Information Resources and Communications University of California, Office of the President Information Technology Services The California State University.

Slides:



Advertisements
Similar presentations
Program Management Office (PMO) Design
Advertisements

Copyright Kathy J. Lang and Ed Mahon, This work is the intellectual property of the authors. Permission is granted for this material to be shared.
Office of Information Technology Affiliates/Guests – Who are these people and how do we give them services? Copyright, Barbara Hope, University of Maryland,
1 The Challenges of Creating an Identity Management Infrastructure for the University of California David Walker Karl Heins Office of the President University.
Copyright Tom Parker, Ron DiNapoli, Andrea Beesing, Joy Veronneau This work is the intellectual property of the authors. Permission is granted for.
Public Key Infrastructure (PKI) Hosting Services.
On Beyond Z Building a Directory Service educause presentation #074 University of Colorado at Boulder Deborah Keyek-Franssen Marin Stanek Paula J. Vaughan.
E-Biz Forum 2002 E-Business Forum May 16, 2002 Steve Relyea Vice Chancellor – Business Affairs University of California, San Diego.
Making the Case for Security: An Application of the NIST Security Assessment Framework to GW January 17, 2003 David Swartz Chief Information Officer Guy.
Information Resources and Communications University of California, Office of the President UCTrust David Walker Office of the President University of California.
1 Penn State’s Identity & Access Management Initiative “It’s all about who you know … and what you know about them”
Serving the Research Mission: An Approach to Central IT’s Role Matthew Stock University at Buffalo.
An Identity Management Vision for California Education A. Michael Berman, Cal Poly Pomona Mark Crase, CSU Office of the Chancellor Copyright A. Michael.
Identity Management: Some Basics Mark Crase, California State University Office of the Chancellor CENIC - March 9, 2011.
August 9, 2005 UCCSC IT Security at the University of California A New Initiative Jacqueline Craig. Director of Policy Information Resources and.
SIMI: Secure Identity Management Infrastructure for the CSU A. Michael Berman, Cal Poly Pomona.
Information Resources and Communications University of California, Office of the President Current Identity Management Initiatives at UC & Beyond: UCTrust.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
The Identity Management Collaborative: A SIMI Pilot Project Cal Poly San Luis Obispo California State University Stanislaus The Office of the Chancellor.
July 12, 2005 CSU SIMI Workshop - Melding Policy and Technology to Manage Identity1 Provisioning Services Collaborative CSU, East Bay and CSU, San Bernardino.
Peter Deutsch Director, I&IT Systems July 12, 2005
UWM CIO Office A Collaborative Process for IT Training and Development Copyright UW-Milwaukee, This work is the intellectual property of the author.
Pam Downs Ajay Gupta The Pennsylvania Prince George’s State University Community College "Copyright Penn State University This work is the intellectual.
Copyright Statement © Jason Rhode and Carol Scheidenhelm This work is the intellectual property of the authors. Permission is granted for this material.
Moving Out of The Shadows: Shining a Light on Data David Rotman Director of Computer Services Mark Mazelin Web Development Coordinator Copyright David.
Risk Assessment 101 Kelley Bradder VP and CIO Simpson College.
Security Issues on Campus: Government Initiatives Rodney J. Petersen University of Maryland Educause/Internet2 Security Task Force Copyright Rodney J.
The Business of Identity Management Barry R. Ribbeck Director Systems Architecture & Infrastructure Rice University
So You Want to Switch Course Management Systems? We Have! Come Find Out What We’ve Learned. Copyright University of Okahoma This work is the intellectual.
1 Institutions as Allies in the Security Challenge Wayne Donald, Virginia Tech Cathy Hubbs, George Mason University Darlene Quackenbush, James Madison.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
Information Security Governance in Higher Education Policy2004 The EDUCAUSE Policy Conference Gordon Wishon EDUCAUSE/Internet 2 Security Task Force This.
Intellectual Property Protocol and Assessment for Distance Learning Liz Johnson Project Manager Advanced Learning Technologies Board of Regents of the.
CAMP Med Mapping HIPAA to the Middleware Layer Sandra Senti Biological Sciences Division University of Chicago C opyright Sandra Senti,
Information Resources and Communications University of California, Office of the President System-Wide Strategies for Achieving IT Security at the University.
EDUCAUSE April 25, 2006Enforcing Compliance with Security Policies … Enforcing Compliance of Campus Security Policies Through a Secure Identity Management.
Basic Research Administration Principles Presented by Ronald Kiguba Research Coordinator, Makerere Medical School.
Credential Provider Operational Practices Statement CAMP Shibboleth June 29, 2004 David Wasley.
Peer Information Security Policies: A Sampling Summer 2015.
NERCOMP Managing Campus Affiliates Managing Campus Affiliates Faculty? Student? Faculty? Student? Staff? Criss Laidlaw Director of Administrative.
Policy, Trust and Technology Mitigating Risk in the Digital World David L. Wasley Camp 2006 © David L. Wasley, 2006.
Managing Intellectual Property for Distance Learning Liz Johnson Project Manager Advanced Learning Technologies Board of Regents of the University System.
Middleware 101 Dave Tomcheck UC Irvine. Overview Drivers and Assumptions Objectives The Components of the Business Architecture Implications for Stakeholders.
Office of Information Technology Balancing Technology and Privacy – the Directory Conundrum January 2007 Copyright Barbara Hope and Lori Kasamatsu 2007.
Value & Excitement University Technology Services Oakland University Information Technology Strategic Planning Theresa Rowe October 2004 Copyright Theresa.
Roles and Responsibilities
UC Middleware Needs David Walker Information & Educational Technology University of California, Davis
March 21, 2006 NERCOMP 2006 Worcester, Massachusetts 1 Copyright Sunny Donenfeld, This work is the intellectual property of the author. Permission.
1 Information Sharing Environment (ISE) Privacy Guidelines Jane Horvath Chief Privacy and Civil Liberties Officer.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
FEDERATIONS Clair Goldsmith, Ph.D., Associate Vice Chancellor and CIO September 27,
Safeguarding Research Data Policy and Implementation Challenges Miguel Soldi February 24, 2006 THE UNIVERSITY OF TEXAS SYSTEM.
Federations 101 John Krienke Internet2 Fall 2006 Internet2 Member Meeting.
Addressing Unauthorized Release of Personal Information at UC Davis August 12, 2003.
What’s Happening at Internet2 Renee Woodten Frost Associate Director Middleware and Security 8 March 2005.
Welcome to Base CAMP: Enterprise Directory Deployment Ken Klingenstein, Director, Internet2 Middleware Initiative Copyright Ken Klingenstein This.
Federations: The New Infrastructure Speaker Name Here Date Here Speaker Name Here Date Here.
NSF Middleware Initiative and Enterprise Middleware: What Can It Do for My Campus? Renee Woodten Frost Internet2/University of Michigan.
Bringing it All Together: Charting Your Roadmap CAMP: Charting Your Authentication Roadmap February 8, 2007 Paul Caskey Copyright Paul Caskey This.
NMI-EDIT and Rice University Federated Identity Management: Managing Access to Resources in Texas Barry Ribbeck Director System Architecture and Infrastructure.
NSF Middleware Initiative and Enterprise Middleware: What Can It Do for My Campus? Mark Luker, EDUCAUSE Copyright Mark Luker, This work is the intellectual.
UTPA 2012: A STRATEGIC PLAN FOR THE UNIVERSITY OF TEXAS-PAN AMERICAN Approved by President Cárdenas November 21, 2005 Goals reordered January 31, 2006.
IT Governance Purpose: Information technology is a catalyst for productivity, creativity and community that enhances learning opportunities in an environment.
University of Southern California Identity and Access Management (IAM)
Tom Barton, Senior Director for Integration, University of Chicago
California State University CSUconnect Federation
Federated Identity to Support Collaboration in the CIC
Defining an IT Workflow, from Request to Support
University of Southern California Identity and Access Management (IAM)
A Business Case for Identity Management in Higher Education
Presentation transcript:

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Identity Management Issues for Multi-Campus Institutions - University of California - David Walker Jacqueline Craig Office of the President University of California © Copyright Regents of the University of California Permission is granted for this material to be shared for non- commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the authors.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor The University of California ● Ten campuses, three national labs, five medical centers ● Most operational responsibilities on campuses – Payroll, Student Information, etc. – Each campus does its own identity management ● A few services are central – Employee self-service and benefits central – Most licensed library materials – Multi-campus collaborations

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Identity Management at UC ● Separate identity management at each campus ● In general, authentication is per-service ● Campuses are starting to develop common authentication – UCB: Kerberos – UCI: Kerberos – UCLA: Home grown – UCSD: Home grown – All four have home-grown identity management

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor What is the problem? ● How can services of one UC campus be accessed by users of another UC campus? ● Moving toward a new business environment – UC employee self-service and benefits – access to any UC campus library system – Inter-campus access to course management systems – collaboration within the Academic Senate – administrative applications

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Federations ● Federations authenticate locally, share identity information globally – Sharing is controlled by policy – Good fit for UC ● Other Structures – Public Key Infrastructure (PKI) ● We tried it. – Active Directory and LDAP-based structures – UC is not hierarchical; one size doesn’t fit all

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor What are we building? ● Trustworthy exchange of identity attributes ● Trustworthy identity attributes ● Create a trust environment – Services trust campuses to provide correct identity information – Campuses trust services not to misuse information they receive – Participants trust campuses not to reveal information in appropriately and application snot to misuse that information

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor InCommon ● Defines technology for trustworthy exchange of identity attributes. ● Defines common identity attributes ● Emphasis is on broad membership. – Specific agreements (e.g., requirements for identity management) are pairwise.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor UCTrust ● Establishes global requirements to facilitate system-wide agreements. ● Creates trust in identity attributes through policy. – Policy controls the release of information – Technology enforces that policy – Technology ensures secure transit of identity attributes ● Extends InCommon

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor UCTrust ● Pilot project with three campuses – UC San Diego – UC Los Angeles – UC Irvine ● UCOP applications – Your Benefits Online – California Digital Library

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor InCommon Requirements ● InCommon criteria – IdM systems “fall under the purview of organization’s executive management – Appropriate risk management practices for issuing end-user credentials – Must be documented ● UCTrust requires greater assurance in identity management practices for conformance with existing UC policies

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor UCTrust Requirements ● Campuses must provide authoritative and accurate attribute assertions ● Campuses must have practices that meet minimum standards – establishing electronic credentials and – maintaining individual identity information ● Providers receiving individual identity attributes must ensure its protection and respect privacy constraints defined by the campus

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Governance ● UCTrust Task Force – Composed of campus Identity Providers, Service Providers, UCTrust Administration, UCOP – Manages operational policies and procedures – Oversight and conflict resolution provided by UC’s Information Technology Leadership Council, the group of UC’s CIOs.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Administration ● UCTrust Federation Administration – Provides operational coordination, when needed – Maintains documentation repository – Not a major resource drain; technology and end- user support is with the Identity and Service Providers.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Identity Provider Responsibilities ● Identification, registration, and authentication processes – Accuracy and timeliness of identity information; tools to update – Availability of access to enterprise directory, authentication, etc. – Audit logs to enable investigation – Support for end-users, service providers and UCTrust Administration ● Dissemination of policy and best practices

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Service Provider Responsibilities ● Secure operation of services – Awareness of Identity Provider service levels – Audit logs to enable investigations – Compliance with Identity Provider standards and best practices – Support for end-users, identity providers, and UCTrust administration

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Community Member Responsibilities ● Community members are the individuals who have officially established an affiliation with a campus ● Community members are responsible for – assurance that their credentials are not given to others – compliance with Identity Provider standards and best practices

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Current State of UCTrust ● Vetting with various UC constituencies – Campus CIOs – Controllers – Vice Chancellors of Administration – Academic Senate IT Committee ● External review for Your Benefits Online ● We expect official creation by campus CIOs in late May

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Interesting Issues – Risk Analysis Potential Risks – Identification: Is correct identification supplied when individual is hired? – Registration: Can someone else’s credential be provided during registration? Can an unauthorized individual obtain a credential? What about legacy information on individuals? – Authentication: Can exchange of user name and password be intercepted or passwords be guesed? What about unattended sessions?

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Interesting Issues – Recommended Practices ● Multifactor authentication – If asking for multiple pieces of information, only one should be a password; others should be well- known to the end-user. ● Synchronization with repositories of record – Payroll – Student Information System

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Interesting Issues – Liability ● Intra-institutional liability and trust – Not legal liability – UC is legally a single entity ● Who is liable when something goes wrong? – E.g., whose budget is impacted? ● Retirement fund represents a large sum of money, even for only one retiree.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Interesting Issues - Dual Campus Authorities ● Two identity authorities for different, but overlapping, subcommunities ● Resulted in better alignment of campus IT organizations

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Interesting Issues – Log Retention ● Logs are required for forensic purposes – So, keep them as long as practical. ● Logs contain private information. – So, don’t keep them. ● Three to six months seems about right.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Identity Management in the CSU Mark Crase, Sr. Director Technology Infrastructure Services CSU Office of the Chancellor Copyright 2005 Mark Crase. This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Secure Identity Management Infrastructure ● SIMI – A system-wide technology and policy infrastructure that will enable CSU campuses to manage identity information and assure efficient and secure transactions that fully respect individual privacy.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor SIMI Goals ● SIMI will improve the secure integration of information technology services across the CSU, to support and enhance learning and improve administrative efficiency. ● SIMI will create the foundation that will enable secure transactions amongst key educational, business and government partners, while protecting personal privacy.

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor The Identity Management Collaborative: A SIMI Pilot Project ● Collaboration between Cal Poly San Luis Obispo, CSU Stanislaus and the Office of the Chancellor with funding from Internet2/NSF through EDUCAUSE ● Goals: – Provide robust Identity Management services by leveraging talent and other resources at one campus to serve the needs of a second campus – Strengthen the operations at the provider campus – Improve services at the client campus – Provide test-bed to address issues related to the system- wide SIMI Project

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor IdMC: Objectives ● Create an inter-campus service/support model – Develop needs assessment tools to determine programmatic needs and resources required to meet them – Develop service proposal templates – Develop performance metrics – Conduct performance assessments ● Document and disseminate lessons learned within the CSU and out to the greater education community

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor IdMC: Progress-to-date ● Stanislaus Requirements defined – Enterprise directory – Authentication for PeopleSoft Access – Authentication for Blackboard Access ● SOW Completed – Project Description, Deliverables, Timelines and Milestones ● MOUs Completed – Campus-specific roles & responsibilities codified

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor IdMC: Progress-to-date (cont.) ● Stanislaus directory configured at Cal Poly ● Secure path established between campuses ● Stanislaus test data sent to Cal Poly ● Directory populated ● Issues remaining: – Determining what data to make viewable – Establishing password change procedures – Directory-enabling access to PeopleSoft

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor IdMC: Benefits ● Stanislaus: – Gain a Directory and Basic Authentication Service – Learning experience for staff re: Id Management – Gain working knowledge of implementing an Enterprise Directory ● San Luis Obispo: – Improved campus buy-in regarding middleware – Input from other middleware team regarding Cal Poly’s implementation – Collaboration process

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor IdMC: Challenges ● Stanislaus – Staff buy-in – Selling the concept of remote directory services – Ensuring secure, reliable access – Staff resources ● San Luis Obispo – Prioritizing resources for the project

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Lessons Learned So Far… ● Synchronizing activities at two campuses is not trivial ● External forces are also at play – Oracle Portal Grant ● Receiving help from a provider campus does not negate the need to do significant preparation at client campus

Information Resources and Communications University of California, Office of the President Information Technology Services The California State University Office of the Chancellor Questions?