Skip to content

Commit

Permalink
Merge pull request #592 from GSA/1002-h1-seo-updates
Browse files Browse the repository at this point in the history
1002-h1-seo-updates
  • Loading branch information
JBPayne007 authored Oct 2, 2023
2 parents b1000ee + b64900a commit 500e783
Show file tree
Hide file tree
Showing 3 changed files with 15 additions and 15 deletions.
8 changes: 4 additions & 4 deletions _arch/icamsolutions.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ This section contains information on the GSA ICAM Solutions Catalog and GSA ICAM
- [GSA Solutions and Shared Services Roadmap](#gsa-icam-solutions-and-shared-services-roadmap) - A roadmap for providing or updating GSA Multiple Award Schedule solutions and shared services that allow agencies to achieve the outcomes in OMB ICAM policy and NIST standards and guidelines.
- [GSA Solutions Catalog](#gsa-icam-solutions-catalog) - A consolidated catalog of existing GSA Multiple Award Schedule ICAM solutions and shared services.

# GSA ICAM Solutions and Shared Services Roadmap
## GSA ICAM Solutions and Shared Services Roadmap

[This document]({{site.baseurl}}/docs/gsa-icam-roadmap.pdf){:target="_blank"}{:rel="noopener noreferrer"} provides a response to the Office of Management and Budget (OMB) memorandum M-19-17, “Enabling Mission Delivery through Improved Identity, Credential, and Access Management.” The memorandum outlines the federal government's Identity, Credential, and Access Management (ICAM) policy and establishes government-wide responsibilities that include the General Services Administration (GSA). GSA is specifically tasked with developing and maintaining "a roadmap for providing or updating GSA solutions and shared services that allow agencies to achieve the outcomes in OMB ICAM policy and NIST standards and guidelines.” GSA analyzed the current state of ICAM solutions and shared services and developed activities to address identified gaps based on the ICAM Services Framework.
The roadmap aligns actions to the following three phases:
Expand Down Expand Up @@ -163,7 +163,7 @@ The following table provides a summary of the roadmap activities. This roadmap i
</tbody>
</table>

# GSA ICAM Solutions Catalog
## GSA ICAM Solutions Catalog

On May 21, 2019, the Office of Management and Budget (OMB) released a new Identity, Credential, and Access Management (ICAM) policy (M-19-17). This memo mandated that GSA publish “a consolidated catalog of existing ICAM solutions and shared services.” The attached catalog includes several special item numbers (SINs) within the Multiple Award Schedules (MAS). Please note that MAS has recently gone through a consolidation; therefore, new SIN designations have been included.

Expand Down Expand Up @@ -256,7 +256,7 @@ Most MAS ICAM solutions can be purchased on GSA eBuy, an online Request for Quot
</tr>
</table>

# GSA eBuy Ordering Instructions For Agencies
## GSA eBuy Ordering Instructions For Agencies

Buyers are required to register on GSA Advantage. Buyers can use the same User ID and Password on GSA eBuy and GSA Advantage. Vendor listings change regularly and are available in eBuy. Below are modified steps to access the GSA eBuy Buyer website:

Expand All @@ -271,7 +271,7 @@ Buyers are required to register on GSA Advantage. Buyers can use the same User I
9. Submit – Review and submit the RFQ/RFI.


# Additional Resources
## Additional Resources

- [GSA eBuy Job Aid](https://www.ebuy.gsa.gov/ebuy/assets/content/eBuy-Buyer_jobaid.pdf){:target="_blank"}{:rel="noopener noreferrer"}{:class="usa-link usa-link--external"}
- [GSA ICAM](https://www.gsa.gov/technology/government-it-initiatives/identity-credentials-and-access-management){:target="_blank"}{:rel="noopener noreferrer"}{:class="usa-link usa-link--external"}
Expand Down
14 changes: 7 additions & 7 deletions _ficampmo/gsapkissp.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,7 @@ subnav:
| 1.0 | 02/14/2023 | Initial draft | -->


# Overview
## Overview

The General Services Administration (GSA), Office of Government-wide Policy, manages the Public Key Infrastructure (PKI) Shared Services Provider (SSP) program. The primary program focus is to help agencies meet the policy intent of Homeland Security Presidential Directive 12, as well as achieve digital signature interoperability.

Expand All @@ -87,7 +87,7 @@ A GSA PKI SSP is a commercial PKI provider who has completed Federal PKI complia
- [Section 2](#section-ii-ssp-application-and-maintenance-activities) -Defines the application and ongoing maintenance process to apply and stay in the GSA PKI SSP Program.
- [Section 3](#section-iii-digital-certificate-services) -Lists available services that a SSP should offer.

# Audience
## Audience

This document is primarily for the following audience:

Expand All @@ -97,7 +97,7 @@ This document is primarily for the following audience:

If you have questions about this document or the outlined process, contact [[email protected]](mailto:[email protected]).

# Section I: GSA PKI SSP Program
## Section I: GSA PKI SSP Program

The GSA SSP Program has a long history of successfully providing digital certificate services for employees, contractors, and affiliates. The program was started in December 2004 when the Office of Management and Budget (OMB) issued a directive, M-05-05, directing federal agencies to buy their digital certificate services through the SSP Program. Almost 20 years later, the program is a cornerstone for some federal agencies despite the drive to expand new services in a thin market.

Expand Down Expand Up @@ -144,7 +144,7 @@ The GSA, Office of Chief Information Security Officer (OCISO) provides securit

The GSA Federal Acquisition Service (FAS) connects government buyers with the GSA PKI SSPs. The FAS organization captures the GSA PKI SSP services and sets prices, terms, and conditions of the Special Item Number (SIN) on the [GSA Multiple Award Schedule](https://www.gsaelibrary.gsa.gov/ElibMain/sinDetails.do?scheduleNumber=MAS&specialItemNumber=541519PKI&executeQuery=YES){:target="_blank"}{:rel="noopener noreferrer"}{:class="usa-link usa-link--external"}. The SSP SIN is intended to make it easier for potential buyers to search for the digital certificate services offered by the GSA PKI SSPs.

# Section II: SSP Application and Maintenance Activities
## Section II: SSP Application and Maintenance Activities

Federal agencies requiring digital certificate services from a SSP will send a Request for Quotation or a Request for Proposal based on the SSP SIN—sending alerts to SSPs. Federal agencies can expect a response from the SSPs that reflects the due diligence completed by the Federal Acquisition Service (FAS) to offer SSPs that satisfy federal requirements.

Expand Down Expand Up @@ -275,7 +275,7 @@ The GSA PKI SSP Program Office and GSA’s security team perform continuous mon

The vendor must maintain its GSA PKI SSP MAS Contract to stay in compliance with the GSA PKI SSP MOA. If a vendor cannot maintain a GSA PKI SSP MAS Contract, the PKI vendor will coordinate decommission activity through the GSA PKI SSP Program Office with customer agencies, the Federal PKI Policy Authority, and supporting GSA offices.

# Section III: Digital Certificate Services
## Section III: Digital Certificate Services

While the SSP Program has primarily focused on digital certificates for Personal Identity Verification (PIV) cards, the [COMMON CP] provides opportunities (and supporting Object Identifiers (OIDs) for SSPs to offer additional services to federal agencies.

Expand Down Expand Up @@ -335,11 +335,11 @@ A digital signature certificate is used to digitally sign documents such as PDF

Key Management Services store and manage private keys associated with encryption certificates. Examples might include Key Escrow and Recovery, Key History, and Data Decryption Services.

# Conclusion
## Conclusion

GSA established the GSA PKI SSP Program to help agencies identify and procure federally-compliant PKI services and digital certificates. There may be multiple types of PKI SSPsrs, but only one type of GSA PKI SSP. This clear definition not only helps agencies identify approved services, but also leverage the governmentwide acquisition vehicles for customer agencies to receive consistent pricing, terms, and services. The GSA PKI SSP Program Office maintains the SSP Program and coordinates government activity on behalf of the GSA PKI SSPs.

# Appendix A - Sample MOA
## Appendix A - Sample MOA

<p align="center">
<b>
Expand Down
8 changes: 4 additions & 4 deletions _partners/fips201-apl.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,11 +30,11 @@ This page is for program managers and acquisition professionals looking for appr

If you think this page is missing something, [contact us]({{site.baseurl}}/contact-us) to ask a question.

# How To Purchase
## How To Purchase

Visit the [Buy Page]({{site.baseurl}}/acquisition-professionals/) to view FICAM products, services and purchasing guidance.

# Approved Products - Physical Access Control Systems
## Approved Products - Physical Access Control Systems

The Physical Access Control System (PACS) products listed under the “Approved” section below have met the security and functional requirements set by GSA’s FIPS 201 Evaluation Program, and have been approved for use by the Federal Government. Note that the Approved PACS Products below are grouped by either 13.01 or 13.02 topologies:

Expand Down Expand Up @@ -140,7 +140,7 @@ The Physical Access Control System (PACS) products listed under the “Approved

Cycle 2 and 3 updates are moved to the front of the test queue once they are installed. While between cycles, solutions may not appear here.

# Approved Products - PIV Smart Cards
## Approved Products - PIV Smart Cards

The Personal Identity Verification (PIV) cards listed below are approved for FICAM implementation under the FIPS 201 Evaluation Program. These are blank PIV cards available for purchase. A PIV service provider will personalize these blank cards for federal agencies and contractors. PIV service providers are required to use PIV cardstock from the Approved Products List (APL).

Expand Down Expand Up @@ -200,7 +200,7 @@ Submit the memo to [GSA’s Associate Administrator for Government-wide Policy (

Note that GSA will provide the Office of the Federal Chief Information Officer (OFCIO) at the Office of Management and Budget (OMB) with copies of all memos submitted.

# Removed Product List
## Removed Product List

{% assign categories = "" | split: "" %}
{% for rpl in site.data.fips201rpl %}
Expand Down

0 comments on commit 500e783

Please sign in to comment.