<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : CIO</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/CIO/default.aspx</link><description>Tags: CIO</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>On Identity Analytics: New HP Labs Technical Report</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/09/on-identity-analytics-new-hp-labs-technical-report.aspx</link><pubDate>Wed, 09 Jul 2008 09:35:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83657</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/09/on-identity-analytics-new-hp-labs-technical-report.aspx#comments</comments><description>&lt;p&gt;This community might be interested to a new HPL Technical Report, just released, titled &amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;On Identity Analytics: Setting the Context&lt;/a&gt;&amp;quot; (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu). &lt;/p&gt;
&lt;p&gt;This report reflects R&amp;amp;D work we are doing at HP Labs, &lt;a href="http://www.hpl.hp.com/research/systems_security.html"&gt;Systems Security Lab&lt;/a&gt;. I am very keen in getting your views and input. The abstract of this technical report follows:&lt;/p&gt;
&lt;p&gt;&amp;quot;This paper aims at setting the context for &amp;quot;Identity Analytics&amp;quot; within enterprises and paving the path towards new R&amp;amp;D opportunities. In our vision, Identity Analytics is about explaining and predicting the impact of identity and identity management (along with other related aspects, such as users&amp;#39; behaviours) on key factors of relevance to decision makers (e.g. CIOs, CISOs), in complex enterprise scenarios - based on their initial assumptions and investment decisions. &lt;/p&gt;
&lt;p&gt;Ultimately the goal is to provide rigorous techniques to help decision makers gain a better understanding of the investment trade-offs within the identity space (e.g. investing in technologies vs. changing processes vs. investing in users&amp;#39; education, etc.). This means providing &amp;quot;decision support&amp;quot; and &amp;quot;what-if analysis&amp;quot; capabilities to decision makers enabling them to explore these investment trade-offs, formulate new policies and/or justify existing ones. Our vision of &amp;quot;Identity Analytics&amp;quot; is introduced and discussed, along with the methodology that we intend to adopt. &lt;/p&gt;
&lt;p&gt;There are many research opportunities and challenges in this space: we believe that a scientific approach is required, involving the usage of modelling and simulation techniques, coupled with the understanding of involved technologies and processes, human behaviours and economic aspects. To ground some of the concepts discussed in this paper, we provide an illustration of Identity Analytics focusing on emerging &amp;quot;web 2.0 enterprise collaborative data sharing&amp;quot;, where unstructured information is created, stored and shared by people in collaborative contexts, within and across organisations. We demonstrate how trade-offs can be explored using the modelling approach hence allowing decision makers to explore the different impacts of policy choices.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83657" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CIO/default.aspx">CIO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/trade-offs/default.aspx">trade-offs</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/decision+support+system/default.aspx">decision support system</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/what-if+analysis/default.aspx">what-if analysis</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/decision+makers/default.aspx">decision makers</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CISO/default.aspx">CISO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/simulation/default.aspx">simulation</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/modelling/default.aspx">modelling</category></item><item><title>Do CIOs care about Data Privacy?  </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/27/do-cios-care-about-data-privacy.aspx</link><pubDate>Thu, 26 Jun 2008 17:23:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83451</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/27/do-cios-care-about-data-privacy.aspx#comments</comments><description>&lt;font face="Times New Roman" size="3"&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;Apparently they don&amp;#39;t, &lt;/span&gt;at least based on a recent Ernst &amp;amp; Young report, whose outcomes have been summarised in &lt;a href="http://www.dofonline.co.uk/governance/audit-chiefs-still-lax-on-data-privacy6637.html"&gt;this article&lt;/a&gt; &lt;span class="small"&gt;written by Adrie van der Luijt &lt;/span&gt;:&lt;/p&gt;&amp;nbsp; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;“IT fraud and data privacy fail to sound the alarm for CIOs and internal audit chiefs, a survey shows. Sixty-five per cent internal audit chiefs do not recognise data privacy and IT fraud as a serious threat to their business.&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;A survey, released by Ernst &amp;amp; Young, found that internal audit chiefs ranked corporate breaches and data privacy regulation sixth in their top ten IT risks for the organisation, while for CIOs it barely made it onto the list at just ninth. &lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;In addition just 14 per cent of internal audit chiefs said that their staff had been trained in fraud investigation. …”&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;I would be interested in having a look at this survey, if only I could find a copy online …&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/p&gt;&lt;/font&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83451" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CIO/default.aspx">CIO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/survey/default.aspx">survey</category></item></channel></rss>