The NIST has completed its review of the Federal Information Processing Standard (FIPS) 201. The organization kicked off the review back in 2020, as part of a standard review cycle for the federal government.
The FIPS standard details the kinds of credentials that federal organizations are allowed to issue to employees and contractors who need access to their sites. The standard was last updated with FIPS version 201-2 in 2013, which prioritized the use of PIV cards as the primary authentication factor for government agents.
The problem, of course, is that access technology has improved dramatically in the years since. FIPS 201-3 is intended to reflect that progress, so federal agencies can take advantage of the latest tools. The updated standard still allows for the use of PIV cards, but supplements that with other multi-factor authenticators, including one-time passwords and FIDO tokens.
The new guidelines also allow federal agencies to verify employee identities and issue credentials remotely. In the past, the process needed to be carried out in person, though the use of remote authenticators has become much more widespread during the pandemic.
“It has become important to provide more flexibility to agencies in choosing credentials to use for authentication,” said NIST computer scientist Hildegard Ferraiolo. “Not all laptop computers are available with built-in PIV card slots, for example, and often, there are cloud-based applications that don’t use public-key infrastructure that PIV cards provide. For these situations we need alternatives.”
FIPS 201-3 will provide federal agencies with more authentication options to help secure a hybrid work environment. All of the newly recognized credentials are detailed in the NIST SP 800-63-3 digital identity guidelines. The organization is currently in the process of revising the NIST SP 800-157 guidelines to help with implementation, and the NIST SP 800-217 guideline to facilitate credential interoperability across multiple agencies.
–
February 7, 2022 – by Eric Weiss
Follow Us