<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : Economics of Identity Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx</link><description>Tags: Economics of Identity Management</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>The Economics of Identity and Access Management (IAM) </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/21/the-economics-of-identity-and-access-management-iam.aspx</link><pubDate>Fri, 20 Mar 2009 17:33:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88486</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/21/the-economics-of-identity-and-access-management-iam.aspx#comments</comments><description>&lt;p&gt;What are the Economics of Identity and Access Management (IAM)? &amp;nbsp;This is a key area that needs to be explored, to really understand, from an economic perspective, the actual value that IAM provides to organizations based on its impact on aspects of relevance to decision makers (such as loss prevention and risk mitigation) and the threat landscape. &lt;/p&gt;
&lt;p&gt;A few core aspects need to be researched:&lt;/p&gt;
&lt;p&gt;1) What are the key &amp;quot;aspects/metrics&amp;quot; that characterize the impact of IAM investments on an enterprise, for example in terms of preventing/reducing losses? In a first analysis important &amp;quot;macro&amp;quot; aspects include: security breaches (B), productivity loss (P), compliance violations (C) and costs (K)... &lt;/p&gt;
&lt;p&gt;2) How do these aspects/metrics relate to the basic IAM &amp;quot;levers&amp;quot; that decision makers (e.g. CIO/CISO/Risk Managers) can act on i.e. configuration, enforcement and audit reporting tools (compliance checking tools)? We need to capture the relevant causal dependencies, for example: what are the consequences and the impact of investing more on audit/compliance checking, rather than in configuration or enforcement? What are the consequences of acting on enforcement in terms of productivity and costs?&lt;/p&gt;
&lt;p&gt;3) Which utility functions, U(B,P,C,K) can effectively model the impact of IAM (e.g. in terms of losses) on security breaches, productivity loss, compliance violations&amp;nbsp; and costs by factoring in the investments in the &amp;quot;configuration, enforcement and audit&amp;quot; levers?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;4) How to effectively use systems modeling to estimate these utility functions, by animating the causal dependencies and inter-relationships among these &amp;quot;levers&amp;quot; and their impact on metrics, inclusive of assumptions on the threat landscape?&lt;/p&gt;
&lt;p&gt;So far I found very little literature and related work in this space - I would be keen to get any reference or link, if available.&lt;/p&gt;
&lt;p&gt;I am going to pursue research in this space, in the context of the &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt; activity (HP Labs Security Analytics project, &lt;a href="http://www.hpl.hp.com/research/systems_security/"&gt;Systems Security Lab&lt;/a&gt;), as I believe this (as for the Economics of Privacy and the Economics of Information Security) can: &lt;/p&gt;
&lt;p&gt;- provide a more rational way to describe and analyse the impact and value that IAM actually offers to organizations; &lt;/p&gt;
&lt;p&gt;- provide key decision makers with a decision support tool that operates at their level of abstraction.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88486" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+IAM/default.aspx">Economics of IAM</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+and+Access+Management/default.aspx">Economics of Identity and Access Management</category></item><item><title>Economics of Identity Management &amp; Risk-driven Identity Management </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/01/07/economics-of-identity-management-amp-risk-driven-identity-management.aspx</link><pubDate>Tue, 06 Jan 2009 22:25:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:87390</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/01/07/economics-of-identity-management-amp-risk-driven-identity-management.aspx#comments</comments><description>&lt;p&gt;Kim Cameron&amp;#39;s post called &lt;a href="http://www.identityblog.com/?p=1031"&gt;&amp;quot;The economics of vulnerabilities ...&amp;quot;&lt;/a&gt;, highlights a few key points made in Gunnar Peterson&amp;#39;s notes about the importance - when making security decisions - of keeping into account the (1) assets at stake in an organization and (2) their value. &lt;/p&gt;
&lt;p&gt;Specifically, I found the following point very interesting:&lt;/p&gt;
&lt;p&gt;&amp;quot;... If you are like most business you will find that you spend most on Network, then Host, then Applications, then Data. Congratulations, Information Security, you are diametrically opposed to the business!&amp;quot;.&lt;/p&gt;
&lt;p&gt;I tend to agree that quite often decisions and investments made in the security space are not really driven by risk management and/or &amp;quot;value-at-risk&amp;quot; criteria.&lt;/p&gt;
&lt;p&gt;This is also true in the Identity Management (IdM) space. Quite often the starting point, when making investment decisions in this field, is purely on IdM functionalities and the &amp;quot;general&amp;quot; added-value that they could provide to a business: it would help coupling this with the analysis of the actual business assets at stake, to be protected (business processes and services, information, etc.), their values, the involved threats and related risks. &lt;/p&gt;
&lt;p&gt;As previously mentioned in my blog, I believe that we should start discussing about the &lt;b&gt;&amp;quot;Economics of Identity Management&amp;quot;&lt;/b&gt;, in the wider context of &lt;b&gt;&amp;quot;Economics of Information Security&amp;quot;&lt;/b&gt; ...&lt;/p&gt;
&lt;p&gt;In the medium/long run, what are the consequences (in terms of costs, risk exposure, usability, agility, reputation loss, etc.) of decisions made in the space of identity management, given the context and the involved assets?&amp;nbsp; What are the feasible trade-offs and available options? Which key factors are truly relevant and need to be kept into account to make informed decisions? &lt;/p&gt;
&lt;p&gt;So far, I have found no major discussions about the &amp;quot;Economics of Identity Management&amp;quot; and the above points. I am very keen in getting your input, observations and links.&lt;/p&gt;
&lt;p&gt;In the context of the &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics R&amp;amp;D project&lt;/a&gt;, I am indeed interested in researching and exploring this area.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=87390" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category></item><item><title>On Identity Analytics: New HP Labs Technical Report</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/09/on-identity-analytics-new-hp-labs-technical-report.aspx</link><pubDate>Wed, 09 Jul 2008 09:35:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83657</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/09/on-identity-analytics-new-hp-labs-technical-report.aspx#comments</comments><description>&lt;p&gt;This community might be interested to a new HPL Technical Report, just released, titled &amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;On Identity Analytics: Setting the Context&lt;/a&gt;&amp;quot; (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu). &lt;/p&gt;
&lt;p&gt;This report reflects R&amp;amp;D work we are doing at HP Labs, &lt;a href="http://www.hpl.hp.com/research/systems_security.html"&gt;Systems Security Lab&lt;/a&gt;. I am very keen in getting your views and input. The abstract of this technical report follows:&lt;/p&gt;
&lt;p&gt;&amp;quot;This paper aims at setting the context for &amp;quot;Identity Analytics&amp;quot; within enterprises and paving the path towards new R&amp;amp;D opportunities. In our vision, Identity Analytics is about explaining and predicting the impact of identity and identity management (along with other related aspects, such as users&amp;#39; behaviours) on key factors of relevance to decision makers (e.g. CIOs, CISOs), in complex enterprise scenarios - based on their initial assumptions and investment decisions. &lt;/p&gt;
&lt;p&gt;Ultimately the goal is to provide rigorous techniques to help decision makers gain a better understanding of the investment trade-offs within the identity space (e.g. investing in technologies vs. changing processes vs. investing in users&amp;#39; education, etc.). This means providing &amp;quot;decision support&amp;quot; and &amp;quot;what-if analysis&amp;quot; capabilities to decision makers enabling them to explore these investment trade-offs, formulate new policies and/or justify existing ones. Our vision of &amp;quot;Identity Analytics&amp;quot; is introduced and discussed, along with the methodology that we intend to adopt. &lt;/p&gt;
&lt;p&gt;There are many research opportunities and challenges in this space: we believe that a scientific approach is required, involving the usage of modelling and simulation techniques, coupled with the understanding of involved technologies and processes, human behaviours and economic aspects. To ground some of the concepts discussed in this paper, we provide an illustration of Identity Analytics focusing on emerging &amp;quot;web 2.0 enterprise collaborative data sharing&amp;quot;, where unstructured information is created, stored and shared by people in collaborative contexts, within and across organisations. We demonstrate how trade-offs can be explored using the modelling approach hence allowing decision makers to explore the different impacts of policy choices.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83657" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CIO/default.aspx">CIO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/trade-offs/default.aspx">trade-offs</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/decision+support+system/default.aspx">decision support system</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/what-if+analysis/default.aspx">what-if analysis</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/decision+makers/default.aspx">decision makers</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CISO/default.aspx">CISO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/simulation/default.aspx">simulation</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/modelling/default.aspx">modelling</category></item><item><title>WEIS 2008 and “Economics of Identity Management”</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/11/weis-2008-and-economics-of-identity-management.aspx</link><pubDate>Tue, 10 Jun 2008 21:47:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83204</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/11/weis-2008-and-economics-of-identity-management.aspx#comments</comments><description>&lt;p class="MsoNormal" style="MARGIN:0pt 30.6pt 0pt 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="COLOR:black;"&gt;R&amp;amp;D papers and work presented at the &lt;/span&gt;Workshops on Economics of Information Security&lt;span style="COLOR:black;"&gt; (WEIS) &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;discuss and explore how economic theory and economic analysis can be successfully applied to information security, instead of focusing just on the traditional technology-driven approaches. &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;span style="COLOR:black;"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&amp;nbsp;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;What are the “Economics of Identity Management”?&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Something I believe it would be worth exploring too, with a scientific approach.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;The &lt;/font&gt;&lt;a href="http://weis2008.econinfosec.org/index.htm"&gt;&lt;font face="Times New Roman" size="3"&gt;7&lt;sup&gt;th&lt;/sup&gt; workshop on Economics of Information Security - WEIS 2008&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt; is going to take place in Hanover, HN, June 25-28, 2008: &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt 30.6pt 0pt 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;“Information security requires not only technology, but a clear understanding of risks, decision-making behaviors and metrics for evaluating business and policy options. How much should we spend on security? What incentives really drive privacy decisions? What are the trade-offs that individuals, firms, and governments face when allocating resources to protect data assets? Are there good ways to distribute risks and align goals when securing information systems?&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt 30.6pt 0pt 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;"&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="COLOR:black;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;The 2008 Workshop on the Economics of Information Security, the seventh workshop, will build on a strong and growing interdisciplinary tradition, bringing together information technology academics and practitioners with social scientists and business and legal scholars to better understand security and privacy threats. Until recently, research in security and dependability focused almost exclusively on technical factors, rather than incentives. However, we know that economic, behavioral, and legal factors often contribute as much as technology to the dependability of information and information systems. The application of economic analysis to these problems has proven to be an exciting and fruitful area of research.”&lt;/font&gt;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;Most of the above points also apply to the “Identity Management” field. An opportunity to contribute.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83204" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/WEIS+2008/default.aspx">WEIS 2008</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category></item></channel></rss>