FB pixel

CyberArk IAM authentication FIDO2 certified

Passwordless potential showcased in USDA adoption
CyberArk IAM authentication FIDO2 certified
 

Identity cybersecurity company CyberArk has received FIDO2 certification for its access management product, confirming that it complies with the FIDO Alliance standards for secure authentication.

The certification was awarded to CyberArk Workforce Identity, an enterprise identity and access management product that is part of the CyberArk Identity Security Platform.

The Israel and U.S.-headquartered information security firm has made a string of acquisitions since its Nasdaq IPO in 2013, including identity management platform Idaptive in 2020. The acquisition allowed CyberArk to boost its identity management capabilities.

The company’s latest acquisition is machine identity management and identity and access (IAM) firm Venafi which was announced in October this year.

“From day one, CyberArk has been a security-first company,” says Peretz Regev, chief product officer at CyberArk. “As cyber threats continue to evolve, increasingly targeting identities and identity infrastructure, it is crucial that we continue to provide our customers with industry-leading tools to secure every identity with privilege controls, on the endpoint and in every application.”

In October, the company also integrated technology from enterprise identity authentication company Badge to eliminate the storing of user credentials.

FIDO certification represents a significant market opportunity for CyberArk, given the widespread adoption of the passwordless approach in the U.S. and elsewhere, not just amongst businesses but also public sector organizations.

A tale of FIDO and the USDA

The U.S. Department of Agriculture is a case in point. The USDA had trouble issuing personal identity verification (PIV) cards to all its workers, because the agency employs large numbers of seasonal workers who are ineligible for PIV cards. Yet the cards were essential to access government systems, and so the USDA allowed these workers to bypass the card, obtaining a user ID and password instead.

However, issues quickly arose when it came to light that sophisticated phishing campaigns could make such credentials vulnerable. USDA needed phishing-resistant multi-factor authentication (MFA). Furthermore, some USDA employees work in lab environments that require decontamination procedures that the standard identification card cannot survive. USDA sought a technical solution that provides the same protections as a PIV but withstands decontamination.

USDA adopted FIDO capabilities as its centralized technology architecture already supported it. Using cryptographic keys on user devices, FIDO’s authentication tools are phishing-resistant and allow the authentication of user identities without using passwords. To date, some 40,000 registered users, some of whom have previously required PIV exemptions,  have accessed USDA’s network using FIDO without the risks involved using usernames and passwords.

FIDO depends on non-password authentication factors like biometrics. FIDO passkeys have a growing profile among organizations and awareness amongst the general public.

The USA’s Cybersecurity and Infrastructure Security Agency has a full report on USDA’s successful FIDO implementation here.

Related Posts

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Ring and Flock call off integration as scrutiny of camera-to-police partnership intensifies

Amazon-owned Ring and Flock Safety have canceled their planned partnership, stepping back from an integration that would have linked one…

 

MOSIP pursues democratization of digital identity with unconference conversations

A democratic vision of digital identity is central to the non-profit, open-source mandate of MOSIP. As the organization and the…

 

Liveness is king: FaceTec’s Jay Meier in conversation with Chris Burt 

It’s best, says Jay Meier, to think about identity management as a system of symbiotic systems. Which is to say,…

 

Ofcom fines Kick, threatens 4chan as OSA enforcement steadily dials up

UK regulator Ofcom has faced criticism for being too slow and lenient with its power to enforce the Online Safety…

 

Innovatrics, ROC improve rankings in NIST ELFT, rising to 2 and 3 respectively

Innovatrics is celebrating success in the latest National Institute of Standards and Technology (NIST) Evaluation of Latent Fingerprint Technologies (ELFT)…

 

Meta plans launch of facial recognition to smart glasses in ‘dynamic political environment’

Meta is reportedly planning to roll out facial recognition capabilities for its smart glasses as early as this year, taking…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events