Skip to content

FAL2 Compliance - Authentication and Attribute Disclosure #77

@dhs-BI

Description

@dhs-BI

Section 3.6 of SP800-63C rev4 documents the requirements for attribute disclosure between IdPs and RPs. Since IPSIE's scope is enterprises who are expected to have business agreements with their vendors, this section does appear to be applicable to IPSIE since it is not a technical control and is likely impacted by local, national, and supranational laws and regulations.

These requirements are captured in #71. Should IPSIE eliminate the requirements in this section for purposes of SL1?

chair hat off
My personal opinion is that these requirements are unenforceable by IPSIE and should be eliminated from consideration when we discuss FAL2 compliance. Our focus should be on technical controls, not business processes.
chair hat on

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions