Secure Identity Verification of End-Users
Know the positioning, international standards, and workflow
Government organizations in many countries want to improve IT security as part of the expansion of public digitalization strategies. An important element is trust in identities.
Documents, standards and regulations are at the forefront in setting the standard for how government bodies—e.g., NIST (National Institute of Standards and Technology) in the USA and the Government Digital Service (part of the Cabinet Office in the UK)—must prove the identity of citizens and consumers, and also in meeting the national requirements of other countries.
Organizations need to prove the identity of their employees too, and there are similarities with proving citizens’ identities. There are, however, also differences. When organizations want to validate, prove the identity of, or verify an employee, each organization needs its own specific guidelines, though some very good inspiration can be found in the official guidelines. With other regulations of this type, we have seen that public organizations demand similar guidelines or regulations are followed by their private partners, and we will then see the same principles applied everywhere. If this is the case, then this document will have value for both public and private organizations.
When organizations want to validate, prove the identity of, or verify an employee, each organization needs its own specific guidelines, this is also called Help Desk Identity Proofing.
Our ambition with this white paper is to inspire managers with security and compliance responsibility to design a logical system for user verification which can be planned and executed.
Even managers of operational units, such as service desks, who perform verification procedures can benefit from this document. All decisions made by organizations must respect efficiency and speed in addition to security. This white paper also suggests a best practice for the use of FastPass Identity Verification Manager (IVM) where organizations have to comply with national or international standards to achieve secure identity verification.
What you can get from the whitepaper:
Identity Verification Positioning
Identity Management
controls what IT resources a person can use. It depends on title, role, hierarchy and other organizational characteristics. The IT resources can’t see people, so it is translated to a user identity. We then assume that only the employee can use this specific identity.
Access Management
then ties the person to the user identity. This is done with credentials. A good credential is unique to the person and can be read and understood by the IT system. The Access Management system will also have control of the directories where we link the credentials to the user-identity. This process is called authentication. It can be 1-factor or multi-factor authentication (MFA).
Identity Verification or Identity Proofing
is the process used to ensure that the person is who he/she claims to be! When we work with credentials, then identity verification must guarantee that the person owns the user identity. The credentials must be administrated by trusted (privileged) persons or systems, which issue the credentials after the person’s identity has been adequately verified.
See workflows on how you can simply verify persons for different levels of secure or sensitive systems according to international standards based on different regions
Proposed model of Identity Verification for end users
Verify if John Doe is legit
The critical part of the password reset process is identity verification.
How can the service desk agent confirm that it is the legitimate user? This task is taken over by IVM, which will control what actions to take and decide when the verification is OK, based on specific knowledge about each user.
As societies are moving to a higher degree of digitalization, it is becoming obvious that security for persons and their user-identities is a prerequisite. Many countries are implementing new regulations to enforce this. But even without legal enforcement, it would be wise for any organization to protect the relationship between users and their user-identities.
The new FastPass V4 brings comprehensive password protection to secure organizations. Making passwords complex, avoiding the use of dictionary passwords and popular phrases as part of the password, changing the password regularly, and protecting the password processes will make your organization unattractive to hackers.
FastPassCorp’s mission is to help organizations provide secure processes for identity verification. We have three criteria in mind:
We and our partners have the experience and tools to inspire you in your considerations for how you can improve identity verification by means of efficient processes.
Transform your business today with FastPass
Get in touch with us today by filling up the form and our team will get back to you as soon as possible.