enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

U.S. Department of Health and Human Services

Embracing Technology for Improved Identity Access Management

Adam McBride, HHS ICAM/IdAM Manager, U.S. Department of Health and Human Services

Adam McBride works with multiple stakeholders across the U.S. Department of Health and Human Services (HHS) to enable strong identity access management (IAM) controls for its applications. With years of experience working with security systems, McBride makes IAM seamless and is always prepared to overcome any challenge that comes with his line of work. In an interview with Enterprise Security Magazine, Adam McBride talks about the importance of IAM and the need for improved data security in the field.

What Are Some Of Your Roles And Responsibilities As The Senior It Program Manager At HHS?

I work in the HHS Program Support Center and oversee IT programs like IAM and HSPD-12. We provide shared services for HHS. I mostly work with internal and external identity access, and we try to build and improve new and existing projects in the system. We also carry out a federated government identity approach to prevent fraud.

What Major Challenges Does The Department Face Today, And How Do You Deal With Them?

Post-pandemic, we embraced a hybrid working model, and carrying out the office procedures remotely had been quite challenging. As we are actively hiring, the recruitment process has become complicated, with candidates finding it difficult to travel and limited available in- processing sites for new staff to go to in person. We are currently working on several projects to deal with this issue. One particular project that we look forward to is establishing remote onboarding kiosks. These kiosks will also help us with onboarding through Supervised Remote In-Person (SRIP) processing. These kiosks will be established in three locations, two in Washington, D.C., and one in Atlanta, GA. The entire verification process can be carried out by following the instructions on the machines and assistance from the SRIP Agent. The kiosks will scan the candidates' required documents and fingerprints and also capture the candidates’ pictures. Once it is complete, the encrypted data packet is sent to our enrollment system for processing. The information sent to our enrollment system will be ready for background checks and further employee in-processing. Once the reviews come back clear, the individual can obtain credentials, whether a PIV card or PKI hard token.

What Are The Technological Trends That You See Impacting The Public Sector?

The mobile driver’s license (mDL) is a game changer in HHS and other government agencies. We want to allow the public to access certain government benefits or information using mDL. It is convenient for the public to use an identity-proofing process they have already completed by getting their Real ID state-issued mDL. Multi-factor authentication is a feature that could be added, which the service providers can quickly do.

What Would Be Your Advice To The Budding Professionals In The Public Sector?

Make sure that you always do the right thing and check everything. For instance, many vendors could provide the technology systems the government needs. You might think that a system will meet your needs when you see it, but most of the time, they oversell and under-deliver it. You need to be aware of the priorities and not make decisions just because it seems good.

What, According To You, Is Essential For The Public To Understand About Identity Proofing?

There is a misconception that the government is trying to steal people’s data. The public needs to understand that by identity proofing, we’re trying to ensure that your data is safe and that you are who you say you are. Better marketing tactics should be employed to bring more clarity about identity proofing and to remove the public’s apprehensions about using Identity systems.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief