Digital Identity Risk Management - Acceptance Statement, v1.0

Organizations must document their digital identity risk acceptance statement including specific details regarding assurance levels implemented and assessed, as well as documenting any compensating controls needed to pass assessments.

Assessment Step

1
Risk Assessment Statement (RiskAssessmentStatement)
Does the organization have a risk assessment statement that provides all required content, specifically including assessed and implemented assurance levels and details on any compensating controls implemented?
Artifact
A1
Provide a copy of the risk management acceptance statement or document that contains it.

Conformance Criteria (1)

C1
The organization shall have a risk assessment statement covering:
  1. Assessed assurance levels,
  2. Implemented assurance levels,
  3. Rationale, if implemented levels differ from assessed levels,
  4. Comparability demonstration of compensating controls when the complete set of applicable 800-63 requirements are not implemented, and
  5. If not accepting federated identities, rationale.
Citation
NIST SP 800-63-3
Section 5.5