HSPD-12 and FIPS-201 Overview v1.4. 2 Learning Objectives At the end of this course, you will be able to: Describe Homeland Security Presidential Directive.

Slides:



Advertisements
Similar presentations
June 27, 2005 Preparing your Implementation Plan.
Advertisements

PIV-I Issuing Procedures for Applicants (New Contractors) v1.1
Status of U.S. Smart Card Deployment Jim Dray Porvoo 7/ World eID Meeting May 2005.
Evolution of Data Use and Stewardship Recent University-wide Data Stewardship Enhancements Integrated System Data Stewardship Shirley C. Payne, CISSP,
Brian Epley, VA PIV Program Manager
1 HSPD-12 Compliance: The Role of Federal PKI Judith Spencer Chair, Federal Identity Credentialing Office of Governmentwide Policy General Services Administration.
NIH is a Valuable Place with Valuable People: We Need to Protect it! Cyber threat is one of the most serious economic and national security challenges.
The Federation for Identity and Cross-Credentialing Systems (FiXs) FiXs ® - Federated and Secure Identity Management in Operation Implementing.
15June’061 NASA PKI and the Federal Environment 13th Fed-Ed PKI Meeting 15 June ‘06 Presenter: Tice DeYoung.
1 1 A Synopsis of Federal Information Processing Standard (FIPS) 201 for Personal Identity Verification (PIV) of Federal Employees and Contractors Presentation.
Department of Health and Human Services Personal Identity Verification Training APPLICANT.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
U.S. Department of Agriculture HSPD 12 Program HSPD 12 Personal Identity Verification (PIV) I Core Training: Issuers.
1 Homeland Security Presidential Directive 12 (HSPD-12) Policies & Procedures Veronica McCann - Security Specialist Western Region Security Office March.
“Personal Identity Verification (PIV) of Federal Employees and Contractors” October 27, 2005 Homeland Security Presidential Directive 12 (HSPD-12)
Department of Labor HSPD-12
PIV-I Issuing Procedures for Applicants (Current Contractors) v1.1.
DoD Information Technology Security Certification and Accreditation Process (DITSCAP) Phase III – Validation Thomas Howard Chris Pierce.
Form I-9 Process An Online Training for Supervisors and Designees Presented by Human Resources Revised November 2009.
Federal Information Processing Standard (FIPS) 201, Personal Identity Verification for Federal Employees and Contractors Tim Polk May.
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Office of the Chief Information Officer EFCOG Annual Meeting Fred Catoe (IM-32) U.S. Department of Energy.
E-Authentication: What Technologies Are Effective? Donna F Dodson April 21, 2008.
1 Implementation of Homeland Security Presidential Directive 12 David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide FED/ED.
PIV-I Issuing Procedures for Applicants (New Volunteers / Affiliates) v1.1.
PIV-I Issuing Procedures for Applicants (New Employees) v1.1.
I DENTITY M ANAGEMENT Joe Braceland Mount Airey Group, Inc.
NASA Personal Identity Verification (PIV) NASA Personal Identity Verification (PIV) High Level System Overview Tice F. DeYoung, PhD 14th Fed/Ed Workshop.
Complying With The Federal Information Security Act (FISMA)
U.S. Department of Agriculture HSPD 12 Program HSPD 12 Personal Identity Verification (PIV) I Core Training: Registrars.
Federal CIO Council Information Security and Identity Management Committee IDManagement.gov FICAM Testing Program and Approved Products List (APL) Overview.
Access and Identity Management System (AIMS) Federal Student Aid PESC Fall 2009 Data Summit October 20, 2009 Balu Balasubramanyam.
IdM Identity Proofing & Registration Gary Chapman David Millman September 2006.
Homeland Security Presidential Directive-12 (HSPD-12)
NIH Policy Manual 2811 Policy on Smart Card Authentication iTrust Forum Mark L. Silverman December 10, 2009
EmpowHR Sponsorship.
1 The Government-wide Implementation of Homeland Security Presidential Directive 12 (HSPD-12) David Temoshok Director, Identity Policy and Management GSA.
Page 1 EmpowHR Adjudicator.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
1 Personnel Security 2007 Data Protection Seminar TMA Privacy Office HEALTH AFFAIRS TRICARE Management Activity.
PIV 1 Ketan Mehta May 5, 2005.
PIV-I Issuing Procedures for Applicants (Current Employee) v1.1.
The U.S. Secret Service Shhhhhh!
Business and Systems Aligned. Business Empowered. TM Federal Identity Management Handbook May 5, 2005.
Real ID Vibhas Chandrachood, Executive Director Office of Application Development Commonwealth Office of Technology Commonwealth of Kentucky December 15,
Homeland Security Presidential
U.S. Department of Agriculture HSPD 12 Program HSPD 12 Personal Identity Verification (PIV) I Core Training: Sponsors.
NTEU Briefing Remote Fingerprinting December 5, 2008.
Non-Employee Identity System (NEIS) Adjudicator Training.
Non-Employee Identity System (NEIS) Adjudicator Training.
HSPD-12 Identity Management Initiative Carol Bales Senior Policy Analyst United States Office of Management and Budget North American Day 2006.
HSPD-12 and the Personal Identity Verification (PIV) System Procurement Briefing by Corrine Irwin January 2008.
Intelligence Reform & Terrorism Act – The Act – Intelligence Reform & Terrorism Act – The Act – -The Process- Centers for Disease Control and Prevention.
1 Federal Identity Management Initiatives Federal Identity Management Initatives David Temoshok Director, Identity Policy and Management GSA Office of.
Site Security Policy Case 01/19/ : Information Assurance Policy Douglas Hines, Jr.
Welcome to HR Presents February 17, :30 am – 11:45 am Milton Hall | Room 185.
11/18/2003 Smart Card Authentication Mechanism Tim W. Baldridge, CISSP Marshall Space Flight Center Office of the Chief Information Officer.
1 Federal Identity Management Infrastructure and Policy David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide August 15,
Identity Crisis: Defining the Problem and Framing a Solution for Terrorism Incident Response Presented by Mark Landahl Supervisor – Homeland Security Section.
HHS Security and Improvement Recommendations Insert Name CSIA 412 Final Project Final Project.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Department of the Navy Security Enterprise Leadership Course Curriculum for Security Program Oversight 1.
The REAL ID Act Minnesota Department of Public Safety Driver and Vehicle Services Division Driver and Vehicle Services Division.
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
E-Authentication: What Technologies Are Effective?
Preparing your Implementation Plan
NASA Personal Identity Verification (PIV) High Level System Overview Tice F. DeYoung, PhD 14th Fed/Ed Workshop December 14, 2006.
Appropriate Access InCommon Identity Assurance Profiles
Presentation transcript:

HSPD-12 and FIPS-201 Overview v1.4

2 Learning Objectives At the end of this course, you will be able to: Describe Homeland Security Presidential Directive (HSPD-12) and its purpose Describe Homeland Security Presidential Directive (HSPD-12) and its purpose Describe the Personal Identification Verification (PIV) subsystem Describe the Personal Identification Verification (PIV) subsystem Describe the different types of PIV standards Describe the different types of PIV standards Describe the PIV Roles and Issuance Process Describe the PIV Roles and Issuance Process

3 FIPS-201 PIV Overview Why a FIPS-201 Compliant Personal Identification Verification (PIV) system? Why a FIPS-201 Compliant Personal Identification Verification (PIV) system? What is HSPD-12? What is HSPD-12? What is FIPS-201? What is FIPS-201? What is PIV-I and PIV-II? What is PIV-I and PIV-II? FIPS – Federal Information Processing Standard

4 HSPD-12 and FIPS-201 Overview On August 27, 2004, President Bush signed Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors. Based upon this directive, the National Institute for Standards and Technology (NIST) developed Federal Information Processing Standards Publication (FIPS Pub) 201 including a description of the minimum requirements for a Federal personal identification verification (PIV) system. HSPD-12 directs the implementation of a new standardized badging process, which is designed to enhance security, reduce identity fraud, and protect the personal privacy of those issued government identification. On August 27, 2004, President Bush signed Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors. Based upon this directive, the National Institute for Standards and Technology (NIST) developed Federal Information Processing Standards Publication (FIPS Pub) 201 including a description of the minimum requirements for a Federal personal identification verification (PIV) system. HSPD-12 directs the implementation of a new standardized badging process, which is designed to enhance security, reduce identity fraud, and protect the personal privacy of those issued government identification.Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors Federal Information Processing Standards Publication (FIPS Pub) 201Homeland Security Presidential Directive 12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors Federal Information Processing Standards Publication (FIPS Pub) 201

5 PIV-I and PIV-II PIV standard consists of two parts – PIV standard consists of two parts –PIV-I: PIV-I satisfies the control objectives and security requirements of HSPD-12 PIV-II: PIV-II specifies implementation and use of identity credentials on integrated circuit cards (Smart Cards) for use in a Federal personal identity verification system.

6 What is Personal Identification Verification (PIV) The PIV process provides a commonly accepted identification card and reliable form of secure identification for all Federal employees that: The PIV process provides a commonly accepted identification card and reliable form of secure identification for all Federal employees that: Is issued based on sound criteria for verifying an individual’s identity Is issued based on sound criteria for verifying an individual’s identity Is strongly resistant to identity fraud, tampering, counterfeiting and terrorist exploitation Is strongly resistant to identity fraud, tampering, counterfeiting and terrorist exploitation Is only issued by providers whose reliability has been established Is only issued by providers whose reliability has been established A PIV card will allow entrance to all VA facilities A PIV card will allow entrance to all VA facilities

7 PIV Roles FIPS 201 requires a separation of roles (jobs) during the PIV issuance process. FIPS 201 requires a separation of roles (jobs) during the PIV issuance process. An employee cannot perform more than one role (except for Facility PIV Card Applicant Representative and Facility Privacy Official) An employee cannot perform more than one role (except for Facility PIV Card Applicant Representative and Facility Privacy Official) Prior to start of the PIV-I process at a facility, employees or contractors must be appointed and certified for each role Prior to start of the PIV-I process at a facility, employees or contractors must be appointed and certified for each role Facility PIV Card Issuance (PCI) Manager Facility PIV Card Issuance (PCI) Manager Official who manages the PIV issuance process at a facility Official who manages the PIV issuance process at a facility Ensures all services specified in FIPS 201 are provided reliably and PIV cards are produced and issued in accordance with requirements. (One primary and one alternate per facility.) Ensures all services specified in FIPS 201 are provided reliably and PIV cards are produced and issued in accordance with requirements. (One primary and one alternate per facility.) PIV Sponsor PIV Sponsor Official who sponsors the Applicant for a PIV card or Temporary Identity Badge Official who sponsors the Applicant for a PIV card or Temporary Identity Badge Is in the best position to know if Applicant requires a PIV Card. (One or more per facility. Facilities may have separate PIV sponsors for employees, contractors, and volunteers/affiliates.) Is in the best position to know if Applicant requires a PIV Card. (One or more per facility. Facilities may have separate PIV sponsors for employees, contractors, and volunteers/affiliates.) PIV Registrar PIV Registrar Official who performs Applicant identity proofing and enrollment functions. (One or more per facility. Most likely assigned to Human Resources or Security and Law Enforcement.) Official who performs Applicant identity proofing and enrollment functions. (One or more per facility. Most likely assigned to Human Resources or Security and Law Enforcement.) PIV Issuer PIV Issuer Official who issues the PIV card or Temporary Identity Badge to the Applicant. (One or more per facility. Most likely assigned to Human Resources or Security and Law Enforcement.) Official who issues the PIV card or Temporary Identity Badge to the Applicant. (One or more per facility. Most likely assigned to Human Resources or Security and Law Enforcement.) Facility PIV Card Applicant Representative Facility PIV Card Applicant Representative Official who represents the interests of PIV Applicants during the PIV card issuance process. (At least one per facility.) Official who represents the interests of PIV Applicants during the PIV card issuance process. (At least one per facility.) Facility Privacy Official Facility Privacy Official Official who oversees privacy issues at the facility. (At least one per facility.) Official who oversees privacy issues at the facility. (At least one per facility.)

8 PIV-I and PIV II VA will implement the PIV card in a two phased approach. VA will implement the PIV card in a two phased approach. In Phase I (PIV-I), a new process will be used for issuing current facility badges. In Phase I (PIV-I), a new process will be used for issuing current facility badges. Starts at VACO on Dec 12, 2006 Starts at VACO on Dec 12, 2006 Other VA sites will start PIV-I throughout Jan-Oct 2006 Other VA sites will start PIV-I throughout Jan-Oct 2006 In Phase II (PIV-II), the PIV Card Issuing (PCI) office will issue a new identity card that will be used for both physical access to VACO buildings and logical access to VA computer systems. In Phase II (PIV-II), the PIV Card Issuing (PCI) office will issue a new identity card that will be used for both physical access to VACO buildings and logical access to VA computer systems. Phase II in Oct Phase II in Oct 2006.