1. The levels of security and trust of the Electronic Identification System and the Digital Identity issued thereby are three: low, medium and high, according to the following general classifications: a. Low level: means a low level of security and trust in the Electronic Identification System that provides a limited degree of trust and acceptability of the alleged identity of a person, and refers to technical and administrative standards and procedures aimed at reducing the risks of misuse or manipulation of that identity. b. Medium level: means a medium level of security and trust in the Electronic Identification System that provides a medium degree of trust and acceptability of the alleged identity of a person, and refers to technical and administrative standards and procedures aimed at minimizing the risks of misuse or manipulation of that identity. c. High level: means a high level of security and trust in the Electronic Identification System that provides a high degree of trust and acceptability of the alleged identity of a person, and refers to technical and administrative standards and procedures aimed at eliminating any risks and preventing misuse or manipulation of that identity. 2. A Licensee shall observe the following: a. Indicating to the Relying Party the levels of security and trust of the Digital Identity issued under the Electronic Identification System. b. Ensuring compliance with the technical specifications, standards and procedures for the relevant level of security in the Electronic Identification System and Digital Identity as approved by TDRA. 3. The Digital Identity used in Qualified Trust Services shall meet a high level of security and trust. 4. TDRA shall, after coordination with the Competent Authorities, set the technical conditions and standards that must be met in terms of security and trust levels, provided that the following are observed: a. Setting criteria for differentiating between the levels of security and trust according to the degree of trust and acceptability. b. Authentication Procedures for the person requesting the issuance of the Digital Identity. c. The technical and security specifications of the Digital Identity, the procedures for its issuance, and its issuing entity. d. Authentication Procedures to confirm the identity of any person to the Relying Party. e. Types of transactions and services provided by public or private entities.
Interpretation and application must be checked against the official text and current version.
