NIEF Simple Attribute, v1.0

Specifies requirements for Identity Provider Organizations (IDPOs) that wish to assert simple National Identity Exchange Federation (NIEF) attributes for Federated ICAM on behalf of their users.

Assessment Steps (2)

1
Usage (Usage)
Does the organization correctly assert this attribute in accordance with the established attribute format rules for the Federated ICAM protocol(s) and conformance or interoperability profile(s) that it uses? Also, does the organization appear to assert attribute values correctly for this attribute?
Artifact
Sample
Provide a sample of a technical protocol assertion (e.g., JSON, XML, SAML, OIDC, etc.) correctly using this attribute.
Parameter
NIEF Attributesrequired
ENUM_MULTI : Select the attributes that this CSP/IDP asserts for their users.
  • https://nief.org/attribute-registry/attributes/user/gfipm/GivenName/2.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/SurName/2.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/EmailAddressText/2.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/FederationId/2.0/
  • https://nief.org/attribute-registry/attributes/user/nief/UniqueSubjectId/1.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/TelephoneNumber/2.0/
  • https://nief.org/attribute-registry/attributes/user/nief/IdentityProviderId/1.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/IdentityProviderId/2.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/EmployerName/2.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/EmployerOrganizationGeneralCategoryCode/2.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/EmployerStateCode/2.0/
  • https://nief.org/attribute-registry/attributes/user/gfipm/LocalId/2.0/
2
Provenance (Provenance)
Does the organization have an appropriate authoritative source for this attribute?
Artifact
Attribute Provenance
Provide details on how the organization sources the attribute from an authoritative source.

Conformance Criteria (1)

Attribute Validity
When asserting a Federated ICAM attribute on behalf of a user, an IDPO or APO shall assert the attribute name correctly, in accordance with the appropriate attribute definition. In addition, an IDPO or APO shall assert attribute values for the attribute in a manner that: (1) conforms to the attribute value format requirements stipulated in the appropriate attribute definition, and (2) faithfully and accurately conveys the latest information currently known by the IDPO or APO about the user with respect to the attribute at the time the assertion is made, regardless of whether that information is based on the contents of a local database, a local policy or procedure that applies to the user, or other source.