NIST SP 800-63 Digital Identity Guidelines
Cross-cutting: Threat Model, Lifecycle, Privacy, Equity

NIST SP 800-63 Digital Identity Guidelines NISTSP63-8: Threat Model, Lifecycle Management, Privacy, Equity, Records, and Subscriber Communication

Operate cross-cutting requirements per NIST SP 800-63-3 / 63A / 63B / 63C. Threat Model per AAL: (a) per Section 8 of SP 800-63B + Section 4.4 of SP 800-63-3 (cover impersonation + verifier compromise + session hijacking + replay + phishing + denial of service threats appropriate to assurance level). Authenticator Lifecycle Management per SP 800-63B Chapter 6: (a) Authenticator Binding per Section 6.1, (b) Authenticator Loss and Replacement per Section 6.2 (post-loss recovery requires re-proofing or strong evidence of identity), (c) Authenticator Expiration per Section 6.3, (d) Authenticator Suspension and Revocation per Section 6.4 + Section 6.5, (e) Authenticator Strength Maintenance per Section 6.6. Subscriber Notification of Changes per Section 6.1.2 + 6.5. Authentication Event Records per SP 800-63B Section 10.2. Privacy per SP 800-63A Section 5.5 + SP 800-63B Section 9 + SP 800-63C Section 9 (purpose limitation + minimisation + subscriber notice + consent + redress + retention limitation). Equity considerations per all four documents (avoid bias in proofing + accessibility + alternatives for those without standard evidence + trusted referee model). Records retention per agency policy with chain of custody for evidence and biometrics. SMS OTP restricted use per Section 5.1.3.3 (still permitted but RESTRICTED with risk-based controls per Section 5.2.10).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.