Unified Identity Attribute Set - Attribute Practice Compliance Statements

Unified Identity Attribute Set - Attribute Practice Compliance Statements

Chief Information Officer

IC Technical Specifications

Unified Identity Attribute Set - Attribute Practice Compliance Statements

Overview

This Attribute Practice Compliance Statements for the Unified Identity Attribute Set (UIAS-APCS) provides concise direction to Intelligence Community (IC) elements required by Intelligence Community Standard (ICS) 500-30, Enterprise Authorization Attributes: Assignment, Authoritative Sources, and Use for Attribute-Based Access Control Of Resources, to produce an Attribute Practice Statement (APS) for each Attribute Service (AS) of an IC element.

Compliance with an Attribute Practice Compliance Statement (APCS) document ensures interoperability and consistently applied attributes in dynamic Information Technology (IT) environments including the Intelligence Community Information Technology Enterprise (IC ITE). An APCS alleviates the need for each IC element to produce an APS and ensure compliance with ICS 500-30, and IC Enterprise Attribute Exchange Between IC Attribute Services Unified Identity Attribute Set (UIAS.XML).

This UIAS-APCS has a dependency on UIAS.XML. Citations for the Controlled Vocabulary Enumeration (CVE)s are covered in the UIAS.XML technical specification and should be complied with in accordance with the needs and practices of the responding organization, and that such compliance should also designate the reasoning for compliance approach or its variations. The UIAS.XML MUST be consulted in conjunction with this document.

This specification is maintained by the IC Chief Information Officer via the Data Standards Coordination Activity (DSCA) and Common Metadata Standards Tiger Team (CMSTT).

Technical Specification Downloads

Latest Approved Public Release:

Mission Requirements

As the IC environment evolves, the user base grows with more diverse membership with unique data sources per member entity. The IC's move to a simplified architecture for access control and authorization is predicated on ABAC and an IC Authorization service being trustworthy. This drives an increased need to better understand attribute provisioning and ensure that all IC elements provision and maintain access control and authorization related attributes consistently. This document specifies compliance statements to confirm that enterprise identity attributes are consistent with the attributes defined in the UIAS.XML technical specification and that IC elements maintain attributes consistent with Appendix C of ICS 500-30, Operation of ASs and AAS. Compliance with the ICS 500-30 will ensure that all IC elements provision and maintain attributes for availability, accuracy, consistency, privacy, confidentiality, and integrity across persona lifecycles.