identity ecosystem framework: establishing rules of the road for digital identity

28
Ian Glazer Vice-Chair, Management Council IDESG @iglazer From Principles to Actions: Identity Ecosystem Framework

Upload: ian-glazer

Post on 09-Feb-2017

688 views

Category:

Internet


0 download

TRANSCRIPT

Page 1: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Ian Glazer Vice-Chair, Management Council IDESG @iglazer

From Principles to Actions: Identity Ecosystem Framework

Page 2: Identity Ecosystem Framework: Establishing rules of the road for digital identity

We are just like you

Page 3: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

How? Tasks roll down hill Multi-disciplinary group comes together Define controls needed to solve the problem

Page 4: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Rules of the Road for

Digital Identity

Page 5: Identity Ecosystem Framework: Establishing rules of the road for digital identity

How did we get here?

Page 6: Identity Ecosystem Framework: Establishing rules of the road for digital identity

People are unhappy

Page 7: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

Americans are less than thrilled The current state of digital identity is fine. But only just fine. Not great.

Page 8: Identity Ecosystem Framework: Establishing rules of the road for digital identity

54%

Page 9: Identity Ecosystem Framework: Establishing rules of the road for digital identity

54% of digital consumers are cautious about the information they share due to lack of confidence in the online security

that protects their personal data

Source: 2015 Accenture Digital Consumer Survey

Page 10: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Management is unhappy

Page 11: Identity Ecosystem Framework: Establishing rules of the road for digital identity
Page 12: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

Executives require action •  US President Obama’s Ninety-Day

Cybersecurity Review, 2009 •  National Strategy for Trusted Identities in

Cyberspace (NSTIC), April 2011

Page 13: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

NSTIC: A Vision of Digital Identity

A P R I L 2 0 11

Enhancing Online Choice, Efficiency, Security, and Privacy

NAT IONA L STR ATEGY FOR TRUSTED IDENT IT IES

IN CY BER SPACE

“The simple fact is, we cannot know what companies have not been launched, what products or services have not been deployed, or what innovations are held back by the inadequacy of tools, like insecure passwords, long ago overwhelmed by the fantastic and unpredictable growth of the Internet. What we do know is this: by making online transactions more trustworthy and enhancing consumers’ privacy, we will prevent costly crime; we will give businesses and consumers new confidence; and we will foster growth and innovation, online and across our economy – in some ways we can predict, and in other ways we can scarcely imagine. Ultimately, this is the goal of this strategy.” – President Obama

Page 14: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

NSTIC Principles Privacy-enhancing and Voluntary Secure and Resilient Interoperable Cost-effective and Easy to use

Page 15: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Principles shape and direct

action

Page 16: Identity Ecosystem Framework: Establishing rules of the road for digital identity

What happens next?

Page 17: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

Identity Ecosystem Steering Group •  Created in August 2012 •  Convened by management (the

government) •  Public-Private partnership •  Tasked to create a (controls) framework

Page 18: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

Mutli-disciplinary by design •  Privacy and Civil Liberties •  Usability and Human Factors •  Consumer Advocates •  U.S. Federal Government •  U.S. State, Local, Tribal, and

Territorial Government •  Research, Development,

Education and Innovation •  Identity and Attribute Providers •  Interoperability

•  IT Infrastructure •  Regulated Industries •  Small Business and

Entrepreneurs •  Security •  Relying Parties •  Unaffiliated Individuals

Page 19: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

Breaking down the work •  Security •  Privacy •  User Experience •  Standards •  Policy Coordination

•  Trust Framework and Trustmarks

•  International Coordination

•  Healthcare

Page 20: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Identity Ecosystem Framework

Page 21: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

The Results Identity Ecosystem Framework •  Functional Model – Reference architecture •  Requirements – Rules of the Road for digital identity •  Supplemental Guidance – How to meet the Requirements •  Scoping Statement – Where we go next

Page 22: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

Self-assessment and beyond… •  A way for good actors to make

themselves known •  Transitioning to a Program Listing and

Certification Scheme in the future

Page 23: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Moving forward

Page 24: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Rules of the Road for

Digital Identity

Page 25: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Principles shape and direct

action

Page 26: Identity Ecosystem Framework: Establishing rules of the road for digital identity

Management is happy

Page 27: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

A reusable pattern Principles to drive action Multi-disciplinary team Create/select controls & frameworks Assess to measure progress

Page 28: Identity Ecosystem Framework: Establishing rules of the road for digital identity

IDESG idesg.org

How you can get involved •  Join us at IdentityRevolution.org

•  Explore the Identity Ecosystem Framework

•  Join the IDESG

•  Be recognized as a good actor