Skip to content

Conversation

@dhs-BI
Copy link

@dhs-BI dhs-BI commented May 1, 2025

I pulled all of the requirements for FAL2 from NIST SP800-63Crev4 using the draft version available as of May 1, 2025.

I'll be updating this doc as I review the requirements against the current OIDC SL1 profile draft. Publishing this PR to allow the WG to more readily see the requirements.

(Edited to add the following on May 2, 2025)
The IPSIE WG needs to determine which parts of the FAL2 guidelines we want to adopt. While our initial levels stated FAL2 compliance, it is my expectation that the WG will narrow this to focus on meaningful controls for enterprise use cases and not wholesale adoption of all FAL2 required controls.

added to the list
Replaced last version with a complete set of requirements tagged by document section.
@dhs-BI dhs-BI requested a review from aaronpk May 1, 2025 21:40
@dhs-BI dhs-BI self-assigned this May 1, 2025
@dhs-BI dhs-BI added the sl1 label May 1, 2025
deansaxe added 5 commits May 1, 2025 15:30
Updated section 2.1
Continuing to work through the doc to identify requirements that are met/not met, and requirements that are unlikely to be useful to IPSIE.
Updated the doc with references to filed issues through section 3.11.2.
deansaxe added 3 commits June 12, 2025 10:53
Completed through line 619.
Reviewed up to line 696
Finalized review of requirements.  Issues have been created where needed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants