Implement IAL2 identity proofing per NIST SP 800-63A Chapter 5 covering remote (Section 5.3.2) and in-person (Section 5.3.3) options. IAL2 requires (a) Identity Evidence Collection per Section 5.2.1 with strength categories (UNACCEPTABLE + WEAK + FAIR + STRONG + SUPERIOR) where IAL2 requires one piece of SUPERIOR or STRONG plus one piece of STRONG or FAIR evidence per Table 5-1, (b) Identity Resolution per Section 5.2.2 (correlating evidence to a single unique identity), (c) Evidence Validation per Section 5.2.3 (authenticity of presented evidence including authoritative source confirmation where available), (d) Identity Verification per Section 5.2.4 (binding evidence to the live applicant via in-person inspection + biometric comparison or live remote engagement with biometric comparison), (e) Knowledge-Based Verification restrictions per Section 5.3.2 (KBV may only be used as a secondary process and only with strict requirements + must not rely solely on publicly-available data), (f) Address Confirmation per Section 5.4 sent via mail or alternative channels), (g) Fraud Mitigation per Section 5.4 across enrolment lifecycle, (h) Notice per Section 5.5 (privacy notice + use + retention + redress).
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.