ID Proofing - Written Policy and Procedures on Trusted Referees, v1.0

Credential Service Providers must have a written policy and/or procedure describing how a trusted referee is determined and describing the lifecycle by which they retains their status.

Assessment Step

1
CSP Trusted Referees (CSPTrustedReferees)
Does the CSP have a written policy and/or procedure for determining how referees are trusted and describing the lifecycle that manages their status?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that establish the policy and procedures for referee lifecycles, including coverage of revocation and suspension requirements.

Conformance Criteria (1)

C1
The CSP SHALL establish written policy and procedures as to how a trusted referee is determined and the lifecycle by which the trusted referee retains their status as a valid referee, to include any restrictions, as well as any revocation and suspension requirements.
Citation
NIST SP 800-63A
Section 5.3.4 (2)