<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheets/rss.css" type="text/css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Your Complete Source for GSA Approved Identity Products: DOD not complying with HSPD-12</title>
    <link>http://www.fips201.com/articles/2008/07/15/dod-not-complying-with-hspd-12</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>DOD not complying with HSPD-12</title>
      <description>&lt;p&gt;An audit by the U.S. Department of Defense&#8217;s Inspector General&#8217;s office shows that the agency is not complying the HSPD-12 and FIPS 201. The White House Office of Management and Budget and the President&#8217;s Council on Integrity and Efficiency requested the audit. &lt;/p&gt;

&lt;p&gt;The report shows that the DOD is lacking in six specific areas with its credentialing project. These include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Failing to meet government-wide milestones for completing background checks.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Staff at stations that issue the Common Access Card cannot electronically verify whether card applicants have initiated or completed a National Agency Check with Written Inquiries.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;DOD displays full Social Security number on the Geneva Conventions credential, increasing the risk of identity theft. &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Purchasing equipment that is not compliant with HSPD-12.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Using bar code technology on the Defense Biometric Identification System credential that is not equivalent to mandatory HSPD-12 security features. &lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;DOD&#8217;s current PIV credential does not meet interoperability requirements.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The Inspector General recommends that the DOD issue HSPD-12 implementation guidance within 90 days; revise and update DOD Directives and Instructions to incorporate FIPS requirements; and submit proposed end-state PIV credential to GSA for conformance testing. &lt;/p&gt;

&lt;p&gt;The Inspector General is requesting comments on the final report by July 30, 2008.&lt;/p&gt;

&lt;p&gt;The full 90-page report can be downloaded &lt;a href="http://www.dodig.mil/Audit/reports/fy08/08-104.pdf"&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
      <pubDate>Tue, 15 Jul 2008 09:26:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:784059e9-6cba-4df7-9f7e-294be224afd9</guid>
      <author>FIPS 201 Administrator</author>
      <link>http://www.fips201.com/articles/2008/07/15/dod-not-complying-with-hspd-12</link>
      <category>News</category>
    </item>
  </channel>
</rss>
