cds-snc / cds-snc/platform-forms-client

Clearly document GC Forms level of assurance (LoA)

Open
#7,799 1 comment 0 reactions 3 assignees Claimed by @bryan-robitaille View on GitHub
documentation policy security
Dominant language
TypeScript
Stars
46
Forks
16
Avg merge
1d 8h
Merged PRs (30d)
85

Description

## Description:

Clearly document GC Forms level of assurance (LoA) -- so it’s easier to reference
> Level of assurance 3 (LoA3) for CCCS Medium, also for AWS infrastructure

## Context

- Related to SSO IA-5(11): Authenticator Management | Hardware Token-based Authentication https://github.com/cds-snc/platform-core-services/issues/1046
- if you have hardware tokens, you need to meet certain requirements, these depend on the assurance level looking to achieve, PKI vs. FIDO compliant to build on memorized password
- targeting medium, medium, medium risk level (see SoS)
- identity assurance level (IAL) Level of Assurance (LoA) 3
- defend against threat determination level TD-4

## Lenses
- SA&A lens: CCCS MEDIUM, PBMM, specific assurance levels, threat that you want to defend against
- Policy lens: Compliance angle, may or may not have to meet specific assurance level
- Risk context: consideration for larger risk perspective, boundaries, impact, and likelihood
- Organization level: Federal Information Processing Standards (FIPS) requirements, depends on organizational risk appetite (SoS), two-factors to reach LoA-3 (password + hardware token)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.