Guidelines for the Authorization of Personal Identity Verification Card Issuers (PCI) and Derived PIV Credential Issuers (DPCI)
Ramaswamy Chandramouli, Dennis Bailey, Nabil Ghadiali, Dennis Keith Branstad · 2008
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) stimulates U.S. economic growth and industrial competitiveness through technical leadership and collaborative research in critical infrastructure technology, including tests, test methods, reference data, and forward-looking standards, to advance the development and productive use of information technology.To overcome barriers to usability, scalability, interoperability, and security in information systems and networks, ITL programs focus on a broad range of networking, security, and advanced information technologies, as well as the mathematical, statistical, and computational sciences.The Special Publication 800-series reports on ITL's research, guidelines, and outreach efforts in information system security, and its collaborative activities with industry, government, and academic organizations. Authority, Usage, and RevisionsThis document has been developed by the National Institute of Standards and Technology (NIST) in furtherance of its statutory responsibilities under Homeland Security Presidential Directive 12, signed August 27, 2004.NIST is responsible for developing standards and guidelines, including specifying minimum requirements, for providing adequate information security for all organizational operations and assets, but such standards and guidelines shall not apply to national security systems.This guideline is consistent with the requirements of the Office of Management and Budget (OMB) Circular A-130, Section 8b(3), Securing Agency Information Systems, as analyzed in A-130, Appendix IV: Analysis of Key Sections.Supplemental information is provided A-130, Appendix III.This document has been prepared for use by Federal agencies but it also may be used by nongovernmental organizations on a voluntary basis.Nothing in this document should be taken to contradict standards and guidelines made mandatory and binding on Federal agencies by the Secretary of Commerce under statutory authority.This document should not be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, Director of the Office of Management and Budget, or any other Federal official.This document is not subject to copyright but attribution for its adoption and use would be appreciated by NIST.