5
1 P-20W Identity Management November 16, 2011 11:15 – 12:15 Bob Swiggum, GA Bill Hurwitch, ME Cathy Wagner, MN

1 P-20W Identity Management November 16, 2011 11:15 – 12:15 Bob Swiggum, GA Bill Hurwitch, ME Cathy Wagner, MN

Embed Size (px)

Citation preview

Page 1: 1 P-20W Identity Management November 16, 2011 11:15 – 12:15 Bob Swiggum, GA Bill Hurwitch, ME Cathy Wagner, MN

1

P-20W Identity Management

November 16, 201111:15 – 12:15

Bob Swiggum, GABill Hurwitch, ME

Cathy Wagner, MN

Page 2: 1 P-20W Identity Management November 16, 2011 11:15 – 12:15 Bob Swiggum, GA Bill Hurwitch, ME Cathy Wagner, MN

2

P-20W Identity Management: GA

Role Based Security

Challenge• Don’t make the district folks remember more ID and passwords

• Don’t cause any more security work for district folks

• Provide role based security access to LDS.

• Provide security to turn off access to individual pieces of information (i.e. – discipline)

Progress• Developed a process to authenticate access to LDS using existing ID and password

• Developed a system to allow existing roles within local SIS to be used in LDS

• Added feature to allow additional roles to be defined by districts at their option

• Working on enhancements to turn off access to individual pieces of information

Page 3: 1 P-20W Identity Management November 16, 2011 11:15 – 12:15 Bob Swiggum, GA Bill Hurwitch, ME Cathy Wagner, MN

3

P-20W Identity Management: ME

State Agencies in P-20W Longitudinal Data System

Departments of: Education, Health and Human Services, Labor, Corrections, University of Maine System, Maine Community Colleges System

Cognos Framework – Client Index Table

• Established by State Office of Information Technology (OIT) to link multiple Health and Human Services database systems with different identifiers

• Stores multiple agency identifiers in one secure table• Agencies submit data requests using own identifiers• The Framework converts the requesting agency’s identifier to the receiving

agency’s identifier and returns the data with the requestor’s identifier• Agencies do not see the other agencies’ identifiers

FirstName MI Last

NameBirthDate Gender Race SSN MaineCare ID SSID UMS ID

John R Smith 1/1/1995 Male C 123456789 123456789A 987654321

Judy L Jones 2/2/1990 Female C 987654321 222222222A 123456789 111223

Page 4: 1 P-20W Identity Management November 16, 2011 11:15 – 12:15 Bob Swiggum, GA Bill Hurwitch, ME Cathy Wagner, MN

4

P-20W Identity Management : ME

Security•OIT Governance and policies

•MOAs/MOUs established between agencies for data sharing

•Ensures adherence to Federal and State policies including FERPA, HIPAA

•Special procedures for collecting/storing SSN

Challenges•Data cleansing to eliminate duplication – 1.2 million records

•Establishing business rules for creating new identities in Client Index Table

•Policy limitations – legislation on use of personal identifiers and SSN

• K-12 collection – SSN optional, cannot be mandated by Maine DOE

• Focus on Career & Technical Education centers

• Fewer issues with Adult Education, Postsecondary and Workforce

•Data sharing/policies with other State agencies and researchers

•Do not create another “SSN”

Page 5: 1 P-20W Identity Management November 16, 2011 11:15 – 12:15 Bob Swiggum, GA Bill Hurwitch, ME Cathy Wagner, MN

Contact Info:Bob Swiggum, 404-657-0810, [email protected] Hurwitch, 207-624-6816, [email protected] Cathy Wagner, 651-582-8688, [email protected]

5

P-20W Identity Management: Contacts