Attachment 01b - OCIO Personal Identity Verification (PIV) Card Authentication Policy OCIO-POL-49.pdf
PDF 502 KB Posted
- Attached to
- Patent Data and Document Management (PDDM) Federal contract opportunity
- Solicitation number
- 1333BJ20R00151004
About this file
This policy document establishes guidelines for the use of Personal Identity Verification cards for authentication on United States Patent and Trademark Office information systems. It requires that eligible employees and contractors use PIV cards as the normal mode of authentication. It defines eligible individuals and provides exemptions for certain user categories. The policy outlines acceptable backup authentication methods that can be used if the PIV card is unavailable. It also addresses PIV card loss, damage, or expiration scenarios for on-campus and telework access. Responsibilities are defined for complying with and monitoring adherence to the policy to ensure compliance with federal directives while not hindering the agency's mission.
The federal contract opportunity is a solicitation from the United States Patent and Trademark Office seeking contractor support to manage the entire life cycle of patent application processing. The support includes initial application filing, processing, and final disposition. Interested offerors must thoroughly review the solicitation and statement of work attachments to understand the requirements, as the attachments have been updated since the presolicitation notice. The solicitation number is 1333BJ20R00151004 and it is for the Patent Data and Document Management requirement. The contracting agency is the Department of Commerce United States Patent and Trademark Office.
View the file
Other files for this federal contract opportunity
Show all 50
Patent Data and Document Management (PDDM) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OFFICE OF THE CHIEF INFORMATION OFFICER
Personal Identity Verification (PIV) Card Authentication Policy Version 3.4
PERSONAL IDENTITY VERIFICATION (PIV) CARD AUTHENTICATION POLICY
OCIO-POL-49
Effective Date: June 30, 2015
Version: 3.4
Last Revision Review Date: April 19, 2018
Reason for Revision: Updated section II, PIV card usage requirements, and replaced Exemption
Enforcement Scenarios tables
TABLE OF CONTENTS
Section
I. Purpose
II. Authority
III. Scope
IV. Definitions
V. Policy
VI. Responsibilities
VII. Effect on Other Policies
I. PURPOSE
This policy provides guidelines for the use of Personal Identity Verification (PIV) card authentication on United States Patent and Trademark Office (USPTO) information systems.
II. AUTHORITY
This policy is issued in accordance with:
Federal Information Security Management Act of 2002 (FISMA)
Federal Information Security Modernization Act of 2014 (FISMA)
Homeland Security Presidential Directive 12 (HSPD-12)
Office of Management and Budget (OMB) Memorandum M-11-11
Federal Information Processing Standard 201-1 (FIPS 201-2)
Cross-Agency Priority Goals for Cybersecurity1
NIST SP 800-63 rev 3, Digital Identity Guidelines
NIST SP 800-157, Guidelines for Derived Personal Identity Verification (PIV) Credentials
1 https://www.performance.gov/node/3401
III. SCOPE
The provisions of this policy apply to all USPTO employees and contractors accessing, using, or operating USPTO workstations, servers, or information systems and to contractors providing telecommunications and information system services to USPTO.
This policy also applies to information systems owned and operated by contractors, contractor employees, USPTO guest researchers, collaborators, and other Federal agencies that carry out the
USPTO mission, whether or not they are located on Government property. Information systems intended to provide unrestricted access (e.g. public web pages and kiosks) are excluded.
Excluded Categories
In accordance with OMB’s provisions for an “agency-risk based decision” regarding the applicability of HSPD-12 to agency specific categories of individuals, the following defined categories of users are not required to use PIV cards for network access:
USPTO employees and contractors who have not been issued PIV cards: USPTO implements a phased approach to PIV card issuance. As a result, some eligible USPTO personnel (as defined above) may not possess PIV cards due to the status of the agency’s PIV card issuance process and should use an authorized backup mode of authentication.
USPTO employees and contractors working remotely using personally owned equipment who have not been issued PIV cards: Employees and contractors using personally owned equipment to access the USPTO network remotely must use PIV cards or approved multi-factor authentication (ex: RSA Token and PTONet credentials) if PIV cards has not been issued.
USPTO employees and contractors with intermittent access to USPTO facilities or systems:
Intermittent access is defined as non-routine access to federally controlled facilities or information systems equaling less than 30 days per calendar year. Users in this category should use a backup mode of authentication.
Temporary USPTO employees, contractors, interns, externs, and students: Employees, contractors, interns, externs, students, and other users assigned to perform work at USPTO facilities on USPTO information systems on a temporary basis may use authorized backup modes of authentication for network access. Temporary status applies to users with an expected service period of fewer than 179 days.
Contractors that only access contractor-owned/managed systems: USPTO enters into contracts with various third-parties to provide services to the agency using externally hosted, contractor managed systems. Users of these systems who do not require access to
USPTO-controlled facilities or systems are not required to employ or utilize PIV card authentication. However, these contractors must still meet security guidelines and criteria for processing, storing, and transferring data to the government in accordance with contractual and
FISMA requirements including use of multifactor authentication.
Anyone otherwise covered by this policy with a physical limitation that makes use of a PIV card for Authentication impossible or impractical.
Any employee using a mobile device approved by the Chief Information Officer: Some employees have mobile devices that are approved by the Chief Information Officer that connect with the PTONet. Employees using mobile devices to access USPTO information and communications systems must conform to OCIO-POL-34, Mobile Device Management Policy.
Any additional exceptions from PIV usage requirement must be approved by the USPTO OCIO.
IV. DEFINITIONS
Backup Mode of Authentication – An approved alternative means for logical access to the network. It is typically used when the normal mode is not possible or when a remote user logs in using personally owned equipment. Examples of backup modes of authentication include
Username/Password and RSA token authentication.
Critical Appointee – An employee of USPTO in a Senior Executive Service position serving under a
Career, Non-career, Limited Term, or Limited Emergency appointment.
Mobile Devices - A mobile device is defined to include smartphones, tablet computers, personal digital assistants (PDAs), and any other portable electronic device that can be used to access Federal government information or communications systems. Laptop computers are excluded from this definition for the purposes of this policy.
Off-Campus Access – Access to USPTO owned or managed information systems from a non-
USPTO facility, including private residences and contractor-owned sites.
On-Campus Access – Access to USPTO owned or managed information systems from a USPTO-controlled facility, including satellite offices.
Normal Mode of Authentication – The default mechanism by which a person gains logical access to the network. For the purposes of this policy, the normal mode of authentication for access to
USPTO information systems is PIV-based authentication.
Person – Any USPTO employee, staff member, contractor, associate, or guest researcher who is required to use a PIV card for logical access.
PIV-based Login – The use of a PIV card or derived credential for logical access.
PIV Card – A FIPS-201 compliant physical artifact (e.g. PIV II smart card) that contains stored credentials so that the claimed identity of the cardholder can be verified against the stored credentials by another person or an automated process.
Privileged Access – Access by a privileged network user who, by virtue of function, has been allocated a network user account with elevated privileges. Such persons will include, for example, the system administrator(s) and network administrator(s) who are responsible for keeping the system available and may need privileges to create new users profiles as well as to add or amend the privileges and access rights of existing users.
Remote Access – The ability for an organization’s users to access its non-public computing resources from locations external to the organization’s facilities.
SOHO – Small Office – Home Office router issued by USPTO to telework employees.
Unprivileged Access – Any access that is not privileged access (see above).
V. POLICY
A. Use of PIV Cards
In order to comply with Federal directives, PIV cards must be used as the normal mode of authentication for all eligible USPTO personnel on PIV-enabled systems. USPTO personnel are eligible for a PIV card if they:
Are a USPTO employee or contractor and are not in one of the excluded categories cited in Section III (“Scope”) of this policy;
Have a Social Security Number;
Have an expected length of federal service or agreement term greater than 179 days within a calendar year;
Require access to federally-controlled information systems; and
Are not a member of a defined workforce category outlined above.
Utilization of normal modes of authentication for privileged access to USPTO information systems is critical for securing sensitive USPTO information and accounts. While the PIV requirements outlined in this policy apply to both privileged and non-privileged access, USPTO employees and contractors must make every attempt to reduce or eliminate the use of backup modes of authentication when utilizing privileged access. If Privileged users are not using their PIV card to log in to the network prior to performing privileged functions on USPTO systems, system and user accounts, and networks, they are not in compliance with the USPTO policy and their actions are subject to review, investigation, and account revocation. Non-privileged users must use their PIV card for an initial access to the PTO network.
B. Backup Modes of Authentication
Eligible USPTO personnel (defined above) must use PIV card authentication as their normal mode of authentication for network access. In the event that an eligible user’s PIV card is lost, forgotten, damaged, stolen, or otherwise unusable, a backup mode of authentication may be authorized temporarily.
The criteria for activating an approved backup mode of authentication are based on the type of PIV card issue encountered and the user’s work categorization. In order to activate the backup mode of authentication, users must first notify their supervisor and/or telework coordinator and the OCIO Service
Desk. User should also contact the USPTO Security Services so that the PIV card can be suspended, revoked, and/or re-issued. Impacted individuals should then follow the USPTO “Logical Access
Procedure” and contact the OCIO Service Desk to activate temporary logical access.
The backup modes of authentication are as follows:
On Campus (Headquarters or Regional Office) – User ID and Password
Telework with SOHO – User ID and password on laptop with RSA Token over VPN
The individual has a responsibility to ensure that they have a PIV card that is functional and return to using the PIV card as the primary mode of authentication within no longer than 4 weeks of initiating the backup mode process.
Following are backup modes of authentication scenarios.
If a user is working on campus (Headquarters or Regional Office) and a PIV card is:
Lost, Damaged, Stolen, or Compromised o Already on-campus. Replacement card is issued the same day if damaged, within 5 business days if lost. Person will use approved backup mode of authentication until card is replaced.
Forgotten o Already on-campus. A temporary badge is issued the same day for physical access. Until the card is found or a replacement card issued, person will use approved backup mode of authentication until card is replaced.
Expired o Already on-campus. A replacement card is issued the same day. Person will use approved backup mode of authentication if there are delays in the card replacement process.
Locked o Already on-campus. Visit the USPTO Security Services Center / Supervisor for a PIN reset the same day.
If a user is teleworking and has no SOHO router (Headquarters or Regional Office) and a PIV card is:
o User must return to campus (Headquarters or assigned Regional Office) for a replacement card.
o Replacement card is issued the same day if damaged, within 5 business days if lost.
o Person will use approved backup mode of authentication until card is replaced once the employee has come to the nearest campus to get authentication policy reset.
Forgotten o If teleworking, the employee must retrieve their card from the office (Headquarters or assigned Regional Office). There is no backup mode of backup mode of authentication without a SOHO router.
o If on campus and they forgot the badge at home, a temporary badge is issued for physical access and exception process is followed (logical access using user name and password).
Expired o Must return to the office (Headquarters or assigned Regional Office) for a replacement card.
o Replacement card is issued the same day.
o Person will use approved backup mode of authentication if there are delays in the card replacement process.
Locked o Must return to the office (Headquarters or assigned Regional Office) and visit the USPTO
Security Services Center / Supervisor for a PIN reset the same day.
If a user is teleworking and has SOHO router and a PIV card is:
o Employee should call the OCIO Service Desk. Remote access from laptop will allow for employee to use the approved backup mode of authentication.
o PIV Card must be replaced within 4 weeks.
Forgotten o Employee should call the OCIO Service Desk. Remote access from laptop will allow for employee to use the approved backup mode of authentication.
o PIV Card must be replaced as soon as possible
Expired o Employee should call the OCIO Service Desk. Remote access from laptop will allow for employee to use the approved backup mode of authentication.
o PIV Card must be replaced within 4 weeks.
Locked o If user has Finger Printer Verifier (FPV), they can reset their PIN at home.
o If user does not have an FPV, user will need to return to the office (Headquarters or assigned Regional Office) and visit the USPTO Security Services Center / Supervisor for a
PIN reset.
o In the interim, employee should call the OCIO Service Desk for permission to use the approved backup mode of authentication.
Frequently Asked Questions (FAQs) and detailed instructions regarding lost, stolen, or damaged PIV cards are available on the USPTO Intranet.2
C. New Employee & Critical Appointee Exemption
New Employees and Critical Appointees are temporarily exempt from the requirement of PIV card authentication as their normal mode of authentication for network access as there may not be enough time for immediate issuing of PIV cards prior to on-boarding. This exemption is valid for the first 180 days of employment, though this may be extended for some employees due to clearance processing issues.
Once a New Employee or Critical Appointee has received their PIV card, they should follow the appropriate backup mode of authentication policy described above in Section V. B.
D. Mission Impact
The USPTO is required to implement PIV card authentication to comply with Federal directives under Homeland Security Presidential Directive (HSPD- 12). HSPD-12 compliance enhances the agency’s security posture; however, PIV card requirements should not present any undue burdens or prevent USPTO employees and contractors from supporting and achieving the agency’s mission.
Backup modes of authentication are permitted as outlined in this policy to ensure that USPTO employees and contractors are able to continue work when the normal mode of authentication is unavailable.
2 http://ptoweb.uspto.gov/ptointranet/ptosecurity/hspd/hspd_faqs.htm http://ptoweb.uspto.gov/ptointranet/ptosecurity/hspd/hspd_faqs.htm
VI. RESPONSIBILITIES
Adherence to this policy is the responsibility of all eligible USPTO employees and contractors using or operating USPTO information systems, as well as the employees of contractor systems owned and operated on behalf of the USPTO.
The USPTO Senior Information Security Officer (SISO) will ensure that PIV card authentication requirements are communicated to eligible users via annual Security Awareness Training and/or agency-wide notifications on an as-needed basis. The USPTO SISO will monitor and report compliance with this policy on an ongoing basis.
VII. EFFECT ON OTHER POLICIES
Exceptions to this policy shall be determined on a case-by-case basis using the process defined in the
IT Policy on Security Risk Acceptance.
OFFICE OF PRIMARY INTEREST: Office of Organizational Policy and Governance
File details come from the government source that posted it. Updated .