NIST SP 800-63-4
Digital Identity Risk Management

NIST SP 800-63-4 1: Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection

Conduct Digital Identity Risk Management per NIST SP 800-63-4 Section 5 (April 2025) using the updated risk management process introduced in Rev 4. The process now explicitly considers (a) impacts to people accessing services (not only impacts to the agency), (b) equity impacts assessed alongside security and privacy impacts, (c) usability impacts on legitimate users. Select Identity Assurance Level (IAL1 + IAL2 + IAL3) per SP 800-63-4 Volume A based on consequences of identity proofing failure to the individual + the agency + third parties. Select Authenticator Assurance Level (AAL1 + AAL2 + AAL3) per SP 800-63-4 Volume B based on consequences of authentication failure. Select Federation Assurance Level (FAL1 + FAL2 + FAL3) per SP 800-63-4 Volume C based on consequences of federation failure. Document the Digital Identity Acceptance Statement with rationale + alternatives considered + equity assessment + privacy impact + ongoing monitoring plan.

What else in your programme already covers this

This control maps to 185 controls across 99 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO 22320:2018 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 56002 · 2 controls

  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • FFIEC-05 Roles and responsibilities definition

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27003:2017 · 1 control

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/SAE 21434 · 1 control

NIST SP 800-190 · 1 control

  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards

OWASP ASVS · 1 control

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)

OWASP MASVS · 1 control

OWASP Top 10:2025 · 1 control

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)

South Korea ISMS-P · 1 control

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 185 it maps to, and the evidence behind each claim, over MCP and REST.