Appropriate Access: Levels of Assurance

Added by the EDUCAUSE Librarian
Title:Appropriate Access: Levels of Assurance (ID: CAMP08115)
Author(s):Stefan Wahe (University of Wisconsin-Madison) and David L. Wasley (University of California Office of the President)
Topics:Access Control, Authentication, Authorization, Identity Management, Security Risk Assessment and Analysis
Origin:Contributed by EDUCAUSE Grant Programs (CAMP) (02/13/2008)
Type:Presentations/Speeches
Abstract:

A level of assurance (LoA) refers to the degree of certainty that (1) a resource owner has that a person's physical self has been adequately verified before credentials are issued by a registration authority, and (2) a user indeed owns the credentials they are subsequently presenting to access the resource. The requirements for the level of certainty at both ends of that set of transactions should be driven by a risk assessment based on the value of the resources being protected. This session will describe the concept of LoA, discuss its importance, outline its technical components, and discuss the proposition that roles of the identity management and security staff are critical for a successful implementation of LoA.

View this resource: