Identification Requirements



Definitions

An identification requirement is any access control requirement that specifies a required amount of the security quality subfactor identification.

Objectives

The typical objectives of a identification requirement are to:

Measurements

Identification requirements are typically specified in terms of the following measurements:

Examples

General Examples

The following are typical examples of identification requirements:

The following are typical examples of identification constraints:

The preceding examples are written as absolutes and are therefore theoretically not feasible because no system is 100% effective against security attacks. To make the requirement more feasible and testable, a minimum success threshold can be added as follows:

Specific Examples

The following are examples of identification requirements from the Global Personal Marketplace (GPM) system, a global Web-based marketplace bringing together private individuals and small companies to buy and sell all manner of items:

Guidelines

The following guidelines have been found to be useful when producing identification requirements: