Level of Assurance: Difference between revisions
Jump to navigation
Jump to search
No edit summary |
|||
Line 12: | Line 12: | ||
* [[NIST SP 800-63-1]] | * [[NIST SP 800-63-1]] | ||
* [[NIST SP 800-63-2]] | * [[NIST SP 800-63-2]] | ||
* [[ISO/IEC 29115 Entity Authentication Assurance]] | * [[NIST SP 800-63-3]] | ||
* [[ISO/IEC 29115 Entity Authentication Assurance]] - was based on 63-2, but has been withdrawn pending upcoming changes from NIST. | |||
* [[NISTIR 8344]] a draft Ontology of Authentication release in 2021-02, comments du on 2021-04-09. It is expected that the ideas on IAA and OAA in tis doc will be carried forward to 63-4. | |||
[[Category: Assurance]] | [[Category: Assurance]] | ||
[[Category: Identity]] | |||
[[Category: Authentication]] | |||
[[Category: Federation]] | |||
[[Category: Health]] | [[Category: Health]] |
Revision as of 00:21, 14 March 2021
Full Title
Early Identity Assurance combined Identity Proofing and Authentication into a single list of four Level of Assurance criteria.
Context
Specification from NIST and ISO are general and difficult to apply in real world situations.
Solutions
Federations are likely to specify a detailed set of criteria that apply to their particular circumstances.
Healthcare
- National HIE Governance Forum - Identity and Access Management for Health Information Exchange
- Direct Trust response to Request for Information on Updates to ONC’s Voluntary Personal Health Record Model Privacy Notice, 2016-04239
References
- NIST SP 800-63-1
- NIST SP 800-63-2
- NIST SP 800-63-3
- ISO/IEC 29115 Entity Authentication Assurance - was based on 63-2, but has been withdrawn pending upcoming changes from NIST.
- NISTIR 8344 a draft Ontology of Authentication release in 2021-02, comments du on 2021-04-09. It is expected that the ideas on IAA and OAA in tis doc will be carried forward to 63-4.