08 - FSA Identity Access Mgt Solution Overview.docx

DOCX document 2 MB Posted

Attached to
Request for Information: Award Eligibility Determination Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of Education

About this file

This document provides an overview of the Federal Student Aid Identity and Access Management (IAM) solutions. The IAM solutions include the Person Authentication Service (PAS), Access and Identity Management System (AIMS), Two-Factor Authentication (TFA), and Privileged Account Management (PAM). PAS is used for non-privileged external users to access their financial aid information, while AIMS provides identity and access services for privileged internal and external users accessing various FSA systems. TFA provides additional authentication for users accessing applications outside the FSA network. PAM manages access for privileged users requiring access to resources in FSA data centers. The overview describes the architecture and functionality of each solution, as well as how different categories of users interact with the various IAM components. Target users include students, borrowers, parents, partners, and privileged administrators. Integration methods for applications to leverage the IAM solutions are also covered.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information: Award Eligibility Determination, newest first.
File Type Posted
10 - AED Draft SLAs.xlsx XLSX spreadsheet
12 - CPS 101 with FA impacts 09102020.pdf PDF
11 - ED CSF Risk Scorecard Overview_July 2020.pdf PDF
09 - FSA Current State.pdf PDF
AED RFI Final.pdf PDF
03 - Security Technical Requirements.xlsx XLSX spreadsheet
05 - Hosting Environments with Approved Agency ATOs.pdf PDF
04 - Additional Current State Technical Constraints.xlsx XLSX spreadsheet
01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf PDF
02 - Pricing Template.xlsx XLSX spreadsheet
07 - Hosting Environments w Approved ATOs.pdf PDF
06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx XLSX spreadsheet
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Department of Education Office of Federal Student Aid Next Generation Financial Services Environment

Attachment 08 – FSA Identity & Access Management Solution Overview

All NextGen solutions must use FSA identity and access management (IAM) solutions for authorization, authentication, single-sign-on (SSO), self-services, and identity management for a consistent and scalable set of security services for provisioning and managing all users.

The FSA IAM solutions provides FSA with a comprehensive Identity, Credential, and Access Management (ICAM) solution that addresses the growing data management, interoperability, and cybersecurity challenges facing FSA today and into the future. ICAM solutions, especially federated ones, aligns FSA applications around common identity and access management practices. The FSA IAM provides operational efficiency and flexibility by making identity and access management for FSA systems more efficient and secure. This applies to all internal and external, privileged, and non-privileged users accessing any FSA applications and systems. FSA’s IAM program is an overarching FSA initiative consisting of the following major applications:

· Person Authentication Service (PAS);

· Access and Identity Management System (AIMS);

· Two-Factor Authentication (TFA); and

· Privileged Account Management (PAM / CyberArk / ezPIV).

Each system provides platforms for identity, credential, and access management for authorized users of FSA applications and services to identify and authenticate themselves to an authorized application through a consistent and scalable set of security services for provisioning and managing users.

Overview of solutions:

· Person Authentication Service (PAS) PAS is a comprehensive security solution used to provide external users (students, parents, and borrowers) access to their own information hosted on various student financial assistance systems within FSA, to apply for federal financial assistance and obtain information about their personal records.

· Access and Identity Management System (AIMS) AIMS provides identity authentication and access services for internal and external users accessing FSA support systems, networks, and applications that supports the FSA mission, consisting of FSA Partners and some FSA Employees and Contractors.

· Two Factor Authentication (TFA) TFA is a major sub-component of AIMS, TFA is often used in conjunction with the AIMS Identity (ID) and password to provide unique user a one-time password (OTP) service for a second form of credentialing when accessing TFA-enabled applications from a non-secure network location outside of the FSA network.

· Privileged Account Management (PAM) PAM manages privileged user access and system administration activities of users with elevated privileges accessing IT resources in FSA data centers; includes servers, network devices, databases, and purpose-built appliances. PAM CyberArk system requires the use of a Department-issued or GSA’s USAccess-issued Personal Identity Verification (PIV) card to enforce a high level of security for access.

· ez/PIV ez/PIV Card Authenticator is a PIV or PIV-I card-based solution that allows authorized privileged FSA users (employees and contractors) to generate a one-time use passcode to authenticate and gain access to FSA mainframes.

Overview of solutions and target users:

Students, borrowers, and parents / "End Users" (~71+ million non-privileged external users) use the FSAID/PAS system for, applying/have applied for Federal Student Aid or will apply for student aid. These users require a FSA ID and password for access to FSA business applications.

Partners (e.g. Schools) / "Power Users" (~88K+ privileged external and internal users) use the AIMS and TFA systems for any user who has higher privilege than the students, parent and borrower users and most likely has access to PII information of other individuals associated with their organization or register other regular users. These users require a second form of authentication with their username and password and typically perform administrative functionalities for the FSA business application.

Administrators “Privileged Users" use the PAM (currently known as CyberArk / ezPIV) system for access to endpoints/resources/servers in a data center for their system. They can be performing as (not limited to) system administrator, database administrator, application administrator, network administrator, mainframe access (using ezPIV), information assurance manager or information assurance officer. These users all require a PIV or PIV-I (through a trusted federal partner) card for access.

See attached presentation for further details.

image1.emf

FSA%20IAM%20Solutions%20v4.pptx FSA IAM Solutions Overview

U.S. Department of Education Federal Student Aid

Aug 10, 2020

Last Modified 11/15/2017 2:19 PM Eastern Standard Time

Printed 11/14/2017 4:44 PM Eastern Standard Time

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Unit of measure

STICKER

Legend

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

CLICK TO ADD TITLE

Agenda

Products

Overview of Products and Integrations leveraged in FSA IAM Program

PAS

PAS Overview and details of architecture and implementation

AIMS/TFA

AIMS/TFA overview and details of architecture and implementation

FSA IAM

General Overview of FSA IAM Program

PAM

PAM overview and details of architecture and implementation

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

FSA IAM Solutions

The FSA IAM solutions provides FSA with a comprehensive Identity, Credential, and Access Management (ICAM) solution that addresses the growing data management, interoperability, and cybersecurity challenges facing FSA today and into the future. ICAM solutions, especially federated ones, aligns FSA applications around common identity and access management practices. The FSA IAM provides operational efficiency and flexibility by making identity and access management for FSA systems more efficient and secure. This applies to all internal and external, privileged, and non-privileged users accessing any FSA applications and systems. FSA’s IAM program is an overarching FSA initiative consisting of the following major applications:

Person Authentication Service (PAS)

Access and Identity Management System (AIMS)

Two-Factor Authentication (TFA)

Privilege Account Management (PAM: CyberArk/ezPIV)

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

IAM Solution

General

AIMS

Products & Integrations

FSA User ECO System

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

FSA User ECO System Categories

Category of Users FSA Employee’s & Support Contractors School & Partner Users Students, Borrowers and Parents

Non-Privileged External Users X X X

Privileged Internal and External Users X X

Privileged Internal Users X

Non-Privileged External Users: Students, Borrowers and Parents "End Users" (~71+ million non-privileged external users): These are Students, parents of students and borrowers who are applying/have applied for Federal Student Aid or will apply for student aid. These users require FSA ID and password for access to FSA business applications including FAFSA, NSLDS, and Student Loans.

Privileged Internal and External Users: School & Partner Users "Power Users" (~88K+ power users internal and external): Any user who has higher privilege than students, parent and borrower users and most likely has access to PII information of other individuals associated with their organization or register other regular users. These users can perform as school administrators, TIVAS administrators, NFP administrators, Guaranty Agency Administrators, private collection agencies. In some cases they are FSA employees or contractors supporting an FSA application. These users require Two-Factor Authentication (TFA) tokens.

Privileged Internal Users: Administrators “Privileged Users" These users are capable of issuing commands on the endpoint/resource/server in the data center for their system. They can be performing as (not limited to) system administrator, database administrator, application administrator, network administrator, information assurance manager or information assurance officer. These users requires a PIV card for access.

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

PAS Overview

PAS is a comprehensive security solution used to generate authentication and log-on credentials for those individuals wishing to access various student financial assistance systems to apply for federal financial assistance and obtain information about their personal records. PAS contains records about former, current, and prospective students and parents who have created an FSA ID. PAS provides authorized FSA non-privileged external users (students, parents, and borrowers) a more secure capability for accessing the FSA systems with the following benefits:

Full range of identity and access management services (e.g., account creation), user provisioning and access, user self-care, and other common capabilities without the use of PII for log-in credentials.

Ability to effectively exchange data with other external and internal FSA systems for authentication and other purposes, including electronically signing the FAFSA and Master Promissory Notes.

Has the ability to efficiently integrate or interoperate with the existing FSA Access and Identity Management System (AIMS).

PAS provides audit, tracking and reporting capabilities.

The FSA ID is the username and password protected account that students, parents, and borrowers utilize to access FSA systems.

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

PAS Overview (Cont.)

What is the Person Authentication Service (PAS)?

PAS is the underlying system of the FSA ID and it provides users with secure identity and access management.

PAS replaced the PIN system in May 2015 and modernized access for users by implementing a more secure username and password log-in solution.

PAS does not require Personal Identity Information (PII) for log-in credentials, unlike the PIN system (required SSN and DOB).

The advantages of the FSA ID / PAS?

PAS does not use PII for log-in credentials

PAS provides users the full range of identity and access management services (e.g. account creation, user provisioning and access, user self-care, and other common capabilities)

PAS enables users to electronically sign the FAFSA, and Master Promissory Notes

PAS integrates with FSA applications

PAS provides audit, tracking and reporting capabilities

PAS ensures the capacity for 100+ million users

PAS responds to OIG audit findings and recommendations

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

Access Policy Enforcement Point

This component is the access point for all traffic destined for PAS protected applications

IBM’s WebSeal is used to make access management decisions, manage active sessions, and provide access controls, encryption, and secure transmissions

User Identity

This component is responsible for storing and maintaining the public user’s identity

Identity information (SSN, Name, DOB, CQA, etc.) is stored in IBM’s Tivoli Directory Server (TDS) using Lightweight Directory Access Protocol (LDAP)

Audit data (events, timestamps, etc.) is stored in an Oracle Database

System data (system errors, notifications, etc.) is stored in server log files

All information is encrypted

Administrative Services

This component provides authorized FSA administrators and customer service representatives with comprehensive admin, management, and reporting capabilities

Authorized admin users are able to perform searches, view ad hoc reports, quarantine or disable accounts, and other routine system admin tasks

User Interface Services (UIS)

This component provides the core public user-facing interface functionality including account creation, user self-service, and extensible custom authentication services

The UIS uses a responsive web design that provides appropriate security warnings and privacy policy information

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

Architecture

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

Login

Authenticate User

Federated

Lock Account

Create Account

Create Username

Create Password

User Account Maintenance

Update PII

Perform Agency Matches

Change Password / Challenge Questions

Manage Challenge Questions

Enable/Disable Account

Manage Preferences

Manage Demographic Info

Account Notifications eSignature for FAFSA and StudentLoans.gov

Username / Password Retrieval

Recovery with SMS and Email

Authentication / Pre–Population Services

FAFSA, NSLDS, Studentloans.gov, DCC, HRA

Auditing and Reporting

Account Administration

Enable/Disable Account

Key Logger / Quarantine

Identity Verification (Manual)

Search

PAS architecture supports high transaction rates

100,000 concurrent sessions

30+ logins per second

10+ registrations per second

PAS architecture supports growth to 80+ million accounts

PAS integration options currently include:

Reverse proxy

Web services

Federated (preferred solution)

The target state is single sign on using federated integration

Key Functionality

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

AIMS Overview

Access and Identity Management System (AIMS) provides the core technology components and the associated processes/workflows necessary for implementing an enterprise security system for FSA’s line-of-business applications.

Consists of IBM Security Access Manager, IBM Security Identity Manager, Federated Identity Manager, and Two Factor Authentication.

Supports over 80,000 privileged users (Partners, Employees, Contractors).

Provides enterprise security supports to 22 systems including COD, PM, NSLDS FAP, eCB, eCDR Appeals and FAA Access

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

AIMS Overview (Cont.)

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

FSA’s line-of-business Applications secured by AIMS can leverage common AIMS services. These common security services include:

Authentication and authorization

Password management and standards

Session management

Single sign-on to other FSA systems secured by AIMS

Access related audit logs

Two Factor Authentication (TFA)

Security Awareness Training

Privacy Act acceptance

Rules of Behavior acceptance

Active confirmation

Privileged Access Management (PAM) Integration - CyberArk

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

Architecture

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

PAM Overview

The PAM system manages privileged user access and system administration activities of users with elevated privileges to IT resources in FSA Next Generation Data Center (NGDC), including servers, network devices, databases, and purpose-built appliances. PAM system requires two-factor authentication for privileged users via Department-issued or GSA’s USAccess -issued Personal Identity Verification (PIV) card, enforcing a high level of security for access to IT resources. PAM allows FSA to minimize the number of privileged users, limit functions that can be performed when using privileged accounts, limit the duration that privileged users can be logged in, limit the privileged functions that can be performed using remote access, and ensure that privileged user activities are logged and that such logs are reviewed regularly. The main tools used to manage our privilege users are:

CyberArk ez/PIV Card Authenticator

This system will support FSA and Contract privileged users (approximately 875).

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

PAM Overview

CyberArk: environment is the central point of management of privileged user access within the FSA Data Center environment. CyberArk will be integrated with the Information Security and Identity Management (ISIM) component for account provisioning from AIMS. Access to the CyberArk portal will require the use of a Personal Identity Verification (PIV) card issued to the privileged user. The CyberArk software technology manages passwords, keeps audit trails, and integrates with existing authentication mechanisms. CyberArk has the following features:

Brokering of passwords

Auditing of user sessions via keystroke logging, screen capture, and video

Workflow and role-based access of servers and infrastructure resources implification of user accounts on hardware to role-based accounts

CyberArk is a commercial off-the-shelf (COTS) product. The installation of CyberArk (password vault, component server, Microsoft Active Directory [AD]) will be placed within the Prod-Secure zone.

ez/PIV Card Authenticator: is a PIV card-based solution that allows authorized privileged FSA users (employees and contractors) to generate a one-time use passcode in order to authenticate and gain access to FSA mainframes. ez/PIV provides multifactor authentication, out-of-band password generation and validation for the privileged FSA users to validate before they gain access to FSA mainframes.

BlueZone: is a 3270 terminal emulation software that provides privileged FSA users (employees and contractors) with a user interface to authenticate and connect into authorized mainframe systems. Credentials generated using the ez/PIV tool are used by privileged mainframe users for authentication when using the Bluezone software for mainframe connections.

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

IBM Security Access Manager (ISAM): The ISAM product is a policy based access management solution that provides authentication and authorization capability to integrate with FSA’s line-of-business applications.

IBM WebSEAL (Reverse Proxy): The WebSEAL is a component of ISAM and supports enforcement of security policy. WebSEAL junction's server as the connection between front-end WebSEAL server and back-end application web servers.

IBM Security Identity Manager (ISIM): Provides account lifecycle and custom workflow capabilities to help FSA setup new accounts and passwords, reset passwords and capability to produce centralized reports about security policy, access rights and audit events.

IBM Adapter: The Adapter is bundled with ISIM software and enables FSA to connect ISIM to different identity resources in order to provision identities. An AD adapter is installed On CyberArk Active Directory to facilitate user provisioning for CyberArk access

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

Products & Integrations (Cont.)

Reverse Proxy: Reverse proxy is a service provided by our IAM solutions that retrieves resources on behalf of a client. These resources are then returned to the client, appearing as if they originated from the IAM solution. The IAM reverse proxy solution acts as an intermediary on behalf of FSA applications and services presenting to the client. FSA applications and services that are co-located in the same datacenter as the IAM solutions, can utilize this approach for authentication, authorization, single sign-on (SSO) and end user session management.

Web Service Authentication: The Web Service Integration login process for applications will not have their user sessions managed by an IAM solution. This integration approach requires the application to maintain its own login page and manage all user credential sessions. The user credentials are collected by the application and are checked against IAM solution Web services.

Federation: FSA applications that are either hosted outside the FSA NGDC datacenter or co-located in the same data center and use Federation Standard Protocol, Security Assertion Markup Language (SAML), wherein the business application maintains session, the end user is temporarily redirected to the IAM solution for credentials validation and then is redirected back to the application. The federation login process for applications will not have their user sessions managed by an IAM solution. This integration approach requires the application to redirect to the IAM solution to perform the authentication. Once the authentication validations are successfully performed within the IAM solution, the user is then redirected back to the application.

Desktop Single Sign-On: FSA’s intranet applications and SharePoint infrastructure use this approach to enable SSO between the user’s desktop (Active Directory) and the IAM solution protected FSA intranet applications.

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy

Products & Integrations (Cont.)

PAS Federated integration is the preferred method. The ECS Application is integrated with PAS using this method.

TRACKER

Unit of measure

1 Footnote

SOURCE : Source

Title

Legend

Legend

Legend

Federal Student Aid an office of the U.S. Department of Education draft – Proprietary and Confidential. Do Not Copy image5.png image2.png image6.jpg image7.png image8.png image9.png image10.png image11.png oleObject1.bin image1.emf

File details come from the government source that posted it. Updated .