Conduct a Digital Identity Risk Assessment per NIST SP 800-63-3 Section 5 and select appropriate assurance levels for each digital transaction or service. The assessment determines (a) Identity Assurance Level (IAL1 self-asserted + IAL2 evidence-based remote or in-person + IAL3 in-person or supervised remote with strong evidence and biometric collection), (b) Authenticator Assurance Level (AAL1 single-factor + AAL2 multi-factor + AAL3 hardware cryptographic with verifier impersonation resistance), (c) Federation Assurance Level (FAL1 bearer assertion + FAL2 encrypted assertion + FAL3 holder-of-key assertion). Selection must consider (a) potential harms from authentication errors + identity proofing errors + federation errors across categories (inconvenience + distress + damage to standing or reputation + financial loss + harm to agency programs or public interests + unauthorised release of sensitive information + personal safety + civil or criminal violations), (b) likelihood of harm, (c) potential mitigations, (d) privacy implications, (e) equity impact. Document the risk assessment + assurance level selection + rationale + privacy impact + equity considerations in a Digital Identity Acceptance Statement approved by the cognisant authorising official.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.