100 likes | 251 Views
Federal Identity Credentialing. Implementing HSPD-12 . Judith Spencer Chair, Federal Identity Credentialing Committee judith.spencer@gsa.gov. October 27, 2006. Deadline for Federal Agencies to begin issuing PIV cards to employees.
E N D
Federal Identity Credentialing Implementing HSPD-12 Judith Spencer Chair, Federal Identity Credentialing Committee judith.spencer@gsa.gov
October 27, 2006 • Deadline for Federal Agencies to begin issuing PIV cards to employees. • All major agencies issued at least one smart card to at least one employee in the agency
October 27, 2007 • All Federal employees (under 15 years service) should have a PIV card. October 27, 2008 • All Federal employees and contractor staff should have a PIV card.
Getting There • Managed Service Offerings • GSA Managed Service Offering • DOI/NBC Managed Service Offering • Going it alone • Social Security Administration • Veterans Affairs • Department of Defense • State Department • & others
Implementing PKI. . . • Shared Service Providers • Commercial service providers & Federal agency providers • Mandated by M-05-05 & FIPS 201 • COMMON Policy Driven • FPKI Certified Provider List • GSA Schedule 70 SIN 132-61 • Legacy Federal Enterprise PKI • Cross-certified with the FBCA at Medium Assurance or Higher • Must migrate to new key sizes as specified
Trust Framework DHS DOJ Treasury Federal Common Policy CA NASA DOD Entrust cross-certified Exostar USPTO Federal Bridge CA DOS ORC Treasury Cybertrust Verisign DOE Certipath State of Illinois Wells Fargo ACES GPO
High MediumHW Medium Basic Rudimentary Federal Bridge Common Policy Certification Authority Certification Authority Federal Identity Management E-Authentication HSPD-12 Level 4 Level 3 Level 2 Level 1
Beyond HSPD-12 • Extra-Federal Interest in Harmonization • States • Industry • Allied Governments • HSPD-12 Compatibility • Technical interoperability • Use FIPS-201 compliant smart cards • Recognition by Trust Framework • Cross Certify with the FBCA at Medium Assurance-Hardware or Higher
So I’ve got my PIV card. . . now what? Well. . . . . It’s the Apps, stupid!