ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
Evidence request list. 41 controls, 41 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Audit
Maintain audit trails for enrolment, credential lifecycle, and authentication events with integrity protection.
- audit log inventory
- log integrity controls (signing, WORM)
- retention schedule
- audit log review records
- logs not integrity protected
- retention shorter than incident detection window
- logs not reviewed proactively
Subject CSP and RA operations to independent assessment confirming claimed LoA is supported by controls.
- independent assessment reports
- assessor qualifications
- scope definitions
- corrective action plans
- assessor not independent
- scope excludes critical processes
- findings not closed before next assessment
Authentication
Use authentication protocols resistant to relevant threats including replay, eavesdropping, and man in the middle.
- protocol selection rationale
- threat resistance matrix
- channel binding evidence
- protocol version inventory
- legacy protocols still active
- channel binding absent
- no MitM protection for LoA 3 and above
Require multi factor authentication at LoA 3 and 4 combining factors from different categories (knowledge, possession, inherence).
- MFA enforcement configurations
- factor diversity verification
- bypass exception register
- step up authentication logs
- two factors from same category (two knowledge)
- MFA bypass for help desk too broad
- step up not used for risky actions
Manage authenticated sessions with binding to authenticator, timeout, and reauthentication for sensitive actions.
- session policy
- session token security analysis
- timeout configurations
- reauthentication trigger list
- session tokens long lived without binding
- no reauthentication for privilege changes
- logout incomplete
Clause 1-4: Framework Introduction
Framework for managing entity authentication assurance in a given context
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Terms related to entity authentication, levels of assurance, credential service providers, and authentication factors
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Abbreviations used in the entity authentication assurance framework
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Clause 10: Criteria and Controls for Levels of Assurance
Criteria for identity proofing at each LoA including evidence requirements and verification methods
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Criteria for credential issuance, renewal, revocation, and storage at each LoA
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Criteria for authentication mechanisms and protocols at each LoA
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Criteria for federation protocols and authentication assertions at each LoA
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Clause 11-12: Mapping and Guidance
Guidance for mapping other authentication assurance schemes to the four LoAs
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Guidance for exchanging authentication results that are based on the four LoAs
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Guidance on controls that should be used to mitigate authentication threats at each LoA
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Clause 5-6: Framework Overview and Context
Overview of the entity authentication assurance framework and its components
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Phases of entity authentication including enrollment, credential management, and authentication
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Factors that determine the required level of authentication assurance in a given context
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Clause 7-8: Levels of Assurance
Little or no confidence in the asserted identity; minimal requirements for authentication
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Some confidence in the asserted identity; single-factor authentication with basic identity proofing
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
High confidence in the asserted identity; multi-factor authentication with strong identity proofing
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Very high confidence in the asserted identity; hard cryptographic token required with in-person identity proofing
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Clause 9: Threats to Authentication
Overview of threats to the entity authentication process across all phases
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Threats during the enrollment and identity proofing phase including impersonation and forgery
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Threats to credential issuance, storage, and revocation including credential theft and compromise
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Threats during the authentication event including replay attacks, man-in-the-middle, and session hijacking
- Identity proofing procedure
- Credential issuance and revocation log
- Authentication assurance level mapping
- Federation and assertion configuration records
- Threat assessment for authentication flows
- Identity proofing relies on single attribute checks
- Credential revocation not timely
- LoA selection not risk-based
- Federation assertions lack signing and replay protection
Credential Management
Manage credentials through issuance, renewal, suspension, revocation, and destruction with LoA appropriate controls.
- lifecycle policy
- renewal procedures
- revocation logs
- destruction evidence
- revocation latency excessive
- destruction unverified for hardware tokens
- renewal does not reverify identity
Bind authenticators to the identity established during enrolment with integrity protected records.
- binding records
- rebinding procedures for lost authenticators
- binding integrity controls
- audit trail of binding events
- rebinding does not require reproofing
- binding records mutable
- no detection of unbound authenticator use
Enrolment
Apply enrolment controls including identity proofing and credential issuance proportionate to required LoA.
- enrolment procedures by LoA
- identity proofing evidence retention policy
- credential issuance logs
- registration authority approvals
- LoA 3 enrolment performed remotely without compensating controls
- evidence retention shorter than credential lifetime
- RA training not refreshed
Federation
When federating identities across providers, ensure LoA is preserved or appropriately downgraded with relying party awareness.
- federation agreements
- LoA mapping between providers
- assertion content specifications
- relying party LoA awareness mechanism
- LoA elevated in transit (federation claims higher than source)
- assertion does not convey LoA
- RP cannot distinguish LoAs
Apply privacy controls to authentication including minimal attribute disclosure and pseudonymisation where appropriate.
- attribute minimisation policy
- pseudonymous identifier use
- PII disclosure in assertions audit
- consent for attribute release
- full identity disclosed when pseudonymous sufficient
- no consent for attribute release
- logs reveal PII across RPs
Foundation
Determine required Level of Assurance (LoA 1 to 4) based on risk analysis of authentication failure consequences.
- risk assessment per relying service
- LoA determination matrix
- consequence categories table
- selection justification document
- LoA selected by IT preference not risk
- consequence categories ignore non financial harm
- no periodic LoA reconfirmation
Identity Proofing
LoA 1 self assertion of identity is sufficient with no verification required of asserted attributes.
- LoA 1 use case justifications
- self assertion capture mechanisms
- limitations notice to relying parties
- LoA 1 service inventory
- LoA 1 used for higher consequence transactions
- relying parties unaware of LoA limitations
- no escalation path to higher LoA
LoA 2 requires verification of at least one valid identity evidence with single factor authentication.
- acceptable evidence list for LoA 2
- verification logs
- evidence validation methods (issuer verification)
- fraud detection results
- evidence accepted without issuer verification
- fraud detection limited to format checks
- no liveness for remote proofing
LoA 3 requires two strong identity evidences verified against authoritative sources plus multi factor authentication.
- LoA 3 evidence requirements
- authoritative source verification logs
- biometric or in person checks
- MFA enrolment records
- only one strong evidence verified
- authoritative source replaced with commercial database
- MFA enrolment over single channel
LoA 4 requires in person proofing or equivalent, multiple strong evidences, and hardware based credentials.
- in person proofing records
- hardware token issuance logs
- trusted referee procedures if remote
- tamper evident credential storage
- in person waived without equivalence analysis
- hardware tokens shipped insecurely
- trusted referee training absent
Operations
Document operating procedures for all authentication services including incident response and exception handling.
- procedures library
- incident playbooks
- exception handling workflows
- version control records
- procedures tribal knowledge
- incident playbooks untested
- exceptions not logged
Provider Assurance
Credential Service Providers demonstrate operational, technical, and management assurance commensurate with offered LoA.
- CSP audit reports
- operational procedures
- management commitment evidence
- personnel screening records
- CSP self attestation not externally audited
- personnel screening waived for contractors
- operational procedures outdated
Registration Authorities operate with documented procedures, trained personnel, and audit trails for enrolment decisions.
- RA procedures manual
- RA training records
- enrolment decision logs
- RA audit reports
- RA decisions not logged with reasoning
- RA training one off (no refresh)
- no four eyes for LoA 4 enrolment
Threats
Map authentication threats to mitigations across enrolment, credential management, and authentication phases.
- threat catalogue
- threat to control mapping
- residual threat acceptance
- threat update process
- catalogue not refreshed for credential stuffing or SIM swap
- mappings high level not specific
- residual threats not formally accepted
Detect authentication fraud through anomaly monitoring and respond with credential actions and investigation.
- fraud detection rules
- anomaly monitoring dashboard
- investigation procedures
- fraud reporting metrics
- fraud rules static for years
- no behavioural analytics
- investigation outcomes not fed back to rules
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.