andrea beesing karen schultz thomas black. 2 cornell case study: student identity life cycle andrea...

37
Andrea Beesing Karen Schultz Thomas Black

Upload: brenda-walsh

Post on 25-Dec-2015

222 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Andrea BeesingKaren SchultzThomas Black

Page 2: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

2

Cornell Case Study: Student Identity Life Cycle

Andrea Beesing

Assistant Director, IT Security

Cornell University

[email protected]

Page 3: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

3

The Cornell student context

• > 100,000 applicants• About 20,000 students enrolled• Around-the-world sites – Ithaca, NY; New

York City, and Washington, D.C. Doha, Qatar, Singapore, Beijing; Paris, France; Rome, Italy; Seville, Spain; London, England; Dublin, Ireland; and Geneva, Switzerland and Geneva, NY, and others

Page 4: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

4

Student Services and Identity Management Shared Goals

• Provide access for the right people to the right information, at the right time, from any place

• Replace paper-based, manual processes with online self-service options

• Improve user experience when accessing services, regardless of who hosts service

• Protect security and privacy

Page 5: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

5

Student identity life cycle

Prospect

Applicant

AcceptedApplicant

New Student

Alumnus

1

2

3

4

6

Time

Student5

Page 6: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

6

Focus on challenges at this phase

Applicant

AcceptedApplicant

New Student

2

3

4

•Authentication required•Short timeline•Remote locations•Volume of applicants

Time

Page 7: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

7

Undergraduate Applicant Communications

What When How

ApplicantID and activation code

Upon processing of application

Email or letter

Status of application, missing items

Through application deadline

Online using ApplicantID

Admission decision March Outsourced to ApplyYourself

Page 8: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

8

Accepted Applicants Communications

What When How

Class of 20xx End of March Class of site using ApplicantID

Cornell Bound End of March Cornell Bound site using Applicant ID

Housing information

End of March Online using ApplicantID

Financial Aid award info

End of March By letter – This takes too long!

Page 9: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

9

New Student Communications

What When How

NetID and activation code

Early April through early August

By letter – This takes too long!

IT policy

Copyright awareness

At NetID activation

Online using Manage Your NetID

Health History

Cornell Card

Dining Plan

Early April through August

Online using NetID

Page 10: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

10

Current Challenge for Cornell

• ApplicantID is low assurance (bronze) credential– Issued via email with attendant exposure– Is financial aid information too sensitive to release solely

on the basis of this credential?

• NetID is higher assurance (silver) credential– Releasing this information solely on the basis of

successful authentication with the ApplicantID reduces it to bronze

– How can we balance customer needs with security and strategic goals?

Page 11: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

11

Addressing the Challenge

• Exploring use of cell phone and telephone number of record for communicating temporary password

• Considering what additional confirmation of identity can used in conjunction with the ApplicantID to release financial aid data– Capture secret with common app supplement– Tie the use of the ApplicantID to a financial

transaction

Page 12: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

12

Guidelines for IdM practice

• InCommon Identity Assurance Profiles

http://www.incommonfederation.com/• NIST Electronic Authentication Guide

http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf

Page 13: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Karen SchultzUniversity Registrar

Penn State UniversityCAMP, February 4 – 6, 2009

Page 14: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Why do students leave?Why do students leave?

GraduateWithdrawLeave of absenceStop out temporarilyTransfer to another institutionDismissed for academic or

disciplinary reasons

Page 15: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Former students need services tooFormer students need services tooTranscriptsVerification of enrollment and/or

degreeReporting CE credits to state Dept of

Ed for teacher certificationLoan billing and repaymentPayment of delinquent balancesAccess to 1098T tax informationAid exit counseling

Page 16: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Transcript serviceTranscript service

FERPA requires signatureCurrent students can authenticate

with userid and password; electronic signature permits online ordering

How to provide this service to students not in attendance

Page 17: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Former students’ accountsFormer students’ accountsFormer student with active account

Account expires 6 months after graduation or 45 days after failure to enroll

Former student who had account at one timeForgotten userid and passwordAccount expired

Former student who never had account

Page 18: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

No account . . . No service?No account . . . No service?Must former students order

transcripts on paper?People expect online servicesOnline services reduce workloadCan we establish mechanism to

provide account which satisfies electronic signature requirement?

Page 19: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

How it works nowHow it works nowFormer student without still-active

account must create new accountSeparate account system New userid and password

How do we ensure that account qualifies as electronic signature?

Former student not on campus, cannot provide photo ID

Page 20: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

How it works nowHow it works now

Former student must complete form and sign, then fax to us

When signed form is received, we activate account and notify former student

Former student can use account to visit web site and place order

Page 21: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Better solutionBetter solutionStudent leaves universityRetains userid and passwordAccess to

Transcript requestEnrollment/degree verificationFinancial recordsLoan repaymentAid exit counseling

Page 22: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

In a perfect world . . . In a perfect world . . . Student has one account for lifeAccount remains active but access

to services varies based on student status

Account migration seamless for student

Provides access to appropriate services at appropriate time

Page 23: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

In a more perfect world . . .In a more perfect world . . .Single account established as

prospect/applicantAdmitted students use account to

access pre-enrollment services (AlcoholEdu), registration

Enrolled students have access to all services

Former students order transcript

Page 24: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Are we there yet?Are we there yet?

Penn State has launched IdM project

Beginning with student lifecycleFirst step is mapping

Page 25: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Thomas BlackUniversity RegistrarStanford University

CAMP, February 4 – 6, 2009

Page 26: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Three Use CasesThree Use CasesFederation Model:

standards compliant, predefined trust relationship, and no separate arrangement

A.S.P.s

Admissions Service Providers

Authorization of identity in perpetuity

Page 27: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

A.S.P.s A.S.P.s (Application Service Providers)(Application Service Providers)CollegeNet: What Do You Think?

On-line Course Evaluation SystemStudents and Faculty Access Surveys and Compiled Reports

National Student ClearinghouseOn-line Enrollment Certification & Degree

VerificationStudents and Staff AccessStudent Data

Page 28: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

W.D.Y.T. W.D.Y.T. (course evaluations)(course evaluations)

Point of Dependency: File Exchanges

Participants must be introduced to the system in advance of launching the site each term.

Enrollment and Instructor data must be current at the 11th hour...

Page 29: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Data File ExchangesData File ExchangesMust send files to CollegeNet to

“prime” W.D.Y.T.

Page 30: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Portal Log-inPortal Log-in

Page 31: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Local AuthenticationLocal Authentication

Page 32: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Navigate to CoursesNavigate to Courses

Page 33: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Vendor’s ServiceVendor’s Service

Page 34: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

N.S.C.N.S.C.Manual Account Setup and Active

Account Problem:

Institutional contact faxes the identity information to NSC to set up accounts.

Institutional contact is charged with notifying NSC if an account should be removed

Page 35: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

LSAC & AMCASLSAC & AMCASLocal authentication and authorization…

for transcripts

Students,Graduate

sStanford

University

AMCAS /LSDAS /

any school

add info request document

electronicrequest & response

identity data

request

elect. doc. xmision

Page 36: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University

Ongoing Identity ServicesOngoing Identity ServicesPermanently Active Authorization Services

School to School: transcripts & certifications

Out-of-Boundary?Vendors: music; videos, cars; tech

components; journal clearinghousesServices: insurance

Page 37: Andrea Beesing Karen Schultz Thomas Black. 2 Cornell Case Study: Student Identity Life Cycle Andrea Beesing Assistant Director, IT Security Cornell University