Annex E: Role-Obligation Matrix
Cross-reference between roles and requirements.
|
Req ID |
Description |
Ctrl |
Dept |
WAL |
VER |
RP |
IPE |
GOV |
HCP |
DG |
DPO |
AG |
LAG |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
BOR-01 |
Identity is innate and inalienable |
EXPT |
X |
||||||||||
|
BOR-02 |
Right to management and control |
EXPT |
X |
X |
|||||||||
|
BOR-03 |
Right to physical identity |
ADMN |
X |
X |
|||||||||
|
BOR-04 |
Right to not be compelled to use digital |
ADMN |
X |
X |
|||||||||
|
BOR-05 |
Right to endorsement on uniform standard |
EXPT |
X |
X |
|||||||||
|
BOR-06 |
Right to legislatively established stand |
ADMN |
X |
||||||||||
|
BOR-07 |
Right to transparency |
EXPT |
X |
||||||||||
|
BOR-08 |
Right to choose disclosed attributes |
AUTO |
X |
X |
X |
||||||||
|
BOR-09 |
Right to service regardless of format |
ADMN |
X |
X |
X |
||||||||
|
BOR-10 |
Right to freedom from surveillance |
AUTO |
X |
X |
|||||||||
|
BOR-11 |
Right to not surrender device |
AUTO |
X |
X |
X |
||||||||
|
PRG-01 |
SEDI issuance compliance |
EXPT |
X |
||||||||||
|
PRG-02 |
Publish technical standards |
EXPT |
X |
||||||||||
|
PRG-03 |
Data governance standards |
EXPT |
X |
||||||||||
|
PRG-04 |
45-day public comment period |
ADMN |
X |
||||||||||
|
PRG-05 |
Response to public comments |
ADMN |
X |
||||||||||
|
PRG-06 |
Fee structure publication |
ADMN |
X |
||||||||||
|
PRG-07 |
Annual program reporting |
ADMN |
X |
||||||||||
|
PRG-08 |
Program manager qualifications |
ADMN |
X |
||||||||||
|
PRG-09 |
Interagency coordination |
ADMN |
X |
||||||||||
|
PRG-10 |
Use case development |
ADMN |
X |
||||||||||
|
PRG-11 |
Coordination standards and guidance |
ADMN |
X |
||||||||||
|
SDI-01 |
Compromise detection |
AUTO |
X |
X |
|||||||||
|
SDI-02 |
Recovery mechanisms |
EXPT |
X |
||||||||||
|
SDI-03 |
Cross-context correlation protections |
AUTO |
X |
X |
|||||||||
|
SDI-04 |
Authenticity and integrity |
AUTO |
X |
X |
|||||||||
|
SDI-05 |
Interoperability |
EXPT |
X |
||||||||||
|
SDI-06 |
Online and offline presentation |
AUTO |
X |
X |
X |
||||||||
|
SDI-07 |
Selective disclosure |
AUTO |
X |
X |
|||||||||
|
SDI-08 |
Age verification without disclosure |
AUTO |
X |
X |
|||||||||
|
SDI-09 |
Wallet choice |
AUTO |
X |
X |
|||||||||
|
SDI-10 |
Usability |
EXPT |
X |
X |
|||||||||
|
SDI-11 |
Identity proofing validation |
EXPT |
X |
X |
|||||||||
|
SDI-12 |
Technological compliance mandate |
EXPT |
X |
||||||||||
|
SDI-13 |
State data center requirement |
EXPT |
X |
||||||||||
|
SDI-14 |
Data center best practices |
EXPT |
X |
||||||||||
|
SDI-15 |
Open standards mandate |
AUTO |
X |
||||||||||
|
SDI-16 |
Endorsed attribute set |
AUTO |
X |
||||||||||
|
SDI-17 |
Anti-surveillance |
AUTO |
X |
||||||||||
|
SDI-18 |
Purpose limitation |
AUTO |
X |
||||||||||
|
SDI-19 |
Individual authorization |
AUTO |
X |
||||||||||
|
SDI-20 |
Retention limitation |
AUTO |
X |
||||||||||
|
SDI-21 |
In-state data storage |
EXPT |
X |
||||||||||
|
SDI-22 |
Disclosure restrictions |
AUTO |
X |
||||||||||
|
SDI-23 |
Revocation constraints |
AUTO |
X |
||||||||||
|
SDI-24 |
Breach reporting |
EXPT |
X |
||||||||||
|
APP-01 |
Age and emancipation eligibility |
AUTO |
X |
||||||||||
|
APP-02 |
Guardian consent for minors |
AUTO |
X |
||||||||||
|
APP-03 |
Guardian-initiated applications |
AUTO |
X |
||||||||||
|
APP-04 |
No mandatory enrollment |
ADMN |
X |
X |
|||||||||
|
APP-05 |
Three eligibility criteria |
AUTO |
X |
X |
|||||||||
|
APP-06 |
Data minimization in application |
EXPT |
X |
||||||||||
|
APP-07 |
Enumerated data collection fields |
EXPT |
X |
||||||||||
|
IDP-01 |
Follow accepted proofing standard |
EXPT |
X |
X |
|||||||||
|
IDP-02 |
Risk-commensurate proofing |
EXPT |
X |
||||||||||
|
IDP-03 |
Privacy-consistent proofing |
EXPT |
X |
X |
|||||||||
|
IDP-04 |
Four verified assertions |
AUTO |
X |
X |
|||||||||
|
IDP-05 |
Sufficient for age assurance reliance |
EXPT |
X |
||||||||||
|
IDP-06 |
Online and offline suitability |
EXPT |
X |
||||||||||
|
IDP-07 |
Point-in-time endorsement |
AUTO |
X |
||||||||||
|
APP-08 |
Fraud prohibition |
ADMN |
X |
||||||||||
|
IDP-08 |
Independence from physical ID system |
AUTO |
X |
||||||||||
|
IDP-09 |
No physical document surrender |
ADMN |
X |
||||||||||
|
IDP-10 |
Multiple proofing methods |
EXPT |
X |
||||||||||
|
IDP-11 |
Proofing entity authorization |
ADMN |
X |
||||||||||
|
GOV-01 |
No material benefit for SEDI use |
ADMN |
X |
||||||||||
|
GOV-02 |
No service withholding for physical ID |
ADMN |
X |
||||||||||
|
GOV-03 |
No device surrender |
AUTO |
X |
||||||||||
|
GOV-04 |
New systems must accept SEDI |
EXPT |
X |
||||||||||
|
GOV-05 |
Technical infeasibility exemption |
ADMN |
X |
||||||||||
|
GOV-06 |
Health care provider SEDI acceptance |
EXPT |
X |
||||||||||
|
GOV-07 |
Health care infeasibility exemption |
ADMN |
X |
||||||||||
|
WAL-01 |
Identity protection safeguards |
AUTO |
X |
||||||||||
|
WAL-02 |
Secure attribute processing |
AUTO |
X |
||||||||||
|
WAL-03 |
Technological compliance |
EXPT |
X |
||||||||||
|
WAL-04 |
Tamper resistance |
AUTO |
X |
||||||||||
|
WAL-05 |
Online and offline presentation |
AUTO |
X |
||||||||||
|
WAL-06 |
Secure presentation log |
AUTO |
X |
||||||||||
|
WAL-07 |
Selective disclosure |
AUTO |
X |
||||||||||
|
WAL-08 |
Age predicate proof |
AUTO |
X |
||||||||||
|
WAL-09 |
Guardian presentation |
AUTO |
X |
||||||||||
|
WAL-10 |
Attribute processing limitation |
AUTO |
X |
||||||||||
|
WAL-11 |
Conspicuous notice |
EXPT |
X |
||||||||||
|
WAL-12 |
Per-transaction consent |
AUTO |
X |
||||||||||
|
WAL-13 |
Primary purpose limitation |
EXPT |
X |
||||||||||
|
WAL-14 |
No unauthorized retention or sharing |
EXPT |
X |
||||||||||
|
WAL-15 |
Utah data protection law compliance |
ADMN |
X |
||||||||||
|
VER-01 |
Identity protection safeguards |
AUTO |
X |
||||||||||
|
VER-02 |
Technological compliance |
EXPT |
X |
||||||||||
|
VER-03 |
Secure attribute processing |
AUTO |
X |
||||||||||
|
VER-04 |
Minimum attribute processing |
AUTO |
X |
X |
|||||||||
|
VER-05 |
Accept guardian presentations |
AUTO |
X |
||||||||||
|
VER-06 |
Four-condition processing gate |
AUTO |
X |
||||||||||
|
VER-07 |
No device surrender |
AUTO |
X |
||||||||||
|
VER-08 |
Utah data protection law compliance |
ADMN |
X |
||||||||||
|
RPY-01 |
Identity protection safeguards |
AUTO |
X |
||||||||||
|
RPY-02 |
Technological compliance |
EXPT |
X |
||||||||||
|
RPY-03 |
Secure attribute processing |
AUTO |
X |
||||||||||
|
RPY-04 |
Minimum attribute processing |
EXPT |
X |
||||||||||
|
RPY-05 |
Accept guardian presentations |
AUTO |
X |
||||||||||
|
RPY-06 |
Four-condition processing gate |
AUTO |
X |
||||||||||
|
RPY-07 |
No device surrender |
AUTO |
X |
||||||||||
|
RPY-08 |
Permissive SEDI acceptance |
ADMN |
X |
||||||||||
|
RPY-09 |
Utah data protection law compliance |
ADMN |
X |
||||||||||
|
LOY-01 |
No conflicting practices |
EXPT |
X |
X |
X |
X |
X |
||||||
|
LOY-02 |
No exploitation of individuals |
ADMN |
X |
X |
X |
X |
X |
||||||
|
LOY-03 |
No disproportionate risk |
EXPT |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
|
LOY-04 |
No detriment |
ADMN |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
|
LOY-05 |
No harm |
ADMN |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
|
PRC-01 |
Purpose-limited record processing |
AUTO |
X |
X |
X |
||||||||
|
PRC-02 |
Primary purpose limitation |
AUTO |
X |
X |
|||||||||
|
PRC-03 |
Notice and consent for secondary use |
AUTO |
X |
X |
|||||||||
|
ENF-01 |
Complaint submission mechanism |
EXPT |
X |
X |
|||||||||
|
ENF-02 |
Attorney general enforcement support |
ADMN |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
X |
|
ENF-03 |
Legislative audit |
EXPT |
X |
||||||||||
|
ENF-04 |
Anti-surveillance architectural proof |
EXPT |
X |
||||||||||
|
ENF-05 |
Audit report deadline |
ADMN |
X |
||||||||||
|
CRY-01 |
Non-callback signature verification |
AUTO |
X |
X |
|||||||||
|
CRY-02 |
Holder-controlled key binding |
AUTO |
X |
X |
|||||||||
|
CRY-03 |
Selective disclosure and predicate proof |
AUTO |
X |
X |
|||||||||
|
CRY-04 |
Open, royalty-free algorithms |
AUTO |
X |
||||||||||
|
CRY-05 |
Cryptographic agility |
EXPT |
X |
||||||||||
|
PRV-01 |
Protocol-level unlinkability |
AUTO |
X |
X |
|||||||||
|
PRV-02 |
Leak-resistant predicate evaluation |
AUTO |
X |
X |
|||||||||
|
PRV-03 |
Architectural anti-surveillance |
EXPT |
X |
||||||||||
|
PRV-04 |
Lifecycle data minimization |
EXPT |
X |
X |
X |
X |
X |
||||||
|
INT-01 |
Open standards for protocols and APIs |
AUTO |
X |
||||||||||
|
INT-02 |
Common format across presentation modes |
AUTO |
X |
X |
X |
||||||||
|
INT-03 |
Wallet portability |
AUTO |
X |
X |
|||||||||
|
INT-04 |
No privacy-degrading fallback |
EXPT |
X |
X |
X |
||||||||
|
KMS-01 |
Key lifecycle policy |
ADMN |
X |
||||||||||
|
KMS-02 |
Key generation ceremonies |
ADMN |
X |
||||||||||
|
KMS-03 |
Hardware security modules |
EXPT |
X |
||||||||||
|
KMS-04 |
Key rotation |
AUTO |
X |
||||||||||
|
KMS-05 |
Key compromise response |
ADMN |
X |
||||||||||
|
ORG-01 |
Access management |
EXPT |
X |
||||||||||
|
ORG-02 |
Personnel security |
ADMN |
X |
||||||||||
|
ORG-03 |
Vulnerability management |
EXPT |
X |
||||||||||
|
ORG-04 |
Logging and monitoring |
AUTO |
X |
||||||||||
|
ORG-05 |
Incident response |
ADMN |
X |
||||||||||
|
ORG-06 |
Third-party compliance |
EXPT |
X |
||||||||||
|
ORG-07 |
Change management |
ADMN |
X |
Obligation Counts
|
Role |
Count |
|---|---|
|
Department |
97 |
|
Wallet Providers |
39 |
|
Verifiers |
26 |
|
Relying Parties |
22 |
|
Identity Proofing Entities |
11 |
|
Governmental Entities |
14 |
|
Health Care Providers |
7 |
|
Digital Guardians |
6 |
|
Data Privacy Ombudsperson |
5 |
|
Attorney General |
4 |
|
Legislative Auditor General |
5 |
Total: 142 requirements