Federation - Limitations on IdP Transmission of Subscriber Information to RPs, v1.0

Identity Providers shall not disclose subscriber information to RPs outside of well defined purposes, such federated authentication, related fraud mitigation, to comply with law or legal process, notification of security issues, or in the case of a specific user request, to transmit the information.

Assessment Step

1
Limit Disclosures (LimitDisclosures)
Does the IdP only disclose subscriber information for appropriate reasons? Appropriate reasons include federated authentication, fraud mitigation, complying with legal processes, notification of security issues, or user request.
Artifact
A1
Provide evidence (e.g., policies, operational details) that the IdP will not disclose subscriber information outside of appropriate reasons.

Conformance Criteria (1)

C1
A subscriber's information SHALL NOT be transmitted between IdP and RP for any purpose other than well defined purposes such as federated authentication, related fraud mitigation, to comply with law or legal process, or in the case of a specific user request, to transmit the information. An IdP MAY disclose information on subscriber activities to other RPs within the federation for security purposes, such as communication of compromised subscriber accounts.
Citation
NIST SP 800-63C
Section 5.2, Paragraphs 4 and 5