Federation - No Assumption of IAL or AAL When Not Specified in Assertion, v1.0

Relying Parties should make IAL and AAL determinations exclusively based on data passed within assertions and not make any assumptions about their values.

Assessment Step

1
IAL and AAL In Assertions (IALandAALInAssertions)
Does the RP make IAL and AAL decisions based on values conveyed within assertions?
Artifact
A1
Provide evidence (e.g. policies, operational details) that the RP uses IAL and AAL values conveyed within in assertions.

Conformance Criteria (1)

C1
If IAL or AAL values are not specified explicitly in an assertion, the RP SHALL NOT assign any specific IAL or AAL to the assertion.
Citation
NIST SP 800-63C
Section 6, Paragraph 5