Federation - Support for IAL1 RPs with User Consent, v1.0

Credential Service Providers that operate at IAL2 and higher should request user consent before transmitting user data to relying parties that only require IAL1

Assessment Step

1
Consent for IAL1 RPs (ConsentforIAL1RPs)
Does the CSP request user consent before enabling RPs that only require IAL1 from the CSP.
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample screenshots of functionality) that the IAL2/3 CSP requests user consent before interacting with an RP that only requires IAL1.

Conformance Criteria (1)

C1
An IAL2 or IAL3 CSP SHOULD support RPs that only require IAL1, if the user consents.
Citation
NIST SP 800-63A
Section 4.3 (3)