Skip to Content.
Sympa Menu

assurance - Re: [Assurance] silver and two-factor ...

Subject: Assurance

List archive

Re: [Assurance] silver and two-factor ...


Chronological Thread 
  • From: Tom Scavo <>
  • To:
  • Subject: Re: [Assurance] silver and two-factor ...
  • Date: Tue, 13 Mar 2012 15:13:21 -0400 (EDT)



> Imagining the future... If an institution qualified at Gold
> assurance (LoA 3), would that automatically qualify the institution
> at Silver?

That depends on how Gold is defined. For example, consider the relationship
between Bronze and Silver. Every Bronze requirement is covered by some
requirement of Silver, so in that sense, Silver implies Bronze. Put another
way, if an IdP has a Silver qualifier in metadata, then that IdP also has a
Bronze qualifier in metadata.

> If a service required Silver assurance I'm assuming a Gold assurance
> should be acceptable in lieu of a Silver assurance.

Again, it depends on how Gold is defined. If Gold is a true superset of
Silver, then the answer is yes, of course.

> I wonder how close these two institutions would be to a Gold spec
> considering their existing policy/procedure that uses two-factor?

Since there is no Gold spec, one can only speculate. It is becoming
increasingly clear that there are use cases that lie outside of the
Bronze/Silver/Gold hierarchy (I can give at least two examples). Whether
there are a significant number of such outliers, I don't know, only time will
tell.

Tom



Archive powered by MHonArc 2.6.16.

Top of Page