Federation - Use of Attribute References, v1.0

Relying Parties must request attribute references when a viable option in place of attributes. Attribute references are derived attributes that answer a question that could also be answered by revealing the attributes value. For example is the subject over 18 as opposed to asking the subject's age.

Assessment Step

1
Attribute References (AttributeReferences)
Does the RP request only the minimum attribute set required using attribute references when viable?
Artifact
A1
Provide evidence (e.g., policies, operational details) that the RP requests only the attributes it needs and attribute references when feasible.

Conformance Criteria (1)

C1
The RP SHALL, where feasible, request attribute references rather than full attribute values. An attribute reference in this context is asking "is the applicant over 18 years old" as opposed to asking for the age of the applicant; ask for as little as possible to get the information needed.
Citation
NIST SP 800-63C
Section 7.3