SlideShare a Scribd company logo
Developing Countries
National ICT Identity
Governance
Strategy
Huntington Ventures Ltd.
The Business of Identity Management
May 2016
This Deck…
• Reviews the governance components required to
successfully implement and maintain an e-
government strategy:
– Identity data governance
– Identity infrastructure governance
– Laws and regulations governance
• So who am I?
Guy Huntington
Guy Huntington is a very
experienced identity
architect, program and
project manager who has led,
as well as rescued, many
large Fortune 500 identity
projects including Boeing and
Capital One. He recently
completed being the identity
architect for the Government
of Alberta’s Digital Citizen
Identity and Authentication
program.
Identity Governance
• Many people don’t understand the governance
requirements to successfully implement and
maintain an e-government strategy
• There are several components:
– Identity data governance
– Identity infrastructure governance
– Laws and regulations governance
• Let’s start with identity data…
Birth
Name Change
Gender Change
Death
Address Change
Tel. Number Change
Parent/Guardian Change
Marriage
Divorce
Authoritative Source
Authoritative Source
Authoritative Source
Authoritative Source
Authoritative Source
Authoritative Source
Authoritative Source
Authoritative Source
Authoritative Source
Business
Processes
Business
Processes
Business
Processes
Business
Processes
Business
Processes
Business
Processes
Business
Processes
Business
Processes
Business
Processes
Citizen
Tombstone
Identity
Directory
National Citizen Identity Lifecycle
Who Has Legal Responsibility?
• For each of the identity data on the left hand side of
the previous screen, what government ministry is
legally responsible for the data?
• There are some new identity challenges that need to
be addressed:
– When a biometric is obtained from a person (e.g. infant,
child or adult) which ministry is ultimately responsible for
the biometric?
– For Parents/legal guardians, which ministry is legally
responsible for establishing this relationship
– For citizen addresses and phone numbers, is there one
ministry who will be legally responsible for the collection
and management of this?
Legal Vs. Operational Responsibility
• Once the legal governance for each piece of identity data
is determined, then there needs to be a determination of
who is operationally responsible for the collection of it
• This is the second column in the previous diagram, i.e.
business processes
• Here’s a hypothetical example:
– When a student goes to school for their first day, they will
provide a face and voice print biometric
• The school district or, a specialized identity team, might be the people
who actually collect the biometrics
• HOWEVER, the ministry legally responsible for the biometric will likely
not be the Education Ministry
• So regulations and standards need to be created and then
audited for the operational governance of each piece of
identity data
Shared Services
• About 20 years ago, when large global
enterprises began to digitize themselves and
centralize operations, it became apparent there
was a need for a shared services group to
collectively manage IT infrastructure
• Governments began to adopt this too
• There needs to be a legal act and regulations
regarding the formation of such an entity
Identity Infrastructure et al
• Shared Services are usually the group who is
responsible for the operational management of the
identity infrastructure
– This includes data centres, clouds, operational data, high
availability, etc.
– It may or many not include the security management
• Note that the Shared Services group only has
operational responsibility and not legal ownership
for each of the underlying identity data components
– The legal ownership remains with the ministry
responsible for each identity data
BUT Sometimes Shared Services
Is Legally Responsible…
• Sometimes, the shared services group also looks
after things like identity phone numbers and
addresses, since there usually isn’t one ministry
assigned to this
• At the last government client I worked with, their
shared services ministry not only managed the
identity infrastructure but also was responsible
for the centralized citizen telephone numbers
and address collection and management
– Citizens would go to one place online to change their
addresses and phone numbers
Government Identity Steering Committee
• Many enterprises deploying global identity
strategies quickly come to the realization that
identity crosses all the enterprise administration
silos
– It’s thus not only operationally very important, BUT
also politically important
• It is not uncommon in large enterprises for them
to form a identity steering committee to oversee
identity infrastructure, identity investments, etc.
Laws and Regulations
• If one examines governments who have already
successfully deployed national e-identity programs,
like Estonia, one finds that a major component to do
this is to create and/or change laws and regulations
• The use of things like digital signatures, digital data
retention, biometrics et al require well thought out
acts and regulations
• So your government will have to do this too
• Let’s take a quick look at some of the laws that
Estonia brought into being…
Legal Framework
• Digital Signatures Act -
https://www.riigiteataja.ee/en/eli/508072014007/consolide
• Public Information Act -
https://www.riigiteataja.ee/en/eli/522122014002/consolide
• Personal Data Protection Act -
https://www.riigiteataja.ee/en/eli/529012015008/consolide
• Act on Intellectual Property
• Uniform Bases for Document Management Procedures -
https://www.riigiteataja.ee/akt/119062012007
• Archives Act - https://www.riigiteataja.ee/akt/112072014028
• Principles of Estonian Information Policy (1998, 2004)
• Action Plan of Estonian Information Policy – (eEstonia) (1998,
1999, 2000, 2001,2002, 2003, 2004, 2005, 2006...)
• http://egov2.eu/knowledge-base/an-overview-of-estonian-
e%E2%80%91government-development-and-projects/
Identity and Credential Assurance
• Your government will have to create two standards; identity
and credential assurance
• Identity assurance covers what documents and biometrics are
allowable under what type of conditions to establish an
identity
• Credential assurance covers what type of credential is
allowable for certain types of risk
• There will have to be memorandums of understanding
between the national government and local state and
municipalities as well as crown corporations
• These documents will also likely be legally referred to in
federation agreements with third parties
• As your country begins to work with other countries on
recognizing national identities and verification, these
documents must then become part of such agreements
Federation Agreements
• Your government’s e-identity strategy will also
require the national identity and authentication
service to work with third parties like banks,
telcos, insurance companies, etc.
• Each of these parties will have to sign a
federation agreement with the government
• This covers many things like identity and
credential assurance, liability, responsibility for
when a session is dropped part way through, etc.
Governance Challenges
• Creating, implementing and sustaining an e-
identity strategy IS VERY CHALLENGING because:
– Crosses over all ministry silo’s
– Extremely public facing
– Literally many thousands of decisions to be made as
the systems are all interconnected
– The system is prone to attack from organized crime
and foreign intelligence agencies
– Large budgets and time cycles involved
Strong, Sustained Leadership
• Therefore, from the top of your government on
down, all must be not only aware but take a
strong, sustained leadership role
• It’s when times get tough, like a denial of service
attack, etc. that the top leaders have to be there
to calm the public and ensure the system will be
properly maintained
There’s A Lot To Governance
• It has been my own past experience that most
enterprises commencing large, global, identity
programs don’t understand the implications of
governance
• It’s usually tacked on towards the end of the
project
• THIS IS A BIG MISTAKE since many projects go
over time and budgets as they finally realize
governance is complex and must be addressed
Governance Should Be Addressed First
• At the very least, governance should be one of
the main project tracks
• Many different government governance
initiatives must be launched in parallel to the
business process and technical activities of the
teams
• Governance work takes time – so plan for it
• If you do this, then there is an excellent chance
your identity program will roll out the door on
time and on budget
Changing the World a Bit
• Guy wants to change the world a bit by assisting
developing countries to leapfrog ahead of most
western societies by:
– Leveraging citizen’s use of the cell phone and their
voice to then access online government services
– Creating a new model for educating students
– Leverage existing technology to deliver healthcare
more effectively
If You Thought This Is Thought Provoking
• Then please pass along a link to the presentation
to people in your country who might be
interested
• You can contact me at:
– guy@hvl.net
– 1-604-861-6804
– Via LinkedIn (https://ca.linkedin.com/in/ghuntington)
• Thanks for your time!

More Related Content

What's hot

National Citizen Target SOA Architecture Sept 2016
National Citizen Target SOA Architecture Sept 2016National Citizen Target SOA Architecture Sept 2016
National Citizen Target SOA Architecture Sept 2016
Guy Huntington
 
19 July 2012 - Loc-poi overview v2
19 July 2012 - Loc-poi overview v2 19 July 2012 - Loc-poi overview v2
19 July 2012 - Loc-poi overview v2
Timothy Holborn
 
Jan 2017 Submission to AG Re: Metadata use in civil proceedings
Jan 2017 Submission to AG Re: Metadata use in civil proceedingsJan 2017 Submission to AG Re: Metadata use in civil proceedings
Jan 2017 Submission to AG Re: Metadata use in civil proceedings
Timothy Holborn
 
Zlatan Sabic ICT for Governance
Zlatan Sabic ICT for GovernanceZlatan Sabic ICT for Governance
Zlatan Sabic ICT for Governanceyahoosch
 
feb 2018 - Sub22 - The impact of new and emerging information and communicati...
feb 2018 - Sub22 - The impact of new and emerging information and communicati...feb 2018 - Sub22 - The impact of new and emerging information and communicati...
feb 2018 - Sub22 - The impact of new and emerging information and communicati...
Timothy Holborn
 
March 2013 Australian Centre Liberal Arts
March 2013 Australian Centre Liberal Arts March 2013 Australian Centre Liberal Arts
March 2013 Australian Centre Liberal Arts
Timothy Holborn
 
Feb 2020 - Senate Submission Financial Technology and Regulatory Technology
Feb 2020 - Senate Submission Financial Technology and Regulatory TechnologyFeb 2020 - Senate Submission Financial Technology and Regulatory Technology
Feb 2020 - Senate Submission Financial Technology and Regulatory Technology
Timothy Holborn
 
eGovernance Infrastructure to build e-Democracy
eGovernance Infrastructure to build e-DemocracyeGovernance Infrastructure to build e-Democracy
eGovernance Infrastructure to build e-Democracy
Cornelia_Amihalachioae
 
E-commerce regulation pria chetty
E-commerce regulation pria chettyE-commerce regulation pria chetty
E-commerce regulation pria chettyEndcode_org
 
Better use of data
Better use of dataBetter use of data
Better use of data
Jerry Fishenden
 
2012 OCT knowledge banking
2012 OCT knowledge banking2012 OCT knowledge banking
2012 OCT knowledge banking
Timothy Holborn
 
eGovernment in Belgium
eGovernment in Belgium eGovernment in Belgium
eGovernment in Belgium
E-Government Center Moldova
 
Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...
Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...
Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...
gallowayandcollens
 
Naela webinar 2015 digital asset powerpoint hhc 11.4.2015 5-eed
Naela webinar 2015   digital asset powerpoint  hhc 11.4.2015 5-eedNaela webinar 2015   digital asset powerpoint  hhc 11.4.2015 5-eed
Naela webinar 2015 digital asset powerpoint hhc 11.4.2015 5-eed
Gideon Ale
 
Trust Factory Slides (2015)
Trust Factory Slides (2015)Trust Factory Slides (2015)
Trust Factory Slides (2015)
Timothy Holborn
 
IAB Online Content Regulation: Trends
IAB Online Content Regulation: Trends IAB Online Content Regulation: Trends
IAB Online Content Regulation: Trends
Endcode_org
 
Human identity inforg
Human identity   inforgHuman identity   inforg
Human identity inforg
Timothy Holborn
 
How to Implement Computerized id cards in Afghanistan?
How to Implement Computerized id cards in Afghanistan?How to Implement Computerized id cards in Afghanistan?
How to Implement Computerized id cards in Afghanistan?
Roohul Amin
 
E Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal ProtectionE Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal Protection
ijtsrd
 
ICT for fighting Corruption
ICT for fighting CorruptionICT for fighting Corruption
ICT for fighting Corruption
Deris Stiawan
 

What's hot (20)

National Citizen Target SOA Architecture Sept 2016
National Citizen Target SOA Architecture Sept 2016National Citizen Target SOA Architecture Sept 2016
National Citizen Target SOA Architecture Sept 2016
 
19 July 2012 - Loc-poi overview v2
19 July 2012 - Loc-poi overview v2 19 July 2012 - Loc-poi overview v2
19 July 2012 - Loc-poi overview v2
 
Jan 2017 Submission to AG Re: Metadata use in civil proceedings
Jan 2017 Submission to AG Re: Metadata use in civil proceedingsJan 2017 Submission to AG Re: Metadata use in civil proceedings
Jan 2017 Submission to AG Re: Metadata use in civil proceedings
 
Zlatan Sabic ICT for Governance
Zlatan Sabic ICT for GovernanceZlatan Sabic ICT for Governance
Zlatan Sabic ICT for Governance
 
feb 2018 - Sub22 - The impact of new and emerging information and communicati...
feb 2018 - Sub22 - The impact of new and emerging information and communicati...feb 2018 - Sub22 - The impact of new and emerging information and communicati...
feb 2018 - Sub22 - The impact of new and emerging information and communicati...
 
March 2013 Australian Centre Liberal Arts
March 2013 Australian Centre Liberal Arts March 2013 Australian Centre Liberal Arts
March 2013 Australian Centre Liberal Arts
 
Feb 2020 - Senate Submission Financial Technology and Regulatory Technology
Feb 2020 - Senate Submission Financial Technology and Regulatory TechnologyFeb 2020 - Senate Submission Financial Technology and Regulatory Technology
Feb 2020 - Senate Submission Financial Technology and Regulatory Technology
 
eGovernance Infrastructure to build e-Democracy
eGovernance Infrastructure to build e-DemocracyeGovernance Infrastructure to build e-Democracy
eGovernance Infrastructure to build e-Democracy
 
E-commerce regulation pria chetty
E-commerce regulation pria chettyE-commerce regulation pria chetty
E-commerce regulation pria chetty
 
Better use of data
Better use of dataBetter use of data
Better use of data
 
2012 OCT knowledge banking
2012 OCT knowledge banking2012 OCT knowledge banking
2012 OCT knowledge banking
 
eGovernment in Belgium
eGovernment in Belgium eGovernment in Belgium
eGovernment in Belgium
 
Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...
Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...
Who Will Run My Fantasy Football Team When I’m Gone: The Latest and Greatest ...
 
Naela webinar 2015 digital asset powerpoint hhc 11.4.2015 5-eed
Naela webinar 2015   digital asset powerpoint  hhc 11.4.2015 5-eedNaela webinar 2015   digital asset powerpoint  hhc 11.4.2015 5-eed
Naela webinar 2015 digital asset powerpoint hhc 11.4.2015 5-eed
 
Trust Factory Slides (2015)
Trust Factory Slides (2015)Trust Factory Slides (2015)
Trust Factory Slides (2015)
 
IAB Online Content Regulation: Trends
IAB Online Content Regulation: Trends IAB Online Content Regulation: Trends
IAB Online Content Regulation: Trends
 
Human identity inforg
Human identity   inforgHuman identity   inforg
Human identity inforg
 
How to Implement Computerized id cards in Afghanistan?
How to Implement Computerized id cards in Afghanistan?How to Implement Computerized id cards in Afghanistan?
How to Implement Computerized id cards in Afghanistan?
 
E Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal ProtectionE Commerce Platform Data Ownership and Legal Protection
E Commerce Platform Data Ownership and Legal Protection
 
ICT for fighting Corruption
ICT for fighting CorruptionICT for fighting Corruption
ICT for fighting Corruption
 

Similar to Developing Countries National ICT Identity Governance Strategy

Legal Knowledge Management for Municipal Attorneys
Legal Knowledge Management for Municipal AttorneysLegal Knowledge Management for Municipal Attorneys
Legal Knowledge Management for Municipal Attorneysajrothman
 
Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby
 
Challenges for an implementation of an electronic single window - Guichet Un...
Challenges for an implementation of an electronic single window -  Guichet Un...Challenges for an implementation of an electronic single window -  Guichet Un...
Challenges for an implementation of an electronic single window - Guichet Un...
AAEC_AFRICAN
 
Implications of acts in organizations
Implications of acts in organizations Implications of acts in organizations
Implications of acts in organizations Swarupa Rani Sahu
 
Public sector e-signature policy webinar 170711
Public sector e-signature policy webinar 170711Public sector e-signature policy webinar 170711
Public sector e-signature policy webinar 170711
K6 Partners
 
eGovernmet.pptx
eGovernmet.pptxeGovernmet.pptx
eGovernmet.pptx
ssuser9cf4e3
 
C2.0 Financial Inclusion Outreach Tutor Training
C2.0 Financial Inclusion Outreach Tutor TrainingC2.0 Financial Inclusion Outreach Tutor Training
C2.0 Financial Inclusion Outreach Tutor Training
PAVS Communities 2.0
 
JamesFWeaver122016
JamesFWeaver122016JamesFWeaver122016
JamesFWeaver122016Jim Weaver
 
Making it Rain: How to be Prepared, Not Scared, for Your Acquisition, IPO & More
Making it Rain:How to be Prepared, Not Scared, for Your Acquisition, IPO & MoreMaking it Rain:How to be Prepared, Not Scared, for Your Acquisition, IPO & More
Making it Rain: How to be Prepared, Not Scared, for Your Acquisition, IPO & More
bbispham
 
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Browne Jacobson LLP
 
All of government information technology strategy: What does this mean for re...
All of government information technology strategy: What does this mean for re...All of government information technology strategy: What does this mean for re...
All of government information technology strategy: What does this mean for re...
polly martin
 
Wayne richard - pia risk management - atlseccon2011
Wayne richard - pia risk management - atlseccon2011Wayne richard - pia risk management - atlseccon2011
Wayne richard - pia risk management - atlseccon2011
Atlantic Security Conference
 
The Double Edge Sword of the Social Network
The Double Edge Sword of the Social NetworkThe Double Edge Sword of the Social Network
The Double Edge Sword of the Social Network
Morris County NJ
 
Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...
Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...
Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...
Ravi Tirumalai
 
GCCS-privacy-PP-final presentation-3-1.pptx
GCCS-privacy-PP-final presentation-3-1.pptxGCCS-privacy-PP-final presentation-3-1.pptx
GCCS-privacy-PP-final presentation-3-1.pptx
MuhammadAbdullah311866
 
Gac, money flow, ds, ar, 2 26-14
Gac, money flow, ds, ar, 2 26-14Gac, money flow, ds, ar, 2 26-14
Gac, money flow, ds, ar, 2 26-14
ACFCS
 
eDem&eGov 2013
eDem&eGov 2013eDem&eGov 2013
eDem&eGov 2013
Denys A. Flores, PhD
 
Digital marketing ppt -e -Commerce unit -5
Digital marketing ppt -e -Commerce unit -5Digital marketing ppt -e -Commerce unit -5
Digital marketing ppt -e -Commerce unit -5
AssocProfMBAVelTechC
 
Getting to Know Open Government Data: Who's done it, how did they do, and so ...
Getting to Know Open Government Data: Who's done it, how did they do, and so ...Getting to Know Open Government Data: Who's done it, how did they do, and so ...
Getting to Know Open Government Data: Who's done it, how did they do, and so ...
jimduncan4
 

Similar to Developing Countries National ICT Identity Governance Strategy (20)

Legal Knowledge Management for Municipal Attorneys
Legal Knowledge Management for Municipal AttorneysLegal Knowledge Management for Municipal Attorneys
Legal Knowledge Management for Municipal Attorneys
 
Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016Tim Willoughby - Presentation to Innovation Masters 2016
Tim Willoughby - Presentation to Innovation Masters 2016
 
Challenges for an implementation of an electronic single window - Guichet Un...
Challenges for an implementation of an electronic single window -  Guichet Un...Challenges for an implementation of an electronic single window -  Guichet Un...
Challenges for an implementation of an electronic single window - Guichet Un...
 
Implications of acts in organizations
Implications of acts in organizations Implications of acts in organizations
Implications of acts in organizations
 
Public sector e-signature policy webinar 170711
Public sector e-signature policy webinar 170711Public sector e-signature policy webinar 170711
Public sector e-signature policy webinar 170711
 
eGovernmet.pptx
eGovernmet.pptxeGovernmet.pptx
eGovernmet.pptx
 
C2.0 Financial Inclusion Outreach Tutor Training
C2.0 Financial Inclusion Outreach Tutor TrainingC2.0 Financial Inclusion Outreach Tutor Training
C2.0 Financial Inclusion Outreach Tutor Training
 
JamesFWeaver122016
JamesFWeaver122016JamesFWeaver122016
JamesFWeaver122016
 
Making it Rain: How to be Prepared, Not Scared, for Your Acquisition, IPO & More
Making it Rain:How to be Prepared, Not Scared, for Your Acquisition, IPO & MoreMaking it Rain:How to be Prepared, Not Scared, for Your Acquisition, IPO & More
Making it Rain: How to be Prepared, Not Scared, for Your Acquisition, IPO & More
 
E gov iimc 2013
E gov iimc 2013E gov iimc 2013
E gov iimc 2013
 
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
Education law conferences, March 2018, Keynote 2 - 10 steps in 10 weeks to GD...
 
All of government information technology strategy: What does this mean for re...
All of government information technology strategy: What does this mean for re...All of government information technology strategy: What does this mean for re...
All of government information technology strategy: What does this mean for re...
 
Wayne richard - pia risk management - atlseccon2011
Wayne richard - pia risk management - atlseccon2011Wayne richard - pia risk management - atlseccon2011
Wayne richard - pia risk management - atlseccon2011
 
The Double Edge Sword of the Social Network
The Double Edge Sword of the Social NetworkThe Double Edge Sword of the Social Network
The Double Edge Sword of the Social Network
 
Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...
Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...
Restructuring The Government Ict Infrastructures And Standards To Achieve Glo...
 
GCCS-privacy-PP-final presentation-3-1.pptx
GCCS-privacy-PP-final presentation-3-1.pptxGCCS-privacy-PP-final presentation-3-1.pptx
GCCS-privacy-PP-final presentation-3-1.pptx
 
Gac, money flow, ds, ar, 2 26-14
Gac, money flow, ds, ar, 2 26-14Gac, money flow, ds, ar, 2 26-14
Gac, money flow, ds, ar, 2 26-14
 
eDem&eGov 2013
eDem&eGov 2013eDem&eGov 2013
eDem&eGov 2013
 
Digital marketing ppt -e -Commerce unit -5
Digital marketing ppt -e -Commerce unit -5Digital marketing ppt -e -Commerce unit -5
Digital marketing ppt -e -Commerce unit -5
 
Getting to Know Open Government Data: Who's done it, how did they do, and so ...
Getting to Know Open Government Data: Who's done it, how did they do, and so ...Getting to Know Open Government Data: Who's done it, how did they do, and so ...
Getting to Know Open Government Data: Who's done it, how did they do, and so ...
 

More from Guy Huntington

One pager - "Trust in an Interdependent World" - October 2017
One pager - "Trust in an Interdependent World" - October 2017One pager - "Trust in an Interdependent World" - October 2017
One pager - "Trust in an Interdependent World" - October 2017
Guy Huntington
 
Requirements for Successful Enterprises in a Federated Economy - October 2017
Requirements for Successful Enterprises in a Federated Economy - October 2017Requirements for Successful Enterprises in a Federated Economy - October 2017
Requirements for Successful Enterprises in a Federated Economy - October 2017
Guy Huntington
 
Identity Federation: Citizen Consent and the Internet of Things - October 2017
Identity Federation: Citizen Consent and the Internet of Things - October 2017Identity Federation: Citizen Consent and the Internet of Things - October 2017
Identity Federation: Citizen Consent and the Internet of Things - October 2017
Guy Huntington
 
Identity Federation: Governments and Economic Growth
Identity Federation: Governments and Economic GrowthIdentity Federation: Governments and Economic Growth
Identity Federation: Governments and Economic Growth
Guy Huntington
 
Identity federation = Biometrics and Governments Sept 2017
Identity federation = Biometrics and Governments Sept 2017Identity federation = Biometrics and Governments Sept 2017
Identity federation = Biometrics and Governments Sept 2017
Guy Huntington
 
Identity federation – Mitigating Risks and Liabilities
Identity federation – Mitigating Risks and Liabilities Identity federation – Mitigating Risks and Liabilities
Identity federation – Mitigating Risks and Liabilities
Guy Huntington
 
National citizen identity strategy
National citizen identity strategyNational citizen identity strategy
National citizen identity strategy
Guy Huntington
 
Proposed country identity strategy july 24, 2015
Proposed country identity strategy july 24, 2015Proposed country identity strategy july 24, 2015
Proposed country identity strategy july 24, 2015
Guy Huntington
 

More from Guy Huntington (8)

One pager - "Trust in an Interdependent World" - October 2017
One pager - "Trust in an Interdependent World" - October 2017One pager - "Trust in an Interdependent World" - October 2017
One pager - "Trust in an Interdependent World" - October 2017
 
Requirements for Successful Enterprises in a Federated Economy - October 2017
Requirements for Successful Enterprises in a Federated Economy - October 2017Requirements for Successful Enterprises in a Federated Economy - October 2017
Requirements for Successful Enterprises in a Federated Economy - October 2017
 
Identity Federation: Citizen Consent and the Internet of Things - October 2017
Identity Federation: Citizen Consent and the Internet of Things - October 2017Identity Federation: Citizen Consent and the Internet of Things - October 2017
Identity Federation: Citizen Consent and the Internet of Things - October 2017
 
Identity Federation: Governments and Economic Growth
Identity Federation: Governments and Economic GrowthIdentity Federation: Governments and Economic Growth
Identity Federation: Governments and Economic Growth
 
Identity federation = Biometrics and Governments Sept 2017
Identity federation = Biometrics and Governments Sept 2017Identity federation = Biometrics and Governments Sept 2017
Identity federation = Biometrics and Governments Sept 2017
 
Identity federation – Mitigating Risks and Liabilities
Identity federation – Mitigating Risks and Liabilities Identity federation – Mitigating Risks and Liabilities
Identity federation – Mitigating Risks and Liabilities
 
National citizen identity strategy
National citizen identity strategyNational citizen identity strategy
National citizen identity strategy
 
Proposed country identity strategy july 24, 2015
Proposed country identity strategy july 24, 2015Proposed country identity strategy july 24, 2015
Proposed country identity strategy july 24, 2015
 

Recently uploaded

ZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdfZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdf
Saeed Al Dhaheri
 
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdfPNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
ClaudioTebaldi2
 
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
ehbuaw
 
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptxPD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
RIDPRO11
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
SERUDS INDIA
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
Get Government Grants
 
2024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 372024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 37
JSchaus & Associates
 
Russian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale warRussian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale war
Antti Rautiainen
 
Transit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group MeetingTransit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group Meeting
Cuyahoga County Planning Commission
 
Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200
GrantManagementInsti
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
JSchaus & Associates
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Congressional Budget Office
 
kupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptxkupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptx
viderakai
 
NHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdfNHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdf
AjayVejendla3
 
Understanding the Challenges of Street Children
Understanding the Challenges of Street ChildrenUnderstanding the Challenges of Street Children
Understanding the Challenges of Street Children
SERUDS INDIA
 
The Role of a Process Server in real estate
The Role of a Process Server in real estateThe Role of a Process Server in real estate
The Role of a Process Server in real estate
oklahomajudicialproc1
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
850fcj96
 
State crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public financesState crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public finances
ResolutionFoundation
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
ARCResearch
 
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptxMHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
ILC- UK
 

Recently uploaded (20)

ZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdfZGB - The Role of Generative AI in Government transformation.pdf
ZGB - The Role of Generative AI in Government transformation.pdf
 
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdfPNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
PNRR MADRID GREENTECH FOR BROWN NETWORKS NETWORKS MUR_MUSA_TEBALDI.pdf
 
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
一比一原版(Adelaide毕业证)阿德莱德大学毕业证成绩单
 
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptxPD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
PD-1602-as-amended-by-RA-9287-Anti-Illegal-Gambling-Law.pptx
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
 
Get Government Grants and Assistance Program
Get Government Grants and Assistance ProgramGet Government Grants and Assistance Program
Get Government Grants and Assistance Program
 
2024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 372024: The FAR - Federal Acquisition Regulations, Part 37
2024: The FAR - Federal Acquisition Regulations, Part 37
 
Russian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale warRussian anarchist and anti-war movement in the third year of full-scale war
Russian anarchist and anti-war movement in the third year of full-scale war
 
Transit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group MeetingTransit-Oriented Development Study Working Group Meeting
Transit-Oriented Development Study Working Group Meeting
 
Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200Uniform Guidance 3.0 - The New 2 CFR 200
Uniform Guidance 3.0 - The New 2 CFR 200
 
2024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 362024: The FAR - Federal Acquisition Regulations, Part 36
2024: The FAR - Federal Acquisition Regulations, Part 36
 
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
Effects of Extreme Temperatures From Climate Change on the Medicare Populatio...
 
kupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptxkupon sample qurban masjid indonesia terbaru.pptx
kupon sample qurban masjid indonesia terbaru.pptx
 
NHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdfNHAI_Under_Implementation_01-05-2024.pdf
NHAI_Under_Implementation_01-05-2024.pdf
 
Understanding the Challenges of Street Children
Understanding the Challenges of Street ChildrenUnderstanding the Challenges of Street Children
Understanding the Challenges of Street Children
 
The Role of a Process Server in real estate
The Role of a Process Server in real estateThe Role of a Process Server in real estate
The Role of a Process Server in real estate
 
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
快速制作(ocad毕业证书)加拿大安大略艺术设计学院毕业证本科学历雅思成绩单原版一模一样
 
State crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public financesState crafting: Changes and challenges for managing the public finances
State crafting: Changes and challenges for managing the public finances
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
 
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptxMHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
MHM Roundtable Slide Deck WHA Side-event May 28 2024.pptx
 

Developing Countries National ICT Identity Governance Strategy

  • 1. Developing Countries National ICT Identity Governance Strategy Huntington Ventures Ltd. The Business of Identity Management May 2016
  • 2. This Deck… • Reviews the governance components required to successfully implement and maintain an e- government strategy: – Identity data governance – Identity infrastructure governance – Laws and regulations governance • So who am I?
  • 3. Guy Huntington Guy Huntington is a very experienced identity architect, program and project manager who has led, as well as rescued, many large Fortune 500 identity projects including Boeing and Capital One. He recently completed being the identity architect for the Government of Alberta’s Digital Citizen Identity and Authentication program.
  • 4. Identity Governance • Many people don’t understand the governance requirements to successfully implement and maintain an e-government strategy • There are several components: – Identity data governance – Identity infrastructure governance – Laws and regulations governance • Let’s start with identity data…
  • 5. Birth Name Change Gender Change Death Address Change Tel. Number Change Parent/Guardian Change Marriage Divorce Authoritative Source Authoritative Source Authoritative Source Authoritative Source Authoritative Source Authoritative Source Authoritative Source Authoritative Source Authoritative Source Business Processes Business Processes Business Processes Business Processes Business Processes Business Processes Business Processes Business Processes Business Processes Citizen Tombstone Identity Directory National Citizen Identity Lifecycle
  • 6. Who Has Legal Responsibility? • For each of the identity data on the left hand side of the previous screen, what government ministry is legally responsible for the data? • There are some new identity challenges that need to be addressed: – When a biometric is obtained from a person (e.g. infant, child or adult) which ministry is ultimately responsible for the biometric? – For Parents/legal guardians, which ministry is legally responsible for establishing this relationship – For citizen addresses and phone numbers, is there one ministry who will be legally responsible for the collection and management of this?
  • 7. Legal Vs. Operational Responsibility • Once the legal governance for each piece of identity data is determined, then there needs to be a determination of who is operationally responsible for the collection of it • This is the second column in the previous diagram, i.e. business processes • Here’s a hypothetical example: – When a student goes to school for their first day, they will provide a face and voice print biometric • The school district or, a specialized identity team, might be the people who actually collect the biometrics • HOWEVER, the ministry legally responsible for the biometric will likely not be the Education Ministry • So regulations and standards need to be created and then audited for the operational governance of each piece of identity data
  • 8. Shared Services • About 20 years ago, when large global enterprises began to digitize themselves and centralize operations, it became apparent there was a need for a shared services group to collectively manage IT infrastructure • Governments began to adopt this too • There needs to be a legal act and regulations regarding the formation of such an entity
  • 9. Identity Infrastructure et al • Shared Services are usually the group who is responsible for the operational management of the identity infrastructure – This includes data centres, clouds, operational data, high availability, etc. – It may or many not include the security management • Note that the Shared Services group only has operational responsibility and not legal ownership for each of the underlying identity data components – The legal ownership remains with the ministry responsible for each identity data
  • 10. BUT Sometimes Shared Services Is Legally Responsible… • Sometimes, the shared services group also looks after things like identity phone numbers and addresses, since there usually isn’t one ministry assigned to this • At the last government client I worked with, their shared services ministry not only managed the identity infrastructure but also was responsible for the centralized citizen telephone numbers and address collection and management – Citizens would go to one place online to change their addresses and phone numbers
  • 11. Government Identity Steering Committee • Many enterprises deploying global identity strategies quickly come to the realization that identity crosses all the enterprise administration silos – It’s thus not only operationally very important, BUT also politically important • It is not uncommon in large enterprises for them to form a identity steering committee to oversee identity infrastructure, identity investments, etc.
  • 12. Laws and Regulations • If one examines governments who have already successfully deployed national e-identity programs, like Estonia, one finds that a major component to do this is to create and/or change laws and regulations • The use of things like digital signatures, digital data retention, biometrics et al require well thought out acts and regulations • So your government will have to do this too • Let’s take a quick look at some of the laws that Estonia brought into being…
  • 13. Legal Framework • Digital Signatures Act - https://www.riigiteataja.ee/en/eli/508072014007/consolide • Public Information Act - https://www.riigiteataja.ee/en/eli/522122014002/consolide • Personal Data Protection Act - https://www.riigiteataja.ee/en/eli/529012015008/consolide • Act on Intellectual Property • Uniform Bases for Document Management Procedures - https://www.riigiteataja.ee/akt/119062012007 • Archives Act - https://www.riigiteataja.ee/akt/112072014028 • Principles of Estonian Information Policy (1998, 2004) • Action Plan of Estonian Information Policy – (eEstonia) (1998, 1999, 2000, 2001,2002, 2003, 2004, 2005, 2006...) • http://egov2.eu/knowledge-base/an-overview-of-estonian- e%E2%80%91government-development-and-projects/
  • 14. Identity and Credential Assurance • Your government will have to create two standards; identity and credential assurance • Identity assurance covers what documents and biometrics are allowable under what type of conditions to establish an identity • Credential assurance covers what type of credential is allowable for certain types of risk • There will have to be memorandums of understanding between the national government and local state and municipalities as well as crown corporations • These documents will also likely be legally referred to in federation agreements with third parties • As your country begins to work with other countries on recognizing national identities and verification, these documents must then become part of such agreements
  • 15. Federation Agreements • Your government’s e-identity strategy will also require the national identity and authentication service to work with third parties like banks, telcos, insurance companies, etc. • Each of these parties will have to sign a federation agreement with the government • This covers many things like identity and credential assurance, liability, responsibility for when a session is dropped part way through, etc.
  • 16. Governance Challenges • Creating, implementing and sustaining an e- identity strategy IS VERY CHALLENGING because: – Crosses over all ministry silo’s – Extremely public facing – Literally many thousands of decisions to be made as the systems are all interconnected – The system is prone to attack from organized crime and foreign intelligence agencies – Large budgets and time cycles involved
  • 17. Strong, Sustained Leadership • Therefore, from the top of your government on down, all must be not only aware but take a strong, sustained leadership role • It’s when times get tough, like a denial of service attack, etc. that the top leaders have to be there to calm the public and ensure the system will be properly maintained
  • 18. There’s A Lot To Governance • It has been my own past experience that most enterprises commencing large, global, identity programs don’t understand the implications of governance • It’s usually tacked on towards the end of the project • THIS IS A BIG MISTAKE since many projects go over time and budgets as they finally realize governance is complex and must be addressed
  • 19. Governance Should Be Addressed First • At the very least, governance should be one of the main project tracks • Many different government governance initiatives must be launched in parallel to the business process and technical activities of the teams • Governance work takes time – so plan for it • If you do this, then there is an excellent chance your identity program will roll out the door on time and on budget
  • 20. Changing the World a Bit • Guy wants to change the world a bit by assisting developing countries to leapfrog ahead of most western societies by: – Leveraging citizen’s use of the cell phone and their voice to then access online government services – Creating a new model for educating students – Leverage existing technology to deliver healthcare more effectively
  • 21. If You Thought This Is Thought Provoking • Then please pass along a link to the presentation to people in your country who might be interested • You can contact me at: – guy@hvl.net – 1-604-861-6804 – Via LinkedIn (https://ca.linkedin.com/in/ghuntington) • Thanks for your time!