Authentication - Privacy Analysis and Privacy Impact Assessment, v1.0

Credential Service Providers must undergo a thorough privacy analysis and impact assessment publishing the results.

Assessment Steps (4)

1
SAOP Privacy Analysis (SAOPPrivacyAnalysis)
Has the CSP performed a privacy analysis that sufficiently covers all of the data they maintain about subscribers?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the privacy assessment was performed.
2
SORN Coverage (SORNCoverage)
Has the CSP published a System of Records Notice (SORN) or identified an existing SORN that covers authentication activity?
Artifact
A1
Provide a copy or link to the SORN that covers the authenticator activity of this agency and/or system.
3
SAOP Analysis (SAOPAnalysis)
Has the CSP performed an analysis to determine whether the E-Government Act applies to any of the agency's activity?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the e-government act assessment was performed.
4
Privacy Impact Assessment (PrivacyImpactAssessment)
Has the agency published a Privacy Impact Assessment (PIA) or specified an existing PIA that covers their activity?
Artifact
A1
Provide a copy or link to the PIA that covers the activity of this agency and/or system.

Conformance Criteria (4)

C1
The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) and conduct an analysis to determine whether the collection of PII to issue or maintain authenticators triggers the requirements of the Privacy Act of 1974
Citation
NIST SP 800-63B
Section 4.4 (1)
C2
The agency SHALL publish a System of Records Notice (SORN) to cover such collection, as applicable.
Citation
NIST SP 800-63B
Section 4.4 (2)
C3
The agency SHALL consult with their SAOP to conduct an analysis determining whether the collection of PII to issue or maintain authenticators triggers E-Government Act of 2002 requirements.
Citation
NIST SP 800-63B
Section 4.4 (3)
C4
The agency SHALL publish a Privacy Impact Assessment (PIA) to cover such collection, as applicable.
Citation
NIST SP 800-63B
Section 4.4 (4)