The Access Control Race
- 17 January, 2006 14:55
- Comments
In August 2004, US President George Bush issued Homeland Security Presidential Directive-12 (HSPD-12), which requires federal agencies to set up one identification system for all staff and contractors who have access to sensitive facilities or information. The move to stiffen access control for several million people who work for the U.S. government and its contractors -- part of post-9/11 efforts to beef up security at federal installations -- has set off a scramble by 2 dozen agencies seeking to comply by October's deadline.
The directive means that the agencies need to reassess the way they check worker backgrounds and issue IDs, and then tailor those checks to comply with a new set of criteria that the National Institute of Standards and Technology issued last February.
Those criteria, called the Federal Information Processing Standard, specify that agencies must initiate in-depth background checks for all new and existing employees with access to sensitive information; that new ID cards must include biometric measures such as an iris scan or fingerprint; that such personal information must be encrypted to ensure employees' privacy; and that new equipment is installed and in place by Oct. 27, 2006.
Alex Conant, White House Office of Management and Budget spokesman, says all 24 agencies met an interim deadline last October to modify the way they checked workers' backgrounds and issued IDs.
That was the easy part. The real test will be this October. Picture a sea of new badges and myriad doorway checks, and you've got an interesting Monday morning on Oct. 30 at federal sites around the nation.
Consultant Jim Ganthier, global director of defense, intelligence and public safety solutions at Hewlett-Packard, notes that many agencies are working on assessments of their access control procedures, "so they're not surprised later or, more important, so they don't end up with a technological dead end." Ganthier adds that those agencies that have to rip and replace their systems face big hurdles.
Challenges include rearranging plans when NIST updates its standard, as officials expect.
Barbra Symonds, director of the IRS Privacy Office, serves as HSPD-12 program manager. Symonds says the IRS has organized a program management office dedicated to HSPD-12 compliance, with a staff of 10 as well as a deputy program manager. The staff likely will increase to help meet the October deadline, for which Symonds is optimistic. "We don't see any roadblocks that would stop us from getting there," she says. "More than likely we'll be sweating down to the wire with all the other federal agencies."
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
BYOD security: How to protect your business on the move
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
IT service management going social
-
PC users admit to pirating software - $US63 billion worth of it
-
OVUM Report: Governance Risk and Compliance-- GRC usage and buying trends in the ANZ markets
The existence of an established and stable governance risk and compliance strategy is extremely important to public and private sector organisations as they strive to meet an evergrowing range of regulatory demands. Given the current constraints, it is one of the few areas where the vast majority of organisations intend to either maintain or in many cases increase spending. Read more. -
Oracle Exadata: Extreme Performance Lowest Cost
As organisations contend with escalating demands for greater quantities of information, more sophisticated data analysis, and a burgeoning user population, Oracle Exadata makes database workloads faster, easier to manage, and less expensive. Oracle Exadata is the world’s first database machine to provide extreme performance for both data warehousing and online transaction processing (OLTP) applications. -
Blurring boundaries: The disappearing gap between work and home life
Call it multi-tasking, life-splicing or bleisure but increasingly, fuelled by advances in technology, employees are blurring the boundaries between home and work. ‘Generation Standby’ employees, never truly ‘switched off’ and always ready to be called upon, are now enjoying, and expecting, greater levels of flexibility and mobility than ever before. Read on.
-
Foundations of Net-enhanced Organisations Wiley International Edition
-
Windows XP Gigabook for Dummies
-
Teach Yourself Visually Mac OS X Snow Leopard
-
MySQL Enterprise Solutions
-
F# for Scientists
-
Supporting Users and Troubleshooting Desktop Applications on a Microsoft Windows XP Operating System (70-272)
-
Photoshop Cs4 Workflow
-
Machine Learning and Data Mining
-
Practical Genetic Algorithms, Second Edition with CD-ROM








Comments
Post new comment