ID Proofing - Address Confirmation for Unsupervised Remote Identity Proofing, v1.0

Credential Service Providers must send an enrollment code to a confirmed address for the applicant, and this enrollment code must be used to complete the identity proofing process. Additionally, the CSP must send a notice to a different confirmed address for the applicant notifying them of identity proofing process.

Assessment Step

1
Remote CSP Address Confirmation and Notice (RemoteCSPAddressConfirmationandNotice)
Does the CSP send a valid enrollment code during identity proofing, as well as a separate notice of proofing to a separate confirmed address for the user? For example sending a enrollment code to e-mail and notice of enrollment to the applicant's postal address.
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample processes) that the CSP properly uses enrollment codes during identity proofing and sends notification of proofing to a separate confirmed address of record.

Conformance Criteria (1)

C1
  1. The CSP SHALL send an enrollment code to a confirmed address of record for the applicant.
  2. The applicant SHALL present a valid enrollment code to complete the identity proofing process.
  3. The CSP SHOULD send the enrollment code to the postal address that has been validated in records. The CSP MAY send the enrollment code to a mobile telephone (SMS or voice), landline telephone, or email if it has been validated in records.
  4. If the enrollment code is also intended to be an authentication factor, it SHALL be reset upon first use.
  5. Enrollment codes must meet this criteria:
    • Minimally, a random six character alphanumeric or equivalent entropy. For example, a code generated using an approved random number generator or a serial number for a physical hardware authenticator.
    • A machine-readable optical label, such as a QR Code, that contains data of similar or higher entropy as a random six character alphanumeric.
  6. and SHALL have the following maximum validities
    • 10 days, when sent to a postal address of record within the contiguous United States;
    • 30 days, when sent to a postal address of record outside the contiguous United States;
    • 10 minutes, when sent to a telephone of record (SMS or voice);
    • 24 hours, when sent to an email address of record.
  7. The CSP SHALL ensure the enrollment code and notification of proofing are sent to different addresses of record. For example, if the CSP sends an enrollment code to a phone number validated in records, a proofing notification will be sent to the postal address validated in records or obtained from validated and verified evidence, such as a driver's license.
Citation
NIST SP 800-63A
Sections 4.4.1.6 (5) and 4.6