verify that unsolicited IdP-initiated assertions are not accepted at FAL2 or above. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FAL2-2_asm-test name: assessment-method prose: Test the RP flow by delivering an assertion directly to the RP's federation endpoint without initiating the transaction at the RP. Confirm the RP rejects it. - id: FAL2-2_gdn name: guidance prose: "IdP-initiated federation processes are prohibited at FAL2 and FAL3 to prevent the RP from accepting unsolicited assertions and assertion references from the IdP. Inclusion and validation of RP-provided nonces in assertions is an indication of an RP-initiated transaction. However, this prohibition does not include processes in which an external party (e.g., the IdP or a federation authority) signals the RP to start a federation process with the IdP, allowing the RP to begin the federation transaction and securely await a response within that transaction." - id: FAL2-3 title: FAL2+ Audience Restriction props: - value: 2.3 C class: index name: label - value: IdP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL2-3_smt name: statement prose: "At FAL2, the assertion SHALL be audience restricted to a single RP." - id: FAL2-3_obj links: - rel: assessment-for href: "#FAL2-3_smt" name: objective prose: "Verify that, at FAL2 and above, the IdP includes an audience restriction in each assertion that designates exactly one RP as the intended recipient." - props: - value: EXAMINE name: method class: assessment-summary id: FAL2-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AUDR-1. - id: FAL2-3_gdn name: guidance prose: "At FAL2, assertions must be explicitly scoped to a single RP to prevent cross-RP assertion replay. Unlike FAL1, where multiple audiences are permitted, FAL2 and above require one-to-one binding between the assertion and the RP, ensuring that a captured assertion cannot be reused at another RP within the federation." - id: FAL2-4 title: RP Assertion Replay Protection Enforcement props: - value: 2.3 D class: index name: label - value: RP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL2-4_smt name: statement prose: The RP SHALL enforce replay protection mechanisms in the assertion. - id: FAL2-4_obj links: - rel: assessment-for href: "#FAL2-4_smt" name: objective prose: Determine whether the RP enforces replay protection mechanisms. - props: - value: EXAMINE name: method class: assessment-summary id: FAL2-4_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by FAL1-5. - id: FAL2-4_gdn name: guidance prose: "This is the FAL2/FAL3 restatement of the replay protection requirement from Sec. 2.2 (see FAL1-5). At FAL2+, multi-audience assertions are not permitted, so replay protection applies to single-audience assertions only. The assessment methodology and test procedures are the same as FAL1-5." - id: FAL2-5 title: Federated Identifier Privacy Protection props: - value: 2.3 E class: index name: label - value: IdP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL2-5_smt name: statement prose: "At FAL2, federated identifiers SHALL NOT contain plaintext personal information, such as usernames, email addresses, employee numbers, etc." - id: FAL2-5_obj links: - rel: assessment-for href: "#FAL2-5_smt" name: objective prose: "Verify that, at FAL2 and above, the IdP issues federated identifiers that do not include any plaintext personal information such as usernames, email addresses, employee numbers, or other directly identifying data." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL2-5_asm-examine name: assessment-method prose: "Examine the IdP's federated identifier construction rules, documentation, and representative issued identifiers to determine whether any federated identifier contains plaintext personal information, such as usernames, email addresses, employee numbers, names, phone numbers, or similar directly identifying values." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FAL2-5_asm-test name: assessment-method prose: Test by generating representative identifiers for sample subscriber accounts and verifying that no identifier reveals plaintext personal information. - id: FAL2-5_gdn name: guidance prose: "At FAL2 and higher, identifiers must be privacy-preserving and non-identifying. This protects subscriber privacy if assertions are intercepted." - id: FAL2-6 title: Pre-Established trust agreements props: - value: 2.3 F class: index name: label - value: IdP/RP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL2-6_smt name: statement prose: "At FAL2 [or higher], a trust agreement SHALL be established prior to the federation transaction taking place (i.e., a \"pre-established\" trust agreement), as discussed in Sec. 4.3.1." - id: FAL2-6_obj links: - rel: assessment-for href: "#FAL2-6_smt" name: objective prose: "Verify that, at FAL2 and above, a trust agreement between the IdP and RP is established and in effect before any federation transaction occurs." - props: - value: EXAMINE name: method class: assessment-summary id: FAL2-6_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by PETA-1, PETA-2, PETA-3, PETA-4, and PETA-7; additionally satisfied by PETA-6 where shared signaling is used, and by PETA-5 where FAL3 is permitted within the trust agreement." - id: FAL2-6_gdn name: guidance prose: |- At FAL2 and above, the IdP and RP must have a trust agreement in place before any federation transaction occurs. The agreement must cover all terms identified in Section 4.3.1, but those terms need not appear in a single document. The required content may be spread across multiple artifacts that, together, establish the technical, operational, and legal basis for trust. Acceptable artifacts can include binding documents such as contracts, memoranda of understanding, or service agreements, and non-binding but authoritative materials such as CSP practice statements, federation authority agreements, or published federation policies. For example, an IdP may publish a policy describing the assurance levels (xALs) it supports, the security controls it enforces, and the responsibilities of RPs. If the RP documents that it has received and accepted that policy, those terms satisfy the corresponding portion of the trust agreement. - id: FAL2-7 title: Key Protection props: - value: 2.3 G class: index name: label - value: IdP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL2-7_smt name: statement prose: "IdPs operated by or on behalf of federal agencies that present assertions at FAL2 or higher SHALL protect signing keys used to generate assertions with mechanisms validated at [FIPS140] Level 1 or higher." - id: FAL2-7_obj links: - rel: assessment-for href: "#FAL2-7_smt" name: objective prose: Determine whether the IdP protects assertion-signing keys using cryptographic modules validated at FIPS 140 Level 1 or higher. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL2-7_asm-examine name: assessment-method prose: "Examine the IdP's federation system documentation and configuration to verify that assertion-signing keys are generated, stored, and used only within a FIPS 140-validated cryptographic module. Confirm that the module appears on the CMVP validation list with a status of Active and is validated at Level 1 or higher." - id: FAL2-7_gdn name: guidance prose: "Assessment is required when: The IdP provides assertions to one or more federal agencies or the IdP is a federal agency." - id: FAL3-1 title: RP Verification of Subscriber Authenticator Control props: - value: 2.4 A class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: FAL3-1_smt name: statement prose: "At FAL3, the RP SHALL verify that the subscriber is in control of an authenticator in addition to the assertion." - id: FAL3-1_obj links: - rel: assessment-for href: "#FAL3-1_smt" name: objective prose: Determine whether the RP verifies subscriber control of an authenticator beyond the assertion at FAL3. - props: - value: EXAMINE name: method class: assessment-summary id: FAL3-1_asm-summary title: Assessment Method name: assessment-method prose: |- For holder-of-key assertions, satisfied by HKA-2. For bound authenticators, satisfied by RPPHBA-1 and RPPHBA-4. - id: FAL3-1_gdn name: guidance prose: |- This is a summative control. Compliance is demonstrated when the authenticator control mechanism(s) utilized by the RP have been assessed. At least one of these two mechanisms must be implemented to achieve compliance. At FAL3, the RP must verify both that it has received a valid assertion from the IdP and that the subscriber controls an authenticator in addition to the assertion. The subscriber-controlled authenticator is either identified in a holder-of-key assertion (see Sec. 3.15) or is an authenticator bound to the RP subscriber account (see Sec. 3.16). In both cases, the authenticator must be phishing-resistant, and the RP must verify proof of control before granting access. - id: FAL3-2 title: FAL3 Pre-Established Trust Agreements props: - value: 2.4 B class: index name: label - value: IdP/RP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: FAL3-2_smt name: statement prose: "At FAL3, a trust agreement SHALL be established prior to the federation transaction taking place (i.e., a \"pre-established\" trust agreement), as discussed in Sec. 4.3.1." - id: FAL3-2_obj links: - rel: assessment-for href: "#FAL3-2_smt" name: objective prose: Determine whether trust agreement artifact(s) are pre-established prior to the federation transaction. - props: - value: EXAMINE name: method class: assessment-summary id: FAL3-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by FAL2-6. - id: FAL3-3 title: Manual Identifier Establishment at FAL3 props: - value: 2.4 C class: index name: label - value: CSP/IdP/RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: FAL3-3_smt name: statement prose: "At FAL3, the identifiers for the CSP, IdP, and RP SHALL be established manually." - id: FAL3-3_obj links: - rel: assessment-for href: "#FAL3-3_smt" name: objective prose: Determine whether identifiers for all federation parties are established through manual processes at FAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL3-3_asm-examine name: assessment-method prose: "Examine configuration documentation to confirm that federation identifiers (e.g., entity IDs, issuer URIs) for the CSP, IdP, and RP are manually configured by authorized personnel. Verify that dynamic registration (Sec. 4.4.2) is not enabled for FAL3 transactions." - id: FAL3-3_gdn name: guidance prose: FAL3 prohibits dynamic or automated identifier establishment. Party identifiers must be manually configured through direct administrative action. This requirement reduces automated attack vectors and ensures human verification of party identity before establishing FAL3 connections. - id: FAL3-4 title: Identifier-Key Association props: - value: 2.4 D class: index name: label - value: CSP/IdP/RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: FAL3-4_smt name: statement prose: "Each [CSP, IdP, and RP] identifier SHALL be uniquely associated with the verification keys for the party represented." - id: FAL3-4_obj links: - rel: assessment-for href: "#FAL3-4_smt" name: objective prose: Determine whether each party identifier is uniquely bound to that party's verification keys. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL3-4_asm-examine name: assessment-method prose: "Examine configuration data or metadata to confirm that each federation participant's identifier (e.g., entity ID) maps to a distinct and authorized verification key or key set. Verify that no key is shared across different identifiers and that key rotation procedures preserve this one-to-one mapping." - id: FAL3-4_gdn name: guidance prose: "This control prevents key-substitution and impersonation attacks by ensuring that when a signature verifies under a stored key, it can only be attributed to the single, specific party whose identifier is bound to that key in the local configuration." - id: FAL3-5 title: Verification Key Transmission props: - value: 2.4 E class: index name: label - value: CSP/IdP/RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: FAL3-5_smt name: statement prose: "Verification keys SHALL be transmitted through a trusted mechanism, which could be manual or automated, as indicated in the trust agreement." - id: FAL3-5_obj links: - rel: assessment-for href: "#FAL3-5_smt" name: objective prose: "Determine whether verification keys are transmitted through a trusted mechanism, ensuring that key material is received from an authenticated and authorized source, and that the mechanism is documented as part of the trust agreement." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FAL3-5_asm-examine name: assessment-method prose: "Examine documented procedures to determine how verification keys are exchanged, confirming that the mechanism matches the trusted method specified in the relevant trust agreement artifact(s). Determine whether the key exchange mechanism is manual or automated. For automated mechanisms, confirm conformance with ICKM-2. For manual mechanisms, verify that procedures are in place to confirm that the requesting party's identity has been sufficiently verified. Verify that the mechanism for transmitting the verification key is accurately documented and made available to the key recipients." - id: FAL3-5_gdn name: guidance prose: "This requirement ensures that each participant obtains verification keys only from validated sources consistent with the established trust agreement. For example, a public-key certificate that represents the RP is uploaded to the IdP during a manual registration process. The RP is manually configured with a URL that it can use to download the IdP's public key. Alternatively, the IdP and RP could each upload their respective public keys to a federation authority and then download each other's keys from that same location. For a subscriber-controlled wallet, the RP could be manually configured with the URL that represents the CSP's public key. The RP fetches this public key and uses it to validate the signature of the attribute bundle presented by the subscriber-controlled wallet. See Sec. 3.6 for more information on the establishment, management, rotation, and revocation of keys and their association with identifiers." - id: RXAL-1 title: RP-Specified Minimum Acceptable xALs props: - value: 2.5 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-1_smt name: statement prose: IdPs SHALL support a mechanism for RPs to specify a set of minimum acceptable xALs as part of the trust agreement. - id: RXAL-1_obj links: - rel: assessment-for href: "#RXAL-1_smt" name: objective prose: Determine whether the IdP provides a mechanism for RPs to specify minimum acceptable xALs in the trust agreement. - props: - value: EXAMINE name: method class: assessment-summary id: RXAL-1_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by PETA-1, item (n)." - id: RXAL-1_gdn name: guidance prose: "PETA-1, item (n) requires the trust agreement artifact(s) to document the xALs required by the RPs the IdP supports." - id: RXAL-2 title: xAL Reporting props: - value: 2.5 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-2_smt name: statement prose: "The IdP SHALL always indicate the resulting xAL in the assertion, even if the request has not been met." - id: RXAL-2_obj links: - rel: assessment-for href: "#RXAL-2_smt" name: objective prose: Determine whether the IdP includes the actual xAL values achieved in every assertion. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RXAL-2_asm-examine name: assessment-method prose: |- The presence of xALs in assertions is satisfied by RXAL-3 (IAL), RXAL-4 (AAL), and RXAL-5 (FAL). Examine the IdP's federation processing logic, assertion-generation logic, configuration, and documentation to determine how the IdP handles transactions in which the RP requests xAL values that the IdP cannot satisfy. Determine whether the IdP issues an assertion containing the xAL values actually achieved, or fails the request and does not issue an assertion. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-2_asm-test name: assessment-method prose: "Test the IdP using a transaction in which the RP requests xAL values that the IdP cannot satisfy. If the IdP is designed to issue an assertion in that case, determine that the assertion contains the xAL values actually achieved rather than the xAL values requested by the RP. If the IdP is designed to fail the request in that case, determine that the transaction fails and that no assertion is issued." - id: RXAL-2_gdn name: guidance prose: "IdPs must report the actual IAL, AAL, and FAL in the assertion, regardless of what the RP requested. This allows RPs to make informed access decisions when requirements aren't met. For example, if the subscriber has an active session that was authenticated at AAL1, but the RP has requested AAL2, the IdP needs to prompt the subscriber for AAL2 authentication to increase the security of the session at the IdP during the subscriber's interaction at the IdP, if possible. The IdP sends the resulting AAL as part of the returned assertion, whether it is AAL1 (i.e., the step-up authentication request was not met) or AAL2 (i.e., the step-up authentication request was met successfully)." - id: RXAL-3 title: IAL Reporting props: - value: 2.5 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-3_smt name: statement prose: |- The IdP SHALL inform the RP of the following information for each federation transaction: The IAL of the subscriber account being presented to the RP, or an indication that no IAL claim is being made. - id: RXAL-3_obj links: - rel: assessment-for href: "#RXAL-3_smt" name: objective prose: Determine whether the IdP informs the RP of the IAL for each federation transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RXAL-3_asm-examine name: assessment-method prose: |- If the IAL is static: Satisfied by RXAL-6. If the IAL is variable: Examine the IdP assertion schema, metadata, or other documentation to confirm that the IdP provides either a claim or attribute conveying the IAL of the subscriber account, or a defined mechanism by which no IAL claim is made in the assertion format used by the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-3_asm-test name: assessment-method prose: "Test by initiating a transaction in which the IdP asserts an IAL value and determine that the assertion or associated message includes that value. Then, initiate a transaction in which the IdP omits an IAL claim and determine that the assertion output matches the IdP's documented no-claim mechanism." - id: RXAL-3_gdn name: guidance prose: The RP obtains this IAL information from a combination of the terms of the trust agreement (see Sec. 3.5) and information included in the assertion (see Sec. 4.9 and Sec. 5.8). - id: RXAL-4 title: AAL Reporting props: - value: 2.5 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-4_smt name: statement prose: |- The IdP SHALL inform the RP of the following information for each federation transaction: The AAL of the currently active session of the subscriber at the IdP, or an indication that no AAL claim is being made. - id: RXAL-4_obj links: - rel: assessment-for href: "#RXAL-4_smt" name: objective prose: Determine whether the IdP informs the RP of the AAL for each federation transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RXAL-4_asm-examine name: assessment-method prose: |- If the AAL is static: Satisfied by RXAL-6. If the AAL is variable: Examine the IdP assertion schema, metadata, or other documentation to confirm that the IdP provides either a claim or attribute conveying the AAL of the subscriber account, or a defined mechanism by which no AAL claim is made in the assertion format used by the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-4_asm-test name: assessment-method prose: "Test by initiating a transaction in which the IdP asserts an AAL value and determine that the assertion or associated message includes that value. Then, initiate a transaction in which the IdP omits an AAL claim and determine that the assertion output matches the IdP's documented no-claim mechanism." - id: RXAL-4_gdn name: guidance prose: The RP obtains this AAL information from a combination of the terms of the trust agreement (see Sec. 3.5) and information included in the assertion (see Sec. 4.9 and Sec. 5.8). - id: RXAL-5 title: FAL Reporting props: - value: 2.5 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-5_smt name: statement prose: |- The IdP SHALL inform the RP of the following information for each federation transaction: The FAL of the federation transaction. - id: RXAL-5_obj links: - rel: assessment-for href: "#RXAL-5_smt" name: objective prose: Determine whether the IdP informs the RP of the FAL for each federation transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RXAL-5_asm-examine name: assessment-method prose: |- If the FAL is static: Satisfied by RXAL-6. If the FAL is variable: Examine the IdP assertion schema, metadata, or other documentation to confirm that the IdP provides a claim or attribute that conveys the FAL of the federation transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-5_asm-test name: assessment-method prose: Test by initiating a transaction where the IdP asserts an FAL value - verify that the assertion or associated message includes that value. - id: RXAL-5_gdn name: guidance prose: The RP obtains this FAL information from a combination of the terms of the trust agreement (see Sec. 3.5) and information included in the assertion (see Sec. 4.9 and Sec. 5.8). - id: RXAL-6 title: Static xALs props: - value: 2.5 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-6_smt name: statement prose: "If the xAL is unchanging for all messages between the IdP and RP (e.g., enterprise scenarios in which all subscribers are identity-proofed at the same IAL and use the same authenticator type), the xAL information SHALL be included in the terms of the trust agreement between the IdP and RP." - id: RXAL-6_obj links: - rel: assessment-for href: "#RXAL-6_smt" name: objective prose: Determine whether the xAL information is included in the terms of the trust agreement between the IdP and RP when the xAL is unchanging for all messages. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RXAL-6_asm-examine name: assessment-method prose: |- Examine the trust agreement artifact(s) the IdP has established with its RPs to verify that values are stated for all static xALs. If PETA-1 item (m) documents fixed xAL values, confirm those values reflect the actual, unchanging xALs for all transactions between the IdP and each RP. - id: RXAL-6_gdn name: guidance prose: |- Assessment is required when: The xAL is the same for all messages between the IdP and RP (e.g., enterprise scenarios in which all subscribers are identity-proofed at the same IAL and use the same authenticator type). The IdP MAY indicate that no claim is made to the IAL or AAL for a given federation transaction. In such cases, no default value is assigned to the resulting xAL by the RP. That is, a federation transaction without an IAL declaration in either the trust agreement or the assertion is functionally considered to have "no IAL" and the RP cannot assume the account meets "IAL1," which is the lowest numbered IAL described in this suite. - id: RXAL-7 title: Variable xALs props: - value: 2.5 G class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-7_smt name: statement prose: "If the xAL could be within a range of possible values specified by the trust agreement, then sufficient information SHALL be included as part of the assertion contents to allow the RP to determine the xALs." - id: RXAL-7_obj links: - rel: assessment-for href: "#RXAL-7_smt" name: objective prose: Determine whether the IdP includes sufficient information in assertions for RPs to determine xALs when values vary within a range. - props: - value: EXAMINE name: method class: assessment-summary id: RXAL-7_asm-summary title: Assessment Method name: assessment-method prose: |- For IALs: Satisfied by the variable-xAL case in RXAL-3. For AALs: Satisfied by the variable-xAL case in RXAL-4. For FALs: Satisfied by the variable-xAL case in RXAL-5. - id: RXAL-7_gdn name: guidance prose: "Assessment is required when: The xAL is within a range of possible values specified by the trust agreement" - id: RXAL-8 title: xAL Requirements props: - value: 2.5 H class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-8_smt name: statement prose: "The RP SHALL determine the minimum IAL, AAL, and FAL that it is willing to accept for access to any offered functionality and assess all IdP assertions to ensure that these xALs have been met before granting access to protected resources." - id: RXAL-8_obj links: - rel: assessment-for href: "#RXAL-8_smt" name: objective prose: Determine whether the RP defines minimum acceptable xALs and validates that incoming assertions meet these requirements before granting access. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RXAL-8_asm-examine name: assessment-method prose: "Examine the RP's Digital Identity Acceptance Statement (DIAS) to confirm that it specifies the minimum IAL, AAL, and FAL required for each offered function. Verify that RP configuration, authorization logic, or policy enforcement mechanisms use these DIAS-defined minimums when evaluating xAL information. Confirm that the RP's evaluation process accepts xALs conveyed through assertions, trust-agreement terms, or both, consistent with how the IdP provides them." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-8_asm-test name: assessment-method prose: Test by presenting transactions where the xALs meet the DIAS-defined minimums - verify that access is granted. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-8_asm-test-2 name: assessment-method prose: Test by presenting transactions where any xAL falls below the DIAS-defined minimum - verify that access is denied. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-8_asm-test-3 name: assessment-method prose: Test by presenting transactions where required xAL information is absent from both the assertion and trust-agreement terms - verify that access is denied. - id: RXAL-8_gdn name: guidance prose: "This requirement mandates that the RP determine the minimum IAL, AAL, and FAL it is willing to accept for access to any offered functionality through the Digital Identity Risk Management (DIRM) process outlined in NIST SP 800-63-4, Section 3, which requires RPs to conduct impact assessments, select initial xALs based on impact, tailor controls if needed, and document decisions in a Digital Identity Acceptance Statement (DIAS). The RP must then assess all IdP assertions to ensure these xALs have been met before granting access to protected resources. The RP must validate the indicated xALs in the assertion (or trust agreement for fixed xALs) against its required minimums, denying access if these requirements are not met. If no xAL claim is made, the RP must treat it as \"no level\" without defaults (e.g., no assumption of IAL1)." - id: RXAL-9 title: Unmet xAL Requirements props: - value: 2.5 I class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-9_smt name: statement prose: "If IdP responses do not meet the requested parameters, the RP SHALL have a mechanism for addressing these requests (e.g., declining the request or routing the user to an exception handling process)." - id: RXAL-9_obj links: - rel: assessment-for href: "#RXAL-9_smt" name: objective prose: Determine that the RP has a defined mechanism for handling cases where IdP responses do not meet the RP's requested or required xAL parameters. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RXAL-9_asm-examine name: assessment-method prose: "Examine the RP's documentation and access-control logic to confirm the presence of a defined mechanism, such as request rejection, access denial, or an exception-handling workflow (such as a step-up mechanism) for transactions that do not satisfy the RP's minimum xAL requirements." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RXAL-9_asm-test name: assessment-method prose: "Test by presenting transactions in which asserted xALs do not meet the RP's required minimums, or required xAL information is missing, and verify that the RP invokes the documented handling mechanism and does not grant protected access unless and until the RP's documented exception process is successfully completed." - id: RXAL-9_gdn name: guidance prose: "If an IdP response does not satisfy the RP's required xALs, the RP must have a mechanism for handling the mismatch. Acceptable mechanisms include denying the request or redirecting the user to an exception-handling process." - id: RXAL-10 title: "IAL, AAL, & FAL Reporting" props: - value: 2.5 J class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-10_smt name: statement prose: "Consequently, the IdP SHALL provide the RP with sufficient information to determine the IAL, AAL, and the IdP's intended FAL for each federation transaction." - id: RXAL-10_obj links: - rel: assessment-for href: "#RXAL-10_smt" name: objective prose: "Determine whether the IdP provides the RP with sufficient information to determine the IAL, AAL, and FAL for each federation transaction." - props: - value: EXAMINE name: method class: assessment-summary id: RXAL-10_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by RXAL-3 (IAL), RXAL-4 (AAL), and RXAL-5 (FAL)." - id: RXAL-11 title: RP FAL Compliance props: - value: 2.5 K class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RXAL-11_smt name: statement prose: The RP SHALL ensure that it meets its obligations in the federation transaction for the FAL declared in the transaction. - id: RXAL-11_obj links: - rel: assessment-for href: "#RXAL-11_smt" name: objective prose: Verify that the RP fulfills all RP-specific requirements associated with the FAL declared in each federation transaction. - props: - value: EXAMINE name: method class: assessment-summary id: RXAL-11_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by the RP components of the following controls: CFAL-1, CFAL-2, CFAL-3, FAL1-2, FAL1-4, and FAL1-5; additionally by FAL2-1, FAL2-2, and FAL2-6 at FAL2 and above; and at FAL3, by FAL3-3, FAL3-4, FAL3-5, and ASRP-2, and as applicable, HKA-2 plus RPPHBA-1, RPPHBA-3, and RPPHBA-4 when holder-of-key assertions are used, or BAUTH-5 plus RPPHBA-1, RPPHBA-3, and RPPHBA-4 when bound authenticators are used." - id: RXAL-11_gdn name: guidance prose: "This requirement states that the RP must adhere to all RP-directed obligations for the FAL declared for the transaction, either in the assertion or the trust agreement. Compliance is demonstrated when the RP satisfies all controls relevant to that FAL." - id: PROXY-1 title: Proxy FAL Accuracy props: - value: 3.3.3 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PROXY-1_smt name: statement prose: "The FAL of the connection between the proxy and the downstream RP is considered to be the lowest FAL along the entire path, and the proxy SHALL accurately represent this to the downstream RP." - id: PROXY-1_obj links: - rel: assessment-for href: "#PROXY-1_smt" name: objective prose: Determine whether a proxy does not mask a lower level FAL from its inbound side. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PROXY-1_asm-examine name: assessment-method prose: "Examine the proxy's downstream federation configuration, xAL signaling logic, and applicable trust agreement terms to determine how the proxy communicates the resulting FAL to the downstream RP." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PROXY-1_asm-test name: assessment-method prose: "Test by initiating a proxied transaction in which the inbound federation leg is at a lower FAL than the downstream leg supports, and determine that the proxy represents the resulting overall FAL to the downstream RP as the lower FAL through the mechanism used in that deployment." - id: PROXY-1_gdn name: guidance prose: |- Assessment is required when: Proxied federation is used. When using a proxy, different federation processes could be used on either side of the proxy. To avoid accidental upgrading of the transaction giving a false perception of security, the overall FAL for the transaction is limited to the lowest FAL used on either side of the proxy. For example, if FAL1 is used inbound to the proxy, but FAL2 (assertion encryption) is used outbound from the proxy, the proxy has to report the entire transaction at FAL1 to the downstream RP. - id: PROXY-2 title: Proxy Compliance props: - value: 3.3.3 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PROXY-2_smt name: statement prose: "As a consequence, all normative requirements that apply to IdPs and RPs SHALL apply to proxies in their respective roles on each side." - id: PROXY-2_obj links: - rel: assessment-for href: "#PROXY-2_smt" name: objective prose: Determine whether a proxy functions as both a compliant IdP and a compliant RP. - props: - value: EXAMINE name: method class: assessment-summary id: PROXY-2_asm-summary title: Assessment Method name: assessment-method prose: This is a summative control. The proxy is assessed against all applicable IdP controls for its IdP-facing role and all applicable RP controls for its RP-facing role. - id: PROXY-2_gdn name: guidance prose: |- Assessment is required when: Proxied federation is used. A proxy needs to fulfill all of the normative requirements for both RPs and IdPs in order to be considered compliant, in addition to any proxy-specific requirements. - id: PROXY-3 title: Proxy Identifier props: - value: 3.3.3 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PROXY-3_smt name: statement prose: The federated identifier (see Sec. 3.4) of an assertion from a proxy SHALL indicate the proxy as the issuer of the assertion. - id: PROXY-3_obj links: - rel: assessment-for href: "#PROXY-3_smt" name: objective prose: Determine whether the federated identifier of an assertion from a proxy indicates the proxy as the issuer of the assertion. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PROXY-3_asm-examine name: assessment-method prose: "Examine the proxy's assertion templates, identifier-generation logic, or documentation to confirm that assertions issued by the proxy use an identifier that unambiguously represents the proxy itself as the issuer. Verify that no upstream IdP identifiers appear as the federated identifier in proxy-issued assertions." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PROXY-3_asm-test name: assessment-method prose: "Test by first receiving an assertion from the upstream IdP at the proxy and verifying the upstream IdP is the issuer in the assertion, then by generating an assertion from the proxy to the downstream RP and verifying that the proxy is the issuer in the assertion." - id: PROXY-3_gdn name: guidance prose: |- Assessment is required when: Proxied federation is used. When a proxy acts as an intermediary between an upstream IdP and downstream RP, it creates new assertions based on upstream assertions. The federated identifier in the proxy's assertion must show the proxy as the issuer, not the original upstream IdP. This ensures proper attribution and prevents confusion about the assertion's source. - id: FEDID-1 title: Unique Federated Identifiers props: - value: 3.4 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FEDID-1_smt name: statement prose: "When federated identifiers are used, the federated identifier SHALL be unique to that subscriber." - id: FEDID-1_obj links: - rel: assessment-for href: "#FEDID-1_smt" name: objective prose: Determine whether the IdP/CSP assigns identifiers that are unique to each subscriber. - props: - value: EXAMINE name: method class: assessment-summary id: FEDID-1_asm-summary title: Assessment Method name: assessment-method prose: |- This is a definitional statement, not an independently assessable requirement. Subject identifier uniqueness is an inherent property of any functioning IdP or CSP identity system. Enforcement of federated identifier uniqueness is satisfied by FEDID-2. - id: FEDID-1_gdn name: guidance prose: "Assessment is required when: Federated identifiers are used." - id: FEDID-2 title: Federated Identifier Single-Subscriber Association props: - value: 3.4 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FEDID-2_smt name: statement prose: Federated identifiers SHALL be associated with a single subscriber at the RP. - id: FEDID-2_obj links: - rel: assessment-for href: "#FEDID-2_smt" name: objective prose: Determine whether the RP associates each federated identifier with a single subscriber. - props: - value: EXAMINE name: method class: assessment-summary id: FEDID-2_asm-summary title: Assessment Method name: assessment-method prose: |- For IdP transactions: Satisfied by ARTC-11. For subscriber-controlled wallet transactions: Satisfied by ARTCN-11. - id: FEDID-2_gdn name: guidance prose: |- Assessment is required when: Federated identifiers are used. Different IdPs manage their subject identifiers independently and may assign identical values to different subscribers. The RP must never process a subject identifier without accounting for the issuer. Failure to do so creates a collision risk where subscribers from different IdPs are incorrectly mapped to the same RP subscriber account. - id: PPI-1 title: PPI Uniqueness props: - value: 3.4.1.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-1_smt name: statement prose: "When using pairwise pseudonymous identifiers within the assertions generated by the IdP for the RP, the IdP SHALL generate a different federated identifier for each RP (see Sec. 3.4.1.2) or set of RPs (see Sec. 3.4.1.3)." - id: PPI-1_obj links: - rel: assessment-for href: "#PPI-1_smt" name: objective prose: Determine whether the IdP generates unique pairwise pseudonymous identifiers for each RP or authorized set of RPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-1_asm-examine name: assessment-method prose: Examine the PPI generation algorithm to confirm that it produces different outputs for each RP or authorized RP set. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PPI-1_asm-test name: assessment-method prose: Test by logging the same subscriber into two unrelated RPs - verify different identifiers are asserted. - id: PPI-1_gdn name: guidance prose: |- Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used. In some circumstances, it is desirable to prevent the subscriber account from being easily linked at multiple RPs through the use of a common subject identifier. A pairwise pseudonymous identifier (PPI) allows an IdP to provide multiple distinct federated identifiers to different RPs for a single subscriber account. The use of a PPI prevents different RPs from colluding to track the subscriber using the federated identifier. - id: PPI-2 title: PPI Correlation Prevention props: - value: 3.4.1.1 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-2_smt name: statement prose: "If PPIs are used alongside identifying attributes, RPs SHALL establish privacy policies, processes, and procedures to prevent the correlation of subscriber data consistent with applicable legal and regulatory requirements." - id: PPI-2_obj links: - rel: assessment-for href: "#PPI-2_smt" name: objective prose: Determine whether RPs prevent correlation of subscriber data when using PPIs alongside identifying attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-2_asm-examine name: assessment-method prose: "Examine the privacy policies, data-handling procedures, and data-sharing agreements to confirm they explicitly address the use of PPIs together with identifying attributes and prohibit correlating subscriber records or activity across organizations except where required or explicitly permitted by applicable law or regulation." - id: PPI-2_gdn name: guidance prose: |- Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used. Some identity attributes such as names, physical addresses, phone numbers, email addresses, and others can be used to identify a subscriber outside of a federation transaction. When PPIs are used alongside these kinds of identifying attributes, it may still be possible for multiple colluding RPs to re-identify a subscriber by correlation across systems. For example, if two independent RPs each see the same subscriber identified with a different PPI, the RPs could still determine that the subscriber is the same person by comparing the name, email address, physical address, or other identifying attributes carried alongside the PPI in the respective assertions. - id: PPI-3 title: PPI Mapping as Subscriber Information props: - value: 3.4.1.1 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-3_smt name: statement prose: |- If a proxy is used: The mapping of a PPI to other identifiers is considered subscriber information and SHALL be treated in accordance with the requirements in Sec. 3.10.1. - id: PPI-3_obj links: - rel: assessment-for href: "#PPI-3_smt" name: objective prose: Determine whether the proxy treats PPI-to-identifier mappings as subscriber information subject to Section 3.10.1 requirements. - props: - value: EXAMINE name: method class: assessment-summary id: PPI-3_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by applying TSI-1, TSI-2, and TSI-3 to the PPI mapping data." - id: PPI-3_gdn name: guidance prose: |- Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used. In a proxied federation model (see Sec. 3.3.3), the upstream IdP may not be able to generate a PPI for the downstream RP, since the proxy could blind the IdP from knowing which RP is being accessed by the subscriber. In such situations, the PPI is generally established between the IdP and the federation proxy. Acting as an IdP, the proxy can provide a PPI to the downstream RP. Depending on the protocol, the federation proxy may need to map the PPI back to the associated identifiers from upstream IdPs in order to allow the identity protocol to function. In such cases, the proxy will be able to track and determine which PPIs represent the same subscriber at different RPs. - id: PPI-4 title: Anonymous PPIs props: - value: 3.4.1.2 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-4_smt name: statement prose: "The PPI SHALL contain no identifying information about the subscriber (e.g., username, email address, employee number)." - id: PPI-4_obj links: - rel: assessment-for href: "#PPI-4_smt" name: objective prose: Determine whether pairwise identifiers contain any identifying information about the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-4_asm-examine name: assessment-method prose: Examine the documentation and generation algorithm used by the IdP to assign a pairwise identifier to a subscriber at an RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PPI-4_asm-test name: assessment-method prose: "Test by generating an assertion containing a PPI, then inspecting the resulting identifier to confirm it contains no readable personal information, such as usernames, email addresses, or employee numbers." - id: PPI-4_gdn name: guidance prose: |- Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used. Pairwise identifiers are intended to protect the privacy of the subscriber and prevent collation of subscriber information. If the identifier itself has any identifying information in it, such as a username or employee number, this protection is lost. To prevent this, pairwise identifiers should be random and unguessable values or generated using information known only to the IdP, such as a secret key. If pairwise identifiers are not used, this requirement does not apply. - id: PPI-5 title: Unguessable PPIs props: - value: 3.4.1.2 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-5_smt name: statement prose: The PPI SHALL be difficult to guess by a party with access to information about the subscriber. - id: PPI-5_obj links: - rel: assessment-for href: "#PPI-5_smt" name: objective prose: Determine whether pairwise identifiers can be guessed or easily generated by a party with access to subscriber information. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-5_asm-examine name: assessment-method prose: "Examine the PPI generation algorithm to confirm that outputs cannot be predicted by a party with knowledge of the subscriber's attributes. Verify that generation relies on inputs known only to the IdP (e.g., a secret key) or uses an approved random bit generator." - id: PPI-5_gdn name: guidance prose: "Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used." - id: PPI-6 title: PPI Brute Force Protection props: - value: 3.4.1.2 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-6_smt name: statement prose: The PPI...SHALL provide sufficient entropy as to be unguessable by an attacker. - id: PPI-6_obj links: - rel: assessment-for href: "#PPI-6_smt" name: objective prose: Determine whether PPIs provide sufficient entropy to be unguessable by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-6_asm-examine name: assessment-method prose: "Examine the mechanism used to generate the Pairwise Pseudonymous Identifier (PPI). If the PPI is generated as a random value, verify it is produced by an approved random bit generator with a security strength of at least 112 bits. If the PPI is derived from other subscriber information (e.g., using a key derivation function), verify the derivation uses an approved key derivation function with a secret key of at least 112 bits of security strength, as discussed in SP 800-131A." - id: PPI-6_gdn name: guidance prose: |- Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used. Per NIST SP 800-131A Rev 2, Section 1.2.1, "a security strength of at least 112 bits is required at this time for applying cryptographic protection." This establishes the technical floor for what constitutes "sufficient entropy" to be "unguessable." - id: PPI-7 title: PPIs Unique to Each RP props: - value: 3.4.1.2 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-7_smt name: statement prose: "Unless the PPI is designated as shared by the trust agreement, the PPI SHALL be disclosed to only a single RP." - id: PPI-7_obj links: - rel: assessment-for href: "#PPI-7_smt" name: objective prose: Determine whether PPIs are disclosed to only a single RP unless designated as shared by the trust agreement artifact(s). - props: - value: EXAMINE name: method class: assessment-summary id: PPI-7_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by PPI-1. - id: PPI-7_gdn name: guidance prose: "Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used." - id: PPI-8 title: Justification and Consent for Shared PPIs props: - value: 3.4.1.3 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-8_smt name: statement prose: |- The same shared PPI SHALL be used for a specific set of RPs if all of the following criteria are met: (a) The trust agreement stipulates a shared PPI for a specific set of RPs. (b) The authorized party consents to and is notified of the use of a shared PPI. (c) Those RPs have a demonstrable relationship that justifies an operational need for the correlation, such as a shared security domain or shared legal ownership. (d) All RPs in the set of a shared PPI consent to being correlated in such a manner (i.e., one RP cannot request to have another RP's PPI without that other RP's knowledge and consent). - id: PPI-8_obj links: - rel: assessment-for href: "#PPI-8_smt" name: objective prose: Determine whether shared PPIs are issued only when all four criteria are satisfied. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-8_asm-examine name: assessment-method prose: "Examine trust agreement artifact(s) to confirm they stipulate a shared PPI for a specific, named set of RPs. Identify the authorized party and confirm documentation of their notification and consent to the shared PPI. Review documentation of the relationship between the RPs in the set to confirm a demonstrable operational need for correlation (e.g., shared security domain, shared legal ownership). Confirm that each RP in the set has documented consent to being correlated with the other RPs in the set." - id: PPI-8_gdn name: guidance prose: "Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used and common pairwise identifiers are requested by RPs." - id: PPI-9 title: Privacy Risks with Shared PPIs props: - value: 3.4.1.3 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-9_smt name: statement prose: The RPs SHALL conduct a privacy risk assessment to consider the privacy risks associated with requesting a shared PPI. See Sec. 7.2 for further privacy considerations. - id: PPI-9_obj links: - rel: assessment-for href: "#PPI-9_smt" name: objective prose: Determine whether the RPs have conducted a privacy risk assessment before requesting a common identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-9_asm-examine name: assessment-method prose: "Examine the RP privacy risk assessment specific to its use of a shared PPI, verifying that it addresses the risks of subscriber correlation across the RPs in the shared set." - id: PPI-9_gdn name: guidance prose: |- Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used and common pairwise identifiers are requested by RPs. If an RP requests a common pairwise identifier, a privacy risk assessment can help the RP consider the likelihood that requesting the same identifier for a subscriber at multiple RPs could create a problem for the applicant and the impact if a problem did occur. The RP should be able to justify any response it takes to identified privacy risks, including accepting the risk, mitigating the risk, and sharing the risk. If common pairwise identifiers are not used, this requirement does not apply. - id: PPI-10 title: Shared PPIs only between Authorized RPs props: - value: 3.4.1.3 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PPI-10_smt name: statement prose: The IdP SHALL ensure that only intended RPs are included in the set. - id: PPI-10_obj links: - rel: assessment-for href: "#PPI-10_smt" name: objective prose: Determine whether only RPs that have been explicitly configured to use a common identifier are given the common identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PPI-10_asm-examine name: assessment-method prose: Examine by comparing the IdP's configured shared PPI sets against the authorized RP sets documented in the trust agreement artifact(s). Confirm that no RP appears in a shared PPI set without corresponding authorization. - id: PPI-10_gdn name: guidance prose: "Assessment is required when: Pairwise Pseudonymous Identifiers (PPIs) are used and common pairwise identifiers are requested by RPs." - id: TRUST-1 title: Trust Agreement Establishment props: - value: 3.5 A class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-1_smt name: statement prose: |- A trust agreement SHALL address one or more of the following relationships: IdP to CSP: The IdP trusts the CSP to provide access to attributes in subscriber accounts, through either an IdP onboarding process or the issuance of attribute bundles. The IdP trusts the CSP's identity proofing processes used in the establishment of the subscriber account. CSP to IdP: The CSP trusts the IdP to accurately represent subscriber identity attributes to RPs and to not disclose identity attributes outside of agreed-upon functionality. The CSP trusts the IdP to protect the release of attributes, such as requiring authentication of the subscriber or the presentation of an activation factor before attributes are released. RP to IdP: The RP trusts the IdP to accurately represent subscriber identity attributes as provided by the CSP. The RP trusts the IdP to authenticate or identify the subscriber when representing an authentication event. IdP to RP: The IdP trusts the RP to only use the requested attributes for its stated purposes RP to CSP: The RP trusts the CSP to provide access to subscriber identity attributes through IdPs. The RP trusts that the CSP has identity-proofed the subscriber and is managing the subscriber account. - id: TRUST-1_obj links: - rel: assessment-for href: "#TRUST-1_smt" name: objective prose: Determine whether the trust agreement artifact(s) address the trust relationships applicable to the federation deployment. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-1_asm-examine name: assessment-method prose: "Examine the set of federation relationships and verify that the trust agreement artifact(s) address each one. For each relationship addressed, verify that the artifact(s) document the parties' specific trust expectations." - id: TRUST-2 title: TAs for All Federation Transactions props: - value: 3.5 B class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-2_smt name: statement prose: All federation transactions SHALL be governed by the terms of one or more trust agreements between the applicable parties. - id: TRUST-2_obj links: - rel: assessment-for href: "#TRUST-2_smt" name: objective prose: Determine whether all trust agreement requirements are met by all federation parties for all federation transactions. - props: - value: EXAMINE name: method class: assessment-summary id: TRUST-2_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by PETA-1 through PETA-7 for pre-established trust agreements, or SDTAE-1 through SDTAE-4 for subscriber-driven trust agreements; by MTA-1 through MTA-9 when a multilateral trust agreement is used; and by TAGREE-1 through TAGREE-3, CR-1, CR-2, CSCW-1, CSCW-2, and RSCW-1 when subscriber-controlled wallets are used." - id: TRUST-2_gdn name: guidance prose: "Trust agreements can take different forms, including formal contractual agreements, informal dynamic user agreements, and other documented bilateral or multilateral trust decisions by the parties in the federation. In many cases, trust agreements can be implemented using a trust framework, which formalizes a set of rules for parties to connect with each other. Trust frameworks are often used by federation authorities to formalize the rules for the federation being managed by the federation authority." - id: TRUST-3 title: TA Customer Experience props: - value: 3.5 C class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-3_smt name: statement prose: "The trust agreement SHALL establish customer experience requirements for the federation transaction, as discussed in Sec. 8." - id: TRUST-3_obj links: - rel: assessment-for href: "#TRUST-3_smt" name: objective prose: Determine whether trust agreements establish customer experience requirements for federation transactions that involve the user. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-3_asm-examine name: assessment-method prose: Examine the trust agreement artifact(s) to verify that they include customer experience requirements for the federation transaction. - id: TRUST-3_gdn name: guidance prose: Trust agreements must define customer experience parameters for federation transactions. Section 8 provides informative guidance that parties should consider when establishing these requirements. The specific customer experience requirements will vary based on the federation implementation and use case. - id: TRUST-4 title: TA CSP Proofing Process props: - value: 3.5 D class: index name: label - value: CSP/IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-4_smt name: statement prose: "The trust agreement SHALL include details of the proofing process used at the CSP for subscribers covered by the trust agreement, including any compensating controls and exception handling processes." - id: TRUST-4_obj links: - rel: assessment-for href: "#TRUST-4_smt" name: objective prose: "Determine whether the RP has access to the details of the proofing process used at the CSP for subscribers covered by the trust agreement, including any compensating controls and exception handling processes." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-4_asm-examine name: assessment-method prose: "Examine the trust agreement artifacts for details on the CSP proofing process, compensating controls, and exception-handling procedures." - id: TRUST-4_gdn name: guidance prose: "The required information may be conveyed directly by the CSP or relayed through the IdP, but it must be available to the relying party because the relying party is responsible for making risk based decisions." - id: TRUST-5 title: TA Subscriber Population props: - value: 3.5 E class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-5_smt name: statement prose: All trust agreements SHALL define a specific population of subscriber accounts to which the agreement is applicable. - id: TRUST-5_obj links: - rel: assessment-for href: "#TRUST-5_smt" name: objective prose: Determine whether each participating party identifies the set of subscriber accounts covered by the relationship and documents how that population is scoped. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-5_asm-examine name: assessment-method prose: Examine the trust agreement artifacts to verify that the population of subscriber accounts covered by the federated relationship is explicitly defined. - id: TRUST-5_gdn name: guidance prose: "The exact means of defining this population are out of scope for this document. In many cases, the population is defined as the full set of subscriber accounts that the CSP manages and makes available through an IdP. In other cases, the population is a demarcated subset of accounts that are available through an IdP. It is also possible for an RP to have a distinct trust agreement established with an IdP for a single subscriber account, such as in a subscriber-driven trust agreement. For pre-established trust agreement artifact(s), this requirement is also addressed by PETA-1 item (e)." - id: TRUST-6 title: Combined Trust Agreement Artifact(s) props: - value: 3.5 F class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-6_smt name: statement prose: "If more than one trust agreement is applicable to a federation transaction, the combined set of terms of all applicable trust agreements SHALL constitute the effective trust agreement of that transaction." - id: TRUST-6_obj links: - rel: assessment-for href: "#TRUST-6_smt" name: objective prose: Determine whether federation transactions are governed by an unambiguous set of trust agreement artifact(s) and whether each transaction meets the requirements of all applicable trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-6_asm-examine name: assessment-method prose: "Examine the set of trust agreement artifacts applicable to the federation relationship (e.g., bilateral contracts, Memoranda of Understanding (MOUs), Interconnection Security Agreements (ISAs), federation authority operating rules, or subscriber terms of service). Then, review a representative sample of federation transactions, verifying that each transaction adheres to the combined requirements of all applicable trust agreement artifacts." - id: TRUST-6_gdn name: guidance prose: "If the combination of multiple agreements creates the potential for conflicting requirements, the parties should have a documented process or order of precedence to resolve those conflicts." - id: TRUST-7 title: Expected and Acceptable xALs props: - value: 3.5 G class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-7_smt name: statement prose: "Trust agreements SHALL establish terms regarding expected and acceptable IALs, AALs, and FALs in connection with the federated relationship." - id: TRUST-7_obj links: - rel: assessment-for href: "#TRUST-7_smt" name: objective prose: "Determine whether the trust agreement artifact(s) establish terms regarding expected and acceptable IALs, AALs, and FALs for the federation relationship." - props: - value: EXAMINE name: method class: assessment-summary id: TRUST-7_asm-summary title: Assessment Method name: assessment-method prose: |- For pre-established trust agreement artifact(s): Satisfied by PETA-1 items (m) and (n). For subscriber-driven trust agreement artifact(s): Satisfied by SDTAE-1. - id: TRUST-8 title: Redress Coordination props: - value: 3.5 H class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-8_smt name: statement prose: "Trust agreements SHALL define necessary mechanisms and materials to coordinate redress and issues between the different participants in the federation, as discussed in Sec. 3.5.3." - id: TRUST-8_obj links: - rel: assessment-for href: "#TRUST-8_smt" name: objective prose: "Determine whether the trust agreement artifact(s) explicitly define the mechanisms (e.g., processes, protocols, escalation paths) and materials (e.g., templates, contact information, shared documentation) required for coordinating the resolution of issues and providing redress among all participants in the federation." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-8_asm-examine name: assessment-method prose: "Examine the trust agreement artifacts (e.g., federation agreements, operating rules, policies, metadata, onboarding documentation) for provisions addressing inter-party coordination of redress and issues, including: contact information or escalation paths for each party, procedures for routing subscriber complaints across party boundaries, defined responsibilities when issues span multiple parties, and timelines or service-level expectations for inter-party communications on subscriber issues." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: TRUST-8_asm-interview name: assessment-method prose: "Interview representatives from each federation party to verify awareness of and adherence to documented coordination mechanisms, including understanding of how to escalate issues to partner organizations and what information is exchanged during coordination." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: TRUST-8_asm-test name: assessment-method prose: "Test by simulating a cross-party redress scenario (e.g., a subscriber complaint involving inaccurate attributes from the CSP affecting an RP session) and observing whether the agreement's mechanisms enable effective coordination and resolution." - id: TRUST-8_gdn name: guidance prose: |- Federation transactions occur between multiple parties that are often controlled by multiple entities, and different stages of the federation transaction can lead to situations in which a subscriber would need to seek redress from the other parties. Federation, therefore, creates distributed responsibility for subscriber redress. A subscriber issue may originate at the RP but require resolution by the IdP or CSP, or may involve multiple parties simultaneously. Section 3.5.3 establishes specific redress obligations for each party type, but those individual requirements (covered in controls RR-1 through RR-6) address subscriber-facing mechanisms. This control addresses the coordination layer: how parties coordinate to resolve cross-organizational issues. The "mechanisms and materials" may include escalation procedures, contact directories, agreed-upon response timeframes, information-sharing protocols for issue investigation, and processes for jointly resolving disputes. In federations operating under a federation authority, these coordination mechanisms may be defined in the trust framework's operating rules. In bilateral relationships, they may be documented in contracts or service agreements. This control is a prerequisite for RR-2, which requires the RP to provide the subscriber with a means of initiating the redress process with the IdP or CSP. That subscriber-facing capability depends on the inter-party coordination mechanisms assessed here. This control does not assess whether subscribers have access to redress (see RR-1 through RR-6); it assesses whether the parties have established the infrastructure to work together when redress requires coordination. - id: TRUST-9 title: Data Retention Policies props: - value: 3.5 I class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-9_smt name: statement prose: Trust agreements SHALL declare the data retention policies expected of all parties. - id: TRUST-9_obj links: - rel: assessment-for href: "#TRUST-9_smt" name: objective prose: Determine whether trust agreement artifact(s) declare the data retention policies expected of each federation party. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-9_asm-examine name: assessment-method prose: "Examine the trust agreement artifacts (e.g., federation agreements, operating rules, data processing agreements, privacy policies referenced in agreements) for declarations of data retention policies applicable to each party, including: types of data subject to retention requirements, retention periods or criteria for determining retention periods, conditions under which retention requirements may differ (e.g., regulatory constraints, risk-based justifications), and expectations for data deletion upon account termination." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: TRUST-9_asm-interview name: assessment-method prose: Interview representatives from each federation party to confirm awareness of declared retention policies and how those policies are operationalized within their organization. - id: TRUST-9_gdn name: guidance prose: |- Data retention policies govern how long each party retains subscriber information, under what conditions, and what happens to that data when accounts are terminated. Declaring these policies in the trust agreement ensures that all parties share expectations and enables subscribers to understand how their data will be handled across the federation. Section 2.4.2 of SP 800-63B-4 requires verifiers to comply with applicable records retention policies and conduct risk management processes to determine retention periods when no mandatory requirements apply. The trust agreement should reflect these determinations for federation contexts. Different parties may have different retention requirements based on their regulatory environment (e.g., NARA schedules for federal agencies, industry-specific requirements). The trust agreement need not mandate uniform retention periods but must declare what each party's policies are so that expectations are clear. - id: TRUST-10 title: Subscriber Disclosure props: - value: 3.5 J class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-10_smt name: statement prose: "As such, the relevant terms of the trust agreement SHALL be made available to subscribers in clear and understandable language." - id: TRUST-10_obj links: - rel: assessment-for href: "#TRUST-10_smt" name: objective prose: Determine whether the relevant terms of the trust agreement are made available to subscribers in clear and understandable language. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-10_asm-examine name: assessment-method prose: "Examine the subscriber-facing disclosures of trust agreement terms (e.g., web pages, notices, runtime decision summaries) for clarity, readability (e.g. a Flesch-Kincaid score of 70 or higher), and avoidance of technical jargon. Verify that the disclosure mechanism is accessible to subscribers and that the content addresses the terms relevant to the subscriber's participation in the federation." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: TRUST-10_asm-test name: assessment-method prose: "Test by attempting to access trust agreement terms through subscriber-facing channels, then evaluating whether the terms are presented in plain language appropriate to the expected subscriber population." - id: TRUST-10_gdn name: guidance prose: |- Although subscribers are not generally directly involved in the trust agreement's terms, they are affected by those terms and the resulting federation transactions. This requirement ensures that subscribers can understand how their identity information will be handled, what attributes may be shared, and what rights and recourse they have. As stated in section 7.2, "a link to a complex, legalistic privacy policy or general terms and conditions that a substantial number of subscribers do not read or understand is never an effective notice." The disclosure must be genuinely comprehensible, not merely technically available. Common disclosure methods identified in Section 3.5 include: providing a subscriber-accessible web page with relevant terms, sending a notice to the subscriber, or displaying a summary of the terms during a runtime decision, with an option to review the full terms. The party responsible for disclosure varies based on the trust agreement. Section 3.5 does not specify which party must provide notice; parties may use contracts or trust framework policies to determine responsibility. This control assesses whether disclosure occurs and meets clarity requirements, regardless of which party provides it. SP 800-63A-4 Section 8.1.1 provides guidance applicable here: write in plain language, avoid technical jargon, tailor language to the literacy level of the intended population, use active voice and conversational style, and follow good information design practices. Related controls PETA-3 (4.3.1 C) and SDTAE-1 (4.3.2 A) address specific disclosure requirements for pre-established and subscriber-driven trust agreements, respectively. - id: TRUST-11 title: Disclosure Security Review props: - value: 3.5 K class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUST-11_smt name: statement prose: "The terms of the trust agreement SHALL be reviewed by all parties (e.g., the CSP, IdP, RP, or a federation authority) that are responsible for informing the subscriber of the terms of the trust agreement before the disclosure to the subscriber occurs in order to avoid revealing sensitive security information." - id: TRUST-11_obj links: - rel: assessment-for href: "#TRUST-11_smt" name: objective prose: Determine whether all parties responsible for informing subscribers of trust agreement terms have reviewed those terms before disclosure to avoid revealing sensitive security information. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUST-11_asm-examine name: assessment-method prose: "Examine documentation of the review process, including records of which parties participated in the review, what was reviewed, and any redactions or modifications made to protect sensitive security information. Examine the subscriber-facing disclosure to verify that sensitive security details (e.g., security monitoring capabilities, fraud detection thresholds) are not exposed." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: TRUST-11_asm-interview name: assessment-method prose: Interview representatives from each party responsible for subscriber disclosure to confirm that a review occurred prior to disclosure and to understand the criteria used to identify and protect sensitive security information. - id: TRUST-11_gdn name: guidance prose: |- This control is a prerequisite for TRUST-10, which requires that trust agreement terms be disclosed to subscribers in clear, understandable language. While subscribers need sufficient information to understand how their data is handled, the disclosure must not inadvertently reveal security details that could be exploited by attackers. Sensitive security information that should be protected from disclosure may include specific fraud-detection mechanisms, security-monitoring thresholds, incident-response procedures, cryptographic implementation details beyond what is necessary for subscriber understanding, and internal system architecture that could aid targeted attacks. The review must include all parties responsible for informing subscribers. Which parties bear this responsibility depends on the trust agreement structure: in bilateral agreements, the IdP and RP coordinate directly; in multilateral agreements, the federation authority may also be involved. - id: MTA-1 title: MTA Vetting Practices props: - value: 3.5.2 A class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-1_smt name: statement prose: The trust agreement SHALL enumerate the required practices for vetting all parties. - id: MTA-1_obj links: - rel: assessment-for href: "#MTA-1_smt" name: objective prose: Determine whether the multilateral trust agreement (MTA) artifact(s) enumerate(s) the required practices for vetting all parties. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-1_asm-examine name: assessment-method prose: "Examine trust framework documentation (e.g., operating rules, membership agreements, onboarding policies) for enumeration of vetting practices applicable to CSPs, IdPs, and RPs." - id: MTA-1_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. This control applies to multilateral trust agreements in which a federation authority facilitates onboarding of CSPs, IdPs, and RPs. The subsequent requirements in Section 3.5.2 (MTA-2 and following) establish minimum criteria that vetting must address. This control assesses whether the trust agreement documents vetting practices; the substantive vetting criteria are assessed separately. NISTIR 8149 (Developing Trust Frameworks to Support Identity Federations) provides additional context on conformance assessment approaches, including self-assessment, third-party assessment, and audit, which federations may use to implement vetting. - id: MTA-2 title: MTA Vetting Responsibility props: - value: 3.5.2 B class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-2_smt name: statement prose: The trust agreement ... SHALL indicate the party or parties that are responsible for performing the vetting process. - id: MTA-2_obj links: - rel: assessment-for href: "#MTA-2_smt" name: objective prose: Determine whether the multilateral trust agreement artifact(s) indicate(s) the party or parties responsible for performing the vetting process. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-2_asm-examine name: assessment-method prose: "Examine trust framework documentation (e.g., operating rules, membership agreements, onboarding policies) for an explicit designation of the party or parties responsible for vetting CSPs, IdPs, and RPs." - id: MTA-2_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. This control complements MTA-1, which requires enumeration of vetting practices. This control ensures accountability by requiring a clear assignment of vetting responsibility. Section 3.5.2 notes that "the federation authority can outsource the vetting process to another party, but the federation authority is ultimately responsible for the results of the vetting process." The trust agreement must make clear who performs vetting, whether that is the federation authority itself, a delegated third-party assessor, or another arrangement. Outsourcing vetting does not transfer ultimate accountability from the federation authority. - id: MTA-3 title: "MTA Vetting: CSP Subscriber Proofing" props: - value: 3.5.2 C class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-3_smt name: statement prose: |- At a minimum, the vetting of CSPs, IdPs, and RPs SHALL establish that: (1) CSPs identity proof subscriber accounts in accordance with [SP800-63A]. - id: MTA-3_obj links: - rel: assessment-for href: "#MTA-3_smt" name: objective prose: Determine whether the federation authority's vetting process establishes that CSPs identity proof subscriber accounts in accordance with SP 800-63A. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-3_asm-examine name: assessment-method prose: "Examine federation authority vetting procedures, checklists, and assessment criteria to verify that CSP identity proofing practices are evaluated against SP 800-63A requirements for each IAL offered by the CSP." - id: MTA-3_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. This is the first of six minimum vetting criteria specified in Section 3.5.2. The federation authority's vetting process must verify that CSPs perform identity proofing consistent with SP 800-63A requirements for the applicable IAL(s) supported by the federation. SP 800-63A-4 establishes requirements for identity proofing at IAL1, IAL2, and IAL3, including evidence collection, validation, and verification processes. The depth of vetting should be commensurate with the IALs the federation supports. - id: MTA-4 title: "MTA Vetting: CSP Subscriber Onboarding" props: - value: 3.5.2 D class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-4_smt name: statement prose: |- The vetting of CSPs, IdPs, and RPs SHALL establish that: (2) CSPs onboard subscriber accounts (including attributes, derived attribute values, and attribute bundles) to IdPs in a secure fashion in adherence to the requirements in Sec. 4.1 or Sec. 5.1, as applicable. - id: MTA-4_obj links: - rel: assessment-for href: "#MTA-4_smt" name: objective prose: "Determine whether the federation authority's vetting process establishes that CSPs onboard subscriber accounts to IdPs securely in accordance with Section 4.1 (general-purpose IdPs) or Section 5.1 (subscriber-controlled wallets), as applicable to the federation model." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-4_asm-examine name: assessment-method prose: "Examine federation authority vetting procedures, checklists, and assessment criteria to verify that CSP onboarding practices are evaluated against the requirements in Section 4.1 for IdP account provisioning or Section 5.1 for attribute bundle issuance to subscriber-controlled wallets, as applicable to the federation's supported models." - id: MTA-4_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. Section 4.1 governs how CSPs provision subscriber accounts to general-purpose IdPs, including the disclosure of provisioning methods in the trust agreement, and the relationship between subscriber accounts and federation-specific attributes. Section 5.1 governs how CSPs issue attribute bundles to subscriber-controlled wallets, including the steps for subscriber identity verification, wallet activation, key generation, and attribute bundle creation. The applicable section depends on the federation model: Section 4.1 applies when the federation uses general-purpose IdPs hosted on remote services; Section 5.1 applies when the federation supports subscriber-controlled wallets. A federation may support both models, in which case vetting must address both sections. - id: MTA-5 title: "MTA Vetting: Subscriber Authenticators" props: - value: 3.5.2 E class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-5_smt name: statement prose: |- The vetting of CSPs, IdPs, and RPs SHALL establish that: (3) The authenticators used to authenticate the subscriber at the IdP (during a federation transaction) or CSP (while issuing attribute bundles to a subscriber controlled wallet) are used in accordance with [SP800-63B]. - id: MTA-5_obj links: - rel: assessment-for href: "#MTA-5_smt" name: objective prose: Determine whether the federation authority's vetting process establishes that the authenticators used to authenticate subscribers at the IdP and/or CSP comply with SP 800-63B requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-5_asm-examine name: assessment-method prose: "Examine federation authority vetting procedures, checklists, and assessment criteria to verify that authenticator usage is evaluated against SP 800-63B requirements for each AAL supported by the IdP or CSP." - id: MTA-5_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. This requirement addresses two authentication contexts: (1) authentication of the subscriber at the IdP during a federation transaction with a general-purpose IdP, and (2) authentication of the subscriber at the CSP when issuing attribute bundles to a subscriber-controlled wallet. SP 800-63B-4 establishes requirements for authenticator types, authenticator lifecycle management, and authentication processes at AAL1, AAL2, and AAL3. The depth of vetting should be commensurate with the AALs the federation supports. - id: MTA-6 title: "MTA Vetting: IdP Assertions" props: - value: 3.5.2 F class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-6_smt name: statement prose: |- The vetting of CSPs, IdPs, and RPs SHALL establish that: (4) The assertions generated by IdPs adhere to the requirements in Sec. 4.9 or Sec. 5.8, as applicable. - id: MTA-6_obj links: - rel: assessment-for href: "#MTA-6_smt" name: objective prose: "Determine whether the federation authority's vetting process establishes that assertions generated by IdPs comply with the requirements in Section 4.9 (general-purpose IdPs) or Section 5.8 (subscriber-controlled wallets), as applicable." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-6_asm-examine name: assessment-method prose: "Examine the federation authority's vetting procedures, checklists, assessment criteria, and records to determine whether the vetting process for IdPs addresses the applicable assertion-content requirements in Sec. 4.9 for general-purpose IdPs or Sec. 5.8 for subscriber-controlled wallets, as applicable to the supported federation models." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: MTA-6_asm-test name: assessment-method prose: Test by selecting a representative vetted IdP or subscriber-controlled wallet implementation and determining that the vetting record shows assessment of the applicable assertion-content requirements. - id: MTA-6_gdn name: guidance prose: "Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement." - id: MTA-7 title: "MTA Vetting: RP Data Handling" props: - value: 3.5.2 G class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-7_smt name: statement prose: |- The vetting of CSPs, IdPs, and RPs SHALL establish that: (5) RPs adhere to requirements for handling subscriber attribute data, such as retention, aggregation, deletion, and disclosure to third parties. - id: MTA-7_obj links: - rel: assessment-for href: "#MTA-7_smt" name: objective prose: "Determine whether the federation authority's vetting process establishes that RPs adhere to requirements for handling subscriber attribute data, including retention, aggregation, deletion, and disclosure to third parties." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-7_asm-examine name: assessment-method prose: |- Examine federation authority vetting procedures, checklists, and assessment criteria to verify that RP data-handling practices are included in the vetting scope. The federation authority's vetting process must address the following controls: (1) Retention/Storage: SSIN-1 (3.11.3), SSIN-3 (3.11.3), CAARP-1 (4.6.6); (2) Deletion: SSIN-2 (3.11.3), SSIN-3 (3.11.3), CAARP-5 (4.6.6); (3) Disclosure: CAARP-2 (4.6.6), CAARP-6 (4.6.6, Federal only); (4) Transmission: TSI-4 (3.10.1), TSI-5 (3.10.1), CAARP-4 (4.6.6); and (5)Usage Limitation: CAARP-3 (4.6.6). - id: MTA-7_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. Before adding an RP to the federation, the federation authority must ensure that the party in question handles all subscriber information appropriately. This is a summative control that verifies that the federation authority's vetting process complies with RP data-handling requirements. The detailed requirements are assessed against the controls in Section 3.10.1 (limitations on transmission of subscriber information), Section 3.11.3 (storage requirements and deletion upon account termination), and Section 4.6.6 (handling of attributes collected outside the federation transaction). - id: MTA-8 title: "MTA Vetting: Protocol Profiles" props: - value: 3.5.2 H class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-8_smt name: statement prose: |- The vetting of CSPs, IdPs, and RPs SHALL establish that: (6) RP and IdP systems use agreed-upon profiles of federation protocols, as specified by the federation authority. - id: MTA-8_obj links: - rel: assessment-for href: "#MTA-8_smt" name: objective prose: Determine whether the federation authority documents acceptable profiles and that IdPs and RPs follow these profiles. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-8_asm-examine name: assessment-method prose: "Examine the federation authority's documentation of acceptable profiles and its enforcement of adherence to those profiles (e.g., SAML 2.0 Web Browser SSO Profile, OpenID Connect Core, specific FAPI profiles)." - id: MTA-8_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. The federation authority determines which federation protocol profiles are approved for use within the federation and must ensure that all federation participants use only these profiles. The federation authority must verify that IdPs and RPs adhere to these profiles before they are added to the federation. NISTIR 8149 Section 5.7 (Technical Specifications) notes that trust frameworks promote interoperability by identifying common protocols and standards. The federation authority's specifications should rely on existing profiles whenever possible, but may create their own profiles if necessary. Whether requiring existing profiles or designing a new profile, vendor support should be carefully considered. - id: MTA-9 title: MTA Periodic Reevaluation props: - value: 3.5.2 I class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MTA-9_smt name: statement prose: "Federation authorities SHALL periodically reevaluate members for compliance, in terms disclosed in the trust agreement." - id: MTA-9_obj links: - rel: assessment-for href: "#MTA-9_smt" name: objective prose: Determine whether the federation authority periodically reevaluates members for compliance and whether the reevaluation schedule is disclosed in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MTA-9_asm-examine name: assessment-method prose: "Examine trust agreement artifact(s) for disclosed reevaluation terms (e.g., frequency, scope, criteria). Examine the federation authority records of completed reevaluations to verify that the schedule is followed." - id: MTA-9_gdn name: guidance prose: |- Assessment is required when: A federation authority facilitates the inclusion of CSPs, IDPs, and RPs under a trust agreement. Initial vetting (MTA-1 through MTA-8) establishes baseline compliance at onboarding. This control ensures ongoing compliance throughout membership. The trust agreement must disclose the reevaluation terms so members understand their continuing obligations. Reevaluation frequency may vary based on risk, federation model, or member role. The trust agreement should specify whether reevaluation applies uniformly or varies by party type (CSP, IdP, RP). Reevaluation may include reassessment of the criteria established in MTA-3 through MTA-8. - id: RR-1 title: RP Subscriber Redress props: - value: 3.5.3 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RR-1_smt name: statement prose: "For matters that involve the RP subscriber account (including any attributes stored in the account), RP functionality, bound authenticators, RP allowlists, and other items under the RP's control, the RP SHALL provide a clear and accessible means of redress to the subscriber." - id: RR-1_obj links: - rel: assessment-for href: "#RR-1_smt" name: objective prose: Determine whether the RP provides a clear and accessible means for subscribers to seek redress for matters under the RP's control. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RR-1_asm-examine name: assessment-method prose: "Examine RP documentation, subscriber-facing interfaces, and help resources for redress mechanisms. Verify that redress mechanisms are clearly presented and accessible to subscribers, and that they address RP subscriber accounts, attributes stored by the RP, RP functionality, bound authenticators, and RP allowlists. Review RP documentation to determine whether there are any other items under the RP's control, and if so, verify that redress mechanisms are sufficient." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RR-1_asm-test name: assessment-method prose: Test the redress process by locating and initiating it as a test subscriber to verify accessibility. - id: RR-1_gdn name: guidance prose: |- Section 3.5.3 establishes that the RP is the subscriber's primary point of access to the federated system, and in some cases, subscribers may be unaware that an IdP is involved. This control addresses redress for matters solely within the RP's control. "Clear and accessible" means the redress mechanism must be easy to find and use. Complex processes, hidden contact information, or technical jargon that prevents subscribers from understanding how to seek redress would fail this requirement. - id: RR-2 title: RP Redress Routing props: - value: 3.5.3 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RR-2_smt name: statement prose: "For matters that involve the IdP or CSP, the RP SHALL provide the subscriber with a means of initiating the redress process with the IdP or CSP, as appropriate." - id: RR-2_obj links: - rel: assessment-for href: "#RR-2_smt" name: objective prose: Determine whether the RP provides subscribers with a means of initiating the redress process with the IdP or CSP for matters outside the RP's control. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RR-2_asm-examine name: assessment-method prose: "Examine RP documentation, subscriber-facing interfaces, and help resources for mechanisms that direct subscribers to IdP or CSP redress processes when appropriate. Verify that the RP distinguishes between matters it handles directly (RR-1) and matters requiring IdP or CSP involvement." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RR-2_asm-test name: assessment-method prose: "Test the RP's interfaces by attempting to locate information for initiating redress with the IdP or CSP, acting as a test subscriber." - id: RR-2_gdn name: guidance prose: |- Since the RP is typically the subscriber's primary point of access to the federated system, subscribers may not know how to reach the IdP or CSP, or when an issue is more appropriately addressed by the IdP or CSP. This control ensures the RP acts as a bridge, directing subscribers to the appropriate party for matters outside the RP's control. TRUST-8 (Redress Coordination) establishes the inter-party infrastructure that enables this routing. This control assesses whether the RP makes that routing accessible to subscribers. - id: RR-3 title: IdP Subscriber Redress props: - value: 3.5.3 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RR-3_smt name: statement prose: "For matters that involve the use of the subscriber account in federation transactions, including attribute values and derived attribute values made available over federation transactions, IdP functionality, holder-of-key authenticators, IdP allowlists, and other items in the IdP's control, the IdP SHALL provide a clear and accessible means of redress to the subscriber." - id: RR-3_obj links: - rel: assessment-for href: "#RR-3_smt" name: objective prose: Determine whether the IdP provides clear and accessible means for subscribers to seek redress for matters under the IdP's control. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RR-3_asm-examine name: assessment-method prose: "Examine IdP documentation, subscriber-facing interfaces, and help resources for redress mechanisms. Verify that redress mechanisms are clearly presented and accessible to subscribers, and that they address subscriber account usage in federation transactions, attribute values, and, if applicable, derived attribute values, IdP functionality, holder-of-key authenticators, and IdP allowlists. Review IdP documentation to determine whether there are any other items under the IdP's control, and if so, verify that redress mechanisms are sufficient." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RR-3_asm-test name: assessment-method prose: Test by locating and initiating the redress process to verify clarity and accessibility. - id: RR-3_gdn name: guidance prose: |- This is the IdP counterpart to RR-1 (RP Subscriber Redress). This control addresses redress for matters solely within the IdP's control. "Clear and accessible" means the redress mechanism must be easy to find and use. Complex processes, hidden contact information, or technical jargon that prevents subscribers from understanding how to seek redress would fail this requirement. - id: RR-4 title: "IdP Redress Routing: RP" props: - value: 3.5.3 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RR-4_smt name: statement prose: "For matters that also involve a particular RP, the IdP SHALL provide the subscriber with a means of initiating the redress process with the RP." - id: RR-4_obj links: - rel: assessment-for href: "#RR-4_smt" name: objective prose: Determine whether the IdP provides subscribers with a means of initiating the redress process with the RP for matters that involve a particular RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RR-4_asm-examine name: assessment-method prose: "Examine IdP documentation, subscriber-facing interfaces, and help resources for mechanisms that direct subscribers to RP redress processes when appropriate. Verify that the IdP distinguishes between matters it handles directly (RR-3) and matters requiring RP involvement." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RR-4_asm-test name: assessment-method prose: "Test the IdP's interfaces by attempting to locate information to initiate redress with the RP, acting as a test subscriber." - id: RR-4_gdn name: guidance prose: |- This is the IdP counterpart to RR-2 (RP Redress Routing). Subscribers may contact the IdP for issues that are more appropriately resolved by a specific RP (e.g., RP mishandling attributes received from the IdP, RP subscriber account issues). This control ensures the IdP directs subscribers to the appropriate RP. TRUST-8 (Redress Coordination) establishes the inter-party infrastructure that enables this routing. This control assesses whether the IdP makes that routing accessible to subscribers. - id: RR-5 title: "IdP Redress Routing: CSP" props: - value: 3.5.3 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RR-5_smt name: statement prose: "For matters that involve a subscriber account that has been made available to the IdP, the IdP SHALL provide the subscriber with a means of initiating the redress process with the CSP." - id: RR-5_obj links: - rel: assessment-for href: "#RR-5_smt" name: objective prose: Determine whether the IdP provides subscribers with a means of initiating the redress process with the CSP for matters involving the CSP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RR-5_asm-examine name: assessment-method prose: "Examine IdP documentation, subscriber-facing interfaces, and help resources for mechanisms that direct subscribers to CSP redress processes when appropriate. Verify that the IdP distinguishes between matters it handles directly (RR-3) and matters requiring CSP involvement." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RR-5_asm-test name: assessment-method prose: "Test the IdP's interfaces by attempting to locate information for initiating redress with the CSP, acting as a test subscriber." - id: RR-5_gdn name: guidance prose: |- When the IdP is separate from the CSP, the subscriber may contact the IdP for issues that are more appropriately resolved by CSP (e.g., identity proofing errors, incorrect attributes in the CSP subscriber account, authenticator binding issues). This control ensures the IdP correctly redirects subscribers to the CSP. TRUST-8 (Redress Coordination) establishes the inter-party infrastructure that enables this routing. This control assesses whether the IdP makes that routing accessible to subscribers. - id: RR-6 title: CSP Redress props: - value: 3.5.3 F class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RR-6_smt name: statement prose: "For matters that involve the subscriber account, including identity attributes and authenticators in the subscriber account, the CSP SHALL provide the subscriber with a clear and accessible means of redress." - id: RR-6_obj links: - rel: assessment-for href: "#RR-6_smt" name: objective prose: Determine whether the CSP provides a clear and accessible means for subscribers to seek redress for matters involving the CSP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RR-6_asm-examine name: assessment-method prose: "Examine CSP documentation, subscriber-facing interfaces, and help resources for redress mechanisms. Verify that redress mechanisms are clearly presented and accessible to subscribers, and that all potential areas of redress are addressed, including the CSP subscriber account, identity attributes (if collected), and authenticators. Review CSP documentation to determine whether there are any other items under the CSP's control, and if so, verify that redress mechanisms are sufficient." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RR-6_asm-test name: assessment-method prose: Test the redress process by attempting to locate and initiate it as a test subscriber to verify accessibility. - id: RR-6_gdn name: guidance prose: |- This is the CSP counterpart to RR-1 (RP Subscriber Redress) and RR-3 (IdP Subscriber Redress). This control addresses redress for matters solely within the CSP's control. "Clear and accessible" means the redress mechanism must be easy to find and use. Complex processes, hidden contact information, or technical jargon that prevents subscribers from understanding how to seek redress would fail this requirement. - id: ICKM-1 title: Secure Discovery and Registration props: - value: 3.6 A class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ICKM-1_smt name: statement prose: The discovery and registration processes SHALL be established in a secure fashion as defined by the trust agreement that governs the federation transaction. - id: ICKM-1_obj links: - rel: assessment-for href: "#ICKM-1_smt" name: objective prose: Determine whether discovery and registration processes are established securely in accordance with the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ICKM-1_asm-examine name: assessment-method prose: |- Examine trust agreement artifact(s) to verify that they define security requirements for discovery and registration processes. The specific implementation requirements are satisfied by ICKM-2 (authenticated protected channel for key exchange); ICKM-3 (symmetric key uniqueness); ICKM-4 (wildcard identifier prohibition); DR-1, DR-2, and DR-3 (IdP discovery and RP registration, Sec. 4.4); MR-1 (manual registration, Sec. 4.4.1); DYR-1 (dynamic registration channel protection, Sec. 4.4.2); and DISCR-1 (CSP verification key determination for wallets, Sec. 5.5). If the trust agreement artifact(s) do not define security requirements for discovery and registration, this control fails regardless of downstream control results. - id: ICKM-1_gdn name: guidance prose: "This control requires that the trust agreement artifact(s) define the security for discovery and registration. The downstream controls assess whether the implementation conforms to specific technical requirements. A federation could pass all downstream controls individually but fail this control if the trust agreement artifact(s) are silent on discovery and registration security, leaving parties without a documented basis for their security expectations." - id: ICKM-2 title: Secure Key Exchange props: - value: 3.6 B class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ICKM-2_smt name: statement prose: "Protocols that require the transfer of cryptographic key information SHALL use an authenticated protected channel to exchange the cryptographic key information needed to operate the federated relationship, including any shared secrets or public keys." - id: ICKM-2_obj links: - rel: assessment-for href: "#ICKM-2_smt" name: objective prose: Determine whether all cryptographic key information is exchanged over an authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ICKM-2_asm-examine name: assessment-method prose: "Examine documentation describing the key exchange processes for all federation relationships. For each relationship, verify that the documented process specifies the use of an authenticated protected channel for all transfers of cryptographic key information, including shared secrets and public keys." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ICKM-2_asm-test name: assessment-method prose: |- Test by selecting a sample of key exchange operations across the federation deployment. For each, verify that the authenticated protected channel is properly implemented (e.g., TLS with server-side certificate validation). Specific key exchange scenarios are satisfied by their respective controls: DR-2 for RP retrieval of IdP keys over a network, DR-3: RP for registration with an IdP, DYR-1 for dynamic registration, and DISCR-1 for RP discovery of CSP wallet keys. If any key exchange in the deployment is not covered by a downstream control (e.g., key exchange between a separated CSP and IdP), document and assess it here. - id: ICKM-2_gdn name: guidance prose: "The IdP, CSP, and RP need access to cryptographic keying materials to validate signatures and encrypt content. The association of these keys with specific parties is vital to the security of the protocol. In order to prevent an attacker impersonating an IdP/CSP or RP, all keys have to be transferred using secure methods. Methods include the publication of asymmetric public keys over HTTPS (and therefore TLS) at a well-known and trusted URL associated with the IdP/CSP or RP, or the use of TLS to transfer keying material in the registration process. Alternatively, keys could be transferred and configured manually by administrators to ensure a strong mapping between the intended party and the value of the key itself." - id: ICKM-3 title: Symmetric Key Uniqueness props: - value: 3.6 C class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ICKM-3_smt name: statement prose: Any symmetric keys used in this relationship SHALL be unique to a pair of federation participants. - id: ICKM-3_obj links: - rel: assessment-for href: "#ICKM-3_smt" name: objective prose: Determine whether symmetric keys are unique to each pair of federation participants. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ICKM-3_asm-examine name: assessment-method prose: Examine documentation describing symmetric key generation and assignment processes. Verify that the documented process produces a unique symmetric key for each pair of federation participants. Determine whether the process ensures that any symmetric key used for one pair of federation participants is not reused for any other pair. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ICKM-3_asm-examine-2 name: assessment-method prose: Examine key management system records or configuration entries for a sample of federation relationships. Verify that distinct key identifiers or key entries exist for each pair of participants. - id: ICKM-3_gdn name: guidance prose: |- Assessment is required when: Symmetric keys, rather than asymmetric key pairs, are used for the federation relationship. Since symmetric keys allow for both the creation and verification of both signed and encrypted content by all parties who possess the key, it's important that any symmetric keys be limited to use between only a single pair of connected parties. If symmetric keys are made available to any other parties, those parties can impersonate each other. Reusing symmetric keys across multiple federation relationships also increases the risk of key compromise: a compromise of one relationship would compromise all relationships that use the same key. This control ensures that a key shared between an IdP and RP-A is different from the key shared between the same IdP and RP-B. - id: ICKM-4 title: Wildcard Identifier Prohibition props: - value: 3.6 D class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ICKM-4_smt name: statement prose: "When domain names, URIs, or other structured identifiers are used to identify parties, wildcards SHALL NOT be used." - id: ICKM-4_obj links: - rel: assessment-for href: "#ICKM-4_smt" name: objective prose: Determine whether party identifiers avoid the use of wildcards. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ICKM-4_asm-examine name: assessment-method prose: "Examine system configurations, discovery/registration records, and trust agreement artifact(s) for party identifiers. Verify that no identifiers contain wildcards (e.g., \"*.csp.com\")." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ICKM-4_asm-test name: assessment-method prose: "Test by attempting to register or configure a party identifier containing a wildcard and verify that the system rejects it, if identifier establishment is performed through an automated interface." - id: ICKM-4_gdn name: guidance prose: "Wildcards in identifiers create ambiguity about which party is being identified, potentially allowing unintended parties to match the identifier. For example, if an RP is deployed at \"www.example.com\", \"service.example.com\", and \"gateway.example.com\", each identifier must be registered separately. A wildcard of \"*.example.com\" cannot be used, as it would unintentionally match \"user.example.com\" and \"unknown.example.com\" under the same RP identifier." - id: CKR-1 title: Key Rotation Documentation props: - value: 3.6.1 A class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CKR-1_smt name: statement prose: The allowable update process for any identifiers and cryptographic keys SHALL be defined by the trust agreement. - id: CKR-1_obj links: - rel: assessment-for href: "#CKR-1_smt" name: objective prose: Determine whether the trust agreement artifact(s) define the allowable update process for identifiers and cryptographic keys. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CKR-1_asm-examine name: assessment-method prose: "Examine trust agreement artifact(s) for documentation of the allowable key and identifier update process, including permitted methods, timing, and any restrictions." - id: CKR-1_gdn name: guidance prose: |- Over time, it may be desirable or necessary to update cryptographic keys associated with a CSP, IdP, or RP due to key expiration, suspected compromise, algorithm deprecation, or organizational changes. The trust agreement must define how these updates are performed so all parties understand the process. Related Controls: - CKR-2 requires that the update process be executed over an authenticated, protected channel. - ICKM-2 establishes the same requirement for initial key exchange. - id: CKR-2 title: Key Rotation Security props: - value: 3.6.1 B class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CKR-2_smt name: statement prose: "The allowable update process for any identifiers and cryptographic keys... SHALL be executed using an authenticated protected channel, as in the initial cryptographic key establishment." - id: CKR-2_obj links: - rel: assessment-for href: "#CKR-2_smt" name: objective prose: Determine whether updates to identifiers and cryptographic keys are executed using an authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CKR-2_asm-examine name: assessment-method prose: Examine system configurations for key rotation mechanisms. Verify that the update process matches the process defined in the trust agreement artifact(s) (see CKR-1). - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CKR-2_asm-test name: assessment-method prose: "Test by performing or observing a key rotation process. For authenticated protected channel verification, see ICKM-2." - id: CKR-2_gdn name: guidance prose: Key rotation requires the same security protection as initial key establishment. Using an authenticated protected channel ensures that updated key material is not intercepted or modified during exchange. - id: CKS-1 title: Secure Key Storage props: - value: 3.6.2 A class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CKS-1_smt name: statement prose: "CSPs, IdPs (including subscriber-controlled wallets), and RPs SHALL store all signing keys, decryption keys, and all symmetric keys in a secure fashion. Cryptographic key storage is subject to applicable [FIPS140] requirements, including applicable tamper resistance requirements." - id: CKS-1_obj links: - rel: assessment-for href: "#CKS-1_smt" name: objective prose: "Determine whether the assessed party stores signing keys, decryption keys, and symmetric keys securely and in accordance with applicable FIPS 140 requirements." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CKS-1_asm-examine name: assessment-method prose: "Examine (1) Documentation describing key storage mechanisms for signing keys, decryption keys, and symmetric keys. Verify that the documented storage approach addresses protection from unauthorized access. (2) FIPS 140 validation certificates for cryptographic modules used to store keys, if applicable. Verify that the validated level meets the organization's requirements and applicable policies. (3) System configurations and access controls for key storage to verify that keys are protected consistent with the documented approach and FIPS 140 requirements." - id: CKS-1_gdn name: guidance prose: |- FIPS 140 establishes security requirements for cryptographic modules, including tamper resistance at higher levels. Federal agencies and their service providers are typically required to use FIPS 140-validated modules. The applicable FIPS 140 level depends on the organization's security requirements and applicable policies. Related Controls: - FAL2-7 requires Federal IdPs at FAL2 or higher to protect assertion signing keys with FIPS 140 Level 1 or higher validated mechanisms. - CKS-2, CKS-3, and CKS-4 establish requirements for non-exportable key storage. - KS-1 and KS-2 establish key storage requirements specific to subscriber-controlled wallets. - id: CKS-2 title: Non-Exportable Key Storage Definition props: - value: 3.6.2 B class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CKS-2_smt name: statement prose: "To be considered non-exportable, key storage SHALL either be a separate piece of hardware or an embedded processor or execution environment, such as a secure element, trusted execution environment (TEE), or trusted platform module (TPM)." - id: CKS-2_obj links: - rel: assessment-for href: "#CKS-2_smt" name: objective prose: Determine whether key storage claimed as non-exportable meets the hardware or embedded processor/execution environment requirements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CKS-2_asm-examine name: assessment-method prose: "Examine documentation describing key storage mechanisms. Verify that any key storage claimed as non-exportable is either a separate piece of hardware or an embedded processor or execution environment that is separate from the host processor (e.g., secure element, TEE, TPM)." - id: CKS-2_gdn name: guidance prose: |- Assessment is required when: Non-exportable key storage is required or claimed. Some circumstances require the cryptographic keys to be stored in a non-exportable manner, such as reaching FAL3 with a subscriber-controlled wallet on a subscriber's device (see Sec. 5.4.1). This control establishes the criteria for key storage to be considered non-exportable. Software-only key stores do not meet the definition of non-exportable, regardless of access controls or encryption applied to the stored keys. - id: CKS-3 title: Non-Exportable Key Isolation props: - value: 3.6.2 C class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CKS-3_smt name: statement prose: Non-exportable key storage SHALL be designed to prohibit the export of the secret keys to the host processor... - id: CKS-3_obj links: - rel: assessment-for href: "#CKS-3_smt" name: objective prose: Determine whether non-exportable key storage is designed to prohibit export of secret keys to the host processor. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CKS-3_asm-examine name: assessment-method prose: Examine documentation and technical specifications for the key storage mechanism. Verify that the design does not include any interface or function that would allow secret keys to be exported to the host processor. - id: CKS-3_gdn name: guidance prose: |- Assessment is required when: Non-exportable key storage is required or claimed. This control ensures that the key storage interface does not permit secret key extraction. Cryptographic operations using the keys must occur within the secure storage environment itself, with only the results (e.g., signatures, decrypted data) returned to the host processor. Related Controls: - CKS-2 defines what qualifies as non-exportable key storage. - CKS-4 requires that non-exportable key storage cannot be reprogrammed to allow key extraction. - id: CKS-4 title: Non-Exportable Storage Immutability props: - value: 3.6.2 D class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CKS-4_smt name: statement prose: Non-exportable key storage... SHALL NOT be capable of being reprogrammed by the host processor to allow the secret keys to be extracted. - id: CKS-4_obj links: - rel: assessment-for href: "#CKS-4_smt" name: objective prose: Determine whether non-exportable key storage is protected against reprogramming by the host processor to allow secret key extraction. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CKS-4_asm-examine name: assessment-method prose: "Examine documentation and technical specifications for the key storage mechanism. Verify that the host processor cannot modify firmware, configuration, or behavior of the key storage in a way that would enable secret key extraction." - id: CKS-4_gdn name: guidance prose: |- Assessment is required when: Non-exportable key storage is required or claimed. This control addresses a different attack vector than CKS-3. Even if the key storage interface does not permit key export during normal operation (CKS-3), an attacker with host processor access could potentially modify the storage's firmware to add an export capability. This control requires that the key storage be designed such that the host processor cannot modify its firmware, configuration, or behavior in ways that would enable key extraction. Related Controls: - CKS-2 defines what qualifies as non-exportable key storage. - CKS-3 requires that non-exportable key storage prohibit key export to the host processor. - id: SATT-1 title: Software Attestation Validation props: - value: 3.6.3 A class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SATT-1_smt name: statement prose: "When attestations are required by the trust agreement or requested as part of the federation protocol, received attestations SHALL be validated by the receiver." - id: SATT-1_obj links: - rel: assessment-for href: "#SATT-1_smt" name: objective prose: Determine whether the receiver validates software or device attestations received as part of the federation protocol. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SATT-1_asm-examine name: assessment-method prose: "Examine trust agreement artifact(s) to identify whether software or device attestations are required and, if so, the validation criteria. Examine system documentation and configurations to verify that attestation validation is implemented." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SATT-1_asm-test name: assessment-method prose: Test by (1) presenting a valid attestation and verifying that it is accepted; (2) presenting an invalid attestation and verifying that it is rejected; and (3) presenting an assertion that is missing a required attestation and verifying that it is rejected. - id: SATT-1_gdn name: guidance prose: |- Assessment is required when: Software or device attestations are required or received. Software and device attestations can augment the establishment of identifiers and cryptographic keys, especially in dynamic and distributed systems. Attestations in this usage are cryptographically bound statements that a particular piece of software, device, or runtime system meets a set of agreed-upon parameters. The attestation is presented by the software in the context of establishing the identity of the software, device, or system with which the receiver is interacting. The attestation allows the receiver to verify the request with a higher degree of certainty than they would be able to otherwise. - id: AAD-1 title: Permissible Attribute Transmission props: - value: 3.7 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAD-1_smt name: statement prose: "A subscriber's identity attributes SHALL only be transmitted between the IdP and the RP for federation transactions or support functions, such as identification of compromised subscriber accounts (see Sec. 3.10.1), even when parties are allowlisted for federation purposes." - id: AAD-1_obj links: - rel: assessment-for href: "#AAD-1_smt" name: objective prose: Determine whether the IdP and RP limit transmission of subscriber identity attributes to permitted purposes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAD-1_asm-examine name: assessment-method prose: "Examine IdP and RP policies, trust agreement artifact(s), data flow documentation, federation configuration, and any identity API, provisioning API, or attribute synchronization mechanisms used to transmit subscriber identity attributes between the IdP and RP. Verify that the policies do not authorize transmission for purposes outside of federation transactions and support functions (as defined in Sec. 3.10.1)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AAD-1_asm-examine-2 name: assessment-method prose: |- Examine the trust agreement artifact(s) to verify that the permitted purposes for attribute transmission fall within these boundaries. The operational enforcement of transmission limits is satisfied by TSI-1 (IdP transmission limits) and TSI-4 (RP transmission limits to the IdP). This control verifies that the governing policies themselves do not permit out-of-scope transmission. - id: AAD-1_gdn name: guidance prose: "This restriction applies even when parties are allowlisted for federation purposes; allowlisting permits federation transactions, not unlimited data sharing." - id: AAD-2 title: RP Attribute Use Limitation props: - value: 3.7 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAD-2_smt name: statement prose: A subscriber's identity attributes SHALL NOT be used by the RP for purposes other than those stipulated in the trust agreement unless the subscriber specifically consents to such purposes. - id: AAD-2_obj links: - rel: assessment-for href: "#AAD-2_smt" name: objective prose: Determine whether the RP limits use of subscriber identity attributes to purposes stipulated in the trust agreement or consented to by the subscriber. - props: - value: EXAMINE name: method class: assessment-summary id: AAD-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by TSI-5. - id: AAD-2_gdn name: guidance prose: TSI-5 establishes the RP's obligation to inform subscribers and obtain consent when using identity information for purposes beyond those described in the trust agreement artifact(s). - id: AAD-3 title: Subscriber Attribute Storage props: - value: 3.7 C class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAD-3_smt name: statement prose: A subscriber's attributes SHALL be stored and managed in accordance with Sec. 3.11.3. - id: AAD-3_obj links: - rel: assessment-for href: "#AAD-3_smt" name: objective prose: Determine whether subscriber attributes are stored and managed in accordance with Section 3.11.3. - props: - value: EXAMINE name: method class: assessment-summary id: AAD-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SSIN-1 through SSIN-3. - id: AAD-4 title: Subscriber Attribute Transmission Notification props: - value: 3.7 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAD-4_smt name: statement prose: The subscriber SHALL be informed of the transmission of attributes to an RP. - id: AAD-4_obj links: - rel: assessment-for href: "#AAD-4_smt" name: objective prose: Determine whether the subscriber is informed of the transmission of their attributes to an RP. - props: - value: EXAMINE name: method class: assessment-summary id: AAD-4_asm-summary title: Assessment Method name: assessment-method prose: |- If the organization is the authorized party: Satisfied by AAD-5. If the subscriber is the authorized party: Satisfied by AAD-6. For non-allowlisted RPs, the notification mechanism assessment is satisfied by IDPRD-2 and IDPRD-3. - id: AAD-4_gdn name: guidance prose: This is a summative control. - id: AAD-5 title: Disclosure of Attributes by an Organization props: - value: 3.7 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAD-5_smt name: statement prose: "If the authorized party is the organization, the organization SHALL make the list of approved RPs and the associated sets of attributes sent to those RPs available to the subscriber." - id: AAD-5_obj links: - rel: assessment-for href: "#AAD-5_smt" name: objective prose: Determine whether the organization makes the list of approved RPs and associated attributes available to subscribers. - props: - value: EXAMINE name: method class: assessment-summary id: AAD-5_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by IALRP-3 and IALRP-5. - id: AAD-5_gdn name: guidance prose: |- Assessment is required when: The authorized party is the organization. This is a summative control. Compliance is demonstrated by meeting the requirements of the following controls: IALRP-3 (RP Allowlist availability to subscribers) and IALRP-5 (attribute indication in allowlist entries). When the organization acts as the authorized party, the subscriber does not directly approve each federation transaction. To maintain transparency, the organization must disclose which RPs receive subscriber attributes and what attributes are sent. - id: AAD-6 title: Subscriber Attribute Release Approval props: - value: 3.7 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AAD-6_smt name: statement prose: "If the authorized party is the subscriber, the subscriber SHALL be prompted prior to the release of attributes using a runtime decision at the IdP as described in Sec. 4.6.1.3." - id: AAD-6_obj links: - rel: assessment-for href: "#AAD-6_smt" name: objective prose: Determine whether the IdP prompts subscribers prior to attribute release using a runtime decision when the subscriber is the authorized party. - props: - value: EXAMINE name: method class: assessment-summary id: AAD-6_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by IDPRD-1 through IDPRD-6. - id: AAD-6_gdn name: guidance prose: |- Assessment is required when: The authorized party is the subscriber. This is a summative control. Compliance is demonstrated when the requirements of the following controls have been met: - IDPRD-1: Runtime authorization - IDPRD-2: Attribute release consent - IDPRD-3: Attribute disclosure before release - IDPRD-4: Selective attribute disclosure - IDPRD-5: Attribute value viewing mechanism - IDPRD-6: Sensitive information masking - id: RPSA-1 title: RP Subscriber Account Termination Data Removal props: - value: 3.8 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSA-1_smt name: statement prose: "Termination SHALL include the removal of all federated identifiers, bound authenticators, attributes, and identity information associated with the account, in accordance with Sec. 3.11.3." - id: RPSA-1_obj links: - rel: assessment-for href: "#RPSA-1_smt" name: objective prose: "Determine whether termination of an RP subscriber account includes removal of all federated identifiers, bound authenticators, attributes, and identity information associated with the account, except when otherwise restricted from doing so by regulations, laws, or policies, or when the risk of an application deems it essential (Sec. 3.11.3)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPSA-1_asm-examine name: assessment-method prose: |- Examine RP policies and procedures for account termination. Examine system implementation to verify that termination processes address the removal of federated identifiers, bound authenticators, attributes, and identity information. If any attributes are not removed, confirm that the reasons for retention are documented and are appropriately attributed to regulations, laws, policies, or risk assessments. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPSA-1_asm-test name: assessment-method prose: Test by terminating a test RP subscriber account and verify that all subscriber information is removed from storage as expected. - id: RPSA-1_gdn name: guidance prose: |- An RP subscriber account is terminated when the RP removes all access to the account at the RP. The reference to Sec. 3.11.3 recognizes that RPs may be required to retain certain subscriber information after account termination due to regulatory or legal obligations, organizational policies, or application risk assessments. - id: RPSA-2 title: Inaccessible Account Policy Documentation props: - value: 3.8 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSA-2_smt name: statement prose: "The RP SHALL document the practices and policies that it enacts when an RP subscriber account reaches a state of having zero associated federated identifiers; no means of access, including alternative authenticators (see Sec. 3.8.3); and no means of recovery, including account linking (see Sec. 3.8.1) and account resolution (see Sec. 3.8.2)." - id: RPSA-2_obj links: - rel: assessment-for href: "#RPSA-2_smt" name: objective prose: Determine whether the RP documents the practices and policies enacted when an RP subscriber account becomes inaccessible. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPSA-2_asm-examine name: assessment-method prose: "Examine the RP documentation for policies addressing RP subscriber accounts that have no associated federated identifiers, no alternative authenticators, and no means of recovery. Verify that the documentation specifies the actions taken (e.g., disable, terminate, retain for investigation)." - id: RPSA-2_gdn name: guidance prose: |- An RP subscriber account may reach a state where the subscriber can no longer access it - for example, when the sole federated identifier is removed, no alternative authenticators exist, and no account linking or account resolution process is available. The RP must have documented policies for handling such accounts. Common approaches include: - Disabling the account - Terminating the account - Retaining the account for investigation if suspicious activity is suspected The specific policy depends on the RP's business requirements, regulatory obligations, and risk posture. - id: RPSA-3 title: Federated Identifier Change Notifications props: - value: 3.8 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSA-3_smt name: statement prose: |- The RP SHALL provide a notice to the subscriber when: (a) A new federated identifier is added to an existing RP subscriber account, or (b) A federated identifier is removed from an RP subscriber account, but the account is not terminated. - id: RPSA-3_obj links: - rel: assessment-for href: "#RPSA-3_smt" name: objective prose: Determine whether the RP provides notice to the subscriber when a federated identifier is added to or removed from an RP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPSA-3_asm-examine name: assessment-method prose: Examine RP notification mechanisms and configurations to verify that notices are sent when federated identifiers are added or removed. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPSA-3_asm-test name: assessment-method prose: "Test by adding a new federated identifier to a test RP subscriber account and verifying that the subscriber receives a notification. Next, remove a federated identifier from a test RP subscriber account without terminating the account, and verify that the subscriber is notified." - id: RPSA-3_gdn name: guidance prose: Changes to federated identifiers associated with an RP subscriber account are security-relevant events. Adding a federated identifier grants a new means of access; removing one revokes access from that identity. Notifying the subscriber allows them to detect unauthorized account linking or removal. - id: RPSA-4 title: Termination Notice Consideration props: - value: 3.8 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSA-4_smt name: statement prose: "The RP SHALL consider the reason for termination when determining whether to send a notice to the subscriber, as discussed in Sec. 5.4 of [SP800-63A]." - id: RPSA-4_obj links: - rel: assessment-for href: "#RPSA-4_smt" name: objective prose: Determine whether the RP considers the reason for termination when deciding whether to send a notice to the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPSA-4_asm-examine name: assessment-method prose: Examine RP policies and procedures for account termination to verify that the reason for termination is considered when determining whether to notify the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: RPSA-4_asm-interview name: assessment-method prose: Interview personnel responsible for account termination or notification decisions to determine how the reason for termination is considered in practice. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPSA-4_asm-test name: assessment-method prose: Test by reviewing a sample of terminated or disabled RP subscriber accounts with different termination reasons and determine that the notice decision in each case reflects consideration of the reason for termination. - id: RPSA-4_gdn name: guidance prose: "Not all termination scenarios warrant subscriber notification. SP 800-63A Section 5.4 identifies various reasons for account termination, including scenarios that may warrant withholding notice, such as an account termination due to suspected fraud, since the notification could alert a malicious actor." - id: ACCL-1 title: Account Linking Authentication Requirement props: - value: 3.8.1 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ACCL-1_smt name: statement prose: "If the RP allows a subscriber to link multiple subscriber accounts..., the RP SHALL require an authenticated session with the subscriber account for all linking functions." - id: ACCL-1_obj links: - rel: assessment-for href: "#ACCL-1_smt" name: objective prose: Determine whether the RP requires an authenticated session for account linking functions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ACCL-1_asm-examine name: assessment-method prose: Examine RP policies and system configurations to verify that account linking functions require an authenticated session. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ACCL-1_asm-test name: assessment-method prose: Test by attempting to link a new federated identifier to an RP subscriber account and verify that an authenticated session is required before the linking function is permitted. - id: ACCL-1_gdn name: guidance prose: |- Assessment is required when: The RP allows a subscriber to link multiple subscriber accounts. Account linking allows a subscriber to associate multiple federated identifiers with a single RP subscriber account. This is a security-sensitive operation - without an authenticated session, an attacker could link their own federated identifier to a victim's account and gain unauthorized access. Requiring an authenticated session ensures that only the legitimate account holder can add new federated identifiers. - id: ACCL-2 title: Removed Federated Identifier Access Prohibition props: - value: 3.8.1 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ACCL-2_smt name: statement prose: "When a federated identifier is removed from an RP subscriber account, the RP SHALL disallow access to the RP subscriber account from the removed federated identifier." - id: ACCL-2_obj links: - rel: assessment-for href: "#ACCL-2_smt" name: objective prose: Determine whether the RP disallows access to the RP subscriber account from a removed federated identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ACCL-2_asm-examine name: assessment-method prose: Examine the RP implementation logic to verify that removing a federated identifier immediately revokes access to the account previously associated with that identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ACCL-2_asm-test name: assessment-method prose: Test by removing a federated identifier from a test RP subscriber account and attempting to authenticate using the removed federated identifier. Verify that access is denied. - id: ACCL-2_gdn name: guidance prose: |- When a federated identifier is unlinked from an RP subscriber account, it must no longer grant access to that account. While this may seem self-evident, the requirement addresses potential implementation patterns that could inadvertently preserve access, such as soft-deleting or marking the identifier as "inactive" without enforcing access prohibition and caching mechanisms that do not immediately reflect the removal. The assessment verifies that removal is immediately and completely effective. - id: ACCR-1 title: Account Resolution Attribute Sufficiency props: - value: 3.8.2 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ACCR-1_smt name: statement prose: An RP that performs account resolution SHALL ensure that the attributes requested from the IdP are sufficient to uniquely resolve the subscriber within the RP's system before linking the federated identifier with the RP subscriber account and granting access. - id: ACCR-1_obj links: - rel: assessment-for href: "#ACCR-1_smt" name: objective prose: Determine whether the RP ensures that the attributes requested from the IdP for account resolution are sufficient to uniquely identify the subscriber before linking the federated identifier with the RP subscriber account and granting access. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ACCR-1_asm-examine name: assessment-method prose: "Examine RP's account resolution process, including the specific attributes used for matching. Then, examine the RP's analysis or justification demonstrating that the selected attribute combination is sufficient to uniquely resolve subscribers within its population." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ACCR-1_asm-test name: assessment-method prose: Test by attempting account resolution as a test subscriber and verify that the federated identifier is linked only after a unique match is confirmed. - id: ACCR-1_gdn name: guidance prose: |- Assessment is required when: The RP performs account resolution. Account resolution occurs when the RP has existing subscriber information (e.g., from a pre-existing database) that is not yet associated with a federated identifier. When a subscriber authenticates via federation, the RP must match the incoming assertion to the correct existing account. Using insufficient attributes risks incorrect matching - for example, matching on common name and DOB alone could link a federated identifier to the wrong subscriber's account. The RP must request and use attributes that, in combination, uniquely identify the subscriber within the RP's population. - id: ACCR-2 title: Account Resolution Accuracy props: - value: 3.8.2 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ACCR-2_smt name: statement prose: An RP that performs account resolution SHALL design the process such that it does not associate an RP subscriber account's information with a federated identifier that does not belong to the subscriber. - id: ACCR-2_obj links: - rel: assessment-for href: "#ACCR-2_smt" name: objective prose: Determine whether the RP's account resolution process is designed to prevent associating an RP subscriber account with a federated identifier that does not belong to the subscriber. - props: - value: EXAMINE name: method class: assessment-summary id: ACCR-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ACCR-1. - id: ACCR-2_gdn name: guidance prose: |- Assessment is required when: The RP performs account resolution. This control requires the RP to design the account resolution process to ensure accurate association between RP subscriber accounts and federated identifiers. Account resolution may occur in scenarios where a federated identifier is not directly provided - for example, a subscriber-controlled wallet providing an attribute bundle without a federated identifier, or a pre-provisioned account being matched to an incoming assertion based on agreed-upon attributes. The RP must design the process so that the resolution correctly identifies the subscriber and does not mistakenly associate account information with an identifier belonging to a different person. - id: ACCR-3 title: Holder-of-Key Account Resolution props: - value: 3.8.2 C class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: ACCR-3_smt name: statement prose: "A similar account resolution process is also used when the RP verifies an authenticator used in a holder-of-key assertion for the first time. In this case, the RP SHALL ensure that the attributes carried with the authenticator uniquely resolve to the RP subscriber account before accepting the authenticator." - id: ACCR-3_obj links: - rel: assessment-for href: "#ACCR-3_smt" name: objective prose: Determine whether the RP ensures that attributes carried with a holder-of-key authenticator uniquely resolve to an RP subscriber account before accepting the authenticator. - props: - value: EXAMINE name: method class: assessment-summary id: ACCR-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ACCR-1. - id: ACCR-3_gdn name: guidance prose: |- Assessment is required when: The RP performs account resolution when verifying an authenticator used in a holder-of-key assertion for the first time. When an RP encounters a holder-of-key authenticator for the first time, it must associate that authenticator with an RP subscriber account. Since the RP did not issue the authenticator, it does not know which account it belongs to. The RP uses attributes carried with the authenticator to resolve to the correct account before accepting the authenticator for FAL3 sessions. - id: ALTAP-1 title: Alternative Authenticator Management props: - value: 3.8.3 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ALTAP-1_smt name: statement prose: "The RP SHALL follow the requirements in [SP800-63B] to manage all alternative authenticators." - id: ALTAP-1_obj links: - rel: assessment-for href: "#ALTAP-1_smt" name: objective prose: Determine whether the RP follows SP 800-63B requirements for managing alternative authenticators. - props: - value: EXAMINE name: method class: assessment-summary id: ALTAP-1_asm-summary title: Assessment Method name: assessment-method prose: This is a summative control. The requirements for this control are met when the RP's management of alternative authenticators meets the applicable requirements in SP 800-63B. - id: ALTAP-1_gdn name: guidance prose: |- Assessment is required when: The RP allows subscribers to access their RP subscriber account using direct authentication processes by allowing the subscriber to add and remove authenticators in the RP subscriber account. Since the RP is using the direct authentication model discussed in [SP800-63], there is no federation transaction and therefore no FAL assigned. - id: ALTAP-2 title: Bound vs. Alternative Authenticators props: - value: 3.8.3 B class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: ALTAP-2_smt name: statement prose: "While it is possible for bound authenticators (see Sec. 3.16) to be used as an alternative authenticator for direct access to the RP, these uses are distinct from each other and an RP SHALL determine whether a given authenticator can be used in one or both scenarios." - id: ALTAP-2_obj links: - rel: assessment-for href: "#ALTAP-2_smt" name: objective prose: "Determine whether the RP has determined whether bound authenticators can be utilized as alternative authenticators, and vice versa." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ALTAP-2_asm-examine name: assessment-method prose: "Examine RP documentation and policies to verify that the RP has explicitly determined whether bound authenticators can also be used for direct access, and vice versa." - id: ALTAP-2_gdn name: guidance prose: |- Assessment is required when: An RP supports both bound and alternative authenticators. A single authenticator may potentially serve two purposes at the RP: 1. As a bound authenticator for FAL3 federation transactions 2. As an alternative authenticator for direct access without federation These are distinct use cases with different security implications. The RP must explicitly determine which authenticators are permitted for each scenario. - id: ASRP-1 title: RP Authenticated Session Requirements props: - value: 3.9 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ASRP-1_smt name: statement prose: |- An authenticated session SHALL be created by the RP only when the following conditions are true: (a) The RP has processed and verified a valid assertion. (b) The assertion is from the expected IdP for a transaction. (c) The IdP that issued the assertion is the IdP identified in the federated identifier of the assertion. (d) The assertion is associated with an RP subscriber account, which may be ephemeral. (e) The RP subscriber account has been provisioned at the RP through the method specified in the trust agreement. - id: ASRP-1_obj links: - rel: assessment-for href: "#ASRP-1_smt" name: objective prose: Determine whether the RP creates authenticated sessions only once all required conditions are met. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ASRP-1_asm-examine name: assessment-method prose: "Examine RP assertion processing logic and session management documentation to verify that: (a) The assertion's signature and validity are verified before session creation; (b) The assertion's issuing IdP is checked against the expected IdP for the transaction, and the assertion is from the expected IdP; (c) The federated identifier's IdP matches the assertion's issuer; (d) The assertion is linked to an RP subscriber account; and (e) The provisioning method matches what is specified in the trust agreement artifact(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ASRP-1_asm-test name: assessment-method prose: Test by presenting a valid assertion meeting all conditions and verify that an authenticated session is created. Then present assertions that fail one or more conditions and verify that no authenticated session is created. - id: ASRP-1_gdn name: guidance prose: The RP must verify all five conditions before creating an authenticated session. This prevents session creation based on invalid or incomplete assertions. - id: ASRP-2 title: "RP Authenticated Session Requirements: HoK Verification" props: - value: 3.9 B class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: ASRP-2_smt name: statement prose: "If the assertion is a holder-of-key assertion at FAL3, the authenticator indicated in the assertion SHALL be verified before the RP subscriber account is associated with an authenticated session, as discussed in Sec. 3.15." - id: ASRP-2_obj links: - rel: assessment-for href: "#ASRP-2_smt" name: objective prose: Determine whether the RP verifies the authenticator indicated in a holder-of-key assertion before associating the RP subscriber account with an authenticated session. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ASRP-2_asm-examine name: assessment-method prose: Examine RP documentation to verify that holder-of-key authenticator verification occurs before session creation. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ASRP-2_asm-test name: assessment-method prose: Test by presenting a holder-of-key assertion and verifying that the RP requires proof of the indicated authenticator before creating an authenticated session. - id: ASRP-2_gdn name: guidance prose: |- Assessment is required when: The assertion is a holder-of-key assertion at FAL3. A holder-of-key assertion contains a reference to an authenticator. Before creating an authenticated session, the RP must verify that the subscriber controls this authenticator - the assertion signature alone is insufficient. - id: ASRP-3 title: "RP Authenticated Session Requirements: Bound Authenticator Verification" props: - value: 3.9 C class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: ASRP-3_smt name: statement prose: "If the assertion also requires authentication with a bound authenticator at FAL3, a bound authenticator SHALL be verified before the RP subscriber account is associated with an authenticated session, as discussed in Sec. 3.16." - id: ASRP-3_obj links: - rel: assessment-for href: "#ASRP-3_smt" name: objective prose: "If the assertion requires authentication with a bound authenticator, determine whether the RP verifies a bound authenticator before associating the RP subscriber account with an authenticated session." - props: - value: EXAMINE name: method class: assessment-summary id: ASRP-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RPPHBA-1 and RPPHBA-4. - id: ASRP-3_gdn name: guidance prose: |- Assessment is required when: The assertion requires authentication with a bound authenticator at FAL3. When an assertion indicates that a bound authenticator is required for FAL3, the RP must verify the bound authenticator before creating an authenticated session - the assertion signature alone is not sufficient. The bound authenticator is registered to the RP subscriber account and managed by the RP. Note: If bound authenticator verification occurs as part of a binding ceremony (see SUBPB-7), this requirement is not satisfied. A new FAL3 federation transaction must be initiated after the binding ceremony completes. - id: PRIVR-1 title: Privacy Act Analysis props: - value: "3.10 #1" class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-1_smt name: statement prose: "The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) to conduct an analysis that determines whether the requirements of the Privacy Act are triggered by the agency that is acting as an IdP, by the agency that is acting as an RP, or both (see Sec. 7.4)." - id: PRIVR-1_obj links: - rel: assessment-for href: "#PRIVR-1_smt" name: objective prose: Determine whether the agency has consulted with its SAOP to analyze Privacy Act applicability for its RP and/or IdP roles. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-1_asm-examine name: assessment-method prose: "Examine the documentation of the SAOP consultation and the resulting Privacy Act analysis, covering the agency's role(s) as an RP, an IdP, or both." - id: PRIVR-1_gdn name: guidance prose: |- Assessment is required when: The assessment target (IdP or RP) is a federal agency. It is critical to involve an agency's SAOP in the earliest stages of federation implementation development to assess and mitigate privacy risks and advise the agency on compliance obligations, such as whether the federation triggers the Privacy Act of 1974 or the E-Government Act of 2002 requirement to conduct a PIA. For example, if the Agency is serving as an IdP in a federation, it is likely that the Privacy Act requirements will be triggered and that coverage is required under either a new or existing Privacy Act system of records, since credentials would be maintained at the IdP on behalf of any RP it federates with. If, however, the agency is an RP and using a third-party IdP, federated authentication may not trigger the requirements of the Privacy Act, depending on what data passed from the RP is maintained by the agency as the RP (in such instances, the agency may have a broader programmatic SORN that covers such data). Due to the many components involved in federation, it is important for the SAOP to have awareness and understanding of each component. For example, other privacy artifacts may be applicable to an agency offering or using federated IdP or RP services, such as Data Use Agreements, Computer Matching Agreements, etc. The SAOP can assist the agency in determining what additional requirements apply. Moreover, a thorough understanding of the individual components of digital authentication will enable the SAOP to assess and mitigate privacy risks through compliance processes or other means. - id: PRIVR-2 title: SORN props: - value: "3.10 #2" class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-2_smt name: statement prose: "The agency SHALL publish or identify coverage by a System of Records Notice (SORN), as applicable." - id: PRIVR-2_obj links: - rel: assessment-for href: "#PRIVR-2_smt" name: objective prose: "Determine whether the agency has published or identified coverage by a SORN, as applicable." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-2_asm-examine name: assessment-method prose: Examine the agency's SORN documentation to verify that federation activities are covered by either a dedicated SORN or an existing programmatic SORN. - id: PRIVR-2_gdn name: guidance prose: |- Assessment is required when: The assessment target (IdP or RP) is a federal agency. This control applies when PRIVR-1 analysis determines that the Privacy Act is triggered. If the SAOP has determined that the Privacy Act is triggered, the agency is required to either publish or identify existing coverage by a SORN. - id: PRIVR-3 title: E-Government Act props: - value: "3.10 #3" class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-3_smt name: statement prose: "The agency SHALL consult with their SAOP to conduct an analysis that determines whether the requirements of the E-Government Act are triggered by the agency that is acting as an IdP, the agency that is acting as an RP, or both." - id: PRIVR-3_obj links: - rel: assessment-for href: "#PRIVR-3_smt" name: objective prose: Determine whether the agency has consulted with its SAOP to analyze E-Government Act applicability for its RP and/or IdP roles. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-3_asm-examine name: assessment-method prose: "Examine the documentation of the SAOP consultation and the resulting E-Government Act analysis, covering the agency's role(s) as RP, IdP, or both." - id: PRIVR-3_gdn name: guidance prose: |- Assessment is required when: The assessment target (IdP or RP) is a federal agency. The E-Government Act of 2002 may require the agency to conduct a Privacy Impact Assessment (PIA) for its federation activities. The SAOP can assist the agency in determining whether a PIA is required. As with PRIVR-1, these considerations should not be read as a requirement to develop a PIA for federation alone - in many cases, it will make the most sense to draft a PIA that encompasses the entire digital identity process or includes federation as part of a larger programmatic PIA. - id: PRIVR-4 title: Privacy Impact Assessment props: - value: "3.10 #4" class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-4_smt name: statement prose: "The agency SHALL publish or identify coverage by a Privacy Impact Assessment (PIA), as applicable." - id: PRIVR-4_obj links: - rel: assessment-for href: "#PRIVR-4_smt" name: objective prose: "Determine whether the agency has published or identified coverage by a PIA, as applicable." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-4_asm-examine name: assessment-method prose: "Examine agency's PIA documentation to verify that federation activities are covered, either by a dedicated PIA or by an existing programmatic PIA." - id: PRIVR-4_gdn name: guidance prose: |- Assessment is required when: The assessment target (IdP or RP) is a federal agency. This control applies when PRIVR-3 analysis determines that the E-Government Act is triggered. The agency must either publish a new PIA or identify an existing PIA that covers the federation activities. A dedicated PIA for federation is not required - coverage may be provided by a broader programmatic PIA that encompasses the digital identity process or the program establishing online access. - id: PRIVR-5 title: Privacy Risk Assessment props: - value: "3.10 #5" class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-5_smt name: statement prose: The agency SHALL conduct a privacy risk assessment regarding the sharing of subscriber identity information between the IdP and RP. - id: PRIVR-5_obj links: - rel: assessment-for href: "#PRIVR-5_smt" name: objective prose: Determine whether the agency has conducted a privacy risk assessment regarding the sharing of subscriber identity information between the IdP and RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-5_asm-examine name: assessment-method prose: Examine the agency's privacy risk assessment documentation addressing the sharing of subscriber identity information in federation transactions. - id: PRIVR-5_gdn name: guidance prose: |- Assessment is required when: The assessment target (IdP or RP) is a federal agency. This assessment focuses specifically on the risks associated with sharing subscriber identity information between federation parties. Unlike the Privacy Act and E-Government Act analyses (PRIVR-1, PRIVR-3), this assessment is required regardless of whether those statutes are triggered. - id: PRIVR-6 title: Provisioning API Privacy Measures props: - value: 3.10 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-6_smt name: statement prose: "If the RP subscriber account life cycle process gives the RP access to attributes through a provisioning API (see Sec. 4.6.3), additional privacy measures SHALL be implemented to account for the difference in the RP subscriber account life cycle (e.g., separation of non-active subscriber accounts, proactive removal of disabled and terminated accounts)." - id: PRIVR-6_obj links: - rel: assessment-for href: "#PRIVR-6_smt" name: objective prose: Determine whether the RP implements additional privacy measures to account for RP subscriber account life cycle differences when using a provisioning API. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-6_asm-examine name: assessment-method prose: "Examine the RP's policies and system documentation for provisioning API integration to verify that additional privacy measures address any differences arising from the RP subscriber account lifecycle, such as the separation of non-active accounts and the proactive removal of disabled and terminated accounts." - id: PRIVR-6_gdn name: guidance prose: |- Assessment is required when: The RP subscriber account life cycle process gives the RP access to attributes through a provisioning API. When an RP receives subscriber attributes through a provisioning API, the RP subscriber account life cycle may differ from the subscriber account life cycle at the IdP. For example, the RP may have accounts that are no longer active at the IdP. Additional privacy measures address these differences by ensuring that subscriber data is appropriately managed throughout the RP subscriber account lifecycle. - id: PRIVR-7 title: Provisioning API Attribute Minimization props: - value: 3.10 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-7_smt name: statement prose: The IdP SHALL minimize the attributes that are made available to the RP through the provisioning API. - id: PRIVR-7_obj links: - rel: assessment-for href: "#PRIVR-7_smt" name: objective prose: Determine whether the IdP minimizes the attributes made available to the RP through the provisioning API. - props: - value: EXAMINE name: method class: assessment-summary id: PRIVR-7_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by TSI-1. - id: PRIVR-7_gdn name: guidance prose: |- Assessment is required when: The IdP provides attributes through a provisioning API. Provisioning APIs can expose a broader set of subscriber attributes than would typically be transmitted in individual federation transactions. The IdP must ensure that only the minimum necessary attributes are made available through this channel, consistent with data minimization principles. - id: PRIVR-8 title: Provisioning API Population Limitation props: - value: 3.10 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-8_smt name: statement prose: The IdP SHALL limit the population of subscriber accounts that are available via the provisioning API to the population of subscribers authorized to use the RP by the trust agreement. - id: PRIVR-8_obj links: - rel: assessment-for href: "#PRIVR-8_smt" name: objective prose: Determine whether the IdP limits the subscriber accounts available via the provisioning API to the population of subscribers authorized to use the RP as specified in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-8_asm-examine name: assessment-method prose: Examine the IdP provisioning API configuration and access control documentation to verify that only subscribers authorized to use the RP per the trust agreement artifact(s) are included in the provisioned population. - id: PRIVR-8_gdn name: guidance prose: |- Assessment is required when: The IdP provides attributes through a provisioning API. Provisioning APIs can pre-populate RP subscriber accounts before subscribers authenticate. The IdP must ensure that only subscribers authorized to use the RP under the trust agreement artifact(s) are included. This prevents the RP from receiving data about subscribers who have no relationship with the RP. - id: PRIVR-9 title: Subscriber Account Deprovisioning via API props: - value: 3.10 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-9_smt name: statement prose: "To prevent RP retention of identity attributes for accounts that have been terminated at the IdP, the IdP SHALL use the provisioning API to deprovision RP subscriber accounts for terminated subscriber accounts except where restricted by RP data retention requirements, policies, or regulation." - id: PRIVR-9_obj links: - rel: assessment-for href: "#PRIVR-9_smt" name: objective prose: "Determine whether the IdP actively uses the provisioning API to deprovision RP subscriber accounts when corresponding subscriber accounts are terminated at the IdP, when the IdP is not restricted from doing so by RP retention requirements, policies, or regulations." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PRIVR-9_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) documenting any RP retention exceptions that restrict automatic deprovisioning. Examine audit logs that correlate subscriber account terminations at the IdP with corresponding deprovisioning actions sent to RPs, and ensure that deprovisioning occurs unless there is an RP exception, and that deprovisioning does not occur if any RP exception conditions have been met." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PRIVR-9_asm-test name: assessment-method prose: "Test by terminating a test subscriber account at the IdP that should result in deprovisioning and verify that a deprovisioning action is sent to the RP via the provisioning API Then, terminate a test subscriber account at the IdP that should not result in deprovisioning and verify that no deprovisioning action is sent to the RP." - id: PRIVR-9_gdn name: guidance prose: |- Assessment is required when: The IdP provides attributes through a provisioning API. This requirement enforces data minimization principles by ensuring the IdP proactively removes subscriber data from RPs when accounts are terminated, rather than allowing indefinite retention of stale identity attributes. The exception clause acknowledges that RPs may have legitimate data retention requirements (legal, regulatory, or policy-based) that prevent immediate deletion. Trust agreement artifact(s) should document any such exceptions. Note that when an RP subscriber account is linked to multiple federated identifiers (see Sec. 3.8.1), deprovisioning one federated identifier may result in a persistent RP subscriber account linked to a different federated identifier. - id: PRIVR-10 title: Data Exchange Minimization props: - value: 3.10 E class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PRIVR-10_smt name: statement prose: The IdP and RP SHALL exchange only the minimum data necessary to achieve the function of the system. - id: PRIVR-10_obj links: - rel: assessment-for href: "#PRIVR-10_smt" name: objective prose: Determine whether the IdP and RP limit data exchanged between them to only what is necessary for system functionality. - props: - value: EXAMINE name: method class: assessment-summary id: PRIVR-10_asm-summary title: Assessment Method name: assessment-method prose: |- For IdPs: Satisfied by TSI-1. For RPs: Examine the trust agreement artifact(s) documenting the attributes to be exchanged and their stated purposes. Review data transmitted from RP to IdP and verify that each data element has a corresponding functional justification and that no extraneous data is transmitted. - id: PRIVR-10_gdn name: guidance prose: |- Assessors should verify that each attribute exchanged has a documented purpose tied to system functionality-attributes exchanged "just in case" or for undefined future use would indicate non-compliance. Transmission of subscriber activities to the IdP is further restricted by TSI-4, which limits such transmission to fraud mitigation and security incident response purposes only. - id: TSI-1 title: IdP Data Exchange Minimization props: - value: 3.10.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TSI-1_smt name: statement prose: The IdP SHALL limit the transmission of subscriber information to only that which is necessary for the system to function and is stipulated and disclosed by the trust agreement. - id: TSI-1_obj links: - rel: assessment-for href: "#TSI-1_smt" name: objective prose: Determine whether the IdP limits transmission of subscriber information to only what is (1) necessary for permissible system functions and (2) stipulated and disclosed in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TSI-1_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) documenting transmissible attributes and their purposes. For each attribute authorized for transmission, verify that it maps to a necessary system function (such as identity service, specific subscriber request, fraud mitigation, or security incident response) and has a documented functional justification. Review IdP attribute release configuration and compare against trust agreement artifact(s) to verify no unauthorized attributes are transmitted." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: TSI-1_asm-test name: assessment-method prose: "Test by generating an assertion for a test RP. Verify that no attributes appear in the assertion beyond those authorized by the trust agreement artifact(s). If the federation protocol permits runtime attribute requests, configure the test RP to request attributes outside the trust agreement artifact(s) and verify the IdP rejects or ignores the unauthorized request." - id: TSI-1_gdn name: guidance prose: |- Typical system functions include the following: - Identity proofing, authentication, or attribute assertions (collectively "identity service"); - A specific subscriber request to transmit the information; - Fraud mitigation related to the identity service; or - Responding to a security incident related to the identity service. RP compliance with data exchange minimization is assessed under PRIVR-10. - id: TSI-2 title: IdP Privacy Risk Management for Additional Processing props: - value: 3.10.1 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TSI-2_smt name: statement prose: "If an IdP discloses information on subscriber activities at an RP to any party, or processes the subscriber's attributes for any purpose other than these cases [Identity proofing, authentication, or attribute assertions (collectively \"identity service\"); A specific subscriber request to transmit the information; Fraud mitigation related to the identity service; or Responding to a security incident related to the identity service], the IdP SHALL implement measures to maintain predictability and manageability commensurate with the privacy risks that arise from the additional processing." - id: TSI-2_obj links: - rel: assessment-for href: "#TSI-2_smt" name: objective prose: "Determine whether the IdP implements measures to maintain predictability and manageability commensurate with privacy risks, when the IdP discloses information on subscriber activities at an RP to any party or processes subscriber attributes for any purpose other than for an identity service, a specific subscriber request, fraud mitigation, or a security incident response." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TSI-2_asm-examine name: assessment-method prose: |- Examine the IdP's policies and practices regarding the processing of subscriber information. First, identify whether the IdP processes subscriber information for any purpose beyond these functions: identity proofing, authentication, or attribute assertions (collectively "identity service"); a specific subscriber request to transmit the information; fraud mitigation related to the identity service; or responding to a security incident related to the identity service. If additional processing occurs, review the IdP's privacy risk assessment for that processing and verify that implemented measures (such as notice, consent, or selective disclosure controls) are commensurate with the identified risks. - id: TSI-2_gdn name: guidance prose: |- Assessment is required when: An IdP discloses information on subscriber activities at an RP to any party, or processes the subscriber's attributes for any purpose other than these case: Identity proofing, authentication, or attribute assertions (collectively "identity service"); A specific subscriber request to transmit the information; Fraud mitigation related to the identity service; or Responding to a security incident related to the identity service. By the nature of a federated protocol, the IdP will know which RPs a subscriber logs in to and will know which attributes have been released to which RPs. This information is used as part of the federated login process, identified here as "identity service", to facilitate login to an RP. IdPs need to use measures to maintain the objectives of predictability (enabling reliable assumptions by individuals, owners, and operators about PII and its processing by an information system) and manageability (providing the capability for granular administration of PII, including alteration, deletion, and selective disclosure) commensurate with privacy risks that can arise from the processing of information for purposes other than identity proofing, authentication, authorization, or attribute assertion, related fraud mitigation, or to comply with law or legal process as in [NISTIR8062]. However, processing information for purposes other than the identity service can create privacy risks when individuals are not expecting or are not comfortable with the additional processing. These exception cases, which are not part of the federated identity protocol process, need to be managed in accordance with the risks associated with such additional processing of the subscriber's information. IdPs can use privacy risk assessments to determine the extent of privacy risks arising from such processing and implement measures commensurate with the privacy risk arising from the additional processing. Such measures may include providing clear notice, obtaining subscriber consent, or enabling selective use or disclosure of attributes, but other measures may be more effective in mitigating the privacy risks depending on the type of processing. - id: TSI-3 title: Prohibition on Coerced Consent props: - value: 3.10.1 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TSI-3_smt name: statement prose: "When an IdP gathers the subscriber's consent to use information outside the identity transaction, the IdP SHALL NOT make consent for the additional processing a condition of the identity service." - id: TSI-3_obj links: - rel: assessment-for href: "#TSI-3_smt" name: objective prose: "Determine whether the IdP refrains from making consent for additional processing a condition of the identity service, when the IdP gathers subscriber consent to use information outside the identity transaction." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TSI-3_asm-examine name: assessment-method prose: Examine the IdP's consent mechanisms and user interface flows for gathering subscriber consent to additional processing. Verify that subscribers can decline consent for additional processing and still complete identity service functions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: TSI-3_asm-test name: assessment-method prose: Test by attempting to use the identity service while declining consent for any additional processing. Verify that the identity service remains available. - id: TSI-3_gdn name: guidance prose: |- Assessment is required when: An IdP gathers the subscriber's consent to use information outside the identity transaction. Subscriber consent must be meaningful. When IdPs use consent measures for processing beyond identity service functions, they cannot make subscriber acceptance of additional processing a condition of providing the identity service. For example, an IdP cannot require a subscriber to consent to marketing use of their data as a condition of federated login. - id: TSI-4 title: RP Subscriber Activity Transmission Limits props: - value: 3.10.1 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TSI-4_smt name: statement prose: |- An RP SHALL limit the transmission of subscriber activities to the associated IdP to the following cases, and only if stipulated and disclosed by the trust agreement: (a) Fraud mitigation related to the identity service (b) Responding to a security incident related to the identity service - id: TSI-4_obj links: - rel: assessment-for href: "#TSI-4_smt" name: objective prose: "Determine whether the RP limits transmission of subscriber activities to the IdP to only fraud mitigation or security incident response, and only when stipulated and disclosed by the trust agreement." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TSI-4_asm-examine name: assessment-method prose: "Examine the RP's system configuration and data flow documentation to determine whether the RP transmits subscriber activity to the IdP. If transmission occurs, verify that (1) the transmission is stipulated and disclosed in the trust agreement artifact(s), and (2) the purpose is limited to fraud mitigation related to the identity service or to responding to a security incident related to the identity service." - id: TSI-4_gdn name: guidance prose: "\"Subscriber activities\" refers to actions the subscriber takes at the RP, such as login events, transactions, or usage patterns." - id: TSI-5 title: Subscriber Notice & Consent for Additional Uses props: - value: 3.10.1 E class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TSI-5_smt name: statement prose: "If an RP uses the subscriber's identity information for any purpose other than those stipulated in the trust agreement, the RP SHALL inform the subscriber and obtain their consent for such additional uses." - id: TSI-5_obj links: - rel: assessment-for href: "#TSI-5_smt" name: objective prose: Determine whether the RP informs the subscriber and obtains consent when using the subscriber's identity information for any purpose other than those stipulated in the trust agreement. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TSI-5_asm-examine name: assessment-method prose: "Examine by reviewing all RP policies that document the purposes for which subscriber identity information is used, and compare that documentation to the purposes stipulated in the trust agreement artifact(s). If uses beyond the trust agreement exist, verify that (1) the RP provides notice to subscribers describing the additional use(s), and (2) the RP obtains subscriber consent prior to the additional use(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: TSI-5_asm-test name: assessment-method prose: "Test by initiating a representative subscriber flow for each category of additional use, and determine that the RP informs the subscriber of the additional use and obtains the subscriber's consent before that additional use occurs." - id: TSI-5_gdn name: guidance prose: |- Assessment is required when: An RP uses the subscriber's identity information for any purpose other than those stipulated in the trust agreement. "Identity information" can include identity attributes received from the IdP as well as subscriber activities at the RP. "Specifically consents" indicates that general terms of service acceptance are insufficient-the subscriber must affirmatively agree to the specific additional use. - id: SIBC-1 title: CSP/IdP Information Transmission Limitations props: - value: 3.10.2 A class: index name: label - value: CSP/IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SIBC-1_smt name: statement prose: All information transmissions between CSPs and/or IdPs SHALL be subject to the limitations for IdPs enumerated in Sec. 3.10.1. - id: SIBC-1_obj links: - rel: assessment-for href: "#SIBC-1_smt" name: objective prose: Determine whether information transmissions between CSPs and/or IdPs comply with the limitations enumerated for IdPs in Sec. 3.10.1. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SIBC-1_asm-examine name: assessment-method prose: "Examine documentation that identifies all information transmitted between CSPs and/or IdPs. For each category of information/attributes transmitted, apply the assessment methods from TSI-1, TSI-2, and TSI-3 to verify that the transmission complies with the stated information-sharing limitations." - id: SIBC-1_gdn name: guidance prose: |- In some larger federation systems, particularly multilateral federations managed by federation authorities, multiple CSPs may be involved in the same trust agreement. In such cases, it may be desirable for CSPs to share information with one another to support activities such as fraud mitigation (e.g., to prevent an attacker from jumping between CSPs with different accounts to avoid detection). While sharing information in this way can help mitigate fraud, there are also substantial privacy concerns, as CSPs could learn subscriber attributes and actions from each other that were not initially disclosed to all CSPs the subscriber uses. Similar information sharing could be desirable between IdPs that operate independently of the CSP, such as between subscriber-controlled wallets hosted on remote systems, and such sharing entails similar privacy considerations. (See NISTIR 8062 for guidance on privacy engineering objectives, including predictability and manageability.) - id: SIBC-2 title: CSP/IdP Information Sharing Privacy Risk Assessment props: - value: 3.10.2 B class: index name: label - value: CSP/IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SIBC-2_smt name: statement prose: Any such information sharing between CSPs and/or IdPs SHALL be included in their privacy risk assessments. - id: SIBC-2_obj links: - rel: assessment-for href: "#SIBC-2_smt" name: objective prose: Determine whether information sharing between CSPs and/or IdPs is included in each party's privacy risk assessment. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SIBC-2_asm-examine name: assessment-method prose: Examine the documentation that identifies all information transmitted between CSPs and/or IdPs. Review each participating CSP's and IdP's privacy risk assessment and verify that the identified information sharing is addressed. - id: SIBC-2_gdn name: guidance prose: |- Assessment is required when: Information is shared between CSPs and/or IdPs. This control ensures that CSPs and IdPs explicitly consider the privacy implications of inter-party information sharing. While such sharing can support fraud mitigation, it also creates risks that CSPs could learn subscriber attributes and actions from each other that were not originally disclosed to all CSPs the subscriber uses. - id: SIBC-3 title: CSP Information Transfer Policy props: - value: 3.10.2 C class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SIBC-3_smt name: statement prose: The terms of the trust agreement that connects CSPs SHALL define the policies that apply for the transfer of information shared between CSPs. - id: SIBC-3_obj links: - rel: assessment-for href: "#SIBC-3_smt" name: objective prose: Determine whether the trust agreement artifact(s) that connect CSPs define policies for the transfer of information shared between CSPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SIBC-3_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) that establish the CSP connections. Verify that policies are defined for the transfer of information shared between CSPs, including what information may be transferred, under what circumstances, and any restrictions on use. Then, examine sample records of information shared between CSPs to verify that all sharing complies with the policies defined in the trust agreement artifact(s)." - id: SIBC-3_gdn name: guidance prose: |- Assessment is required when: Two or more CSPs are connected under a (set) of trust agreement artifact(s). In a trust agreement managed by a federation authority, the federation authority defines these terms. - id: SECC-1 title: IdP/CSP Security Controls props: - value: 3.11 A class: index name: label - value: CSP/IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECC-1_smt name: statement prose: "IdPs and CSPs SHALL employ appropriately tailored security controls from at least the moderate baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard that the organization has determined for the information systems, applications, and online services that these guidelines are used to protect." - id: SECC-1_obj links: - rel: assessment-for href: "#SECC-1_smt" name: objective prose: Determine whether the IdP/CSP employs appropriately tailored security controls from at least the moderate baseline defined in SP 800-53 or an equivalent standard. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECC-1_asm-examine name: assessment-method prose: Examine evidence that the IdP/CSP has been assessed against at least the moderate baseline security controls defined in SP 800-53 or an equivalent standard. Verify that the resulting authorization or certification is current and covers all systems supporting federation services. - id: SECC-1_gdn name: guidance prose: |- A compromise of the IdP/CSP or its cryptographic material would be detrimental to the federation network. As a consequence, the IdP/CSP has to employ stringent security controls, and these controls help protect the network as a whole. NIST SP 800-53 rev.5 and SP 800-53B provide a comprehensive catalog of controls, three security control baselines (low, moderate, and high impact), and guidance for tailoring the appropriate baseline to specific needs and risk environments for federal information systems. These controls are the operational, technical, and management safeguards to maintain the integrity, confidentiality, and security of federal information systems and are intended to be used in conjunction with the NIST risk management framework outlined in SP 800-37 and SP 800-63-3 section 5, Digital Identity Risk Management. NIST SP 800-53B presents security control baselines determined by the security categorization of the information system (low, moderate or high) from NIST FIPS 199 Standards for Security Categorization of Federal Information and Information Systems. The moderate and high baseline controls may be considered the starting point for the selection, enhancement, and tailoring of the security controls presented. Guidance on tailoring the control baselines to best meet the organization's risk environment, systems and operations is presented in SP 800-53B section 2.4 Tailoring Baseline Security Controls. While SP 800-53B and other NIST Special Publications in the SP-800-XXX series apply to federal agencies for the implementation of the Federal information Security Modernization (Management) Act (FISMA), non-federal entities providing services for federal information systems may also need to demonstrate appropriate controls and should similarly use SP 800-53 and associated publications as resources. Non-federal entities may be subject to and conformant with other applicable controls systems and processes for information system security (e.g., FEDRAMP, ISO/IEC 27001). - id: SECC-2 title: RP Security Controls props: - value: 3.11 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECC-2_smt name: statement prose: "RPs SHALL employ appropriately tailored security controls from at least the low baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard that the organization has determined for the information systems, applications, and online services that these guidelines are used to protect." - id: SECC-2_obj links: - rel: assessment-for href: "#SECC-2_smt" name: objective prose: Determine whether the RP employs appropriately tailored security controls from at least the low baseline defined in SP 800-53 or an equivalent standard. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECC-2_asm-examine name: assessment-method prose: |- Examine evidence that the RP has been assessed against at least the low baseline security controls defined in SP 800-53 or an equivalent standard. Verify that the resulting authorization or certification is current and covers all systems supporting federation services. - id: SECC-2_gdn name: guidance prose: |- Assessment is required when: The RP does not request or process personal information. RPs that request or process personal information must implement security controls at the moderate baseline or higher (see SECC-3). - id: SECC-3 title: RP Security Controls for Personal Information props: - value: 3.11 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECC-3_smt name: statement prose: "RPs that request or process personal information SHALL employ appropriately tailored security controls from at least the moderate baseline security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard." - id: SECC-3_obj links: - rel: assessment-for href: "#SECC-3_smt" name: objective prose: "Determine whether RPs that request or process personal information employ appropriately tailored security controls from at least the moderate baseline defined in [SP800-53] or an equivalent standard." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECC-3_asm-examine name: assessment-method prose: Examine evidence that the RP has been assessed against at least the moderate baseline security controls defined in SP 800-53 or an equivalent standard. Verify that the resulting authorization or certification is current and covers the systems supporting federation services. - id: SECC-3_gdn name: guidance prose: |- Assessment is required when: The RP processes personal information. This control supersedes SECC-2 for RPs handling personal information, raising the minimum baseline from low to moderate. - id: SECC-4 title: Assurance Level Baseline Controls props: - value: 3.11 D class: index name: label - value: CSP/IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SECC-4_smt name: statement prose: "CSPs, IdPs, and RPs SHALL ensure that the minimum assurance-related controls for the appropriate systems or equivalent are satisfied or exceeded." - id: SECC-4_obj links: - rel: assessment-for href: "#SECC-4_smt" name: objective prose: "Determine whether CSPs, IdPs, and RPs satisfy or exceed the minimum assurance-related controls for their selected IAL(s), AAL(s), and FAL(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SECC-4_asm-examine name: assessment-method prose: "Examine the documentation that identifies the IAL(s), AAL(s), and/or FAL(s) that the organization accepts/provides. Then, identify the applicable baseline controls from [SP800-63A] for the selected IAL(s), [SP800-63B] for the selected AAL(s), and [SP800-63C] for the selected FAL(s). Assess or verify the assessment of each applicable set of baseline controls. Record the compliance status based on the results of the baseline control assessment. Determine whether the minimum assurance-related controls have been satisfied or exceeded." - id: SECC-4_gdn name: guidance prose: "Compliance with this control is demonstrated through the results of the applicable baseline control assessments from SP 800-63A, SP 800-63B, and SP 800-63C." - id: PSI-1 title: IdP-RP Communication Protection props: - value: 3.11.2 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PSI-1_smt name: statement prose: Communications between the IdP and the RP SHALL be protected in transit using an authenticated protected channel. - id: PSI-1_obj links: - rel: assessment-for href: "#PSI-1_smt" name: objective prose: Determine whether all communications between the IdP and RP are protected in transit using an authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PSI-1_asm-examine name: assessment-method prose: "Examine documentation that reveals the functions for which the IdP and RP communicate (e.g., assertion exchange, provisioning API, key retrieval, dynamic registration), and list those functions. For communications covered by specific controls (BCP-8, DR-2, DYR-1, ICKM-2, CKR-2, PAPI-3), assess or verify assessment of each applicable control. For any IdP-RP communications not covered by a specific control, verify that the communication is configured to use an authenticated protected channel." - id: PSI-1_gdn name: guidance prose: "This control is the umbrella requirement for protecting IdP-RP communication. Most IdP-RP communication scenarios have dedicated controls with specific assessment procedures. This control catches any communication pathways that fall outside those dedicated controls. If all IdP-RP communications are covered by the specific controls listed in the assessment method, step (3) will have no additional items to assess, and the assessor should document that." - id: PSI-2 title: Subscriber Communication Protection props: - value: 3.11.2 B class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PSI-2_smt name: statement prose: Communications between the subscriber and either the IdP or the RP (usually through a user agent) SHALL be made using an authenticated protected channel. - id: PSI-2_obj links: - rel: assessment-for href: "#PSI-2_smt" name: objective prose: Determine whether communications between the subscriber and the IdP or RP occur over an authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PSI-2_asm-examine name: assessment-method prose: "Examine documentation that reveals the functions for which the subscriber communicates with the IdP or RP (e.g., authentication, assertion conveyance, consent), and list those functions. For communications covered by specific controls (BCP-7, FCP-3), assess or verify the assessment of each applicable control. For any subscriber-IdP or subscriber-RP communications not covered by a specific control, verify that the communication is configured to use an authenticated protected channel. Record compliance status based on the results." - id: PSI-2_gdn name: guidance prose: |- Compliance is determined by assessing the applicable specific controls (BCP-7, FCP-3) and verifying that any communications not covered by those controls also use an authenticated protected channel. "User agent" refers to the subscriber's browser or application. - id: PSI-3 title: Identity API Enumeration in Trust Agreement props: - value: 3.11.2 C class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PSI-3_smt name: statement prose: The use of identity APIs SHALL be enumerated in the terms of the trust agreement. - id: PSI-3_obj links: - rel: assessment-for href: "#PSI-3_smt" name: objective prose: Determine whether the use of identity APIs is enumerated in the trust agreement artifact(s). - props: - value: EXAMINE name: method class: assessment-summary id: PSI-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by IDAP-1. - id: PSI-3_gdn name: guidance prose: |- Assessment is required when: An identity API is used. Identity attributes MAY be included outside of the assertion itself by authorizing access to an identity API, as discussed in Sec. 3.12.3. Splitting identity information in this manner can help protect subscriber privacy and can allow for the limited disclosure of personal information in addition to the essential information in the authentication assertion itself. IDAP-1 establishes the requirement to record and disclose all possible use of identity APIs in the trust agreement artifact(s), including which provisioning models are available through the API. - id: SSIN-1 title: Personal Information Storage Security props: - value: 3.11.3 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIN-1_smt name: statement prose: "Whether the account is active or not, the IdP and RP SHALL store personal information in a subscriber account or RP subscriber account using tailored security controls defined in [SP800-53] or an equivalent federal (e.g., [FEDRAMP]) or industry standard." - id: SSIN-1_obj links: - rel: assessment-for href: "#SSIN-1_smt" name: objective prose: "Determine whether the IdP and RP store personal information in subscriber accounts using tailored security controls from [SP800-53] or an equivalent standard." - props: - value: EXAMINE name: method class: assessment-summary id: SSIN-1_asm-summary title: Assessment Method name: assessment-method prose: |- For IdPs, satisfied by SECC-1. For satisfied by SECC-3. - id: SSIN-1_gdn name: guidance prose: |- Storage of personal information is a form of processing. SECC-1 requires IdPs and CSPs to implement at least moderate baseline security controls. SECC-3 requires RPs that request or process personal information to implement at least moderate baseline security controls. - id: SSIN-2 title: Justification for Non-Deletion props: - value: 3.11.3 B class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIN-2_smt name: statement prose: IdPs and RPs that do not support deletion SHALL provide a statutory or risk-based justification and document it in the trust agreement. - id: SSIN-2_obj links: - rel: assessment-for href: "#SSIN-2_smt" name: objective prose: Determine whether IdPs and RPs that do not support deletion provide a statutory or risk-based justification documented in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIN-2_asm-examine name: assessment-method prose: "Examine evidence to determine whether the IdP or RP supports the deletion of personal information. If deletion is not supported, verify that a statutory or risk-based justification is documented in the trust agreement artifact(s), as required by TRUST-9." - id: SSIN-2_gdn name: guidance prose: |- Assessment is required when: The IdP/RP does not support the deletion of personal information. TRUST-9 requires trust agreement artifact(s) to declare data retention policies for all parties. This control adds the requirement that when deletion is not supported, a statutory or risk-based justification must be provided-general policy statements are insufficient. - id: SSIN-3 title: Attribute Removal Upon Account Termination props: - value: 3.11.3 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIN-3_smt name: statement prose: "When the RP subscriber account is terminated, the RP SHALL remove all subscriber attributes from storage, except when otherwise restricted by regulations, laws, or policies or when the risk of an application deems it essential." - id: SSIN-3_obj links: - rel: assessment-for href: "#SSIN-3_smt" name: objective prose: "Determine whether the RP removes all subscriber attributes from storage when the RP subscriber account is terminated, except when restricted by regulations, laws, policies, or application risk requirements." - props: - value: EXAMINE name: method class: assessment-summary id: SSIN-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RPSA-1. - id: SSIN-3_gdn name: guidance prose: "Assessment of attribute removal upon RP subscriber account termination is performed under RPSA-1, which covers the full scope of data removal, including federated identifiers, bound authenticators, attributes, and identity information. Exceptions must be documented with a specific regulatory, legal, policy, or risk-based justification; general data retention policies are insufficient." - id: IDA-1 title: Attribute Presentation Documentation props: - value: 3.12 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDA-1_smt name: statement prose: "Attributes SHALL be either unbundled (i.e., presented directly in an assertion by the IdP) or bundled into a package that is cryptographically signed by the CSP, as described in Sec. 3.12.1." - id: IDA-1_obj links: - rel: assessment-for href: "#IDA-1_smt" name: objective prose: "Determine whether the IdP documents which attribute presentation technique(s) it uses - unbundled, bundled, or both." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDA-1_asm-examine name: assessment-method prose: "Examine the IdP's technical documentation to confirm that the IdP specifies whether attributes are presented unbundled in assertions, bundled with CSP signatures per Section 3.12.1, or both. Verify that this documentation is available to RPs." - id: IDA-1_gdn name: guidance prose: "This documentation enables RPs to implement the appropriate validation logic. For unbundled attributes, the RP validates via the assertion signature. For bundled attributes, the RP must additionally validate the CSP's bundle signature per ABUN-2." - id: IDA-2 title: Attribute Type Documentation props: - value: 3.12 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDA-2_smt name: statement prose: "Attributes SHALL be either attribute values (e.g., a date of birth) or derived attribute values (e.g., an indication of age of majority)." - id: IDA-2_obj links: - rel: assessment-for href: "#IDA-2_smt" name: objective prose: "Determine whether the IdP documents which attribute types it provides - attribute values, derived attribute values, or both." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDA-2_asm-examine name: assessment-method prose: "Examine the IdP's technical documentation to confirm that the IdP specifies, for each attribute, whether it is an attribute value or a derived attribute value. Verify that this information is available to RPs." - id: IDA-2_gdn name: guidance prose: "RPs need to know whether they will receive actual attribute values (e.g., \"2/20/2000\") or derived values (e.g., \"over 21\"). This affects RP business logic and data handling. Derived attribute values support privacy by disclosing only what is necessary; see DAV-1." - id: IDA-3 title: Attribute Delivery Method Documentation props: - value: 3.12 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDA-3_smt name: statement prose: Attributes SHALL be either presented in the assertion and covered by the assertion's signature or be made available as part of a protected identity API. - id: IDA-3_obj links: - rel: assessment-for href: "#IDA-3_smt" name: objective prose: "Determine whether the IdP documents how attributes are delivered - in the assertion, via identity API, or both." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDA-3_asm-examine name: assessment-method prose: "Examine the IdP's technical documentation to confirm that the IdP specifies, for each attribute, whether it is delivered in the assertion or via an identity API. Verify that this information is available to RPs." - id: IDA-4 title: CSP Practice Statement Reference props: - value: 3.12 D class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDA-4_smt name: statement prose: Trust agreements SHALL point to the CSP's practice statements that describe the processes and sources used for attribute validation. - id: IDA-4_obj links: - rel: assessment-for href: "#IDA-4_smt" name: objective prose: Determine whether the trust agreement artifact(s) point to the CSP's practice statements describing the processes and sources used for attribute validation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDA-4_asm-examine name: assessment-method prose: Examine the trust agreement artifact(s) to verify that they include a reference to the CSP's practice statements. Review the referenced practice statements to verify that they describe the processes and sources used for attribute validation. - id: IDA-4_gdn name: guidance prose: "The CSP practice statement enables RPs to evaluate the trustworthiness of attributes by understanding how the CSP validates them. Practice statements typically describe evidence requirements, authoritative sources consulted, and validation procedures used during identity proofing or attribute collection." - id: ABUN-1 title: Attribute Bundle Presentation Protection props: - value: 3.12.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ABUN-1_smt name: statement prose: The presentation of an attribute bundle SHALL be protected by the IdP in the same manner as non-bundled attributes. - id: ABUN-1_obj links: - rel: assessment-for href: "#ABUN-1_smt" name: objective prose: Determine whether the IdP protects the presentation of attribute bundles in the same manner as non-bundled attributes. - props: - value: EXAMINE name: method class: assessment-summary id: ABUN-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SIGNA-1 and SIGNA-3. - id: ABUN-1_gdn name: guidance prose: |- Attribute bundles are protected by the IdP's assertion signature per SIGNA-1 and SIGNA-3. The attribute bundle also retains its own CSP signature, which the RP must validate per ABUN-2. Note: Other protocols and specifications often refer to attribute bundles as credentials. However, this term would be in conflict with its use within these guidelines for a different concept. Consequently, these guidelines use the term "attribute bundle" instead. - id: ABUN-2 title: Attribute Bundle Signature Validation props: - value: 3.12.1 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ABUN-2_smt name: statement prose: "The RP SHALL validate the signature specific to the attribute bundle as well as any container signatures, such as the signature of the assertion as a whole." - id: ABUN-2_obj links: - rel: assessment-for href: "#ABUN-2_smt" name: objective prose: Determine whether the RP validates both the signature specific to the attribute bundle and any container signatures such as the assertion signature. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ABUN-2_asm-test name: assessment-method prose: |- IdP assertion signature validation is satisfied by FAL1-2. For CSP-issued attribute bundles: Examine the RP's assertion processing documentation to verify that it validates the CSP's signature on the attribute bundle. Test by presenting an assertion containing an attribute bundle with an invalid bundle signature but a valid assertion signature. Verify that the RP rejects it. - id: ABUN-2_gdn name: guidance prose: Attribute bundles carry the CSP's signature attesting to the authenticity of the attributes. The assertion signature (validated per FAL1-2) protects the bundle from substitution or tampering during the federation transaction. See ARTVL-1 for the equivalent requirement in subscriber-controlled wallet scenarios. - id: ABUN-3 title: Bundle-Embedded IdP Verification Key Validation props: - value: 3.12.1 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ABUN-3_smt name: statement prose: The RP SHALL confirm that the assertion is presented by the identity claimed in the attribute bundle by verifying the signature over the assertion using the IdP's verification key in the signed attribute bundle. - id: ABUN-3_obj links: - rel: assessment-for href: "#ABUN-3_smt" name: objective prose: "Determine whether the RP uses the IdP verification key embedded in the CSP-signed attribute bundle to verify the assertion signature, thereby confirming the assertion was issued by the IdP authorized by the CSP to present the bundle." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ABUN-3_asm-examine name: assessment-method prose: Examine the RP's assertion-processing documentation to confirm that the RP extracts the IdP's verification key from the CSP-signed attribute bundle and uses it to verify the assertion's signature. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ABUN-3_asm-test name: assessment-method prose: "Test by presenting an assertion containing an attribute bundle with a valid embedded IdP verification key. Verify that the RP successfully validates the assertion signature using that key. Then, present an assertion signed by a different IdP than the one whose key is embedded in the attribute bundle. Verify the RP rejects the assertion." - id: ABUN-3_gdn name: guidance prose: |- Assessment is required when: The attribute bundle includes a verification key for the IdP. This control establishes a CSP-to-IdP binding. When the CSP signs an attribute bundle containing a specific IdP's verification key, the CSP restricts which IdP may present that bundle. The RP enforces this restriction by verifying the assertion signature against the embedded key, rather than a key obtained from metadata or trust agreement artifact(s). Note: The phrase "identity claimed in the attribute bundle" in the source text refers to the IdP whose verification key is embedded in the CSP-signed bundle. - id: DAV-1 title: Derived Attribute Value Non-Disclosure props: - value: 3.12.2 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DAV-1_smt name: statement prose: "To preserve privacy, derived attribute values SHALL NOT disclose the underlying attribute value to a requester." - id: DAV-1_obj links: - rel: assessment-for href: "#DAV-1_smt" name: objective prose: Determine whether derived attribute values are provided without disclosing the underlying attribute value. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DAV-1_asm-examine name: assessment-method prose: "Examine a sample or documentation describing IdP assertions and identity API responses containing derived attribute values. For each derived attribute (e.g., \"over 21\"), verify that the underlying attribute value (e.g., date of birth) is not also included in the same response." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: DAV-1_asm-test name: assessment-method prose: Test by request a derived attribute value from the IdP. Verify the response contains only the derived value and does not include the underlying attribute value. - id: DAV-1_gdn name: guidance prose: |- Assessment is required when: Derived attribute values are used. Derived attribute values exist to preserve privacy by disclosing only what is necessary. If the underlying value is also disclosed, the privacy benefit is negated. For example, if an RP only needs to know a subscriber is over 21, disclosing the full date of birth defeats the purpose. - id: IDAP-1 title: Identity API Disclosure in Trust Agreement props: - value: 3.12.3 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDAP-1_smt name: statement prose: "All possible use of identity APIs, including which provisioning models are available through the API, SHALL be recorded and disclosed as part of the trust agreement." - id: IDAP-1_obj links: - rel: assessment-for href: "#IDAP-1_smt" name: objective prose: Determine whether the trust agreement artifact(s) document the permitted uses of identity APIs and the provisioning models available through those APIs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDAP-1_asm-examine name: assessment-method prose: Examine the relevant trust agreement artifact(s) for each identity API offered to verify that they document all supported uses of the identity API and the provisioning model(s) available through the API. - id: IDAP-1_gdn name: guidance prose: |- Assessment is required when: An Identity API is offered by the IdP. Identity APIs allow RPs to retrieve subscriber attributes outside of the assertion itself. Provisioning models include pre-provisioning, just-in-time provisioning, and ephemeral provisioning (see Sec. 4.6.3). - id: IDAP-2 title: Identity API Access Time Limitation props: - value: 3.12.3 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDAP-2_smt name: statement prose: Access to the identity API SHALL be time-limited by the trust agreement. - id: IDAP-2_obj links: - rel: assessment-for href: "#IDAP-2_smt" name: objective prose: Determine whether access to the identity API is time-limited as specified in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDAP-2_asm-examine name: assessment-method prose: Examine the relevant trust agreement artifact(s) to verify that they specify time limits for identity API access. Review the IdP's identity API configuration to verify that access is time-limited in accordance with the trust agreement artifact(s). - id: IDAP-2_gdn name: guidance prose: |- Assessment is required when: An Identity API is offered by the IdP. Access to the identity API should be limited to the duration of the federation transaction plus the time necessary to synchronize attributes (see Sec. 4.6.4). Time limits prevent indefinite access to subscriber attributes after a federation transaction. - id: IDAP-3 title: Identity API Access Insufficient for Session Establishment props: - value: 3.12.3 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDAP-3_smt name: statement prose: "Since the time limitation is separate from the validity time window of the assertion and the lifetime of the authenticated session at the RP, access to an identity API by the RP without an associated valid assertion SHALL NOT be sufficient for the establishment of an authenticated session at the RP." - id: IDAP-3_obj links: - rel: assessment-for href: "#IDAP-3_smt" name: objective prose: "Determine whether the RP requires a valid assertion to establish an authenticated session for the subscriber, and does not establish sessions based solely on identity API access." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDAP-3_asm-examine name: assessment-method prose: "Examine the RP's session establishment documentation to verify that a valid assertion is required to establish an authenticated session, and that identity API access alone is insufficient." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDAP-3_asm-test name: assessment-method prose: Test by attempting to establish an RP session using only identity API access (without a valid assertion). Verify that the RP rejects session establishment. - id: IDAP-3_gdn name: guidance prose: |- Assessment is required when: An Identity API is offered by the IdP. Identity API access is separate from assertion validity and from the lifetime of any authenticated session. Therefore, the ability to call an identity API must not be treated as evidence of a successful federation transaction or used to create an authenticated session. See also RASR-2, which prohibits using identity API access to extend an existing session. - id: IDAP-4 title: Identity API Transaction Scope props: - value: 3.12.3 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDAP-4_smt name: statement prose: "When access to the identity API is granted within the context of a federation transaction, the attributes provided by an identity API SHALL be associated with only the single subscriber identified in the associated assertion." - id: IDAP-4_obj links: - rel: assessment-for href: "#IDAP-4_smt" name: objective prose: "Determine whether attributes provided by an identity API, when accessed within the context of a federation transaction, are associated only with the single subscriber identified in the associated assertion." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDAP-4_asm-examine name: assessment-method prose: "Examine the IdP's identity API documentation to verify that when access is granted within a federation transaction, returned attributes are scoped to the subscriber identified in the associated assertion." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDAP-4_asm-test name: assessment-method prose: "Test by attempting to use the identity API to retrieve attributes for a subscriber other than the one identified in the assertion, during a federation transaction. Verify that the IdP rejects or ignores the request." - id: IDAP-4_gdn name: guidance prose: |- Assessment is required when: An Identity API is offered by the IdP. An identity API deployment may be capable of providing attributes for all subscribers for whom the IdP can create assertions. This control ensures that when API access is granted during a federation transaction, the RP cannot use that access to query attributes for other subscribers. - id: IDAP-5 title: Identity API Subject Identifier Inclusion props: - value: 3.12.3 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDAP-5_smt name: statement prose: "If the identity API is hosted by the IdP, the returned attributes SHALL include the subject identifier for the subscriber." - id: IDAP-5_obj links: - rel: assessment-for href: "#IDAP-5_smt" name: objective prose: Determine whether the identity API returns the subject identifier for the subscriber when the API is hosted by the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDAP-5_asm-examine name: assessment-method prose: Examine the Identity API response structure to verify that the subject identifier is included in the returned attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDAP-5_asm-test name: assessment-method prose: Test by querying the identity API and verifying that the response includes the subject identifier for the subscriber. - id: IDAP-5_gdn name: guidance prose: |- Assessment is required when: An Identity API is offered by the IdP. The subject identifier allows the RP to correlate the identity API response with the assertion's subject, ensuring attributes are associated with the correct subscriber. - id: IDAP-6 title: Pre-Provisioning Privacy Evaluation props: - value: 3.12.3 F class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDAP-6_smt name: statement prose: "For pre-provisioning use cases, the privacy considerations SHALL be evaluated and recorded as part of the trust agreement." - id: IDAP-6_obj links: - rel: assessment-for href: "#IDAP-6_smt" name: objective prose: Determine whether privacy considerations for pre-provisioning use cases are evaluated and recorded in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDAP-6_asm-examine name: assessment-method prose: Examine the relevant trust agreement artifact(s) to verify that the privacy considerations for pre-provisioning are documented. - id: IDAP-6_gdn name: guidance prose: |- Assessment is required when: An Identity API is offered by the IdP and pre-provisioning is utilized. Pre-provisioning grants the RP access to subscriber attributes before any federation transaction, creating privacy risks that must be explicitly addressed. - id: EAI-1 title: External Identity API Documentation props: - value: 3.12.3.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: EAI-1_smt name: statement prose: Any use of external identity APIs for providing attributes SHALL be enumerated by the trust agreement as part of listing attribute sources. - id: EAI-1_obj links: - rel: assessment-for href: "#EAI-1_smt" name: objective prose: Determine whether any use of external identity APIs for providing attributes is enumerated in the trust agreement artifact(s) as part of listing attribute sources. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: EAI-1_asm-examine name: assessment-method prose: "Examine the relevant trust agreement artifact(s) to verify that the external identity APIs are listed as attribute sources, including which attributes are provided by each external API." - id: EAI-1_gdn name: guidance prose: |- Assessment is required when: External APIs are used for providing attributes. External identity APIs are hosted by a party other than the IdP and typically provide attributes from sources other than the CSP (e.g., a medical licensure agency providing license status). The IdP is responsible for associating the external identity API's content with the subscriber account. - id: ARTP-1 title: Assertion Protection Requirements props: - value: 3.13 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTP-1_smt name: statement prose: Assertions SHALL include a set of protections to prevent attackers from manufacturing valid assertions or reusing captured assertions at different RPs. - id: ARTP-1_obj links: - rel: assessment-for href: "#ARTP-1_smt" name: objective prose: Determine whether assertions include the required protection mechanisms. - props: - value: EXAMINE name: method class: assessment-summary id: ARTP-1_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by ARTI-1, SIGNA-1, SIGNA-3, SIGNA-4, and AUDR-1; and by ENCA-1 when assertions are encrypted." - id: ARTP-1_gdn name: guidance prose: "Assertions are the fundamental building block of a federated identity transaction, and protecting assertions is essential to the security of the overall system. If an attacker were able to create or modify an assertion and have that assertion accepted by an RP, the attacker would be able to impersonate a valid subscriber and log in to the target system. If an attacker were able to capture an assertion in transit and replay that assertion to a different RP, the attacker would be able to steal a valid session from the legitimate subscriber and log in to the target system. As a consequence, there are a suite of protections that are required for all assertions in a federated system, regardless of how the trust between the parties is established or how the assertion itself is." - id: ARTI-1 title: Assertion Uniqueness props: - value: 3.13.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTI-1_smt name: statement prose: Assertions SHALL be sufficiently unique to permit unique identification by the target RP. - id: ARTI-1_obj links: - rel: assessment-for href: "#ARTI-1_smt" name: objective prose: Determine whether assertions are sufficiently unique to permit unique identification by the target RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTI-1_asm-examine name: assessment-method prose: "Examine IdP's assertion structure(s) and documentation to verify inclusion of elements that enable unique identification (e.g., assertion identifier, embedded nonce, issuance timestamp)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTI-1_asm-test name: assessment-method prose: Test by generating multiple assertions and verifying that each can be uniquely identified by an RP. - id: ARTI-1_gdn name: guidance prose: "Unique identification supports replay protection, logging, auditing, and correlation of federation events. Common techniques include the use of an embedded nonce, an issuance timestamp, an assertion identifier, or a combination of these techniques." - id: SIGNA-1 title: Signed Assertions props: - value: 3.13.2 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SIGNA-1_smt name: statement prose: Assertions SHALL be cryptographically signed by the issuer (IdP). - id: SIGNA-1_obj links: - rel: assessment-for href: "#SIGNA-1_smt" name: objective prose: Determine whether assertions are signed by the IdP using appropriate cryptography. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SIGNA-1_asm-examine name: assessment-method prose: Examine the IdP's assertion configuration and documentation to determine that assertions are cryptographically signed by the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SIGNA-1_asm-test name: assessment-method prose: Test by having the IdP issue an assertion. Examine the assertion to determine whether it includes a digital signature or MAC that uses NIST-approved cryptography. - id: SIGNA-1_gdn name: guidance prose: "The IdP uses a signature to protect the contents of the assertion from modification by an attacker, and to prevent an attacker from creating a fraudulent assertion. Every assertion issued by the IdP needs to be signed and the signature attached to the assertion for transit and processing by the RP." - id: SIGNA-2 title: RP Signed Assertion Validation props: - value: 3.13.2 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SIGNA-2_smt name: statement prose: The RP SHALL validate the digital signature or MAC of each such assertion based on the issuer's verification key. - id: SIGNA-2_obj links: - rel: assessment-for href: "#SIGNA-2_smt" name: objective prose: Determine whether the RP validates the signature or MAC of an assertion. - props: - value: EXAMINE name: method class: assessment-summary id: SIGNA-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by FAL1-2. - id: SIGNA-2_gdn name: guidance prose: "It is not sufficient for the assertion to have a signature, the signature itself needs to have been made by the correct party (the IdP) and be valid for the signed content of the assertion. The RP is required to validate the signature as part of its processing." - id: SIGNA-3 title: Signature Coverage props: - value: 3.13.2 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SIGNA-3_smt name: statement prose: "This signature SHALL cover the entire assertion, including its identifier, issuer, audience, subject, and time validity window." - id: SIGNA-3_obj links: - rel: assessment-for href: "#SIGNA-3_smt" name: objective prose: Determine whether the signature method used to protect the assertion covers all required components. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SIGNA-3_asm-examine name: assessment-method prose: Examine the IdP's assertion configuration and documentation to determine that all necessary elements of the assertions are covered by the IdP signature. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SIGNA-3_asm-test name: assessment-method prose: Test by having the IdP generate an assertion. Examine the assertion to determine whether all required assertion components are covered by the signature. - id: SIGNA-3_gdn name: guidance prose: "Some signature mechanisms allow for selective coverage of the signature, placing some items outside of the cryptographic protection. This requirement specifies that all the required fields and vital information of the assertion need to be covered by the signature mechanism in use." - id: SIGNA-4 title: Signature Mechanisms props: - value: 3.13.2 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SIGNA-4_smt name: statement prose: The assertion signature SHALL either be a digital signature using asymmetric keys or a MAC using a symmetric key that is shared between the RP and issuer with approved cryptography. - id: SIGNA-4_obj links: - rel: assessment-for href: "#SIGNA-4_smt" name: objective prose: Determine whether the signature method used to protect the assertion and the keys used to create and verify it falls under one of these defined categories. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SIGNA-4_asm-examine name: assessment-method prose: "Examine the IdP's assertion signing configuration and documentation to verify that (1) the assertion signature uses either a digital signature with asymmetric keys or a MAC with a symmetric key shared between the RP and IdP, and (2) that the algorithm and key size conform to NIST-approved cryptography requirements as defined in SP 800-63C-4." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SIGNA-4_asm-test name: assessment-method prose: Test by generating an assertion and verifying that the signature method is one of the two permitted mechanisms and uses approved cryptography. - id: SIGNA-4_gdn name: guidance prose: "Assertions must be signed using one of two mechanisms: a digital signature using asymmetric keys, or a MAC using a symmetric key shared between the IdP and RP. Both mechanisms must use approved cryptography as defined in SP 800-63C-4. For digital signatures, the relevant standard is FIPS 186-5 (Digital Signature Standard). For MACs, relevant standards include FIPS 198-1 (HMAC) and SP 800-38B (CMAC). Assessors should verify the algorithm and key size against SP 800-131A." - id: ENCA-1 title: Encryption props: - value: 3.13.3 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ENCA-1_smt name: statement prose: "When encrypting assertions, the IdP SHALL encrypt the contents of the assertion using the RP's encryption key with approved cryptography." - id: ENCA-1_obj links: - rel: assessment-for href: "#ENCA-1_smt" name: objective prose: Determine whether the IdP uses approved cryptography and the RP's encryption key when encrypting assertions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ENCA-1_asm-examine name: assessment-method prose: "Examine the IdP's assertion encryption configuration and documentation to verify that assertions are encrypted using the RP's encryption key, and that the encryption algorithm and key size conform to NIST-approved cryptography requirements as defined in SP 800-63C-4." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ENCA-1_asm-test name: assessment-method prose: Test by generating an encrypted assertion and determining that it is encrypted for the intended RP using the configured encryption mechanism. - id: ENCA-1_gdn name: guidance prose: "SP 800-63C-4 defines approved cryptography as an encryption algorithm, hash function, random bit generator, or similar technique that is FIPS-approved or NIST-recommended. Approved algorithms and techniques are either specified or adopted in a FIPS or NIST recommendation. Assessors must verify that the IdP's assertion encryption algorithm and key size conform to these requirements." - id: AUDR-1 title: Assertion Audience Restriction props: - value: 3.13.4 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUDR-1_smt name: statement prose: Assertions SHALL use audience restriction techniques to allow an RP to recognize whether it is the intended target of an issued assertion. - id: AUDR-1_obj links: - rel: assessment-for href: "#AUDR-1_smt" name: objective prose: Determine whether all assertions include audience restrictions identifying the target RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUDR-1_asm-examine name: assessment-method prose: "Examine IdP documentation to verify that an audience restriction technique is implemented for all assertions. For FAL2+ transactions, examine sample assertions to confirm that the audience restriction field contains exactly one RP identifier." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AUDR-1_asm-test name: assessment-method prose: "Test by initiating a federation transaction and verifying that the resulting assertion contains audience restriction information identifying the target RP. For FAL2+ transactions, examine sample assertions to confirm that the audience restriction field contains exactly one RP identifier." - id: AUDR-1_gdn name: guidance prose: "Assertions are targeted messages from an IdP to an RP that are created in direct response to a specific federated login process. Each assertion must be targeted to specific RPs so that an assertion intended for one RP cannot be used at an unintended RP, either by the subscriber or an attacker. At FAL1, an assertion may include multiple target RPs. At FAL2 and above, assertions must be restricted to a single RP." - id: AUDR-2 title: RP Audience Validation props: - value: 3.13.4 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUDR-2_smt name: statement prose: All RPs SHALL check that the audience of an assertion contains an identifier for their RP to prevent the assertion injection and replay of an assertion generated for one RP at another RP. - id: AUDR-2_obj links: - rel: assessment-for href: "#AUDR-2_smt" name: objective prose: Determine whether RPs enforce audience restrictions in presented assertions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUDR-2_asm-examine name: assessment-method prose: Examine the RP documentation and configuration to confirm that audience validation occurs and that only assertions listing the RP's identifier are accepted. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUDR-2_asm-examine-2 name: assessment-method prose: "Examine the documented results of conformance testing to the federation standards, protocols, and/or profiles implemented by the RP, if available." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AUDR-2_asm-test name: assessment-method prose: "Test by presenting an assertion whose audience contains the RP's identifier and determining that the RP accepts it, and an assertion whose audience does not contain the RP's identifier and determining that the RP rejects it. If the RP accepts assertions with multiple audience identifiers at FAL1, test an assertion that contains the RP's identifier along with other RP identifiers and determine that the RP processes it correctly." - id: AUDR-2_gdn name: guidance prose: "If the RP utilizes an IdP that lists multiple RPs in a single assertion at FAL1, confirm that the RP correctly handles assertions containing multiple RP identifiers." - id: HKA-1 title: HoK Authenticator Identifier props: - value: 3.15 A class: index name: label - value: IdP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: HKA-1_smt name: statement prose: "A holder-of-key assertion (Fig. 3) SHALL include a unique identifier for an authenticator that can be verified independently by the RP, such as the public key of a certificate controlled by the subscriber." - id: HKA-1_obj links: - rel: assessment-for href: "#HKA-1_smt" name: objective prose: Determine whether HoK assertions include the public key (or key identifier) of the authenticator controlled by the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: HKA-1_asm-examine name: assessment-method prose: Examine the IdP HoK documentation to confirm that HoK assertions contain the necessary authenticator identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: HKA-1_asm-test name: assessment-method prose: "Test by generating a HoK assertion and verifying it contains a unique identifier for the subscriber's authenticator (e.g., a public key or key identifier)." - id: HKA-1_gdn name: guidance prose: "The public key allows the RP to verify that the subscriber controls the corresponding private key, binding the assertion to the subscriber." - id: HKA-2 title: HoK Validation props: - value: 3.15 B class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: HKA-2_smt name: statement prose: The RP SHALL verify that the subscriber possesses the authenticator identified by the assertion. Holder-of-key assertions are most often used when the authenticator technology is tied to a public-key infrastructure (PKI) trusted by both the IdP and RP. - id: HKA-2_obj links: - rel: assessment-for href: "#HKA-2_smt" name: objective prose: Determine whether the RP validates the subscriber's key for holder-of-key assertions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: HKA-2_asm-examine name: assessment-method prose: Examine the RP's assertion processing documentation to verify that holder-of-key authenticator verification is implemented before granting FAL3 access. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: HKA-2_asm-test name: assessment-method prose: "Test by presenting a holder-of-key assertion and authenticating with the correct subscriber key. Verify that the RP grants FAL3 access. Next, present a holder-of-key assertion and authenticate with an incorrect key. Verify rejection. Finally, present a holder-of-key assertion without presenting any key. Verify rejection." - id: HKA-2_gdn name: guidance prose: "Holder-of-key assertions are built around proving that a subscriber is not only known to the IdP, and therefore able to get an assertion issued, but also able to present proof of a cryptographic key in the assertion. This key represents the subscriber, not the IdP or the RP, and the proof of possession of the key is presented by the subscriber directly to the RP. This requirement does not assume that the RP has registered the key for the subscriber, and the subscriber key might be unknown to the RP ahead of processing the assertion. Additionally, the technology in place might use different keys for a subscriber over time. Because of these aspects, the RP needs to validate the subscriber's key separately upon login." - id: HKA-3 title: HoK Authenticator Phishing Resistance props: - value: 3.15 C class: index name: label - value: IdP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: HKA-3_smt name: statement prose: "The authenticator identified in a holder-of-key assertion SHALL be phishing-resistant, as defined by Sec. 3.2.5 of [SP800-63B]." - id: HKA-3_obj links: - rel: assessment-for href: "#HKA-3_smt" name: objective prose: "Determine whether the authenticator identified in the HoK assertion is phishing-resistant as defined by Sec. 3.2.5 of [SP800-63B]." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: HKA-3_asm-examine name: assessment-method prose: "Examine the documentation indicating the authenticator type(s) used in HoK assertions to verify that they meet phishing-resistance requirements per [SP800-63B] Sec. 3.2.5." - id: HKA-4 title: HoK Authenticator Account Resolution props: - value: 3.15 D class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: HKA-4_smt name: statement prose: "When the RP encounters an authenticator in a holder-of-key assertion for the first time, the RP SHALL ensure that the authenticator can be uniquely resolved to the RP subscriber account, as discussed in Sec. 3.8.2." - id: HKA-4_obj links: - rel: assessment-for href: "#HKA-4_smt" name: objective prose: Determine whether the RP ensures that a new HoK authenticator can be uniquely resolved to the RP subscriber account upon first encounter. - props: - value: EXAMINE name: method class: assessment-summary id: HKA-4_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ACCR-1. - id: HKA-5 title: HoK Prohibitions props: - value: 3.15 E class: index name: label - value: IdP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: HKA-5_smt name: statement prose: A holder-of-key assertion SHALL NOT include an unencrypted private key or symmetric key to be used as an authenticator. - id: HKA-5_obj links: - rel: assessment-for href: "#HKA-5_smt" name: objective prose: Determine whether the subscriber keys present in a holder-of-key assertion are of an appropriate type. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: HKA-5_asm-examine name: assessment-method prose: Examine IdP assertion generation documentation to confirm that assertions do not result in exposure of private keys or symmetric keys. Examine test assertions and logs of assertion tests to validate the operational configuration. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: HKA-5_asm-test name: assessment-method prose: Test by generating a holder-of-key assertion and ensure that the assertion does not include an unencrypted private key or symmetric key as the subscriber key. - id: HKA-5_gdn name: guidance prose: "The security of holder-of-key assertions stems from the separation of the key representing the subscriber and the assertion itself. The RP will need access to some set of keying material to verify the key presented by the subscriber in a holder-of-key assertion. There are different methods of identifying this keying material to the RP, such as including the public key of an asymmetric key pair in the assertion or including an identifier for a key that the RP can securely dereference. However, if the assertion were to include private key material or a symmetric key, then any reader of the assertion would be able to create a proof to present alongside the assertion. Therefore, these types of keys are not allowed to be included in the assertion in holder-of-key presentations." - id: BAUTH-1 title: Bound Authenticator Indicator props: - value: 3.16 A class: index name: label - value: IdP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-1_smt name: statement prose: The IdP SHALL include an indicator in the assertion when the assertion is to be used with a bound authenticator at FAL3. - id: BAUTH-1_obj links: - rel: assessment-for href: "#BAUTH-1_smt" name: objective prose: Determine whether the IdP includes an indicator in the assertion when the assertion is to be used with a bound authenticator at FAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-1_asm-examine name: assessment-method prose: Examine the assertion structure to verify inclusion of a bound authenticator indicator when bound authenticators are used at FAL3. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAUTH-1_asm-test name: assessment-method prose: Test by requesting an FAL3 assertion for use with a bound authenticator. Verify the assertion contains the expected bound authenticator indicator. - id: BAUTH-1_gdn name: guidance prose: |- The indicator signals to the RP that it must verify a bound authenticator before accepting the assertion. (Per ARTC-8, an FAL3 assertion must include either a HoK key identifier or a bound authenticator indicator.) - id: BAUTH-2 title: Bound Authenticator Identifier Storage props: - value: 3.16 B class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-2_smt name: statement prose: The unique identifier for the authenticator (such as its public key) SHALL be stored in the RP subscriber account. - id: BAUTH-2_obj links: - rel: assessment-for href: "#BAUTH-2_smt" name: objective prose: Determine whether the RP stores the unique identifier for the bound authenticator (such as its public key) in the RP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-2_asm-examine name: assessment-method prose: "Examine the RP subscriber account schema to identify where bound authenticator identifiers are stored. Then, examine sample RP subscriber accounts that have a bound authenticator and verify that the unique identifier (e.g., public key) is present." - id: BAUTH-3 title: Bound Authenticator Uniqueness props: - value: 3.16 C class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-3_smt name: statement prose: A bound authenticator SHALL be unique per subscriber at the RP such that two subscribers cannot present the same authenticator for their separate RP subscriber accounts. - id: BAUTH-3_obj links: - rel: assessment-for href: "#BAUTH-3_smt" name: objective prose: "Determine whether bound authenticators are unique per subscriber at the RP, such that two subscribers cannot present the same authenticator for their separate RP subscriber accounts." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-3_asm-examine name: assessment-method prose: Examine RP-bound authenticator binding logic to verify that a uniqueness constraint prevents the same authenticator identifier from being associated with multiple RP subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAUTH-3_asm-test name: assessment-method prose: Test by attempting to bind the same authenticator to two different RP subscriber accounts. Verify that the RP rejects the second binding. - id: BAUTH-4 title: Bound Authenticator Phishing Resistance props: - value: 3.16 D class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-4_smt name: statement prose: "All bound authenticators SHALL use phishing-resistant authentication mechanisms, as defined by Sec. 3.2.5 of [SP800-63B]." - id: BAUTH-4_obj links: - rel: assessment-for href: "#BAUTH-4_smt" name: objective prose: "Determine whether bound authenticators use phishing-resistant authentication mechanisms as defined by Sec. 3.2.5 of [SP800-63B]." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-4_asm-examine name: assessment-method prose: "Examine the documentation of the authenticator types permitted as bound authenticators to verify that they meet phishing-resistance requirements per [SP800-63B] Sec. 3.2.5." - id: BAUTH-5 title: Bound Authenticator Verification Timing props: - value: 3.16 E class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-5_smt name: statement prose: Bound authenticators SHALL be accepted for authentication in the context of processing an FAL3 assertion for a federated transaction. - id: BAUTH-5_obj links: - rel: assessment-for href: "#BAUTH-5_smt" name: objective prose: "Determine whether the RP verifies the bound authenticator during FAL3 assertion processing, rather than in a separate transaction." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-5_asm-examine name: assessment-method prose: Examine the RP's transaction flow documentation to verify that bound authenticator verification is integrated into the FAL3 assertion processing flow rather than performed as a separate authentication transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAUTH-5_asm-test name: assessment-method prose: "Test by initiating an FAL3 federated transaction requiring a bound authenticator, and successfully complete the bound authenticator verification. Verify that the RP accepts the bound authenticator and establishes the FAL3 session. Review the RP transaction logs to confirm the bound authenticator verification is recorded as part of the assertion processing event, not as a separate authentication event." - id: BAUTH-6 title: Bound vs. Direct Authentication Documentation props: - value: 3.16 F class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-6_smt name: statement prose: "While it is possible for the same authenticator to also be used for direct authentication to the RP (see Sec. 3.8.3), such use is not considered a bound authenticator, and the RP SHALL document these as distinct use cases." - id: BAUTH-6_obj links: - rel: assessment-for href: "#BAUTH-6_smt" name: objective prose: "Determine whether the RP documents for subscribers that bound authentication and direct authentication are distinct use cases, and whether the same authenticator may be used for both." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-6_asm-examine name: assessment-method prose: "Examine the RP's subscriber-facing documentation (e.g., help pages, account settings, authenticator registration guidance) to verify that the RP explains that bound authentication and direct authentication are distinct use cases, and states whether the RP permits the same authenticator to be used for both." - id: BAUTH-6_gdn name: guidance prose: |- Assessment is required when: An RP supports both bound and alternative authenticators. See ALTAP-2 for RP determination of permitted authenticator uses. - id: BAUTH-7 title: Pre-existing Bound Authenticator Reference in RP Subscriber Account props: - value: 3.16 G class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-7_smt name: statement prose: "Before an RP can successfully accept an FAL3 assertion, the RP subscriber account SHALL include a reference to a bound authenticator that is to be verified during the FAL3 transaction." - id: BAUTH-7_obj links: - rel: assessment-for href: "#BAUTH-7_smt" name: objective prose: Determine whether the RP subscriber account includes a reference to a bound authenticator before the RP accepts an FAL3 bound authenticator assertion. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-7_asm-examine name: assessment-method prose: Examine the RP's FAL3 assertion processing logic to verify that it checks for a bound authenticator reference in the RP subscriber account before accepting the assertion. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAUTH-7_asm-test name: assessment-method prose: Test by attempting to process an FAL3 assertion with a bound authenticator indicator for an RP subscriber account that has no bound authenticator reference. Verify the RP rejects the assertion. - id: BAUTH-7_gdn name: guidance prose: The bound authenticator must be registered to the RP subscriber account before it can be verified during an FAL3 transaction. - id: BAUTH-8 title: Bound Authenticator Change Notification props: - value: 3.16 H class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: BAUTH-8_smt name: statement prose: |- The RP SHALL send a notification to the subscriber via an out-of-band mechanism (e.g., an email to an address previously associated with the subscriber)...if any of the following events occur: (a) A new bound authenticator is added to the RP subscriber account. (b) An existing bound authenticator is removed from the RP subscriber account. - id: BAUTH-8_obj links: - rel: assessment-for href: "#BAUTH-8_smt" name: objective prose: Determine whether the RP sends an out-of-band notification to the subscriber when a bound authenticator is added to or removed from the RP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BAUTH-8_asm-examine name: assessment-method prose: Examine the RP's bound authenticator management system to verify that out-of-band notifications are configured to be sent when authenticators are added or removed. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BAUTH-8_asm-test name: assessment-method prose: "Test as follows: (1) Add a bound authenticator to an RP subscriber account. Verify that the subscriber receives an out-of-band notification. (2) Remove a bound authenticator from an RP subscriber account. Verify that the subscriber receives an out-of-band notification." - id: BAUTH-8_gdn name: guidance prose: "Out-of-band notifications alert the subscriber to potentially unauthorized changes to their account. See [SP800-63B] Sec. 4.6 for notification requirements and considerations." - id: RPPBAI-1 title: RP-Provided Bound Authenticator Issuance props: - value: 3.16.1 A class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: RPPBAI-1_smt name: statement prose: "For RP-provided authenticators, the system administrator of the RP SHALL issue the authenticator directly to the subscriber for use with an FAL3 federation transaction." - id: RPPBAI-1_obj links: - rel: assessment-for href: "#RPPBAI-1_smt" name: objective prose: Determine whether RP-provided bound authenticators are issued directly to the subscriber for use with FAL3 federation transactions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPPBAI-1_asm-examine name: assessment-method prose: "Examine the RP's authenticator issuance procedures and a sample of issuance records, tracking records, or other issuance evidence to determine that RP-provided bound authenticators are issued directly to the subscriber for use with an FAL3 federation transaction." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: RPPBAI-1_asm-interview name: assessment-method prose: "Interview the system administrator to determine that RP-provided bound authenticators are issued directly to the subscriber for use with an FAL3 federation transaction, if no recent issuance records are available." - id: RPPBAI-2 title: RP-Provided Bound Authenticator Subscriber Verification props: - value: 3.16.1 B class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: RPPBAI-2_smt name: statement prose: "The system administrator of the RP SHALL use an independent means to determine whether the identified subject of the RP subscriber account is the party to which the authenticator is issued. The system administrator of the RP SHALL follow the initial authenticator binding requirements in Sec. 4 of [SP800-63A] or the post-enrollment binding requirements in Sec. 4.1.2 of [SP800-63B], as appropriate." - id: RPPBAI-2_obj links: - rel: assessment-for href: "#RPPBAI-2_smt" name: objective prose: "Determine whether the RP system administrator verifies that the subscriber receiving the bound authenticator is the subject of the RP subscriber account by following the initial authenticator binding requirements in Sec. 4 of [SP800-63A] or the post-enrollment binding requirements in Sec. 4.1.2 of [SP800-63B]." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPPBAI-2_asm-examine name: assessment-method prose: "Examine the RP's bound authenticator issuance procedures to identify which binding path is used in each applicable case: Sec. 4 of SP 800-63A for initial binding or Sec. 4.1.2 of SP 800-63B for post-enrollment binding." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPPBAI-2_asm-examine-2 name: assessment-method prose: "Examine a sample of issuance records or other issuance evidence to determine that, for each sampled issuance, the system administrator used an independent means to determine that the identified subject of the RP subscriber account was the party receiving the authenticator and followed the applicable binding path." - props: - ns: http://csrc.nist.gov/ns/rmf value: INTERVIEW name: method id: RPPBAI-2_asm-interview name: assessment-method prose: Interview the system administrator if the records are insufficient to establish how the determination was made. - id: RPPBAI-2_gdn name: guidance prose: "The choice between 63A and 63B requirements depends on context: if the RP subscriber account was just established and this is the initial authenticator binding, use 63A requirements. If the subscriber already has an established account with authenticators and is adding an RP-provided bound authenticator, use 63B post-enrollment requirements." - id: RPPBAI-3 title: RP-Provided Bound Authenticator Identifier Storage props: - value: 3.16.1 C class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: RPPBAI-3_smt name: statement prose: "The system administrator of the RP SHALL store a unique identifier for the bound authenticator in the RP subscriber account, such as the public key of the authenticator." - id: RPPBAI-3_obj links: - rel: assessment-for href: "#RPPBAI-3_smt" name: objective prose: Determine whether the RP stores a unique identifier for each RP-provided bound authenticator in the associated RP subscriber account. - props: - value: EXAMINE name: method class: assessment-summary id: RPPBAI-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by BAUTH-2. - id: SUBPB-1 title: Binding Ceremony for Subscriber-Provided Bound Authenticators props: - value: 3.16.2 A class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-1_smt name: statement prose: "If no bound authenticators are associated with the RP subscriber account, the RP SHALL perform a binding ceremony to establish the connection between the authenticator, the subscriber, and the RP subscriber account, as shown in Fig. 5." - id: SUBPB-1_obj links: - rel: assessment-for href: "#SUBPB-1_smt" name: objective prose: "Determine whether the RP performs a binding ceremony to establish the connection between the authenticator, the subscriber, and the RP subscriber account, as shown in Fig. 5, when no bound authenticators are associated with the RP subscriber account." - props: - value: EXAMINE name: method class: assessment-summary id: SUBPB-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SUBPB-2 through SUBPB-12. - id: SUBPB-1_gdn name: guidance prose: |- This is a summative control. Compliance is determined by the results of all binding ceremony controls: SUBPB-2 through SUBPB-12. The RP MAY provide a process for associating subscriber-provided authenticators to the RP subscriber account on a trust-on-first-use basis. This process is known as a binding ceremony and has additional requirements beyond a typical FAL3 federation process. - id: SUBPB-2 title: Binding Ceremony Session Establishment props: - value: 3.16.2 B class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-2_smt name: statement prose: "The RP SHALL first establish an authenticated session using federation with an assertion that meets all the other requirements of FAL3, including an indication that the assertion is intended for use at FAL3 with a bound authenticator (e.g., the assertion contains an authentication class reference or a Vectors of Trust [RFC8485] value indicating this)." - id: SUBPB-2_obj links: - rel: assessment-for href: "#SUBPB-2_smt" name: objective prose: Determine whether the RP requires a valid FAL3 assertion with a bound authenticator indicator before initiating a binding ceremony. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUBPB-2_asm-examine name: assessment-method prose: Examine the RP binding ceremony implementation to verify that it requires an FAL3 assertion containing a bound authenticator indicator before the ceremony proceeds. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-2_asm-test name: assessment-method prose: Test by initiating an FAL3 bound authenticator request for an account that lacks a bound authenticator. Verify that the RP performs validation per CFAL-2 and initiates a binding ceremony session only if validation succeeds. - id: SUBPB-2_gdn name: guidance prose: |- Note: SUBPB-2 through SUBPB-12 should be evaluated together. This applies to the initial binding ceremony when no bound authenticator is yet associated with the RP subscriber account. The subscriber cannot prove possession of a bound authenticator at this stage because none has been bound yet. - id: SUBPB-3 title: Binding Ceremony Authenticator Prompt props: - value: 3.16.2 C class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-3_smt name: statement prose: The subscriber SHALL immediately be prompted to present and authenticate with the proposed authenticator. - id: SUBPB-3_obj links: - rel: assessment-for href: "#SUBPB-3_smt" name: objective prose: Determine whether the RP immediately prompts the subscriber to present and authenticate with the proposed authenticator after establishing the binding ceremony session. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-3_asm-test name: assessment-method prose: |- Continue from SUBPB-2 (binding ceremony session established). Test by verifying that the RP immediately prompts the subscriber to present and authenticate with the proposed authenticator. - id: SUBPB-4 title: Binding Ceremony Authenticator Identifier Storage props: - value: 3.16.2 D class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-4_smt name: statement prose: "Upon successful presentation of the authenticator, the RP SHALL store a unique identifier for the authenticator (such as its public key) and associate this with the RP subscriber account that is associated with the federated identifier." - id: SUBPB-4_obj links: - rel: assessment-for href: "#SUBPB-4_smt" name: objective prose: "Determine whether, during the binding ceremony, the RP stores a unique identifier for the authenticator and associates it with the RP subscriber account upon successful authenticator presentation." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-4_asm-test name: assessment-method prose: |- Continue from SUBPB-3 (successful authenticator presentation). Test by authenticating with an appropriate authenticator, then inspecting the RP subscriber account record to confirm that an authenticator identifier was stored that uniquely identifies the authenticator. - id: SUBPB-4_gdn name: guidance prose: This is functionally equivalent to RPPBAI-3 but is evaluated as a discrete step during a binding ceremony. - id: SUBPB-5 title: Binding Ceremony Session Timeout props: - value: 3.16.2 E class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-5_smt name: statement prose: The binding ceremony session SHALL have a timeout of five minutes or less. - id: SUBPB-5_obj links: - rel: assessment-for href: "#SUBPB-5_smt" name: objective prose: Determine whether the binding ceremony session has a timeout of five minutes or less. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-5_asm-test name: assessment-method prose: "Test by initiating a binding ceremony session and continuing through the RP prompt to the subscriber to present and authenticate with the proposed authenticator (SUBPB-3). Then, wait five minutes without authenticating. Verify that the session expires and the binding ceremony fails." - id: SUBPB-5_gdn name: guidance prose: "If the subscriber fails to successfully authenticate to the RP using an appropriate authenticator within five minutes of being prompted to do so, the binding ceremony fails." - id: SUBPB-6 title: Binding Ceremony Session Restriction props: - value: 3.16.2 F class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-6_smt name: statement prose: "The binding ceremony session... SHALL NOT be used as an authenticated session for any other purpose, as described in Sec. 3.9." - id: SUBPB-6_obj links: - rel: assessment-for href: "#SUBPB-6_smt" name: objective prose: Determine whether the RP restricts the binding ceremony session to binding purposes only and does not use it as an authenticated session for any other purpose. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-6_asm-test name: assessment-method prose: Test by attempting to access RP functions or resources that require an authenticated session during a binding ceremony session. Verify that the RP denies access. - id: SUBPB-6_gdn name: guidance prose: "Per Sec. 3.9, an authenticated session allows subscriber access to RP functions, identification, or attribute processing. The binding ceremony session exists solely to complete the binding process and must not grant these capabilities." - id: SUBPB-7 title: Post-Binding Ceremony Transaction Initiation props: - value: 3.16.2 G class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-7_smt name: statement prose: "Upon successful completion of the binding ceremony, the RP SHALL immediately request a new assertion from the IdP at FAL3." - id: SUBPB-7_obj links: - rel: assessment-for href: "#SUBPB-7_smt" name: objective prose: Determine whether the RP initiates a new FAL3 federation transaction immediately upon successful completion of the binding ceremony. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-7_asm-test name: assessment-method prose: "Test by verifying that the RP immediately initiates a new federation transaction requesting a new assertion at FAL3, following the completion of the binding ceremony." - id: SUBPB-8 title: Post-Binding Ceremony Authenticator Prompt props: - value: 3.16.2 H class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-8_smt name: statement prose: "Upon receiving the new assertion, the RP SHALL prompt the subscriber for the newly bound authenticator and SHALL validate the authenticator output." - id: SUBPB-8_obj links: - rel: assessment-for href: "#SUBPB-8_smt" name: objective prose: Determine whether the RP prompts the subscriber to authenticate with the newly bound authenticator upon receiving the new FAL3 assertion. - props: - value: EXAMINE name: method class: assessment-summary id: SUBPB-8_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RPPHBA-1. - id: SUBPB-8_gdn name: guidance prose: This is standard FAL3 bound authenticator processing applied to the post-binding ceremony context. - id: SUBPB-9 title: Adding an Additional Bound Authenticator (1) props: - value: 3.16.2 I class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-9_smt name: statement prose: "During the initial authentication step of the binding ceremony, the RP SHALL request authentication with an existing bound authenticator to reach FAL3." - id: SUBPB-9_obj links: - rel: assessment-for href: "#SUBPB-9_smt" name: objective prose: Determine whether the RP requires authentication with an existing bound authenticator during the initial step of the binding ceremony when adding additional bound authenticators to an account that already has one or more. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SUBPB-9_asm-examine name: assessment-method prose: "Examine the RP's binding ceremony implementation to confirm that when a subscriber account has one or more existing bound authenticators, the workflow for adding additional authenticators requires initial authentication with an existing bound authenticator at FAL3." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-9_asm-test name: assessment-method prose: "Test by identifying a test subscriber account with at least one existing bound authenticator. Using that account, initiate a binding ceremony for an additional authenticator. Verify the RP requests authentication with an existing bound authenticator as the initial step. Next, attempt to proceed with the binding ceremony without authenticating with an existing bound authenticator; verify the RP rejects the attempt." - id: SUBPB-9_gdn name: guidance prose: |- This requirement applies to the alternative binding ceremony workflow for adding authenticators to accounts that already have bound authenticators. Unlike the initial binding ceremony (SUBPB-1 through SUBPB-8), which uses federation at FAL3 with a trust-on-first-use approach, this workflow requires proof of possession of an existing bound authenticator before new authenticators can be bound. See SUBPB-10 for the subsequent step of authenticating with and associating the new authenticator. - id: SUBPB-10 title: Adding an Additional Bound Authenticator (2) props: - value: 3.16.2 J class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-10_smt name: statement prose: "Once this authentication is complete and the binding ceremony session is established, the RP SHALL request authentication with the new authenticator and associate it with the RP subscriber account as a bound authenticator." - id: SUBPB-10_obj links: - rel: assessment-for href: "#SUBPB-10_smt" name: objective prose: "Determine whether the RP, after the subscriber authenticates with an existing bound authenticator (SUBPB-9), requests authentication with the new bound authenticator and stores its identifier in the RP subscriber account." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-10_asm-test name: assessment-method prose: "Test by identifying a test subscriber account with at least one existing bound authenticator. Using that account, complete a binding ceremony to add an additional authenticator. Verify that the RP then prompts the subscriber to authenticate with that new authenticator. Authenticate with the new authenticator. Then, inspect the RP subscriber account record to confirm that a unique identifier for the new authenticator (such as its public key) was stored and associated with the account as a bound authenticator. Confirm that the account now contains at least two unique bound authenticator identifiers. Verify that the new authenticator can be used for subsequent FAL3 transactions." - id: SUBPB-11 title: Bound Authenticator Removal - Session Termination props: - value: 3.16.2 K class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-11_smt name: statement prose: "When a bound authenticator is removed, the RP SHALL terminate all current FAL3 sessions for the subscriber and SHALL require reauthentication of the subscriber from the IdP at FAL3." - id: SUBPB-11_obj links: - rel: assessment-for href: "#SUBPB-11_smt" name: objective prose: Determine whether the RP terminates all active FAL3 sessions for the subscriber and requires IdP reauthentication at FAL3 when a bound authenticator is removed from the RP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-11_asm-test name: assessment-method prose: "Test using a test subscriber account with at least one bound authenticator and an active FAL3 session by doing the following: (1) Establish one or more additional active FAL3 sessions for the test subscriber (e.g., multiple browser sessions or devices). (2) Remove a bound authenticator from the RP subscriber account. (3) Verify that all active FAL3 sessions for the subscriber are immediately terminated. (4) Attempt to access the RP at FAL3. Verify that the RP requires a new assertion from the IdP at FAL3 before granting access." - id: SUBPB-11_gdn name: guidance prose: |- This control addresses the security response when a bound authenticator is removed, whether initiated by the subscriber (e.g., lost or compromised authenticator) or by the RP (e.g., authenticator no longer meets requirements). Terminating all FAL3 sessions and requiring reauthentication ensures that any sessions potentially established using the removed authenticator are invalidated. See SUBPB-12 for the related requirement that the RP not prompt for the removed authenticator during this process. - id: SUBPB-12 title: Bound Authenticator Removal - No Prompt for Removed Authenticator props: - value: 3.16.2 L class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: SUBPB-12_smt name: statement prose: "The RP SHALL NOT prompt the subscriber to authenticate with the authenticator being removed, since the subscriber will often not have access to the authenticator in question during the unbinding process, particularly if the authenticator is lost or compromised." - id: SUBPB-12_obj links: - rel: assessment-for href: "#SUBPB-12_smt" name: objective prose: Determine whether the RP avoids prompting the subscriber to authenticate with the specific authenticator being removed during the unbinding process. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SUBPB-12_asm-test name: assessment-method prose: |- Test using a test subscriber account with at least one bound authenticator by initiating the removal of a bound authenticator from the RP subscriber account. Verify that the RP does not prompt the subscriber to authenticate with the authenticator while the authenticator is being removed. (Note: If the account has multiple bound authenticators, the RP may prompt for a different bound authenticator, but never the one being removed.) - id: RPPHBA-1 title: Bound Authenticator Verification props: - value: "3.17 #1" class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: RPPHBA-1_smt name: statement prose: "The subscriber SHALL prove possession of the bound authenticator to the RP, in addition to presenting the assertion itself." - id: RPPHBA-1_obj links: - rel: assessment-for href: "#RPPHBA-1_smt" name: objective prose: Determine whether the RP prompts the subscriber to prove possession of the expected authenticator and validates the authenticator output. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPPHBA-1_asm-test name: assessment-method prose: "Test by doing the following: (1) Initiate an FAL3 federation transaction. Verify the RP prompts the subscriber to prove possession of the authenticator in addition to presenting the assertion. (2) Authenticate with the correct authenticator. Verify FAL3 access is granted. (3) Authenticate with an incorrect authenticator. Verify rejection. (4) Present the assertion without any authenticator. Verify rejection." - id: RPPHBA-1_gdn name: guidance prose: |- Assessment is required when: Authentication is required at both the IdP and the RP. Note: This control was intended to apply to both HoK and bound authenticator assertions. When the errata corrections are issued, this control will be updated to read: "The subscriber SHALL prove possession of the authenticator to the RP, in addition to presenting the assertion itself." - id: RPPHBA-2 title: HoK Authenticator Reference Trust Level props: - value: "3.17 #2" class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: RPPHBA-2_smt name: statement prose: "For a holder-of-key assertion, a reference to a given authenticator that is found within an assertion SHALL be trusted at the same level as all other information within the assertion, as stipulated in the trust agreement." - id: RPPHBA-2_obj links: - rel: assessment-for href: "#RPPHBA-2_smt" name: objective prose: Determine whether the RP validates the complete HoK assertion and does not rely solely on verification of the referenced authenticator. - props: - value: EXAMINE name: method class: assessment-summary id: RPPHBA-2_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by CFAL-2 (assertion validation), FAL1-2 (signature verification), SIGNA-2 (signed assertion validation), and SIGNA-3 (signature coverage)." - id: RPPHBA-2_gdn name: guidance prose: |- Assessment is required when: The assertion is a HoK assertion. Note: This control was intended to apply to HoK assertions only. When the errata corrections are issued, this control will be moved to section 3.15. - id: RPPHBA-3 title: Assertion Validation with Bound Authenticator props: - value: "3.17 #3" class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: RPPHBA-3_smt name: statement prose: The RP SHALL process and validate the assertion in addition to the bound authenticator. - id: RPPHBA-3_obj links: - rel: assessment-for href: "#RPPHBA-3_smt" name: objective prose: Determine whether the RP validates the assertion from the IdP when processing transactions that require RP authenticator validation. - props: - value: EXAMINE name: method class: assessment-summary id: RPPHBA-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by CFAL-2. - id: RPPHBA-3_gdn name: guidance prose: |- Assessment is required when: Authentication is required at both the IdP and the RP. Note: This control was intended to apply to both HoK and bound authenticator assertions. When the errata corrections are issued, this control will be updated to read: "The RP SHALL process and validate the assertion in addition to verifying the authenticator." - id: RPPHBA-4 title: Bound Authenticator Failure Handling props: - value: "3.17 #4" class: index name: label - value: RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: RPPHBA-4_smt name: statement prose: Failure to authenticate with the bound authenticator SHALL result in an error at the RP and SHALL NOT create an authenticated session at the RP. - id: RPPHBA-4_obj links: - rel: assessment-for href: "#RPPHBA-4_smt" name: objective prose: Determine whether the RP rejects the transaction and prevents session creation when the subscriber fails to successfully authenticate at the RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPPHBA-4_asm-test name: assessment-method prose: "Test, using a test subscriber account with a bound authenticator, by initiating an FAL3 federation transaction with a valid bound authenticator assertion. When prompted for the bound authenticator, fail authentication (e.g., cancel the prompt, provide an incorrect activation factor, or allow the request to timeout). Verify that the RP returns an error and does not create an authenticated session." - id: RPPHBA-4_gdn name: guidance prose: |- Assessment is required when: Authentication is required at both the IdP and the RP. Note: This control was intended to apply to both HoK and bound authenticator assertions. When the errata corrections are issued, this control will be updated to read: "Failure to verify the authenticator SHALL result in an error at the RP and SHALL NOT create an authenticated session at the RP." - id: IDPAP-1 title: Account Provisioning Disclosure props: - value: 4.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPAP-1_smt name: statement prose: "In order to make subscriber accounts available through an IdP, the subscriber accounts need to be provisioned at the IdP. The means by which the subscriber account is provisioned to the IdP SHALL be disclosed in the trust agreement." - id: IDPAP-1_obj links: - rel: assessment-for href: "#IDPAP-1_smt" name: objective prose: Determine whether the trust agreement artifact(s) disclose the means by which subscriber accounts are provisioned to the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPAP-1_asm-examine name: assessment-method prose: Examine the relevant trust agreement artifact(s) to confirm that they include a description of the account provisioning method(s) used to make subscriber accounts available through the IdP. - id: IDPAP-1_gdn name: guidance prose: RPs rely on this disclosure to understand the provenance and trustworthiness of identity assertions. Different provisioning methods carry different risk profiles and may affect RP decisions about accepting assertions from a given IdP. - id: IDPAP-2 title: Attribute Bundle Signing props: - value: 4.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPAP-2_smt name: statement prose: |- If the CSP issues attribute bundles to the RP: The CSP SHALL sign attribute bundles issued to the IdP. - id: IDPAP-2_obj links: - rel: assessment-for href: "#IDPAP-2_smt" name: objective prose: Determine whether the CSP signs attribute bundles before issuing them to the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPAP-2_asm-test name: assessment-method prose: Test by obtaining an attribute bundle issued by the CSP to the IdP. Verify that the attribute bundle contains a valid cryptographic signature from the CSP. - id: IDPAP-2_gdn name: guidance prose: "The CSP can provide attributes from the subscriber account to the IdP as attribute values, derived attribute values, or attribute bundles." - id: TRUSTA-1 title: Trust Agreement Establishment Method props: - value: 4.3 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TRUSTA-1_smt name: statement prose: |- Trust agreements for general-purpose IdPs SHALL be established either: (a) As the result of an agreement by the federated parties, prior to the federation transaction; or (b) As the result of decision or action by the subscriber, during the federation transaction. - id: TRUSTA-1_obj links: - rel: assessment-for href: "#TRUSTA-1_smt" name: objective prose: Determine whether the IdP uses one of the two trust agreement establishment methods. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TRUSTA-1_asm-examine name: assessment-method prose: "Examine the relevant trust agreement artifact(s) to verify that the establishment method is either pre-established by the federated parties prior to the federation transaction, or subscriber-driven during the federation transaction." - id: TRUSTA-1_gdn name: guidance prose: |- For pre-established trust agreement requirements, see PETA series (Sec. 4.3.1). For subscriber-driven trust agreement requirements, see SDTAE series (Sec. 4.3.2). - id: PETA-1 title: Pre-Established Trust Agreement Terms props: - value: 4.3.1 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PETA-1_smt name: statement prose: |- When the trust agreement is established by the federated parties prior to the federation transaction, the trust agreement SHALL establish the following terms: (a) The set of subscriber attributes, derived attributes, and attribute bundles that the IdP can make available to the RP. (b) The attribute storage policy of the IdP for the subscriber account, including any available means for the subscriber to request deletion. (c) Any attribute sources from which the IdP receives applicable subscriber attributes, derived attributes, and attribute bundles, including the CSP. (d) Any identity APIs that are made available by the IdP, either directly or through an external provider, and which subscriber attributes are available at these APIs. (e) The population of subscriber accounts for which the IdP can create assertions. (f) Any additional uses of subscriber information beyond providing the identity service. (g) The set of subscriber attributes, derived attributes, and attribute bundles that the RP is allowed to request (i.e., a subset of the attributes made available). (h) The purpose for each attribute requested by the RP. (i) The provisioning models used by the RP for RP subscriber accounts. (j) The authorized party responsible for decisions regarding the release of subscriber attributes to the RP (e.g., the IdP organization, the subscriber). (k) The process and techniques used to inform subscribers about attribute sharing. (l) The process and techniques for collecting consent from the authorized party when necessary. (m) The xALs available from the IdP. (n) The xALs required by the RP. - id: PETA-1_obj links: - rel: assessment-for href: "#PETA-1_smt" name: objective prose: Determine whether pre-established trust agreement artifact(s) document all required terms. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PETA-1_asm-examine name: assessment-method prose: Examine the trust agreement artifact(s) and verify that each of the terms (a-n) is documented. - id: PETA-2 title: Trust Agreement Availability to Operators props: - value: 4.3.1 B class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PETA-2_smt name: statement prose: The terms of the trust agreement SHALL be available to the operators of the RP and the IdP upon its establishment. - id: PETA-2_obj links: - rel: assessment-for href: "#PETA-2_smt" name: objective prose: Determine whether trust agreement terms are made available to RP and IdP operators when the agreement is established. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PETA-2_asm-examine name: assessment-method prose: Examine the trust agreement artifact(s) accessible to both the IdP and RP operators to ensure that all terms required by PETA-1 are available to them. Confirm that the terms became available to them prior to the initiation of operational federated transactions between the RP and IdP. - id: PETA-3 title: Trust Agreement Availability to Subscribers props: - value: 4.3.1 C class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PETA-3_smt name: statement prose: The terms of the trust agreement SHALL be made available to subscribers upon request to the IdP or RP. - id: PETA-3_obj links: - rel: assessment-for href: "#PETA-3_smt" name: objective prose: Determine whether subscribers can obtain trust agreement terms upon request to the IdP or RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PETA-3_asm-test name: assessment-method prose: "Test by requesting the trust agreement terms documented in PETA-1, as a subscriber. Verify that the terms are provided." - id: PETA-4 title: Redress Mechanism Assessment & Disclosure props: - value: 4.3.1 D class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PETA-4_smt name: statement prose: The IdP and RP SHALL each assess their respective redress mechanisms for efficacy in resolving complaints or problems and disclose the results of this assessment as part of the trust agreement. - id: PETA-4_obj links: - rel: assessment-for href: "#PETA-4_smt" name: objective prose: Determine whether the assessed party has evaluated its redress mechanisms and disclosed the assessment results in trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PETA-4_asm-examine name: assessment-method prose: "Examine the relevant trust agreement artifact(s) to verify that they include the results of the party's assessment of the efficacy of its redress mechanism, and that the information has been made available to the other party." - id: PETA-4_gdn name: guidance prose: See Sec. 3.5.3 (RR-1 to RR-6) for additional requirements and considerations for redress mechanisms. - id: PETA-5 title: FAL3 Trust Agreement Terms props: - value: 4.3.1 E class: index name: label - value: IdP/RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: PETA-5_smt name: statement prose: |- If FAL3 is allowed within the trust agreement, the trust agreement SHALL stipulate the following terms regarding holder-of-key assertions (see Sec. 3.15) and bound authenticators (see Sec. 3.16): (a) The means by which holder-of-key assertions can be verified by the RP (such as a common trusted PKI system). (b) The means by which the RP can associate holder-of-key assertions with specific. RP subscriber accounts (such as attribute-based account resolution or pre-provisioning) (c) Whether bound authenticators are supplied by the RP or the subscriber. (d) Documentation of the binding ceremony used for any subscriber-provided bound authenticators. - id: PETA-5_obj links: - rel: assessment-for href: "#PETA-5_smt" name: objective prose: Determine whether trust agreement artifact(s) document all required holder-of-key and bound authenticator terms when FAL 3 is permitted. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PETA-5_asm-examine name: assessment-method prose: "Examine the relevant trust agreement artifact(s) and verify the following: (1) If holder-of-key assertions are used, terms (a) and (b) are documented. (2) If bound authenticators are used, term (c) is documented. (3) If subscriber-provided bound authenticators are used, term (d) is documented." - id: PETA-6 title: Shared Signaling Trust Agreement Terms props: - value: 4.3.1 F class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PETA-6_smt name: statement prose: "If shared signaling is used by the IdP or RP (see Sec. 4.8), the terms of the trust agreement SHALL establish: the events that trigger a signal to be sent; which signals are sent for each trigger; the information included in each signal; and the expected behavior of the party receiving the signal." - id: PETA-6_obj links: - rel: assessment-for href: "#PETA-6_smt" name: objective prose: Determine whether the trust agreement artifact(s) establish all four required elements for shared signaling. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PETA-6_asm-examine name: assessment-method prose: |- Examine the relevant trust agreement artifact(s) to verify documentation of each required element: (1) Triggering events: Identify and list each event that initiates a signal (e.g., account compromise detection, account termination, credential revocation). (2) Signal types per trigger: For each triggering event, verify that the specific signal(s) to be sent are identified. (3) Signal content: For each signal type, verify that the information included is specified (including whether personal information is included per SSIG-5). (4) Receiver processing: For each signal type, verify that the expected behavior of the receiving party is defined. - id: PETA-6_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used. This control ensures operational clarity for shared signaling by requiring explicit documentation of the complete signal lifecycle: trigger -> signal selection -> content -> response. SSIG-2 requires that this documentation be made available to authorized parties. - id: PETA-7 title: Trust Agreement Periodic Review props: - value: 4.3.1 G class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PETA-7_smt name: statement prose: The trust agreement SHALL be reviewed periodically to ensure that it is still fit for purpose and to avoid unnecessary data exchange and the over-collection of subscriber data. - id: PETA-7_obj links: - rel: assessment-for href: "#PETA-7_smt" name: objective prose: "Determine whether the trust agreement is periodically reviewed, and that, as part of that review, subscriber data collection and data exchanges are assessed to determine whether they are still necessary." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PETA-7_asm-examine name: assessment-method prose: "Examine relevant documentation to verify that the cadence of trust agreement reviews is documented and that clear ownership for the review is assigned. Determine whether the periodic reviews address whether the trust agreement remains fit for purpose and whether subscriber data exchange and collection remain necessary. For trust agreements that have been in effect long enough for a review cycle to have occurred, verify that reviews have been conducted as scheduled." - id: SDTAE-1 title: Subscriber-Driven Trust Agreement Disclosure Terms props: - value: 4.3.2 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SDTAE-1_smt name: statement prose: |- In a subscriber-driven trust agreement, the trust agreement takes the form of a set of terms of use as opposed to a formal contract between parties. Consequently, the following terms SHALL be disclosed to the subscriber upon request: (a) Any attribute sources from which the IdP receives applicable subscriber attributes, including the CSP. (b) Any identity APIs that are made available by the IdP, either directly or through an external provider, and which subscriber attributes are available at these APIs. (c) The set of subscriber attributes, derived attributes, and attribute bundles that the IdP can make available to the RP. (d) The attribute storage policy of the IdP for the subscriber account, including any available means for the subscriber to request deletion; the use of any shared signaling between the IdP and RP. (e) The population of subscriber accounts for which the IdP can create assertions; any additional uses of subscriber information, beyond providing the identity service; the xALs available from the IdP. (f) The xALs required by the RP. - id: SDTAE-1_obj links: - rel: assessment-for href: "#SDTAE-1_smt" name: objective prose: Determine whether the IdP discloses the required terms to subscribers upon request. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SDTAE-1_asm-test name: assessment-method prose: "Test by requesting the trust agreement terms from the IdP, as a subscriber. Verify that all nine terms are provided." - id: SDTAE-1_gdn name: guidance prose: "Assessment is required when: The subscriber is the authorized party." - id: SDTAE-2 title: Subscriber-Driven Redress Assessment Disclosure props: - value: 4.3.2 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SDTAE-2_smt name: statement prose: The IdP SHALL assess its redress mechanisms for efficacy in resolving complaints or problems and disclose the results of this assessment to the subscriber. - id: SDTAE-2_obj links: - rel: assessment-for href: "#SDTAE-2_smt" name: objective prose: Determine whether the IdP has assessed the efficacy of its redress mechanisms and discloses the results to subscribers. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SDTAE-2_asm-test name: assessment-method prose: |- The redress mechanism efficacy assessment is satisfied by PETA-4. Test for disclosure to the subscriber by requesting the results of the redress mechanism efficacy assessment, as a test subscriber. Verify that the results are provided. - id: SDTAE-2_gdn name: guidance prose: |- Assessment is required when: The subscriber is the authorized party. See Sec. 3.5.3 for additional requirements and considerations for redress mechanisms. (RR-1, RR-3, RR-4, RR-6) - id: SDTAE-3 title: Subscriber-Driven Attribute Release props: - value: 4.3.2 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SDTAE-3_smt name: statement prose: "The release of subscriber attributes SHALL be managed using a runtime decision at the IdP, as described in Sec. 4.6.1.3. The authorized party SHALL be the subscriber." - id: SDTAE-3_obj links: - rel: assessment-for href: "#SDTAE-3_smt" name: objective prose: Determine whether the IdP manages attribute release using runtime decisions with the subscriber as the authorized party. - props: - value: EXAMINE name: method class: assessment-summary id: SDTAE-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by AAD-6. - id: SDTAE-3_gdn name: guidance prose: "Assessment is required when: The subscriber is the authorized party." - id: SDTAE-4 title: Runtime Decision Disclosure Terms props: - value: 4.3.2 D class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SDTAE-4_smt name: statement prose: |- The following terms of the trust agreement SHALL be disclosed to the subscriber during the runtime decision: (a) The set of subscriber attributes, derived attributes, and attribute bundles that the RP will request (i.e., a subset of the attributes made available by the IdP). (b) The purpose for each attribute requested by the RP. (c) The attribute storage policy of the RP for the RP subscriber account, including any available means for the subscriber to request deletion. - id: SDTAE-4_obj links: - rel: assessment-for href: "#SDTAE-4_smt" name: objective prose: "Determine whether the subscriber is informed of the requested attributes, their purpose, and the RP's storage policy prior to making the runtime attribute-release decision." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SDTAE-4_asm-test name: assessment-method prose: |- Test by initiating a federation transaction that triggers a runtime decision, as a test subscriber. Before making the attribute-release decision as the subscriber, verify that the following disclosures are presented to the subscriber across the IdP's and RP's combined interfaces: (1) the attributes the RP is requesting (see also IDPRD-3); (2) the purpose of the requested attributes; and (3) the RP's attribute storage policy, including deletion options. For each disclosure, record whether it was presented by the IdP, the RP, or both. If any disclosure is absent from both, the control is not satisfied. For RPs, repeat this test for each IdP (or wallet) supported by the RP. For IdPs, repeat this test for a representative sample of RPs that use the IdP. - id: SDTAE-4_gdn name: guidance prose: |- Assessment is required when: The subscriber is the authorized party. All information disclosed to the subscriber needs to be conveyed in a manner that is understandable and actionable, as discussed in Sec. 8. - id: DR-1 title: IdP Identifier-Key Association props: - value: 4.4 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DR-1_smt name: statement prose: "The RP SHALL associate the assertion validation keys and other relevant configuration information with the IdP's identifier, as stipulated by the trust agreement." - id: DR-1_obj links: - rel: assessment-for href: "#DR-1_smt" name: objective prose: Determine whether the RP associates the IdP's public signing key(s) and configuration information with the IdP's identifier per the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DR-1_asm-examine name: assessment-method prose: "Examine the RP's federation configuration and discovery/registration to determine that the RP associates the IdP's assertion validation key(s), and other relevant IdP-specific configuration information with the IdP's identifier, as stipulated by the trust agreement artifacts." - id: DR-1_gdn name: guidance prose: See FAL3-4 for the related requirement that each party's identifier be uniquely associated with its verification keys. - id: DR-2 title: Network Key Retrieval Protection props: - value: 4.4 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DR-2_smt name: statement prose: "If the validation keys and configuration information are retrieved over a network connection, request and retrieval SHALL be made over an authenticated protected channel from a location that is associated with the IdP's identifier by the trust agreement." - id: DR-2_obj links: - rel: assessment-for href: "#DR-2_smt" name: objective prose: Determine whether the RP retrieves IdP keys and configuration information over an authenticated protected channel from a location specified in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DR-2_asm-examine name: assessment-method prose: |- Examine the relevant trust agreement artifact(s) to determine the location(s) associated with the IdP's identifier for retrieval of validation keys and configuration information. Examine the RP's federation configuration to verify that it retrieves keys and configuration information only from the specified location(s). The requirement that an authenticated protected channel be used is satisfied by ICKM-2. - id: DR-2_gdn name: guidance prose: |- Assessment is required when: The validation keys and configuration information are retrieved over a network connection. In many federation protocols, this is accomplished by the RP fetching the public keys and configuration data from a URL specified in the trust agreement artifact(s) as controlled by the IdP or offered on the IdP's behalf. It is also possible for the RP to be configured directly with this information in a manual fashion, whereby the RP's system administrator enters the IdP information directly into the RP software's configuration. - id: DR-3 title: RP Registration props: - value: 4.4 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DR-3_smt name: statement prose: "The RP SHALL register its information with either the IdP or an authority that the IdP trusts, as stipulated by the trust agreement." - id: DR-3_obj links: - rel: assessment-for href: "#DR-3_smt" name: objective prose: Determine whether the RP has registered its information with the IdP or an IdP-trusted authority per the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DR-3_asm-examine name: assessment-method prose: |- Examine the relevant trust agreement artifact(s) to identify the required RP registration mechanism (direct with the IdP or via a federation authority). Verify that the RP has completed registration via the specified mechanism. - id: DR-3_gdn name: guidance prose: |- In many federation protocols, the RP is assigned an identifier during this stage, which the RP will use in subsequent communication with the IdP. See also ICKM-1. - id: MR-1 title: Automated Tooling for Manual Registration props: - value: 4.4.1 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: MR-1_smt name: statement prose: "If [automated updates are utilized following manual registration], the trust agreement SHALL enumerate the allowable terms of the cryptographic key distribution and assignment, including allowable cache lifetimes." - id: MR-1_obj links: - rel: assessment-for href: "#MR-1_smt" name: objective prose: "Determine whether trust agreement artifact(s) document the allowable terms for cryptographic key distribution and assignment, including allowable cache lifetimes, when automated updates are used following manual registration." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: MR-1_asm-examine name: assessment-method prose: |- Examine the relevant trust agreement artifact(s) to verify that they include the allowable terms of cryptographic key distribution and assignment, and the allowable cache lifetimes. - id: MR-1_gdn name: guidance prose: |- Assessment is required when: Automated updates are utilized following manual registration. Key updates following manual registration may be facilitated by automated tooling that points systems to a trusted source of information (e.g., a metadata URL) that can be updated over time. Cache lifetimes determine how long a party may use cached keys before re-fetching. - id: DYR-1 title: Dynamic Registration Channel Protection props: - value: 4.4.2 A class: index name: label - value: RP class: target name: marking - value: FAL1/FAL2 class: xal-level name: marking parts: - id: DYR-1_smt name: statement prose: All transmission of configuration information SHALL be made over a secure protected channel to endpoints that are associated with the IdP's identifier by the trust agreement. - id: DYR-1_obj links: - rel: assessment-for href: "#DYR-1_smt" name: objective prose: Determine whether configuration information transmitted during dynamic registration uses an authenticated protected channel to endpoints associated with the IdP per the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DYR-1_asm-examine name: assessment-method prose: Examine the relevant trust agreement artifact(s) to identify the endpoint(s) associated with the IdP's identifier for dynamic registration. Verify the RP is configured to use the specified endpoint(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: DYR-1_asm-test name: assessment-method prose: |- Test by initiating a dynamic registration from the RP and verify that configuration information is transmitted only to the endpoint(s) specified in the trust agreement artifact(s). The requirement that an authenticated protected channel be used is satisfied by ICKM-2. - id: DYR-1_gdn name: guidance prose: |- Assessment is required when: Dynamic registration is used. At FAL1 and FAL2, the cryptographic keys and identifiers of the RP can be exchanged in a dynamic process, whereby the RP software presents its configuration to the IdP either directly or through a trusted third party and receives the identifier to use with that IdP. This process is specific to the federation protocol in use but requires machine-readable configuration data to be made available over the network. - id: SAI-1 title: Subscriber Authentication Before IdP Actions props: - value: 4.5 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SAI-1_smt name: statement prose: |- The IdP SHALL require the subscriber to have an authenticated session before any of the following events: (a) Approval of attribute release. (b) Creation and issuance of an assertion. (c) Establishment of a subscriber-driven trust agreement. - id: SAI-1_obj links: - rel: assessment-for href: "#SAI-1_smt" name: objective prose: "Determine whether the IdP requires the subscriber to have an authenticated session before approving attribute release, creating/issuing assertions, or establishing subscriber-driven trust agreements." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SAI-1_asm-test name: assessment-method prose: "Test by (1) attempting to approve attribute release without an authenticated session. Verify that the IdP rejects the attempt. (2) Attempt to trigger assertion creation without an authenticated session. Verify that the IdP rejects the attempt. (3) If subscriber-driven trust agreements are supported, attempt to establish one without an authenticated session. Verify that the IdP rejects the attempt." - id: SAI-1_gdn name: guidance prose: "In a federation context, the IdP acts as the verifier for authenticators bound to the subscriber account, as described in [SP800-63B]. Verification of one or more authenticators creates an authentication event that begins the authenticated session at the IdP. This authentication event serves as the basis of the IdP's claim that the subscriber is present." - id: AUTHAD-1 title: Authorized Party Decision props: - value: 4.6 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUTHAD-1_smt name: statement prose: "The authorized party stipulated by the trust agreement SHALL decide whether a federation transaction proceeds and, therefore, whether an assertion is issued and attributes are released to the RP." - id: AUTHAD-1_obj links: - rel: assessment-for href: "#AUTHAD-1_smt" name: objective prose: Determine whether the authorized party identified in the trust agreement artifact(s) makes the decision on whether federation transactions proceed. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AUTHAD-1_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to identify the designated authorized party or parties for the RPs supported by the IdP. Ensure that all covered cases are assessed by the authorized party identified in the trust agreement. If the subscriber is an authorized party, satisfied by IDPRD-1 through IDPRD-8. If the organization is an authorized party satisfied by IALRP-1 through IALRP-6, and IDPBRP-1 and IDPBRP-2." - id: AUTHAD-1_gdn name: guidance prose: |- This decision can be calculated in a variety of ways, including: - An allowlist, which determines the circumstances under which the system can allow the federation transaction to proceed in an automated fashion; - A blocklist, which determines the circumstances under which the system will not allow the federation transaction to proceed; and - A runtime decision, which allows the authorized party (e.g., the subscriber) to decide whether the transaction can proceed and under what precise terms. A runtime decision can be stored and applied to future transactions. The applicability of an allowlist, blocklist, or runtime decision can be influenced by aspects of the federation transaction, including the identity of the IdP and RP, the subscriber attributes requested, the xAL required, and other factors. These decisions can be facilitated by risk management systems, federation authorities, and local system policies. For a non-normative example of an RP that has been allowlisted at an IdP for a set of subscribers to facilitate single sign-on for an enterprise application, see Sec. 9.5. - id: AUTHAD-2 title: IdP Redress Mechanisms props: - value: 4.6 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AUTHAD-2_smt name: statement prose: "The IdP SHALL provide effective mechanisms for the redress of subscriber complaints or problems (e.g., subscriber identifies an inaccurate attribute value)." - id: AUTHAD-2_obj links: - rel: assessment-for href: "#AUTHAD-2_smt" name: objective prose: Determine whether the IdP provides effective mechanisms for redress of subscriber complaints or problems. - props: - value: EXAMINE name: method class: assessment-summary id: AUTHAD-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RR-3. - id: AUTHAD-2_gdn name: guidance prose: "IdPs need to provide effective mechanisms for redress of subscriber complaints or problems arising from the federation (e.g., subscriber identifies an inaccurate attribute value). The Privacy Act requires federal agencies that maintain a system of records to follow procedures to enable applicants to access and, if incorrect, amend their records. Any Privacy Act Statement should include a reference to the applicable SORN(s), which provide the subscriber with instructions on how to make a request for access or correction. Non-federal entities should have comparable procedures, including contact information for any third parties if they are the source of the information." - id: IALRP-1 title: "Allowlist: RP Conformance" props: - value: 4.6.1.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IALRP-1_smt name: statement prose: "When placing an RP on its allowlist, the IdP SHALL confirm that the RP abides by the terms of the trust agreement." - id: IALRP-1_obj links: - rel: assessment-for href: "#IALRP-1_smt" name: objective prose: Determine whether RPs in an IdP's allowlist are compliant with the terms of their trust agreement. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IALRP-1_asm-examine name: assessment-method prose: "Examine the IdP's policies and procedures for adding RPs to the allowlist to verify that a process exists to confirm RP compliance with the trust agreement artifact(s) before allowlisting. For a sample of allowlisted RPs, verify that evidence of compliance exists (e.g., review records, attestations, federation authority approval)." - id: IALRP-1_gdn name: guidance prose: "Assessment is required when: The IdP utilizes an allowlist for RPs." - id: IALRP-2 title: "Allowlist: IdP Attribute Determination for RPs" props: - value: 4.6.1.1 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IALRP-2_smt name: statement prose: The IdP SHALL determine which identity attributes are passed to the allowlisted RP upon authentication. - id: IALRP-2_obj links: - rel: assessment-for href: "#IALRP-2_smt" name: objective prose: Determine whether the IdP controls which identity attributes are released to allowlisted RPs upon authentication. - props: - value: EXAMINE name: method class: assessment-summary id: IALRP-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by IALRP-5 and IALRP-6. - id: IALRP-2_gdn name: guidance prose: "Assessment is required when: The IdP utilizes an allowlist for RPs." - id: IALRP-3 title: "Allowlist: Subscriber Availability" props: - value: 4.6.1.1 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IALRP-3_smt name: statement prose: "IdPs SHALL make allowlists available to subscribers, as described in Sec. 7.2." - id: IALRP-3_obj links: - rel: assessment-for href: "#IALRP-3_smt" name: objective prose: Determine whether the list of allowlisted RPs is available to subscribers. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IALRP-3_asm-examine name: assessment-method prose: Examine the IdP's allowlist configuration to identify the full set of allowlisted RPs applicable to a test subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IALRP-3_asm-test name: assessment-method prose: "Test by requesting the allowlist from the IdP, as the same test subscriber above. Compare the returned list against the allowlist identified in the examine step and verify it is complete." - id: IALRP-3_gdn name: guidance prose: |- Assessment is required when: The IdP utilizes an allowlist for RPs. When an RP is allowlisted by an IdP, some subset of the subscriber's information is made available to the RP during the login process without the subscriber being prompted at runtime for additional consent or confirmation. The IdP needs to make the list of allowlisted RPs available to subscribers to allow subscribers to view which sites their information will be sent to during a federation transaction without the subscriber being specifically prompted. - id: IALRP-4 title: "Allowlist: RP Identification" props: - value: 4.6.1.1 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IALRP-4_smt name: statement prose: "IdP allowlists SHALL uniquely identify RPs through fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. Any entities that share an identifier SHALL be considered equivalent for the purposes of the allowlist. An allowlist entry for an RP SHALL NOT use a wildcard domain identifier." - id: IALRP-4_obj links: - rel: assessment-for href: "#IALRP-4_smt" name: objective prose: "Determine whether IdP allowlist entries uniquely identify RPs using appropriate identifiers, and whether entities sharing an identifier are treated as equivalent." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IALRP-4_asm-examine name: assessment-method prose: "Examine the IdP allowlist entries and verify each RP is identified using fully qualified domain names, cryptographic keys, or other protocol-appropriate unique identifiers. Verify that no wildcard domain identifiers are used." - id: IALRP-4_gdn name: guidance prose: |- Assessment is required when: The IdP utilizes an allowlist for RPs. For blocklists, see IDPBRP-2. - id: IALRP-5 title: "Allowlist: Attribute Indication" props: - value: 4.6.1.1 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IALRP-5_smt name: statement prose: IdP allowlist entries for an RP SHALL indicate which attributes are included as part of an allowlisted decision. - id: IALRP-5_obj links: - rel: assessment-for href: "#IALRP-5_smt" name: objective prose: Determine whether IdP allowlist entries specify which attributes can be released to each allowlisted RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IALRP-5_asm-examine name: assessment-method prose: Examine the IdP allowlist entries and verify that each entry specifies the attributes that can be released to the RP. - id: IALRP-5_gdn name: guidance prose: |- Assessment is required when: The IdP utilizes an allowlist for RPs. Allowlist entries must not just identify the RP, but also define what attributes can be released. See IALRP-6 for handling of RP requests for additional attributes beyond the allowlist entry. - id: IALRP-6 title: "Allowlist: Additional Attribute Requests" props: - value: 4.6.1.1 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IALRP-6_smt name: statement prose: |- If additional attributes are requested by the RP, the request SHALL be: (a) Subject to a runtime decision of the authorized party to approve the additional attributes requested. (b) Redacted to only the attributes in the allowlist entry, or (c) Denied outright by the IdP. - id: IALRP-6_obj links: - rel: assessment-for href: "#IALRP-6_smt" name: objective prose: "Determine whether the IdP handles RP requests for attributes beyond the allowlist entry by either obtaining authorized party approval, redacting to allowlist attributes, or denying the request." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IALRP-6_asm-test name: assessment-method prose: "Test by configuring an allowlist entry for a test RP with a defined set of attributes, then submitting a federation request from that RP that includes a request for additional attributes beyond those listed in the allowlist entry. Verify the IdP responds with one of the following: (a) Prompts the authorized party to approve the additional attributes (see IDPRD-1 through IDPRD-6), or (b) returns only the attributes specified in the allowlist entry, or (c) denies the request entirely." - id: IALRP-6_gdn name: guidance prose: |- Assessment is required when: The IdP utilizes an allowlist for RPs. This control ensures that allowlist entries are not simply bypassed by an RP requesting additional attributes. The IdP must have a policy for handling such requests and enforce it. - id: IDPBRP-1 title: Blocklist Assertion Prohibition props: - value: 4.6.1.2 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPBRP-1_smt name: statement prose: "If an RP is on an IdP's blocklist, the IdP SHALL NOT produce an assertion that targets the RP in question under any circumstances." - id: IDPBRP-1_obj links: - rel: assessment-for href: "#IDPBRP-1_smt" name: objective prose: Determine whether the IdP refuses to issue assertions to blocklisted RPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPBRP-1_asm-test name: assessment-method prose: "Test by adding a test RP to the IdP's blocklist, then submitting a federation request as the blocklisted RP. Verify the IdP refuses to produce an assertion." - id: IDPBRP-1_gdn name: guidance prose: "Assessment is required when: The IdP utilizes a blocklist for RPs." - id: IDPBRP-2 title: "Blocklist: RP Identification" props: - value: 4.6.1.2 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPBRP-2_smt name: statement prose: "IdP blocklists SHALL identify RPs through the means of domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. Any entities that share an identifier SHALL be considered equivalent for the purposes of the blocklist." - id: IDPBRP-2_obj links: - rel: assessment-for href: "#IDPBRP-2_smt" name: objective prose: "Determine whether IdP blocklist entries identify RPs using appropriate identifiers, and whether entities sharing an identifier are treated as equivalent." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPBRP-2_asm-examine name: assessment-method prose: "Examine the IdP blocklist entries and verify that each RP is identified using domain names, cryptographic keys, or other protocol-applicable identifiers." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPBRP-2_asm-test name: assessment-method prose: "Test by adding a wildcard entry (e.g., \"*.example.com\") to the IdP's blocklist, then submitting federation requests from multiple subdomains matching the wildcard (e.g., \"www.example.com\", \"service.example.com\"). Verify all matching requests are blocked." - id: IDPBRP-2_gdn name: guidance prose: |- Assessment is required when: The IdP utilizes a blocklist for RPs. The Current text incorrectly states: IdP blocklists SHALL uniquely identify RPs through the means of fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. The text will be updated in the errata volume. - id: IDPRD-1 title: "RP Not on Allowlist: Runtime Authorization" props: - value: 4.6.1.3 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-1_smt name: statement prose: Every RP that is in a trust agreement with an IdP but not on an allowlist with that IdP SHALL be governed by a default policy in which runtime authorization decisions will be made by an authorized party that is identified by the trust agreement. - id: IDPRD-1_obj links: - rel: assessment-for href: "#IDPRD-1_smt" name: objective prose: Determine whether a request for information release by an RP that is not allowlisted triggers a runtime authorization decision by the authorized party. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRD-1_asm-examine name: assessment-method prose: Examine the IdP configuration to verify that a default policy exists requiring runtime authorization decisions for non-allowlisted RPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-1_asm-test name: assessment-method prose: "Test by initiating a federation transaction from a non-allowlisted RP and verify that the IdP presents a runtime authorization decision to the authorized party, who can both approve and deny the request." - id: IDPRD-1_gdn name: guidance prose: |- Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist. If a given RP is allowed to request a connection from an IdP, and that RP has not been allowlisted by the IdP, then the IdP must present a runtime authorization decision to the authorized party identified in the trust agreement. The purpose of this requirement is to allow authorized party-driven connection decisions where possible in addition to traditional pre-negotiated connections enabled by allowlists. - id: IDPRD-2 title: "RP Not on Allowlist: Attribute Release Consent" props: - value: 4.6.1.3 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-2_smt name: statement prose: The IdP SHALL provide the authorized party with explicit notice and prompt them for positive confirmation before any attributes about the subscriber are transmitted to the RP. - id: IDPRD-2_obj links: - rel: assessment-for href: "#IDPRD-2_smt" name: objective prose: Determine whether the IdP provides the authorized party with explicit notice and obtains positive confirmation before transmitting subscriber attributes to the RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-2_asm-test name: assessment-method prose: Test by initiating a federation transaction from a non-allowlisted RP. Verify that the IdP presents explicit notice and requires positive confirmation from the authorized party before transmitting any attributes. Verify that denying confirmation prevents attribute transmission. - id: IDPRD-2_gdn name: guidance prose: "Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist." - id: IDPRD-3 title: "RP Not on Allowlist: Attribute Disclosure Before Release" props: - value: 4.6.1.3 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-3_smt name: statement prose: The IdP SHALL disclose which attributes will be released to the RP if the transaction is approved. - id: IDPRD-3_obj links: - rel: assessment-for href: "#IDPRD-3_smt" name: objective prose: Determine whether the IdP discloses to the authorized party the specific attributes that will be released to the RP before the transaction is approved. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRD-3_asm-examine name: assessment-method prose: Examine the IdP's runtime decision screens and related configurations to verify that a runtime decision prompt displays the list of attributes to be released prior to authorization. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-3_asm-test name: assessment-method prose: Test by initiating a federation transaction that triggers a runtime decision and verifying that the IdP presents the list of attributes to be released before the authorized party approves the transaction. - id: IDPRD-3_gdn name: guidance prose: |- Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist. This control ensures informed decisions are made by requiring the IdP to show which attributes will be transmitted before the authorized party approves the transaction. Related Controls: - IDPRD-2 requires explicit notice and positive confirmation before attribute transmission. - IDPRD-5 requires the IdP to provide mechanisms for viewing attribute values. - IDPRD-4 addresses selective disclosure of optional attributes. - id: IDPRD-4 title: "RP Not on Allowlist: Selective attribute disclosure" props: - value: 4.6.1.3 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-4_smt name: statement prose: "If the federation protocol in use allows for optional or selective attribute disclosure at runtime, the authorized party SHALL be given the option to decide whether to transmit specific attributes to the RP without terminating the federation transaction entirely." - id: IDPRD-4_obj links: - rel: assessment-for href: "#IDPRD-4_smt" name: objective prose: Determine whether the authorized party can selectively approve or deny the RP access to any optional attributes without terminating the transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRD-4_asm-examine name: assessment-method prose: Examine the IdP's runtime decision interface to verify that optional attributes are clearly delineated from required attributes and that the authorized party is given the option to approve or deny individual optional attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-4_asm-test name: assessment-method prose: "Test by initiating a federation transaction that includes a request for optional attributes. Verify that: (1) The authorized party is presented with a clear distinction between required and optional attributes. (2) The authorized party can deny optional attributes. (3) Denied optional attributes are not released to the RP. (4) The transaction continues after the denial of optional attributes." - id: IDPRD-4_gdn name: guidance prose: |- Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist, and the federation protocol supports optional attributes in the request Some federation protocols allow for attributes to be requested for optional release. In such cases, the IdP must provide the authorized party with the opportunity to decide, during the process, whether to transmit those optional attributes to the RP. Optional attributes and the selection method need to be clearly delineated for the authorized party. - id: IDPRD-5 title: "RP Not on Allowlist: Attribute Value Viewing Mechanism" props: - value: 4.6.1.3 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-5_smt name: statement prose: "If the authorized party is the subscriber, the IdP SHALL provide mechanisms for the subscriber to view the attribute values and derived attribute values to be sent to the RP." - id: IDPRD-5_obj links: - rel: assessment-for href: "#IDPRD-5_smt" name: objective prose: Determine whether the IdP provides the subscriber with a mechanism to view the actual attribute values and derived attribute values that will be transmitted to the RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRD-5_asm-examine name: assessment-method prose: Examine the runtime decision screens to verify that mechanisms exist to display attribute and derived attribute values to the subscriber. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-5_asm-test name: assessment-method prose: Test by initiating a federation transaction as a subscriber that triggers a runtime decision. Verify that the subscriber can view the actual values of the attributes and derived attributes to be released. - id: IDPRD-5_gdn name: guidance prose: |- Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist. This control goes beyond IDPRD-3 (which requires disclosure of which attributes will be released) by requiring the IdP to show the actual values of those attributes. This enables the subscriber to verify correctness and make an informed decision. Related Controls: - IDPRD-3 requires disclosure of which attributes will be released. - IDPRD-6 requires masking of sensitive information by default. - id: IDPRD-6 title: "RP Not on Allowlist: Sensitive Information Masking" props: - value: 4.6.1.3 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-6_smt name: statement prose: "To mitigate the risk of unauthorized exposure of sensitive information (e.g., shoulder surfing), the IdP SHALL, by default, mask sensitive information displayed to the subscriber." - id: IDPRD-6_obj links: - rel: assessment-for href: "#IDPRD-6_smt" name: objective prose: Determine whether sensitive information is masked upon display by default. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-6_asm-test name: assessment-method prose: Test by initiating a federation transaction that triggers a runtime decision. Verify that all sensitive information displayed to the subscriber is masked by default. - id: IDPRD-6_gdn name: guidance prose: |- Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist. The IdP is a trusted holder of information for the subscriber. When the subscriber interacts with the IdP, the IdP may need to display sensitive information to the subscriber to allow the subscriber to confirm and authorize its release to the RP. When doing so, the IdP must present that information so that the full value of the sensitive information is not displayed on the screen by default. - id: IDPRD-7 title: "RP Not on Allowlist: Remembered Decision Disclosure" props: - value: 4.6.1.3 G class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-7_smt name: statement prose: The IdP SHALL disclose to the authorized party that the storage mechanism is in use. - id: IDPRD-7_obj links: - rel: assessment-for href: "#IDPRD-7_smt" name: objective prose: Determine whether the IdP discloses to the authorized party that a mechanism is in use to remember their authorization decision. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRD-7_asm-examine name: assessment-method prose: Examine the runtime decision screens and IdP documentation to verify that disclosure of the remembered decision mechanism is presented to the authorized party. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-7_asm-test name: assessment-method prose: Test by initiating a federation transaction that triggers a runtime decision and verify that the IdP either (a) gives the authorized party a choice whether or not the decision should be remembered for future transactions or (b) discloses that the authorization decision may be remembered for future transactions. - id: IDPRD-7_gdn name: guidance prose: |- Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist, and the IdP employs a mechanism to remember the authorized party's decision. Related Control: IDPRD-8 requires the IdP to allow revocation of remembered decisions. - id: IDPRD-8 title: "RP Not on Allowlist: Remembered Decision Revocation" props: - value: 4.6.1.3 H class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IDPRD-8_smt name: statement prose: "[The IdP] SHALL allow the authorized party to revoke such remembered access at a future time." - id: IDPRD-8_obj links: - rel: assessment-for href: "#IDPRD-8_smt" name: objective prose: Determine whether a previous runtime decision can be revoked by the authorized party. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IDPRD-8_asm-examine name: assessment-method prose: Examine the IdP interface to verify that the authorized party can view and revoke remembered authorization decisions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-8_asm-test name: assessment-method prose: "Test by approving a non-allowlisted RP at runtime and have the IdP remember the decision. Then, initiate a new transaction with the same RP. Verify no runtime prompt appears." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IDPRD-8_asm-test-2 name: assessment-method prose: "Test by revoking the above remembered decision using the IdP's revocation mechanism. Then, initiate another transaction with the same RP. Verify the runtime prompt reappears." - id: IDPRD-8_gdn name: guidance prose: |- Assessment is required when: The IdP is party to a trust agreement with an RP but does not have that RP on an allowlist, and the IdP employs a mechanism to remember the authorized party's decision. When the IdP remembers an authorized party's runtime decision, the IdP must provide a mechanism for the authorized party to revoke that decision so that future transactions with the same RP will trigger a new runtime authorization prompt. Related control: IDPRD-7 requires the IdP to disclose that the remembered decision mechanism is in use. - id: RPAIDP-1 title: "RP Allowlist: IdP Conformance" props: - value: 4.6.2.1 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPAIDP-1_smt name: statement prose: "When placing an IdP in its allowlist, the RP SHALL confirm that the IdP abides by the terms of the trust agreement. This confirmation can be facilitated by a federation authority or undertaken directly by the RP." - id: RPAIDP-1_obj links: - rel: assessment-for href: "#RPAIDP-1_smt" name: objective prose: Determine whether all IdPs in an RP's allowlist are compliant with the requirements of their trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPAIDP-1_asm-examine name: assessment-method prose: "Examine RP policies and procedures for adding IdPs to the allowlist to verify that a process exists for confirming IdP compliance with trust agreement artifact(s) before allowlisting. For a sample of allowlisted IdPs, verify that evidence of compliance confirmation exists (e.g., review records, attestation, federation authority approval)." - id: RPAIDP-1_gdn name: guidance prose: |- Assessment is required when: The RP maintains an IdP allowlist. Before adding an IdP to its allowlist, the RP must confirm that the IdP abides by the terms of the trust agreement artifact(s). This confirmation may be facilitated by a federation authority or undertaken directly by the RP. - id: RPAIDP-2 title: "RP Allowlist: IdP Identification" props: - value: 4.6.2.1 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPAIDP-2_smt name: statement prose: "RP allowlists SHALL uniquely identify IdPs through fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. An allowlist entry for an IdP SHALL NOT use a wildcard domain identifier." - id: RPAIDP-2_obj links: - rel: assessment-for href: "#RPAIDP-2_smt" name: objective prose: Determine whether the RP's allowlist uniquely identifies IdPs using appropriate identifiers for the federation protocol in use. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPAIDP-2_asm-examine name: assessment-method prose: "Examine the RP's allowlist configuration to verify that each IdP entry uses a unique identifier such as a fully qualified domain name, cryptographic key, or other protocol-appropriate identifier, and that no entries use wildcard domain identifiers." - id: RPAIDP-2_gdn name: guidance prose: |- Assessment is required when: The RP maintains an IdP allowlist. Wildcard identifiers (e.g., "*.example.com") are prohibited because they could match unintended IdPs, undermining the security of the allowlist. - id: RPBIDP-1 title: "RP Blocklist: IdP Identification" props: - value: 4.6.2.2 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPBIDP-1_smt name: statement prose: "RP blocklists SHALL identify IdPs through domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use. Any entities that share an identifier SHALL be considered equivalent for the purposes of the blocklist." - id: RPBIDP-1_obj links: - rel: assessment-for href: "#RPBIDP-1_smt" name: objective prose: Determine whether the RP's blocklist identifies IdPs using appropriate identifiers for the federation protocol in use and treats entities sharing an identifier as equivalent for blocking purposes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPBIDP-1_asm-examine name: assessment-method prose: "Examine the RP blocklist entries and verify that each IdP is identified using domain names, cryptographic keys, or other protocol-applicable identifiers." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPBIDP-1_asm-test name: assessment-method prose: "Test with representative matching IdPs and determine that all matching entities are treated as equivalent for blocklist purposes, if the RP uses an identifier that can match multiple IdPs," - id: RPBIDP-1_gdn name: guidance prose: |- Assessment is required when: The RP maintains an IdP blocklist. Unlike allowlists, blocklists may use wildcard domain identifiers to block multiple malicious or untrusted IdPs under a common domain. The Current text incorrectly states: "RP blocklists SHALL uniquely identify IdPs through fully qualified domain names, cryptographic keys, or other identifiers that are applicable to the federation protocol in use." The text will be updated in the errata volume. - id: RPRD-1 title: "RP Runtime Decision: IdP Acceptance" props: - value: 4.6.2.3 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPRD-1_smt name: statement prose: Every IdP that is in a trust agreement with an RP but not on an allowlist with that RP SHALL be governed by a default policy in which runtime authorization decisions will be made by the authorized party indicated in the trust agreement. - id: RPRD-1_obj links: - rel: assessment-for href: "#RPRD-1_smt" name: objective prose: Determine whether non-allowlisted IdPs are governed by a default policy in which runtime authorization decisions are made by the authorized party identified in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPRD-1_asm-examine name: assessment-method prose: Examine the trust agreement artifact(s) and RP decision logic to determine which party is designated as the authorized party for non-allowlisted IdPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPRD-1_asm-test name: assessment-method prose: "Test by initiating a federation transaction using an IdP that is in a trust agreement with the RP but is not allowlisted, and determine that the runtime decision is made by the authorized party identified in the trust agreement." - id: RPRD-1_gdn name: guidance prose: |- Assessment is required when: The RP is in a trust agreement with an IdP, but does not include that IdP in an allowlist. For IdPs that are in a trust agreement with the RP but not allowlisted, the RP must present a runtime authorization decision to the authorized party. Common implementations include allowing the authorized party to type a directed identifier to facilitate discovery, or using an account chooser to select from available IdPs. - id: RPRD-2 title: "RP Runtime Decision: Remembered Decision Disclosure" props: - value: 4.6.2.3 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPRD-2_smt name: statement prose: The RP SHALL disclose to the authorized party that the storage mechanism is in use. - id: RPRD-2_obj links: - rel: assessment-for href: "#RPRD-2_smt" name: objective prose: Determine whether the RP discloses to the authorized party that a mechanism is in use to remember their prior IdP authorization decision. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPRD-2_asm-examine name: assessment-method prose: Examine runtime decision screens and RP documentation to verify that the remembered IdP decision is disclosed to the authorized party. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPRD-2_asm-test name: assessment-method prose: "Test by initiating a federation transaction that triggers a runtime IdP selection and verify that the RP either (a) gives the authorized party a choice whether the decision should be remembered for future transactions, or (b) discloses that the decision may be remembered for future transactions." - id: RPRD-2_gdn name: guidance prose: |- Assessment is required when: The RP is in a trust agreement with an IdP, but does not include that IdP in an allowlist, and the RP employs a mechanism to remember the authorized party's decision. This is the RP-side equivalent of IDPRD-7. The RP's remembered decision concerns which IdP to contact, not which attributes to release. Since this mechanism operates prior to authentication (e.g., via a browser cookie outside the authenticated session), it is separate from the RP subscriber account. Related Controls: RPRD-3 requires the RP to allow revocation of remembered decisions. - id: RPRD-3 title: "RP Runtime Decision: Remembered Decision Revocation" props: - value: 4.6.2.3 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPRD-3_smt name: statement prose: "[The RP] SHALL allow the authorized party to revoke such remembered access at a future time." - id: RPRD-3_obj links: - rel: assessment-for href: "#RPRD-3_smt" name: objective prose: Determine whether a previous runtime decision can be revoked by the authorized party. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPRD-3_asm-examine name: assessment-method prose: Examine the RP interface to verify a mechanism exists for the authorized party to view and revoke remembered IdP selection decisions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RPRD-3_asm-test name: assessment-method prose: "Test by selecting a non-allowlisted IdP at runtime and having the RP remember the decision. Then, initiate a new transaction and verify that no IdP selection prompt appears. Next, revoke the remembered decision using the RP's revocation mechanism. Initiate another transaction and verify that the IdP selection prompt reappears." - id: RPRD-3_gdn name: guidance prose: "Assessment is required when: The RP is in a trust agreement with an IdP, but does not include that IdP in an allowlist, and the RP employs a mechanism to remember the authorized party's decision." - id: PMRPSA-1 title: RP Subscriber Account Provisioning Methods props: - value: 4.6.3 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PMRPSA-1_smt name: statement prose: |- The RP subscriber account SHALL be provisioned at the RP prior to the establishment of an authenticated session at the RP in one of the following ways: (a) Just-In-Time Provisioning (b) Pre-Provisioning (c) Ephemeral Provisioning (d) Other Provisioning Methods - id: PMRPSA-1_obj links: - rel: assessment-for href: "#PMRPSA-1_smt" name: objective prose: Determine whether the RP subscriber account is provisioned prior to session establishment using a documented provisioning method. - props: - value: EXAMINE name: method class: assessment-summary id: PMRPSA-1_asm-summary title: Assessment Method name: assessment-method prose: |- The underlying requirement that the RP subscriber account be provisioned through the method specified in the trust agreement artifact(s) before an authenticated session is created is satisfied by ASRP-1 and PMRPSA-7. If Just-In-Time Provisioning is used, this control is further satisfied by PMRPSA-2. If Pre-Provisioning is used, this control is further satisfied by PMRPSA-3 and PMRPSA-4. If Ephemeral Provisioning is used, this control is further satisfied by PMRPSA-5. If Alternative Provisioning Methods are used, this control is further satisfied by PMRPSA-6. - id: PMRPSA-2 title: Just-In-Time Provisioning Cached Attribute Management props: - value: 4.6.3 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PMRPSA-2_smt name: statement prose: The RP SHALL be responsible for managing any cached attributes it might have. - id: PMRPSA-2_obj links: - rel: assessment-for href: "#PMRPSA-2_smt" name: objective prose: Determine whether the RP manages cached subscriber attributes obtained through just-in-time provisioning. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PMRPSA-2_asm-examine name: assessment-method prose: "Examine RP policies and system documentation for attribute caching and lifecycle management, including retention periods, update procedures, and deletion processes." - id: PMRPSA-2_gdn name: guidance prose: |- Assessment is required when: Just-In-Time Provisioning is used. In just-in-time provisioning, the RP subscriber account is created or updated at the time of the federation transaction based on attributes provided in the assertion. The RP may cache these attributes locally for use between federation transactions. This control ensures the RP has defined processes for managing the lifecycle of cached attributes. - id: PMRPSA-3 title: Pre-Provisioned Account Access Method props: - value: 4.6.3 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PMRPSA-3_smt name: statement prose: "Pre-provisioned accounts SHALL be bound to a federated identifier at the time of provisioning, unless an alternative means of access is defined by the trust agreement, such as an account linking policy (see Sec. 3.8.1), an account resolution policy (see Sec. 3.8.2), or alternative authentication mechanisms (see Sec. 3.8.3)." - id: PMRPSA-3_obj links: - rel: assessment-for href: "#PMRPSA-3_smt" name: objective prose: "Determine whether pre-provisioned RP subscriber accounts have a defined means of subscriber access, either through a federated identifier bound at the time of provisioning or through an alternative means of access defined in the trust agreement artifact(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PMRPSA-3_asm-examine name: assessment-method prose: "Examine the provisioning model documentation assessed under PMRPSA-7, and identify the means by which subscribers access pre-provisioned RP subscriber accounts. If a federated identifier is bound at provisioning time, verify that provisioning records include a federated identifier for each pre-provisioned account. If an alternative means of access is used, verify that the trust agreement artifact(s) define the alternative access method (e.g., account linking per Sec. 3.8.1, account resolution per Sec. 3.8.2, or alternative authentication per Sec. 3.8.3) and that the method is implemented." - id: PMRPSA-3_gdn name: guidance prose: |- Assessment is required when: Pre-Provisioning is used. This requirement ensures that pre-provisioned RP subscriber accounts are not created without a defined path for subscribers to access them. The default mechanism is binding a federated identifier at provisioning time. If the trust agreement defines an alternative, such as account linking, account resolution, or direct authentication, that alternative must be documented and implemented. - id: PMRPSA-4 title: Pre-Provisioning Privacy Considerations props: - value: 4.6.3 D class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PMRPSA-4_smt name: statement prose: The privacy considerations of the RP having access to this information prior to a federation transaction SHALL be accounted for in the trust agreement. - id: PMRPSA-4_obj links: - rel: assessment-for href: "#PMRPSA-4_smt" name: objective prose: Determine whether the trust agreement artifact(s) address the privacy considerations of the RP having access to subscriber information prior to a federation transaction. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PMRPSA-4_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to verify that, when pre-provisioning is used, they account for the privacy considerations of the RP receiving subscriber information prior to a federation transaction. Verify that the trust agreement addresses, as applicable: (1) the categories of subscriber information the RP receives through pre-provisioning; (2) the fact that pre-provisioned data may include subscribers who may never interact with the RP; and (3) any privacy protections or limitations applicable to that pre-provisioned information, such as restrictions on collection, use, disclosure, retention, or synchronization." - id: PMRPSA-4_gdn name: guidance prose: |- Assessment is required when: Pre-Provisioning is used. In this model, the RP also receives attributes about subscribers who have not yet interacted with the RP and who may never do so. This is in contrast to other models in which the RP only receives information about the subset of subscribers that use the RP, and then only after the subscriber uses the RP for the first time. - id: PMRPSA-5 title: Ephemeral Provisioning Identifier Unlinking props: - value: 4.6.3 E class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PMRPSA-5_smt name: statement prose: "If a federation identifier is supplied in the assertion, the RP SHALL remove any linkage of the federated identifier from an RP subscriber account." - id: PMRPSA-5_obj links: - rel: assessment-for href: "#PMRPSA-5_smt" name: objective prose: Determine whether the RP removes any linkage between the federated identifier and the RP subscriber account when using ephemeral provisioning. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PMRPSA-5_asm-examine name: assessment-method prose: Examine RP system documentation and data retention policies to verify that federated identifiers are not persistently linked to ephemerally provisioned RP subscriber accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PMRPSA-5_asm-test name: assessment-method prose: Test by conducting an ephemeral provisioning transaction and verifying that the federated identifier is not retained or linked to the RP subscriber account after the session ends. - id: PMRPSA-5_gdn name: guidance prose: |- Assessment is required when: Ephemeral Provisioning is used, and a federation identifier is supplied in the assertion. When processing an assertion, the RP establishes a link between that assertion and a new or existing RP subscriber account but removes that link when the authenticated session ends. This process is similar to just-in-time provisioning, but the RP keeps no long-term record of the subscriber when the session is complete, in accordance with Sec. 3.11.3. This form of provisioning is useful for RPs that fully externalize access rights to the IdP, allowing the RP to be more simplified with less internal state. If this form of provisioning is used, the federated identifier is not required in the assertion. - id: PMRPSA-6 title: Alternative Provisioning Privacy Assessment props: - value: 4.6.3 F class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PMRPSA-6_smt name: statement prose: The details of any alternative provisioning model SHALL be included in the privacy risk assessments of the IdP and RP. - id: PMRPSA-6_obj links: - rel: assessment-for href: "#PMRPSA-6_smt" name: objective prose: Determine whether the privacy risk assessments of the IdP and RP include the details of any alternative provisioning model in use. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PMRPSA-6_asm-examine name: assessment-method prose: "Examine the privacy risk assessment to verify that it addresses the alternative provisioning model, including a description of the alternative provisioning model and the privacy risks specific to the model (e.g., data exposure, retention, minimization)." - id: PMRPSA-6_gdn name: guidance prose: "Assessment is required when: An Alternative Provisioning Method is used." - id: PMRPSA-7 title: Provisioning Model Documentation props: - value: 4.6.3 G class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PMRPSA-7_smt name: statement prose: All organizations SHALL document their provisioning models as part of their trust agreement. - id: PMRPSA-7_obj links: - rel: assessment-for href: "#PMRPSA-7_smt" name: objective prose: Determine whether the organization documents its provisioning model in the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PMRPSA-7_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) for documentation of the provisioning model(s) in use. Verify that each documented model is identifiable as one of the provisioning methods enumerated in Sec. 4.6.3: just-in-time, pre-provisioning, ephemeral, or an alternative method." - id: ATSYNC-1 title: RP Processing of Termination Signal props: - value: 4.6.4 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ATSYNC-1_smt name: statement prose: "Upon receiving such a signal, the RP SHALL process the RP subscriber account as stipulated in the trust agreement and in accordance with Sec. 3.11.3." - id: ATSYNC-1_obj links: - rel: assessment-for href: "#ATSYNC-1_smt" name: objective prose: Determine whether the RP processes the RP subscriber account in accordance with the trust agreement artifact(s) and Section 3.11.3 upon receiving a termination or revocation signal from the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ATSYNC-1_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to identify the stipulated processing requirements for termination and revocation signals. Review RP account termination procedures to verify alignment with those requirements, and with SSIN-1, SSIN-2, and SSIN-3." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ATSYNC-1_asm-test name: assessment-method prose: "Test by sending a termination signal to the RP and verifying that the RP subscriber account is processed according to the requirements for termination and revocation signals stipulated in the trust agreement artifact(s), and in accordance with SSIN-1, SSIN-2, and SSIN-3." - id: ATSYNC-1_gdn name: guidance prose: "Assessment is required when: The RP may receive a signal from an IdP indicating that a subscriber account has been terminated or the subscriber's access to the RP has been revoked." - id: ATSYNC-2 title: IdP Notification of Terminations due to Fraud or Suspicious Activity props: - value: 4.6.4 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ATSYNC-2_smt name: statement prose: "If the reason for termination is suspicious or fraudulent activity, the IdP SHALL notify the RP of the termination and include the reason in its signal to the RP to allow the RP to review the associated RP subscriber account's activity for suspicious activity, if specified in the trust agreement with that RP." - id: ATSYNC-2_obj links: - rel: assessment-for href: "#ATSYNC-2_smt" name: objective prose: "Determine whether the IdP notifies the RP and includes the reason when terminating a subscriber account due to suspicious or fraudulent activity, as specified in the trust agreement artifact(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ATSYNC-2_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to determine whether notification of termination due to suspicious or fraudulent activity is required. If required, review IdP procedures for signaling terminations to verify that the procedures include notifying the RP of the reason for termination." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ATSYNC-2_asm-test name: assessment-method prose: "Test by simulating a termination due to suspicious activity and verify that the IdP's signal to the RP includes the reason for termination, if the trust agreement artifact(s) require notification of termination due to suspicious or fraudulent activity." - id: ATSYNC-2_gdn name: guidance prose: |- Assessment is required when: The RP may receive a signal from an IdP indicating that a subscriber account has been terminated or the subscriber's access to the RP has been revoked. This notification enables the RP to review the associated RP subscriber account's activity for suspicious activity. - id: PAPI-1 title: "Provisioning API: Attributes Limited to RP Functions" props: - value: 4.6.5 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-1_smt name: statement prose: "The attributes in the provisioning API that are available to a given RP SHALL be limited to only those necessary for the RP to perform its functions, including any audit and security purposes, as discussed in Sec. 3.10.1." - id: PAPI-1_obj links: - rel: assessment-for href: "#PAPI-1_smt" name: objective prose: Determine whether the attributes available to the RP through the provisioning API are limited to those necessary for the RP to perform its functions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-1_asm-examine name: assessment-method prose: "Examine the provisioning API configuration to identify which attributes are available to each RP via the API. For each attribute, verify that it maps to a documented functional need of the RP (including audit and security purposes) as established in the trust agreement artifact(s). Verify that no attributes beyond those necessary are exposed through the API." - id: PAPI-1_gdn name: guidance prose: "Assessment is required when: The IdP provides a provisioning API." - id: PAPI-2 title: "Provisioning API: Documentation of Access Requirements" props: - value: 4.6.5 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-2_smt name: statement prose: |- As part of establishing the trust agreement, the IdP SHALL document when an RP is given access to a provisioning API, including at least the following: (a) The purpose for the access using the provisioning model. (b) The set of attributes made available to the RP. (c) Whether the API functions as a push to the RP, a pull from the RP, or both. (d) The population of subscribers whose attributes are made available to the RP. - id: PAPI-2_obj links: - rel: assessment-for href: "#PAPI-2_smt" name: objective prose: Determine whether the trust agreement artifact(s) document the requirements for provisioning API access. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-2_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to verify adequate documentation of the following: (1) the purpose for provisioning API access; (2) the set of attributes made available to the RP; (3) whether the API functions as push, pull, or both; and (4) the population of subscribers whose attributes are made available." - id: PAPI-2_gdn name: guidance prose: "Assessment is required when: The IdP provides a provisioning API." - id: PAPI-3 title: Provisioning API Mutual Authentication props: - value: 4.6.5 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-3_smt name: statement prose: Access to the provisioning API SHALL occur over a mutually authenticated protected channel. - id: PAPI-3_obj links: - rel: assessment-for href: "#PAPI-3_smt" name: objective prose: Determine whether access to the provisioning API occurs over a mutually authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-3_asm-examine name: assessment-method prose: Examine the provisioning API configuration and documentation to verify that mutual authentication is required for all connections. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PAPI-3_asm-test name: assessment-method prose: Test by attempting to access the provisioning API without presenting RP credentials and verify that access is denied. - id: PAPI-3_gdn name: guidance prose: |- Assessment is required when: The IdP provides a provisioning API. A mutually authenticated protected channel requires both parties (IdP and RP) to authenticate to each other, unlike a standard authenticated protected channel where only the server is authenticated. - id: PAPI-4 title: Provisioning API Prohibition for Subscriber-Driven Trust Agreements props: - value: 4.6.5 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-4_smt name: statement prose: A provisioning API SHALL NOT be made available under a subscriber-driven trust agreement. - id: PAPI-4_obj links: - rel: assessment-for href: "#PAPI-4_smt" name: objective prose: Determine whether the IdP prohibits provisioning API access under subscriber-driven trust agreements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-4_asm-examine name: assessment-method prose: Examine IdP policies and provisioning API access controls to verify that provisioning API access is not granted to RPs operating under subscriber-driven trust agreements. - id: PAPI-4_gdn name: guidance prose: |- Assessment is required when: The IdP provides a provisioning API. Subscriber-driven trust agreements rely on runtime decisions by the subscriber rather than pre-established organizational agreements. Provisioning APIs provide bulk or out-of-band access to subscriber attributes, which is incompatible with the subscriber-controlled nature of subscriber-driven trust agreements. - id: PAPI-5 title: Trust Agreement Required for Provisioning API props: - value: 4.6.5 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-5_smt name: statement prose: The IdP SHALL NOT make a provisioning API available to any RP outside of an established trust agreement. - id: PAPI-5_obj links: - rel: assessment-for href: "#PAPI-5_smt" name: objective prose: Determine whether the IdP restricts provisioning API access to RPs with established trust agreements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-5_asm-examine name: assessment-method prose: Examine IdP provisioning API access control configuration to verify that each RP with API access has a corresponding established trust agreement with the IdP that allows provisioning API access (see PAPI-2). - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PAPI-5_asm-test name: assessment-method prose: Test by attempting to access the provisioning API as an RP without an established trust agreement with the IdP. Verify that access is denied. - id: PAPI-5_gdn name: guidance prose: "Assessment is required when: The IdP provides a provisioning API." - id: PAPI-6 title: Provisioning API Purpose Limitation props: - value: 4.6.5 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-6_smt name: statement prose: "IdP SHALL provide access to a provisioning API only as part of a federated identity relationship with an RP to facilitate federation transactions with that RP and related functions, such as signaling revocation of the subscriber account." - id: PAPI-6_obj links: - rel: assessment-for href: "#PAPI-6_smt" name: objective prose: Determine whether the IdP limits provisioning API access to the purpose of facilitating federation transactions and related functions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-6_asm-examine name: assessment-method prose: |- The purpose for provisioning API access is satisfied by PAPI-2(a). Examine the IdP's provisioning API capabilities to verify that API functionality is limited to facilitating federation transactions and related functions (e.g., account provisioning, attribute synchronization, account revocation signaling). Verify that no API capabilities serve purposes outside the federated identity relationship (e.g., general-purpose directory queries, marketing data access, analytics unrelated to federation). - id: PAPI-6_gdn name: guidance prose: "Assessment is required when: The IdP provides a provisioning API." - id: PAPI-7 title: Provisioning API Access Revocation props: - value: 4.6.5 G class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-7_smt name: statement prose: The IdP SHALL revoke an RP's access to the provisioning API once access is no longer required by the RP for its functioning purposes or when the trust agreement is terminated. - id: PAPI-7_obj links: - rel: assessment-for href: "#PAPI-7_smt" name: objective prose: Determine whether the IdP revokes RP access to the provisioning API when no longer required or when the trust agreement is terminated - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-7_asm-examine name: assessment-method prose: Examine IdP policies and procedures for provisioning API access lifecycle management to verify that access is terminated when the trust agreement is terminated or when the RP notifies the IdP that access is no longer needed. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PAPI-7_asm-test name: assessment-method prose: Test by revoking a test RP's provisioning API access and verifying that the RP can no longer access the API. - id: PAPI-7_gdn name: guidance prose: "Assessment is required when: The IdP provides a provisioning API." - id: PAPI-8 title: Provisioning API Control and Jurisdiction props: - value: 4.6.5 H class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-8_smt name: statement prose: Any provisioning API provided to the RP SHALL be under the control and jurisdiction of the IdP. - id: PAPI-8_obj links: - rel: assessment-for href: "#PAPI-8_smt" name: objective prose: "Determine whether the IdP is responsible for the content and accuracy of the provisioning API, including when the API infrastructure is operated by a third party." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-8_asm-examine name: assessment-method prose: "Examine the system architecture documentation to determine whether the provisioning API is operated directly by the IdP or by a third party. If it is operated by a third party, examine the agreement between the IdP and the third party to verify that the IdP retains responsibility for the content and accuracy of the API's outputs. Verify that the agreement defines how the IdP enforces content and accuracy requirements (e.g., attribute validation, error correction, audit rights)." - id: PAPI-8_gdn name: guidance prose: "Assessment is required when: The IdP provides a provisioning API." - id: PAPI-9 title: Provisioning API Account State Change Signaling props: - value: 4.6.5 I class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-9_smt name: statement prose: "When a provisioning API is in use, the IdP SHALL signal to the RP when the state of a subscriber account has been changed, such as when the account has been terminated or disabled." - id: PAPI-9_obj links: - rel: assessment-for href: "#PAPI-9_smt" name: objective prose: Determine whether the IdP signals the RP through the provisioning API when the state of a subscriber account changes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-9_asm-examine name: assessment-method prose: "Examine the IdP's provisioning API documentation and procedures to verify that account state changes (termination, disabling, etc.) trigger signals to the RP." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PAPI-9_asm-test name: assessment-method prose: "Test by changing the state of a subscriber account (e.g., disable the account) and verifying that the IdP sends a signal to the RP indicating the state change." - id: PAPI-9_gdn name: guidance prose: |- Assessment is required when: The IdP provides a provisioning API. PRIVR-9 addresses the specific requirement to deprovision terminated accounts via the provisioning API. - id: PAPI-10 title: Federated Identifier Unbinding Upon Terminated/Disabled Signal props: - value: 4.6.5 J class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-10_smt name: statement prose: "When receiving such a signal, the RP SHALL remove the binding of the federated identifier from the account." - id: PAPI-10_obj links: - rel: assessment-for href: "#PAPI-10_smt" name: objective prose: Determine whether the RP removes the federated identifier from the RP subscriber account upon receiving a signal that the subscriber account has been terminated or disabled. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: PAPI-10_asm-examine name: assessment-method prose: "Examine the RP's design, configuration, and signal-processing logic for handling IdP signals indicating that a subscriber account has been terminated or disabled. Verify that receipt of such a signal causes the RP to remove the corresponding federated identifier from the affected RP subscriber account." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: PAPI-10_asm-test name: assessment-method prose: Test by sending a signal indicating that a test subscriber account has been terminated or disabled. Verify that the RP removes the federated identifier associated with that IdP from the RP subscriber account. - id: PAPI-10_gdn name: guidance prose: |- Assessment is required when: The IdP provides a provisioning API. In the errata publication, this control will be changed to: When receiving a signal indicating that the account has been terminated or disabled, the RP SHALL remove the federated identifier from the RP subscriber account. Related Controls: - PAPI-9 requires the IdP to signal account state changes. - ACCL-2 prohibits access once a federated identifier is removed. - id: PAPI-11 title: "Provisioning API: Personal Information Handling" props: - value: 4.6.5 K class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: PAPI-11_smt name: statement prose: The RP SHALL treat all personal information sourced from the provisioning API in accordance with Sec. 3.11.3. - id: PAPI-11_obj links: - rel: assessment-for href: "#PAPI-11_smt" name: objective prose: Determine whether the RP treats personal information sourced from the provisioning API in accordance with Section 3.11.3 requirements. - props: - value: EXAMINE name: method class: assessment-summary id: PAPI-11_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by CAARP-1. - id: PAPI-11_gdn name: guidance prose: "Assessment is required when: The IdP provides a provisioning API." - id: CAARP-1 title: RP Subscriber Account Attribute Storage props: - value: 4.6.6 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CAARP-1_smt name: statement prose: All attributes in the RP subscriber account - regardless of source - SHALL be stored in accordance with Sec. 3.11.3. - id: CAARP-1_obj links: - rel: assessment-for href: "#CAARP-1_smt" name: objective prose: Determine whether the RP stores all attributes in the RP subscriber account in accordance with Section 3.11.3 requirements. - props: - value: EXAMINE name: method class: assessment-summary id: CAARP-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by SSIN-1 through SSIN-3. - id: CAARP-1_gdn name: guidance prose: "This control applies to all attributes regardless of source (assertion, provisioning API, identity API, or other sources)." - id: CAARP-2 title: Disclosure of Purpose for Additional Attributes props: - value: 4.6.6 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CAARP-2_smt name: statement prose: The RP SHALL disclose to the subscriber the purpose for collecting any additional attributes. - id: CAARP-2_obj links: - rel: assessment-for href: "#CAARP-2_smt" name: objective prose: Determine whether the RP discloses to the subscriber the purpose for any additional attributes collected. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAARP-2_asm-examine name: assessment-method prose: "Examine RP subscriber-facing documentation, such as privacy notices and consent screens, to verify that the purpose for collecting additional attributes is disclosed to the subscriber." - id: CAARP-2_gdn name: guidance prose: "Assessment is required when: The RP collects additional attributes not provided by the IdP." - id: CAARP-3 title: Additional Attribute Use Limitation props: - value: 4.6.6 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CAARP-3_smt name: statement prose: These attributes SHALL be used solely for the stated purposes of the RP's functionality. - id: CAARP-3_obj links: - rel: assessment-for href: "#CAARP-3_smt" name: objective prose: Determine whether the RP limits use of additional attributes to the stated purposes of its functionality. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAARP-3_asm-examine name: assessment-method prose: Examine RP policies and procedures for handling additional attributes to verify that use is limited to the purposes disclosed per CAARP-2. - id: CAARP-3_gdn name: guidance prose: |- Assessment is required when: The RP collects additional attributes not provided by the IdP. This control requires the RP to adhere to the purpose disclosed under CAARP-2. - id: CAARP-4 title: RP Attribute Transmission Limitations props: - value: 4.6.6 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CAARP-4_smt name: statement prose: The transmission of additionally collected attributes SHALL be handled in accordance with Sec. 3.10.1. - id: CAARP-4_obj links: - rel: assessment-for href: "#CAARP-4_smt" name: objective prose: Determine whether the RP handles the transmission of additionally collected attributes in accordance with the limitations in Sec. 3.10.1. - props: - value: EXAMINE name: method class: assessment-summary id: CAARP-4_asm-summary title: Assessment Method name: assessment-method prose: "Apply the assessment methods from TSI-1, TSI-2, and TSI-3 to the RP's transmission of additionally collected attributes, substituting the RP for the IdP in each assessment." - id: CAARP-4_gdn name: guidance prose: |- Assessment is required when: The RP collects additional attributes not provided by the IdP. Section 3.10.1 establishes limitations on transmitting subscriber information, directed at the IdP (TSI-1 through TSI-3). This control extends those same limitations to the RP when transmitting additionally collected attributes - attributes the RP gathered independently, not through the federation transaction. - id: CAARP-5 title: Redress for Additionally Collected Attributes props: - value: 4.6.6 E class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CAARP-5_smt name: statement prose: The RP SHALL provide a secure and effective means of redress for the subscriber to update and remove these additionally collected attributes from the RP subscriber account. - id: CAARP-5_obj links: - rel: assessment-for href: "#CAARP-5_smt" name: objective prose: Determine whether the RP provides a secure and effective means of redress for subscribers to request updates to or removal of additionally collected attributes. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAARP-5_asm-examine name: assessment-method prose: "Examine the RP's subscriber-facing interfaces and account management capabilities to verify that subscribers can request updates to, and removal of, any additionally collected attributes from their RP subscriber account." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: CAARP-5_asm-test name: assessment-method prose: "Test by requesting an update to an attribute value and requesting the removal of an attribute, as a test subscriber who has additionally collected attributes in their RP subscriber account. Verify that both requests are processed." - id: CAARP-5_gdn name: guidance prose: "Assessment is required when: The RP collects additional attributes not provided by the IdP." - id: CAARP-6 title: Federal RP SORN Disclosure for Additional Attributes props: - value: 4.6.6 F class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CAARP-6_smt name: statement prose: An RP SHALL disclose any additional attributes collected and their use as part of its System of Records Notice (SORN). - id: CAARP-6_obj links: - rel: assessment-for href: "#CAARP-6_smt" name: objective prose: Determine whether the federal agency RP discloses additionally collected attributes and their use in its SORN. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CAARP-6_asm-examine name: assessment-method prose: Examine the RP's System of Records Notice (SORN) to verify that additionally collected attributes and their uses are disclosed. - id: CAARP-6_gdn name: guidance prose: |- Assessment is required when: The RP is a federal agency and collects additional attributes not provided by the IdP. This control applies only to RPs that are federal agencies. SORN requirements derive from the Privacy Act of 1974 (5 U.S.C. 552a). - id: TBRRP-1 title: Time-Based Termination Notice and Reactivation props: - value: 4.6.7 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TBRRP-1_smt name: statement prose: "When processing an inactive account, the RP SHALL provide sufficient notice to the subscriber about the pending termination of the account and provide the subscriber with an option to re-activate the account prior to its scheduled termination." - id: TBRRP-1_obj links: - rel: assessment-for href: "#TBRRP-1_smt" name: objective prose: "Determine whether the RP provides sufficient notice to subscribers about pending account termination and an option to reactivate the account prior to scheduled termination, when processing inactive accounts for time-based removal." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TBRRP-1_asm-examine name: assessment-method prose: "Examine the RP's policies and procedures for time-based account termination, including notice timelines and reactivation processes. Also, examine sample termination notices to verify they inform subscribers of pending termination and provide a reactivation option." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: TBRRP-1_asm-test name: assessment-method prose: "Test by triggering a time-based termination process for a test account and verifying that notice is provided, and reactivation is available prior to termination." - id: TBRRP-1_gdn name: guidance prose: |- Assessment is required when: The RP uses time-based removal of RP subscriber accounts. "Sufficient notice" should be tailored to expected usage patterns at the RP. For example, an RP that expects weekly access might provide 30 days' notice, while an RP that expects monthly access might provide 90 days or more. - id: TBRRP-2 title: Personal Information Removal Upon Time-Based Termination props: - value: 4.6.7 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TBRRP-2_smt name: statement prose: "Upon termination, the RP SHALL remove all personal information associated with the RP subscriber account in accordance with Sec. 3.11.3." - id: TBRRP-2_obj links: - rel: assessment-for href: "#TBRRP-2_smt" name: objective prose: Determine whether the RP removes all personal information associated with the RP subscriber account upon termination in accordance with Sec. 3.11.3. - props: - value: EXAMINE name: method class: assessment-summary id: TBRRP-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RPSA-1. - id: TBRRP-2_gdn name: guidance prose: "Assessment is required when: The RP uses time-based removal of RP subscriber accounts." - id: RASR-1 title: Communication of Authentication Recency props: - value: 4.7 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RASR-1_smt name: statement prose: "The IdP SHALL communicate to the RP any information that the IdP has regarding the recency of the subscriber's latest authentication event at the IdP, and the RP MAY use this information to make authorization and access decisions." - id: RASR-1_obj links: - rel: assessment-for href: "#RASR-1_smt" name: objective prose: Determine whether the IdP communicates information regarding the recency of the subscriber's latest authentication event to the RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RASR-1_asm-examine name: assessment-method prose: Examine the IdP assertion structure and documentation to verify that recency information for the subscriber's latest authentication event is included in assertions. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RASR-1_asm-test name: assessment-method prose: "Test by having the IdP generate a test assertion and verify the authentication timestamp is present. Next, trigger a new authentication event at the IdP to generate a second assertion. Verify the second assertion reflects the updated authentication time." - id: RASR-1_gdn name: guidance prose: "A federated assertion is generated in the context of an active authentication event for the subscriber at the IdP. When communicating the authentication state of the subscriber to the RP in an assertion, the IdP has to communicate the timing of that authentication event to the RP. This information can help the RP make access decisions, such as requesting the subscriber to re-authenticate at the IdP directly before being allowed to access highly sensitive information." - id: RASR-2 title: Identity API Access Insufficient for Session Extension props: - value: 4.7 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RASR-2_smt name: statement prose: The RP's ability to successfully fetch additional attributes through an identity API SHALL NOT be used to establish or extend a session at the RP. - id: RASR-2_obj links: - rel: assessment-for href: "#RASR-2_smt" name: objective prose: Determine whether the RP refrains from using successful identity API attribute fetches to extend an existing authenticated session. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RASR-2_asm-examine name: assessment-method prose: |- The prohibition on session establishment via identity API access, is satisfied by IDAP-3. For the session extension prohibition: Examine the RP session-management logic, session renewal/extension code, and timeout handling to verify that successful identity API calls do not trigger session extension or reset the overall or inactivity timeout. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: RASR-2_asm-test name: assessment-method prose: Test by establishing an authenticated session at the RP and allowing it to approach an overall or inactivity timeout threshold. Successfully fetch attributes via the identity API. Verify that the session is not extended or refreshed solely as a result of the API call. - id: RASR-2_gdn name: guidance prose: |- Assessment is required when: An identity API is available to the RP. The lifetime of the access to the identity API is independent of the lifetime of the assertion. - id: SSIG-1 title: Shared Signaling Purpose Limitations props: - value: 4.8 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-1_smt name: statement prose: "Shared signaling SHALL be limited to the allowable functions of the identity process, as discussed in Sec. 3.10.1." - id: SSIG-1_obj links: - rel: assessment-for href: "#SSIG-1_smt" name: objective prose: Determine whether all shared signals serve one of the allowable identity process functions defined in Section 3.10.1. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-1_asm-examine name: assessment-method prose: "Examine the shared signals documentation (see SSIG-2 and SSIG-3). For each signal type, verify that the stated purpose maps to one of the allowable functions: (1) identity service (identity proofing, authentication, or attribute assertions), (2) a specific subscriber request, (3) fraud mitigation related to the identity service, or (4) security incident response related to the identity service. Flag any signal that serves a purpose outside these four categories." - id: SSIG-1_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used. Shared signals are communications between the IdP and RP that occur outside of the federation transaction to alert federation partner(s) of important changes in state that would not otherwise be known, such as suspected fraud or an account status change. This control gates all shared signaling to the same purpose limitations that govern other subscriber information transmissions under Section 3.10.1. SSIG-2 and SSIG-3 require documentation of signal purposes; this control verifies those purposes are permissible. - id: SSIG-2 title: Shared Signaling Documentation and Disclosure props: - value: 4.8 B class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-2_smt name: statement prose: All uses of shared signaling SHALL be documented in the trust agreement and made available to the authorized party stipulated by the trust agreement. - id: SSIG-2_obj links: - rel: assessment-for href: "#SSIG-2_smt" name: objective prose: "Determine whether (1) all uses of shared signaling are documented in the trust agreement artifact(s), and (2) that this documentation is made available to the authorized party." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-2_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to verify that all shared signaling uses are documented. Identify the authorized party designated to receive this documentation. Verify the documentation has been made available to that party (e.g., through disclosure records, acknowledgment of receipt, or accessibility via published terms)." - id: SSIG-2_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used. For documentation content requirements, see SSIG-3. The "authorized party" varies by trust agreement type. In subscriber-driven agreements, this is typically the subscriber (see SDTAE-1, which includes shared signaling in required disclosures). In pre-established agreements, this may be the federation parties or a federation authority. SSIG-3 specifies the required content of this documentation; PETA-6 establishes trust agreement terms for shared signaling. - id: SSIG-3 title: Shared Signaling Documentation Content props: - value: 4.8 C class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-3_smt name: statement prose: "[The Trust Agreement artifact(s)] SHALL include the events under which a signal is sent, the type of information included in such a signal (including any personal information), any additional parameters sent with the signal, and the expected processing of a received signal." - id: SSIG-3_obj links: - rel: assessment-for href: "#SSIG-3_smt" name: objective prose: Determine whether the trust agreement artifact(s) document the required shared signaling content elements. - props: - value: EXAMINE name: method class: assessment-summary id: SSIG-3_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by PETA-6. - id: SSIG-3_gdn name: guidance prose: "Assessment is required when: Shared signaling is used." - id: SSIG-4 title: Shared Signaling Privacy Review props: - value: 4.8 D class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-4_smt name: statement prose: The use of shared signaling SHALL be subject to privacy review under the trust agreement. - id: SSIG-4_obj links: - rel: assessment-for href: "#SSIG-4_smt" name: objective prose: Determine whether shared signaling has been subject to privacy review under the trust agreement. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-4_asm-examine name: assessment-method prose: "Examine each party's privacy risk assessment (or equivalent privacy review documentation) to verify that shared signaling is addressed, including the events that trigger signals, any personal information transmitted, and the expected processing by the receiving party. Refer to SSIG-2 and PETA-6 for the documented signaling terms that should be covered by the privacy review." - id: SSIG-4_gdn name: guidance prose: "Assessment is required when: Shared signaling is used." - id: SSIG-5 title: Shared Signal Personal Information Minimization props: - value: 4.8 E class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-5_smt name: statement prose: "Shared signals SHALL NOT include personal information except what is necessary to identify the subscriber account in question (e.g., an account identifier or attributes that can be correlated by the receiving party)." - id: SSIG-5_obj links: - rel: assessment-for href: "#SSIG-5_smt" name: objective prose: Determine whether shared signals limit personal information to only what is necessary to identify the subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-5_asm-examine name: assessment-method prose: Examine the shared signal documentation (per PETA-6) to identify any personal information included. Verify that each personal information element is necessary for subscriber account identification by the receiving party. Flag any personal information that serves purposes beyond account identification. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SSIG-5_asm-test name: assessment-method prose: Test by capturing sample shared signals and verifying that the actual content matches the documented content and contains no personal information beyond what is required for identification. - id: SSIG-5_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used. This control applies data minimization principles to shared signaling. The permitted personal information is limited to what enables the receiving party to match the signal to the correct subscriber account - typically an opaque identifier or correlation handle already known to both parties. - id: SSIG-6 title: "IdP-to-RP Signaling: Pre-Established Trust Agreement Required" props: - value: 4.8 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-6_smt name: statement prose: Signaling from the IdP to the RP SHALL require a pre-established trust agreement. - id: SSIG-6_obj links: - rel: assessment-for href: "#SSIG-6_smt" name: objective prose: Determine whether IdP-to-RP shared signaling occurs only under a pre-established trust agreement. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-6_asm-examine name: assessment-method prose: Examine the IdP shared signaling configuration to verify that outbound signals to RPs are sent only to RPs whose pre-established trust agreement artifact(s) explicitly authorize shared signaling (see PETA-6). Verify that no IdP-to-RP signaling is configured for RPs operating under subscriber-driven trust agreements or for RPs whose trust agreement artifact(s) do not include shared signaling terms. - id: SSIG-6_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used. In a subscriber-driven trust agreement, the IdP has no pre-existing relationship with the RP and therefore no established channel for signaling. Per Sec. 4.8, signaling from the RP to the IdP MAY be used in both pre-established and subscriber-driven trust agreements; only IdP-to-RP signaling requires a pre-established trust agreement. - id: SSIG-7 title: IdP Compromise Signal Review props: - value: 4.8 G class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-7_smt name: statement prose: "If the IdP receives a signal that a subscriber account is suspected of compromise, the IdP SHALL review actions taken by that account at the IdP for suspicious activity." - id: SSIG-7_obj links: - rel: assessment-for href: "#SSIG-7_smt" name: objective prose: Determine whether the IdP reviews subscriber account activity upon receiving a compromise signal. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-7_asm-examine name: assessment-method prose: "Examine the IdP incident response procedures for documented processes triggered by receipt of a subscriber account compromise signal, including the scope of activity review (e.g., authentication events, attribute changes, federation transactions)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SSIG-7_asm-test name: assessment-method prose: Test by simulating a compromise signal for a test subscriber account and verifying that the IdP initiates a review of that account's activity. - id: SSIG-7_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used. Related: SSIG-8 (4.8 H) requires the IdP to signal additional RPs if suspicious activity is confirmed. - id: SSIG-8 title: IdP Compromise Notification to Affected RPs props: - value: 4.8 H class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-8_smt name: statement prose: "If suspicious activity is confirmed at the IdP, the IdP SHALL signal any additional RPs that the subscriber account was used for during the suspected time frame." - id: SSIG-8_obj links: - rel: assessment-for href: "#SSIG-8_smt" name: objective prose: Determine whether the IdP signals all RPs that the compromised subscriber account was used for during the suspected time frame when suspicious activity is confirmed. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-8_asm-examine name: assessment-method prose: "Examine the IdP's incident response procedures to identify a documented process for signaling RPs when suspicious activity is confirmed on a subscriber account. Determine whether the IdP retains federation transaction records sufficient to identify which RPs the subscriber account interacted with during the suspected time frame. If yes, verify the process signals the RPs identified from those federation transaction records for the suspected time frame. If no, verify the process signals all RPs with which the IdP has a pre-established trust agreement authorizing shared signaling that could have been impacted for the relevant subscriber population or transaction context." - id: SSIG-8_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used. The IdP is not required to retain records of which RPs a subscriber account interacted with. However, the obligation to signal affected RPs remains. If the IdP cannot scope the notification to RPs the account actually used during the suspected time frame, the IdP must signal all RPs that could have been impacted. In practice, this means all RPs with pre-established trust agreement artifact(s) that authorize shared signaling (see SSIG-6, PETA-6). Prerequisite: SSIG-7 (IdP review upon receiving compromise signal). - id: SSIG-9 title: Security and Privacy Reviews of Additional Signals props: - value: 4.8 I class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-9_smt name: statement prose: "Additional signals from both the IdP and RP SHALL be subject to a security review, included in the privacy risk assessment, and addressed in the trust agreement." - id: SSIG-9_obj links: - rel: assessment-for href: "#SSIG-9_smt" name: objective prose: "Determine whether signals beyond those recommended in Sec. 4.8 have undergone a security review, been included in the privacy risk assessment, and are addressed in the trust agreement artifact(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-9_asm-examine name: assessment-method prose: |- Examine all shared signals implemented by the assessed party. Identify any signals not in the following recommended sets: (1) IdP-to-RP recommended signals: account terminated/suspended/disabled; account suspected of being compromised; attributes changed (including non-federated identifiers such as email address or certificate common name); possible range of IAL, AAL, or FAL for the account has changed; authenticators have been updated. (2) RP-to-IdP recommended signals: account terminated/suspended/disabled; suspected of being compromised; bound authenticator added; bound authenticator removed. For each additional signal identified, verify that it has been subject to a security review, included in the privacy risk assessment, and addressed in the applicable trust agreement artifact(s), including the event that triggers the signal, the information included in the signal, any additional parameters, and the expected processing by the receiving party. - id: SSIG-9_gdn name: guidance prose: "Assessment is required when: Shared signaling is used." - id: SSIG-10 title: Linked Account Signal Handling Documentation props: - value: 4.8 J class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-10_smt name: statement prose: "If the RP allows for account linking to multiple IdPs, the RP SHALL document their practices regarding signals for linked accounts." - id: SSIG-10_obj links: - rel: assessment-for href: "#SSIG-10_smt" name: objective prose: Determine whether the RP documents its practices for handling shared signals that affect RP subscriber accounts linked to multiple IdPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-10_asm-examine name: assessment-method prose: "Examine the RP policy documentation for practices governing how signals received from one IdP are applied to an RP subscriber account that is also linked to one or more other IdPs (e.g., whether a compromise signal from one IdP triggers suspension of the entire RP subscriber account or only the affected federated identifier)." - id: SSIG-10_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used and the RP allows account linking to multiple IdPs. This control addresses the ambiguity that arises when a signal pertains to one IdP's subscriber account, but the RP subscriber account is also accessible via other IdPs. Without documented practices, signal handling for linked accounts is ad hoc and potentially inconsistent. Related: SSIG-11 constrains these practices by requiring that shared signals not reveal the identity of a subscriber's linked IdPs - id: SSIG-11 title: Linked IdP Identity Protection in Shared Signals props: - value: 4.8 K class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: SSIG-11_smt name: statement prose: The RP SHALL ensure that the shared signals do not reveal the identity of a subscriber's linked IdPs. - id: SSIG-11_obj links: - rel: assessment-for href: "#SSIG-11_smt" name: objective prose: Determine whether the RP's shared signals are constructed so as not to reveal the identity of any other IdPs linked to the subscriber's RP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: SSIG-11_asm-examine name: assessment-method prose: "Examine the RP shared signal message content and structure to verify that no signal includes or implies the identity of other IdPs linked to the subscriber's RP subscriber account (e.g., IdP identifiers, IdP-specific federated identifiers, or attributes uniquely associated with a particular IdP)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: SSIG-11_asm-test name: assessment-method prose: Test by generating one or more shared signals for a test RP subscriber account linked to multiple IdPs and verifying that the outbound signal content does not directly or indirectly reveal the identity of any other linked IdP. - id: SSIG-11_gdn name: guidance prose: |- Assessment is required when: Shared signaling is used and the RP allows account linking to multiple IdPs. Companion to SSIG-10, which requires the RP to document its signal-handling practices for linked accounts. This control constrains what those signals may contain. Revealing linked IdP identities could enable profiling of a subscriber's identity provider relationships, undermining federation privacy goals. - id: ARTC-1 title: Assertions represent Discrete Authentication Events props: - value: 4.9 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-1_smt name: statement prose: Assertions SHALL represent a discrete authentication event of the subscriber at the IdP. - id: ARTC-1_obj links: - rel: assessment-for href: "#ARTC-1_smt" name: objective prose: "Determine whether each assertion issued by the IdP represents a single, discrete authentication event of the subscriber." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-1_asm-examine name: assessment-method prose: "Examine the IdP assertion issuance process to verify that each assertion is generated in response to a specific authentication event and does not represent a standing authorization, batch of events, or ongoing session state." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-1_asm-examine-2 name: assessment-method prose: Examine sample assertions to verify that each contains a unique authentication time corresponding to a single event. - id: ARTC-1_gdn name: guidance prose: |- SAI-1 (4.5 A) is a prerequisite: the subscriber must have an authenticated session before assertion issuance. ARTC-3 (4.9 C) reinforces this requirement by requiring an authentication time timestamp in every assertion. - id: ARTC-2 title: RP Assertion Processing as Discrete Event props: - value: 4.9 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-2_smt name: statement prose: Assertions...SHALL be processed as a discrete authentication event at the RP. - id: ARTC-2_obj links: - rel: assessment-for href: "#ARTC-2_smt" name: objective prose: Determine whether the RP processes each assertion as a discrete authentication event. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-2_asm-examine name: assessment-method prose: "Examine the RP assertion processing procedures to verify that each received assertion is treated as a discrete event rather than being merged with, appended to, or treated as a continuation of a prior assertion." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-2_asm-examine-2 name: assessment-method prose: Examine the RP session management practices to verify that a new assertion does not automatically extend or refresh an existing authenticated session established by a prior assertion. - id: ARTC-3 title: Assertion Attribute Requirements props: - value: 4.9 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-3_smt name: statement prose: |- All assertions SHALL include the following attributes: (1) Issuer identifier: An identifier for the issuer of the assertion (i.e., the IdP). (2) Audience identifier: An identifier for the party intended to consume the assertion (i.e., the RP). An assertion can contain more than one audience identifier at FAL1. (3) Issuance time: A timestamp that indicates when the IdP issued the assertion. (4) Validity time window: A period of time outside of which the assertion SHALL NOT be accepted as valid by the RP for the purposes of authenticating the subscriber and starting an authenticated session at the RP. This is usually communicated by means of an expiration timestamp for the assertion in addition to the issuance timestamp. (5) Assertion identifier: A value that uniquely identifies this assertion and is used to prevent attackers from replaying prior assertions. (6) Authentication time: A timestamp that indicates when the IdP last verified the presence of the subscriber at the IdP through a primary authentication event. (7) Signature: Digital signature or MAC, including verification key identifier, that covers the entire assertion. - id: ARTC-3_obj links: - rel: assessment-for href: "#ARTC-3_smt" name: objective prose: Determine whether assertions generated contain at least this list of required fields with appropriate values and that the assertion's contents are covered by the signature. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTC-3_asm-test name: assessment-method prose: Test by generating a test assertion for a test RP. Examine the assertion for all required fields and verify their contents. - id: ARTC-3_gdn name: guidance prose: "This criterion presents all of the elements required in every assertion. Each element provides a different and vital piece of information for the secure conveyance of the identity information. Assertions can contain additional information, whether about the subscriber or about the authentication event itself, but these fields are all required at all FALs." - id: ARTC-4 title: Subscriber Identification in Non-Ephemeral Assertions props: - value: 4.9 D class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-4_smt name: statement prose: "If the RP subscriber account does not use an ephemeral provisioning process, the subscriber SHALL be identified in the assertion using a federated identifier (see Sec. 3.4) or through an account resolution process (see Sec. 3.8.2)." - id: ARTC-4_obj links: - rel: assessment-for href: "#ARTC-4_smt" name: objective prose: "Determine whether the subscriber is identified in the assertion using a federated identifier or through attributes sufficient for account resolution, when the RP subscriber account does not use ephemeral provisioning." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-4_asm-examine name: assessment-method prose: |- Examine sample assertions to determine which subscriber identification information they include for IdPs. If a federated identifier is used, satisfied by ARTC-5 (subject identifier) and FEDID-1. If account resolution is used, examine the trust agreement artifact(s) for the agreed-upon attributes used for resolution, then examine a sample of assertions to confirm that those attributes are present. For RPs, if a federated identifier is used, satisfied by FEDID-2. If account resolution is used, satisfied by ACCR-1. - id: ARTC-4_gdn name: guidance prose: "Assessment is required when: The RP subscriber account does not use an ephemeral provisioning process." - id: ARTC-5 title: Subject Identifier in Assertion props: - value: 4.9 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-5_smt name: statement prose: |- If the subscriber is identified using a federated identifier, the assertion SHALL include: Subject Identifier: An identifier for the party to which the assertion applies (i.e., the subscriber). - id: ARTC-5_obj links: - rel: assessment-for href: "#ARTC-5_smt" name: objective prose: Determine whether the assertion includes a subject identifier when the subscriber is identified using a federated identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-5_asm-examine name: assessment-method prose: Examine the IdP's assertion generation configuration to verify that a subject identifier is included in assertions when federated identifiers are the subscriber identification method. - id: ARTC-5_gdn name: guidance prose: |- Assessment is required when: The subscriber is identified using a federated identifier. The subject identifier is separated from the unconditional assertion requirements in ARTC-3 because subscriber-controlled wallets acting as IdPs may not include a subject identifier in their assertions. For example, mobile driver's licenses may identify the subscriber through the driver's license number and issuer rather than a subject identifier. This control ensures a subject identifier is present when federated identifiers are the identification method. - id: ARTC-6 title: xAL Information in Assertion or Trust Agreement props: - value: 4.9 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-6_smt name: statement prose: |- The following aspects of the federation transaction SHALL be provided through information contained in the assertion contents or the applicable trust agreement: (1) The IAL as well as the type of verification used during the identity proofing process (e.g., biometric, address verification), an indication of the identity proofing processes used to establish the subscriber account, or an indication that no IAL is asserted. (2) The AAL used when the subscriber authenticated to the IdP or an indication that no AAL is asserted. (3) The IdP's intended FAL of the federation process represented by the assertion. - id: ARTC-6_obj links: - rel: assessment-for href: "#ARTC-6_smt" name: objective prose: Determine whether all required xAL information is conveyed through the assertion contents or trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-6_asm-examine name: assessment-method prose: |- Examine sample assertions where IAL and AAL are asserted. For IAL, verify that the verification method used during identity proofing (e.g., biometric, home address verification, cell phone verification) is provided. Also verify that the proofing process(es) used to establish the subscriber account are indicated. Where multiple proofing pathways are possible at a given IAL, the information provided must be sufficient for the RP to determine which process was used. The conveyance of the IAL is satisfied by RXAL-3. For AAL, satisfied by RXAL-4. For FAL, satisfied by RXAL-5 - id: ARTC-6_gdn name: guidance prose: "The IAL alone tells the RP the level of identity proofing, but not how it was achieved. SP 800-63A-4 defines multiple proofing pathways at each IAL, each with a different risk profile. Without the verification type and proofing pathway, the RP cannot make fine-grained, risk-informed access decisions; it can only make a binary accept/reject decision based on the IAL number. This control ensures the IdP provides that granularity." - id: ARTC-7 title: Cryptographic Nonce props: - value: 4.9 G class: index name: label - value: IdP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: ARTC-7_smt name: statement prose: |- At FAL2 and above, the assertion SHALL include: 1. Nonce: A cryptographic nonce from the RP's federation request. - id: ARTC-7_obj links: - rel: assessment-for href: "#ARTC-7_smt" name: objective prose: Determine whether FAL2 and FAL3 assertions include a cryptographic nonce from the RP's federation request. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-7_asm-examine name: assessment-method prose: Examine the sample assertions to verify that each contains a cryptographic nonce. Verify that the nonce in the assertion corresponds to the nonce provided in the RP's federation request (see ARTRQ-1). - id: ARTC-7_gdn name: guidance prose: |- The nonce is a mechanism by which FAL2 achieves its defining security property: assertion injection protection (see FAL2-1). It cryptographically binds the RP's specific federation request to the resulting assertion, preventing an attacker from injecting a captured or manufactured assertion into a different transaction. The requirement operates as a three-part chain: the RP sends a nonce in its request (ARTRQ-1, Sec. 4.10 A), the IdP echoes it in the assertion (this control), and the RP validates its presence (ARTC-10 item 5). In the errata publication, this control will be changed to: At FAL2 and above, the assertion SHALL include the cryptographic nonce from the RP's federation request. - id: ARTC-8 title: FAL3 Assertion Mechanism props: - value: 4.9 H class: index name: label - value: IdP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: ARTC-8_smt name: statement prose: |- At FAL3, the assertion SHALL include one of the following: (1) The public key, key identifier, or other identifier for a holder-of-key assertion; or (2) An indicator that the verification of a bound authenticator is required to process this assertion - id: ARTC-8_obj links: - rel: assessment-for href: "#ARTC-8_smt" name: objective prose: Determine whether FAL3 assertions meet holder-of-key or bound authenticator requirements. - props: - value: EXAMINE name: method class: assessment-summary id: ARTC-8_asm-summary title: Assessment Method name: assessment-method prose: |- Holder-of-key assertions: Satisfied by HKA-1. Bound authenticators: Satisfied by BAUTH-1. - id: ARTC-8_gdn name: guidance prose: "FAL3 achieves its defining security property, subscriber authentication at the RP as well as at the IdP, through one of two mechanisms: holder-of-key assertions or bound authenticators. The assertion must signal which mechanism is in use so the RP knows which verification path to execute." - id: ARTC-9 title: Prohibition of Authentication Secrets in Assertions props: - value: 4.9 I class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-9_smt name: statement prose: "Assertions SHALL NOT contain subscriber authentication secrets (e.g., passwords)." - id: ARTC-9_obj links: - rel: assessment-for href: "#ARTC-9_smt" name: objective prose: Determine whether the IdP's assertions exclude subscriber authentication secrets. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-9_asm-examine name: assessment-method prose: "Examine sample assertions to verify that no subscriber authentication secrets are present, including but not limited to passwords, shared secrets, or other authenticator values. Verify that the IdP's assertion generation process has no mechanism or configuration that would embed authentication secrets in assertion payloads." - id: ARTC-9_gdn name: guidance prose: "Assertions are an identity conveyance mechanism, not an authentication credential. Including authentication secrets in an assertion would expose them to the RP and any intermediary that processes the assertion, creating a direct credential compromise vector. HKA-5 (Sec. 3.15) addresses the narrower case of prohibiting unencrypted private or symmetric keys in holder-of-key assertions. This control covers the general case across all assertion types and all categories of authentication secrets." - id: ARTC-10 title: RP Assertion Validation Checklist props: - value: 4.9 J class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-10_smt name: statement prose: |- The RP SHALL validate the assertion by checking that all of the following are true: (1) Signature validation: Ensure that the signature of the assertion is valid and corresponds to a verification key that belongs to the IdP sending the assertion. (2) Issuer verification: Ensure that the assertion was issued by the expected IdP. (3) Time validation: Ensure that the validity time window is within acceptable limits of the current timestamp. (4) Audience restriction: Ensure that this RP is the intended recipient of the assertion. (5) Nonce: Ensure that the cryptographic nonce included in the RP's request (if applicable) is included in the presentation. (6) Transaction terms: Ensure that the IAL, AAL, and FAL represented by the assertion are allowable under the applicable trust agreement and are suitable for the RP's needs. (7) Assertion identifier: Ensure that the assertion has not been replayed within its validity time window at this RP. - id: ARTC-10_obj links: - rel: assessment-for href: "#ARTC-10_smt" name: objective prose: Determine whether the RP validates all required elements of an assertion before accepting it. - props: - value: EXAMINE name: method class: assessment-summary id: ARTC-10_asm-summary title: Assessment Method name: assessment-method prose: |- Verify that the RP's assertion validation process includes all of the following checks: (1) Signature validation, satisfied by FAL1-2. (2) Issuer verification, satisfied by ASRP-1 (b). (3) Time validation: Examine the RP's assertion processing logic to confirm it compares the assertion's issuance time and expiration against the current timestamp and rejects assertions outside the validity window. (4) Audience restriction, satisfied by AUDR-2. (5) Nonce validation (required at FAL2 & FAL3): Test by doing the following: (a) Generate a test federation transaction at FAL2 or above and capture the nonce sent in the RP's federation request. (b) Verify the RP accepts an assertion containing the matching nonce. (c) Present an otherwise valid assertion containing a different nonce value - verify rejection. (d) Present an otherwise valid assertion with the nonce omitted - verify rejection. (6) Transaction terms: Examine the xAL terms established in the trust agreement artifact(s) (see TRUST-7) and ensure that the RP is configured to only accept those xALs. Suitability terms are satisfied by RXAL-8. (7) Assertion identifier: satisfied by FAL1-5. - id: ARTC-10_gdn name: guidance prose: |- This control consolidates the RP's assertion validation obligations into a single checklist. Items 1, 2, 4, 6b, and 7 defer to dedicated controls; the unique assessment work here is time validation (item 3), nonce validation (item 5), and trust agreement xAL conformance (item 6a). - id: ARTC-11 title: Subject ID Uniqueness props: - value: 4.9 K class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-11_smt name: statement prose: An RP that uses the federated identifier to identify the subscriber SHALL NOT treat subject identifiers as inherently globally unique across IdPs. - id: ARTC-11_obj links: - rel: assessment-for href: "#ARTC-11_smt" name: objective prose: Determine whether an RP treats the same subject identifier from different IdPs as different accounts. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-11_asm-examine name: assessment-method prose: "Examine the RP's code, configuration, and documentation to verify that subject identifiers are always interpreted in the context of the IdP that asserted them." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTC-11_asm-test name: assessment-method prose: Test by configuring two test IdPs to assert the same subject identifier. Submit an assertion from each IdP to the RP. Verify that the RP creates two distinct subscriber accounts and does not associate them. - id: ARTC-11_gdn name: guidance prose: |- Assessment is required when: The RP uses the federated identifier to identify the subscriber. Even if an IdP uses a collision-resistant namespace such as a UUID for its subscriber identifiers, the tying of a specific identifier to a particular subscriber is still under the control of the IdP making the assertion. An RP's internal processing of an assertion needs to take this into account by processing the combination of the subject identifier along with the IdP that issued the assertion. If the RP does not account for the source IdP when determining the identity of the subscriber, a rogue or compromised IdP could impersonate subscribers from another IdP at a susceptible RP by mimicking the valid IdP's subject identifiers. - id: ARTC-12 title: RP Session Time Independent of Assertion props: - value: 4.9 L class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTC-12_smt name: statement prose: Assertion validity time windows SHALL NOT be used to limit the session at the RP. See Sec. 4.7 for more information. - id: ARTC-12_obj links: - rel: assessment-for href: "#ARTC-12_smt" name: objective prose: Determine whether the RP manages its session lifetime independently of the assertion validity time window. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTC-12_asm-examine name: assessment-method prose: "Examine the RP's session management configuration to confirm the session timeout is set by RP policy, and is not the same as the assertion's expiration timestamp." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTC-12_asm-test name: assessment-method prose: Test by authenticating via federation and establishing an RP session. Confirm that the RP session remains valid after the assertion's validity window has expired. - id: ARTC-12_gdn name: guidance prose: "The assertion validity window exists solely for the RP to process the assertion and create a local session; it is not a session duration directive from the IdP. Section 4.7 establishes that assertion validity, IdP session lifetime, and RP session lifetime are three independent time periods. An RP that terminates sessions when the assertion expires would force unnecessary reauthentication and effectively let the IdP dictate RP session policy. RP session management requirements are governed by SP 800-63B Section 5 (Session Management)." - id: ARTRQ-1 title: Assertion Request Requirements props: - value: 4.10 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTRQ-1_smt name: statement prose: |- When the federation transaction is initiated by the RP, the RP's request for an assertion SHALL contain: (1) An identifier for the RP. (2) A cryptographic nonce to be returned in the assertion. - id: ARTRQ-1_obj links: - rel: assessment-for href: "#ARTRQ-1_smt" name: objective prose: Determine if the RP includes the required identifier and cryptographic nonce in requests for an assertion. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTRQ-1_asm-examine name: assessment-method prose: Examine the RP's federation configuration to confirm that it sends its identifier and a cryptographic nonce in all assertion requests. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTRQ-1_asm-test name: assessment-method prose: Test by initiating a request for an assertion. Examine the request and verify that the request contains a unique identifier for the RP and a cryptographic nonce. - id: ARTRQ-1_gdn name: guidance prose: "The cryptographic nonce binds the assertion to the specific request, preventing replay and injection attacks. The RP's request should also contain the set of requested attributes and their purpose, and the authentication event requirements." - id: BCP-1 title: Tamper & Fabrication Resistant Assertion References props: - value: 4.11.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-1_smt name: statement prose: The assertion reference itself contains no information about the subscriber and SHALL be resistant to tampering and fabrication by an attacker. - id: BCP-1_obj links: - rel: assessment-for href: "#BCP-1_smt" name: objective prose: Determine whether the IdP generates and manages assertion references such that they are resistant to tampering and fabrication by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-1_asm-examine name: assessment-method prose: |- Examine the IdP's assertion reference design and generation process to verify that the assertion reference contains no subscriber information. Verify the reference is generated and managed in a way that resists tampering and fabrication by an attacker (e.g., cryptographic randomness with sufficient entropy, or cryptographic integrity protection). - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BCP-1_asm-test name: assessment-method prose: "Test by obtaining a valid assertion reference, modifying it, and presenting the modified value to the IdP. Verify rejection. Present a fabricated reference not issued by the IdP. Verify rejection." - id: BCP-1_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. Assertion references are used to limit the information that is exposed to different parties within the federation transaction, such as the user's browser. As a consequence, it is counterproductive to put any information about the subscriber in the assertion reference itself. Additionally, since the RP will trade the assertion reference for the actual assertion, the assertion reference needs to be something that an attacker can neither guess nor manipulate in order to alter the assertion received. It is recommended that assertion references be cryptographically random values. - id: BCP-2 title: RP-Specific Assertion Reference props: - value: "4.11.1 #1" class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-2_smt name: statement prose: |- The assertion reference: 1. SHALL be limited to use by a single RP. - id: BCP-2_obj links: - rel: assessment-for href: "#BCP-2_smt" name: objective prose: "Determine whether the IdP enforces a binding between each issued assertion reference and exactly one designated Relying Party, ensuring that the reference can only be used by a single RP." - props: - value: EXAMINE name: method class: assessment-summary id: BCP-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by BCP-10. - id: BCP-2_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. Since assertion references are traded for assertions, the IdP needs to ensure that the assertion reference is presented only by the specific RP to which it was issued. Otherwise, an attacker could capture an assertion reference and inject it into a different RP to fake a log in. This requirement applies even if the RPs are logistically related, such as being configured to receive a common identifier. If assertion references are not used, this requirement does not apply. - id: BCP-3 title: Single-use Assertion Reference props: - value: "4.11.1 #2" class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-3_smt name: statement prose: |- The assertion reference: 2. SHALL be single-use. - id: BCP-3_obj links: - rel: assessment-for href: "#BCP-3_smt" name: objective prose: Determine whether assertion references can be successfully used only once. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-3_asm-examine name: assessment-method prose: "Examine the IdP's assertion reference lifecycle configuration to confirm that the IdP maintains a state record for each issued reference. Verify that references are invalidated (e.g., flagged or deleted) upon first successful redemption." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BCP-3_asm-test name: assessment-method prose: "Test by obtaining a valid assertion reference and redeeming it once through the IdP's assertion-resolution endpoint. Attempt a second redemption of the same reference; verify that the IdP rejects the request (e.g., returns an error such as \"invalid_reference,\" \"expired,\" or \"already_used\")." - id: BCP-3_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. The IdP is responsible for ensuring that once an assertion reference has been redeemed (i.e., used by the designated Relying Party to obtain the assertion), it cannot be used again. This control prevents replay attacks and the unauthorized reuse of valid assertion references by an attacker or another RP session. - id: BCP-4 title: Assertion Reference Time Limitation props: - value: "4.11.1 #3" class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-4_smt name: statement prose: |- The assertion reference: 3. SHALL be time-limited. - id: BCP-4_obj links: - rel: assessment-for href: "#BCP-4_smt" name: objective prose: Determine whether assertion references are time-limited. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-4_asm-examine name: assessment-method prose: "Examine the IdP's federation protocol configuration (e.g., authorization code lifetime in OIDC, artifact validity window in SAML) to identify the configured assertion reference lifetime." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BCP-4_asm-test name: assessment-method prose: "Test by completing a back-channel federation transaction up to the point where the test RP receives the assertion reference, but do not immediately redeem it. Wait beyond the configured lifetime, then have the test RP present the reference to the IdP. Confirm that the IdP rejects the expired reference." - id: BCP-4_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. The assertion reference is a temporary artifact whose sole purpose is to allow the RP to retrieve the full assertion from the IdP. A short lifetime limits the window for interception, replay, or misuse. The guidelines recommend (SHOULD) a validity window of no more than five minutes. - id: BCP-5 title: RP Authentication at Assertion Reference Redemption props: - value: "4.11.1 #4" class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-5_smt name: statement prose: |- The assertion reference: 4. SHALL be presented along with authentication of the RP to the IdP. - id: BCP-5_obj links: - rel: assessment-for href: "#BCP-5_smt" name: objective prose: Determine whether the RP authenticates itself to the IdP when presenting the assertion reference. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-5_asm-examine name: assessment-method prose: Examine the RP's federation configuration to confirm that the RP authenticates to the IdP when redeeming assertion references. - id: BCP-5_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. RP authentication at the point of assertion reference redemption prevents an attacker who intercepts or steals an assertion reference from redeeming it at the IdP. Without RP authentication, possession of the reference alone would be sufficient to obtain the full assertion. - id: BCP-6 title: Assertion Reference Security props: - value: "4.11.1 #5" class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-6_smt name: statement prose: |- The assertion reference: 5. SHALL NOT be predictable or guessable by an attacker. - id: BCP-6_obj links: - rel: assessment-for href: "#BCP-6_smt" name: objective prose: Determine whether assertion references are generated in a manner that prevents prediction or guessing by an attacker. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-6_asm-examine name: assessment-method prose: Examine the IdP documentation describing the assertion reference generation mechanism to confirm it uses an approved random bit generator or equivalent method that produces values with at least 112 bits of security strength per SP 800-131A. - id: BCP-6_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. This control complements BCP-1, which requires tamper and fabrication resistance. BCP-1 addresses integrity protection of assertion references; this control addresses the unpredictability of their values. Together they ensure an attacker can neither guess a valid reference nor modify an intercepted one. - id: BCP-7 title: Subscriber Back-Channel Protection props: - value: 4.11.1 B class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-7_smt name: statement prose: Conveyance of the assertion reference from the IdP to the subscriber and from the subscriber to the RP SHALL be made over an authenticated protected channel. - id: BCP-7_obj links: - rel: assessment-for href: "#BCP-7_smt" name: objective prose: "Determine whether the delivery of the assertion reference occurs over authenticated protected channels, across all connections." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-7_asm-examine name: assessment-method prose: "Examine the endpoint configuration to confirm that assertion reference exchange occurs only over authenticated protected channels. (e.g., HTTPS/TLS)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BCP-7_asm-test name: assessment-method prose: "Test by attempting to convey the assertion reference from the IdP to the subscriber and from the subscriber to the RP over an unprotected channel (e.g., plain HTTP) and verify that each attempt fails, is rejected, or the connection is refused. A protocol-specific error is not required if the endpoints refuse unprotected connections entirely." - id: BCP-7_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. In this model, the assertion reference is passed through the front channel using the subscriber's browser. This process consists of two separate network connections over which information flows, from the subscriber to the IdP and the subscriber to the RP. Both legs of this connection have to be protected from attackers by using authenticated protected channels, such as HTTPS over TLS connections. - id: BCP-8 title: RP-IdP Back-Channel Protection props: - value: 4.11.1 C class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-8_smt name: statement prose: Conveyance of the assertion reference from the RP to the IdP and vice versa SHALL be made over an authenticated protected channel. - id: BCP-8_obj links: - rel: assessment-for href: "#BCP-8_smt" name: objective prose: Determine whether the connection between the RP and IdP takes place over an authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-8_asm-examine name: assessment-method prose: Examine the relevant federation configuration to verify that assertion references are conveyed between the RP and IdP only over authenticated protected channels. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BCP-8_asm-test name: assessment-method prose: "Test by attempting to convey the assertion reference between the RP and IdP over an unprotected channel (e.g., plain HTTP) and verify that the attempt fails, is rejected, or the connection is refused." - id: BCP-8_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. In this model, the assertion reference is traded for the assertion by the RP making a direct call to the IdP. This call, which carries both the assertion reference and the assertion itself, needs to be protected from attackers by using an authenticated protected channel, such as HTTPS over TLS connections. - id: BCP-9 title: Assertion Reference Injection Prevention props: - value: 4.11.1 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-9_smt name: statement prose: "The RP SHALL protect itself against the injection of manufactured or captured assertion references by using cross-site scripting (XSS) and cross-site request forgery (CSRF) protection, rejecting assertion references outside of the correct stage of a federation transaction, or other accepted techniques discussed in Sec. 3.11.1." - id: BCP-9_obj links: - rel: assessment-for href: "#BCP-9_smt" name: objective prose: Determine whether the RP employs best practices for its platform to protect against injection of assertion references. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-9_asm-examine name: assessment-method prose: "Examine the RP's federation implementation to verify that it protects against assertion reference injection through XSS and CSRF protections, rejection of assertion references outside the correct stage of the federation transaction, and other RP-side countermeasures such as request correlation, nonce use, and transaction state tracking." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: BCP-9_asm-test name: assessment-method prose: "Test by initiating a federation transaction in one RP session, capturing the resulting assertion reference, and submitting that assertion reference in a different RP session that has a different session identifier and unrelated transaction state. Verify that the RP rejects the assertion reference and does not complete the federation transaction." - id: BCP-9_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. The assertion reference needs to be delivered to the RP in some fashion, and for many protocols this happens through a front-channel redirect through the subscriber's browser. The RP needs to ensure that any assertion references presented to it are legitimate by protecting itself against common injection attacks. The techniques for protection vary depending on the type of RP application and its deployment model, but there are many resources and documented best practices for different applications and platforms. For example, ensuring that the assertion reference is returned in the same browser session that was used to request the assertion reference in the front channel. Without these protections, an attacker could convince an RP to trade an injected (but otherwise valid) assertion reference and therefore get a fraudulent assertion and give the attacker access to the RP. - id: BCP-10 title: RP-Assertion Reference Binding props: - value: 4.11.1 E class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: BCP-10_smt name: statement prose: "When assertion references are presented to the IdP, the IdP SHALL verify that the RP presenting the assertion reference is the same RP that made the assertion request that resulted in the assertion reference." - id: BCP-10_obj links: - rel: assessment-for href: "#BCP-10_smt" name: objective prose: Determine whether an assertion reference is bound to a single RP identified by the IdP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: BCP-10_asm-examine name: assessment-method prose: "Examine IdP documentation to ensure the IdP verifies the RP presenting the assertion reference using client credentials, PKCE, or alternative mechanism providing equivalent protections." - id: BCP-10_gdn name: guidance prose: |- Assessment is required when: A back-channel presentation is used. Before issuing an assertion to the RP in exchange for the assertion reference, the IdP needs to ensure that the RP making the exchange request is the same RP that the assertion reference was intended for. Otherwise, an attacker could substitute an assertion reference for one RP in order to get an assertion for a different RP, or trick the subscriber into authorizing one RP only to authorize the attacker's RP. The IdP can do this by associating a specific RP with the assertion reference when the reference is created. - id: FCP-1 title: Front-Channel Assertion Replay Protection props: - value: 4.11.2 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FCP-1_smt name: statement prose: The RP SHALL use the assertion identifier to ensure that a given assertion is presented at most once during the assertion's validity time window. - id: FCP-1_obj links: - rel: assessment-for href: "#FCP-1_smt" name: objective prose: Determine whether the RP uses the assertion identifier to prevent replay within the assertion's validity time window. - props: - value: EXAMINE name: method class: assessment-summary id: FCP-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by FAL1-5. - id: FCP-1_gdn name: guidance prose: |- Assessment is required when: Front-channel presentation is used. Front-channel presentation passes the full assertion through the subscriber's browser (user agent), increasing the risk of capture and replay. This requirement mandates that the RP track assertion identifiers to ensure each assertion is accepted at most once within its validity window. - id: FCP-2 title: RP Front-Channel Injection Protection props: - value: 4.11.2 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FCP-2_smt name: statement prose: "The RP SHALL protect itself against the injection of manufactured or captured assertions by using XSS and CSRF protection, rejecting assertions outside of the correct stage of a federation transaction, or other accepted techniques discussed in Sec. 3.11.1." - id: FCP-2_obj links: - rel: assessment-for href: "#FCP-2_smt" name: objective prose: Determine whether the RP employs best practices for its platform to protect against the injection of assertions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FCP-2_asm-examine name: assessment-method prose: "Examine the RP's federation implementation for XSS and CSRF protections, session-binding of federation transactions, and other injection countermeasures appropriate to the platform" - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FCP-2_asm-test name: assessment-method prose: Test by capturing an assertion for the RP and injecting it into an unrelated active session at the RP. Ensure that the RP does not accept the injected assertion. - id: FCP-2_gdn name: guidance prose: |- Assessment is required when: Front-channel presentation is used. The assertion needs to be delivered to the RP in some fashion, and for many protocols, this happens through a front-channel redirect through the subscriber's browser. The RP needs to ensure that any assertions presented to it are legitimate by protecting itself against common injection attacks. The techniques for protection vary by RP application and deployment model, but there are many resources and documented best practices for different applications and platforms. Without these protections, an attacker could convince an RP to accept an injected (but otherwise valid) assertion and gain access to the subscriber's account at an RP. - id: FCP-3 title: Subscriber Front-Channel Protection props: - value: 4.11.2 C class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FCP-3_smt name: statement prose: Conveyance of the assertion from the IdP to the subscriber and from the subscriber to the RP SHALL be made over an authenticated protected channel. - id: FCP-3_obj links: - rel: assessment-for href: "#FCP-3_smt" name: objective prose: Determine whether the connections between the subscriber and the RP as well as the subscriber and IdP take place over an authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FCP-3_asm-examine name: assessment-method prose: "Examine the assessed party's front-channel federation endpoints to confirm they require authenticated protected channels (e.g., HTTPS/TLS) and that connections over non-protected channels are refused." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FCP-3_asm-test name: assessment-method prose: "Test by initiating a front-channel federation transaction targeting the assessed party's endpoints. Verify the connection uses an authenticated protected channel. Attempt to connect to the assessed party's front-channel endpoints over a non-protected channel (e.g., plain HTTP) and verify the request is rejected, or the connection is refused." - id: FCP-3_gdn name: guidance prose: "Assessment is required when: Front-channel presentation is used." - id: FCP-4 title: Front-Channel Personal Information Protection props: - value: 4.11.2 D class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: FCP-4_smt name: statement prose: "As a consequence, an IdP that uses HTTP redirects for the front-channel presentation of assertions SHALL encrypt all personal information in the assertion, as discussed in Sec. 3.13.3." - id: FCP-4_obj links: - rel: assessment-for href: "#FCP-4_smt" name: objective prose: Determine whether any personal information in assertions that is passed through the front channel is encrypted. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: FCP-4_asm-examine name: assessment-method prose: "Examine the IdP's assertion generation configuration to confirm that assertions delivered via front-channel presentation encrypt all personal information. For encryption mechanism requirements, see ENCA-1." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: FCP-4_asm-test name: assessment-method prose: Test by generating a test assertion containing personal information via a front-channel presentation mechanism. Examine the assertion payload as transmitted through the front channel and verify that all personal information is encrypted. - id: FCP-4_gdn name: guidance prose: |- Assessment is required when: Front-channel presentation is used. Front-channel presentation passes the assertion through the subscriber's browser, exposing it to intermediaries. Encryption ensures that even if the assertion is intercepted, personal information remains protected. ENCA-1 assesses the encryption mechanism; this control verifies that encryption is applied when front-channel delivery is used. - id: IABSCW-1 title: Wallet Attribute Bundle Issuance Process props: - value: 5.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IABSCW-1_smt name: statement prose: |- When the CSP issues attribute bundles to the subscriber-controlled wallet, the process SHALL include the following steps: (1) The subscriber proves their identity to the CSP's issuance functionality using the CSP's identity proofing process or by authenticating to the subscriber account. (2) The subscriber activates the wallet using an activation factor, which might entail authenticating to a hosted wallet service. (3) The wallet generates or chooses a signing key and corresponding verification key. The wallet proves possession of its signing key to the CSP. (4) The CSP creates one or more attribute bundles that include subscriber attributes and the wallet's verification key (or a reference to that key). (5) The wallet stores the attribute bundle for later presentation to RPs. - id: IABSCW-1_obj links: - rel: assessment-for href: "#IABSCW-1_smt" name: objective prose: Determine whether the CSP's issuance process requires the subscriber to prove their identity and prove possession of a wallet-generated key before an attribute bundle is issued. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IABSCW-1_asm-examine name: assessment-method prose: "Examine the following: (1) The CSP's issuance process to confirm it requires subscriber identity verification (via identity proofing or authentication) before bundle creation. Identity proofing requirements are assessed under SP 800-63A; authentication requirements are assessed under SP 800-63B. (2) The CSP's documentation to confirm that the CSP has evaluated that the target wallet platform enforces activation factor requirements before permitting signing key operations. Wallet activation requirements are assessed separately under Section 5.4 controls. (3) The CSP's issuance protocol to confirm it requires and validates proof of possession of the wallet's signing key before creating the attribute bundle. (4) The CSP's bundle creation process to confirm the resulting attribute bundle includes subscriber attributes and the wallet's verification key or a reference to it. Attribute bundle content requirements are assessed under the ABUN series (Section 3.12.1). (5) The CSP's delivery mechanism to confirm the bundle is transmitted to the requesting wallet." - id: IABSCW-1_gdn name: guidance prose: |- This is a process-level control covering the end-to-end issuance process from the CSP's perspective. SP 800-63C-4 uses the terms "signing key" and "verification key" throughout Section 5 rather than the "private key" and "public key" terminology used in other NIST cryptographic standards. The signing key is the wallet's private key used to sign assertions; the verification key is the corresponding public key. The CSP cannot observe wallet activation at runtime but can control which wallet platforms it issues to. Before issuing attribute bundles to a given wallet platform, the CSP should verify that the platform enforces activation requirements. This may involve reviewing wallet platform documentation, security certifications, or independent security evaluations. - id: IABSCW-2 title: Attribute Bundle Uniqueness props: - value: 5.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IABSCW-2_smt name: statement prose: The CSP SHALL create a unique attribute bundle for each requesting wallet. - id: IABSCW-2_obj links: - rel: assessment-for href: "#IABSCW-2_smt" name: objective prose: Determine whether the CSP creates a unique attribute bundle for each requesting wallet. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: IABSCW-2_asm-examine name: assessment-method prose: "Examine the CSP's attribute bundle issuance process to verify that each bundle is uniquely bound to the requesting wallet (e.g., by including the wallet's verification key per IABSCW-1 #4)." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: IABSCW-2_asm-test name: assessment-method prose: Test by requesting attribute bundles from the CSP using two different wallets for the same subscriber. Compare the bundles and verify they are distinct. - id: IABSCW-3 title: Multi-CSP Attribute Bundle Assertion Conformance props: - value: 5.1 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: IABSCW-3_smt name: statement prose: "The simultaneous presentation of attribute bundles from multiple CSPs in a single assertion is possible with some technologies. When this occurs, the assertion of multiple attribute bundles SHALL conform to the assertion requirements in this guideline." - id: IABSCW-3_obj links: - rel: assessment-for href: "#IABSCW-3_smt" name: objective prose: Determine whether assertions containing attribute bundles from multiple CSPs conform to assertion requirements. - props: - value: EXAMINE name: method class: assessment-summary id: IABSCW-3_asm-summary title: Assessment Method name: assessment-method prose: "When an assertion contains attribute bundles from multiple CSPs, satisfied by the IdP-directed requirements in ARTCN-1 to ARTCN-6 and ARTCN-12 (Sec. 5.8)." - id: IABSCW-3_gdn name: guidance prose: |- Assessment is required when: The wallet presents attribute bundles from multiple CSPs in a single assertion. If a wallet allows combining attribute bundles from different CSPs into a single assertion (e.g., a driver's license from one CSP and professional credentials from another), each bundle must be individually validated per the assertion requirements, regardless of how many are combined. - id: INVABSCW-1 title: Attribute Bundle Invalidation Capability props: - value: 5.1.1 A class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: INVABSCW-1_smt name: statement prose: The CSP SHALL provide a means of invalidating attribute bundles that are issued to a subscriber-controlled wallet. - id: INVABSCW-1_obj links: - rel: assessment-for href: "#INVABSCW-1_smt" name: objective prose: Determine whether the CSP provides a means of invalidating attribute bundles issued to subscriber-controlled wallets. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: INVABSCW-1_asm-examine name: assessment-method prose: "Examine CSP documentation for a defined invalidation process covering at minimum the three scenarios identified in Sec. 5.1.1: subscriber account termination, wallet termination due to loss/theft/compromise, and attribute bundle compromise or disclosure to an attacker." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: INVABSCW-1_asm-test name: assessment-method prose: "Test by issuing an attribute bundle to a test wallet. Next, invoke the CSP's invalidation process for that bundle. Verify that the CSP's systems reflect the bundle as invalidated (e.g., marked as invalid in the CSP's status registry or list, removed from active bundle records, or otherwise flagged as invalid)." - id: INVABSCW-1_gdn name: guidance prose: |- Attribute bundle invalidation is used when: -The subscriber account is terminated, thereby rendering downstream federation actions invalid; -The wallet needs to be terminated due to the device being lost, stolen, or compromised; or -The attribute bundle is disclosed to an attacker or otherwise compromised. - id: INVABSCW-2 title: Attribute Bundle Status Verification Privacy props: - value: 5.1.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: INVABSCW-2_smt name: statement prose: "The CSP SHOULD provide a means to independently verify the status of attribute bundles (i.e., whether a specific bundle has been revoked by the CSP). If such a service is offered, the service SHALL be deployed in a privacy-preserving way such that the CSP is not alerted to the use of a specific attribute bundle at a specific RP." - id: INVABSCW-2_obj links: - rel: assessment-for href: "#INVABSCW-2_smt" name: objective prose: Determine whether the CSP's attribute bundle status verification service is deployed in a privacy-preserving manner that does not alert the CSP to the use of a specific attribute bundle at a specific RP. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: INVABSCW-2_asm-examine name: assessment-method prose: "Examine the architecture and design documentation for the status verification service. Verify that the service design does not enable the CSP to correlate a specific attribute bundle with a specific RP. Identify the privacy-preserving mechanism in use (e.g., status lists, batch download of revocation data)." - id: INVABSCW-2_gdn name: guidance prose: |- Assessment is required when: The CSP offers an attribute bundle status verification service. Status verification mechanisms where the RP queries the CSP directly with a specific bundle identifier (e.g., standard OCSP) would fail this requirement because the CSP can correlate the querying RP's network identity with the specific bundle being checked, revealing which RP the subscriber visited. Privacy-preserving alternatives include mechanisms where the RP downloads a complete status dataset and checks bundle status locally, preventing the CSP from learning which specific bundle was checked. One example is the W3C Bitstring Status List. - id: TAGREE-1 title: Wallet Runtime Attribute Release props: - value: "5.3 #1" class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TAGREE-1_smt name: statement prose: "1. The release of subscriber attributes SHALL be managed using a runtime decision managed by the wallet, as described in Sec. 4.6.1.3." - id: TAGREE-1_obj links: - rel: assessment-for href: "#TAGREE-1_smt" name: objective prose: Determine whether the wallet manages attribute release using runtime decisions as described in Sec. 4.6.1.3. - props: - value: EXAMINE name: method class: assessment-summary id: TAGREE-1_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by IDPRD-1 through IDPRD-8, treating the wallet as the IdP. These controls apply unconditionally in the wallet context, regardless of whether the RP is on an allowlist." - id: TAGREE-1_gdn name: guidance prose: |- Due to the architectures and design of subscriber-controlled wallets, the trust agreements that support federated transactions are less direct than with general-purpose IdPs. To maintain privacy outcomes and prevent the tracking of user transactions, CSPs and RPs do not typically have direct communication with each other. Unlike the general IdP case (Sec. 4.6.1.3), where allowlisting an RP can bypass the runtime decision, wallet attribute release always requires a runtime decision regardless of whether an allowlist is used. An allowlist in the wallet context may constrain which RPs can request attributes, but the subscriber still approves release at transaction time. TAGREE-2 establishes that the authorized party for this decision is the subscriber. - id: TAGREE-2 title: Wallet Authorized Party props: - value: "5.3 #2" class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TAGREE-2_smt name: statement prose: 2. The authorized party SHALL be the subscriber. - id: TAGREE-2_obj links: - rel: assessment-for href: "#TAGREE-2_smt" name: objective prose: Determine whether the wallet designates the subscriber as the authorized party for attribute release decisions. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAGREE-2_asm-examine name: assessment-method prose: Examine the wallet documentation to verify that the subscriber is the party making the attribute release decisions. - id: TAGREE-2_gdn name: guidance prose: "In the general IdP case, the trust agreement identifies the authorized party, which may be the subscriber, an administrator, or another surrogate. For subscriber-controlled wallets, the authorized party is always the subscriber." - id: TAGREE-3 title: Wallet Runtime Decision Disclosure Terms props: - value: "5.3 #3" class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: TAGREE-3_smt name: statement prose: |- 3. The following terms SHALL be disclosed to the subscriber during the runtime decision: (a) The set of subscriber attributes, derived attributes, and attribute bundles that the RP will request (a subset of the attributes made available). (b) The purpose of each attribute requested by the RP. - id: TAGREE-3_obj links: - rel: assessment-for href: "#TAGREE-3_smt" name: objective prose: Determine whether the wallet discloses the required terms to the subscriber during the runtime decision. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: TAGREE-3_asm-examine name: assessment-method prose: Examine the runtime decision screen(s) to verify that it is designed to display the required disclosure terms. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: TAGREE-3_asm-test name: assessment-method prose: "Test by initiating a transaction that triggers a runtime decision. Verify that the following information is disclosed to the subscriber: (1) the attributes the RP will request (see also IDPRD-3), and (2) the purpose of the requested attributes" - id: TAGREE-3_gdn name: guidance prose: "All information disclosed to the subscriber needs to be conveyed in a manner that is understandable and actionable, as discussed in Sec. 8." - id: CR-1 title: Federation Authority Wallet Ecosystem Trust Agreement Contents props: - value: 5.3.1 A class: index name: label - value: Federation Authority class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CR-1_smt name: statement prose: |- Such trust agreements SHALL contain: (a) The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles. (b) The set of subscriber attributes and derived attributes that the wallet can make available to the RP. (c) The population of subscriber accounts that the CSP can represent. (d) The IALs or issuance processes of subscriber accounts that are associated with the attribute bundles from the CSP. (e) The issuance process related to CSP attribute bundles. (f) The FALs supported by subscriber-controlled wallets. (g) The allowable purposes for each attribute RPs may request. (h) Expectations of RPs for the protection and management of subscriber data provided through attribute bundles. - id: CR-1_obj links: - rel: assessment-for href: "#CR-1_smt" name: objective prose: Determine whether the federation authority's trust agreement artifacts for a subscriber-controlled wallet ecosystem contains the required terms. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CR-1_asm-examine name: assessment-method prose: Examine the federation authority trust agreement artifact(s) to verify all required terms are present. - id: CR-1_gdn name: guidance prose: |- Assessment is required when: The trust relationship between the RP and CSP is facilitated by a federation authority. In subscriber-controlled wallet ecosystems, the CSP and RP typically do not communicate directly. A federation authority can bridge this gap by defining ecosystem-wide trust agreement artifact(s) that govern the relationships among RPs, CSPs, and wallets. - id: CR-2 title: CSP Publication of Wallet Ecosystem Information props: - value: 5.3.1 B class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CR-2_smt name: statement prose: |- CSPs SHALL publish the following information to a trusted location for RPs to evaluate: (a) The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles. (b) The set of subscriber attributes and derived attributes that the wallet can make available to the RP. (c) The population of subscriber accounts that the CSP can represent. (d) The IALs or issuance processes of subscriber accounts associated with the attribute bundles from the CSP. - id: CR-2_obj links: - rel: assessment-for href: "#CR-2_smt" name: objective prose: Determine whether the CSP publishes the required information to a location accessible to RPs for evaluation. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CR-2_asm-examine name: assessment-method prose: Examine the CSP-published information at the identified location to verify all required information is present. The assessor should verify the location is accessible to RPs and that the information is current. - id: CR-2_gdn name: guidance prose: |- Assessment is required when: Trust is established unilaterally by RP evaluation of publicly available CSP information (i.e., no federation authority facilitates the trust relationship). The CSP defines the boundaries of attribute disclosure through its trust agreement artifact(s) with the wallet (see Sec. 5.3.2). The bundle may contain more attributes than any single RP is authorized to receive; selective disclosure technology allows the wallet to reveal different subsets to different RPs without reissuance. "The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles" reflects the full set issued by the CSP, while "The set of subscriber attributes and derived attributes that the wallet can make available to the RP" reflects the subset the wallet is authorized to disclose. This information may also be published through a federation authority's discovery service (see Sec. 5.3.1). - id: CSCW-1 title: CSP-Wallet Trust Agreement props: - value: 5.3.2 A class: index name: label - value: CSP/IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CSCW-1_smt name: statement prose: There SHALL be a trust agreement between the CSP and the subscriber-controlled wallets into which they issue attribute bundles. - id: CSCW-1_obj links: - rel: assessment-for href: "#CSCW-1_smt" name: objective prose: Determine whether a trust agreement exists between the CSP and the subscriber-controlled wallets to which it issues attribute bundles. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CSCW-1_asm-examine name: assessment-method prose: |- For CSPs: Examine documentation to identify trust agreement artifact(s) governing the relationship with subscriber-controlled wallets. Verify the agreement exists prior to issuance of attribute bundles. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CSCW-1_asm-examine-2 name: assessment-method prose: |- For wallets (IdPs): Examine documentation to identify trust agreement artifact(s) governing the relationship with the CSP(s) from which it receives attribute bundles. - id: CSCW-1_gdn name: guidance prose: CSCW-2 specifies the minimum required contents of this trust agreement. - id: CSCW-2 title: CSP-Wallet Trust Agreement Requirements props: - value: 5.3.2 B class: index name: label - value: CSP/IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: CSCW-2_smt name: statement prose: |- At a minimum, this trust agreement SHALL include the following: (1) The set of subscriber attributes and derived attributes that the CSP makes available to wallets in attribute bundles. (2) The set of subscriber attributes and derived attributes that the wallet can make available to the RP. (3) Any processes the subscriber-controlled wallet needs to implement to support the issuance of attribute bundles (e.g., PAD, data collection, risk scoring). (4) Data storage and security practices for the wallet service. (5) The activation factors or AALs that subscribers use to access the wallet service prior to the generation of any assertion. (6) The FALs supported by subscriber-controlled wallets. (7) The allowable purposes or any restrictions that the wallets need to enforce related to the release of attributes to RP. - id: CSCW-2_obj links: - rel: assessment-for href: "#CSCW-2_smt" name: objective prose: Determine whether the trust agreement between the CSP and subscriber-controlled wallets contains the minimum required terms. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CSCW-2_asm-examine name: assessment-method prose: |- For CSPs: Examine CSP-published information to verify that terms (1), (3), and (7) are present. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: CSCW-2_asm-examine-2 name: assessment-method prose: |- For wallets (IdPs): Examine wallet-published information to verify terms (2), (4), (5), and (6) are present. - id: CSCW-2_gdn name: guidance prose: The trust agreement may be composed of information published independently by each party. The CSP publishes what it issues and the constraints it imposes on wallets. The wallet publishes its own capabilities and security practices. Together these constitute the trust agreement. - id: RSCW-1 title: Wallet Disclosure to RPs props: - value: 5.3.3 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RSCW-1_smt name: statement prose: |- Subscriber-controlled wallets SHALL disclose to RPs: (1) Activation or authentication methods they use to authenticate subscribers prior to presentation of an assertion. (2) Security features of how the wallet protects the attribute bundles. (3) Key management information. (4) Indications of the integrity of the subscriber-controlled wallet's software. - id: RSCW-1_obj links: - rel: assessment-for href: "#RSCW-1_smt" name: objective prose: Determine whether the wallet discloses all required information to RPs. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RSCW-1_asm-examine name: assessment-method prose: "Examine wallet-published documentation, metadata, or runtime disclosures to verify all four required items are disclosed to RPs. Items (1) and (2) may already be documented under CSCW-2 terms (5) and (4) respectively. Verify that the same information is made available to RPs, not only to the CSP. Items (3) and (4) are unique to this control." - id: RSCW-1_gdn name: guidance prose: |- The RP needs this information to make trust decisions about the wallet presenting attribute bundles. Software integrity indications can be provided through platform-specific attestation mechanisms. - id: FAL3SCW-1 title: "FAL3 Hosted Wallet: HoK or Bound Authenticator" props: - value: 5.3.4 A class: index name: label - value: IdP/RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: FAL3SCW-1_smt name: statement prose: "To reach FAL3, federation transactions with a subscriber-controlled wallet on a hosted service SHALL use either a holder-of-key assertion (see Sec. 3.15) or a bound authenticator (see Sec. 3.16)." - id: FAL3SCW-1_obj links: - rel: assessment-for href: "#FAL3SCW-1_smt" name: objective prose: Determine whether federation transactions with a hosted subscriber-controlled wallet at FAL3 use either a holder-of-key assertion or a bound authenticator. - props: - value: EXAMINE name: method class: assessment-summary id: FAL3SCW-1_asm-summary title: Assessment Method name: assessment-method prose: |- For holder-of-key assertions, satisfied by HKA-1 through HKA-5. For assertions that use bound authenticators, satisfied by BAUTH-1 through BAUTH-8. - id: FAL3SCW-1_gdn name: guidance prose: |- Assessment is required when: A subscriber-controlled wallet on a hosted service is used at FAL3. Device-based subscriber-controlled wallets inherently hold signing keys that can satisfy HoK requirements. Hosted wallets do not, because the subscriber does not directly control the key material. This control requires hosted wallets to bridge that gap through either an additional HoK authenticator separate from the wallet's signing key, or a bound authenticator at the RP. FAL3SCW-2 requires all other FAL3 requirements (Sec. 2.4) to also be met. - id: FAL3SCW-2 title: Wallet FAL3 Compliance props: - value: 5.3.4 B class: index name: label - value: CSP/IdP/RP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: FAL3SCW-2_smt name: statement prose: All requirements for FAL3 in Sec. 2.4 SHALL be met. - id: FAL3SCW-2_obj links: - rel: assessment-for href: "#FAL3SCW-2_smt" name: objective prose: Determine whether federation transactions involving a subscriber-controlled wallet meet all FAL3 requirements specified in Sec. 2.4. - props: - value: EXAMINE name: method class: assessment-summary id: FAL3SCW-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by FAL3-1 through FAL3-5. - id: WACT-1 title: Wallet Activation for Signing Operations props: - value: 5.4 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WACT-1_smt name: statement prose: "The subscriber-controlled wallet SHALL require the presentation of an activation factor from the subscriber for the following actions that result in the creation of a signed artifact from the wallet's signing keys: providing proof of possession of the wallet's signing key to the CSP during the issuance process; and signing the assertion for presentation to the RP." - id: WACT-1_obj links: - rel: assessment-for href: "#WACT-1_smt" name: objective prose: Determine whether the subscriber-controlled wallet requires presentation of an activation factor from the subscriber before performing signing operations with the wallet's signing keys. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: WACT-1_asm-examine name: assessment-method prose: Examine the wallet platform's security architecture documentation to confirm that signing-key operations are gated behind the presentation of an activation factor. Confirm that the architecture does not allow access to the signing key without activation. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WACT-1_asm-test name: assessment-method prose: "Test by doing the following: (1) During an attribute bundle issuance flow with a CSP, observe that the wallet prompts the subscriber for an activation factor before completing proof-of-possession of the signing key. (2) During a federation transaction with an RP, observe that the wallet prompts the subscriber for an activation factor before signing the assertion for presentation. (3) For each operation above, dismiss or cancel the activation prompt and confirm that the signing operation does not proceed." - id: WACT-1_gdn name: guidance prose: "The activation factor ensures the subscriber is present and consenting before any signing operation occurs. If the activation factor is a secret (e.g., PIN or password), it must meet the activation secret requirements in SP 800-63B Sec. 3.2.10. If the activation factor is biometric, it must meet the requirements in SP 800-63B Sec. 3.2.3. WACT-2 addresses the requirement that wallet activation be separate from device unlock for device-based wallets." - id: WACT-2 title: Wallet Activation Separation from Device Unlock props: - value: 5.4 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WACT-2_smt name: statement prose: "For subscriber-controlled wallets that run on a device that the subscriber controls, the submission of the activation factor SHALL be a separate operation from the unlocking of the host device (e.g., smartphone), although the same activation factor used to unlock the host device MAY be used in the activation operation. Organizations MAY relax this requirement for subscriber-controlled wallets managed by or on behalf of the CSP (e.g., via mobile device management) and that are constrained to have short, organization-determined inactivity timeouts and device activation factors that meet the above requirements." - id: WACT-2_obj links: - rel: assessment-for href: "#WACT-2_smt" name: objective prose: "Determine whether the subscriber-controlled wallet requires a separate activation operation from host device unlock, or whether the organization qualifies for the MDM relaxation." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: WACT-2_asm-examine name: assessment-method prose: Examine the wallet's security architecture documentation to confirm that wallet activation is implemented as an operation distinct from host device unlock. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: WACT-2_asm-examine-2 name: assessment-method prose: |- Examine documentation to verify that: (1) The wallet is managed by or on behalf of the CSP (e.g., via MDM); (2) The device is constrained to short, organization-determined inactivity timeouts; and (3) The device activation factors meet the requirements in Sec. 3.2.10 of SP 800-63B-4, if the organization claims the MDM relaxation. If all three conditions are met, device-level controls satisfy the separation requirement. If any condition is not met, the relaxation does not apply, and the base requirement must be assessed. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WACT-2_asm-test name: assessment-method prose: "Test by unlocking the host device (e.g., smartphone) using the device unlock mechanism if the MDM relaxation is not claimed or applicable." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WACT-2_asm-test-2 name: assessment-method prose: Test by Immediately initiate a wallet signing operation (issuance or assertion presentation per WACT-1) if the MDM relaxation is not claimed or applicable. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: WACT-2_asm-test-3 name: assessment-method prose: Test by confirming the wallet requires a separate activation prompt before proceeding - device unlock alone does not satisfy the wallet activation requirement if the MDM relaxation is not claimed or applicable. - id: WACT-2_gdn name: guidance prose: |- Assessment is required when: The subscriber-controlled wallet runs on a device controlled by the subscriber (i.e., not a hosted wallet). The requirement permits the same activation factor (e.g., the same fingerprint or PIN) to be used for both device unlock and wallet activation, provided the wallet requires its own distinct activation event. Activation factor requirements for authenticators are discussed in Sec. 3.2.10 of SP 800-63B-4. The MDM relaxation applies to enterprise or government scenarios where the CSP controls both the identity credential and the device environment. In such cases, device management policies can enforce equivalent security properties at the device level, making a separate wallet activation event redundant. This relaxation does not apply to consumer scenarios where the CSP has no management authority over the subscriber's device. - id: KS-1 title: Wallet Signing Key Sync and Sharing Prohibition props: - value: 5.4.1 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: KS-1_smt name: statement prose: Keys used for signing assertions SHALL NOT be synced or shared across devices. - id: KS-1_obj links: - rel: assessment-for href: "#KS-1_smt" name: objective prose: Determine whether wallet signing keys used for assertions are prohibited from being synced or shared across devices. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: KS-1_asm-examine name: assessment-method prose: "Examine the wallet's key management architecture, configuration, and subscriber-facing key management features to confirm that signing keys are generated and stored per-device and that no mechanism exists to sync, replicate, or share signing keys across devices (e.g., cloud key sync, cross-device backup, or key export functionality)." - id: KS-1_gdn name: guidance prose: CKS-1 covers general secure key storage requirements under FIPS 140; this control adds the wallet-specific prohibition on key syncing across devices. Non-exportable key storage becomes a SHALL for wallets whose signing key is used as a holder-of-key authenticator at FAL3 (see KS-2). The definition of non-exportable key storage is established in CKS-2. - id: KS-2 title: Wallet HoK Signing Key Non-Exportable Storage props: - value: 5.4.1 B class: index name: label - value: IdP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: KS-2_smt name: statement prose: "If the wallet's signing key is used as a holder-of-key authenticator for FAL3, the key SHALL be stored in non-exportable key storage, as discussed in Sec. 3.6.2." - id: KS-2_obj links: - rel: assessment-for href: "#KS-2_smt" name: objective prose: "Determine whether the wallet's signing key, when used as a holder-of-key authenticator for FAL3, is stored in non-exportable key storage." - props: - value: EXAMINE name: method class: assessment-summary id: KS-2_asm-summary title: Assessment Method name: assessment-method prose: |- This is a summative control. Compliance is demonstrated when the requirements of the following controls have been met: (a) CKS-2: Non-Exportable Key Storage Definition (b) CKS-3: Non-Exportable Key Isolation (c) CKS-4: Non-Exportable Storage Immutability - id: KS-2_gdn name: guidance prose: |- Assessment is required when: The wallet's signing key is used as a holder-of-key authenticator for FAL3. KS-1 prohibits key syncing across devices for all wallet signing keys. This control elevates the storage requirement to non-exportable for the specific case of HoK at FAL3. - id: DISCR-1 title: CSP Verification Key Determination props: - value: 5.5 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: DISCR-1_smt name: statement prose: "To perform a federation transaction with a subscriber-controlled wallet, the RP SHALL first determine the attribute bundle verification key of the CSP through a secure process as stated by the trust agreement." - id: DISCR-1_obj links: - rel: assessment-for href: "#DISCR-1_smt" name: objective prose: Determine whether the RP obtains the CSP's attribute bundle verification key through a secure process defined in the trust agreement artifact(s) prior to performing federation transactions with a subscriber-controlled wallet. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: DISCR-1_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to identify the process specified for the RP to obtain the CSP's attribute bundle verification key (e.g., retrieval from a URL controlled by the CSP, manual configuration, or retrieval through a federation authority). Review the RP's configuration to confirm that the CSP's verification key was obtained through the specified process. Confirm that the process used to obtain the key provides authentication of the source (e.g., authenticated protected channel, manual out-of-band verification, or federation authority trust chain)." - id: DISCR-1_gdn name: guidance prose: "This control is the wallet-specific counterpart to DR-1, which covers the RP's association of assertion validation keys with the IdP's identifier. In the wallet model, the trust anchor is the CSP's signature on the attribute bundle rather than the IdP's assertion signature. Sec. 5.5 describes several mechanisms: retrieval from a URL known to be controlled by the CSP, manual configuration before deployment, or facilitation by a third-party discovery and registration service (such as a federation authority) in multi-lateral trust agreement artifact(s). ARTVL-1 covers the RP's validation of the attribute bundle signature and depends on this control being satisfied. For network-based key retrieval, DR-2 requirements for authenticated protected channels also apply." - id: WAAD-1 title: Wallet Subscriber Transaction Authorization props: - value: 5.6 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WAAD-1_smt name: statement prose: "The decision of whether a federation transaction proceeds and, therefore, an assertion is issued and attributes are released to the RP SHALL be determined by the subscriber acting in the role of the authorized party." - id: WAAD-1_obj links: - rel: assessment-for href: "#WAAD-1_smt" name: objective prose: "Determine whether the subscriber-controlled wallet ensures that the subscriber, acting as the authorized party, controls the decision of whether a federation transaction proceeds and attributes are released to the RP." - props: - value: EXAMINE name: method class: assessment-summary id: WAAD-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by TAGREE-1 and TAGREE-2. - id: WAAD-2 title: Wallet Remembered Decision Disclosure props: - value: 5.6 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WAAD-2_smt name: statement prose: "If [the subscriber-controlled wallet provides a mechanism to remember a disclosure decision by the authorized party (i.e., the subscriber) to apply to future requests from the same RP], the subscriber-controlled wallet SHALL disclose to the authorized party that the storage mechanism is in use." - id: WAAD-2_obj links: - rel: assessment-for href: "#WAAD-2_smt" name: objective prose: Determine whether the subscriber-controlled wallet discloses to the subscriber that a mechanism to remember their authorization decision is in use. - props: - value: EXAMINE name: method class: assessment-summary id: WAAD-2_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by IDPRD-7, applied to the wallet as the party implementing the runtime decision." - id: WAAD-2_gdn name: guidance prose: "Assessment is required when: The subscriber-controlled wallet provides a mechanism to remember a subscriber's disclosure decision for future requests from the same RP." - id: WAAD-3 title: Wallet Remembered Decision Revocation props: - value: 5.6 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WAAD-3_smt name: statement prose: "If [the subscriber-controlled wallet provides a mechanism to remember a disclosure decision by the authorized party (i.e., the subscriber) to apply to future requests from the same RP], the subscriber-controlled wallet... SHALL allow the authorized party to revoke such remembered access at a future time." - id: WAAD-3_obj links: - rel: assessment-for href: "#WAAD-3_smt" name: objective prose: Determine whether the subscriber-controlled wallet allows the subscriber to revoke a previously remembered authorization decision. - props: - value: EXAMINE name: method class: assessment-summary id: WAAD-3_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by IDPRD-8, applied to the wallet as the party implementing the runtime decision." - id: WAAD-3_gdn name: guidance prose: "Assessment is required when: The subscriber-controlled wallet provides a mechanism to remember a subscriber's disclosure decision for future requests from the same RP." - id: WAAD-4 title: CSP Wallet Subscriber Redress props: - value: 5.6 D class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: WAAD-4_smt name: statement prose: "The CSP SHALL provide secure and effective means of redress of subscriber complaints or problems (e.g., subscriber identifies an inaccurate attribute value, the need to invalidate attribute bundles that were previously issued to a subscriber-controlled wallet)." - id: WAAD-4_obj links: - rel: assessment-for href: "#WAAD-4_smt" name: objective prose: Determine whether the CSP provides secure and effective means of redress for subscriber complaints or problems related to attribute bundles issued to a subscriber-controlled wallet. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: WAAD-4_asm-examine name: assessment-method prose: |- The base CSP redress mechanism is satisfied by RR-6. Examine the CSP's redress documentation and procedures for coverage of wallet-specific scenarios, including correction of inaccurate attribute values in issued bundles and invalidation of previously issued attribute bundles (e.g., due to compromise, account termination, or subscriber request). Verify that these redress mechanisms protect the integrity of the redress process (e.g., authenticating the subscriber before modifying or invalidating bundles) and produce effective outcomes for the subscriber. - id: AREQ-1 title: Wallet Assertion Request Contents props: - value: 5.7 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: AREQ-1_smt name: statement prose: |- When federation transactions are initiated by the RP, the RP's request for an assertion SHALL contain: (1) An identifier for the RP (2) A cryptographic nonce (3) The set of identity attributes, derived attributes, and attribute bundles requested by the RP and their purpose of use at the RP. - id: AREQ-1_obj links: - rel: assessment-for href: "#AREQ-1_smt" name: objective prose: Determine whether the RP's requests for assertions from subscriber-controlled wallets contain all required elements. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: AREQ-1_asm-examine name: assessment-method prose: "Examine the RP's wallet federation configuration to confirm it includes its identifier, a cryptographic nonce, and the set of requested attributes, with the purpose of use, in all assertion requests to subscriber-controlled wallets." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: AREQ-1_asm-test name: assessment-method prose: "Test by initiating a federation transaction between an RP and a subscriber-controlled wallet and capturing the RP's assertion request. Verify that it contains: (1) a unique identifier for the RP; (2) b. a cryptographic nonce; (3)the set of identity attributes, derived attributes, and attribute bundles requested by the RP and their purpose of use at the RP." - id: ARTCN-1 title: Wallet Assertion Contents props: - value: 5.8 A class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-1_smt name: statement prose: |- Assertions from a subscriber-controlled wallet SHALL contain: (1) A signed attribute bundle from the CSP. (2) Audience identifier: An identifier for the party that is intended to consume the assertion (i.e., the RP). (3) Issuance time: A timestamp that indicates when the wallet issued the assertion. (4) Validity time window: A period of time outside of which the assertion SHALL NOT be accepted as valid by the RP for the purposes of authenticating the subscriber and starting an authenticated session at the RP. This is usually communicated by means of an expiration timestamp for the assertion in addition to the issuance timestamp. (5) Assertion identifier: A value that uniquely identifies this assertion and is used to prevent attackers from replaying prior assertions. For example, this can be a unique nonce generated by the wallet and included in the assertion. (6) Signature: A digital signature that uses asymmetric cryptography and covers the entire assertion. - id: ARTCN-1_obj links: - rel: assessment-for href: "#ARTCN-1_smt" name: objective prose: Determine whether assertions from a subscriber-controlled wallet contain all required elements. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-1_asm-test name: assessment-method prose: Test by initiating a federation transaction and capture the wallet's assertion. Verify the assertion contains all required elements. - id: ARTCN-1_gdn name: guidance prose: RP enforcement of the validity time window is assessed under ARTVL-3 item 3. - id: ARTCN-2 title: Wallet Assertion xAL and Activation Information props: - value: 5.8 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-2_smt name: statement prose: |- The following aspects of the federation transaction SHALL be provided through information contained in the assertion contents or the applicable trust agreement: (1) The IAL of the subscriber account being represented in the assertion, an indication of the issuance processes, or an indication that no IAL is asserted. (2) The nature of the activation method used to activate the wallet. (3) The wallet's intended FAL of the federation process that is represented by the assertion. - id: ARTCN-2_obj links: - rel: assessment-for href: "#ARTCN-2_smt" name: objective prose: "Determine whether the required IAL, activation method, and FAL information is conveyed through the wallet assertion contents or the applicable trust agreement artifact(s)." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTCN-2_asm-examine name: assessment-method prose: Examine sample assertions and/or trust agreement artifact(s) to confirm they convey all required information. - id: ARTCN-3 title: Hosted Wallet AAL Reporting props: - value: 5.8 C class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-3_smt name: statement prose: "If a subscriber-controlled wallet is hosted as a remote service, the AAL of the subscriber's current session at the hosted wallet service SHALL be provided through information contained in the assertion contents or the applicable trust agreement." - id: ARTCN-3_obj links: - rel: assessment-for href: "#ARTCN-3_smt" name: objective prose: Determine whether the AAL of the subscriber's current session at the hosted wallet service is conveyed through the assertion contents or the applicable trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTCN-3_asm-examine name: assessment-method prose: Examine sample assertions and/or trust agreement artifact(s) to confirm the AAL of the subscriber's session at the hosted wallet service is conveyed. - id: ARTCN-3_gdn name: guidance prose: "Assessment is required when: The subscriber-controlled wallet is hosted as a remote service." - id: ARTCN-4 title: Wallet Assertion Nonce Inclusion props: - value: 5.8 D class: index name: label - value: IdP class: target name: marking - value: FAL2/FAL3 class: xal-level name: marking parts: - id: ARTCN-4_smt name: statement prose: |- At FAL2 and above, the assertion SHALL include: 1. Nonce: A cryptographic nonce from the RP's federation request. - id: ARTCN-4_obj links: - rel: assessment-for href: "#ARTCN-4_smt" name: objective prose: Determine whether the wallet's assertion includes the cryptographic nonce from the RP's federation request at FAL2 and above. - props: - value: EXAMINE name: method class: assessment-summary id: ARTCN-4_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ARTC-7. - id: ARTCN-4_gdn name: guidance prose: |- In the errata publication, this control will be changed to: At FAL2 and above, the assertion SHALL include the cryptographic nonce from the RP's federation request. - id: ARTCN-5 title: Wallet FAL3 Assertion Mechanism Indicator props: - value: 5.8 E class: index name: label - value: IdP class: target name: marking - value: FAL3 class: xal-level name: marking parts: - id: ARTCN-5_smt name: statement prose: "At FAL3, the assertion SHALL include one of the following: the public key, key identifier, or other identifier for a holder-of-key assertion. This MAY be the same key that the subscriber-controlled wallet uses to sign the assertion; or, an indicator that the verification of a bound authenticator is required to process this assertion." - id: ARTCN-5_obj links: - rel: assessment-for href: "#ARTCN-5_smt" name: objective prose: Determine whether the wallet's assertion at FAL3 includes either a holder-of-key identifier or a bound authenticator indicator. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-5_asm-test name: assessment-method prose: |- Test by initiating a federation transaction at FAL3 with a subscriber-controlled wallet. Capture the assertion and verify it contains either: (a) a public key, key identifier, or other identifier for a holder-of-key assertion, or (b) an indicator that verification of a bound authenticator is required. - id: ARTCN-5_gdn name: guidance prose: "ARTC-8 establishes the equivalent requirement for traditional federation (Sec. 4.9 H). In the wallet model, the wallet's own signing key may also serve as the holder-of-key authenticator, since the attribute bundle from the CSP already binds that key to the subscriber." - id: ARTCN-6 title: Wallet Assertion Authentication Secret Prohibition props: - value: 5.8 F class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-6_smt name: statement prose: "Assertions SHALL NOT contain subscriber authentication secrets (e.g., passwords)." - id: ARTCN-6_obj links: - rel: assessment-for href: "#ARTCN-6_smt" name: objective prose: Determine whether wallet assertions are free of subscriber authentication secrets. - props: - value: EXAMINE name: method class: assessment-summary id: ARTCN-6_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ARTC-9. - id: ARTCN-7 title: Attribute Bundle Contents props: - value: 5.8 G class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-7_smt name: statement prose: |- The signed attribute bundle from the CSP SHALL contain: (1) Keys: A verification key or key identifier for the key used by the subscriber controlled wallet to sign assertions. (2) Issuer identifier: An identifier for the issuer of the attribute bundle (i.e., the CSP). (3) Issuance time: A timestamp that indicates when the CSP issued the attribute bundle. (4) IAL: Indicator of the IAL of the subscriber account being represented in the attribute bundle or an indication that no IAL is asserted. (5) Signature: A digital signature that uses asymmetric cryptography and covers the entire attribute bundle. (6) Attribute values and derived attribute values: Information about the subscriber. - id: ARTCN-7_obj links: - rel: assessment-for href: "#ARTCN-7_smt" name: objective prose: Determine whether signed attribute bundles from the CSP contain all required elements. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-7_asm-test name: assessment-method prose: Test by obtaining a signed attribute bundle issued by the CSP to a subscriber-controlled wallet. Verify the bundle contains all required elements. - id: ARTCN-8 title: Wallet Assertion Subscriber Identification props: - value: 5.8 H class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-8_smt name: statement prose: "If the RP subscriber account does not use an ephemeral provisioning process (see Sec. 4.6.5) or an account resolution process (see Sec. 3.8.2), the subscriber SHALL be identified in the assertion using a federated identifier (see Sec. 3.4)." - id: ARTCN-8_obj links: - rel: assessment-for href: "#ARTCN-8_smt" name: objective prose: Determine whether the subscriber is identified in the wallet assertion using a federated identifier when neither ephemeral provisioning nor account resolution is used. - props: - value: EXAMINE name: method class: assessment-summary id: ARTCN-8_asm-summary title: Assessment Method name: assessment-method prose: This is a functional requirement describing when a federated identifier is used. Assessment of federated identifier handling is covered under the RP subscriber account controls in Sec. 3.8. - id: ARTCN-8_gdn name: guidance prose: "Assessment is required when: The RP subscriber account does not use an ephemeral provisioning process or an account resolution process." - id: ARTCN-9 title: Wallet Federated Identifier Issuer props: - value: 5.8 I class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-9_smt name: statement prose: The issuer identifier SHALL be of the CSP that issued the signed attribute bundle. - id: ARTCN-9_obj links: - rel: assessment-for href: "#ARTCN-9_smt" name: objective prose: Determine whether the RP uses the CSP's issuer identifier as the issuer component of the federated identifier. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-9_asm-test name: assessment-method prose: Test by presenting a wallet assertion where the wallet's issuer identifier in the outer assertion differs from the CSP's issuer identifier in the signed attribute bundle. Confirm that the RP constructs the federated identifier using the CSP's issuer identifier. - id: ARTCN-9_gdn name: guidance prose: |- Assessment is required when: The subscriber is identified in the assertion using a federated identifier. When wallets act as an IdP, the assertion has two issuers: the wallet (outer assertion) and the CSP (signed attribute bundle). The federated identifier must use the CSP as the issuer component because the CSP is the authority over the subscriber account and the subject identifier. - id: ARTCN-10 title: Wallet Subject Identifier in Signed Attribute Bundle props: - value: 5.8 J class: index name: label - value: CSP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-10_smt name: statement prose: The subject identifier SHALL be contained in the signed attribute bundle. - id: ARTCN-10_obj links: - rel: assessment-for href: "#ARTCN-10_smt" name: objective prose: Determine whether the CSP includes the subject identifier within the signed attribute bundle issued to the wallet. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTCN-10_asm-examine name: assessment-method prose: Examine the CSP's attribute bundle issuance process and configuration to confirm that the subject identifier is included as a field within the signed attribute bundle. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-10_asm-test name: assessment-method prose: Test by requesting issuance of an attribute bundle from the CSP and inspect its signed contents to confirm the subject identifier is present inside the bundle (rather than in the outer wallet assertion). - id: ARTCN-10_gdn name: guidance prose: "Assessment is required when: The subscriber is identified in the assertion using a federated identifier." - id: ARTCN-11 title: Wallet Subject Identifier Namespace Processing props: - value: 5.8 K class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-11_smt name: statement prose: The subject identifier SHALL be... processed in the namespace of the CSP that issued the attribute bundle. - id: ARTCN-11_obj links: - rel: assessment-for href: "#ARTCN-11_smt" name: objective prose: Determine whether the RP scopes the subject identifier to the namespace of the CSP that issued the signed attribute bundle. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTCN-11_asm-examine name: assessment-method prose: Examine the RP's assertion processing logic to confirm that subject identifiers extracted from CSP-signed attribute bundles are paired with the CSP's issuer identifier when resolving to an RP subscriber account. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-11_asm-test name: assessment-method prose: Test by presenting assertions from two different CSPs containing attribute bundles with the same subject identifier value. Confirm the RP treats them as different subscribers. - id: ARTCN-11_gdn name: guidance prose: |- Assessment is required when: The subscriber is identified in the assertion using a federated identifier. See ARTC-11 for the equivalent requirement for non-wallet federation. - id: ARTCN-12 title: Attribute Bundle Validity Window Enforcement props: - value: 5.8 L class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-12_smt name: statement prose: "The signed attribute bundle from the CSP SHOULD contain a validity time window, which is defined as a period of time outside of which the attribute bundle SHALL NOT be accepted as valid by the RP for the purposes of authenticating the subscriber and starting an authenticated session at the RP." - id: ARTCN-12_obj links: - rel: assessment-for href: "#ARTCN-12_smt" name: objective prose: Determine whether the RP rejects signed attribute bundles presented outside their validity time window. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-12_asm-test name: assessment-method prose: Test by presenting an assertion from a wallet that contains an attribute bundle with an expired validity time window to the RP. Confirm the RP rejects it and does not establish an authenticated session. - id: ARTCN-12_gdn name: guidance prose: "Assessment is required when: The signed attribute bundle contains a validity time window." - id: ARTCN-13 title: Wallet Selective Disclosure props: - value: 5.8 M class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-13_smt name: statement prose: "Attributes SHALL be made available to the RP using a selective disclosure method if such a method is made available by the underlying attribute bundle. In selective disclosure, a subset of attributes is revealed rather than the entire set." - id: ARTCN-13_obj links: - rel: assessment-for href: "#ARTCN-13_smt" name: objective prose: "Determine whether the wallet uses selective disclosure when presenting attributes to the RP, when the attribute bundle supports it." - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTCN-13_asm-examine name: assessment-method prose: "Examine the wallet's assertion presentation logic to confirm that when the underlying attribute bundle supports selective disclosure, the wallet uses it to present only the attributes requested by the RP rather than the full bundle contents." - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTCN-13_asm-test name: assessment-method prose: Test by initiating a federation transaction where the RP requests a subset of the attributes available in the attribute bundle. Confirm the wallet presents only the requested subset. - id: ARTCN-13_gdn name: guidance prose: |- Assessment is required when: The underlying attribute bundle supports selective disclosure. This requirement ensures that the wallet does not over-disclose attributes to the RP. - id: ARTCN-14 title: Unsigned Attributes as Self-Asserted props: - value: 5.8 N class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTCN-14_smt name: statement prose: Identity attributes that are in the assertion but outside of a signed attribute bundle SHALL be considered self-asserted. - id: ARTCN-14_obj links: - rel: assessment-for href: "#ARTCN-14_smt" name: objective prose: Determine whether the RP treats identity attributes present in the assertion but outside of a signed attribute bundle as self-asserted. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTCN-14_asm-examine name: assessment-method prose: Examine the RP's assertion processing logic or documentation to confirm that attributes outside a signed attribute bundle are classified as self-asserted and not treated as CSP-verified for access or trust decisions. - id: ARTCN-14_gdn name: guidance prose: The RP may validate these additional attributes using its own validation process. - id: ARTPT-1 title: Wallet Assertion Presentation Channel Protection props: - value: 5.9 A class: index name: label - value: IdP/RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTPT-1_smt name: statement prose: Assertions SHALL be presented to the RP through an authenticated protected channel. - id: ARTPT-1_obj links: - rel: assessment-for href: "#ARTPT-1_smt" name: objective prose: Determine whether assertions from a subscriber-controlled wallet are presented to the RP over an authenticated protected channel. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTPT-1_asm-examine name: assessment-method prose: |- For network-based assertion presentations, this control is satisfied by PSI-1. Examine the presentation protocol specification and implementation documentation to confirm that the protocol establishes an authenticated protected channel for assertion presentation, for each wallet and non-network presentation method that will be utilized. - id: ARTPT-2 title: Wallet Presentation Nonce Inclusion props: - value: 5.9 B class: index name: label - value: IdP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTPT-2_smt name: statement prose: "The presentation SHALL include the cryptographic nonce from the RP's request, if present (this is required at FAL2 and above)." - id: ARTPT-2_obj links: - rel: assessment-for href: "#ARTPT-2_smt" name: objective prose: Determine whether the wallet includes the RP's cryptographic nonce in the assertion presentation. - props: - value: EXAMINE name: method class: assessment-summary id: ARTPT-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ARTCN-4. - id: ARTPT-2_gdn name: guidance prose: "Assessment is required when: The RP sends a cryptographic nonce in its federation request (required at FAL2 and above)." - id: ARTPT-3 title: Wallet Presentation Nonce Verification props: - value: 5.9 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTPT-3_smt name: statement prose: The RP SHALL verify the nonce in accordance with the federation protocol. - id: ARTPT-3_obj links: - rel: assessment-for href: "#ARTPT-3_smt" name: objective prose: Determine whether the RP verifies the cryptographic nonce in the wallet's presentation. - props: - value: EXAMINE name: method class: assessment-summary id: ARTPT-3_asm-summary title: Assessment Method name: assessment-method prose: "Satisfied by ARTVL-3, item 5." - id: ARTPT-3_gdn name: guidance prose: "Assessment is required when: The RP sends a cryptographic nonce in its federation request (required at FAL2 and above)." - id: ARTPT-4 title: Wallet Assertion Injection Protection props: - value: 5.9 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTPT-4_smt name: statement prose: "The RP SHALL protect itself against the injection of manufactured or captured assertions by using XSS and CSRF protection, rejecting assertions outside of the correct stage of a federation transaction, or other accepted techniques discussed in Sec. 3.11.1." - id: ARTPT-4_obj links: - rel: assessment-for href: "#ARTPT-4_smt" name: objective prose: Determine whether the RP protects itself against injection of manufactured or captured wallet assertions. - props: - value: EXAMINE name: method class: assessment-summary id: ARTPT-4_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by FCP-2. - id: ARTVL-1 title: Wallet Attribute Bundle Signature Validation props: - value: 5.10 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTVL-1_smt name: statement prose: The RP SHALL validate the signature on all signed attribute bundles in the assertion using the verification key from the CSP that issued the signed attribute bundle. - id: ARTVL-1_obj links: - rel: assessment-for href: "#ARTVL-1_smt" name: objective prose: Determine whether the RP validates the signature on all signed attribute bundles in the assertion using the verification key from the CSP that issued the bundle. - props: - value: EXAMINE name: method class: assessment-summary id: ARTVL-1_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ABUN-2. - id: ARTVL-1_gdn name: guidance prose: ABUN-2 establishes the requirement for RPs to validate CSP signatures on attribute bundles. This control applies that requirement to subscriber-controlled wallet scenarios. - id: ARTVL-2 title: Wallet Assertion Signature Validation props: - value: 5.10 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTVL-2_smt name: statement prose: The RP SHALL validate the signature of the assertion using the verification key of the subscriber controlled wallet contained in the signed attribute bundle. - id: ARTVL-2_obj links: - rel: assessment-for href: "#ARTVL-2_smt" name: objective prose: Determine whether the RP validates the wallet's assertion signature using the wallet's verification key contained in the signed attribute bundle. - props: - value: EXAMINE name: method class: assessment-summary id: ARTVL-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ABUN-3. - id: ARTVL-3 title: Wallet Assertion Validation Checklist props: - value: 5.10 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: ARTVL-3_smt name: statement prose: |- The RP SHALL validate the assertion by checking that all the following are true: (1) Bundle verification: Ensure that the bundle was issued to the wallet that is presenting the assertion to the RP. (2) Issuer verification: If a specific wallet was requested by the RP, ensure that the assertion was issued by the requested wallet. (3) Time validation: Ensure that the validity time window is within acceptable limits of the current timestamp. (4) Audience restriction: Ensure that this RP is the intended recipient of the assertion. (5) Nonce: Ensure that the cryptographic nonce included in the RP's request is also included in the presentation. (6) Transaction terms: Ensure that the IAL, AAL, and FAL represented by the assertion are allowable under the applicable trust agreement and are suitable for the RP's needs. (7) Assertion identifier: Ensure that the assertion has not been replayed within its validity time window at this RP by validating a transaction specific assertion identifier, such as a wallet-provided nonce. - id: ARTVL-3_obj links: - rel: assessment-for href: "#ARTVL-3_smt" name: objective prose: Determine whether the RP validates all required elements of a wallet assertion before accepting it. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: ARTVL-3_asm-examine name: assessment-method prose: Examine the RP assertion validation documentation to confirm that all requirements are checked. - props: - ns: http://csrc.nist.gov/ns/rmf value: TEST name: method id: ARTVL-3_asm-test name: assessment-method prose: Test the RP system to validate all assertions are checked for the required elements and reject if they are not present. - id: RPSUBA-1 title: Wallet Account Resolution Attribute Minimization props: - value: 5.11 A class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSUBA-1_smt name: statement prose: "If a federated identifier is not present (e.g., in the case of mDL), the RP will need to request the necessary attributes to resolve the subscriber to the RP subscriber account for each federated transaction. This attribute set SHALL be the minimum necessary to achieve accurate resolution." - id: RPSUBA-1_obj links: - rel: assessment-for href: "#RPSUBA-1_smt" name: objective prose: Determine whether the RP requests only the minimum attributes necessary for accurate account resolution when a federated identifier is not present. - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPSUBA-1_asm-examine name: assessment-method prose: Examine the set of attributes that the RP requests from the wallet for account resolution. Confirm that each requested attribute is necessary for accurate resolution and that no extraneous attributes are included. - id: RPSUBA-1_gdn name: guidance prose: |- Assessment is required when: A federated identifier is not present in the wallet assertion and account resolution is used. ACCR-1 requires that the requested attributes are sufficient for unique resolution; this control requires that they are no more than necessary. Together they establish the bound: request enough to resolve accurately, but nothing beyond that. This supports the data minimization principles in Sec. 7. - id: RPSUBA-2 title: Wallet Federated Identifier Linking props: - value: 5.11 B class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSUBA-2_smt name: statement prose: Linking to multiple federated identifiers SHALL be managed as discussed in Sec. 3.8.1. - id: RPSUBA-2_obj links: - rel: assessment-for href: "#RPSUBA-2_smt" name: objective prose: Determine whether linking to multiple federated identifiers in the wallet context is managed in accordance with Sec. 3.8.1. - props: - value: EXAMINE name: method class: assessment-summary id: RPSUBA-2_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by ACCL-1 and ACCL-2. - id: RPSUBA-3 title: RP Subscriber Information Management Disclosure props: - value: 5.11 C class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSUBA-3_smt name: statement prose: The RP SHALL disclose its practices for managing subscriber information as part of the trust agreement. - id: RPSUBA-3_obj links: - rel: assessment-for href: "#RPSUBA-3_smt" name: objective prose: Determine whether the RP discloses its practices for managing subscriber information as part of the trust agreement artifact(s). - props: - ns: http://csrc.nist.gov/ns/rmf value: EXAMINE name: method id: RPSUBA-3_asm-examine name: assessment-method prose: "Examine the trust agreement artifact(s) to confirm the RP's practices for managing subscriber information are disclosed, including how subscriber data is collected, stored, used, and disposed of." - id: RPSUBA-4 title: Wallet RP Subscriber Account Redress props: - value: 5.11 D class: index name: label - value: RP class: target name: marking - value: ALL class: xal-level name: marking parts: - id: RPSUBA-4_smt name: statement prose: The RP SHALL provide effective means of redress to the subscriber for correcting information in the RP subscriber account. See Sec. 3.5.3 for additional requirements and considerations for redress mechanisms. - id: RPSUBA-4_obj links: - rel: assessment-for href: "#RPSUBA-4_smt" name: objective prose: Determine whether the RP provides effective means of redress to the subscriber for correcting information in the RP subscriber account. - props: - value: EXAMINE name: method class: assessment-summary id: RPSUBA-4_asm-summary title: Assessment Method name: assessment-method prose: Satisfied by RR-1. metadata: version: "0.1" published: 2026-09-30T13:10:04Z title: NIST SP 800-63-4 revisions: - version: 63C title: 63C - version: 63B title: 63B - version: 63A title: 63A - version: 63Base title: 63Base last-modified: 2026-09-30T13:10:04Z oscal-version: 1.2.2