ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
Clause 6: Levels of assurance – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework

ISO/IEC 29115:2013 - Entity Authentication Assurance Framework 6.4: 6.4 Level of assurance 4 (LoA4)

At LoA4 there is very high confidence in the identity, for high risk; it is LoA3 plus in-person identity proofing for human entities and tamper-resistant hardware devices for the storage of all secret or private cryptographic keys, and all PII and other sensitive data in authentication protocols shall be cryptographically protected in transit and at rest; it suits services where authentication failure risks harm or distress or criminal liability for the responsible party and approval of transactions with high risk of financial loss; digital certificates (X.509, card-verifier certificates) may authenticate NPEs such as smartphones or smart meters.

Maintained by Gerard BlokdykControl text last updated

Other controls in Clause 6: Levels of assurance – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.