Federation - Specification of AAL and IAL in Assertion, v1.0

Assertions that cover authentication events should include the AAL, and when assertions include identity attributes, they should include the IAL.

Assessment Steps (2)

1
Assertion Includes AAL (AssertionIncludesAAL)
Does the assertion specify the AAL when an authentication event is being asserted? This can be conveyed via an attribute or some other protocol/profile specific mechanism.
Artifact
A1
Provide evidence (e.g. policies, operational samples) that the assertions include AAL appropriately.
2
Assertion Includes IAL (AssertionIncludesIAL)
Does the assertion specify the IAL when identity attributes are being asserted? This can be conveyed via an attribute or some other protocol/profile specific mechanism.
Artifact
A1
Provide evidence (e.g. policies, operational samples) that assertions contain IAL appropriately.

Conformance Criteria (2)

C1
Assertions SHOULD specify the AAL when an authentication event is being asserted.
Citation
NIST SP 800-63C
Section 6
C2
Assertions SHOULD specify the IAL when identity proofed attributes (or references) are being asserted.
Citation
NIST SP 800-63C
Section 6