Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW! Transforming Data Center
Managed Services
Service Oriented Architecture
Training & Simulation
Networking Communications
Security Directives and Compliance
Data Center Virtualization
Air Force ELSG Contract Guide

More >>



Latest News
ADVERTISEMENT





 

6 smart ways to use smart credentials

By Florence Olsen
Published on September 5, 2005

Comment

Click here to comment on this article


Related story links

Feds cram to meet ID deadlines

Reporting template for HSPD 12 plans


Newsletters

You might also be interested in these FCW newsletters:

Daily

To learn more, click here.


President Bush issued a directive last year that will soon change how employees and contractors enter federal buildings and log on to federal computers. The government's implementation of Homeland Security Presidential Directive (HSPD) 12 is based on computer-readable personal identity cards and a governmentwide public-key infrastructure (PKI).

With those technologies, federal officials say, they can prevent almost anyone from accessing federal buildings or information systems with fake identity cards.

But people familiar with the government's implementation of HSPD 12 say that agencies can derive many additional benefits from those technologies. From interviews with nearly a dozen security experts, Federal Computer Week came up with a list of six other possible uses for the secure smart cards and PKI that most federal agencies will have by the end of 2006.

oneGet control of the devils inside

Several security experts said they expect the Army and some federal agencies to use the new security infrastructure for tracking the activities of service members on military bases or employees in federal buildings, a use that many privacy experts oppose. Most building security and computer systems generate activity logs. The use of a single identity credential to access those systems will make it easier, within established privacy guidelines, "to find out what people are doing and where they're doing it," said J.R. Reagan, managing director of the security and identity management practice at BearingPoint, a business consulting and systems integration company. "There's some of that today," Reagan added.

But cost-effective uses of personnel tracking require a unified security management infrastructure that most military bases and federal facilities have not implemented. HSPD 12 and a related set of specifications known as Federal Information Processing Standard (FIPS) 201 require an infrastructure that could help agencies uncover possible insider threats to data security or data privacy, said Christopher Michael, technology strategist at Computer Associates International.

Such a use of government-issued smart cards would be appropriate, said Phil Libin, president of CoreStreet, which sells electronic identity verification services. "As a private citizen, I want government employees to have these cards," he said. "I want to know that all actions in the government can be logged and audited to give accountability."



upcoming event

Green Computing Summit, Ronald Reagan Building, Washington, DC
December 2 - December 3, 2008

Trusted Internet Connection and the Comprehensive National Cyber Security Initiative, The Willard Intercontinental Hotel, Washington, DC
December 4, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email