Identity Proofing - Trusted Referee, v3.0

The requirements for a CSP to identity proof Trusted Referees at an equivalent or higher assurance level then that of regular applicants.

Assessment Steps (5)

1
IAL (IAL)
Does the CSP identity proof trusted referees according to the same criteria and at the same IAL or higher to that which applies to normal applicants?
Artifact
Documentation
Provide policies, practices, or existing security audit reports indicating conformance.
2
Determined (Determined)
Does the CSP document how Trusted Referees are determined?
Artifact
Documentation
Provide policies, practices, or existing security audit reports indicating conformance.
3
Lifecycle (Lifecycle)
Does the CSP document the lifecycle by whichTrusted Referees maintain their status as valid referees?
Artifact
Documentation
Provide policies, practices, or existing security audit reports indicating conformance.
4
Restrictions (Restrictions)
Does the CSP document any restrictions as well as revocation and suspension requirements that apply to Trusted Referees?
Artifact
Documentation
Provide policies, practices, or existing security audit reports indicating conformance.
5
Binding (Binding)
Does the CSP document the evidence required to bind Trusted Referees with Applicants?
Artifact
Documentation
Provide policies, practices, or existing security audit reports indicating conformance.

Conformance Criteria (5)

IAL
CSPs SHALL identity-proof Trusted Referees according to the same criteria and, as a minimum, at the same IAL that are applied to normal Applicants on whose behalf they act.
Citation
SP800-63A
Section 4.4.2
Determined
The CSP SHALL document in their Credential Policy how a Trusted Referee is determined.
Citation
SP800-63A
Section 5.3.4 P2
Lifecycle
The CSP SHALL document the lifecycle by which the Trusted Referee retains their status as a valid referee.
Citation
SP800-63A
Section 5.3.4 P2
Restrictions
The CSP SHALL document any restrictions, as well as any revocation and suspension requirements, which are applicable to Trusted Referees.
Citation
SP800-63A
Section 5.3.4 P2
Binding
The CSP SHALL document the minimum evidence required to bind the relationship between the Trusted Referee and the Applicant.
Citation
SP800-63A
Section 5.3.4 P3