IDEF Credential Issuance, v1.0

Specifies requirements in accordance with Identity Ecosystem Framework (IDEF) requirement SECURE-5: CREDENTIAL ISSUANCE.

Assessment Steps (2)

1
Credential Issuance (CredentialIssuance)
Does the entity issue and/or manage credentials and tokens in a manner designed to assure that they are granted to the appropriate and intended user(s) only?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
2
Coordination of Registration and Credential Issuance Across Separate Entities (CoordinationofRegistrationandCredentialIssuanceAcrossSeparateEntities)
If the entity executes the registration and credential issuance process in coordination with one or more separate entities, do its operating policies and business arrangements with those entities include procedures for ensuring accurate exchange of registration and issuance information that are commensurate with the stated assurance level? Indicate "Not Applicable" (N/A) if the entity does not coordinate these processes with any separate entities.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Credential Issuance
Entities that issue or manage credentials and tokens MUST do so in a manner designed to assure that they are granted to the appropriate and intended user(s) only. Where registration and credential issuance are executed by separate entities, procedures for ensuring accurate exchange of registration and issuance information that are commensurate with the stated assurance level MUST be included in business agreements and operating policies.
Citation
IDEF
Page 28