EO 13681Executive OrderObama · D Quiet signal

Executive Order 13681

Improving the Security of Consumer Financial Transactions

This executive order mandates federal agencies adopt chip-and-PIN technology for government payment cards and terminals by early 2015, streamlines identity theft victim remediation through a centralized FTC website, and requires multi-factor authentication for federal digital services within 18 months.

Impact dates

  1. Agencies complete multi-factor authentication implementation

  2. Enhanced IdentityTheft.gov made available to public

  3. DOJ, Commerce, SSA provide identity theft resource information to FTC

  4. Attorney General and DHS issue guidance on compromised credentials submissions

  5. NSC/OSTP/OMB present multi-factor authentication plan to President

  6. New payment terminals must include enhanced security hardware; Treasury enabling software plan due; GSA begins card replacement; Treasury Direct Express replacement plan due; other agencies submit card security plans to OMB

Key directives

  • Treasury ensures new payment terminals acquired by agencies have enhanced security hardware by January 1, 2015
  • Treasury develops plan for enabling software by January 1, 2015
  • GSA begins replacing non-enhanced payment cards by January 1, 2015
  • Treasury develops plan for replacing non-enhanced Direct Express cards by January 1, 2015
  • Other agencies submit payment card security plans to OMB by January 1, 2015
  • Attorney General and DHS issue guidance on compromised credentials by February 15, 2015
  • DOJ, Commerce, SSA identify and submit identity theft resources to FTC by March 15, 2015
  • OMB and GSA assist FTC in enhancing IdentityTheft.gov by May 15, 2015
  • NSC/OSTP/OMB present multi-factor authentication plan within 90 days
  • Agencies complete multi-factor authentication implementation within 18 months

Who is ordered

Timeline

Immediate

  • Agencies begin transition to chip-and-PIN payment terminals
  • Treasury develops plan for enabling software

Near term (90d)

  • National Security Council/OSTP/OMB present multi-factor authentication plan to President (by January 15, 2015)
  • All January 1, 2015 deadlines for payment card/terminal upgrades
  • Attorney General issues guidance on compromised credentials (by February 15, 2015)
  • Agencies submit identity theft resources to FTC (by March 15, 2015)

Long term

  • Enhanced IdentityTheft.gov launched (by May 15, 2015)
  • Agencies complete multi-factor authentication implementation (by April 17, 2016)
  • Ongoing technology upgrades as threats evolve

Risks & tensions

  • Implementation subject to 'availability of appropriations' may delay upgrades if funding unavailable
  • Voluntary consensus standards requirement (Section 1) may slow adoption if industry standards conflict with security goals
  • IdentityTheft.gov coordination with credit bureaus depends on private sector cooperation ('to the extent feasible')
  • 18-month authentication timeline is relatively long for cybersecurity measures; threat landscape may evolve faster
  • No enforcement mechanism specified for agency non-compliance with plans
Executive Order 13681: Improving the Security of Consumer Financial Transactions · Executive Orders