Attachment 01b - OCIO Personal Identity Verification (PIV) Card Authentication Policy OCIO-POL-49.pdf

PDF 502 KB Posted

Attached to
Patent Data and Document Management (PDDM) Federal contract opportunity
Solicitation number
1333BJ20R00151004
Issued by
Department of Commerce US Patent and Trademark Office

About this file

This policy document establishes guidelines for the use of Personal Identity Verification cards for authentication on United States Patent and Trademark Office information systems. It requires that eligible employees and contractors use PIV cards as the normal mode of authentication. It defines eligible individuals and provides exemptions for certain user categories. The policy outlines acceptable backup authentication methods that can be used if the PIV card is unavailable. It also addresses PIV card loss, damage, or expiration scenarios for on-campus and telework access. Responsibilities are defined for complying with and monitoring adherence to the policy to ensure compliance with federal directives while not hindering the agency's mission.

The federal contract opportunity is a solicitation from the United States Patent and Trademark Office seeking contractor support to manage the entire life cycle of patent application processing. The support includes initial application filing, processing, and final disposition. Interested offerors must thoroughly review the solicitation and statement of work attachments to understand the requirements, as the attachments have been updated since the presolicitation notice. The solicitation number is 1333BJ20R00151004 and it is for the Patent Data and Document Management requirement. The contracting agency is the Department of Commerce United States Patent and Trademark Office.

View the file

Other files for this federal contract opportunity

Other files attached to Patent Data and Document Management (PDDM), newest first.
File Type Posted
1333BJ20R00151004_Amendment 0003_track changes.pdf PDF
Attachment 26 - DCB 2020-17.docx DOCX document
Attachment 26 - DCB 2020-16.docx DOCX document
Attachment 40-Pricing Template_updated.xlsx XLSX spreadsheet
Attachment 08 - Glossary of Terms_updated.docx DOCX document
Attachment 13a - FEPIB 2020-04.doc DOC document
PDDM RFP Questions and Responses.pdf PDF
Attachment 39 - Transition Plan Framework_updated.docx DOCX document
Attachment 26 - DCB 2020-14.docx DOCX document
Attachment 13a - FEPIB 2020-06.doc DOC document
Amendment 0001_1333BJ20R00151004.pdf PDF
Attachment 26.zip ZIP file
Attachment 17b - (jpg) u-bibdat1.jpg JPG image
Attachment 18 - DCB 2020-04.docx DOCX document
Attachment 38a - Cloud Services Usage Policy.pdf PDF
Attachment 38 - IT Security Requirements - 2020-04.docx DOCX document
Attachment 13a - FEPIB 2020-03.doc DOC document
Attachment 08 - Glossary of Terms.docx DOCX document
Attachment 17d - (jpg) us-request-v15-2013-01-25.jpg JPG image
Attachment 07 - IFW Document Codes - Document Code Dictionary 2020-04-15.pdf PDF
Attachment 18 - DCB 2020-12.docx DOCX document
Attachment 03a - USPTO Computer Specs.xlsx XLSX spreadsheet
Attachment 43 - Surveillance Plan.docx DOCX document
Request for Proposals No. 1333BJ20R00151004.pdf PDF
Attachment 05b- Weekly Serialized Filings.xls XLS spreadsheet
Attachment 32 - CofC Patent Term Adjustment SOP_Nov 13 2017.pptx PPTX presentation
Attachment 12 - Front End Processes.pdf PDF
Attachment 25b - Consolidated Listing of Official Gazette Notices_2018-01-25.pdf PDF
Attachment 16 - PG Pub Processes.pdf PDF
Attachment 39 - Transition Plan Framework.docx DOCX document
Attachment 13a - FEPIB 2020-02.doc DOC document
Attachment 25a - eOG_manual_2020.docx DOCX document
Attachment 14 - Quality Assurance of EFS-Web Submissions20190917.docx DOCX document
Attachment 05c - QA of EFS WEb Submissions Error Categories and Historical Volumes.xlsx XLSX spreadsheet
Attachment 10b.zip ZIP file
Attachment 13 - Front End Processing (FEP) Manual for Indexing and Scanning.docx DOCX document
Attachment 38b - IT_Security_Handbook.pdf PDF
Attachment 33 - PALM Basics.pptx PPTX presentation
Attachment 05a - Historical Data_Page Counts and Volumes.docx DOCX document
Attachment 41 - Past Performance Questionnaire.docx DOCX document
Attachment 31a - DCB 2020-None.docx DOCX document
Attachment 17e - (txt) -ExportTOC1.txt TXT text file
Attachment 21 - Post Allowance Processes.pdf PDF
Attachment 35a - PE2E-eDRS-Manual.pdf PDF
Attachment 28 - Grant - Yellow Book Instructions.docx DOCX document
Attachment 23 - DataEntryManual-NON-UTILITY-2020.doc DOC document
Attachment 17c - (jpg) u-suppub8-2012-12-04.jpg JPG image
Attachment 37 - PreExam Manual with Supplemental Instructions 9-20-2018.pdf PDF
Attachment 30 - Certificate of Correction Process.pdf PDF
Attachment 27 - Grant - Red Book Instructions.docx DOCX document
Show all 50

Patent Data and Document Management (PDDM) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

OFFICE OF THE CHIEF INFORMATION OFFICER

Personal Identity Verification (PIV) Card Authentication Policy Version 3.4

PERSONAL IDENTITY VERIFICATION (PIV) CARD AUTHENTICATION POLICY

OCIO-POL-49

Effective Date: June 30, 2015

Version: 3.4

Last Revision Review Date: April 19, 2018

Reason for Revision: Updated section II, PIV card usage requirements, and replaced Exemption

Enforcement Scenarios tables

TABLE OF CONTENTS

Section

I. Purpose

II. Authority

III. Scope

IV. Definitions

V. Policy

VI. Responsibilities

VII. Effect on Other Policies

I. PURPOSE

This policy provides guidelines for the use of Personal Identity Verification (PIV) card authentication on United States Patent and Trademark Office (USPTO) information systems.

II. AUTHORITY

This policy is issued in accordance with:

Federal Information Security Management Act of 2002 (FISMA)

Federal Information Security Modernization Act of 2014 (FISMA)

Homeland Security Presidential Directive 12 (HSPD-12)

Office of Management and Budget (OMB) Memorandum M-11-11

Federal Information Processing Standard 201-1 (FIPS 201-2)

Cross-Agency Priority Goals for Cybersecurity1

NIST SP 800-63 rev 3, Digital Identity Guidelines

NIST SP 800-157, Guidelines for Derived Personal Identity Verification (PIV) Credentials

1 https://www.performance.gov/node/3401

III. SCOPE

The provisions of this policy apply to all USPTO employees and contractors accessing, using, or operating USPTO workstations, servers, or information systems and to contractors providing telecommunications and information system services to USPTO.

This policy also applies to information systems owned and operated by contractors, contractor employees, USPTO guest researchers, collaborators, and other Federal agencies that carry out the

USPTO mission, whether or not they are located on Government property. Information systems intended to provide unrestricted access (e.g. public web pages and kiosks) are excluded.

Excluded Categories

In accordance with OMB’s provisions for an “agency-risk based decision” regarding the applicability of HSPD-12 to agency specific categories of individuals, the following defined categories of users are not required to use PIV cards for network access:

USPTO employees and contractors who have not been issued PIV cards: USPTO implements a phased approach to PIV card issuance. As a result, some eligible USPTO personnel (as defined above) may not possess PIV cards due to the status of the agency’s PIV card issuance process and should use an authorized backup mode of authentication.

USPTO employees and contractors working remotely using personally owned equipment who have not been issued PIV cards: Employees and contractors using personally owned equipment to access the USPTO network remotely must use PIV cards or approved multi-factor authentication (ex: RSA Token and PTONet credentials) if PIV cards has not been issued.

USPTO employees and contractors with intermittent access to USPTO facilities or systems:

Intermittent access is defined as non-routine access to federally controlled facilities or information systems equaling less than 30 days per calendar year. Users in this category should use a backup mode of authentication.

Temporary USPTO employees, contractors, interns, externs, and students: Employees, contractors, interns, externs, students, and other users assigned to perform work at USPTO facilities on USPTO information systems on a temporary basis may use authorized backup modes of authentication for network access. Temporary status applies to users with an expected service period of fewer than 179 days.

Contractors that only access contractor-owned/managed systems: USPTO enters into contracts with various third-parties to provide services to the agency using externally hosted, contractor managed systems. Users of these systems who do not require access to

USPTO-controlled facilities or systems are not required to employ or utilize PIV card authentication. However, these contractors must still meet security guidelines and criteria for processing, storing, and transferring data to the government in accordance with contractual and

FISMA requirements including use of multifactor authentication.

Anyone otherwise covered by this policy with a physical limitation that makes use of a PIV card for Authentication impossible or impractical.

Any employee using a mobile device approved by the Chief Information Officer: Some employees have mobile devices that are approved by the Chief Information Officer that connect with the PTONet. Employees using mobile devices to access USPTO information and communications systems must conform to OCIO-POL-34, Mobile Device Management Policy.

Any additional exceptions from PIV usage requirement must be approved by the USPTO OCIO.

IV. DEFINITIONS

Backup Mode of Authentication – An approved alternative means for logical access to the network. It is typically used when the normal mode is not possible or when a remote user logs in using personally owned equipment. Examples of backup modes of authentication include

Username/Password and RSA token authentication.

Critical Appointee – An employee of USPTO in a Senior Executive Service position serving under a

Career, Non-career, Limited Term, or Limited Emergency appointment.

Mobile Devices - A mobile device is defined to include smartphones, tablet computers, personal digital assistants (PDAs), and any other portable electronic device that can be used to access Federal government information or communications systems. Laptop computers are excluded from this definition for the purposes of this policy.

Off-Campus Access – Access to USPTO owned or managed information systems from a non-

USPTO facility, including private residences and contractor-owned sites.

On-Campus Access – Access to USPTO owned or managed information systems from a USPTO-controlled facility, including satellite offices.

Normal Mode of Authentication – The default mechanism by which a person gains logical access to the network. For the purposes of this policy, the normal mode of authentication for access to

USPTO information systems is PIV-based authentication.

Person – Any USPTO employee, staff member, contractor, associate, or guest researcher who is required to use a PIV card for logical access.

PIV-based Login – The use of a PIV card or derived credential for logical access.

PIV Card – A FIPS-201 compliant physical artifact (e.g. PIV II smart card) that contains stored credentials so that the claimed identity of the cardholder can be verified against the stored credentials by another person or an automated process.

Privileged Access – Access by a privileged network user who, by virtue of function, has been allocated a network user account with elevated privileges. Such persons will include, for example, the system administrator(s) and network administrator(s) who are responsible for keeping the system available and may need privileges to create new users profiles as well as to add or amend the privileges and access rights of existing users.

Remote Access – The ability for an organization’s users to access its non-public computing resources from locations external to the organization’s facilities.

SOHO – Small Office – Home Office router issued by USPTO to telework employees.

Unprivileged Access – Any access that is not privileged access (see above).

V. POLICY

A. Use of PIV Cards

In order to comply with Federal directives, PIV cards must be used as the normal mode of authentication for all eligible USPTO personnel on PIV-enabled systems. USPTO personnel are eligible for a PIV card if they:

Are a USPTO employee or contractor and are not in one of the excluded categories cited in Section III (“Scope”) of this policy;

Have a Social Security Number;

Have an expected length of federal service or agreement term greater than 179 days within a calendar year;

Require access to federally-controlled information systems; and

Are not a member of a defined workforce category outlined above.

Utilization of normal modes of authentication for privileged access to USPTO information systems is critical for securing sensitive USPTO information and accounts. While the PIV requirements outlined in this policy apply to both privileged and non-privileged access, USPTO employees and contractors must make every attempt to reduce or eliminate the use of backup modes of authentication when utilizing privileged access. If Privileged users are not using their PIV card to log in to the network prior to performing privileged functions on USPTO systems, system and user accounts, and networks, they are not in compliance with the USPTO policy and their actions are subject to review, investigation, and account revocation. Non-privileged users must use their PIV card for an initial access to the PTO network.

B. Backup Modes of Authentication

Eligible USPTO personnel (defined above) must use PIV card authentication as their normal mode of authentication for network access. In the event that an eligible user’s PIV card is lost, forgotten, damaged, stolen, or otherwise unusable, a backup mode of authentication may be authorized temporarily.

The criteria for activating an approved backup mode of authentication are based on the type of PIV card issue encountered and the user’s work categorization. In order to activate the backup mode of authentication, users must first notify their supervisor and/or telework coordinator and the OCIO Service

Desk. User should also contact the USPTO Security Services so that the PIV card can be suspended, revoked, and/or re-issued. Impacted individuals should then follow the USPTO “Logical Access

Procedure” and contact the OCIO Service Desk to activate temporary logical access.

The backup modes of authentication are as follows:

On Campus (Headquarters or Regional Office) – User ID and Password

Telework with SOHO – User ID and password on laptop with RSA Token over VPN

The individual has a responsibility to ensure that they have a PIV card that is functional and return to using the PIV card as the primary mode of authentication within no longer than 4 weeks of initiating the backup mode process.

Following are backup modes of authentication scenarios.

If a user is working on campus (Headquarters or Regional Office) and a PIV card is:

Lost, Damaged, Stolen, or Compromised o Already on-campus. Replacement card is issued the same day if damaged, within 5 business days if lost. Person will use approved backup mode of authentication until card is replaced.

Forgotten o Already on-campus. A temporary badge is issued the same day for physical access. Until the card is found or a replacement card issued, person will use approved backup mode of authentication until card is replaced.

Expired o Already on-campus. A replacement card is issued the same day. Person will use approved backup mode of authentication if there are delays in the card replacement process.

Locked o Already on-campus. Visit the USPTO Security Services Center / Supervisor for a PIN reset the same day.

If a user is teleworking and has no SOHO router (Headquarters or Regional Office) and a PIV card is:

o User must return to campus (Headquarters or assigned Regional Office) for a replacement card.

o Replacement card is issued the same day if damaged, within 5 business days if lost.

o Person will use approved backup mode of authentication until card is replaced once the employee has come to the nearest campus to get authentication policy reset.

Forgotten o If teleworking, the employee must retrieve their card from the office (Headquarters or assigned Regional Office). There is no backup mode of backup mode of authentication without a SOHO router.

o If on campus and they forgot the badge at home, a temporary badge is issued for physical access and exception process is followed (logical access using user name and password).

Expired o Must return to the office (Headquarters or assigned Regional Office) for a replacement card.

o Replacement card is issued the same day.

o Person will use approved backup mode of authentication if there are delays in the card replacement process.

Locked o Must return to the office (Headquarters or assigned Regional Office) and visit the USPTO

Security Services Center / Supervisor for a PIN reset the same day.

If a user is teleworking and has SOHO router and a PIV card is:

o Employee should call the OCIO Service Desk. Remote access from laptop will allow for employee to use the approved backup mode of authentication.

o PIV Card must be replaced within 4 weeks.

Forgotten o Employee should call the OCIO Service Desk. Remote access from laptop will allow for employee to use the approved backup mode of authentication.

o PIV Card must be replaced as soon as possible

Expired o Employee should call the OCIO Service Desk. Remote access from laptop will allow for employee to use the approved backup mode of authentication.

o PIV Card must be replaced within 4 weeks.

Locked o If user has Finger Printer Verifier (FPV), they can reset their PIN at home.

o If user does not have an FPV, user will need to return to the office (Headquarters or assigned Regional Office) and visit the USPTO Security Services Center / Supervisor for a

PIN reset.

o In the interim, employee should call the OCIO Service Desk for permission to use the approved backup mode of authentication.

Frequently Asked Questions (FAQs) and detailed instructions regarding lost, stolen, or damaged PIV cards are available on the USPTO Intranet.2

C. New Employee & Critical Appointee Exemption

New Employees and Critical Appointees are temporarily exempt from the requirement of PIV card authentication as their normal mode of authentication for network access as there may not be enough time for immediate issuing of PIV cards prior to on-boarding. This exemption is valid for the first 180 days of employment, though this may be extended for some employees due to clearance processing issues.

Once a New Employee or Critical Appointee has received their PIV card, they should follow the appropriate backup mode of authentication policy described above in Section V. B.

D. Mission Impact

The USPTO is required to implement PIV card authentication to comply with Federal directives under Homeland Security Presidential Directive (HSPD- 12). HSPD-12 compliance enhances the agency’s security posture; however, PIV card requirements should not present any undue burdens or prevent USPTO employees and contractors from supporting and achieving the agency’s mission.

Backup modes of authentication are permitted as outlined in this policy to ensure that USPTO employees and contractors are able to continue work when the normal mode of authentication is unavailable.

2 http://ptoweb.uspto.gov/ptointranet/ptosecurity/hspd/hspd_faqs.htm http://ptoweb.uspto.gov/ptointranet/ptosecurity/hspd/hspd_faqs.htm

VI. RESPONSIBILITIES

Adherence to this policy is the responsibility of all eligible USPTO employees and contractors using or operating USPTO information systems, as well as the employees of contractor systems owned and operated on behalf of the USPTO.

The USPTO Senior Information Security Officer (SISO) will ensure that PIV card authentication requirements are communicated to eligible users via annual Security Awareness Training and/or agency-wide notifications on an as-needed basis. The USPTO SISO will monitor and report compliance with this policy on an ongoing basis.

VII. EFFECT ON OTHER POLICIES

Exceptions to this policy shall be determined on a case-by-case basis using the process defined in the

IT Policy on Security Risk Acceptance.

OFFICE OF PRIMARY INTEREST: Office of Organizational Policy and Governance

File details come from the government source that posted it. Updated .