This is the draft preview of version 3.1 for the Federal Identity, Credential, and Access Management architecture.

Edit this page

Standards and Policies

Review the federal policies and standards that impact and shape the implementations of ICAM programs and systems.

Each section of this page lists documents in reverse chronological order, with the latest documents first.

Laws

The Privacy Act of 1974 (September 2015)

This Act protects certain Federal Government records pertaining to individuals. In particular, the Act covers systems of records that an agency maintains and retrieves by an individual’s name or other personal identifier, such as a Social Security Number.

Federal Information Security Modernization Act (FISMA) of 2014 (December 2014)

This Act provides a framework for measuring the effectiveness of federal information systems, and it calls for the development and implementation of continuous monitoring oversight mechanisms. It also acknowledges federal agencies should take advantage of commercially-available security products (including software, hardware, etc.) that often provide robust information security solutions.

E-Government Act of 2002 (December 2002)

This Act enhances the management and promotion of electronic federal services and processes by establishing a Federal CIO within the Office of Management and Budget (OMB) and by establishing a broad framework of measures that require using Internet-based information technology (IT) to enhance citizen access to government information and services, and for other purposes.

Electronic Signatures in Global and National (ESIGN) Commerce Act of 2000 (June 2000)

This Act facilitates the use of electronic records and electronic signatures in interstate and foreign commerce by ensuring the validity and legal effect of electronic contracts.

Government Paperwork Elimination Act of 1998 (GPEA) (October 1998)

This Act requires federal agencies to allow individuals or entities that deal with the agencies the option to submit information or transact with the agency electronically when possible, and to maintain records electronically when possible. This Act specifically states that electronic records and their related electronic signatures cannot be denied legal effect, validity, or enforceability just because they are in electronic form. This Act also encourages Federal Government use of a range of electronic signature alternatives.

Policies

M 20-19: Harnessing Technology to Support Mission Continuity (PDF, March 2020)

Temporary. This memorandum directs that agencies utilize technology to the greatest extent practicable to support mission continuity during the national emergency. By aggressively embracing technology to support business processes, the Federal Government is better positioned to maintain the safety and well-being of the Federal workforce and the American public while supporting the continued delivery of vital mission services. The set of frequently asked questions are intended to provide additional guidance and further assist the IT workforce as it addresses impacts.

Office of Personnel Management Memorandum: Temporary Procedures for Personnel Vetting and Appointment of New Employees during Maximum Telework Period due to Coronavirus COVID-19 (March 2020)

Temporary. This memorandum sets forth temporary procedures for the vetting and appointment of federal personnel, collection of biometrics for federal employment, and employment authorization and eligibility.

M-19-17: Enabling Mission Delivery through Improved Identity, Credential, and Access Management (ICAM) (PDF, May 2019)

This memorandum sets forth the Federal Government’s ICAM policy. To ensure secure and efficient operations, agencies of the Federal Government must be able to identify, credential, monitor, and manage subjects that access Federal resources. This includes information, information systems, facilities, and secured areas across their respective enterprises. In particular, how agencies conduct identity proofing, establish enterprise digital identities, and adopt sound processes for authentication and access control significantly affects the security and delivery of their services, as well as individuals’ privacy.

M-19-03: Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset (HVA) Program (PDF, December 2018)

With the creation of the HVA initiative in 2015, the Federal Government’s CFO Act agencies took a pivotal step toward the identification of its most critical assets. DHS, in coordination with OMB, established a capability to assess agency HVAs, resulting in the identification of critical areas of weakness and plans to remediate those areas of weakness. It established three possible categories for designating Federal information or a Federal information system as an HVA: Informational Value, Mission Essential, or Federal Civilian Enterprise Essential (FCEE). It also updates the required approach for agencies to report, assess, and remediate HVAs to protect against cyberattacks.

Executive Order 13833: Enhancing the Effectiveness of Agency Chief Information Officers (CIOs) (May 2018)

This executive order authorizes federal agency CIOs to ensure that agency IT systems are as modern, secure, and well-managed as possible to reduce costs, mitigate cybersecurity risks, and deliver improved services to the American people.

Executive Order 13800: Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure (May 2017)

This executive order places an emphasis on modernizing and securing federal networks and critical infrastructure from the ever-growing threat of cyber-attacks.

Circular A-130: Managing Federal Information as a Strategic Resource (PDF, July 2016)

Information and IT resources are critical to the U.S. social, political, and economic well-being. They enable the Federal Government to provide quality services to citizens, generate and disseminate knowledge, and facilitate greater productivity and advancement as a Nation. It is important for the Federal Government to maximize the quality and security of federal information systems, and to develop and implement uniform and consistent information resources management policies in order to inform the public and improve the productivity, efficiency, and effectiveness of agency programs. Additionally, as technology evolves, it is important that agencies manage information systems in a way that addresses and mitigates security and privacy risks associated with new IT resources and new information processing capabilities.

OMB Circular A-108, Federal Agency Responsibilities for Review, Reporting, and Publication under the Privacy Act (December 2016)

This circular describes agency responsibilities for implementing the review, reporting, and publication requirements of the Privacy Act of 1974 and related OMB policies.

OMB Circular A-123: Management’s Responsibility for Enterprise Risk Management (ERM) and Internal Control (July 2016)

The policy changes in this circular modernize existing efforts by requiring agencies to implement an ERM capability coordinated with the strategic planning and strategic review process established by Government Performance and Results Act Modernization Act (GPRAMA), and the internal control processes required by Federal Managers’ Financial Integrity Act (FMFIA) and Government Accountability Office (GAO)’s Green Book. This integrated governance structure will improve mission delivery, reduce costs, and focus corrective actions towards key risks.

Executive Order 13681: Improving the Security of Consumer Financial Transactions (PDF, October 2014)

This executive order requires agencies to strengthen the security of consumer data and encourage the adoption of enhanced safeguards nationwide in a manner that protects privacy and confidentiality while maintaining an efficient and innovative financial system.

Final Credentialing Standards for Issuing Personal Identity Verification (PIV) Cards under HSPD-12 (PDF, July 2008)

This memorandum provides final government-wide credentialing standards to be used by all federal departments and agencies in determining whether to issue or revoke PIV credentials to their employees and contractor personnel, including those who are non-United States citizens.

M-05-24: Implementation of HSPD-12 Policy for a Common Identification Standard for Federal Employees and Contractors (PDF, August 2005)

This memorandum provides implementation instructions for HSPD-12 and Federal Information Processing Standards (FIPS) 201.

HSPD-12: Policy for a Common Identification Standard for Federal Employees and Contractors (August 2004)

HSPD-12 calls for a mandatory, government-wide standard for secure and reliable forms of identification issued by the Federal Government to its employees and employees of federal contractors for access to federally-controlled facilities and networks.

Standards

NIST SP 800-63-3: Digital Identity Guidelines (June 2017)

Agencies use these guidelines as part of the risk assessment and implementation of their digital service(s). These guidelines provide mitigations for an authentication error’s negative impacts by separating the individual elements of identity assurance into its component parts.

NIST SP 800-63A: Digital Identity Guidelines - Enrollment and Identity Proofing (PDF, June 2017)

This guideline focuses on the enrollment and verification of an identity for use in digital services. Central to this is a process known as identity proofing in which an applicant provides evidence to a credential service provider (CSP) reliably identifying themselves, thereby allowing the CSP to assert that identification at an Identity Assurance Level (IAL). This document defines technical requirements for each of three IALs.

NIST SP 800-63B: Digital Identity Guidelines - Authentication and Lifecycle Management (PDF, June 2017)

These guidelines focus on the authentication of subjects interacting with government systems over open networks, establishing that a given claimant is a subscriber who has been previously authenticated. The result of the authentication process may be used locally by the system performing the authentication or may be asserted elsewhere in a federated identity system. This document defines technical requirements for each of the three Authentication Assurance Levels (AALs).

NIST SP 800-63C: Digital Identity Guidelines - Federation and Assertions (PDF, June 2017)

These guidelines provide technical requirements for federal agencies implementing digital identity services and are not intended to constrain the development or use of standards outside of this purpose. This guideline focuses on the use of federated identity and the use of assertions to implement identity federations. Federation allows a given CSP to provide authentication and (optionally) subscriber attributes to a number of separately-administered relying parties. Similarly, relying parties may use more than one CSP.

NIST SP 800-162: Guide to Attribute Based Access Control (ABAC) Definition and Considerations (PDF, January 2014)

This guideline provides federal agencies with a definition of ABAC. ABAC is a logical access control methodology where authorization to perform a set of operations is determined by evaluating attributes associated with the subject, object, requested operations, and, in some cases, environment conditions against policy, rules, or relationships that describe the allowable operations for a given set of attributes.

NIST SP 800-205: Attribute Considerations for Access Control Systems (PDF, June 2019)

This guideline provides federal agencies with information for implementing attributes in access control systems. Attributes enable a logical access control methodology where authorization to perform a set of operations is determined by evaluating attributes associated with the subject, object, requested operations, and, in some cases, environment conditions against policy, rules, or relationships that describe the allowable operations for a given set of attributes. This document outlines factors which influence attributes that an authoritative body must address when standardizing an attribute system and proposes some notional implementation suggestions for consideration.

NIST SP 800-116 Rev. 1: Guidelines for the Use of PIV Credentials in Facility Access (PDF, June 2018)

This guideline provides resources for using PIV credentials in facility access; enabling federal agencies to operate as government-wide interoperable enterprises. This guideline covers the risk-based strategy to select appropriate PIV authentication mechanisms as expressed within FIPS 201.

NIST SP 800-73-4: Interfaces for PIV (PDF, February 2016)

This guideline specifies the PIV data model, command interface, client application programming interface (API), and references to transitional interface specifications.

NIST SP 800-79-2: Guidelines for the Authorization of PIV Card Issuers (PCI) and Derived PIV Credential Issuers (DPCI) (PDF, July 2015)

The guideline specifies the assessment for the reliability of issuers of PIV credentials and Derived PIV credentials. The reliability of an issuer is of utmost importance when a federal agency is required to trust the identity credentials of individuals that were created and issued by another federal agency.

NIST SP 800-53 Rev. 4: Security and Privacy Controls for Federal Information Systems and Organizations (PDF, January 2015)

This guideline provides a catalog of security and privacy controls for federal information systems and organizations and a process for selecting controls to protect organizational operations, assets, individuals, other organizations, and the Nation from a diverse set of threats.

NIST SP 800-53A Rev. 4: Assessing Security and Privacy Controls in Federal Information Systems and Organizations - Building Effective Security Assessment Plans (PDF, December 2014)

This guideline provides a set of procedures for conducting assessments of security controls and privacy controls employed within federal information systems and organizations. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST SP 800-53, Revision 4.

NIST SP 800-157: Guidelines for Derived PIV Credentials (PDF, December 2014)

This guideline provides technical instructions for the implementation of standards-based, secure, reliable, interoperable public key infrastructure (PKI) based identity credentials that are issued by federal departments and agencies to individuals who possess and prove control over a valid PIV credential.

FIPS 201-2: PIV of Federal Employees and Contractors (PDF, August 2013)

This standard specifies the architecture and technical requirements for a common identification standard for federal employees and contractors. The overall goal is to achieve appropriate security assurance for multiple applications by efficiently verifying the claimed identity of individuals seeking physical access to federally controlled government facilities and electronic access to government information systems.

NIST SP 800-76-2: Biometric Data Specification for PIV (PDF, July 2013)

This guideline contains technical specifications for biometric data mandated in FIPS. These specifications reflect the design goals of interoperability and performance of the PIV credential. This specification addresses image acquisition to support the background check, fingerprint template creation, retention, and authentication. The biometric data specification in this document is the mandatory format for biometric data carried in the PIV Data Model (SP 800-73-1, Appendix A). Biometric data used only outside the PIV Data Model is not within the scope of this standard.

NIST SP 800-122: Guide for Protecting the Confidentiality of Personally Identifiable Information (PII) (PDF. April 2010)

This guideline assists federal agencies in protecting the confidentiality of a specific category of data commonly known as PII. This document provides practical, context-based guidance for identifying PII and determining what level of protection is appropriate for each instance of PII. The document also suggests safeguards that may offer appropriate levels of protection for PII and provides recommendations for developing response plans for breaches involving PII.

Additional Resources

Continuous Diagnostics and Mitigation

The Continuous Diagnostics and Mitigation (CDM) Program is an approach to fortifying the cybersecurity of government networks and systems. The CDM Program provides cybersecurity tools, integration services, and dashboards to participating agencies to support them in improving their respective security posture. The CDM approach focuses on five areas for the federal enterprise: Data Protection Management, Network Security Management, Identity and Access Management, Asset Management, and Monitoring and Dashboards.

Digital Identity Risk Assessment (DIRA) Playbook (PDF, September 2020)

Requires MAX.gov login. This playbook is a companion guide for defining agency processes to incorporate Digital Identity Risk Assessments. The playbook accompanies existing and planned NIST guides and offers plain language explanations for the processes.

Application Rationalization Playbook (PDF, June 2019)

This playbook is a practical guide for application rationalization and IT portfolio management under the Federal Government’s Cloud Smart initiatives. Application rationalization will help federal agencies mature IT portfolio management capabilities, empower leaders to make informed decisions, and improve the delivery of key mission and business services. It requires buy-in from stakeholders across the enterprise, including senior leaders, technology staff members, cybersecurity experts, business leads, financial practitioners, acquisition and procurement experts, and end user communities. Rationalization efforts rely on leadership support and continual engagement with stakeholders to deliver sustainable change.

Federal Identity, Credential, and Access Management (FICAM) Program Management Guide

This guide contains tips and examples for planning and executing an agency ICAM program. In this guide, you’ll find content for ICAM program managers who need agency-level planning guides to drive adoption of enterprise ICAM within an agencu, as well as how to govern the program, identify and communicate with stakeholders, manage risk, and other related topics.

Physical Access Control System (PACS) Guide

This guide explains concepts related to Physical Access Control Systems (PACS). At a high level, a PACS is a collection of technologies that control physical access at one or more federal agency sites by electronically authenticating employees, contractors, and visitors.

Personal Identity Verification (PIV) Guides

These guides are intended to help you implement common PIV configurations at your agency, including using PIV credentials for network authentication, and digital signatures on documents.

NIST: Privacy Framework (PDF, January 2020)

The Privacy Framework is a voluntary tool intended to help organizations identify and manage privacy risk to build innovative products and services while protecting individuals’ privacy. The Privacy Framework approach to privacy risk is to consider privacy events as potential problems individuals could experience arising from system, product, or service operations with data, whether in digital or non-digital form, through a complete life cycle from data collection through disposal.

NIST SP 800-63-3 Implementation Resources (PDF, July 2020)

These resources are intended as informative implementation guidance for NIST SP 800-63-3. These implementation resources provide guidance for SP 800-63-3 in three parts: Part A addresses SP 800-63A, Part B addresses SP 800-63B, and Part C addresses SP 800-63C.

NIST SP 800-63 Frequently Asked Questions (FAQs) (January 2020)

The Frequently Asked Questions for NIST SP 800-63-3, Digital Identity Guidelines answers recurring questions to provide additional clarification.

NIST FISMA Implementation Project: Risk Management Framework Overview (August 2020)

The selection and specification of security controls for a system is accomplished as part of an organization-wide information security program that involves the management of organizational risk—that is, the risk to the organization or to individuals associated with the operation of a system. The management of organizational risk is a key element in the organization’s information security program and provides an effective framework for selecting the appropriate security controls for a system—the security controls necessary to protect individuals and the operations and assets of the organization.

NIST White Paper: Best Practices for Privileged User PIV Authentication (PDF, April 2016)

This white paper was developed in response to the Cybersecurity Strategy and Implementation Plan to explain the need for multi-factor PIV-based user authentication for privileged users. It provides best practices for agencies implementing PIV authentication for privileged users.