<?xml version="1.0" encoding="UTF-8"?>
<StrategicPlan xsi:schemaLocation="http://www.stratml.net  http://xml.gov/stratml/references/StrategicPlan.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.stratml.net"><id/><Name>About NIEF</Name><Description>To ensure public safety and uphold law in the face of threats that have become geographically distributed and increasingly mobile, it is imperative that criminal justice and law enforcement agencies in the U.S. and around the world communicate with each other, sharing critical information as needed throughout all aspects of the criminal justice process. But sharing information across jurisdictional boundaries is fraught with practical challenges at many levels, including both policy and technology. The National Identity Exchange Federation (NIEF) seeks to address this problem.</Description><OtherInformation/><StrategicPlanCore><Organization><Name>National Identity Exchange Federation</Name><Acronym>NIEF</Acronym><Identifier>_1f566c4c-4128-11e4-a0a9-58edd4b69755</Identifier><Description>The National Identity Exchange Federation Center (“NIEF Center”) is a non-profit 501(c)(3) legal entity and a subsidiary of the Georgia Tech Applied Research Corporation... While NIEF is run as a 501(c)(3) legal entity, it is really a justice-based identity federation which has been constructed using the Global Federated Identity and Privilege Management (GFIPM) standards to provide an operational, national identity federation for the purpose of secure information sharing within the  justice, homeland security, emergency management, and public safety communities.</Description><Stakeholder><Name>Georgia Tech Applied Research Corporation</Name><Description>The NIEF Center is managed and operated through the Georgia Tech Research Institute (GTRI) under contract with the U.S. Dept. of Justice, in conjunction with GTRI’s role in supporting the Global Federated Identity and Privilege Management (GFIPM) program.</Description></Stakeholder><Stakeholder><Name>Law Enforcement Community</Name><Description>NIEF is a collection of agencies in the U.S. that have come together to share sensitive law enforcement information. It was created in 2008 as an outgrowth of the Global Federated Identity and Privilege Management (GFIPM) program, which seeks to develop secure, scalable, and cost-effective technologies for information sharing within the law enforcement and criminal justice communities based on the paradigm of federated identity and privilege management.</Description></Stakeholder><Stakeholder><Name>Criminal Justice Community</Name><Description/></Stakeholder><Stakeholder><Name>Global Federated Identity and Privilege Management (GFIPM) Program</Name><Description>NIEF maintains a symbiotic relationship with GFIPM, leveraging existing GFIPM work products and also serving as a source of real-world feedback to drive the development of new GFIPM work products.</Description></Stakeholder><Stakeholder><Name>Bureau of Justice Assistance</Name><Description>This Web site is funded in part through a grant from the Bureau of Justice Assistance, Office of Justice Programs, and U.S. Department of Justice. Neither the U.S. Department of Justice nor any of its components operate, control, are responsible for, or necessarily endorse, this Web site (including, without limitation, its content, technical infrastructure, and policies, and any services or tools provided).</Description></Stakeholder><Stakeholder><Name>NIEF Members</Name><Description>Membership in NIEF is open to all U.S. justice, homeland security, emergency management, and public safety agencies, as well as other agencies and organizations that provide information services to these communities...

The following agencies are currently members of the National Identity Exchange Federation (NIEF), or are in the process of joining NIEF.</Description></Stakeholder><Stakeholder><Name>Criminal Information Sharing Alliance (CISA)</Name><Description/></Stakeholder><Stakeholder><Name>Pennsylvania Justice Network (JNET)</Name><Description/></Stakeholder><Stakeholder><Name>Regional Information Sharing Systems (RISS)</Name><Description/></Stakeholder><Stakeholder><Name>U.S. Department of Homeland Security (DHS)</Name><Description/></Stakeholder><Stakeholder><Name>Los Angeles County</Name><Description/></Stakeholder><Stakeholder><Name>Federal Bureau of Investigation (FBI)</Name><Description/></Stakeholder><Stakeholder><Name>Institute for Intergovernmental Research (IIR)</Name><Description/></Stakeholder><Stakeholder><Name>Tennessee Bureau of Investigation</Name><Description>Tennessee Methamhetamine and Pharmaceutical Task Force</Description></Stakeholder><Stakeholder><Name>Verisk Crime Analytics</Name><Description/></Stakeholder><Stakeholder><Name>Tennessee Integrated Criminal Justice Program</Name><Description/></Stakeholder><Stakeholder><Name>Texas Department of Public Safety (TX DPS)</Name><Description/></Stakeholder></Organization><Vision><Description/><Identifier>_1f566e40-4128-11e4-a0a9-58edd4b69755</Identifier></Vision><Mission><Description>To address the challenges associated with sharing information across jurisdictional boundaries</Description><Identifier>_1f566f44-4128-11e4-a0a9-58edd4b69755</Identifier></Mission><Value><Name/><Description/></Value><Goal><Name>Identity &amp; Privilege Management</Name><Description>Develop secure, scalable, and cost-effective technologies for information sharing within the law enforcement and criminal justice communities based on the paradigm of federated identity and privilege management.</Description><Identifier>_1f5676d8-4128-11e4-a0a9-58edd4b69755</Identifier><SequenceIndicator/><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/><Objective><Name>User Identity Information</Name><Description>Protect user identity information.</Description><Identifier>_1f5676d9-4128-11e4-a0a9-58edd4b69755</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>How does NIEF protect user identity information? NIEF has adopted the GFIPM suite of technical standards, which are built on the Security Assertion Markup Language (SAML) and require the protection of personally identifiable information (PII) in transit using FIPS 140-2 compliant cryptography.</OtherInformation></Objective><Objective><Name>Authorization, Provisioning &amp; Auditing</Name><Description>Use of PII to making authorization decisions, dynamically provisioning accounts, and performing audit logging.</Description><Identifier>_1f5676da-4128-11e4-a0a9-58edd4b69755</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>What can NIEF partners do with the identity information? NIEF service providers are required by policy to limit their use of PII to making authorization decisions, dynamically provisioning accounts, and performing audit logging. Any additional use of PII about a user is prohibited unless the following conditions are met: (1) the user’s IDP must agree to it, and (2) it must be disclosed to the user.</OtherInformation></Objective><Objective><Name>Partnerships</Name><Description>Partner with other information-sharing federations.</Description><Identifier>_1f5676db-4128-11e4-a0a9-58edd4b69755</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder><Name>Trusted Identity Broker Organizations</Name><Description>A Trusted Identity Broker Organization (TIBO) maintains a relationship with agencies in both federations, and bridges the trust gap between the two. A TIBO joins NIEF on behalf of the agencies that it represents, and asserts identity information to NIEF service providers for those agencies’ users.</Description></Stakeholder><OtherInformation>Does NIEF partner with other information-sharing federations? Yes. NIEF supports “inter-federation” connections via a “Trusted Identity Broker” model, in which an agency acts as a broker between one federation and another. </OtherInformation></Objective><Objective><Name>Data Exchange Agreements</Name><Description>Enable a wide range of secure information exchanges among member agencies.</Description><Identifier>_1f5676dc-4128-11e4-a0a9-58edd4b69755</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder><Name>NIEF Partners</Name><Description/></Stakeholder><OtherInformation>Can I create separate data exchange agreements with NIEF partners?Yes. The primary goal of NIEF is to enable a wider range of secure information exchanges among its member agencies. In support of this goal, NIEF provides a basic infrastructure consisting of governance, policies and procedures, cryptographic trust, and open standards for securely sharing identity information about users and non-user (system) entities. NIEF members are encouraged to leverage this federated security infrastructure to meet their business information exchange goals. For example, NIEF enables and supports all of these data exchange relationships.
* Some member agencies operate on a fee-based service model, and want to charge other member agencies for access to services.
* Some member agencies regard NIEF membership as a minimal security requirement and impose additional peer-to-peer requirements on other NIEF members as a prerequisite for information exchanges with those agencies.
* Some member agencies join NIEF despite having pre-existing business relationships with one or more other NIEF members and technology infrastructure in support of those relationships.
In these cases and others, NIEF seeks to enable new, more efficient ways of sharing data where possible, while also supporting pre-existing relationships and business processes where required.</OtherInformation></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate/><EndDate/><PublicationDate>2014-09-20</PublicationDate><Source>https://nief.gfipm.net/</Source><Submitter><FirstName>Owen</FirstName><LastName>Ambur</LastName><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></StrategicPlan>