Difference between revisions of "Assurance"

From MgmtWiki
Jump to: navigation, search
(Context)
m (Context)
Line 8: Line 8:
 
* The rest of this page is about establishing a level of assurance for [[User Information]] about a [[User]] also known as a [[Subject]].
 
* The rest of this page is about establishing a level of assurance for [[User Information]] about a [[User]] also known as a [[Subject]].
 
* [https://pages.nist.gov/800-63-3/sp800-63-3.html New version of SP 800-63-3] with [[Assurance]] separated out from the other [[Authentication]] [[Attribute]]s.
 
* [https://pages.nist.gov/800-63-3/sp800-63-3.html New version of SP 800-63-3] with [[Assurance]] separated out from the other [[Authentication]] [[Attribute]]s.
* [[Provenance]] is a term that is sometimes used for the level of [[Assurance]] that a [[Data Controller]] has in the origin and reliability of [[User]] [[Attribute]]s, especialially health care data
+
* [[Provenance]] is a term that is sometimes used for the level of [[Assurance]] that a [[Data Controller]] has in the origin and reliability of [[User]] [[Attribute]]s, especially health care data
  
 
For a [[User]] that wants some [[Assurance]] about a [[Web Site]] see [[Trusted Third Party]].
 
For a [[User]] that wants some [[Assurance]] about a [[Web Site]] see [[Trusted Third Party]].

Revision as of 14:43, 14 September 2018

Full Title or Meme

The level of trust that can be afforded a claim of an Identifier or Attribute.

Context

For a User that wants some Assurance about a Web Site see Trusted Third Party.

Problems

  • In contexts where names are not validated (of low Assurance) the problem arises that trolls many adopt the name of some well-known person to be able to make statements that falsely appear to be from the real person.[1]
  • See discussion on the pages for Ephemeral and Persistent.
  • Most of the existing protocols, like OpenID Connect and SAML 2.0 support the older NIST SP 800-63-2 level of assurance ratings. These are also baked into RFC 6711 "An IANA Registry for Level of Assurance (LoA) Profiles" and ISO/IEC 291151.

Solutions

A rather facile mapping of the NIST SP 800-63-3 levels of Assurance to the processes known today is:

  • AAL1 ==> password
  • AAL2 ==> 2FA
  • AAL3 ==> U2F

The best source of Truth about an Identity is obtained by documentation of the Identity Proofing process. That is something that can be audited to measure reality against expectations.

References

  1. Synonyms include: Validated which typically is used with Assurance of claims, or Attested which typically is used with Assurance of User Devices.
    1. Jack Nicas, Oprah, Is That You? Most Likely, It's Not. 2018-07-08 New York Times page BU1