Identity Proofing - No Social Security Number, v3.0

Requirements to avoid using Social Security Numbers (SSN) for identity proofing and resolution.

Assessment Step

1
SSN (SSN)
Does the CSP not collect SSNs? Or if it does collect them, does it have a very well documented requirement to do so?
Artifact
Documentation
Provide policies and practices indicating conformance.

Conformance Criteria (1)

SSN
The CSP SHOULD NOT collect the Social Security Number (SSN) unless it is necessary for performing identity resolution, and identity resolution cannot be accomplished by collection of another attribute or combination of attributes.
Citation
SP800-63A
Section 4.2 P13