FB pixel

NIST finalizes first full Digital Identity Guidelines update since 2017

Adds passkeys, digital wallets, risk management context, biometrics alternatives
NIST finalizes first full Digital Identity Guidelines update since 2017
 

The U.S. National Institute of Standards and Technology has finalized the update of its digital identity guidelines to incorporate new technologies including digital wallets and passkeys.

Revision 4 of NIST’s Digital Identity Guidelines, SP 800-63-4, is the first completed update since 2017. The guidelines are intended to direct agencies on how to manage risk within the context of digital identity programs.

In addition to advice on how to integrate digital wallets and passkeys, the guidelines also provide new advice on setting context for risk management, measuring continuous evaluation and identity proofing processes, and adds controls to address identity fraud through the use of injection attacks to deliver deepfakes. They also more clearly define roles and types of identity proofing and emphasize the importance of providing alternatives to face biometrics in the process.

“And…for those of you looking for it, since we know you are out there, changes to the password composition and rotation expectations are also included in the document,” write NIST Digital Identity Program Lead for the Applied Cybersecurity Division Ryan Galluzzo, NIST IT Lab Senior Technology Policy Advisor Connie LaSalle and NIST Computer Security Division Project Lead for Applied Cryptography Andrew Regenscheid in a blog post on the changes. “All these changes represent an extensive update from NIST SP 800-63 Revision 3 — drawing heavily from real-world lessons and innovations.”

Electrosoft supported the finalization of NIST’s digital identity guidelines under a contract awarded last October. A draft was published in August for review, when previous versions released since 2022 had already received 4,000 comments from 140 organizations.

NIST is already developing implementation resources to go with the Guidelines, and also exploring setting criteria for machine-readable conformance and creating a Digital Identity Risk Management tool, according to the post.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Socure brings Aeropay into RiskOS to connect identity verification with bank payments

Socure is extending its RiskOS platform further into payments through an integration with Aeropay that combines identity verification, bank account…

 

trinamiX accuses Apple of infringing Face ID skin-detection patents

Germany-based BASF subsidiary trinamiX has sued Apple in U.S. federal court, alleging that Face ID technology in newer iPhones and…

 

Florida modernizes driver’s license enrollment with Veridos biometric capture

Florida is modernizing the enrollment process behind its driver’s licenses and state IDs, deploying new biometric capture equipment to standardize…

 

Tobago launches sub-national digital ID for public service access

A digital ID system dubbed Tobago ID to ease access to services has been launched for residents of the island…

 

Unico responds to ‘DIY Deepfakes,’ fraud spike with authentication orchestration

Unico has put numbers to the dramatic rise in volume of sophisticated and AI-powered fraud attempts this year, and introduced…

 

Gabon turns to Rwanda for digital identity, government expertise

Gabon has reached out to Rwanda for collaboration on the implementation of a digital government ecosystem as the Central African…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events