ID Management at UGA

EITS remains committed to helping all areas comply with the directive of our Senior Vice President to eliminate the use of Social Security Numbers as a means of identifying members of the UGA community. EITS has developed this document to introduce you to a number of tools that we have designed to be used within your business processes to reduce or eliminate the need for SSNs.

ID Management Project

  1. Phase 1 (Completion: Aug 2009)

Establish the identity management infrastructure and provide tools to eliminate the use of SSN at UGA. (e.g., SSN translation database; SSN translation Web forms; web-based workflows to add, remove, and modify identities.)

  • Establish an identity life cycle to add, remove, and change users from the identity store
  • Address risks associated with MyID to CAN/SSN
  • Provide automated processes to manage/remove SSN
  • Avoid duplicate identity management systems
  • Improve security for over 300 of the highest risk servers storing SSNs at UGA (e.g., eliminate users from the system with terminated accounts)
  1. Phase 2 (Est. Completion: Highest Risk system, Jun 2010; All Systems, Dec 2011)

Utilizing the tools and managed processes developed in Phase 1, implement SSN replacement in highest risk distributed systems and/or processes. The prioritization of these systems is running concurrently with Phase 1. (e.g., Graduate School, Terry, MyID, Bigcard, Help Desk authentication, Parking Services, among many others.)

  • Identify SSN use in distributed systems across UGA
  • Assess risk and prioritize SSN removal efforts
  • Mitigate SSN risk in priority order

SSN Out of Business Processes: Core/Enterprise and Mainframe systems (Est. Completion: Dec 2012)

Reduce the use of SSN in administrative business processes that use the Core Mainframe systems. (e.g., Student, Student Financial, Human Resources, Payroll, and Finance business processes.)

  1. SSN Out of business Processes
  • Identify SSN use in administrative systems
  • Assess risk to SSN use in administrative system
  • Mitigate SSN use in business processes according to assessed risk
  1. IMS to DB2 Conversion

* Dates are target completion dates and are subject to change as due diligence evaluations are completed.