Federation - Privacy Risk Assessment for Attributes Requested from IdPs, v1.0

Relying Parties must conduct a privacy risk assessment to determine which attributes to request from IdPs.

Assessment Step

1
Privacy Risk Assessment for Attributes (PrivacyRiskAssessmentforAttributes)
Does the RP properly document their requested attributes within their privacy risk assessment?
Artifact
A1
Provide evidence (e.g., policies, federation rules, privacy risk assessments) that the RP has documented risk associated with requested attributes.

Conformance Criteria (1)

C1
RPs SHALL conduct a privacy risk assessment when determining which attributes to request.
Citation
NIST SP 800-63C
Section 7