ICAM Privacy - Appropriate ICAM Attribute Usage, v1.0

Defines privacy requirements related to the use of ICAM attributes requested and received during Federated ICAM transactions.

Assessment Step

1
ICAM Privacy - Appropriate ICAM Attribute Usage (ICAMPrivacy-AppropriateICAMAttributeUsage)
Does the organization use requested ICAM attributes only for the purposes of making authorization decisions, dynamically provisioning accounts, or performing audit logging?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (1)

C1
An organization MUST use requested ICAM attributes only for the purposes of making authorization decisions, dynamically provisioning accounts, or performing audit logging.
Citation
NIEFPP
Section 4: NIEF Privacy Policy Rules, Item 6: Appropriate ICAM Attribute Request and Usage