U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NISTIR 8335 (Draft)

Identity as a Service for Public Safety Organizations

Date Published: June 2021
Comments Due: August 2, 2021 (public comment period is CLOSED)
Email Questions to: psfr-nccoe@nist.gov

Author(s)

William Fisher (NIST), Christopher Brown (MITRE), Mark Russell (MITRE), Sudhi Umarji (MITRE), Karen Scarfone (Scarfone Cybersecurity)

Announcement

Identity as a service (IDaaS) is when a company offers identity, credential, and access management (ICAM) services to customers through a software-as-a-service (SaaS) cloud-service model. Public safety organizations (PSOs) could potentially reduce costs and adopt new standards and authenticators more easily by using IDaaS to provide authentication services for their own applications. This would allow PSOs to offload some or most of their authentication responsibilities to the IDaaS provider.

This report informs PSOs about IDaaS and how they can benefit from it. It also lists questions that PSOs can ask IDaaS providers when evaluating their services to ensure the PSOs’ authentication needs are met and the risk associated with authentication is mitigated properly. PSOs considering IDaaS usage are encouraged to use this NISTIR. This report was developed in joint partnership between the National Cybersecurity Center of Excellence (NCCoE) and the Public Safety Communications Research Division (PSCR) at NIST.

NOTE: A call for patent claims is included on page iii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

Abstract

Keywords

authentication; identity, credential, and access management (ICAM); identity as a service (IDaaS); multifactor authentication; public safety and first responders; public safety organization (PSO)
Control Families

None selected

Documentation

Publication:
NISTIR 8335 (Draft) (DOI)
Local Download

Supplemental Material:
Submit comments (web)

Document History:
06/16/21: NISTIR 8335 (Draft)

Topics

Security and Privacy
authentication; risk management

Technologies
cloud & virtualization

Sectors
public safety