ID Proofing - Identity Evidence Validation, v1.0

Credential Service Providers must validate evidence presented by an applicant as part of the credential issuance process. The validation methods must meet guidance specified within NIST 800-63-3.

Assessment Step

1
CSP Evidence Validation (CSPEvidenceValidation)
Does the CSP validate each piece of Identity Proofing evidence appropriately for the strength of that evidence? Details on how to validate different types of evidence is available in NIST 800-63-3 Section 5-2.
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that describe the evidence validation methods employed by the CSP.

Conformance Criteria (1)

C1
The CSP SHALL validate each piece of evidence with a process that can achieve the same strength as the evidence presented. For example, if two forms of STRONG identity evidence are presented, each piece of evidence will be validated at a strength of STRONG. NIST 800-63-3 Section 5-2 has details on evidence validation strengths.
Citation
NIST SP 800-63A
Sections 4.4.1.3, 4.5.3, and 5.2.2