1 of 53

�Treasury Board Identity Management Policy �and Pan-Canadian Trust Framework��Identity Management Policy Workshop�� �

UNCLASSIFIED / NON CLASSIFIÉ

2 of 53

Workshop Objectives

Policy Overview & Federated Identity

    • Overview of TB Policy Suite Architecture
    • PGS – Identity Management
    • Identity as a starting point for Services & Benefits
    • Drive to Digital Identity
    • Federated Approach

Pan-Canadian Identity Validation Standard

Guideline on Defining Authentication Requirements

Guideline on Identity Assurance

CSE User Authentication Guidance for IT Systems

Case Studies

Annexes – Additional information

2

UNCLASSIFIED / NON CLASSIFIÉ

3 of 53

Policy Overview �& �Federated Identity

3

UNCLASSIFIED / NON CLASSIFIÉ

4 of 53

Policy Foundation and Application

Issued under Policy on Government Security (PGS)

2009: Directive on Identity Management (applies to employees, external clients, organizations, and devices)

2011: Federating Identity Management in the GC

2012: Guideline on Defining Authentication Requirements

2013: Standard on Identity and Credential Assurance

2015: Guideline on Identity Assurance

2016: CSE User Authentication Guidance for IT Systems

4

Policy

Application

Individuals

Organizations

Devices

Internal

*ICAS - Internal Centralized Authentication Service

  • GC Employees
  • Contractors
  • Departments / Agencies
  • Crown Corporations
  • Mobile devices

External

Access to online services offered to the public

  • Citizens
  • Clients of GC services
  • Corporations
  • Associations
  • Proprietorships
  • Smart devices
  • IoT

UNCLASSIFIED / NON CLASSIFIÉ

5 of 53

5

Policies

Directives

Mandatory Procedures and Standards

Legislation

Guideline on Developing a Departmental Security Plan

 Other Guidelines and Tools

Guidelines and Tools

Detailed Government-wide Responsibilities

GC Security Event Management Protocols

Lead Security Agencies Guidance and Tools

Financial Administration Act  

Directive on Identity Management 

Policy on Government Security 

Policy on Government Security (PGS) (2009 – amended 2012) 

Directive on Departmental Security Management (DDSM) (2009)

Physical Security (2004)

Security Screening (2014)

Security Organization & Administration (1994)

Security in Contracting (1994)

Readiness Levels for Federal Government Facilities (2002)

Business Continuity Planning (2004)

Information Technology Incident Management Plan 

Financial Administration Act (FAA)

Directive on Identity Management (2009) 

Developing a Departmental Security Plan 

Security Screening and Security in Contracting Guidelines and Tools (e.g. briefing form, SRCL)

Guideline on Identity Assurance (2015)

Lead Security Agencies Guidance and Tools

Management of Information Technology Security (2004) 

Identity and Credential Assurance (2013)

5

NOTE: Standard on Security Screening not included in the reset exercise

NEW (PROPOSED)

CURRENT (OLD)

Guideline on Identity Assurance (2015)

Policy on Acceptable Network and Device Use (PANDU) (2013) 

Standard on Security Categorization

Mandatory Procedures on Security Controls 

Standard on Identity and Credential Assurance

Standard on Security Event Reporting

  • Security Screening
  • Security Awareness & Training
  • Business Continuity Management
  • Information Management Security

  • Information Technology Security 
  • Physical Security
  • Security in Contracts and Other Arrangements
  • Security Event Management

Security Policy Architecture

Standard on Acceptable Network and Device Use

Directive on Security Management 

UNCLASSIFIED / NON CLASSIFIÉ

6 of 53

Trusted Digital Identity

6

‘This is me’

New PGS Definitions:

  • trusted digital identity: An electronic representation of a person, used exclusively by that same person, to receive valued services and to carry out transactions with trust and confidence.
  • trust framework: A set of agreed on definitions, principles, conformance criteria, assessment approach, standards and specifications.
  • Credential Assurance

‘I am the same user for each interaction’

  • Notice and Consent

‘I have given my consent’

  • Trusted Infrastructure

‘ Services/capabilities are �enabled using trusted infrastruct’

  • Identity Assurance

‘I am a real person’

Trusted Digital Identity

UNCLASSIFIED / NON CLASSIFIÉ

7 of 53

Directive on Identity Management

New requirements:

4.1.7. Accepting trusted digital identities provided through an approved trust framework as an equivalent alternative to in-person interactions, through an assessment of the following processes:

    • Identity and program-specific information
    • Identity and credential assurance (according to Standard on Identity and Credential Assurance)
    • Identity enrolment
    • Notification and consent

4.1.9 Using mandatory enterprise services for identity management, credential management and cyber authentication.

7

UNCLASSIFIED / NON CLASSIFIÉ

8 of 53

To fulfil client service, personal information collected to

    • Establish person is who they claim to be (identity proofing)
        • In future, could include validation of personal information with Provinces/Territories
    • determine benefit entitlement/eligibility

Desired outcome: provide high quality (digital) services and improved client experience through

  • seamless online transactions with GC institutions through single, secure login
  • re-use of personal information for various government services without need to re-enter with each application for service (tell-us-once)
  • Minimizing cyber security risk through single secure log in

8

Identity and Authentication in Service Context

UNCLASSIFIED / NON CLASSIFIÉ

9 of 53

Identity: Starting Point for Services & Benefits

9

Healthcare Sector

Public Sector

Financial Sector

Who are you?

How will you pay?

Who are you?

What is your medical history?

Who are you?

Are you eligible for a government benefit?

Sector Issues

  • Financial fraud
  • Money laundering
  • Higher transaction fees

Sector Issues

  • Benefits fraud
  • Longer processing times
  • Redundant processes

Sector Issues

  • Prescription fraud
  • Patient Privacy
  • Record integrity

… but the impacts are felt by everyone

!

Identity risks�translate into:

!

Identity risks�translate into:

!

Identity risks�translate into:

Today, identity is managed separately by each sector…

UNCLASSIFIED / NON CLASSIFIÉ

10 of 53

The Drive to Digital Service Delivery

Priorities

    • Creation of a Single Online Window
    • Citizen-focused digital service delivery
      • Access to information
      • Improved client experience
      • Web Renewal: Canada.ca portal

Strategy

    • Policy to enable standardized services
    • Leverage private sector solutions
    • Enable federated identity across domestic and international boundaries

10

ID

UNCLASSIFIED / NON CLASSIFIÉ

11 of 53

Choose Sign-In Partner or GCKey

11

UNCLASSIFIED / NON CLASSIFIÉ

12 of 53

Evolution to Federating Identity

12

  • Multiple Recognized Providers
  • Multiple Credential Options
  • Multiple Levels of Assurance

Cyber Authentication�Service

Commercial

Government of�Canada Issued

Mandatory Services

Other jurisdictions

Federating Credentials

Federating Identity

Government of Canada Approach

  • Government of Canada Identity Validation Service
  • Identity Business & Technical Architecture

Government of Canada �Identity Federation�Service

Federation

Government of Canada�Identity �Validation Service

Pilot Projects

Standards-based

Government of Canada�Identity Assurance�Service

Pan-Canadian Approach

Identity Federation�Service

Federation Enablers

Identity �Services

  • Commercial Services
  • Multiple Authoritative Identity Sources

Policy Enablers

Federation

Standards-based

Federation

Standards-based

Legislative Enablers

Identity�Federation �Services

Credential �Federation�Services

UNCLASSIFIED / NON CLASSIFIÉ

13 of 53

Principles:

  • Respects privacy
  • Client choice
  • Governments play key role
  • Collaborate with trusted Federal, Provincial, Territorial and private sector institutions
  • Phased approach to evolving services and infrastructure

13

Pan-Canadian Policy Direction

2014: Identity Validation Standard

2016/17: Pan-Canadian Trust Framework

(Technical Standards, Specifications, Certifications, Privacy, Security, Service delivery, Organizational)

Federated Approach

Trusting credentials and identities:

  • Across jurisdictions
  • Across sectors
  • Internationally

Federating Credentials

Federating Identity

trusting credentials �issued by other jurisdictions and industry sectors’

trusting identities �that have been established by other jurisdictions’

Pan-Canadian Collaboration

UNCLASSIFIED / NON CLASSIFIÉ

14 of 53

Pan-Canadian Trust Framework

14

UNCLASSIFIED / NON CLASSIFIÉ

15 of 53

Pan-Canadian Trust Framework: Context

FPT Deputy Ministers’ Table on Service Delivery Collaboration

FPT Clerks and Cabinet Secretaries

Joint Councils

Identity Management Sub Committee (IMSC)

Public Sector �Service Delivery Council

Public Sector �CIO Council

Digital Identification Authentication Council of Canada (DIACC)

DIACC* Board of Directors�(Includes Public Sector membership)

IMSC Working Groups

DIACC Working Groups

Public Sector

Private Sector/�Industry Initiatives

Canada’s Digital Interchange�(CDI)

Immigration Refugee Citizenship Canada / Employment Social Development Canada

IRCC/ESDC

Identity Linkages Project (ILP)

CDI�Working Groups

15

Other Initiatives Underway

  • Death Notification Project
  • Business Number or Expedited Business Start
  • DIACC Proof of Concept for Residency

*Digital Identification and Authentication Council of Canada

UNCLASSIFIED / NON CLASSIFIÉ

16 of 53

Building a Pan-Canadian Trust Framework

Has the user given consent?

16

Trusted Digital Identity

Including Public Sector and Private Sector Considerations

Verified Person Component

  • Identity Resolution
  • Identity Establishment
  • Identity Validation*
  • Identity Verification
  • Identity Maintenance*

Consent and Delegation

  • Credential Determination
  • Identity Linking
  • Owner Authorization

Is it a real/existing person?

Verified Login

  • Credential Issuance
  • Credential Authentication
  • Credential Recovery
  • Credential Revocation

Verified Person

  • Identity Resolution
  • Identity Establishment
  • Identity Validation
  • Identity Verification
  • Identity Maintenance

Is it the same person?

Pan-Canadian InfrastructureTechnical Standards, Specifications, Certifications Privacy, Security, Service Delivery, Organizational

UNCLASSIFIED / NON CLASSIFIÉ

17 of 53

Pan-Canadian Standardized Concepts

17

UNCLASSIFIED / NON CLASSIFIÉ

18 of 53

The Personal Information Categories

18

2016-09-26

  1. PERSON NAME
  2. DATE OF EVENT
  3. PLACE OF EVENT
  4. SEX, GENDER, DOCUMENTED SEX
  5. ASSIGNED IDENTIFIER
  6. PERSON STATUS
  7. ADDRESS
  8. ASSOCIATED PERSON
  9. BIOMETRIC IMAGE
  10. PERSON AGE
  11. CONTACT DETAIL
  12. BIRTH VITAL EVENT DETAIL
  13. DEATH VITAL EVENT DETAIL
  14. STILLBIRTH VITAL EVENT DETAIL

UNCLASSIFIED / NON CLASSIFIÉ

19 of 53

Personal Information Categories�by Function

19

Personal Information Category

Function

PERSON NAME

Validation

Retrieval

Notification

DATE OF EVENT

PLACE OF EVENT

SEX, GENDER, DOCUMENTED SEX

ASSIGNED IDENTIFIER

PERSON STATUS

ADDRESS

ASSOCIATED PERSON

BIOMETRIC IMAGE

PERSON AGE

CONTACT DETAIL

BIRTH VITAL EVENT DETAIL

DEATH VITAL EVENT DETAIL

STILLBIRTH VITAL EVENT DETAIL

UNCLASSIFIED / NON CLASSIFIÉ

20 of 53

Guideline on Defining Authentication Requirements

20

UNCLASSIFIED / NON CLASSIFIÉ

21 of 53

Evolution of Authentication

‘State of the art’ authentication practices are rapidly evolving

    • More holistic, adaptive and responsive approach to authentication
    • Credential authentication is now considered part of an overall ‘layered security’ scheme that can be employed to mitigate risk. Examples include
      • Device identification, challenge questions, Out-of-band transmission, Suspicious activity detection and response
    • ‘weakness in one control may be compensated for by the strength of a different control’ (Revised Federal Financial Institution Examination Council Guidance 2011 - USA)

Recently published guidance documents are defining ‘compensating factors’ (or ‘compensating controls’) as a key concept to address the following:

    • Added flexibility to authenticate users in many contexts and scenarios (e.g. domestic vs. international, browser vs. mobile apps, account-to-account access)

21

UNCLASSIFIED / NON CLASSIFIÉ

22 of 53

Guideline on Defining Authentication Requirements

Purpose of Guidance:

    • Sets out Government of Canada direction
    • Assists departments and agencies to define their authentication requirements relative to program and service delivery requirements
    • Enables departments to use standardized approaches while retaining flexibility to further define requirements as necessary

Tools Provided:

    • Assurance Level Requirement Worksheet
      • Comprehensive assessment approach to determine a standardized level of assurance requirement
    • Determination of Authentication Requirements
      • Identity Assurance Requirements
      • Credential Assurance Requirements
      • Authentication Solution Requirements
      • Compensating Factors, Other Safeguards and Acceptable Risk

22

UNCLASSIFIED / NON CLASSIFIÉ

23 of 53

23

Guideline on Identity Assurance

Information Technology Security Guideline�ITSP.30.031 V2: �User Authentication �Guidance for IT Systems

ITSG-33:�IT Security Risk Management: �A Lifecycle Approach

Guideline on Defining Authentication Requirements

Step 1:

Determine assurance level requirement

Step 2:

Determine authentication options (including compensating factors and other safeguards)

Implementing �identity assurance level requirements

Impact Assessment

Risk Mitigation

Use of cyber authentication services

Identity Assurance �Level Requirement

Credential Assurance Level Requirement

Authentication Requirements

Identity Context

Federation of Identity?

Federation of

Credential?

Enabling Federation

UNCLASSIFIED / NON CLASSIFIÉ

24 of 53

Approach to Defining Requirements

24

Assurance Level �Requirement

Impact Assessment determines �the level of assurance required

Selection of Controls uses standardized requirements (where possible), compensating factors, and acceptable risk

Performed by the program/service owners

Performed by security and IT practitioners

What level of assurance do I need to achieve my program objectives?

What methods, safeguards or measures do I have, or need to put in place?

Answers the question

Answers the question

Collaboration between Program/Service owners & IT/Security practitioners…

Level 4 �Very high confidence required

Level 3 �High confidence required

Level 2�Some confidence required

Level 1 �Low confidence required

UNCLASSIFIED / NON CLASSIFIÉ

25 of 53

Major Steps in Defining Requirements

25

Enabling Departmental Flexibility

Facilitate Adoption of Standardized �Solutions and Services

Step 1

Determine Assurance �Level Requirement

Step 2

Determine Authentication

Requirements

What level of assurance do I need to achieve my program objectives?

What methods, safeguards or measures do I have, or need to put in place?

Assurance�Level

Requirement

Key Assessment Factors

  • Program Objectives
  • Business Context
  • Client Impact
  • Service Delivery
  • Transactions

Key Assessment Factors

  • Delivery Channels
  • Threats/Vulnerabilities
  • Departmental Mandate
  • Costs, Constraints
  • Legal Privacy and Security
  • Client/User Experience

Key Outcomes

Identity Assurance �Requirements

Decision�Outputs

Credential Assurance�Requirements

Authentication�Solution Requirements

Compensating �Factors

Other �Safeguards

Acceptable �Risk

Key Activities

Input of existing assessments

  • Corporate Risk Profile
  • TRAs, SOS, Risk Assessments
  • etc.

UNCLASSIFIED / NON CLASSIFIÉ

26 of 53

Compensating Factors

  • Additional measure employed during the authentication process that reduces the likelihood of an authentication error (also referred to as compensating control)
  • Compensating factors may be employed when a specific control does not provide a required assurance level (due to cost, usability, etc.)
  • Examples
    • Shared secrets
    • Validation of identity information, �program information
    • Token/grid card challenge, IP address, �device confirmation
    • Out-of-band (e.g. call to mobile)

26

26

Assurance Level

Level 4

Level 3

Level 2

Level 1

None

Required Assurance Level

Standardized

requirements (i.e. measures) provide a specified level of assurance

Compensating factors�can be used to manage residual risk

UNCLASSIFIED / NON CLASSIFIÉ

27 of 53

Use of Compensating Factors, Other Safeguards and Acceptable Risk

Defined in guidance

    • Compensating Factors – additional safeguards employed during the authentication process
    • Other Safeguards – use of other security control mechanisms that are outside of the authentication process (e.g. downstream security controls) which can also mitigate risk
    • Residual Risk –Residual risk can be mitigated using compensating controls and/or other safeguards

These concepts enable departments to have flexibility in determining their optimal authentication solution requirements. Departments must decide on:

    • Adoption of commercial services and use of standardized requirements
    • Use of compensating controls, and/or safeguards to mitigate residual risk.

27

UNCLASSIFIED / NON CLASSIFIÉ

28 of 53

Guideline on Identity Assurance

28

UNCLASSIFIED / NON CLASSIFIÉ

29 of 53

Credential and Identity Assurance

29

Level 4 Very high confidence required

Compromise: serious to catastrophic harm

Level 3 High confidence required

Compromise: moderate to serious harm

Level 2 Some confidence required

Compromise: minimal to moderate harm

Level 1 Little confidence required

Compromise: nil to minimal harm

Credential Assurance

Identity Assurance

User X

Binding a credential to a unique individual

Assurance Levels

An individual

Establishing the real identity of an individual

Assurance Levels

Level 4 Very high confidence required

Compromise: serious to catastrophic harm

Level 3 High confidence required

Compromise: moderate to serious harm

Level 2 Some confidence required

Compromise: minimal to moderate harm

Level 1 Little confidence required

Compromise: nil to minimal harm

UNCLASSIFIED / NON CLASSIFIÉ

30 of 53

Overview of Guideline on Identity Assurance

Provides implementation guidance on four requirements specified in Appendix C of the Standard on Identity and Credential Assurance:

  1. Uniqueness: An identity must be unique
    • Definition of identity information (versus program information)�
  2. Evidence of Identity: Evidence must support the claims made by an individual
    • Foundational and supporting evidence of identity�
  3. Accuracy of Identity Information: Identity information must be accurate
    • Confirmation of identity information using an authoritative source�
  4. Linkage of identity information to individual: Identity information must relate to the individual making the claim.
    • Linkage methods: knowledge-based, biological/behavioural characteristics, trusted referee, physical possession

30

UNCLASSIFIED / NON CLASSIFIÉ

31 of 53

Overview of Guideline (cont’d)

Provides guidance on integrating identity assurance into departmental business and system processes:

  • Efficient and Transparent Procedures
  • Privacy Concerns
  • Linkage and Binding
  • Using Identity Lifecycle Models�

Federation consideration for departments when:

  • Acting in the role of an authoritative or relying party
  • A member or not a member of a federation�

Considerations for main types of fraud:

  • Document,
  • Record
  • Impostor

31

UNCLASSIFIED / NON CLASSIFIÉ

32 of 53

Example: Establishing Identity Assurance (for Level 3)

32

Requirement

Level 3 Identity Assurance

Uniqueness

Define identity information

Define context

Evidence of Identity

Two instances of evidence of identity

Accuracy of Identity Information

Identity information acceptably matches assertion by an individual and all instances of evidence of identity

and

Confirmation of the foundational evidence of identity using authoritative source

and

Confirmation that supporting evidence of identity originates from appropriate authority, using authoritative source or inspection by trained examiner

Linkage of Identity Information to Individual

At least one of the following:

  1. Knowledge-based confirmation
  2. Biological or behavioural characteristic confirmation
  3. Trusted referee confirmation
  4. Physical possession confirmation

UNCLASSIFIED / NON CLASSIFIÉ

33 of 53

Standard on Identity and Credential Assurance�Appendix C: Minimum Requirements

33

Requirement

Level 1

Level 2

Level 3

Level 4

Uniqueness

Define identity information

Define context

Evidence of Identity

No restriction on what is provided as evidence

One instance of evidence of identity

Two instances of evidence of identity

(At least one must be foundational evidence of identity.)

Three instances of evidence of identity

(At least one must be foundational evidence of identity.)

Accuracy of Identity Information

Acceptance of self-assertion of identity information by an individual

Identity information acceptably matches assertion by an individual and evidence of identity

and

Confirmation that evidence of identity originates from appropriate authority

Identity information acceptably matches assertion by an individual and all instances of evidence of identity

and

Confirmation of the foundational evidence of identity using authoritative source

and

Confirmation that supporting evidence of identity originates from appropriate authority, using authoritative source

or inspection by trained examiner

Identity information acceptably matches assertion by an individual and all instances of evidence of identity

and

Confirmation of the foundational evidence of identity using authoritative source

and

Confirmation that supporting evidence of identity originates from appropriate authority, using authoritative source

or inspection by trained examiner

Table continued on next slide…

UNCLASSIFIED / NON CLASSIFIÉ

34 of 53

Standard on Identity and Credential Assurance�Appendix C: Minimum Requirements

34

Requirement

Level 1

Level 2

Level 3

Level 4

Linkage of Identity Information to �Individual

No requirement

No requirement

At least one of the following:

i) Knowledge-based confirmation

ii) Biological or behavioural characteristic confirmation

iii) Trusted referee confirmation

iv) Physical possession confirmation

At least three of the following:

i) Knowledge-based confirmation

ii) Biological or behavioural characteristic confirmation

iii) Trusted referee confirmation

iv) Physical possession confirmation

Note: When the authoritative source is outside of Canadian jurisdiction, the accuracy of identity information will be determined through a risk-managed approach.

Table continued from previous slide…

UNCLASSIFIED / NON CLASSIFIÉ

35 of 53

35

Assurance Level Impact Assessment Summary Table

Name of Program/Service/Transaction:

Assessment Question:

If this program, service or transaction benefits the wrong person, would it like result in… (complete each question using the table cells below)

Assessment Category

Level 1�Assessment

Level 2 Assessment

Level 3 Assessment

Level 4 Assessment

1. Inconvenience, distress/loss of standing or reputation

2. Financial loss

3. Harm to program or public interest

4. Unauthorized release of sensitive personal or commercial information.

5. Unauthorized release of sensitive government information.

6. Civil or criminal violations

7. Personal Safety

8. National security

ASSURANCE LEVEL REQUIREMENT

  • Minimum Level 1 Required
  • Minimum Level 2 Required
  • Minimum Level 3 Required
  • Minimum Level 4 Required

UNCLASSIFIED / NON CLASSIFIÉ

36 of 53

Example: Passport Program

UNCLASSIFIED / NON CLASSIFIÉ

37 of 53

CSE User Authentication Guidance for IT Systems

37

UNCLASSIFIED / NON CLASSIFIÉ

38 of 53

Relation to TBS Guidelines

  • The TBS Guideline on Defining Authentication Requirements separates authentication into identity assurance and credential assurance.
  • ITSP.30.31 provides the guidance for credential assurance.

Identity

Guideline on Defining Authentication Requirements

Standard on Identity and Credential Assurance

Credential

ITSP.30.031

UNCLASSIFIED / NON CLASSIFIÉ

39 of 53

Levels of Assurance - Recommended use in the GC

  • Examples of recommended uses of LoA credentials in the GC:

LoA

Recommended Use in the GC

1

Not recommended for GC use.

2

End-user access to systems or information.

3

Administrative access to systems or information.

4

Administrative access to high-value systems or information.

UNCLASSIFIED / NON CLASSIFIÉ

40 of 53

Levels of Assurance Applied to Tokens

  • ITSP.30.031 provides a framework for selecting authentication solutions:

LoA

Main Characteristic

Examples

1

Basic authentication methods – not recommended for GC use.

Password or PIN systems with poorly secured databases and/or recovery methods

2

Standard, typically single-factor end-user authentication solutions

Memorized Secret Tokens, Pre-Registered Knowledge Tokens, Look-up Secret Tokens, Out of Band Tokens, software cryptographic tokens, and Single Factor One-Time Password Devices

3

Two-factor authentication methods using a hardware factor

Passwords/PINS combined with OTP Tokens and Smartphones

4

Two-factor authentication with a cryptographically-based hardware factor

Hardware cryptographic tokens, multi-factor One-Time-Password devices

UNCLASSIFIED / NON CLASSIFIÉ

41 of 53

Case Studies

41

UNCLASSIFIED / NON CLASSIFIÉ

42 of 53

Case Study: Passport Program

Context

  • Small organization
  • Comparably few products/programs to assess
    • Eight travel document products
  • Highly visible and used product

Preparation

  • Briefings at senior management committees on Standard and Guideline during drafting stages
  • Preparatory briefing on assessments with affected senior managers

Key Lessons

  • Importance of organizational awareness of impacts
  • Conduct assessments as soon as possible

UNCLASSIFIED / NON CLASSIFIÉ

43 of 53

Case Study: Passport Program

Conducting the Assessments

  • Gathered key players
    • Senior managers from Operations (Chief Operating Officer), Security, and Policy
    • Invited subject matter experts from Treasury Board to observe and advise
  • Opened session with review of key sections of Guidelines to ensure common understanding of task and methodology
  • Reviewed all eight products in one session
    • Allowed for consistency of application of Guideline
  • Used a custom grid to methodically assess each product across all eight categories of harm
    • Obtained consensus on each category before advancing to the next
    • Documented the rationale for each decision

Key Lessons

  • In addition to program experts, include SME on the TB policy suite
  • Provide custom tools
  • Debates can digress, ensure a strong chair manages the discussion�

UNCLASSIFIED / NON CLASSIFIÉ

44 of 53

Case Study: Passport Program

Documenting the Results

  • Prepared a separate assessment for each product
  • Documented the rationale for each category of harm
  • Consulted with legal services
  • Documented any change to agreed upon levels under separate cover
  • Circulated for approval by participating senior managers and legal services

Key Lessons

  • When in doubt – Consult
  • Some levels will likely change as rationale is elaborated
  • If possible, have dedicated resource(s) for project to see it through from beginning to end

UNCLASSIFIED / NON CLASSIFIÉ

45 of 53

Case Study: CRA

Overview

  • The CRA offers numerous online services for individuals, businesses and representatives

  • The CRA establishes an identity assurance, through processes and IT systems, when there is a need to know who is at the other end of the computer

  • An Identity Assurance Risk Assessment is completed for each new or modified service to determine the identity assurance level required

Key Lesson

  • Informing impacted stakeholders of the purpose of the risk assessment process allows for a better understanding and appreciation

UNCLASSIFIED / NON CLASSIFIÉ

46 of 53

Case Study: CRA

Risk Assessment Process

  • The CRA’s risk assessment process involves completing an Assurance Level Requirement Worksheet to:
    • identify categories of harm and impacts to an individual or the Agency
    • evaluate the risks and threats with the proposed or modified online service

  • Based on the assessment results, a recommendation with a rationale is prepared and provided to the responsible program area

Key Lesson

  • Performing a thorough analysis of the program/service to be implemented is a crucial step in determining the appropriate level of identity assurance

UNCLASSIFIED / NON CLASSIFIÉ

47 of 53

Case Study: CRA

Outcome and Next Steps

  • The program area makes the final decision on the service’s risk profile as the risk accountability ultimately is borne by functional owners

  • Next steps include assisting program area in the determination of the authentication options in order to meet the assurance level requirement

Key Lesson

  • Conducting risk assessments at the onset of a project to determine the level of identity assurance saves time and effort

UNCLASSIFIED / NON CLASSIFIÉ

48 of 53

Annex

For Further Information

48

UNCLASSIFIED / NON CLASSIFIÉ

49 of 53

Annex A - Links to Key Documents

TB/TBS CIO/CSE Approved Versions:

Draft Versions

49

UNCLASSIFIED / NON CLASSIFIÉ

50 of 53

Annex B - Key PGS Definitions

50

Term

Definition

Credential

A unique physical object or electronic identifier issued to, or associated with, an individual, organization or device.

Evidence of Identity

A record from an authoritative source indicating an individual's identity. There are two categories of evidence of identity: foundational and supporting.

Foundational Evidence of Identity

Evidence of identity that establishes core identity information such as given name(s), surname, date of birth and place of birth. Examples include records of birth, immigration or citizenship from an authority with the necessary jurisdiction.

Identity

A reference or designation used to distinguish a unique individual, organization or device.

Supporting Evidence of Identity

Evidence of identity that corroborates the foundational evidence of identity and assists in linking the identity information to an individual. It may also provide additional information such as a photo, signature or address.

Trust Framework

A set of agreed on definitions, principles, conformance criteria, assessment approach, standards, and specifications.

Trusted Digital Identity

An electronic representation of a person, used exclusively by that same person, to receive valued services and to carry out transactions with trust and confidence.

UNCLASSIFIED / NON CLASSIFIÉ

51 of 53

Annex C - Pan-Canadian Definitions

51

Term

Definition

Identity resolution

The establishment of the uniqueness of a person within a program/service population through the use of identity information

Identity validation

The confirmation of the accuracy of identity information about a person as established by an authoritative party

Identity verification

The confirmation that the identity information being presented relates to the person who is making the claim

Assigned Identifier

An artificial identity attribute that is used solely for the purpose of providing identity uniqueness

….

UNCLASSIFIED / NON CLASSIFIÉ

52 of 53

Annex D - US-Canada Mapping

Common

Process Patterns

US

Canada

Assessment

  • OMB M04-04
  • Directive on Identity Management

  • Guideline on Defining Authentication Requirements

Unique identification

  • Uniqueness
  • NIST SP 800 63 A (draft)
  • Guideline on Identity Assurance

Identity Proofing

  • Evidence of identity
  • Identity validation
  • Identity verification
  • NIST SP 800 63 A (draft)

  • Guideline on Identity Assurance

Credential Management

  • Lifecycle Management
  • Issuance
  • Authentication
  • NIST SP 800 63 B (draft)

  • User Authentication Guidance for Information Technology Systems
  • Cyber Authentication Technical Specification 2.1

Enrolment Binding

  • NIST SP 800 63A (draft)

Notification and Consent

Requirements woven throughout 800-63-A/B/C

Trust/ Federation

  • NIST SP 800 63C
  • Pan-Canadian Trust Framework
  • PCIM Validation, Notification & Retrieval Standard Suite
  • PCIM Information Exchange Specification

Identity Assurance Level 1

Identity Assurance Level

Credential�Assurance Level

Identity Enrolment

Notification & Consent

Identity Information

Trusted �Digital Identity 2

US

Canada

Standards and Guidance Mapping

Concept Mapping

  1. Defined in US OMB M04-04
  2. Defined in TB Directive on Identity Management

800-63-A�IAL

800-63-B�AAL

800-63-C�FAL

UNCLASSIFIED / NON CLASSIFIÉ

53 of 53

Annex E - 2014- 2017 Federating Identity: Milestones and Initiatives

Milestones/Deliverables

  • 2004: Secure Channel, including its epass authentication service, operational
  • 2007: Identity Management & Authentication (IATF) Task Force Report
  • 2008: Cyber Auth Report on Future Requirements for the Government of Canada
  • 2009: TBS Directive on Identity Management
  • 2009: ITSG-31 Authentication Guidance
  • 2010: Pan-Canadian Assurance Model
  • 2010: BC Identity Assurance Standard
  • 2010: BC Evidence of Identity Standard
  • 2010: BC Electronic Credential & Authentication Standard
  • 2010: CIC (Passport Program) Facial Recognition capability operational
  • 2010: Cyber Auth RFP 1/RFP2/RFP3
  • 2011: Federating Identity for the Government of Canada: Backgrounder1
  • 2011: IMSC Pan-Canadian Approach to Trusting Identities
  • 2011: National Routing System (NRS) Data Exchanges Standard
  • 2012: Cyber Authentication Technical Specification
  • 2012: Guideline on Defining Authentication Requirements
  • 2012: Federating Identity Broker Architecture
  • 2013: GC Federated Credential operational
  • 2013: Standard on Identity and Credential Assurance
  • 2013 Cyber Auth Close Out Report
  • 2013: ePassport operational
  • 2013: Issuing new BC Services Card commenced
  • 2013: Service Quebec now responsible for clicSÉQUR
  • 2013: Ontario approves Electronic Identification, Authentication and Authorization (IAA) policy
  • 2014: Pan-Canadian Identity Validation Standard
  • 2015: GC Guideline on Identity Assurance
  • 2015: BC Identity Information Standard
  • 2016: Pan-Canadian Identity Trust Framework

53

Initiatives/Oversight

National Routing System

  • 2004-2006: Pilot
  • 2006-Present: In Production

Cyber Authentication Renewal

  • 2008: Creation of DM Cyber Auth Committee
  • 2008-2010: Consultation & Strategy
  • 2010-212: Procurement & Transition
  • 2012: Services Operational: (SecureKey Concierge & GCKey)
  • 2013 Conclusion (DM membership incorporated in DM SFI)

Federating Identity

  • 2010: GC Guideline on Defining Authentication Working Group
  • 2011: GC Guideline on Identity Assurance Working Group
  • 2013: GC Pilot Projects (Individuals/Businesses)
  • 2013: GC Policy & Legal Implications Working Group
  • 2014 Canada’s Digital Interchange
  • 2015 Identity Linkages Project

Task Force for Payments System Review

  • 2012: Recommendation to create Digital Identification and Authentication Task Force (DIAC)
  • 2015: DIACC Trust Framework Working Group

Identity Management Sub-Committee (IMSC)

  • 2012: Changed Reporting Structure to Joint Councils
  • 2013: IMSC Working Group

International

  • 2013-2015: Identity Summits
  • Involvement in Kantara, ISO & ANSI Standards

DM Committee on Service and Federating Identity (SFI)

  • 2013: Inaugural meeting

Related Arrangements & MOUs

  • Citizenship Certificate Validation (CIC & Provinces)

Lessons Learned

Strategic Alignment

UNCLASSIFIED / NON CLASSIFIÉ