15 Tactical Improvements to IT Security Virtual Keyboard, Two Factor Authentication, Active Confirmation and FAA Access to CPS Online Ganesh Reddy.

Slides:



Advertisements
Similar presentations
MFA for Business Banking – Security Questions with 2nd Request Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing.
Advertisements

MFA for Business Banking – Security Code Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing these QT sheets.
MFA for Business Banking – Security Questions with Reset Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing.
Digital Certificate Installation & User Guide For Class-2 Certificates.
Installation & User Guide
Digital Certificate Installation & User Guide For Class-2 Certificates.
Session #56 Two-Factor Authentication Steven Burke & James McMahon U.S. Department of Education.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
Security Security comes in three forms. 1.Encryption – making data and information transmitted by one person unintelligible to anyone other than the intended.
Department of Labor HSPD-12
Education Professional Standards Board Password Recovery Process.
Online Login Security Enhancement Creating an online username & password January, 2015.
Online Banking Fraud Prevention Recommendations and Best Practices This document provides you with fraud prevention best practices that every employee.
Two Factor Authentication Protocol and the Protection of PII Steven A. Burke U.S. Department of Education 1.
Federal Student Aid Technical Architecture Initiatives James McMahon Ganesh Reddy U.S. Department of Education Session T-03.
Lesson 11-Virtual Private Networks. Overview Define Virtual Private Networks (VPNs). Deploy User VPNs. Deploy Site VPNs. Understand standard VPN techniques.
Penn State University College Of Education Understanding College of Education Resources.
Alternative Input Devices. Digital Camcorder View recordings on a regular TV or copy them to VHS tape Send MPEG video clips by way of to a mobile.
Access and Identity Management System (AIMS) Federal Student Aid PESC Fall 2009 Data Summit October 20, 2009 Balu Balasubramanyam.
Federal Student Aid Identification username and password – this is how students and parents will sign the FAFSA application. The FSA ID process replaced.
Session Session 26 SAIG (Title IV WAN) Connectivity.
© NeoAccel, Inc. TWO FACTOR AUTHENTICATION Corporate Presentation.
Proprietary and Confidential rev. 3/2012 Topic Module Overview 1 Consumer Experience2 Administrator Set-Up3 System Maintenance4 User Maintenance 5 Reports6.
BUSINESS B1 Information Security.
Signing On for FSA Systems Tokens/Two-Factor Authentication and Modifications to User Sign-on in 2013 Bridget-Anne Hampden U.S. Department of Education.
Session #23 Hands On NSLDS for Beginners Valerie Sherrer & Andrea Wise.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Identity on Force.com & Benefits of SSO Nick Simha.
Module 3: Administrator Set-Up Intuit Financial Services University Internet Banking Certification Training.
G061 - Network Security. Learning Objective: explain methods for combating ICT crime and protecting ICT systems.
Session #44 First Time Student Aid Internet Gateway (SAIG) Users Reza Venegas Charlie Henkle Sue Rager.
Federal Student Aid Technical Architecture Initiatives James McMahon Ganesh Reddy U.S. Department of Education Session T-03.
One Platform, One Solution: eToken TMS 5.1 Customer Presentation November 2009.
Module 2: Consumer Experience Intuit Financial Services University Internet Banking Certification Training.
Setting up/Managing Bank Personnel Intuit Financial Services University Business Financial Solutions Certification.
Multifactor Identification for Internet Banking Citizens State Bank Monticello, Iowa
Keystroke Authentication It’s All in How You Type John C. Checco BiometriTech 2003 bioChec™
Bridget-Anne Hampden | Nov U.S. Department of Education 2012 Fall Conference Enterprise Identity Management – Leveraging Participation Management.
1 Using FAA Access to CPS Online to Request ISIRs from the New ISIR Datamart Ginger Klock Matt Kain Session 22.
Amber Johnson U.S. Department of Education WVASFAA Fall 2015 Conference October 29, 2015 FSA ID: The FSA PIN Replacement.
NSLDS on the Web Jim Yoder & Andrea Wise Session 3.
Session 28 FAA Access to CPS Online for New Users Misty Parkinson Ginger Klock.
1 Data Access Control, Password Policy and Authentication Methods for Online Bank Md. Mahbubur Rahman Alam B. Sc. (Statistics) Dhaka University M. Sc.
Page 1 of 42 To the ETS – Create Client Account & Maintenance Online Training Course Individual accounts (called a Client Account) are subsets of the Site.
Page 1 of 17 To the ETS – Password Reset Online Training Course Clients have the ability to automatically update passwords at any time through the automated.
ASSIGNMENT 2 Salim Malakouti. Ticketing Website  User submits tickets  Admins answer tickets or take appropriate actions.
CSCE 201 Identification and Authentication Fall 2015.
My topic is…………. - It is the fundamental building block and the primary lines of defense in computer security. - It is a basic for access control and.
VPN. CONFIDENTIAL Agenda Introduction Types of VPN What are VPN Tokens Types of VPN Tokens RSA How tokens Work How does a user login to VPN using VPN.
Policies and Security for Internet Access
© 2015 Eaton. All Rights Reserved.. Supplier Registration and Access.
Session 3 -2 Session 3 FAA Access to CPS Online – Designed for Efficiency.
Business Objects XIr2 Windows NT Authentication Single Sign-on 18 August 2006.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
ASHRAY PATEL Protection Mechanisms. Roadmap Access Control Four access control processes Managing access control Firewalls Scanning and Analysis tools.
American Diploma Project Administrative Site Training.
American Diploma Project Administrative Site Training.
1 FAA Access to CPS Online Hands-on Nina Colon Eric Smith Session 5.
STARR Companies: HR Portal New User Registration Guide
How Can NRCS Clients Use the Conservation Client Gateway
Session
Customer Log-In One-Stop Service Tracking (OSST) System
Chapter One: Mastering the Basics of Security
Authentication.
How To Create Cox New Account?
To the ETS – Password Reset Online Training Course
First-time Login to Business Banking:
How to Create and Start a Test Session
To the ETS – Password Reset Online Training Course
Presentation transcript:

15 Tactical Improvements to IT Security Virtual Keyboard, Two Factor Authentication, Active Confirmation and FAA Access to CPS Online Ganesh Reddy

16 Tactical Improvements to IT Security Quick fixes and high impact improvements that can be implemented in a short timeframe to enhance the IT security  Virtual Keyboard Implement technologies appropriate for Federal Student Aid that evade potential "key logging"  Two-Factor Authentication (T-FA) Implement Two-Factor Authentication solution for privileged users to access National Student Loan Data System (NSLDS) from internet  Active Confirmation Assess current state of access controls for partners and deploy an “active confirmation” process  FAA Access to CPS Online Login Enhance current state of access to limit use of Personal Identifying Information (PII)

17 Virtual Keyboard

18 Keylogging – Virtual Keyboard Keylogging (Keystroke logging) is a method of capturing and recording user keystrokes. Some of the common technologies used to evade keylogging include:  Anti-spyware  Monitoring what programs are running  Firewall  Network Monitors  Automatic form filler programs  Alternative keyboard layouts  One-time passwords  Smartcards  Virtual keyboards Virtual keyboards are provided on the application login page and do not require end users acquire additional software

19 Keylogging – Virtual Keyboard

20 Keylogging – Virtual Keyboard

21 Virtual Keyboard at Federal Student Aid

22 Federal Student Aid Virtual Keyboard Features Virtual keyboards are provided on the Security Architecture (SA) login page and do not require end users acquire additional software. Some of the features of Federal Student Aid Virtual Keyboard include:  Highly effective in evading “Key Logging”  Widely used by many financial institutions  Least expensive technology to deploy (even for 50 million users)  Does not require any new hardware or software on client machines  Does not require any changes to the applications  Available to all applications that use SA  Works in conjunction with the existing keyboard  Usage is optional but can be made mandatory based on security policy  Keys can entered by mouse click or by leaving mouse on the key for 2 seconds  Virtual keyboard randomly shifts on the screen  Supports multiple keyboard layouts (US and Dvork)

23 Two-Factor Authentication

24 T-FA Implementation Objectives Federal Student Aid is implementing Two- Factor Authentication (T-FA) for privileged users to access Federal Student Aid systems from the internet to enhance the security of its information systems

25 What is Two-Factor Authentication? Two-Factor Authentication (T-FA) uses two pieces of information and processes (two different methods) to authenticate a person's identity for security purposes. Authentication factors are generally classified into three categories:  Something the user has ID card, security token, software token, phone, or cell phone  Something the user knows password, pass phrase, or personal identification number  Something the user is fingerprint or retinal pattern, voice recognition, or another biometric identifier Two-Factor Authentication requires the use of solutions from two of the three categories of factors.

26 T-FA Technologies Some of the common technologies used as the second factor authentication in concert with User ID and Password include:  Hardware Tokens - generate a constantly changing one-time password to enable authentication.  Software Tokens on PCs - enable authentication with computer as second factor authenticator.  Software Tokens on Mobile Devices - allow authentication from smart phones and PDAs.  Smart Cards - enable authentication as well as of physical access.  USB Tokens - enable authentication without the need to key in a token code (can be plugged into a standard USB port).  Biometric Devices - enable authentication according to the physical characteristics of a user (fingerprint and retina scans).

27 Federal Student Aid T-FA Features Two-Factor Authentication solution features:  Reliable, scalable, available, and meets sub-second performance standards  Compatible and interoperable with Federal Student Aid Standards  Integrates seamlessly with existing Federal Student Aid architectures  Supports web applications and does not require client-side software  Compliant with NIST, FIPS and other federal T-FA standards  Has ongoing operations and maintenance product support  Based on mature technology with a broad installed market base

28 Active Confirmation

29 What is Active Confirmation?  Active confirmation is the process of a Designated Point Administrator (DPA) reviewing users' access privileges on a establish time schedule and confirming these users' privileges. This will help ensure an updated and secure environment for system accessibility.  The Federal Student Aid DPAs will be required to review their list of users who access Federal Student Aid systems and confirm that each individual continues to be a valid user. This will be done on a periodic basis.

30 “Active Confirmation” Process The DPA Roster  Placed in all “Primary” TG Number mailboxes  Provided a list of employees that currently possess TG numbers  Requires validation or deletion of TG Numbers assigned to your organization in the SAIG Enrollment Web site The FAA Roster  Placed in mailboxes of Primary TG Numbers of organizations  Provided a list of employees at your organization who are currently enrolled for access to FAA Access to CPS Online services  Requires validation or deletion of FAA Users assigned to your organization in the SAIG Enrollment Web site

31 FAA Access to CPS Online

32 FAA Access to CPS Online Login Enhance current state of access to limit use of Personal Identifying Information (PII)  New FAA Access to CPS Online Login  First Time Registration  Self Service Password Reset  Implementation Schedule

33 Current FSA Web Enroll Site Login Currently: Enter SSN and DOB on the login page to access the Student Aid Internet WebEnroll Site

34 Current FAA Access to CPS Online Login Currently: Enter SSN, first 2 letters of last name, DOB, and PIN on the FAA Access to CPS Online login page to access the application

35 New FAA Access to CPS Online Login FAA Access to CPS Online Registration link can be accessed from the FAA Access Login page

36 FSA SA Registration – Confirm Identity Confirm your identity by entering the FSA provided Unique Identifier

37 Confirm or update your current address Your name retrieved from SAIG Participation Management System cannot be updated SA Registration - Address

38 SA Registration - Select a Password Select a password and choose any three Challenge Response Questions and provide answers These questions will be used to reset your password

39 SA Registration – Confirm Role Confirm the Role retrieved from SAIG Participation Management enrollment system

40 SA Registration - Confirmation Confirm the registration information

41 SA Registration - Acknowledgement System confirms successful Registration You will receive your User ID in the

42 Forgot Password If you forget your password, the “Forgot Password” link can be used to reset your password. This link is located on the Login Page.

43 Forgot Password Provide your User ID to retrieve your challenge questions

44 Answer Challenge Question You will be prompted to answer one of the Challenge Response Questions to confirm your identity

45 Enter New Password Provide a new password - this will replace your old password

46 New Password Confirmation Your password has been changed

47 FAA Access to CPS Online Login Enter User ID and password on the FAA Access to CPS Online Login page to access the application fafsa.ed.gov/FOTWWebApp/faa/faa.jsp

48 Password Policies  Password Policy Expires every 90 days Complex alpha-numeric passwords Answer challenge questions to reset password  Password Lockout 3 unsuccessful login attempts Can still use “Forgot Password” application Login disabled for 30 minutes

49 Questions?

50 We appreciate your feedback and comments. We can be reached at: Contact Information