cds-snc / cds-snc/platform-forms-client
Clearly document GC Forms level of assurance (LoA)
- Dominant language
- TypeScript
- Stars
- 46
- Forks
- 16
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 85
Description
## Description:
Clearly document GC Forms level of assurance (LoA) -- so it’s easier to reference
> Level of assurance 3 (LoA3) for CCCS Medium, also for AWS infrastructure
## Context
- Related to SSO IA-5(11): Authenticator Management | Hardware Token-based Authentication https://github.com/cds-snc/platform-core-services/issues/1046
- if you have hardware tokens, you need to meet certain requirements, these depend on the assurance level looking to achieve, PKI vs. FIDO compliant to build on memorized password
- targeting medium, medium, medium risk level (see SoS)
- identity assurance level (IAL) Level of Assurance (LoA) 3
- defend against threat determination level TD-4
## Lenses
- SA&A lens: CCCS MEDIUM, PBMM, specific assurance levels, threat that you want to defend against
- Policy lens: Compliance angle, may or may not have to meet specific assurance level
- Risk context: consideration for larger risk perspective, boundaries, impact, and likelihood
- Organization level: Federal Information Processing Standards (FIPS) requirements, depends on organizational risk appetite (SoS), two-factors to reach LoA-3 (password + hardware token)
Contributor guide
Assessment
This issue has not been assessed yet.