Setting the record straight on US, Canadian governments’ trusted identity programs

Opinion
Sep 9, 20113 mins

One of last week’s newsletters (“Canada is out front once again”) caught the attention of folks at the U.S. National Institute for Standards and Technology (NIST), and not in a good way.

Jeremy Grant, a senior executive adviser to NIST, noted the article and got Gail Porter, NIST’s director of public affairs, to drop me a line. Grant, by the way, has been selected to manage the establishment of a National Program Office for the National Strategy for Trusted Identities in Cyberspace (NSTIC).

BACKGROUND: NSTIC director: ‘We’re trying to get rid of passwords’

I’d implied that NSTIC was a Johnny-come-lately to Canada’s Treasury Board of Canada Secretariat which recently released the final version of a document called “Federating Identity Management in the Government of Canada: A Backgrounder.”

But as the dynamic duo from NIST pointed out to me, the Canadian action was more akin to another U.S. program, the Federal Identity, Credential, and Access Management (FICAM). In 2009 (the same year the Canadian federation project was launched), the U.S. launched the Open Identity Solutions for Open Government initiative.

Since that time, according to Porter, three organizations have been accredited through the U.S. General Services Administration (GSA) as Trust Framework Providers and five firms have become Certified Identity Providers for the U.S. government. A number of other providers are in the queue for certification, and we expect to see a notable increase over the next year in U.S. government websites that rely upon these Certified Identity Providers.

According to a paper (“Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance” [warning: it’s a PDF file]) from the Smart Card Alliance:

“The CIO Council established the Identity, Credential, and Access Management Subcommittee (ICAMSC) with the charter to foster effective ICAM policies and enable trust across organizational, operational, physical, and network boundaries. The intersection of digital identities, credentials, and access control and the need for one comprehensive management approach has been officially stated.

“The ‘Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance’ was developed in support of the ICAM mission to provide a common segment architecture and implementation guidance.”

So, I stand corrected. Not only was the U.S. government not a Johnny-come-lately but they may have been out front. My apologies to the good people at NIST.

There’s a similar program in the U.K., by the way, called the Digital Identity Assurance project — a key effort in the U.K. government’s drive to get more citizens accessing public sector services online. According to a story in the U.K.’s Computer Weekly, the government has already rejected Facebook as a possible identity provider. Protecting citizen privacy will be key to the project, according to Bill McCluggage, deputy government CIO. He said, “Facebook is one organization that we haven’t spoken to, because we are concerned about what they may do with people’s data.” I’ll wager Google+ isn’t on their priority list, either!