Attention, Identity Practitioners: Initial NIST SP 800-63-4 Implementation Resources are Now Available!
NIST has rolled out initial implementation resources to support practitioners in navigating the Digital Identity Guidelines. The Resource Hub offers helpful materials including FAQs, conformance criteria, reference architectures, and interactive tools. These are NOT new requirements – they are complementary to the guidelines and help explain the normative requirements in SP 800-63-4, clarify identity concepts, and give examples of how you might approach your own implementation.
The SP 800-63-4 Implementation Resource Hub: What to Expect
The initial resources include the following releases:
-
Frequently Asked Questions (FAQs): NIST provides direct answers to the questions we hear most from agencies and CSPs implementing SP 800-63-4, including topics like authoritative sources, core attributes, password managers, and mDLs. Specific terms can be found through the search bar, or users can select a volume for a multitude of questions already addressed.
-
Conformance Criteria: These are intended to be used by agencies and organizations looking to evaluate products for alignment with the requirements defined in each volume of the Digital Identity Guidelines. To accommodate the broadest possible use, the criteria are offered in three different formats: Excel, PDF, and OSCAL (JSON, XML, and YAML). New to OSCAL? Check out NIST’s learning resources on automated control-based assessment!
-
Subscriber Controlled Wallet (SCW) Model: SCWs (or Digital Wallets) are software apps on smartphones and other devices that securely store electronic versions of credit cards, ID cards, passports, and more. While different types of wallets exist, SP 800-63C-4 addresses digital wallets that are used to manage verifiable digital credentials (VDCs). These implementation resources help clarify the subscriber-controlled wallet model, describe the characteristics of a VDC and mobile driver’s licenses (mDLs), and links directly to the NCCoE mDL Project Pages Site to find reference implementations and best practices for mDL deployments to minimize adoption challenges.
-
Authenticator Examples: This page offers details around different authenticator types for easy reference. The table includes authenticator type, a description, examples, whether the authenticator is replay resistant, and whether it supports phishing resistance.
More Implementation Resources to Come!
NIST’s goal is to provide a centralized hub to best support our stakeholders in implementing the Digital Identity Guidelines. These will be living resources, updated based on feedback from the community to provide new materials, and improve the existing material over time.
These are initial versions of these resources, and we need your input to continually improve them. If you have additional questions, ideas for new resources, or suggested updates, we want to hear them! Please send us an email at: dig-comments@nist.gov or submit a GitHub issue here: open an issue.
NIST Cybersecurity and Privacy Program Questions and comments can be directed to: dig-comments@nist.gov
|