Showing posts with label SaaS. Show all posts
Showing posts with label SaaS. Show all posts

Wednesday, August 11

Identity as a Platform

I was asked for my thoughts on an article titled Hosters Need to Think about Identity as a Platform Play. When I clicked to read the article, I was happy to see it was written by Novell's Dale Olds who always has interesting and informed things to say.

I agree with Olds' assessment. SaaS platform vendors (hosters) should really get on the ball with offering identity services as part of their hosting packages. They should do similar with data encryption as well (both to the endpoint and in storage). Security is complicated -- extremely important and extremely easy to get wrong. It only takes a small oversight somewhere along the line to break the chain. SaaS application vendors would be wise to leverage proven, trusted solutions for access management rather than trying to create their own.

I think Olds overstated how simple it would be for applications to switch platforms. It seems to me that it's pretty complicated even in the case of moving a simple PHP website to another host. And most SaaS applications will be much more complicated than that. And the other part of that thought was that providing identity services would tie-in the application provider to that platform. I would recommend to hosting providers that they make it easier rather than harder to move. That'll be a key differentiator and ultimately drive more business/revenue to your brand. (I'm not saying that Dale was recommending to purposely make it complicated - it's just how it is.) BUT - there's still a business driver to build identity into the platform. Removing the complexities of security from the application development process could save 30% of time and resources in standing up a new application versus having to build it all from scratch.

And to Steve (from Axciom)'s point (in the comments), yes! Ideally, Platform as a Service vendors will provide more than authentication. Baked in security could incorporate firewalls, authentication, multi-factor authentication (& transaction-based), authorization, encryption (in-motion and at-rest), activity and access audit, SoD monitoring, and more.

We're obviously very early in this whole process. I think we're moving in the right direction, but it'll take time to get it all right.

Wednesday, June 16

Value Beyond Bits

An article in the June 7 edition of ComputerWorld discusses the IT industry's energy crisis. People are overworked and tired.
"Head count is decreasing, and workload is increasing. User expectations and regulatory requirements are expanding exponentially."
The article goes on to discuss how to re-energize IT. It specifically mentions removing negative people (yes!) and improving upon IT finances (not sure about that one).

I would add something to that short list - take a look at managed services or cloud solutions. These solutions present an opportunity to get IT professionals' heads out of the 'bits and bytes' that can really drain energy. I've been there. When you spend 4 or 8 hours focused on applying some technical fix or getting a program to work, it can be physically and mentally exhausting. Those are the parts of the IT job that many people don't enjoy. And those are precisely the aspects of the job that get handed off with SaaS and managed solutions.

By removing those annoyances and freeing IT staffers to be proactive about providing greater business value, it generates new energy and enthusiasm. Clearly though, many IT folks disagree.

Another article in the same edition discusses the issue of IT staff mistrust of cloud solutions. One IT director states:
"They flat-out asked. 'What does this mean for me and my job?'"
IT professionals are clearly concerned. I've heard it first hand. Why would I want to recommend a managed solution when that's my job.

Well, I understand the concern, but I think that viewpoint is a bit myopic. Think of car ownership. If you can offload the maintenance and upkeep of the vehicle, driving is much more fun. You can accelerate quicker, take turns tighter, brake harder, take it off road, etc. and let someone else worry about changing the oil, maintaining tire pressure and watching the treads. In my opinion, managed solutions equate to more freedom.

And the first time you (as an IT staffer) show a business manager how you can save them time or money in their job through creative use of technology, I think you'll be hooked. You'll appreciate that you were able to put your creative, problem-solving mind to work on business issues (still requiring in-depth technology knowledge) rather than being bogged down in the bits.

Just a thought.

Monday, May 11

Defining the Cloud

I just read another definition of Cloud Computing. It was a pretty good one, similar to what I submitted to the non-geek definition conversation. To save you the suspense and extra clicks, Andre Yee defined Cloud Computing as:
An on-demand delivery model for IT services or applications with the characteristics of multi-tenant hosting, elasticity (variable capacity) and utility based billing.
My version was:
Shared computing infrastructure over the web that distributes cost across participants and lowers the cost for each.
I actually like Yee's better than mine. I was focused more on the business purpose than actually describing what it is.

In thinking further, I think we should remove applications from the definition. Applications are delivered As a Service or On Demand. But it is infrastructure that is provided 'in the Cloud'. When we talk about Cloud Computing, we're talking about shared infrastructure (hardware, OS, security mechanisms, backup, etc.). I personally wouldn't use cloud terminology to describe what salesforce.com has made famous.

Salesforce isn't sharing infrastructure with other software providers. They're just including the infrastructure as part of the value they provide to customers. Their delivery mechanism internally looks a lot like what cloud computing providers offer, but they're offering it to their own customers.

Cloud Computing is a service for software or solution developers that can reduce cost by leveraging a shared infrastructure that is billed based on use. Those developers then offer their solution As A Service. But, they can also offer their solution As A Service without utilizing a Cloud infrastructure. They can, as Salesforce did, build their own infrastructure.

What do you think? Worthwhile distinction? Clear?

Friday, September 12

DIDW 2008

I saw, heard, and did a lot of interesting things this week at DIDW in Anaheim.

First, thank you Ping Identity for a good mid-week party at the HoB. (We should all publicly thank Ping and give them reason to continue hosting such events.)

We had a bloggers meet-up, though you won't hear too many others talk about that (maybe Ash). I did get to meet a number of folks who I've only previously met online. And I had many good conversations.

I heard more about the consulting (and other) capabilities of companies like Identropy, CoreBlox, and Optimal IdM – all worth a conversation if you need some Identity consulting help. And each has unique strengths. I wonder if you would all benefit from some kind of cooperative network rather than having the perception of competition. I'll have to think about that.

We gave away a lot of sticky eye balls. One became known as the eye in the sky.

I learned about important things like:
And heard a lot of interesting discussions and tidbits, including:
  • The US Treasury Dept transfers more than $1 Billion each day via PKI
  • There seems to be consensus that enterprises will be affected by market forces on consumer identity and Web 2.0. ...perhaps TPS reports will be replaced by Twitter.
  • Searching on "Identity Management" has declined throughout 2006, 2007, and 2008. My own research reveals that searching on "Microsoft", "Oracle" and "Active Directory" have all declined at a similar rate. So, it may mean nothing.
  • One interesting case for synchronization vs. virtualization: If you front-end data that you don't own (and therefore can't control), you should replicate data and sync rather than using a totally virtual approach. It sounded like someone learned that the hard way.
  • Not all Virtual Directories are created equal. I heard a panelist ask vendors for a feature that I know exists in at least two Virtual Directory products.
  • Virtual Directories might be able to fill a gap in the real-time link between physical and logical security (grant access only when employee is swiped in).
On the flight back, a crazy thing happened. I heard a horrible scream outside the window of the airplane and when I looked outside, I saw something that seemed to be flying past us at a close distance. I quickly grabbed my camera and got a shot of it. (OK - you probably had to be at DIDW to appreciate that.) If you weren't, use this short waste of your time as inspiration to go check out Symplified and see what they're doing with SaaS-based Web Access Management. Pretty cool stuff. Their model removes a lot of the pain that gave Identity Management a bad name in its early days. And no, that's not Che.

I guess that's it for my DIDW update. For now.

Wednesday, July 16

SaaS Eases Security Cost and Complexity

I first read an article in InformationWeek titled SaaS Makes A Run At Security and then found this very similar article by the same author online.

I've posted recently about identity as a service (be sure to check the comments and links if you visit that posting). But my day job dictates that I think more about identity reporting as a service. (intelligence around who has what access and what changes are being made).

One of the striking take-aways from the article is the Gartner estimate that by 2018, 85% of security intelligence will be offered as a service. I guess the words "offered as" seem to deflate the energy of the claim. I wonder what the estimates are for how much will be consumed as a service in 10 years.

In any case, I think the writer hits on the right points - cost and complexity. Especially for the mid-market (his target audience). I think (particularly in the mid-market) the simplification of key capabilities will outweigh the emotional hurdles that make SaaS a tough sell for security. Of course, actual security capabilities may remain a harder sell than security capabilities. That is, companies may be more willing to have managed identity reporting than managed provisioning.

I think mid-market security practitioners want their lives to be easier. They're not driven by the same concerns as large enterprises. What do you think?