Nondisclosure of Pairwise Pseudonymous Identifier Mappings, v1.0

When a federation proxy maps a user identifier to a pseudonymous identifier for consumption within a federation that uses pseudonymous identifiers, the proxy must not divulge this mapping except where it is necessary for legal reasons or to the proxied user if he or she requests this information.

Assessment Step

1
Proxied Pseudonymous Identifier Mappings (ProxiedPseudonymousIdentifierMappings)
Do all federation proxies properly protect identifiers from mapping disclosures?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the proxy does not incorrectly disclose the pseudonymous identifier mappings.

Conformance Criteria (1)

C1
The proxy SHALL NOT disclose the mapping between the pairwise pseudonymous identifier and any other identifiers to a third party or use the information for any purpose other than federated authentication, related fraud mitigation, to comply with law or legal process, or in the case of a specific user request for the information.
Citation
NIST SP 800-63C
Section 6.3.1