Where are States Now? Preliminary Legal & Security Survey Results Jim Whitter National Governors’Association Center for Best Practices January 9, 2001
General Information 15 states responded so far (30%) Laws and Policies –14 have electronic signature laws –95% have state or agency policies on system security and electronic signatures –Only 40% have policies on electronic recordkeeping
General Information 75% currently receive electronic data –Air, state specific programs, SDWA, RCRA, NPDES 66% planning to receive electronic data in next 1-2 years –NPDES, RCRA, state specific, Air, SDWA State programs include: Oil & gas permitting, toxics, stormwater monitoring, septic & wastewater, etc.
General Information States are evenly split between planning and implementation stages –40% operational, 33% conceptual stage, rest fall out someplace in between Of 9 systems in operation: –5 working for 3+ years –4 less than 3 years
General Information States are using multiple transmittal methods –50% Internet based transfer (Web or ) –28% diskette; only 3% VAN (1 state) File Formats –Commercial DB, delimited files, on-line data entry –5 states using XML
Electronic Signature Methods
Data Integrity Methods
Submitter Registration Method Most states use a combination of methods to register users, usually a signed application along with one or more of the following: –PIN Holder Agreement –Notarized Application –Online Registration Only 2 states rely on a single registration method
Submitter Registration Method Only 1 state currently using PKI and they are following the ACES Model. 2 states are proposing using PKI in the future.
Submitter Registration Method 1 state proposes to incorporate individuals authorized to send electronic data into permits via modifications. 1 state verifies and assign a "super-user" for the corporation, who in turn can authorize others users within that corporation. 4 states rely on corporations to self register and abide by governing statutory requirements.
Submitter Registration Method 3 states using a specific agreement on digital signatures that needed to be signed. Several others were proposing to do so. 1 state has a formal policy describing certificate revocation process. 5 states had less formal safeguards or processes for revoking electronic submission privileges.
Electronic Signature Certification 9 states: certification at time of submittal 8 states: review submission and submit changes Feedback Mechanisms –Automatic Acknowledgement: 8 –Echo Back: 2 –Paper Certification Language: 5 –Positive Acknowledgement by User: 5 –Complete Review of Data: 5
Electronic Signature Certification 9 states: certification at time of submittal 8 states: review submission and submit changes Feedback Mechanisms –Automatic Acknowledgement: 8 –Paper Certification Language: 5 –Positive Acknowledgement by User: 5 –Complete Review of Data: 5 –Echo Back: 2
Electronic Signature Certification Detecting Spurious Submissions –Investigate double submissions (5) –Response to automatic acknowledgement (3) –Submitter given opportunity to correct (2) –Data checked against permit (1) –Monthly summaries (1)
Transaction Record Record Types –Date and time of receipt (12) –Submittal records (8) –System access (6) –Signature use/certification log (4) –Submitter address information (3)
Transaction Record Paper Copies –None (5) –Required (4) –Optional (4) Copy of Record –Submitted Electronic File (9) –Paper (2) –Archived Microfilm (1) Preservation of contextual information varies
System Archives States are still determining archive process Methods –Tape, File Server, CD-ROM, Microfilm Most states archive immediately on receipt or entering submission into database Retention schedules are based on applicable statutes or state policies
System Archives Most states do not plan to archive signature or PIN information Most states have not addressed system migration, storage media degradation, or expiration of digital certificates