LANGUAGE
  • 日本語
  • 한국어
  • 简体中文
  • English
  • 如何加入 FIDO 联盟
FIDO Alliance
  • The Alliance
    About FIDO Alliance
    • 关于 FIDO 联盟
    • 在线快速身份认证(FIDO)发展历程
    • 联系方式
    Our Membership
    • 工作组
    • FIDO Members
    • Liaison Partners
    • Committees and Study Groups
    Join FIDO Alliance
    • 会员权益和会费级别
    • 如何加入 FIDO 联盟
    Newsletter Sign-Up
    FIDO Explained
  • Standards & Technology
    Work Areas
    • FIDO Authentication
    • Identity Verification & Binding
    • Internet of Things
    FIDO Authentication
    • FIDO 的工作原理
    • FIDO2: WebAuthn & CTAP
    • Metadata Service
    Specifications
    • Specifications Overview
    • Download Specifications
    Developers
    • Getting Started
    • Developer Resources
  • Discover FIDO
    Getting Started Knowledge Base
    • Intro to FIDO
    • Building the Business Case
    • Buying, Building & Partnering
    • Implementation & Deployment
    Adoption
    • FIDO Case Studies
    • Case Studies
    • FIDO 联盟政府和政策计划
    • Market Solutions
    • Government & Public Policy
    • PSD2 Compliance
    • Commercial Deployments
    Resources
    Showcase
    Research
    Videos
    White Papers
    Presentations
    FAQ
  • FIDO® Certified
    FIDO Certification Programs
    • FIDO Certified Professional Program
    • Functional Certification
    • Authenticator Certification
    Get Certified
    • 认证提交
    Certified Products
    • FIDO® Certified Products
    • FIDO Certified Showcase
  • News & Events
    Latest Updates
    • Events Calendar
    • FIDO in the News
    • Press Center
    • FIDO Blog
  • 如何加入 FIDO 联盟
Language
  • 日本語
  • 한국어
  • 简体中文
  • English
search
  • Adoption (2)
    • FIDO Case Studies
    • FIDO 联盟政府和政策计划
    1. Home 
    2. FIDO Alliance Public Policy Submissions

    FIDO Alliance Public Policy Submissions

    FIDO Alliance Input to NIST (April 2023) and Comment Template:
    In this input document, the FIDO Alliance comments to NIST – SP 800-63-4 Digital Identity Guidelines (Draft).

    FIDO Alliance Input to CFPB (January 2023):
    In this input document, the FIDO Alliance comments to the CFPB – Small Business Advisory Review Panel on Required Rulemaking on Personal Financial Date Rights.

    FIDO Alliance Input to DFS (January 2023):
    In this input document, the FIDO Alliance comments to the DFS – Proposed Cybersecurity Requirements for Financial Services Companies – 23 NYCRR Part 500.

    FIDO Alliance Input to DFS (August 2022):
    In this input document, the FIDO Alliance comments to the DFS – Proposed Cybersecurity Requirements for Financial Services Companies.

    FIDO Alliance Input to SEC (April 2022):
    In this input document, the FIDO Alliance comments to the SEC – Proposed Cybersecurity Risk Management Rules for Investment Advisers, Registered Investment Companies, and Business Development Companies. 

    FIDO Alliance Input to FCC (November 2021):
    In this input document, the FIDO Alliance comments to the FCC – NPRM on Rules to Prevent SIM Swapping and Port-Out Fraud. 

    FIDO Alliance Input to NIST (October 2021):
    In this input document, the FIDO Alliance comments on NIST’s Consumer Labeling for IoT Devices. 

    FIDO Alliance Input to the European Commission (October 2021):
    In this input document, the FIDO Alliance comments on the European Commission – using FIDO Standards in eIDAS 2.0. 

    FIDO Alliance Input to CISA (October 2021):
    In this input document, the FIDO Alliance comments on the Draft Zero Trust Maturity Model and Cloud Security Technical Reference Architecture. 

    FIDO Alliance Input to OMB (September 2021):
    In this input document, the FIDO Alliance comments on the Draft Federal Zero Trust Strategy published by the White House Office of Management and Budget (OMB). 

    FIDO Alliance Input to NIST (February 2021):
    In this input document, the FIDO Alliance comments on NIST’s Draft Guidance for Federal Agencies and IoT Device Manufacturers. 

    FIDO Alliance Input to the Consumer Financial Protection Bureau (February 2021):
    In this input document, the FIDO Alliance comments to the Consumer Financial Protection Bureau (CFPB) on Consumer Access to Financial Records.

    FIDO Alliance Input to NIST (October 2020):
    In this input document, the FIDO Alliance comments on the NIST’s draft on Trusted Internet of Things (IoT) Device Network-Layer Onboarding and Lifecycle Management.

    FIDO Alliance Input to the European Commission (September 2020):
    In this input document, the FIDO Alliance comments on the European Commission’s (EC) Inception Impact Assessment regarding the future of eIDAS. FIDO Alliance comments in four areas for the EC’s consideration: 1. With regard to authentication – the EC should ensure that any LOA High solutions require high assurance authentication. 2. Extension of eIDAS to the private sector under Option 2 would be well-received by many companies. 3. All Europeans could benefit by creating new options for creating digital versions of physical identity documents. 4. Mutual recognition and re-use of pre-approved ID products. 

    FIDO Alliance Input to the National Institute of Standards and Technology (NIST) (August 2020):
    In this input document, the FIDO Alliance comments on NIST’s Pre-Draft Call for Comments on Digital Identity Guidelines. FIDO Alliance offers comments in three areas for the NIST’s consideration: 1. Recognize changes in both threat and technology since the publication of SP 800-63-3. 2. AAL3 – explore new paths. 3. Reference to FIDO standards.

    FIDO Alliance Input to the Drug Enforcement Administration (DEA) (June 2020):
    In this input document, the FIDO Alliance comments on Docket No. DEA-218I, the Drug Enforcement Administration’s (DEA) Request for Comments on the Interim Final Rule for Electronic Prescriptions for Controlled Substances (EPCS). FIDO Alliance comments in four parts and are largely focused on the portions of the request for comment that focus on authentication requirements in the interim final rule: 1. Observations on current regulations and how technology has evolved over the last ten years. 2. An introduction to FIDO Authentication and FIDO Alliance certification programs. 3. Answers to specific DEA questions from the Request for Comments. 4. Suggestions on ways DEA can ensure revised EPCS regulations stay current as technology and threat evolve.

    How FIDO Standards Meet PSD2’s Regulatory Technical Standards Requirements On Strong Customer Authentication (December 2018):
    This document provides a detailed review of the security requirements listed in the Regulatory Technical Standards For Strong Customer Authentication and Common and Secure Open Standards Of Communication under PSD2 (the RTS) and describes how the FIDO standards meet such requirements. 

    FAQ on FIDO relevance for the GDPR (September 2018):
    This document provides answers to questions on authentication, user consent, use of biometrics…in the context of the European General Data Protection Regulation. It shows how FIDO authentication can help service providers comply with the regulation.

    FIDO Alliance Letter Regarding Payment Services Directive 2 (August 2017):
    FIDO Alliance’s letter to European Commission and European Parliament on whether screen scraping should be allowed as a fallback option under PSD2

    FIDO Alliance Input to the National Institute of Standards and Technology (NIST): Request for Information (RFI) on the Framework for Improving Critical Infrastructure Cybersecurity (April 2017):
    In its input to NIST on the proposed changes to the Cybersecurity Framework, the FIDO Alliance recommends that NIST clarify their language and explicitly require MFA in the next update to the Framework. The Alliance urges NIST to add a new “authentication” sub-category to the Framework core with the recommendation that: “authentication of authorized users is protected by multiple factors.” Explicitly addressing MFA with this language is necessary to help government and industry address growing risks caused by weak authentication, and should be part of any proper update of the Framework.

    Response to the European Banking Authority (EBA) Discussion Paper on Future Draft Regulatory Technical Standards on Strong Customer Authentication and Secure Communication Under the Revised Payment Services Directive (PSD2)
    In this response to the EBA, the FIDO Alliance details how FIDO-compliant implementations that follow security best practices are ideal examples of what the EBA regulations for “strong customer authentication” under PSD2 are striving to foster: simpler, stronger authentication capabilities that merchants and consumers will adopt at scale. The response also describes how the EBA’s acceptance of FIDO’s public key cryptographic architecture, especially when combined with on-device biometrics, will reduce the vulnerability surface of their payment service providers — and presumably also reduce online fraud rates as a result — and accelerate overall online payment volume through reduced friction in the user experience.

    Input to the Commission on Enhancing National Cybersecurity
    In this input document, the FIDO Alliance makes three recommendations to the U.S. government for addressing cyberthreats: 1. Make it a national priority to replace passwords and other “shared secret” authentication approaches with more secure solutions. 2. Promote the use of new authentication standards such as FIDO as a best practice for authentication and 3. Accelerate the adoption of strong authentication through actions that will help create demand for these solutions.

    FIDO Privacy: FIDO Alliance White Paper
    This white paper describes how privacy has been taken into account in the design of the FIDO protocols, and how they can help meet privacy requirements from certain regulatory authorities.

    FIDO Alliance
    • FIDO 的工作原理
    • 关于 FIDO 联盟
    • HOW FIDO WORKS
    • Terms of Use
    • Specifications Overview
    • Certification Overview
    • Knowledge Base
    • Privacy Policy
    • Press Center

    Join the Community

    Get the Latest Updates Participate in FIDO-Dev Forum

    Categories

    • Announcements
    • Building the Business Case
    • Buying, Building & Partnering
    • FIDO in the News
    • Implementation & Deployment
    • Intro to FIDO
    • Market Research
    • Perspectives
    • Uncategorized
    FIDO Alliance Public Policy Submissions

    Document Authenticity (DocAuth) Certification Program for Remote Identity Verification

    Sign up for updates!Get news from FIDO Alliance in your inbox.

    By submitting this form, you are consenting to receive communications from: FIDO Alliance, 3855 SW 153rd Drive, Beaverton, OR 97003, US, http://www.fidoalliance.org. You can revoke your consent to receive emails at any time by using the unsubscribe link found at the bottom of every email.

    First Name
    Last Name
    Email
    Country
    Company
    Job Title
    • 日本語
    • 한국어
    • 简体中文
    • English