ID Proofing - Applicant Address Confirmation via Authoritative Sources with High Assurance, v1.0

Credential Service Providers engaging in high assurance identity proofing must confirm the address of record for the applicant.

Assessment Step

1
CSP Address Confirmation High Assurance (CSPAddressConfirmationHighAssurance)
Does the CSP confirm the applicant's address of record and send a notification to the confirmed address of record?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample processes) that the CSP confirms the applicant's address and sends notification to the address.

Conformance Criteria (1)

C1
  1. The CSP SHALL confirm address of record. The CSP SHOULD confirm address of record through validation of the address contained on any supplied, valid piece of identity evidence. The CSP MAY confirm address of record by validating information supplied by the applicant, not contained on any supplied, valid piece of identity evidence.
  2. Self-asserted address data SHALL NOT be used for confirmation.
  3. A notification of proofing SHALL be sent to the confirmed address of record.
  4. The CSP MAY provide an enrollment code directly to the subscriber if binding to an authenticator will occur at a later time.
  5. The enrollment code SHALL be valid for a maximum of 7 days.
  6. Enrollment codes must meet this criteria:
    • Minimally, a random six character alphanumeric or equivalent entropy. For example, a code generated using an approved random number generator or a serial number for a physical hardware authenticator.
    • A machine-readable optical label, such as a QR Code, that contains data of similar or higher entropy as a random six character alphanumeric.
Citation
NIST SP 800-63A
Section 4.5.6 and Section 4.6