Enterprise & FIPS 201

The FIPS 201 standard has provided Federal agencies with a blueprint for designing and implementing a comprehensive smart card credentialing program, but it also has provided industry a standard for credentialing and security throughout the enterprise. The signing of HSPD-12 and the subsequent creation of FIPS 201 has been termed a landmark event for the industry. For the first time, a formal standard now exists for government and industry to purchase biometric and credentialing solutions with the assurance of interoperability and accredited trust. In conjunction with other federal ID programs like TWIC (the Transportation Worker Identification Credential), Registered Traveler and the FRAC (First Responder Access Card), industry can now reliable implement enhanced credentials without fear of non-compliance to either Federal or industry standards.

Progressive organizations are pointing to FIPS 201 as a means of achieving a more holistic approach to security, incorporating personnel security (vetting, background checks, security training and awareness), logical security (network and application access), physical security (facility access, including video analytics), and incident monitoring and response. Although the current state of enterprise security may arguably be the best ever, enterprises still have a long way to go in terms of recognizing and breaking down various security “stovepipes” that result in disjointed and less than efficient security implementations.

Security convergence is a real and growing concept in the commercial world. Enterprises such as Sun, Boeing, Pfizer, Unisys, Lockheed Martin, Northrop Grumman and others are implementing smart card-based badges that provide employee access to both physical and logical resources. Vendors are building capabilities into systems so that physical access control systems can communicate with enterprise identity management systems and provide consolidated access control. Consolidating access control will enable corporations to realize some of the benefits that government agencies are beginning to enjoy. Centralizing operations that are often performed locally, such as personnel screening and vetting, can improve overall IT security and physical security. In addition, removing redundant stovepipe functions across an enterprise significantly reduces costs.

One of the most important benefits of using a FIPS 201 model in the enterprise is the strong assurance that the identity associated with a credential belongs to the correct individual. Special care needs to be taken early in the process so that the identity and associated credential can be trusted across logical and physical access control applications and across locations. FIPS 201 and the personal identity verification process identify a number of required steps and individuals and describes individual roles in the process:

• Sponsorship. A sponsor’s duty is to vouch for an applicant’s need for an enterprise credential and authorize applicant enrollment. The sponsor may also authorize the cost incurred by the credentialing process.

• Enrollment. The enrollment process is designed to verify the identity of an applicant and collect information from the applicant. Applicants must bring identification and are optionally fingerprinted and photographed at enrollment.

• Adjudication. Trusted adjudicators determine whether an applicant should receive a credential based on the results of the suitability check. Identity vetting procedures are part of the adjudication process, with disqualifiers defined as part of vetting procedures. Successfully passing adjudication triggers credential production. The level of adjudication varies from organization to organization, depending on the level of security/access required. Adjudication can be structured so that individuals who need access to something like a network operations center or security operations center are subjected to more extensive adjudication.

• Credential Production. Credentials can be personalized in a centralized facility or at local issuing stations. Relevant information is printed according to the standards, security features are added, and the electronic smart card chip is encoded with personal data.

• Issuance and Activation. When an applicant arrives to pick up the personalized credential, the issuer verifies the applicant’s identity by re-verifying the identity documents presented at enrollment and possibly matching the applicant’s fingerprint to the one used to enroll. The credential is then “unlocked,” digital certificates and a PIN are loaded onto the chip, and the credential is released to the applicant for use.

• Credential Use. Activated credentials can be used to validate identity electronically and access secure physical locations and computer networks. All of these process steps must be supported not only by technology but also by policies and procedures. It is only by the consistent execution and enforcement of policies and procedures that the overall integrity of the system can be ensured. FIPS 201 provides a best-practice framework for the entire identity proofing and issuance process that can be used by enterprises implementing robust employee identity management systems.

Enterprises have the opportunity to leverage the work that the Federal Government has done in FIPS 201 to define identity vetting and verification processes and specify conforming identity credential technology. While only Federal agencies can issue "official" cards, enterprises can follow FIPS 201 processes, use FIPS 201-defined technologies, and implement credentials that are interoperable or compatible, as appropriate. An interoperable credential is a credential that meets the FIPS 201 technical standards (and can therefore work with infrastructure elements, such as card readers) and also follows the FIPS 201 process for issuing credentials. Following the FIPS 201 process for credential issuance allows all Federal relying parties to trust the card, across organizations. This trust is established by a common enrollment, registration, and issuance process and a strong authentication credential that leverages a cross-certified and federated public key infrastructure. An interoperable credential would be of great value to enterprises that do business with the government and have a requirement to issue interoperable identity credentials. In addition, related organizations within an industry could decide to follow common FIPS 201 processes to establish a basis for trusting identity credentials across organizations or industry.

A compatible credential is a credential that meets the FIPS 201 technical specifications but does not follow the FIPS 201 process for credential issuance. Federal relying parties cannot automatically trust the card. Enterprises issuing compatible credentials can benefit by being able to use the growing range of products on the FIPS-201 Approved Products List. Cards, readers, software, and other products can be purchased from a variety of vendors, be connected, and function as a system.

FIPS 201 provides a defined framework and technical specifications for enterprises to:

• Follow a proven process for employee identity vetting;

• Implement an identity vetting process that provides the basis for trusting identities across organizations or with Federal agencies;

• Implement an identity credentialing solution that has the potential to be interoperable and compatible across organizations or with Federal agencies; and,

• Acquire proven products and services that meet FIPS 201 technical specifications from multiple vendors

The FIPS 201 standard delivers the following benefits to both government organizations and commercial enterprises:

• Specifies a “useful” and “secure” identity card that supports a wide range of use cases;

• Enables card support across a wide range of PCs, servers, and mobile devices;

• Defines processes and technical specifications that enable interoperability across organizations; and,

• Fosters competition to reduce prices

The FIPS 201 card offers the following advantages over other credentialing approaches for enterprises:

• It is supported by a wide range of manufacturers and integrators;

• It does not compel an organization to use a single vendor for key components;

• It provides flexible authentication, signature, and encryption functionality;

• It is well positioned to take advantage of emerging technologies, such as biometrics;

• As a standard that will be used by Federal agencies to issue credentials to millions of U.S. Federal employees and contractors, it has the advantage of scale; and,

• It provides the framework to support interoperable identity credentials across organizations.

Because of these factors, implementing a FIPS 201 card-based approach to identity credentials can be extremely beneficial to organizations. An organization using the FIPS 201 model and standard can take advantage of a high level of functionality at economical volume prices. The identity technology has been thoroughly scrutinized and is trusted at the highest levels. And, the credentialing process is flexible and has been thoroughly vetted to represent best practice.

The standardization of identity credentialing processes and approaches is a major step forward for identity management in both enterprises and government organizations. Standardization fosters interoperability. Standardization simplifies implementation by driving the industry to develop products, applications, processes, and practices that meet the standard and are interoperable. Standardization provides enterprises with a greater variety of products at a lower cost.

The FIPS 201 standard has established a foundation for both government and commercial identity credentialing programs. By using FIPS 201 as the basis for an employee identity credentialing system, enterprises can move toward standardized processes and technologies that enable interoperability and are supported by commercial off-the-shelf products from multiple vendors. By using FIPS 201, enterprises can take advantage of the investment being made by the U.S. government to implement standards-based identity credentialing programs.