Security for the Digital Transformation: Cloud, Data, Identity & Access.
Saturday, November 22
U of Rochester IdM Journal
[enter Leslie Nielsen]
"I just want to tell you both good luck. We're all counting on you."
Friday, November 21
Identity Management is Like Watching Paint Dry
On the humorous side, twenty one percent of respondents in an Imanami research report found managing Active Directory to be more boring than filling out expense reports. (It's great that they even included that option in the survey - it could be fodder for OfficeSpace 2?)
On the serious side (from the research):
And back to the article:5.8 person-hours per 1,000 users is spent during a typical week on updating or otherwise managing groups in Active Directory.
81% of respondent organizations manage groups manually, while 55% use scripts and 34% use some sort of automated solution.
I've talked about the motivations behind Identity Management projects before, but I wasn't accounting for the current economic climate. There's definitely an argument to be made that the pendulum is swinging back toward cost savings as the prime mover of Identity projects."User provisioning and multifactor authentication are two projects you should keep if you are thinking about cutting back," said Forrester Research's Andras Cser about identity management today. "These are areas where there's a real opportunity to increase efficiency and cost savings."
42% of organizations report that someone has accessed information from Active Directory that they were not authorized to access.
This issue becomes even more acute during difficult financial times, when employees may become disgruntled following layoffs or pay disputes, experts noted. During such times, the ability to quickly provision and deprovision employees may play an important role in the enterprise's overall security, they said.
Two Kinds of Security Threats
- Noisy threats that break things people care about.
- Quiet threats everyone besides security geeks ignore, because it doesn’t screw up their ability to get their job done or browse ESPN during lunch.
It also helps call out why some people throw money at compliance in a way that just quiets it down without really providing the best risk mitigation or value.
Saturday, November 15
Log Management
The first paragraph gives a nice summary of the log management dilemma:
IT managers–and system admins, for that matter–hate logs, because they seemingly go on forever and often provide an overabundance of useless information. Administrators get lost looking for one or two important log entries scattered through a log file with tens of thousands of entries.It goes on to discuss how LogLogic and LogRythym attempt to deal with the problem.
We (NetVision) don't compete with these vendors because we don't take a horizontal approach attempting to cover every system under the sun that can produce a log. We're focused on core network directories (Active Directory and eDirectory) and related file systems. But, we take a different approach to the overabundance problem.
Rather than trying to streamline the search into a huge mountain of useless information, we process events very carefully so that you never even create a mountain. Instead, you create a streamlined set of highly relevant information.
Because of our focus on core platforms, we're able to really excel at depth and provide unparalleled filters and capabilities -- such as capturing lots of information that doesn't even exist in the logs. We get user names, before and after values, any combination of objects or attributes, and even failed attempts.
And if you're enterprise still needs enterprise log management, we can contribute highly relevant event information about arguably the most important security component in the environment - the network directory (Active Directory) and its related file system (Windows). ...which ultimately makes the mountain easier to navigate.
Events we cover? User accounts, access rights, administrative changes, and user activity. In addition to platform focus, we're also focused on what events we care about -- identity and access. We answer Who Has Access to What? and monitor any changes that affect the answer to that question.
Tuesday, November 11
Outsourcing Security is NOT Riskier
Expert Advice
The first take-away is that there is almost never consensus. So, add your own perspective to whatever security advice you hear. There will usually be someone smart who disagrees and you'll need to find your own middle ground based on your individual needs.
Outsourcing Security
The other really interesting thing I took away is on the topic of Outsourcing Security. Other than one, all of the experts seem to acknowledge the potential for better security in outsourcing. I often hear the argument that outsourcing has benefits in spite of security concerns. But, this panel had good reasons why outsourcing may create better security. Here are a few of the responses:
People are risky, whether they get a paycheck signed by you or one signed by the outsourcer... Often, an outsourcer has more security measures in place than you do.As I said above, think about your own needs and make your own analysis, but hopefully we can agree to stop assuming that outsourced security is less secure.
- Bruce Schneier
If you need 24/7 coverage, choose a solid managed security service provider, and choose the right services to outsource.
- John Pescatore
Outsourcers can hire better people and because they see more real bad things, they are better at reacting.
- Richard Stiennon
Thursday, November 6
SC World Congress - New York City
The SC World Congress will happen Dec. 9-10 at the Jacob Javits Center in NYC. New York is a great place to visit in December - let me know if you plan to be there. Maybe we can meet for a drink. Also, NetVision will be there as a sponsor. Stop at the booth - we'd love to talk to you about our latest accomplishments.
I'll also be blogging about the event as part of the Security Bloggers Network. The SBN is pleased to offer our readers a 35% discount on conference rates. It could be just what you need to get approval to attend the event. To take advantage of the discount, just use the promotional code BLOG1 (for one day pass) or BLOG2 (for two day pass).
For more info, go to the SC World Congress site.
Monday, November 3
FREE Pass: CSI 2008 (DC Area)
I have been authorized to give away a FULL 3-Day Conference Pass FREE (an $1895 value).I only have one to give, so I'll have a small contest. Here's how to enter:
CONTEST DETAILS
You must enter by Thurs. 11/6. I will contact the winner on Fri. 11/7.
To enter, send me the most creative, interesting, unusual, funny, or exciting thing that you've seen, heard-of, done, or would-like-to-do with Active Directory.
Be sure to include email, phone, company name and title in your response.
If you want to win, but can't think of anything, try something like "use it to store network credentials". - you never know. That might be enough to win ;)
Those of you who don't win, can still take advantage of a 25% Discount!
The 25% Discount code is: BLOG25
You can also go directly to the site for a FREE Exhibition-Only pass.
I look forward to reading your entries!
Thursday, October 30
Productivity was the big motivator
The link occurs in the line:
And while user productivity was the "big motivator" behind identity management strategies several years ago...So, I think the writer may have read one of my previous posts which said:
Provisioning has typically been about increased efficiency and reduced cost. But, it's time to extend the ROI into security and compliance as well.I expanded on the theme in a later post and then discussed the topic in an article on eBizQ.
You might notice that my ultimate conclusion is a little different than the one in the article. Here's the full paragraph from the IT World Canada article:
And while user productivity was the "big motivator" behind identity management strategies several years ago, it has now assumed a back seat as the rough economy has brought to the fore the need to reduce help desk and security administrative staff by automating previously manual user access processes, said Shohan. “People at least pay lip service to the idea of regulatory compliance and improving security, although I suspect in many cases, they… are really more interested in ROI and access termination,” he said.So, it sounds like they're saying that the initial drivers for IAM were user-productivity and that has shifted to operational cost savings. In contrast, I would say that the initial driver was operational cost savings, it later included user-productivity, and now the shift is toward greater security and compliance / audit-ability.
In a completely separate post, I also talk about the difference between enabling end-user productivity in some SSO solutions and enabling security in others. ...perhaps that was the motivation for the link?
Either way, thanks to IT World Canada for the link!