NIST SP 800-63 Digital Identity Guidelines
Digital Identity Risk and Assurance Level Selection

NIST SP 800-63 Digital Identity Guidelines NISTSP63-1: Digital Identity Risk Assessment and Assurance Level Selection (IAL, AAL, FAL)

Conduct a Digital Identity Risk Assessment per NIST SP 800-63-3 Section 5 and select appropriate assurance levels for each digital transaction or service. The assessment determines (a) Identity Assurance Level (IAL1 self-asserted + IAL2 evidence-based remote or in-person + IAL3 in-person or supervised remote with strong evidence and biometric collection), (b) Authenticator Assurance Level (AAL1 single-factor + AAL2 multi-factor + AAL3 hardware cryptographic with verifier impersonation resistance), (c) Federation Assurance Level (FAL1 bearer assertion + FAL2 encrypted assertion + FAL3 holder-of-key assertion). Selection must consider (a) potential harms from authentication errors + identity proofing errors + federation errors across categories (inconvenience + distress + damage to standing or reputation + financial loss + harm to agency programs or public interests + unauthorised release of sensitive information + personal safety + civil or criminal violations), (b) likelihood of harm, (c) potential mitigations, (d) privacy implications, (e) equity impact. Document the risk assessment + assurance level selection + rationale + privacy impact + equity considerations in a Digital Identity Acceptance Statement approved by the cognisant authorising official.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.