Paul Grassi
- Lead author of NIST SP 800-63-3, Digital Identity Guidelines (2017)
- Split assurance into separate identity, authenticator, and federation levels
- Removed password composition and rotation requirements from federal guidance
Bio
Paul Grassi led NIST SP 800-63-3 with Michael Garcia and James Fenton in NIST's Applied Cybersecurity Division. The 2017 revision restructured federal digital identity guidance and, in the process, changed what most of the industry considered good practice.
Profile built from public NIST publication records.
Where their work shows up
Two changes from that document travelled well beyond federal systems. It split a single assurance level into IAL, AAL, and FAL, so an organization can demand strong authentication without demanding document proofing, or the reverse. And it told federal agencies to stop requiring password composition rules and periodic rotation, citing the usability research, which gave every security team elsewhere the citation they needed to do the same. See NIST 800-63 and what is passwordless.
Related on Start with Identity
- ExpertChief Architect of Aadhaar and India Stack
Pramod Varma was chief architect of Aadhaar and of the India Stack layers built on top of it: eSign, DigiLocker, UPI, and the Data Empowerment and Protection Ar
- ExpertChief Identity Strategist, Open Identity Exchange
Nick Mothershaw is chief identity strategist at the Open Identity Exchange, where he leads work on trust frameworks and how they map to one another across juris
- ExpertCoordinator, Better Identity Coalition
Jeremy Grant established and led NSTIC at NIST, the first new cybersecurity programme of the Obama administration, and built what became NIST's Trusted Identiti