The Inner Circle

 View Only

DOD ICAM Federation Framework

  • 1.  DOD ICAM Federation Framework

    Posted Jan 15, 2025 10:40:00 AM
      |   view attached

    Hi All,

    The DoD ICAM Federation is an essential component of DoD CIO strategy that aims to improve ICAM services and enable secure, automated, information sharing between internal and external partners across DoD.  ICAM Federation establishes trust relationships that exchange Identity Provider (IdP) and/or ICAM Service Provider (SP) information between organizations to enhance information sharing.  This framework establishes the DoD FP, which outlines the process for establishing ICAM federations within DoD and with external partners, and requires the creation, operation, and maintenance of an enterprise ICAM Federation Hub.

    Federation allows an organization to accept ICAM information and decisions across organizational boundaries based on an established trust.  For DoD's purposes, there are two types of Federated Trust: internal and external.   Internal federation is between DoD-approved ICAM SPs.  Internal federation is established by ensuring each DoD organization's Federation Practice Statement (FPS) aligns to the DoD FP.  Federation between approved ICAM SPs will ensure secure and interoperable access to systems and resources across the DoD enterprise, balancing the responsibility to share with the need to protect.  

    External federation is between DoD and organizations outside of DoD, commonly referred to as a mission partner, and is facilitated by mapping the external partner's FP to the DoD's FP and ensuring they are in alignment to aid in the development of an ICAM Federation Trust Agreement (IFTA).  An IFTA is required between DoD and external federation partners because external organizations are not managed under the authority of DoD IT policy.  

    These agreements, policies, and practice statements will enable consistent, reliable, and secure communications while sharing between partners and across information domains.  For instance, Mission Partner Environments (MPE) have a need to employ this federation across a wide range of internal and external partners.  DoD CIO will adopt an ICAM Reference Architecture, revise the ICAM Strategy and Reference Design documents, and update other policy documents, as needed, to support successful implementation of federation. 



    ------------------------------
    Michael Roza CPA, CISA, CIA, CC, CCSKv5, CCZTv1, MBA, EMBA, CSA
    ------------------------------

    Attachment(s)