The Future of Identity Management? It is all about Managing Risk … - Research on Security and Identity Management (by Marco Casassa Mont) -
The Future of Identity Management? It is all about Managing Risk …
Research on Security and Identity Management (by Marco Casassa Mont)

Syndication

As I have been posting for a while, I believe that Identity Management will evolve, during the next few years, from a pure “control point and compliance”-based approach towards an approach that will increasingly factor in the management of Risk.

Decision makers (CIOs, CISOs, etc.) are shifting from a “compliance management” mentality to a “risk management” mentality, when making investment decisions on IT security solutions. Their investment decisions (including the ones on Identity Management) are going to be increasingly questioned, due to the shrinking of resources available. Hence the need to prioritise based on real business objectives and needs.

I am glad that Burton Group is now making some statements in the same direction, as it is possible to evince from this article:

“Identity management is evolving to include a closer recognition of risk and how to manage it rather than trying to eliminate it using technology, according to the head of the Burton Group consulting firm.

“Companies are looking at controls from a risk perspective instead of trying to control everything,” said Jamie Lewis, CEO of the Burton Group during the opening day of the firm’s annual Catalyst Conference. “It is about people managing risk and not about technology trying to make risk disappear.””

I believe there is a whole new set of research and commercial opportunities in this space (i.e. beyond compliance management and control points), whilst traditional Identity Management solutions are becoming more and more a commodity.


--- NOTE:  use this mirror blog if you prefer posting on an external blog site  ---


Posted 06-29-2008 1:57 AM by marcocasassamont

Comments

Matt Flynn wrote re: The Future of Identity Management? It is all about Managing Risk …
on 06-30-2008 1:48 PM

I've also been saying this to some degree. As technology people, we want to ensure that our solutions align with core business goals.  But, I haven't seen it resonate with customers in the field.  I'd be curious to hear from IdM consultants about what their customers are saying.  Is the move to Risk-Based approach actually happening?  Or is it something reserved for analysts and bloggers?

marcocasassamont wrote re: The Future of Identity Management? It is all about Managing Risk …
on 07-12-2008 5:19 PM

Hi Matt.

Sorry for the delay to publish your comment. I just noticed it now (no notification from this blog platform ...).

I can publicly say is that there is currently a trend drven by key decision makers (some of them are actually our customers) from a compliance driven approach to a risk-based approach.

This is a process that wil ltake long time (5-10 years) so expect no immediate change of directions.

Anyway, you are asking the right questions.

Any input about this trend coming from other people operating in this area?

Powered by Community Server (Non-Commercial Edition), by Telligent Systems