ID Proofing - Address Confirmation for In-Person and Supervised Remote Identity Proofing with Moderate Assurance, v1.0

Credential Service Providers must send notice to an applicant's confirmed address regarding their identity proofing. This notice may include an expiring enrollment code used to bind an authenticator to the applicant.

Assessment Step

1
In-Person CSP Notice To Confirmed Address (In-PersonCSPNoticeToConfirmedAddress)
Does the CSP send notification of proofing to a confirmed address of record? If an enrollment code is used for authenticator binding, the enrollment code must have a limited validity window and minimum entropy.
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample processes) that the CSP properly sends notification of proofing to a confirmed address of record with a proper enrollment code if necessary.

Conformance Criteria (1)

C1
  1. The CSP SHOULD send a notification of proofing to a confirmed address of record.
  2. The CSP MAY provide an enrollment code directly to the subscriber if binding to an authenticator will occur at a later time.
  3. The enrollment code SHALL be valid for a maximum of 7 days.
  4. An enrollment code SHALL be comprised of one of the following:
    • Minimally, a random six character alphanumeric or equivalent entropy. For example, a code generated using an approved random number generator or a serial number for a physical hardware authenticator.
    • A machine-readable optical label, such as a QR Code, that contains data of similar or higher entropy as a random six character alphanumeric.
Citation
NIST SP 800-63A
Sections 4.4.1.6 (4) and 4.6