[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-191578-105":53,"doc-detail-191578-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","w_turbeville-identity-assurance-and-risk-management-comments","W_Turbeville - Identity Assurance and Risk Management Comments","","The content presents structured commentary on NIST identity assurance and related risk management requirements across multiple sections, citing specific concerns about terminology consistency, requirements precedence, and the adequacy of guidelines. It emphasizes the need for clear hierarchy for normative provisions, suggests KPI and auditing mechanisms to measure tailoring effectiveness, and proposes metrics such as fraud rates, pass/fail outcomes, abandonment, verification time, and total cost per user. It also highlights practical issues around identity resolution, validation, and verification for users lacking records, advocating biometrics and additional technical checks like device-based and geofenced controls.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":41,"@type":70,"position":76},"https://docshare.wps.com/template/letters/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/w_turbeville-identity-assurance-and-risk-management-comments/191578/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/w_turbeville-identity-assurance-and-risk-management-comments/191578.png","ImageObject",442,249,{"name":88,"@type":89},"Valentina","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-29","2026-09-03",true,{"@type":98,"interactionType":99,"userInteractionCount":79},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What clarification does the draft request regarding requirements precedence?","Question",{"text":108,"@type":109},"The comments ask how the NIST RMF and requirement tailoring relate to other normative requirements, including whether one approach supersedes others when Trusted Referees make risk-based decisions.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What KPI measurement framework is recommended for tailoring adoption?",{"text":113,"@type":109},"The comments recommend KPI tracking with auditing mechanisms, including pass rates net of fraud, fail/unsuccessful rates, abandonment rates, fraud rates, time spent verifying, and cost per user based on total cost of ownership.",{"name":115,"@type":106,"acceptedAnswer":116},"How should identity resolution and validation be handled when users are not present in records?",{"text":117,"@type":109},"The comments argue that identity resolution and validation may be impossible without additional methods, advocating biometrics and other checks (including device-based and geofencing) to establish an inception point and mitigate synthetic or malicious identity risks.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},191578,1790638523,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":40,"category_name":41,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":79,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":140,"read_time":76},13056703020460,"https://ap-avatar.wpscdn.com/avatar/be000253dac470eee5d?_k=1778207105932848923","| Organization: | [ID.me](ID.me) |\n| --- | --- |\n| Name of Submitter/POC: | Wes Turbeville |\n| Email Address of Submitter/POC:  |  |\n\n\n| Comment \\# | Publication\u003Cbr>(Base, 63A, 63B, 63C) | Section | Page \\# | Line \\# | Comment\u003Cbr>(Include rationale for comment) | Suggested Change |\n| --- | --- | --- | --- | --- | --- | --- |\n| 1 | 63-Base | N/A | N/A | N/A | Clarification from NIST is sought regarding the order of precedence for requirements listed throughout the draft. For example, the main document discusses use of the NIST RMF and tailoring of requirements. Does that supersede normative requirements in other areas (e.g. 63A)? Additionally there are other elements such as allowing Trusted Referees to make risk based decisions on criteria. Does that supersede other normative requirements? Establishing a hierarchy would add clarity greatly aid in conformity assessments.\u003Cbr>As an example of one area where this is the case is [2.4.2.3](2.4.2.3). As written, NIST makes it sound as though CSPs have no alternatives to complete verification for users whose:\u003Cbr>-core attributes cannot be validated in credible or authoritative sources\u003Cbr>- information on submitted evidence can’t be validated in credible or authoritative sources |  |\n| 2 | 63-Base | 3 | 24 | 1030 | To promote effective risk management processes, NIST should require any agency or CSP considering adoption of “tailoring” to adopt a KPI measurements framework with auditing mechanisms\u003Cbr>The key metrics to measure include: pass rates net of fraud, fail / unsuccessful rates, abandonment rates, fraud rates, time spent verifying, and cost per user.\u003Cbr>-Note, cost per user should consider the “total cost of ownership” of the user’s access – verification costs, authentication costs, end-user support costs, and fraud losses\u003Cbr>These metrics can then be sliced by demographic groups and tracked over time to assess how an agency’s Risk Management process is performing and how its decisions are impacting the beneficiaries of the agency.\u003Cbr>These metrics could be independently assessed by an organization such as Kantara. They could be used to:\u003Cbr>- Inform policy decisions by OMB\u003Cbr>- Inform technical guidance from NIST on the effectiveness of different compensating controls or verification methods in different situations\u003Cbr>-Support accountability and transparency activities from Inspector Generals or Government Accountability Office (GAO) |  |\n| 3 | 63A | 1.2 | 2 | 416 | For IAL1, [ID.me](ID.me) has several points:\u003Cbr>The impact of changing the definition of a term used in previous NIST drafts is non-negligible. Data structures used by CSPs and identity proofing vendors reference NIST in terms of language and meaning. When the same term changes in terms of meaning, this has downstream implications that impacts industry negatively. We encourage NIST to be consistent when it comes to language and meaning.\u003Cbr>We remind NIST that NIST removed the concept of NIST 800-63-2 Level of Assurance 2, which would bethe legacy equivalent of what is proposed for Identity Assurance Level 1 here, precisely because agencies had applied the NIST 800-63-2 Level of Assurance 2 controls to high-risk programs that should have been protected by Level of Assurance 3. The result was a series of high profile scaled data breaches where the vulnerability exploited was identity proofing and specifically Knowledge Based Authentication. Financial losses to taxpayers were significant and tens of thousands to hundreds of thousands of Americans were impacted for each incident. Without strict, consistent, and clear guidelines for when IAL1 is appropriate and when it is not appropriate, we see history repeating itself ina negative way with NIST 800-63-4. Our assessment is that the approach is well-intended but poorly executed in terms of guidelines. This is a general observation we will support with specific comments later in the text. | Keep IAL1 defined as is, and call the-4’s IAL1 proofing a different term. |\n| 4 | 6","cbCaiugtX73JNUry","https://ap.wps.com/l/cbCaiugtX73JNUry","pdf",334507,9,"English","# Comment Log\n## Requirements precedence and tailoring\n## KPI measurement and auditing mechanisms\n## Identity assurance level guidance and terminology\n## Identity resolution, validation, and verification methods","[{\"question\":\"What clarification does the draft request regarding requirements precedence?\",\"answer\":\"The comments ask how the NIST RMF and requirement tailoring relate to other normative requirements, including whether one approach supersedes others when Trusted Referees make risk-based decisions.\"},{\"question\":\"What KPI measurement framework is recommended for tailoring adoption?\",\"answer\":\"The comments recommend KPI tracking with auditing mechanisms, including pass rates net of fraud, fail/unsuccessful rates, abandonment rates, fraud rates, time spent verifying, and cost per user based on total cost of ownership.\"},{\"question\":\"How should identity resolution and validation be handled when users are not present in records?\",\"answer\":\"The comments argue that identity resolution and validation may be impossible without additional methods, advocating biometrics and other checks (including device-based and geofencing) to establish an inception point and mitigate synthetic or malicious identity risks.\"}]","W_Turbeville - Identity Assurance and Risk Management Comments | PDF",1788409452]