08 - FSA Identity Access Mgt Solution Overview.docx
DOCX document 2 MB Posted
- Attached to
- Request for Information: Award Eligibility Determination Federal contract opportunity
- Solicitation number
- Not on record
- Issued by
- Department of Education
About this file
This document provides an overview of the Federal Student Aid Identity and Access Management (IAM) solutions. The IAM solutions include the Person Authentication Service (PAS), Access and Identity Management System (AIMS), Two-Factor Authentication (TFA), and Privileged Account Management (PAM). PAS is used for non-privileged external users to access their financial aid information, while AIMS provides identity and access services for privileged internal and external users accessing various FSA systems. TFA provides additional authentication for users accessing applications outside the FSA network. PAM manages access for privileged users requiring access to resources in FSA data centers. The overview describes the architecture and functionality of each solution, as well as how different categories of users interact with the various IAM components. Target users include students, borrowers, parents, partners, and privileged administrators. Integration methods for applications to leverage the IAM solutions are also covered.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 10 - AED Draft SLAs.xlsx | XLSX spreadsheet | |
| 12 - CPS 101 with FA impacts 09102020.pdf | ||
| 11 - ED CSF Risk Scorecard Overview_July 2020.pdf | ||
| 09 - FSA Current State.pdf | ||
| AED RFI Final.pdf | ||
| 03 - Security Technical Requirements.xlsx | XLSX spreadsheet | |
| 05 - Hosting Environments with Approved Agency ATOs.pdf | ||
| 04 - Additional Current State Technical Constraints.xlsx | XLSX spreadsheet | |
| 01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf | ||
| 02 - Pricing Template.xlsx | XLSX spreadsheet | |
| 07 - Hosting Environments w Approved ATOs.pdf | ||
| 06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx | XLSX spreadsheet |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. Department of Education Office of Federal Student Aid Next Generation Financial Services Environment
Attachment 08 – FSA Identity & Access Management Solution Overview
All NextGen solutions must use FSA identity and access management (IAM) solutions for authorization, authentication, single-sign-on (SSO), self-services, and identity management for a consistent and scalable set of security services for provisioning and managing all users.
The FSA IAM solutions provides FSA with a comprehensive Identity, Credential, and Access Management (ICAM) solution that addresses the growing data management, interoperability, and cybersecurity challenges facing FSA today and into the future. ICAM solutions, especially federated ones, aligns FSA applications around common identity and access management practices. The FSA IAM provides operational efficiency and flexibility by making identity and access management for FSA systems more efficient and secure. This applies to all internal and external, privileged, and non-privileged users accessing any FSA applications and systems. FSA’s IAM program is an overarching FSA initiative consisting of the following major applications:
· Person Authentication Service (PAS);
· Access and Identity Management System (AIMS);
· Two-Factor Authentication (TFA); and
· Privileged Account Management (PAM / CyberArk / ezPIV).
Each system provides platforms for identity, credential, and access management for authorized users of FSA applications and services to identify and authenticate themselves to an authorized application through a consistent and scalable set of security services for provisioning and managing users.
Overview of solutions:
· Person Authentication Service (PAS) PAS is a comprehensive security solution used to provide external users (students, parents, and borrowers) access to their own information hosted on various student financial assistance systems within FSA, to apply for federal financial assistance and obtain information about their personal records.
· Access and Identity Management System (AIMS) AIMS provides identity authentication and access services for internal and external users accessing FSA support systems, networks, and applications that supports the FSA mission, consisting of FSA Partners and some FSA Employees and Contractors.
· Two Factor Authentication (TFA) TFA is a major sub-component of AIMS, TFA is often used in conjunction with the AIMS Identity (ID) and password to provide unique user a one-time password (OTP) service for a second form of credentialing when accessing TFA-enabled applications from a non-secure network location outside of the FSA network.
· Privileged Account Management (PAM) PAM manages privileged user access and system administration activities of users with elevated privileges accessing IT resources in FSA data centers; includes servers, network devices, databases, and purpose-built appliances. PAM CyberArk system requires the use of a Department-issued or GSA’s USAccess-issued Personal Identity Verification (PIV) card to enforce a high level of security for access.
· ez/PIV ez/PIV Card Authenticator is a PIV or PIV-I card-based solution that allows authorized privileged FSA users (employees and contractors) to generate a one-time use passcode to authenticate and gain access to FSA mainframes.
Overview of solutions and target users:
Students, borrowers, and parents / "End Users" (~71+ million non-privileged external users) use the FSAID/PAS system for, applying/have applied for Federal Student Aid or will apply for student aid. These users require a FSA ID and password for access to FSA business applications.
Partners (e.g. Schools) / "Power Users" (~88K+ privileged external and internal users) use the AIMS and TFA systems for any user who has higher privilege than the students, parent and borrower users and most likely has access to PII information of other individuals associated with their organization or register other regular users. These users require a second form of authentication with their username and password and typically perform administrative functionalities for the FSA business application.
Administrators “Privileged Users" use the PAM (currently known as CyberArk / ezPIV) system for access to endpoints/resources/servers in a data center for their system. They can be performing as (not limited to) system administrator, database administrator, application administrator, network administrator, mainframe access (using ezPIV), information assurance manager or information assurance officer. These users all require a PIV or PIV-I (through a trusted federal partner) card for access.
See attached presentation for further details.
image1.emf
FSA%20IAM%20Solutions%20v4.pptx FSA IAM Solutions Overview
U.S. Department of Education Federal Student Aid
Aug 10, 2020
Last Modified 11/15/2017 2:19 PM Eastern Standard Time
Printed 11/14/2017 4:44 PM Eastern Standard Time
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Unit of measure
STICKER
Legend
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
CLICK TO ADD TITLE
Agenda
Products
Overview of Products and Integrations leveraged in FSA IAM Program
PAS
PAS Overview and details of architecture and implementation
AIMS/TFA
AIMS/TFA overview and details of architecture and implementation
FSA IAM
General Overview of FSA IAM Program
PAM
PAM overview and details of architecture and implementation
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
FSA IAM Solutions
The FSA IAM solutions provides FSA with a comprehensive Identity, Credential, and Access Management (ICAM) solution that addresses the growing data management, interoperability, and cybersecurity challenges facing FSA today and into the future. ICAM solutions, especially federated ones, aligns FSA applications around common identity and access management practices. The FSA IAM provides operational efficiency and flexibility by making identity and access management for FSA systems more efficient and secure. This applies to all internal and external, privileged, and non-privileged users accessing any FSA applications and systems. FSA’s IAM program is an overarching FSA initiative consisting of the following major applications:
Person Authentication Service (PAS)
Access and Identity Management System (AIMS)
Two-Factor Authentication (TFA)
Privilege Account Management (PAM: CyberArk/ezPIV)
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
IAM Solution
General
AIMS
Products & Integrations
FSA User ECO System
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
FSA User ECO System Categories
Category of Users FSA Employee’s & Support Contractors School & Partner Users Students, Borrowers and Parents
Non-Privileged External Users X X X
Privileged Internal and External Users X X
Privileged Internal Users X
Non-Privileged External Users: Students, Borrowers and Parents "End Users" (~71+ million non-privileged external users): These are Students, parents of students and borrowers who are applying/have applied for Federal Student Aid or will apply for student aid. These users require FSA ID and password for access to FSA business applications including FAFSA, NSLDS, and Student Loans.
Privileged Internal and External Users: School & Partner Users "Power Users" (~88K+ power users internal and external): Any user who has higher privilege than students, parent and borrower users and most likely has access to PII information of other individuals associated with their organization or register other regular users. These users can perform as school administrators, TIVAS administrators, NFP administrators, Guaranty Agency Administrators, private collection agencies. In some cases they are FSA employees or contractors supporting an FSA application. These users require Two-Factor Authentication (TFA) tokens.
Privileged Internal Users: Administrators “Privileged Users" These users are capable of issuing commands on the endpoint/resource/server in the data center for their system. They can be performing as (not limited to) system administrator, database administrator, application administrator, network administrator, information assurance manager or information assurance officer. These users requires a PIV card for access.
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
PAS Overview
PAS is a comprehensive security solution used to generate authentication and log-on credentials for those individuals wishing to access various student financial assistance systems to apply for federal financial assistance and obtain information about their personal records. PAS contains records about former, current, and prospective students and parents who have created an FSA ID. PAS provides authorized FSA non-privileged external users (students, parents, and borrowers) a more secure capability for accessing the FSA systems with the following benefits:
Full range of identity and access management services (e.g., account creation), user provisioning and access, user self-care, and other common capabilities without the use of PII for log-in credentials.
Ability to effectively exchange data with other external and internal FSA systems for authentication and other purposes, including electronically signing the FAFSA and Master Promissory Notes.
Has the ability to efficiently integrate or interoperate with the existing FSA Access and Identity Management System (AIMS).
PAS provides audit, tracking and reporting capabilities.
The FSA ID is the username and password protected account that students, parents, and borrowers utilize to access FSA systems.
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
PAS Overview (Cont.)
What is the Person Authentication Service (PAS)?
PAS is the underlying system of the FSA ID and it provides users with secure identity and access management.
PAS replaced the PIN system in May 2015 and modernized access for users by implementing a more secure username and password log-in solution.
PAS does not require Personal Identity Information (PII) for log-in credentials, unlike the PIN system (required SSN and DOB).
The advantages of the FSA ID / PAS?
PAS does not use PII for log-in credentials
PAS provides users the full range of identity and access management services (e.g. account creation, user provisioning and access, user self-care, and other common capabilities)
PAS enables users to electronically sign the FAFSA, and Master Promissory Notes
PAS integrates with FSA applications
PAS provides audit, tracking and reporting capabilities
PAS ensures the capacity for 100+ million users
PAS responds to OIG audit findings and recommendations
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
Access Policy Enforcement Point
This component is the access point for all traffic destined for PAS protected applications
IBM’s WebSeal is used to make access management decisions, manage active sessions, and provide access controls, encryption, and secure transmissions
User Identity
This component is responsible for storing and maintaining the public user’s identity
Identity information (SSN, Name, DOB, CQA, etc.) is stored in IBM’s Tivoli Directory Server (TDS) using Lightweight Directory Access Protocol (LDAP)
Audit data (events, timestamps, etc.) is stored in an Oracle Database
System data (system errors, notifications, etc.) is stored in server log files
All information is encrypted
Administrative Services
This component provides authorized FSA administrators and customer service representatives with comprehensive admin, management, and reporting capabilities
Authorized admin users are able to perform searches, view ad hoc reports, quarantine or disable accounts, and other routine system admin tasks
User Interface Services (UIS)
This component provides the core public user-facing interface functionality including account creation, user self-service, and extensible custom authentication services
The UIS uses a responsive web design that provides appropriate security warnings and privacy policy information
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
Architecture
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
Login
Authenticate User
Federated
Lock Account
Create Account
Create Username
Create Password
User Account Maintenance
Update PII
Perform Agency Matches
Change Password / Challenge Questions
Manage Challenge Questions
Enable/Disable Account
Manage Preferences
Manage Demographic Info
Account Notifications eSignature for FAFSA and StudentLoans.gov
Username / Password Retrieval
Recovery with SMS and Email
Authentication / Pre–Population Services
FAFSA, NSLDS, Studentloans.gov, DCC, HRA
Auditing and Reporting
Account Administration
Enable/Disable Account
Key Logger / Quarantine
Identity Verification (Manual)
Search
PAS architecture supports high transaction rates
100,000 concurrent sessions
30+ logins per second
10+ registrations per second
PAS architecture supports growth to 80+ million accounts
PAS integration options currently include:
Reverse proxy
Web services
Federated (preferred solution)
The target state is single sign on using federated integration
Key Functionality
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
AIMS Overview
Access and Identity Management System (AIMS) provides the core technology components and the associated processes/workflows necessary for implementing an enterprise security system for FSA’s line-of-business applications.
Consists of IBM Security Access Manager, IBM Security Identity Manager, Federated Identity Manager, and Two Factor Authentication.
Supports over 80,000 privileged users (Partners, Employees, Contractors).
Provides enterprise security supports to 22 systems including COD, PM, NSLDS FAP, eCB, eCDR Appeals and FAA Access
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
AIMS Overview (Cont.)
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
FSA’s line-of-business Applications secured by AIMS can leverage common AIMS services. These common security services include:
Authentication and authorization
Password management and standards
Session management
Single sign-on to other FSA systems secured by AIMS
Access related audit logs
Two Factor Authentication (TFA)
Security Awareness Training
Privacy Act acceptance
Rules of Behavior acceptance
Active confirmation
Privileged Access Management (PAM) Integration - CyberArk
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
Architecture
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
PAM Overview
The PAM system manages privileged user access and system administration activities of users with elevated privileges to IT resources in FSA Next Generation Data Center (NGDC), including servers, network devices, databases, and purpose-built appliances. PAM system requires two-factor authentication for privileged users via Department-issued or GSA’s USAccess -issued Personal Identity Verification (PIV) card, enforcing a high level of security for access to IT resources. PAM allows FSA to minimize the number of privileged users, limit functions that can be performed when using privileged accounts, limit the duration that privileged users can be logged in, limit the privileged functions that can be performed using remote access, and ensure that privileged user activities are logged and that such logs are reviewed regularly. The main tools used to manage our privilege users are:
CyberArk ez/PIV Card Authenticator
This system will support FSA and Contract privileged users (approximately 875).
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
PAM Overview
CyberArk: environment is the central point of management of privileged user access within the FSA Data Center environment. CyberArk will be integrated with the Information Security and Identity Management (ISIM) component for account provisioning from AIMS. Access to the CyberArk portal will require the use of a Personal Identity Verification (PIV) card issued to the privileged user. The CyberArk software technology manages passwords, keeps audit trails, and integrates with existing authentication mechanisms. CyberArk has the following features:
Brokering of passwords
Auditing of user sessions via keystroke logging, screen capture, and video
Workflow and role-based access of servers and infrastructure resources implification of user accounts on hardware to role-based accounts
CyberArk is a commercial off-the-shelf (COTS) product. The installation of CyberArk (password vault, component server, Microsoft Active Directory [AD]) will be placed within the Prod-Secure zone.
ez/PIV Card Authenticator: is a PIV card-based solution that allows authorized privileged FSA users (employees and contractors) to generate a one-time use passcode in order to authenticate and gain access to FSA mainframes. ez/PIV provides multifactor authentication, out-of-band password generation and validation for the privileged FSA users to validate before they gain access to FSA mainframes.
BlueZone: is a 3270 terminal emulation software that provides privileged FSA users (employees and contractors) with a user interface to authenticate and connect into authorized mainframe systems. Credentials generated using the ez/PIV tool are used by privileged mainframe users for authentication when using the Bluezone software for mainframe connections.
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
IBM Security Access Manager (ISAM): The ISAM product is a policy based access management solution that provides authentication and authorization capability to integrate with FSA’s line-of-business applications.
IBM WebSEAL (Reverse Proxy): The WebSEAL is a component of ISAM and supports enforcement of security policy. WebSEAL junction's server as the connection between front-end WebSEAL server and back-end application web servers.
IBM Security Identity Manager (ISIM): Provides account lifecycle and custom workflow capabilities to help FSA setup new accounts and passwords, reset passwords and capability to produce centralized reports about security policy, access rights and audit events.
IBM Adapter: The Adapter is bundled with ISIM software and enables FSA to connect ISIM to different identity resources in order to provision identities. An AD adapter is installed On CyberArk Active Directory to facilitate user provisioning for CyberArk access
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
Products & Integrations (Cont.)
Reverse Proxy: Reverse proxy is a service provided by our IAM solutions that retrieves resources on behalf of a client. These resources are then returned to the client, appearing as if they originated from the IAM solution. The IAM reverse proxy solution acts as an intermediary on behalf of FSA applications and services presenting to the client. FSA applications and services that are co-located in the same datacenter as the IAM solutions, can utilize this approach for authentication, authorization, single sign-on (SSO) and end user session management.
Web Service Authentication: The Web Service Integration login process for applications will not have their user sessions managed by an IAM solution. This integration approach requires the application to maintain its own login page and manage all user credential sessions. The user credentials are collected by the application and are checked against IAM solution Web services.
Federation: FSA applications that are either hosted outside the FSA NGDC datacenter or co-located in the same data center and use Federation Standard Protocol, Security Assertion Markup Language (SAML), wherein the business application maintains session, the end user is temporarily redirected to the IAM solution for credentials validation and then is redirected back to the application. The federation login process for applications will not have their user sessions managed by an IAM solution. This integration approach requires the application to redirect to the IAM solution to perform the authentication. Once the authentication validations are successfully performed within the IAM solution, the user is then redirected back to the application.
Desktop Single Sign-On: FSA’s intranet applications and SharePoint infrastructure use this approach to enable SSO between the user’s desktop (Active Directory) and the IAM solution protected FSA intranet applications.
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy
Products & Integrations (Cont.)
PAS Federated integration is the preferred method. The ECS Application is integrated with PAS using this method.
TRACKER
Unit of measure
1 Footnote
SOURCE : Source
Title
Legend
Legend
Legend
Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy image5.png image2.png image6.jpg image7.png image8.png image9.png image10.png image11.png oleObject1.bin image1.emf
File details come from the government source that posted it. Updated .