Attachment III - DOL Identity and Access Management Requirements.pdf

PDF 204 KB Posted

Attached to
E-Discovery, Litigation Support, and Hosted Evidence Management Solutions "EMI - III" Federal contract opportunity
Solicitation number
1605C1-21-R-00004
Issued by
Not on record

View the file

Other files for this federal contract opportunity

Other files attached to E-Discovery, Litigation Support, and Hosted Evidence Management Solutions "EMI - III", newest first.
File Type Posted
EMI III_RFP_1605C1-21-R-00004_AMEND 1.pdf PDF
Attachment I Past Performance Questionnaire.docx DOCX document
Attachment IV - Wage Determinations.pdf PDF
Attachment II Question and Answer Spreadsheet.xlsx XLSX spreadsheet
EMI III_RFP_1605C1-21-R-00004_FINAL.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT III - DOL IDENTITY AND ACCESS MANAGEMENT

REQUIREMENTS

The DOL has implemented and continually improves its Enterprise Identity and Access Management (IAM) solution to provide authoritative identity and security entitlement management services as a common service across employee, customer, and business partner communities of interest. For internal communities of interest, this solution will fully support DOL HSPD-12 program goals by providing common service capabilities that will enhance identification and security management for the authorized users of its IT system and physical facilities. Security entitlement services are realized through automated provisioning and de-provisioning of security entitlements that are based upon Public Key Infrastructure (PKI) credentials (i.e., X.509v3 certificates) resident within the standards based Personal Identity Verification (PIV) credential.

For external communities of interest, this solution will require at least the security services of identification and authentication. Identification and authentication services are supported through federated identity management services (e.g., SAML), and through preferred approaches for authorization security services that are more integrated to the IAM Services. Identification, Authentication, and Authorization security services shall be supported through the use of standards based protocols and approaches (e.g., XACML, OASIS WS-* (i.e., WS-Federation, WS-Trust, WS-Provisioning, and WS-Security)).

DOL has implemented Personal Identity Verification credentials. Integration to these Enterprise IAM services is a mandatory requirement for DOL applications, as they will be expected to leverage the services of this enterprise solution as part of their identity and security management functions. DOL is diligently working to achieve the highest possible security posture to protect government environments and data, and as such the highest security option will be the preferred option. Therefore, Contractor shall describe and provide the following functionality in support of this initiative:

Authentication High Assurance Security Services o Option 1 (Multi-factor Security) – The application or service provider must describe its capability to leverage federal investments in standards based PIV Credentials as a secure and mobile authentication mechanism. Specifically, the application or service provider must describe the application processes associated with validating a user to the PIV smart card device to expose X.509v3 PKI identification and authentication services or to expose biometric authentication services, and must describe how it utilizes these services over secure channels to support the user identification and authentication process;

o Option 2 (Federated Security) – The application or service provider must support web services for the security services of identification and authentication via standards based approaches (e.g., SAML, eAuthentication Credential Service Providers (CSP), XML for eXtensible Access Control Markup Language (XACML), or other standards-based federation mechanisms) when working over networks external to the DOL network. Where federated identity management approaches are supported:

The application or service provider must support user account, user name, or user identifier correlation services provided by the DOL IAM solution where any user repository local to the application that is required and maintained for back-end authentication purposes to ensure full synchronization of user identity and identity security attributes.

The application or service provider must support password standards established by DOL policies and procedures if a local user repository is maintained for back-end authentication purposes.

The application or service provider must support password synchronization over a secured channel if a local repository is maintained for back-end authentication purposes.

Moderate Assurance Security Services o Option 1 or Option 2 above

Basic Assurance Security Services o Option 1 or Option 2 above; OR o Option 3 The application or service provider must demonstrate application flexibility to securely provide data to existing LDAP (or LDAP-compliant) user repositories hosted by DOL using the LDAPS protocol; and the application or service provider must demonstrate application flexibility to utilize data from existing LDAP (or LDAP-compliant) user repositories hosted by DOL in support of application or service provider application identification and authentication security services;

Provisioning The application or service provider must demonstrate the capability for an external client to provision user accounts and roles within the application through a standards based interface.

Reconciliation Account reconciliation involves the comparison of DOL’s understanding of accounts known to be provisioned to application or service provider and the accounts actually present on the application or service. In order to perform account reconciliation, the application or service provider shall demonstrate an interface that allows for bulk extraction of user account information.

In addition, the application or service provider must support the following requirements:

• The application or service provider must support appropriate transport security services by demonstrating support for mutually authenticated SSLv3.0 or TLSv1.0 authentication approaches—or other common industry standard—when exchanging data over networks;

• The application or service provider must be capable of utilizing a DOL determined unique identifiers (UID) (e.g., Microsoft Active Directory UserPrincipalName (UPN) values, DOL Employee ID, etc.) as the basis for authoritatively determining the identity of the user.

• The application or service provider must describe whether the application is required to make its own internal authorization decisions, independent of a third party system for access to internal application or service provider system functionality, or if the capability exists within the application security model to utilize the preferred authorization services from a standards based IAM COTS solution.

ATTACHMENT - DOL IDENTITY AND ACCESS MANAGEMENT REQUIREMENTS

File details come from the government source that posted it. Updated .