Federation Assurance Level (FAL)

The NIST SP 800-63C-4 measure, from FAL1 to FAL3, of how strongly a federation protects the assertion an identity provider sends to a relying party.

Federation assurance level describes the robustness of the federation process: how well the assertion an identity provider sends to a relying party is protected against forgery, replay, injection and misuse. NIST SP 800-63C-4 defines three levels, each including the requirements of the ones below. At FAL1 the identity provider signs the assertion, restricts it to its intended audience, and presents it as a bearer assertion. FAL2 adds strong protection against assertion injection, restricts each assertion to a single relying party, and requires a trust agreement established in advance. FAL3 also requires the subscriber to prove control of an authenticator alongside the assertion, which the document presents as protection against a compromised identity provider.

FAL is one of three separate scales in the SP 800-63-4 family. Identity assurance level covers proofing and authentication assurance level covers authentication, and each is selected for the harm its own failure could cause. A high FAL does not make up for weak proofing or weak authentication; it protects the hand-off.

Exam relevance: a scenario is likely to describe a federated login and ask which assurance measure applies to the assertion itself. Candidates are expected to match FAL to federated identity, IAL to proofing and AAL to authentication, and not to treat the three as one scale.