Credential Service Provider |
CSP
|
An equivalent term for an Identity Provider Organization (IDPO). |
Federated Identity, Credential, and Access Management |
Federated ICAM
|
Describes activities involving the reuse of previously issued local credentials, such that end-users can use those locally issued credentials to access remote resources through a federated "Single Sign-On" (SSO) protocol. |
ICAM Attribute |
|
A piece of data about an end-user that can be transmitted from one system to another, for the purpose of enabling the receiving system to make access control decisions and take other actions (e.g., audit logging) related to that end-user. |
Identity Provider Organization |
IDPO
|
An organization that vets individuals, collects attributes about these individuals, and maintains those attributes in an accurate manner. An IDPO typically operates one or more Identity Provider (IDP) systems that support a Single Sign-On (SSO) protocol such as the Security Assertion Markup Language (SAML) or OpenID Connect (OIDC). An IDPO is also sometimes called a Credential Service Provider (CSP). |
Identity, Credential, and Access Management |
ICAM
|
Describes acitivites related to identify-proofing end-users, issuing authentication credentials to end-users, lifecycle-managing the issued credentials, and using the issued credentials as part of a strategy whereby end-users' access to sensitive resources is controlled in accordance with applicable policies. |
Personally Identifiable Information |
PII
|
Information which can be used to distinguish or trace an individual's identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother's maiden name, etc. |
Service Provider Organization |
SPO
|
An organization that manages one or more sensitive data resources or applications, and offers access to those resources or applications for federated users from partner organizations, subject to applicable access controls. An SPO typically operates one or more Service Provider (SP) systems that support a Single Sign-On (SSO) protocol such as the Security Assertion Markup Language (SAML) or OpenID Connect (OIDC). |