Legislation and Market Forces PKI Drivers for the U. S. Mortgage ...

Reviews
Shared by: arnold2
Stats
views:
13
rating:
not rated
reviews:
0
posted:
12/11/2008
language:
English
pages:
0
Legislation and Market Forces: PKI Drivers for the U. S. Mortgage Industry November 27, 2006 R. J. Schlecht Director, Industry Technology – Security & Compliance Secure Identity Services Accreditation Corporation SISAC • Develops baseline standards for auditing and accreditation of certificate/credential issuers » SISAC does not issue credentials, rather accredits Service Providers, e.g., VeriSign, GeoTrust, Mortgage entities, etc. • • • • Technical, Business and Legal requirements B2B model for authentication Wholly-owned subsidiary of MBA www.sisac.org SISAC - Requirements • Standards developed by SISAC Advisory Group » Fannie Mae, Freddie Mac and mortgage participants » Advisory group is open to other entities » Standards drafted by Relying Parties » Federal Bridge (FBCA), OMB 0404, NIST, etc. • Aligned with PKI best practices • Business contract infrastructure • Liability requirements » RA, Subscriber, Relying Party agreements » Defined obligations for all participants » Credential Issuer Liable for Errors & Omission (E&O) » Basic ($1M), Medium ($5M), High ($10M) • Not fraud or transaction eMortgage Process Flow External Docs Legal eDocs (Land records, tax liens, other docs/affidavits ) eRecording Servicing eOrigination & Underwriting eDoc Prep eClosing Secondary Investor, Aggregator eDocuments eSignatures Service Ordering: Credit Flood Hazard Title MI eNotarization Buyer Seller eVault eVault eNote Data, Messaging & Control MERS® eRegistry (National eNote Registry) SISAC – Flexibility • Three levels of Assurance » Basic, Medium & High • Accreditation models » Full and outsourced providers » Independent or corporate providers • Types of Subscriber Certificates » User certificates • Individual or Organizational » Device certificates • Ability for Replying Parties to add requirements Legislation • Uniform Electronic Transactions Act (UETA) • Electronic Signatures in Global and National Commerce Act (E-SIGN) • Gramm-Leach-Bliley Act • Regulations » Federal Financial Institution Examination Council (FFIEC) » Federal Trade Commission (FTC) • U. S. States » California Senate Bill 1386 (Security Breach) » Over 30 other States MERS – National eNote Registry • Designation of authoritative Promissory eNote • Single source for Mortgage Industry of electronic Note • Launch production » April 26, 2004 » Notes are traded between primary, warehouse, secondary. • MERS Requirements » Tamper-evidence seal on envelope » Individual Identity on specific Transactions • SISAC Organizational Medium Assurance Cert • SISAC Individual Medium Assurance Cert eNote Registry National Notary Association (NNA) • eNotarizaiton of electronic records • State and County Recorders/Requirements • Strong authentication, with validation and revocation • Document integrity • Potential fraudulent exploitation of notaries • Non-proprietary model Lessons Learned • Business infrastructure and liability • Relying parties are interested in complying with legislative and business requirements; not credential services • Legislation legalized electronic signatures and documents, and security controls for protecting personal information • Relying parties bear the risk and therefore should have a critical role in defining policy requirements • Ability to leverage existing CPs/CPSs and audit practices • Emergence of early industry adopters; eRegistry and eNotarization services • Flexible model without compromise of standards Addressing the PKI Adoption Issues • Poor or missing support for PKI in software applications; • High adoption costs; • Poor understanding of PKI among senior managers and end-users; • Too much focus on technology and not enough on business needs; and, • Interoperability problems. Contact R. J. Schlecht Director, Industry Technology Security & Compliance Mortgage Bankers Association Washington, DC 20006 202 557-2843 rschlecht@mortgagebankers.org

Related docs
GSA PKI-SC Business Case
Views: 13  |  Downloads: 0
GSA PKI-SC Business Case
Views: 1  |  Downloads: 0
U
Views: 0  |  Downloads: 0
Ga Drivers License Name Change
Views: 54  |  Downloads: 1
The Major Drivers Of Globalization
Views: 136  |  Downloads: 5
Travel and tourism in 2020
Views: 320  |  Downloads: 104
Legislation
Views: 0  |  Downloads: 0
premium docs
Other docs by arnold2
Oxendine v State
Views: 410  |  Downloads: 4
at155
Views: 89  |  Downloads: 0
IP Table2
Views: 306  |  Downloads: 9
Real estate valuation arbitration rules
Views: 321  |  Downloads: 7
Burnham v S C of CA
Views: 291  |  Downloads: 5
Revell v Lidov
Views: 609  |  Downloads: 6
Notes for outilne
Views: 225  |  Downloads: 1
Bankruptcy proceedings representation
Views: 290  |  Downloads: 4
Victory in Jesus
Views: 267  |  Downloads: 0
Brief Baby M
Views: 457  |  Downloads: 3
Above All
Views: 234  |  Downloads: 3
Why Patients Use Alternative Medicine
Views: 382  |  Downloads: 4
dv120
Views: 503  |  Downloads: 6
Fisher v Carrousel Motor Hotel Inc
Views: 468  |  Downloads: 3