{
  "ConformanceCriteria": [{
    "Description": "When asserting an Employer Originating Agency Identifier (ORI) on behalf of a user, an IDPO or APO shall assert the attribute name correctly, as stipulated in the attribute definition at <a href=\"https://nief.org/attribute-registry/attributes/user/gfipm/EmployerORI/2.0/\">https://nief.org/attribute-registry/attributes/user/gfipm/EmployerORI/2.0/<\/a>. In addition, an IDPO or APO shall assert ORI attribute values in a manner that: (1) conforms to FBI CJIS ORI attribute value format requirements, and (2) faithfully and accurately conveys the latest Employer ORI information currently known by the IDPO or APO about the user.",
    "Number": 1,
    "Citations": [],
    "$id": "criterion1",
    "Name": "Attribute Validity"
  }],
  "AssessmentSteps": [
    {
      "ConformanceCriteria": [{"$ref": "#criterion1"}],
      "Artifacts": [{
        "Description": "Provide a sample of a technical protocol assertion (e.g., JSON, XML, SAML, OIDC, etc.) correctly using this attribute.",
        "Name": "Sample"
      }],
      "Description": "Does the organization correctly assert the ORI attribute in accordance with the established attribute format rules for the Federated ICAM protocol(s) and conformance or interoperability profile(s) that it uses? Also, does the organization appear to assert attribute values correctly for this attribute?",
      "Number": 1,
      "$id": "Usage",
      "Name": "Usage"
    },
    {
      "ConformanceCriteria": [{"$ref": "#criterion1"}],
      "Artifacts": [{
        "Description": "A list of all ORI codes the IDPO will assert for their users.  This may be a single organizational ORI code, but many IDPOs support users from numerous Law Enforcement Agencies.  In this case the IDP should provide a list of all supported agency ORIs and the assessor should validate that list.",
        "Name": "ORI Code List"
      }],
      "Description": "Has the organization provided all ORI codes it will assert for this attribute, and have all codes been validated?",
      "Number": 2,
      "$id": "Provenance",
      "Name": "Provenance"
    }
  ],
  "$TMF_VERSION": "1.4",
  "IssuanceCriteria": "yes(ALL)",
  "Metadata": {
    "PublicationDateTime": "2017-11-21T00:00:00.000Z",
    "TargetRecipientDescription": "Identity Provider Organizations (IDPOs) and Attribute Provider Organizations (APOs) that intend to assert Federated ICAM attributes in a manner that conforms to the attribute assertion requirements stipulated by NIEF.",
    "Description": "Specifies requirements for Identity Provider Organizations (IDPOs) that wish to assert Employer Originating Agency Identifier (ORI) codes on behalf of their users. Note that all ORI codes asserted by IDPOs in association with trustmarks issued under this TD should be approved by the Federal Bureau of Investigation (FBI) Criminal Justice Information Services (CJIS) Division.",
    "Keywords": [
      "NIEF",
      "National Identity Exchange Federation",
      "Attributes",
      "NIEF Attributes",
      "Identity Provider Organization",
      "IDPO",
      "Attribute Provenance",
      "Attribute Provider Organization",
      "APO",
      "Interoperability",
      "ORI"
    ],
    "ExtensionDescription": "This Trustmark Definition requires no extension data.",
    "Name": "NIEF Employer ORI Attribute",
    "Identifier": "https://trustmark.nief.org/tpat/tds/nief-employer-ori-attribute/1.0/",
    "TargetProviderDescription": "Trustmark Providers that are capable of issuing Federated ICAM interoperability trustmarks. Note that the Trustmark Provider must have a access to a fully functional Federated ICAM test federation to perform the necessary assessment steps for this trustmark.",
    "ProviderEligibilityCriteria": "Any organization or business entity may act as a Trustmark Provider for trustmarks under this Trustmark Definition.",
    "Version": "1.0",
    "TrustmarkRevocationCriteria": "For any trustmark issued under this Trustmark Definition, the Trustmark Provider must revoke the trustmark upon any condition whereby one or more Conformance Criteria cease to be satisfied, unless the trustmark contains appropriate documentation of that condition in accordance with the exception reporting requirements specified by the Trustmark Framework Technical Specification.",
    "LegalNotice": "This document and the information contained herein is provided on an \"AS IS\" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.",
    "TargetRelyingPartyDescription": "Federated ICAM Relying Parties that require assurances about the quality of attributes asserted by NIEF IDPOs and APOs.",
    "TargetStakeholderDescription": "Identity Provider Organizations (IDPOs) and Attribute Provider Organizations (APOs) within the NIEF community, as well as Federated ICAM Relying Parties that require assurances about the quality of attributes asserted by NIEF IDPOs and APOs.",
    "AssessorQualificationsDescription": "Any individual employed or contracted by the Trustmark Provider may act as the assessor for trustmarks under this Trustmark Definition.",
    "TrustmarkDefiningOrganization": {
      "Identifier": "https://nief.org/",
      "PrimaryContact": {
        "Email": "help@nief.org",
        "Kind": "PRIMARY",
        "WebsiteURL": "https://nief.org/",
        "Responder": "NIEF Support"
      },
      "Name": "NIEF"
    }
  },
  "Terms": [
    {
      "Definition": "An applied research program in federated identity and credential management that was initiated in 2005 as part of the Global Justice Information Sharing Initiative. The GFIPM program sought to develop secure, scalable, and cost-effective technologies for information sharing within the law enforcement and criminal justice communities.",
      "Abbreviations": ["GFIPM"],
      "Name": "Global Federated Identity and Privilege Management"
    },
    {
      "Definition": "A software entity that performs user authentication each time an individual presents themselves to a federated identity trust framework or issues user assertions about the individual for a given information technology session. These user assertions are presented to systems deployed by Service Provider Organizations (SPOs) in a federated identity trust framework for the purposes of access control and audit.",
      "Abbreviations": ["IDP"],
      "Name": "Identity Provider"
    },
    {
      "Definition": "An organization that vets individuals, collects attributes about these individuals, and maintains those attributes in an accurate manner. The IDPO may operate one or more Identity Provider (IDP) systems in a federated identity trust framework.",
      "Abbreviations": ["IDPO"],
      "Name": "Identity Provider Organization"
    },
    {
      "Definition": "A collection of agencies in the U.S. that have come together to share sensitive law enforcement information.",
      "Abbreviations": ["NIEF"],
      "Name": "National Identity Exchange Federation"
    },
    {
      "Definition": "A collection of attribute definitions that are intended for use by organizations and communities that wish to implement Federated Identity, Credential, and Access Management (ICAM) technologies within the context of the National Identity Exchange Federation (NIEF).",
      "Name": "NIEF Attribute Registry"
    }
  ],
  "$Type": "TrustmarkDefinition",
  "Sources": []
}