In-Person Authentication On Behalf Of A PKI Registration Authority (RA), v1.0

Addresses requirements for in-person authentication for PKI registration to be performed on behalf of a registration authority by an authorized entity.
If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Step

1
In-Person Authentication On Behalf Of A PKI Registration Authority (RA) (In-PersonAuthenticationOnBehalfOfAPKIRegistrationAuthorityRA)
If the organization permits entities certified by a State or Federal Entity as being authorized to confirm identities on behalf of the RA, is the information collected from the applicant forwarded directly to the RA in a secure manner (including but not limited to packages secured in a tamper-evident manner)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Secure Forwarding Typerequired
ENUM_MULTI : Select the acceptable type\(s\) of secure forwarding of applicant information to the RA.
  • Tamper Evident Packaging
  • Other
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (1)

C1
An entity certified by a State or Federal Entity as being authorized to confirm identities may perform in-person authentication on behalf of the RA. The certified entity forwards the information collected from the applicant directly to the RA in a secure manner. Packages secured in a tamper-evident manner by the certified entity satisfy this requirement; other secure methods are also acceptable. Such authentication does not relieve the RA of its responsibility to verify the presented data.
Citation
FBCA-CP
Section 3.2.3.1