�Treasury Board Identity Management Policy �and Pan-Canadian Trust Framework��Identity Management Policy Workshop��� �
UNCLASSIFIED / NON CLASSIFIÉ
Workshop Objectives
Policy Overview & Federated Identity
Pan-Canadian Identity Validation Standard
Guideline on Defining Authentication Requirements
Guideline on Identity Assurance
CSE User Authentication Guidance for IT Systems
Case Studies
Annexes – Additional information
2
UNCLASSIFIED / NON CLASSIFIÉ
Policy Overview �& �Federated Identity
3
UNCLASSIFIED / NON CLASSIFIÉ
Policy Foundation and Application
Issued under Policy on Government Security (PGS)
2009: Directive on Identity Management (applies to employees, external clients, organizations, and devices)
2011: Federating Identity Management in the GC
2012: Guideline on Defining Authentication Requirements
2013: Standard on Identity and Credential Assurance
2015: Guideline on Identity Assurance
2016: CSE User Authentication Guidance for IT Systems
4
Policy
Application | Individuals | Organizations | Devices |
Internal *ICAS - Internal Centralized Authentication Service |
|
|
|
External Access to online services offered to the public |
|
|
|
UNCLASSIFIED / NON CLASSIFIÉ
5
Policies
Directives
Mandatory Procedures and Standards
Legislation
Guideline on Developing a Departmental Security Plan
Other Guidelines and Tools
Guidelines and Tools
Detailed Government-wide Responsibilities
GC Security Event Management Protocols
Lead Security Agencies Guidance and Tools
Financial Administration Act
Directive on Identity Management
Policy on Government Security
Policy on Government Security (PGS) (2009 – amended 2012)
Directive on Departmental Security Management (DDSM) (2009)
Physical Security (2004)
Security Screening (2014)
Security Organization & Administration (1994)
Security in Contracting (1994)
Readiness Levels for Federal Government Facilities (2002)
Business Continuity Planning (2004)
Information Technology Incident Management Plan
Financial Administration Act (FAA)
Directive on Identity Management (2009)
Developing a Departmental Security Plan
Security Screening and Security in Contracting Guidelines and Tools (e.g. briefing form, SRCL)
Guideline on Identity Assurance (2015)
Lead Security Agencies Guidance and Tools
Management of Information Technology Security (2004)
Identity and Credential Assurance (2013)
5
NOTE: Standard on Security Screening not included in the reset exercise
NEW (PROPOSED)
CURRENT (OLD)
Guideline on Identity Assurance (2015)
Policy on Acceptable Network and Device Use (PANDU) (2013)
Standard on Security Categorization
Mandatory Procedures on Security Controls
Standard on Identity and Credential Assurance
Standard on Security Event Reporting
Security Policy Architecture
Standard on Acceptable Network and Device Use
Directive on Security Management
UNCLASSIFIED / NON CLASSIFIÉ
Trusted Digital Identity
6
‘This is me’
New PGS Definitions:
‘I am the same user for each interaction’
‘I have given my consent’
‘ Services/capabilities are �enabled using trusted infrastruct’
‘I am a real person’
Trusted Digital Identity
UNCLASSIFIED / NON CLASSIFIÉ
Directive on Identity Management
New requirements:
4.1.7. Accepting trusted digital identities provided through an approved trust framework as an equivalent alternative to in-person interactions, through an assessment of the following processes:
4.1.9 Using mandatory enterprise services for identity management, credential management and cyber authentication.
7
UNCLASSIFIED / NON CLASSIFIÉ
To fulfil client service, personal information collected to
Desired outcome: provide high quality (digital) services and improved client experience through
8
Identity and Authentication in Service Context
UNCLASSIFIED / NON CLASSIFIÉ
Identity: Starting Point for Services & Benefits
9
Healthcare Sector
Public Sector
Financial Sector
Who are you?
How will you pay?
Who are you?
What is your medical history?
Who are you?
Are you eligible for a government benefit?
Sector Issues
Sector Issues
Sector Issues
… but the impacts are felt by everyone
!
Identity risks�translate into:
!
Identity risks�translate into:
!
Identity risks�translate into:
Today, identity is managed separately by each sector…
UNCLASSIFIED / NON CLASSIFIÉ
The Drive to Digital Service Delivery
Priorities
Strategy
10
ID
UNCLASSIFIED / NON CLASSIFIÉ
Choose Sign-In Partner or GCKey
11
UNCLASSIFIED / NON CLASSIFIÉ
Evolution to Federating Identity
12
Cyber Authentication�Service
Commercial
Government of�Canada Issued
Mandatory Services
Other jurisdictions
Federating Credentials
Federating Identity
Government of Canada Approach
Government of Canada �Identity Federation�Service
Federation
Government of Canada�Identity �Validation Service
Pilot Projects
Standards-based
Government of Canada�Identity Assurance�Service
Pan-Canadian Approach
Identity Federation�Service
Federation Enablers
Identity �Services
Policy Enablers
Federation
Standards-based
Federation
Standards-based
Legislative Enablers
Identity�Federation �Services
Credential �Federation�Services
UNCLASSIFIED / NON CLASSIFIÉ
Principles:
13
Pan-Canadian Policy Direction
2014: Identity Validation Standard
2016/17: Pan-Canadian Trust Framework
(Technical Standards, Specifications, Certifications, Privacy, Security, Service delivery, Organizational)
Federated Approach
Trusting credentials and identities:
Federating Credentials
Federating Identity
‘trusting credentials �issued by other jurisdictions and industry sectors’
‘trusting identities �that have been established by other jurisdictions’
Pan-Canadian Collaboration
UNCLASSIFIED / NON CLASSIFIÉ
Pan-Canadian Trust Framework
14
UNCLASSIFIED / NON CLASSIFIÉ
Pan-Canadian Trust Framework: Context
FPT Deputy Ministers’ Table on Service Delivery Collaboration
FPT Clerks and Cabinet Secretaries
Joint Councils
Identity Management Sub Committee (IMSC)
Public Sector �Service Delivery Council
Public Sector �CIO Council
Digital Identification Authentication Council of Canada (DIACC)
DIACC* Board of Directors�(Includes Public Sector membership)
IMSC Working Groups
DIACC Working Groups
Public Sector
Private Sector/�Industry Initiatives
Canada’s Digital Interchange�(CDI)
Immigration Refugee Citizenship Canada / Employment Social Development Canada
IRCC/ESDC
Identity Linkages Project (ILP)
CDI�Working Groups
15
Other Initiatives Underway
*Digital Identification and Authentication Council of Canada
UNCLASSIFIED / NON CLASSIFIÉ
Building a Pan-Canadian Trust Framework
Has the user given consent?
16
Trusted Digital Identity
Including Public Sector and Private Sector Considerations
Verified Person Component
Consent and Delegation
Is it a real/existing person?
Verified Login
Verified Person
Is it the same person?
Pan-Canadian Infrastructure�Technical Standards, Specifications, Certifications Privacy, Security, Service Delivery, Organizational
UNCLASSIFIED / NON CLASSIFIÉ
Pan-Canadian Standardized Concepts
17
UNCLASSIFIED / NON CLASSIFIÉ
The Personal Information Categories
18
2016-09-26
UNCLASSIFIED / NON CLASSIFIÉ
Personal Information Categories�by Function
19
Personal Information Category | Function | ||
PERSON NAME | Validation | Retrieval | Notification |
DATE OF EVENT | |||
PLACE OF EVENT | |||
SEX, GENDER, DOCUMENTED SEX | |||
ASSIGNED IDENTIFIER | |||
PERSON STATUS | |||
ADDRESS | |||
ASSOCIATED PERSON | |||
BIOMETRIC IMAGE | | ||
PERSON AGE | | | |
CONTACT DETAIL | |||
BIRTH VITAL EVENT DETAIL | |||
DEATH VITAL EVENT DETAIL | |||
STILLBIRTH VITAL EVENT DETAIL | |||
UNCLASSIFIED / NON CLASSIFIÉ
Guideline on Defining Authentication Requirements
20
UNCLASSIFIED / NON CLASSIFIÉ
Evolution of Authentication
‘State of the art’ authentication practices are rapidly evolving
Recently published guidance documents are defining ‘compensating factors’ (or ‘compensating controls’) as a key concept to address the following:
21
UNCLASSIFIED / NON CLASSIFIÉ
Guideline on Defining Authentication Requirements
Purpose of Guidance:
Tools Provided:
22
UNCLASSIFIED / NON CLASSIFIÉ
23
Guideline on Identity Assurance
Information Technology Security Guideline�ITSP.30.031 V2: �User Authentication �Guidance for IT Systems�
ITSG-33:�IT Security Risk Management: �A Lifecycle Approach
Guideline on Defining Authentication Requirements
Step 1:
Determine assurance level requirement
Step 2:
Determine authentication options (including compensating factors and other safeguards)
Implementing �identity assurance level requirements
Impact Assessment
Risk Mitigation
Use of cyber authentication services
Identity Assurance �Level Requirement
Credential Assurance Level Requirement
Authentication Requirements
Identity Context
Federation of Identity?
Federation of
Credential?
Enabling Federation
UNCLASSIFIED / NON CLASSIFIÉ
Approach to Defining Requirements
24
Assurance Level �Requirement
Impact Assessment determines �the level of assurance required
Selection of Controls uses standardized requirements (where possible), compensating factors, and acceptable risk
Performed by the program/service owners
Performed by security and IT practitioners
What level of assurance do I need to achieve my program objectives?
What methods, safeguards or measures do I have, or need to put in place?
Answers the question
Answers the question
Collaboration between Program/Service owners & IT/Security practitioners…
Level 4 �Very high confidence required |
Level 3 �High confidence required |
Level 2�Some confidence required |
Level 1 �Low confidence required |
UNCLASSIFIED / NON CLASSIFIÉ
Major Steps in Defining Requirements
25
Enabling Departmental Flexibility
Facilitate Adoption of Standardized �Solutions and Services
Step 1
Determine Assurance �Level Requirement
Step 2
Determine Authentication
Requirements
What level of assurance do I need to achieve my program objectives?
What methods, safeguards or measures do I have, or need to put in place?
Assurance�Level
Requirement
Key Assessment Factors
Key Assessment Factors
Key Outcomes
Identity Assurance �Requirements
Decision�Outputs
Credential Assurance�Requirements
Authentication�Solution Requirements
Compensating �Factors
Other �Safeguards
Acceptable �Risk
Key Activities
Input of existing assessments
UNCLASSIFIED / NON CLASSIFIÉ
Compensating Factors
26
26
Assurance Level |
Level 4 |
Level 3 |
Level 2 |
Level 1 |
None |
Required Assurance Level
Standardized
requirements (i.e. measures) provide a specified level of assurance
Compensating factors�can be used to manage residual risk
UNCLASSIFIED / NON CLASSIFIÉ
Use of Compensating Factors, Other Safeguards and Acceptable Risk
Defined in guidance
These concepts enable departments to have flexibility in determining their optimal authentication solution requirements. Departments must decide on:
27
UNCLASSIFIED / NON CLASSIFIÉ
Guideline on Identity Assurance
28
UNCLASSIFIED / NON CLASSIFIÉ
Credential and Identity Assurance
29
Level 4 Very high confidence required |
Compromise: serious to catastrophic harm |
Level 3 High confidence required |
Compromise: moderate to serious harm |
Level 2 Some confidence required |
Compromise: minimal to moderate harm |
Level 1 Little confidence required |
Compromise: nil to minimal harm |
Credential Assurance
Identity Assurance
User X
Binding a credential to a unique individual
Assurance Levels
An individual
Establishing the real identity of an individual
Assurance Levels
Level 4 Very high confidence required |
Compromise: serious to catastrophic harm |
Level 3 High confidence required |
Compromise: moderate to serious harm |
Level 2 Some confidence required |
Compromise: minimal to moderate harm |
Level 1 Little confidence required |
Compromise: nil to minimal harm |
UNCLASSIFIED / NON CLASSIFIÉ
Overview of Guideline on Identity Assurance
Provides implementation guidance on four requirements specified in Appendix C of the Standard on Identity and Credential Assurance:
30
UNCLASSIFIED / NON CLASSIFIÉ
Overview of Guideline (cont’d)
Provides guidance on integrating identity assurance into departmental business and system processes:
Federation consideration for departments when:
Considerations for main types of fraud:
31
UNCLASSIFIED / NON CLASSIFIÉ
Example: Establishing Identity Assurance (for Level 3)
32
Requirement | Level 3 Identity Assurance |
Uniqueness | Define identity information Define context |
Evidence of Identity | Two instances of evidence of identity |
Accuracy of Identity Information | Identity information acceptably matches assertion by an individual and all instances of evidence of identity and Confirmation of the foundational evidence of identity using authoritative source and Confirmation that supporting evidence of identity originates from appropriate authority, using authoritative source or inspection by trained examiner |
Linkage of Identity Information to Individual | At least one of the following:
|
UNCLASSIFIED / NON CLASSIFIÉ
Standard on Identity and Credential Assurance�Appendix C: Minimum Requirements
33
Requirement | Level 1 | Level 2 | Level 3 | Level 4 |
Uniqueness | Define identity information Define context | |||
Evidence of Identity | No restriction on what is provided as evidence | One instance of evidence of identity | Two instances of evidence of identity (At least one must be foundational evidence of identity.) | Three instances of evidence of identity (At least one must be foundational evidence of identity.) |
Accuracy of Identity Information | Acceptance of self-assertion of identity information by an individual | Identity information acceptably matches assertion by an individual and evidence of identity and Confirmation that evidence of identity originates from appropriate authority | Identity information acceptably matches assertion by an individual and all instances of evidence of identity and Confirmation of the foundational evidence of identity using authoritative source and Confirmation that supporting evidence of identity originates from appropriate authority, using authoritative source or inspection by trained examiner | Identity information acceptably matches assertion by an individual and all instances of evidence of identity and Confirmation of the foundational evidence of identity using authoritative source and Confirmation that supporting evidence of identity originates from appropriate authority, using authoritative source or inspection by trained examiner |
Table continued on next slide…
UNCLASSIFIED / NON CLASSIFIÉ
Standard on Identity and Credential Assurance�Appendix C: Minimum Requirements
34
Requirement | Level 1 | Level 2 | Level 3 | Level 4 |
Linkage of Identity Information to �Individual | No requirement | No requirement | At least one of the following: i) Knowledge-based confirmation ii) Biological or behavioural characteristic confirmation iii) Trusted referee confirmation iv) Physical possession confirmation | At least three of the following: i) Knowledge-based confirmation ii) Biological or behavioural characteristic confirmation iii) Trusted referee confirmation iv) Physical possession confirmation |
Note: When the authoritative source is outside of Canadian jurisdiction, the accuracy of identity information will be determined through a risk-managed approach.
Table continued from previous slide…
UNCLASSIFIED / NON CLASSIFIÉ
35
Assurance Level Impact Assessment Summary Table | ||||
Name of Program/Service/Transaction: | | |||
Assessment Question: | If this program, service or transaction benefits the wrong person, would it like result in… (complete each question using the table cells below) | |||
Assessment Category | Level 1�Assessment | Level 2 Assessment | Level 3 Assessment | Level 4 Assessment |
1. Inconvenience, distress/loss of standing or reputation | ||||
2. Financial loss | ||||
3. Harm to program or public interest | ||||
4. Unauthorized release of sensitive personal or commercial information. | ||||
5. Unauthorized release of sensitive government information. | ||||
6. Civil or criminal violations | ||||
7. Personal Safety | ||||
8. National security | ||||
ASSURANCE LEVEL REQUIREMENT |
|
|
|
|
UNCLASSIFIED / NON CLASSIFIÉ
Example: Passport Program
UNCLASSIFIED / NON CLASSIFIÉ
CSE User Authentication Guidance for IT Systems
37
UNCLASSIFIED / NON CLASSIFIÉ
Relation to TBS Guidelines
Identity
Guideline on Defining Authentication Requirements
Standard on Identity and Credential Assurance
Credential
ITSP.30.031
UNCLASSIFIED / NON CLASSIFIÉ
Levels of Assurance - Recommended use in the GC
LoA | Recommended Use in the GC |
1 | Not recommended for GC use. |
2 | End-user access to systems or information. |
3 | Administrative access to systems or information. |
4 | Administrative access to high-value systems or information. |
UNCLASSIFIED / NON CLASSIFIÉ
Levels of Assurance Applied to Tokens
LoA | Main Characteristic | Examples |
1 | Basic authentication methods – not recommended for GC use. | Password or PIN systems with poorly secured databases and/or recovery methods |
2 | Standard, typically single-factor end-user authentication solutions | Memorized Secret Tokens, Pre-Registered Knowledge Tokens, Look-up Secret Tokens, Out of Band Tokens, software cryptographic tokens, and Single Factor One-Time Password Devices |
3 | Two-factor authentication methods using a hardware factor | Passwords/PINS combined with OTP Tokens and Smartphones |
4 | Two-factor authentication with a cryptographically-based hardware factor | Hardware cryptographic tokens, multi-factor One-Time-Password devices |
UNCLASSIFIED / NON CLASSIFIÉ
Case Studies
41
UNCLASSIFIED / NON CLASSIFIÉ
Case Study: Passport Program
Context
Preparation
Key Lessons
UNCLASSIFIED / NON CLASSIFIÉ
Case Study: Passport Program
Conducting the Assessments
Key Lessons
UNCLASSIFIED / NON CLASSIFIÉ
Case Study: Passport Program
Documenting the Results
Key Lessons
UNCLASSIFIED / NON CLASSIFIÉ
Case Study: CRA
Overview
Key Lesson
UNCLASSIFIED / NON CLASSIFIÉ
Case Study: CRA
Risk Assessment Process
Key Lesson
UNCLASSIFIED / NON CLASSIFIÉ
Case Study: CRA
Outcome and Next Steps
Key Lesson
UNCLASSIFIED / NON CLASSIFIÉ
Annex
For Further Information
48
UNCLASSIFIED / NON CLASSIFIÉ
Annex A - Links to Key Documents
TB/TBS CIO/CSE Approved Versions:
Draft Versions
49
UNCLASSIFIED / NON CLASSIFIÉ
Annex B - Key PGS Definitions
50
Term | Definition |
Credential | A unique physical object or electronic identifier issued to, or associated with, an individual, organization or device. |
Evidence of Identity | A record from an authoritative source indicating an individual's identity. There are two categories of evidence of identity: foundational and supporting. |
Foundational Evidence of Identity | Evidence of identity that establishes core identity information such as given name(s), surname, date of birth and place of birth. Examples include records of birth, immigration or citizenship from an authority with the necessary jurisdiction. |
Identity | A reference or designation used to distinguish a unique individual, organization or device. |
Supporting Evidence of Identity | Evidence of identity that corroborates the foundational evidence of identity and assists in linking the identity information to an individual. It may also provide additional information such as a photo, signature or address. |
Trust Framework | A set of agreed on definitions, principles, conformance criteria, assessment approach, standards, and specifications. |
Trusted Digital Identity | An electronic representation of a person, used exclusively by that same person, to receive valued services and to carry out transactions with trust and confidence. |
UNCLASSIFIED / NON CLASSIFIÉ
Annex C - Pan-Canadian Definitions
51
Term | Definition |
Identity resolution | The establishment of the uniqueness of a person within a program/service population through the use of identity information |
Identity validation | The confirmation of the accuracy of identity information about a person as established by an authoritative party |
Identity verification | The confirmation that the identity information being presented relates to the person who is making the claim |
Assigned Identifier | An artificial identity attribute that is used solely for the purpose of providing identity uniqueness |
…. | |
UNCLASSIFIED / NON CLASSIFIÉ
Annex D - US-Canada Mapping
Common Process Patterns | US | Canada |
Assessment |
|
|
Unique identification
|
|
|
Identity Proofing
|
|
|
Credential Management
|
|
|
Enrolment Binding |
| |
Notification and Consent | Requirements woven throughout 800-63-A/B/C | |
Trust/ Federation |
|
|
Identity Assurance Level 1
Identity Assurance Level
Credential�Assurance Level
Identity Enrolment
Notification & Consent
Identity Information
Trusted �Digital Identity 2
US
Canada
Standards and Guidance Mapping
Concept Mapping
800-63-A�IAL
800-63-B�AAL
800-63-C�FAL
UNCLASSIFIED / NON CLASSIFIÉ
Annex E - 2014- 2017 Federating Identity: Milestones and Initiatives
Milestones/Deliverables
53
Initiatives/Oversight
National Routing System
Cyber Authentication Renewal
Federating Identity
Task Force for Payments System Review
Identity Management Sub-Committee (IMSC)
International
DM Committee on Service and Federating Identity (SFI)
Related Arrangements & MOUs
Lessons Learned
Strategic Alignment
UNCLASSIFIED / NON CLASSIFIÉ