{"id":1851,"date":"2017-04-26T00:26:07","date_gmt":"2017-04-25T22:26:07","guid":{"rendered":"http:\/\/www.identitycosmos.com\/?p=1851"},"modified":"2017-04-26T00:26:07","modified_gmt":"2017-04-25T22:26:07","slug":"nist-digital-identity-guidelines","status":"publish","type":"post","link":"https:\/\/identitycosmos.com\/index.php\/2017\/04\/26\/nist-digital-identity-guidelines\/","title":{"rendered":"Le National Institute of Standards and Technology (NIST) met \u00e0 jour ses recommandations sur &#8220;Digital Identity Guidelines&#8221;"},"content":{"rendered":"<p><a href=\"http:\/\/www.identitycosmos.com\/http:\/www.identitycosmos.com\/non-classe\/nist-digital-identity-guidelines\/attachment\/nist-logo\" rel=\"attachment wp-att-1852\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1852\" src=\"http:\/\/www.identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-logo.png\" alt=\"\" width=\"337\" height=\"79\" srcset=\"https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-logo.png 337w, https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-logo-300x70.png 300w\" sizes=\"auto, (max-width: 337px) 100vw, 337px\" \/><\/a>Le National Institute of Standards and Technology (NIST) est un institut\u00a0am\u00e9ricain d\u00e9livrant r\u00e9guli\u00e8rement des documents de sp\u00e9cifications et des recommandations \u00e0 l&#8217;attention de l&#8217;ensemble des autres organisations gouvernementales am\u00e9ricaines. M\u00eame si les documents publi\u00e9s ne sont pas exclusivement orient\u00e9s sur les aspects s\u00e9curit\u00e9 (comme par l&#8217;exemple <a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63b.html\">l&#8217;ANSSI <\/a>en France) de nombreuses recommandations traitent de ces sujets, et de nombreux documents sont publi\u00e9s pour aider les organismes am\u00e9ricains \u00e0 l&#8217;impl\u00e9mentation de solutions fiables et standardis\u00e9es.<\/p>\n<p>Le NIST a r\u00e9cemment publi\u00e9 un brouillon (Draft) de trois documents importants traitant de Digital Identity:<\/p>\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63a.html\">Document SP 800-63A: Digital Identity Guidelines &#8211; Enrollment and Identity Proofing Requirements<\/a><\/p>\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63a.html\" rel=\"attachment wp-att-1854\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-1854\" src=\"http:\/\/www.identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-1-300x70.png\" alt=\"\" width=\"300\" height=\"70\" srcset=\"https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-1-300x70.png 300w, https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-1.png 754w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63b.html\">Document SP 800-63B: Digital Identity Guidelines &#8211; Authentication and Lifecycle Management<\/a><\/p>\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63b.html\" rel=\"attachment wp-att-1855\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-1855\" src=\"http:\/\/www.identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-2-300x70.png\" alt=\"\" width=\"300\" height=\"70\" srcset=\"https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-2-300x70.png 300w, https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-2.png 733w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63c.html\">Document SP 800-63C: Digital Identity Guidelines &#8211; Federation and Assertions<\/a><\/p>\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63c.html\" rel=\"attachment wp-att-1856\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-1856\" src=\"http:\/\/www.identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-3-300x68.png\" alt=\"\" width=\"300\" height=\"68\" srcset=\"https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-3-300x68.png 300w, https:\/\/identitycosmos.com\/wp-content\/uploads\/2017\/04\/NIST-guidelines-3.png 750w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Ces trois documents, m\u00eame \u00e0 l&#8217;\u00e9tat de brouillon, sont une v\u00e9ritable mine d&#8217;or (et je p\u00e8se mes mots&#8230;) pour toute personne travaillant dans la s\u00e9curit\u00e9 informatique et dans le domaine de la gestion des identit\u00e9s. Le premier document donne par exemple les grandes lignes en ce qui concerne la gestion des identit\u00e9s de fa\u00e7on globale, le deuxi\u00e8me r\u00e9alise un focus sur les m\u00e9thodologies d&#8217;authentification et fournit\u00a0des conseils sur les r\u00e8gles de s\u00e9curit\u00e9 li\u00e9es aux mots de passe alors que le troisi\u00e8me traite particuli\u00e8rement des technologies de F\u00e9d\u00e9ration d&#8217;Identit\u00e9.<\/p>\n<p>Ce que j&#8217;appr\u00e9cie particuli\u00e8rement dans ces documents, c&#8217;est qu&#8217;ils ne sont pas uniquement un recueil b\u00eate et m\u00e9chant de bonnes pratiques mais liste de fa\u00e7on exhaustives les technologies associ\u00e9es et les standards du moment\u00a0&#8211; par exemple le document traitant de la f\u00e9d\u00e9ration d&#8217;identit\u00e9 ne se contente pas de recenser les bonnes pratiques\u00a0\u00e0 suivre autour de la f\u00e9d\u00e9ration\u00a0mais liste l&#8217;int\u00e9gralit\u00e9 des termes \u00e0 conna\u00eetre et \u00e0 utiliser &#8211; le grand int\u00e9r\u00eat est que du coup on peut choisir de consid\u00e9rer le document du NIST comme document de r\u00e9f\u00e9rence sur les termes \u00e0 employer, et dans un monde aussi confus que la F\u00e9d\u00e9ration d&#8217;Identit\u00e9 par exemple, cela ne fait pas de mal de s&#8217;appuyer sur un lexique de r\u00e9f\u00e9rence&#8230;<\/p>\n<p>Bref, c&#8217;est un peu long, mais c&#8217;est \u00e0 lire absolument&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Le National Institute of Standards and Technology (NIST) est un institut\u00a0am\u00e9ricain d\u00e9livrant r\u00e9guli\u00e8rement des documents de sp\u00e9cifications et des recommandations \u00e0 l&#8217;attention de l&#8217;ensemble des autres organisations gouvernementales am\u00e9ricaines. M\u00eame si les documents publi\u00e9s ne sont pas exclusivement orient\u00e9s sur les aspects s\u00e9curit\u00e9 (comme par l&#8217;exemple l&#8217;ANSSI en France) de nombreuses recommandations traitent de ces sujets, et de nombreux documents sont publi\u00e9s pour aider les organismes am\u00e9ricains \u00e0 l&#8217;impl\u00e9mentation de solutions fiables et standardis\u00e9es.<\/p>\n<p>Le NIST a r\u00e9cemment publi\u00e9 un brouillon (Draft) de trois documents importants traitant de Digital Identity:<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,6,7],"tags":[29,89,161,180],"class_list":["post-1851","post","type-post","status-publish","format-standard","hentry","category-non-classe","category-strategie","category-technique","tag-anssi","tag-federation","tag-nist","tag-password"],"_links":{"self":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/posts\/1851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/comments?post=1851"}],"version-history":[{"count":0,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/posts\/1851\/revisions"}],"wp:attachment":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/media?parent=1851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/categories?post=1851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/tags?post=1851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}