Secure Identity Best Practice
Facebook Twitter LinkedIn

Navigating NIST Sp-800-63-3 Thanks to Practical xAL Cheat Sheets

Combined Session
Wednesday, May 15, 2019 14:30—15:30
Location: CHIEMSEE

Trust. Trust is the most fundamental notion in every one of our business interactions, whatever our needs are: low or high assurance.

Do you know that, by June 2019, NIST SP-800-63-3 will celebrate its second birthday? It is a framework that improved lots of points over the previous LoA scale and gained a lot of maturity thanks to implementers, researchers, and confrontations to other Trust frameworks.
Still you may find it hard to find your way wherever you try to be a compliant IAL2 compliant CSP to ensure a third party that your users are IAL3 proofed or authenticated through an AAL2 authenticator, etc.

Surely you know that you enrolled this user thanks to a photocopied electricity bill and authenticated him/her based on an Out-of-Band single factor device generating OATH compliant OTP tokens. Those are real life examples but you will have to find in which xAL box this may fit.
This specific situation was raised within IDPro and we formalized some cheat sheets for you to navigate the inherent difficulties such as:
• Main differences between levels of assurance;
• Differences and ways to categorized WEAK, LOW, STRONG, and SUPERIOR real-life identity evidences;
• Differences and ways to categorize real-life authenticators;
• Ways to map NIST xALs to other Trust frameworks categories.

By attending this session you will get a clearer, simpler, and more actionable picture of NIST SP-800-63-3 that will ease your path for your Vector of Trust journey.

Navigating NIST Sp-800-63-3 Thanks to Practical xAL Cheat Sheets
Presentation deck
Navigating NIST Sp-800-63-3 Thanks to Practical xAL Cheat Sheets
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Jean-François Lombardo
Jean-François Lombardo
EXFO
With 13 years [Wavestone (2005), Facilité Inc. (2013), then CGI (2018)] of field experience in Identity, Access, Authentication, and mostly Information Protection space; Jean-François...
Subscribe for updates
Please provide your email address