Identity Assurance Level (IAL)

NIST SP 800-63 measure of how rigorously a person's identity was proofed before an account was issued, from IAL1 to IAL3, chosen by the harm a proofing failure would cause.

An Identity Assurance Level (IAL) describes the robustness of the identity proofing process that established who a person is. NIST SP 800-63-4 defines three levels. IAL1 supports the real-world existence of the claimed identity and gives some assurance that the applicant is linked to it. IAL2 adds more evidence and a more rigorous process for validating it and verifying the person. IAL3 adds a trained proofing agent interacting directly with the applicant in an attended session, and the collection of at least one biometric.

SP 800-63-4 sets IAL beside two other kinds of assurance level, each on its own scale: the authentication assurance level (AAL) for the strength of each login, and the federation assurance level (FAL) for the assertion passed to a relying party. Each is chosen from the impact of that function failing. Strong authentication proves control of an authenticator bound at enrolment; what it says about who holds that authenticator is bounded by the proofing.

Exam relevance: questions in this area tend to test whether a candidate treats IAL, AAL and FAL as separate scales. A scenario that asks how confident an organisation can be about who a user really is points to IAL, not to the strength of the login.