ID Proofing - Privacy Analysis and Privacy Impact Assessment, v1.0

Credential Service Providers must undergo a thorough privacy analysis and impact assessment publishing the results.

Assessment Steps (4)

1
SAOP Privacy Analysis (SAOPPrivacyAnalysis)
Has the CSP performed a privacy analysis that sufficiently covers all of the data they maintain about subscribers?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the privacy assessment was performed.
2
SORN Coverage (SORNCoverage)
Has the CSP published a System of Records Notice (SORN) or identified an existing SORN that covers federated activity?
Artifact
A1
Provide a copy or link to the SORN that covers the federated activity of this agency and/or system.
3
SAOP Analysis (SAOPAnalysis)
Has the CSP performed an analysis to determine whether the E-Government Act applies to any of the agency's identity proofing?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the e-government act assessment was performed.
4
Privacy Impact Assessment (PrivacyImpactAssessment)
Has the agency published a Privacy Impact Assessment (PIA) or specified an existing PIA that covers their identity proofing?
Artifact
A1
Provide a copy or link to the PIA that covers the identity proofing of this agency and/or system.

Conformance Criteria (4)

C1
The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) to conduct an analysis determining whether the collection of PII to conduct identity proofing triggers Privacy Act requirements.
Citation
NIST SP 800-63A
Section 4.2 (12)
C2
The agency SHALL publish a System of Records Notice (SORN) to cover such collection, as applicable.
Citation
NIST SP 800-63A
Section 4.2 (12)
C3
The agency SHALL consult with their SAOP to conduct an analysis determining whether the collection of PII to conduct identity proofing triggers E-Government Act of 2002 requirements.
Citation
NIST SP 800-63A
Section 4.2 (12)
C4
The agency SHALL publish a Privacy Impact Assessment (PIA) to cover such collection, as applicable.
Citation
NIST SP 800-63A
Section 4.2 (12)