NIEF Sworn Law Enforcement Officer Indicator Attribute, v1.0

Specifies requirements for Identity Provider Organizations (IDPOs) that wish to assert the National Identity Exchange Federation (NIEF) Sworn Law Enforcement Officer (SLEO) Indicator attribute on behalf of their users.

Assessment Steps (2)

1
Usage (Usage)
Does the organization correctly assert the SLEO attribute in accordance with the established attribute format rules for the Federated ICAM protocol(s) and conformance or interoperability profile(s) that it uses? Also, does the asserted attribute name align with the attribute definition provided in the NIEF Attribute Registry? See https://nief.org/attribute-registry/attributes/user/gfipm/SwornLawEnforcementOfficerIndicator/2.0/.
Artifact
Sample
Provide a sample of a technical protocol assertion (e.g., JSON, XML, SAML, OIDC, etc.) correctly using this attribute.
2
Provenance (Provenance)
Does the organization assert the SLEO attribute appropriately? Provide details on how the organization asserts this attribute in a manner that aligns with the requirements as per the attribute's definition.
Artifact
SLEO Users
Provide details on the users for whom SLEO is asserted and provide clarity on how the organization certifies SLEOs.

Conformance Criteria (1)

Attribute Validity
When asserting the NIEF Sworn Law Enforcement Officer (SLEO) Indicator on behalf of a user, an IDPO or APO shall assert the attribute name correctly, in accordance with the attribute definition as stipulated at https://nief.org/attribute-registry/attributes/user/gfipm/SwornLawEnforcementOfficerIndicator/2.0/. In addition, an IDPO or APO shall assert attribute values for the SLEO Indicator attribute as follows.
  1. When asserting the SLEO Indicator attribute, an IDPO or APO may assert an attribute value of 'true' for a user if all of the following conditions are true.
    1. The user is a full time employee of a state-recognized law enforcement agency.
    2. The user is authorized (has the authority) to make an arrest.
    3. The user is certified by a State Certifying Authority (i.e., Peace Officer Standards and Training (POST)), or equivalent.
  2. Alternatively, an IDPO or APO may assert an attribute value of 'true' for a user if the user is a full time employee of a state-recognized law enforcement agency, acting on behalf of a SLEO, in performance of the user's assigned duties.