Search
A large federal agency, with hundreds of thousands of external users, needed a solution to provide authentication and validation for these users upon login. The process required modern technology, updates to the organization’s Zero Trust policies, and compliance with OMB Directive M-19-17, “Enabling Mission Delivery through Improved Identity, Credential, and Access Management”1. The federal standard outlines how agencies must protect external user data, and access through identity and credential management, and access control methods.
The agency recognized that security measures for users outside the organization must be different than those implemented for users within it, including the need to vet internal and external accounts to varying degrees. The tools to vet external users had to reflect the necessity to prove personhood and identity. With a new solution, the agency considered the following criteria:
The Guidehouse team led the selection and deployment of an identity provider (IdP) to consolidate identity data and authenticate external users to access applications and data. The team also applied NIST 800-63-3, “Digital Identity Guidelines for Authentication Assurance Levels,”2 to the solution which included:
While the implementation started with a smaller pilot, the organization, with Guidehouse’s support, is planning for and integrating hundreds of future applications. This effort will consolidate other legacy IdPs to the new IdP solution. Guidehouse is also providing training for end users, administrators, and help desk personnel to support solution deployment and usage.
The platform enables secure, phishing-resistant authentication and single sign-on (SSO) capabilities for all internal and external users accessing the agency’s information systems and networks. The IdP met the agency’s criteria and enhanced security for the organization by placing internal users in one hub, and external users in another, while utilizing the same IdP platform.
The solution also simplified the process of vetting identities with application accounts by placing that responsibility and risk with the application owners. These outcomes have enabled stronger security protocols for the department and streamlined login processes across applications.
Generative AI (GenAI) is reshaping the cybersecurity landscape both as a powerful tool for organizations and a potent weapon for cyber attackers. Are you ready to adopt this transformative technology? Read The State of GenAI Today report by Guidehouse and CDO Magazine.
1. “Enabling Mission Delivery through Improved Identity, Credential, and Access Management”, May 21, 2019, MEMORANDUM FOR HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES (whitehouse.gov).
2. “NIST Special Publication 800-63-3", June 2017, Digital Identity Guidelines (nist.gov).
Guidehouse is a global consultancy providing advisory, digital, and managed services to the commercial and public sectors. Purpose-built to serve the national security, financial services, healthcare, energy, and infrastructure industries, the firm collaborates with leaders to outwit complexity and achieve transformational changes that meaningfully shape the future.