Credential Management Systems
A credential is the binding between an authenticator and an identifier (user/service/ system). A credential management system (CMS) is an established form of issuing and managing credentials, based on software.
9 slides · 2 min read · Domain 5
CMS software can be used as part of public key infrastructure (PKI) systems, as well as for issuing twofactor-authentication (2FA) identities. Credentials may be collected and managed by a credential service provider (CSP). Credential examples include but are not limited to smart cards, private/public cryptographic keys and digital certificates.
In 2009, the U.S. federal government realized that a framework for identity management was needed for federal agencies to ensure compliance throughout the entire federal sector. They published the Federal Identity, Credential, and Access Management (FICAM architecture, which provided common Identity Credential Access Management (ICAM) rules for building sound credential architecture in federal agencies.
inPageSelected (position pos
The FICAM Roadmap and Implementation Guidance Version 2.0 has the following five-step enrollment process
Text on this slide
1. SPONSORSHIP
An authorized entity sponsors claimant for a credential with a credential service provider (CSP).
4. ISSUANCE
Claimant is issued credential.
2. ENROLLMENT AND REGISTRATION
The sponsored claimant enrols for the credentials. This step would include identity proofing, which might include capture of biographic and biometric data.
3. CREDENTIAL PRODUCTION
Credentials are produced in the form of smart cards, private/public cryptographic keys, and digital certificates.
5. CREDENTIAL LIFECYCLE MANAGEMENT
Credentials are maintained through activities that include revocation, re-issuance, re-enrollment, expiration, suspension, or reinstatement.
00g-1
Maliane
FICAM did not originally address online, on-demand or just-in-time identity concepts; nor did its five-step conceptual model address self-service or user-initiated changes.
Most business processes do need to have some self-service capability for end users to request access to network and physical resources based on established credentials, reset forgotten passwords, update identity and credential status information, and view corporate and organizational identity information using electronic interfaces. Organizational security policies may require any or all of these changes to be subject to review and approval prior to the credentials and permissions being updated.
This architecture and guide can be used as reference to how a CMS can be implemented in various organizations.
While FICAM provides useful guidelines, it was last updated in December 2011. In late 2020, the U.S. government's chief information officer and the General Services Administration began a migration, update, and restructure effort on these, known as the Managing Federal Identity Programs Roadmap and Playbook.
Security professionals who need to deal with federal identity and credential management processes may find this evolving FICAM architecture useful. Other, more current systems such as the NIST Digital Identity Guidelines (Special Publication 800-63) and ISO 27001 Annex 9 (Access Control) may also be helpful.
