Business and Systems Aligned. Business Empowered. TM Federal Identity Management Handbook May 5, 2005
Confidential and Proprietary 1 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Introduction Guidance for credentialing managers, their leadership, implementation teams, and other stakeholders as they pursue compliance with HSPD 12. Provides specific implementation direction on course of action, business & policy, schedule requirements, acquisition planning, migration planning, lessons learned, and case studies and implementation tools. A collaborative effort: The Federal Identity Credentialing Committee (FICC) Smart Card Interagency Advisory Board (IAB) Federal PKI Authority (FPKIA) Office of Management and Budget (OMB) National Institute for Standards and Technology (NIST) U.S. Department of Defense Smart Card Alliance Many other contributors
Confidential and Proprietary 2 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Organization Information Flow is similar to FIPS 201 with some key differences Major Sections Include 1.0 Introduction 2.0 PIV I – Common Identification, Security and Privacy Requirements 3.0 PIV - Validation Certification & Accreditation 4.0 PIV II – Front End Sub-System 5.0 Implementation Planning Appendix – Tools and References Primary Flow of PIV I and PIV II Sections Description Mandatory Requirements Optional Items Implementation Recommendations Idea and Suggestions Summary
Confidential and Proprietary 3 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Organization (Continued) Additional Guidance Meant to be all-inclusive and informative – but not too technical A “living” document with plans for regular update OMB Guidance & FAQ’s Agency Plan Template Implementation Roadmap Migration Planning Acquisition Planning Lesson’s Learned Case Studies Tools & Illustrations Useful Index Common Thread – Education, Training & Awareness
Confidential and Proprietary 4 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Implementation Plan Template
Confidential and Proprietary 5 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Implementation Roadmap Making the best use of the information Recognizes that all Agencies are at different starting points Provides a sample implementation path (how to get started) 1.Gain a clear understanding of your agency’s current access control policies 2.Reach agreement on future policy as it pertains to HSPD-12. This is key because these policies will drive your requirements 3.Involve the primary Agency Stakeholders in the process 4.Establish a list of objectives your agency wants to achieve while meeting the directive 5.Using the policy decisions develop an initial list of requirements. 6.Communication, Training & Awareness
Confidential and Proprietary 6 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Migration Planning
Confidential and Proprietary 7 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Sample Organization
Confidential and Proprietary 8 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Acquisition Planning Identifying Resource Requirements Change Management Identifying Potential Funding Streams Current Procurement Methods GSA Smart Card Contract Vehicle GSA Schedules Aggregated buy Acquisition Stakeholders
Confidential and Proprietary 9 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Acquisition Planning (Continued) Major Components of an Identity Management System
Confidential and Proprietary 10 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Anticipating Costs
Confidential and Proprietary 11 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Acquisition Planning (Continued) Agency Sponsorship Shared Service Providers Acquisition Planning Template (Appendix A) Statement of Need Background Acquisition Alternatives Life Cycle Costs Delivery Requirements Performance Period Risks as Identified in the OMB Agency Plan
Confidential and Proprietary 12 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Lessons Learned & Case Studies Lesson’s Learned Implementation Management Stakeholder Involvement System Design User Training Pre-Issuance Post-Issuance Case Studies Department of State Department of Interior Department of Homeland Security
Confidential and Proprietary 13 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Tools Sample PIV Request Form
Confidential and Proprietary 14 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Tools Implementation Checklist
Confidential and Proprietary 15 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Tools
Confidential and Proprietary 16 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Schedule Released for Public Comment Feb Comment Period Closed Mar Comments Incorporated Apr Revision submitted to FICC for Review & Comment Addition of OMB Guidance & Revised Agency Plan Template Planned Updates Conformance Testing Certification & Accreditation Reference Implementation End-User Training GSA Acquisition Services Agency Sponsorship NIST Special Technical Pubs Section 508 (Disabilities Act)
Confidential and Proprietary 17 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. References Supporting Publications SP – Interfaces for Personal Identity Verification (card interface commands and responses) SP – Biometric Data Specification for Personal Identity Verification SP –Cryptographic Algorithms and Key Sizes for Personal Identity Verification NIST PIV Website ( Documents Frequently Asked Questions (FAQs) Comments Received in Original Format FICC Website (CIO.Gov/FICC) Identity Management Handbook Smart Card Handbook
Confidential and Proprietary 18 © 2005 BearingPoint, Inc. All trademarks are property of their respective owners. Contact Ralph Billeri BearingPoint Inc Duke St. Suite 700 Alexandria, VA