Start with Identity
Policy & Public Identity

Paul Grassi

Lead author, NIST SP 800-63-3 · NIST (former) · 20+ years in identity
Focus areas
Digital Identity GuidelinesIdentity AssuranceAuthentication Policy
Notable work
  • Lead author of NIST SP 800-63-3, Digital Identity Guidelines (2017)
  • Split assurance into separate identity, authenticator, and federation levels
  • Removed password composition and rotation requirements from federal guidance

Bio

Paul Grassi led NIST SP 800-63-3 with Michael Garcia and James Fenton in NIST's Applied Cybersecurity Division. The 2017 revision restructured federal digital identity guidance and, in the process, changed what most of the industry considered good practice.

Profile built from public NIST publication records.

Where their work shows up

Two changes from that document travelled well beyond federal systems. It split a single assurance level into IAL, AAL, and FAL, so an organization can demand strong authentication without demanding document proofing, or the reverse. And it told federal agencies to stop requiring password composition rules and periodic rotation, citing the usability research, which gave every security team elsewhere the citation they needed to do the same. See NIST 800-63 and what is passwordless.

Built from public information only. This is an independent profile and is not an endorsement by, or affiliation with, the person listed. Corrections: [email protected].