Digital Identity Risk Management (DIRM) – Step 1: Define the Online Service
The first step in DIRM is about clarity and scope. Before risks can be assessed, organizations must fully understand the purpose, objectives, dependencies, and impact of the online service. This includes:
✔ Mission & objectives
✔ Legal, regulatory, and privacy requirements
✔ Service functionality & data scope
✔ User groups, transactions, and access privileges
✔ Impacted entities & processes
✔ Current identity technology state (proofing, authentication, federation)
Defining the online service creates a shared understanding of what’s at stake and forms the foundation for selecting the right assurance levels (IAL, AAL, FAL).
Check out this infographic for an overview of DIRM – Step 1: Define the Online Service.

