Risk
2/4/2011
03:33 PM
Connect Directly
RSS
E-Mail
50%
50%

Feds Set Deadline For Identity Smart Card Program

Agencies have until March 31 to come up with an implementation plan for a government-wide biometric-based credential system for employees and contractors.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters

Federal agencies have until March 31 to come up with an implementation plan for a new government-wide identification system that leverages biometric technology and smart cards.

The federal government has stepped up plans to use the Federal Personal Identity Verification (PIV) system to verify employee and contractor credentials to access federal facilities and IT networks and systems, according to a memo from the Department of Homeland Security (DHS) issued Thursday.

The move to the system is mandated by Homeland Security Presidential Directive 12 (HSPD 12), a federal cybersecurity initiative the government said is aimed at increasing security and efficiency, reducing identity fraud, cutting costs and protecting personal privacy. Cybersecurity is a chief concern of the federal government, and the system is one of many it's taking to provide more security both internally and externally.

To qualify for PIV credentials, federal employees must have their fingerprints scanned and undergo background checks. Their personal identifying information is contained in cards that are scanned on card readers before entering federal facilities or logging on to federal IT networks. As of December 2010, 4.5 million federal employees had achieved PIV credentials, and 5 million of 5.7 million federal employees and contractors have completed background investigations, according to the memo.

In addition to outlining a time frame, the memo also lays out requirements for how agencies must ensure their facilities and IT systems are ready to accept the PIV cards.

Accessing systems at Marine Camp Lejeune

The DHS mandates that all new systems under development must support PIV credentials according to guidelines from the National Institute of Technology (NIST) before they can be deployed.

Further, effective in October at the beginning of the government's 2012 fiscal year, agencies must upgrade all existing "physical and logical" access control systems to support the PIV system before they can use any technology refresh funds for other projects.

The DHS also is requiring that any procurements involving facility or IT system access meet HSPD-12 policy. PIV credentials and acceptance of the credentials also must be interoperable, according to the memo.

The memo directs each agency to pick a lead official to oversee their implementation plan.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVE-2012-5487
Published: 2014-09-30
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVE-2012-5488
Published: 2014-09-30
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVE-2012-5489
Published: 2014-09-30
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.