Commonwealth Office of Technology Finance and Administration Cabinet Electronic Signature Overview Name:Chris Clark Date: October 28, 2004
Title Goes Here Name Date COT has made strenuous efforts to support conducting state business electronically.
Title Goes Here Name Date Electronic signatures are an important piece of the puzzle.
Title Goes Here Name Date To spur growth of e-government, COT and other agencies promoted UETA legislation adopted in 2000.
Title Goes Here Name Date Kentucky Uniform Electronic Transactions Act (UETA) Model legislation adopted by many states. Allows electronic transactions where both parties agree to conduct business electronically. Is technology neutral. See statute at 00/CHAPTER.HTM 00/CHAPTER.HTM
Title Goes Here Name Date In the conduct of state business, we require signatures... To authorize To be non-repudiable To be auditable, where necessary.
Title Goes Here Name Date Two requirements to implement e- signatures: Assess level of risk associated with business transactions Develop signing mechanisms appropriately secure for level of risk.
Title Goes Here Name Date For example: Simple passwords for low- risk transactions PINs for moderate-level risk PKI (digital signatures) for very secure transactions
Title Goes Here Name Date Agencies have taken a variety of approaches for signing.
Title Goes Here Name Date There are red pens for signing employee evaluations.
Title Goes Here Name Date Agency Examples – Many agencies conduct internal business through use of standard . Simple logons establish sufficient level of security to conduct daily business. –It is assumed that if you receive an from me, it’s authentic. –This is highly dependent on observance of normal password security. –Sign-able, encrypted available where needed.
Title Goes Here Name Date Agency Examples - NR Piloted Use of ApproveIt ApproveIt - –Mimics paper-based approval –Supports routing and multiple approvals –Met requirements of NR legal staff Subsequent to NR pilot, ApproveIt added to Enterprise Standard 2370 as recommended product.
Title Goes Here Name Date Agency Examples - Revenue PINs for Time Reporting Application reviewed by COT and KDLA under authority of: Enterprise Architecture and Standards KDLA Record-keeping standards authority under UETA – see 00/117.PDF) 00/117.PDF
Title Goes Here Name Date Standards framework Ensures business can be conducted electronically Ensures associated transactional records can be reliably created and maintained over time
Title Goes Here Name Date COT’s goal - Choose best available products Incorporate in Enterprise Architecture and Standards Remove the need for citizens to have multiple passwords or PINs, one for each agency
Title Goes Here Name Date Relevant Enterprise Standards 2370 Electronic Commerce - Electronic Signature ( ment-9357/2370_- _Electronic_Commerce_- _Electronic_Signature.doc) ment-9357/2370_- _Electronic_Commerce_- _Electronic_Signature.doc 2340 Electronic Forms ( ment-9354/ Electronic+Forms.doc) ment-9354/ Electronic+Forms.doc
Title Goes Here Name Date Electronic Records Working Group Workgroup of Enterprise Architecture and Standards Committee Legal perspective – Attorney General COT legal Audit perspective – State Auditor’s Office Records management/archival – Libraries and Archives ERWG drafts standards relating to electronic record-keeping for EASC
Title Goes Here Name Date Identity and Access Management Project Provides a PKI infrastructure over time to facilitate e-signing where that level of security and authentication are needed to transact business within state government, government to businesses, and government to citizens.