Federation to a low-assurance partner app currently releases full Social Security numbers with every login. What trust-boundary fix is required?
Select an answer to reveal the explanation.
Short Explanation
Handing SSNs to a low-assurance partner app is oversharing at login. Trim the claims to what that app actually needs—and skip SSNs unless policy truly demands them. More sensitive fields, public identity dumps, or cleartext assertions pour fuel on federation risk.
Full Explanation
Federation trust risks include excessive attribute release beyond the relying party’s need and assurance. Minimizing claims—especially government identifiers—limits privacy and fraud exposure. Expanding release of sensitive identifiers, publishing broad identity datasets, or transmitting assertions without confidentiality controls increase breach impact. Attribute governance is a core control when municipalities federate to external applications.