ID Proofing - Written Policy or Practice Statement, v1.0

Credential Service Providers must have a written policy or practice statement that details the identity proofing and enrollment processes that they perform.

Assessment Step

1
CSP Written Policy (CSPWrittenPolicy)
Does the CSP have a written policy or practice statement that details how it's identity proofing and enrollment process works including details on errors, alternatives when issues arise, and counter-measures to prevent fraud.
Artifact
A1
Provide a copy of the written policy or practice statement or the document that contains it.

Conformance Criteria (1)

C1
The identity proofing and enrollment processes SHALL be performed according to an applicable written policy or *practice statement* that specifies the particular steps taken to verify identities. The *practice statement* SHALL include control information detailing how the CSP handles proofing errors that result in an applicant not being successfully enrolled. For example, the number of retries allowed, proofing alternatives (e.g., in-person if remote fails), or fraud counter-measures when anomalies are detected.
Citation
NIST SP 800-63A
Section 4.2 (6)