| 1 |
Low |
This level is relevant to environments
where Risks and consequences of data Compromise are
low. Subscriber Private Keys shall be stored in
software at this Identity Assurance Level (IAL). |
| 2 |
LowDevice |
This policy is identical to that defined
for the Low Assurance policy (above) with the exception
of identity proofing, re-key, and Activation Data. |
| 3 |
Low-TSP Mediated Signature |
This policy is identical to that defined
for the Low Assurance policy (above) with the exception
that the Private key is not in the possession of the user,
but rather by a Trust Service Provider. |
| 4 |
Medium |
This level is relevant to environments
where Risks and consequences of data Compromise are
moderate. This may include transactions having substantial
monetary value or Risk of fraud or involving access to
private information where the likelihood of malicious
access is substantial.
Subscriber Private Keys shall be stored in software at
this IAL. |
| 5 | MediumDevice |
This policy is identical to that defined
for the Medium Assurance policy (above) with the exception
of identity proofing, re-key, and Activation Data. |
| 6 |
Medium-TSP Mediated Signature |
This policy is identical to that defined
for the Medium Assurance policy (above) with the exception
that the Private key is not in the possession of the user,
but rather by a Trust Service Provider. |
| 7 |
MediumHardware |
This policy is identical to that defined
for the Medium Assurance policy (above) with the exception
of Subscriber Cryptographic Module requirements described
in . |
| 8 |
MediumDeviceHardware |
This policy is identical to that defined
for the Medium Hardware Assurance policy (above) with the
exception of identity proofing, re-key, and Activation
Data. |
| 9 |
High |
This level is relevant to environments
where Risks and consequences of data Compromise are high.
Certificates issued at the High-cardAuth IAL shall only
be issued for Card Authentication, as defined by NIST SP
800-73 or equivalent standard.
Further, this policy is identical to that defined for
the identical to the MediumHardware IAL except where
specifically noted in . |
| 10 |
High-CardAuth |
This level is relevant to environments
where Risks and consequences of data Compromise are high.
Certificates issued at the High-cardAuth IAL shall only
be issued for Card Authentication, as defined by NIST SP
800-73 or equivalent standard. |
| 11 |
High-ContentSigning |
This level is relevant to environments
where Risks and consequences of data Compromise are High.
This may include transactions having substantial monetary
value or Risk of fraud or involving access to private
information where the likelihood of malicious access is
substantial.
Certificates issued at the High IAL shall only be issued
to human Subscribers.
Certificates issued at the High-contentSigning IAL shall
only be issued to the CMS for signing the HIGH card
security objects (e.g. Certificates, CRLs, OCSP
responses).
Further, this policy is identical to that defined for
the identical to the MediumHardware IAL except where
specifically noted in . |