About 18 months ago, I wrote a paper for MaXware about Identity Management in a Service Oriented Architecture (SOA) and described the scenario of initiating provisioning events from enterprise applications via SPML to the provisioning system (now called the Provisioning Service Provider in an SPML scenario).
Martin Raepple of SAP just published an article titled No Limits for Identities. In it, he discusses the process and business value of leveraging SPML for provisioning. He also discusses the role of the Provisioning Service Provider (PSP).
It seems that SAP has done a good job of quickly leveraging one of MaXware's core strengths to enable the NetWeaver platform to act as an open and available PSP for the enterprise. Many of the other major provisioning platforms also support SPML, but I haven't heard of many customers leveraging a service-based provisioning model. I still expect this type of architecture to become more commonly used. Have you seen it in action?
Security for the Digital Transformation: Cloud, Data, Identity & Access.
Thursday, November 29
Wednesday, November 28
Identity Mgt. Deployment Tips
I was soliciting input from Corbin Links on something and it brought me to his latest blog post which is titled When Good IAM Software Goes Bad. It describes the common pitfalls of Identity Management software deployment. He really hits the nail on the head in terms of the types of frustrating issues you encounter when deploying IdM solutions. AND - he provides some tips on how to avoid them and gives some great advice.
Incidentally, it's not the first really useful post by Corbin. If you're a company that needs to roll out Identity Management solutions, he should be on your reading list. e.g.) For a pragmatic approach to dealing with Role Management, check out his post on Role Mayonnaise. ...not to be confused with Mayonnaise on a Roll, which I've been told was a tasty snack during The Depression. (sorry for that)
Incidentally, it's not the first really useful post by Corbin. If you're a company that needs to roll out Identity Management solutions, he should be on your reading list. e.g.) For a pragmatic approach to dealing with Role Management, check out his post on Role Mayonnaise. ...not to be confused with Mayonnaise on a Roll, which I've been told was a tasty snack during The Depression. (sorry for that)
Monday, November 19
NetVision Links and Stelogging
I haven't been blogging much lately. I've been busy though. I already mentioned my whiteboard presentation and my recent white paper on Surviving an Identity Audit. We also recently launched a new NetVision web site where we talk more about Policing the Power of Identity and our slick new Reporting Console. You might also be interested in NetVision solutions for Active Directory, PCI-DSS, or ISO 17799 / ISO 27002. You can also sign up for our upcoming webinar
on Identity Audit.
Stelogging
I also found out this week via a Google Alert that someone is stealing and reprinting my blog content for profit. And they're using my RSS feed to do it. I've seen it called a Splog, but this is actually not Splogging (according to Wikipedia) because I'm not doing it to drive up link traffic or SPAM my audience. This is someone else re-purposing my content. Maybe this will be called Stelogging? I generally like to see people including my content in their discussions, but this doesn't feel right. What's worse is that Google helps them out by advertising (via Google Alerts) and providing a revenue stream (via Google Adwords). I'm not going to disable the RSS feed -- the point of this is to allow people to read the content. I'm not really sure there's anything to do other than ask them to stop. I suppose I can also include a footnote on my posts to the effect of:
on Identity Audit.
Stelogging
I also found out this week via a Google Alert that someone is stealing and reprinting my blog content for profit. And they're using my RSS feed to do it. I've seen it called a Splog, but this is actually not Splogging (according to Wikipedia) because I'm not doing it to drive up link traffic or SPAM my audience. This is someone else re-purposing my content. Maybe this will be called Stelogging? I generally like to see people including my content in their discussions, but this doesn't feel right. What's worse is that Google helps them out by advertising (via Google Alerts) and providing a revenue stream (via Google Adwords). I'm not going to disable the RSS feed -- the point of this is to allow people to read the content. I'm not really sure there's anything to do other than ask them to stop. I suppose I can also include a footnote on my posts to the effect of:
If you're reading this at a site other than 360tek.blogspot.com, please DO NOT click on the advertising and support the use of stolen content.I suspect we'll see more of this kind of thing. If this snow balls, it may become difficult at some point to discern the original author from the re-publishers. Is this something I should even care about? I suppose if I had 4 million visitors daily and my blog was my primary source of income, it would be a big deal. As it stands, I'm not sure why I'd be a target for this sort of thing since I have a very niche (but excellent) audience. This is a strange thing to be thinking about.
Monday, November 5
HP's Security Handbook
Thanks Marco for pointing out HP's Security Handbook. It's a guide for securing an enterprise with a focus on identity management, proactive security management, and trusted infrastructures.
One section worth pointing out is in Chapter 1 on Governance where they define the differences between corporate governance, security governance and IT governance. I find that people often use these interchangeably or confuse the regulation-of or solution-for one with another.
I also like the section later in this chapter which suggests a move to continuous, real-time assurance or continuous compliance -- what I (and others) have previously referred to as creating a culture of compliance. Identity Management gets an entire chapter. And there's a glossary and appendices that cover topics such as IPsec-over-L2TP, placement of a reverse proxy server, and the difference between TACACS+ and DIAMETER. Good Stuff.
One section worth pointing out is in Chapter 1 on Governance where they define the differences between corporate governance, security governance and IT governance. I find that people often use these interchangeably or confuse the regulation-of or solution-for one with another.
I also like the section later in this chapter which suggests a move to continuous, real-time assurance or continuous compliance -- what I (and others) have previously referred to as creating a culture of compliance. Identity Management gets an entire chapter. And there's a glossary and appendices that cover topics such as IPsec-over-L2TP, placement of a reverse proxy server, and the difference between TACACS+ and DIAMETER. Good Stuff.
Tuesday, October 30
Surviving an Identity Audit
Smaller companies can feel overwhelmed by big company issues. Although they don't have the reach of the Fortune 500, they still feel the effects of governmental and industry regulations. They have similar requirements with much fewer resources to get the job done.
In this whitepaper titled Surviving an Identity Audit, I tried to help people at smaller organizations get their arms around some of the big challenges related to compliance. Specifically, the focus is on the identity portion of an IT audit.
Regulations such as SOX, HIPAA, GLBA and PCI-DSS have requirements and/or guidance that relate directly to IT – more specifically to information security. And digital identities are at the core of information security. So, an audit of an organization's identity infrastructure is a vital component of an IT audit or a larger regulatory audit.
In this paper, I cover the Identity Audit project lifecycle, leveraging a multi-regulatory approach, and creating a culture of compliance.
For more info:
In this whitepaper titled Surviving an Identity Audit, I tried to help people at smaller organizations get their arms around some of the big challenges related to compliance. Specifically, the focus is on the identity portion of an IT audit.
Regulations such as SOX, HIPAA, GLBA and PCI-DSS have requirements and/or guidance that relate directly to IT – more specifically to information security. And digital identities are at the core of information security. So, an audit of an organization's identity infrastructure is a vital component of an IT audit or a larger regulatory audit.
In this paper, I cover the Identity Audit project lifecycle, leveraging a multi-regulatory approach, and creating a culture of compliance.
For more info:
- SOX – Sarbanes-Oxley Act
- HIPAA – Health Insurance Portability and Accountability Act
- GLBA – Gramm-Leach-Bliley Act
- PCI-DSS – Payment Card Industry Data Security Standards
Tuesday, October 9
Securing borderless networks
Here's a nice blog entry on 10 ways to secure borderless networks. It could have been written by EMC/RSA as it covers many of the capabilities they've been talking about for the past year (and for which they have pretty nice solutions).
The reason I mention this article is to re-raise the point that security needs to be handled from numerous directions and in numerous ways. There's no single security solution that will prevent against every type of attack or breach. People are mobile and our information is mobile. A good security strategy needs to cover many fronts - from remote user authentication to data encryption.
One note to the author: MIIS/ILM is not a federation solution. And while I'm on that subject, I wouldn't have even included Federation as a solution to make systems more secure. Although the argument can be made that it provides greater control over user accounts by the identity provider, it's primarily a solution that enables ease-of-use in a secure way rather than a solution for increased security.
And since there's an empty spot on the list, we could replace it with real-time user behavior monitoring as another good way to enhance security in a borderless environment.
The reason I mention this article is to re-raise the point that security needs to be handled from numerous directions and in numerous ways. There's no single security solution that will prevent against every type of attack or breach. People are mobile and our information is mobile. A good security strategy needs to cover many fronts - from remote user authentication to data encryption.
One note to the author: MIIS/ILM is not a federation solution. And while I'm on that subject, I wouldn't have even included Federation as a solution to make systems more secure. Although the argument can be made that it provides greater control over user accounts by the identity provider, it's primarily a solution that enables ease-of-use in a secure way rather than a solution for increased security.
And since there's an empty spot on the list, we could replace it with real-time user behavior monitoring as another good way to enhance security in a borderless environment.
Tuesday, September 25
NetVision: Policing the Power of Identity
NetVision issued a press release today in conjunction with our appearance at Digital ID World. It's primarily about our very cool new reporting capabilities to be officially released in October. The release also points to a four minute whiteboard session explaining what we mean by Policing the Power of Identity. If you have four minutes, please take a look. Since I created the presentation, I especially hope you enjoy it.
Labels:
identity,
identity audit,
insider threat,
NetVision,
power of identity
Tuesday, September 18
The End of Encryption?
OK, I realize it's not the end of encryption, but this is a big deal. Separate groups of researchers in Australia and China have independently used quantum computers to factor the large numbers used for much of today's asymmetric encryption. Asymmetric encryption is used for PKI which is the underlying concept behind SSL -- probably the most fundamental component of security on the web.
Here's how SSL works (simplified):
The security of the process hinges on the fact that an eaves dropper wouldn't be able to take x and z1 (which are both passed openly) and quickly figure out y1 (the secret key) -- or do the same for y2. If that were possible, they would be able to listen in on SSL transactions. And that's pretty much what these researchers are now able to do.
The article suggests that "For the moment, enterprise computers seem pretty secure, since you'd have to be a quantum physicist to crack today's codes." But, one might speculate that if a secret is worth enough to a would-be attacker, quantum physicists or their tools may become purchase-able. It's probably not a big deal for joe consumer, but for governments, large defense contractors and the like, it's probably time to take a look at their use of certain algorithms in asymmetric encryption. That analysis of course should be and probably is a continuous, on-going process. Interesting stuff.
Here's how SSL works (simplified):
- persons 1 & 2 agree on a base number (x)
- person 1 raises x to the power of a large secret key (y1) = z1
- person 2 raises x to the power of a large secret key (y2) = z2
- persons 1 & 2 exchange values z1 & z2
- person 1 raises z2 to the power of y1 = k
- person 2 raises z1 to the power of y2 = k
The security of the process hinges on the fact that an eaves dropper wouldn't be able to take x and z1 (which are both passed openly) and quickly figure out y1 (the secret key) -- or do the same for y2. If that were possible, they would be able to listen in on SSL transactions. And that's pretty much what these researchers are now able to do.
The article suggests that "For the moment, enterprise computers seem pretty secure, since you'd have to be a quantum physicist to crack today's codes." But, one might speculate that if a secret is worth enough to a would-be attacker, quantum physicists or their tools may become purchase-able. It's probably not a big deal for joe consumer, but for governments, large defense contractors and the like, it's probably time to take a look at their use of certain algorithms in asymmetric encryption. That analysis of course should be and probably is a continuous, on-going process. Interesting stuff.
Subscribe to:
Posts (Atom)