<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : IAM</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAM/default.aspx</link><description>Tags: IAM</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Identity Management and the IT Monoculture </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/05/identity-management-and-the-it-monoculture.aspx</link><pubDate>Wed, 04 Mar 2009 17:55:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88190</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/05/identity-management-and-the-it-monoculture.aspx#comments</comments><description>&lt;p&gt;A recent &lt;a href="http://www2.computer.org/portal/c/document_library/get_file?uuid=a9f8e91d-30f5-4420-9c3f-e1ac4bed7f9a&amp;amp;groupId=53319"&gt;article&lt;/a&gt; (called &amp;quot;IT Monoculture: Security Risks and Defenses&amp;quot;) published by the IEEE Security and Privacy magazine, discusses pros and cons of having an IT Monoculture, i.e. where no diversity is introduced for specific IT solutions deployed within organizations.&lt;/p&gt;
&lt;p&gt;Quite interestingly this applies also for Identity Management. On one side deploying the same Identity Management (IAM) solutions across an organization increases efficiency, central control and uniformity. On the other hand, it might potentially increases the exposure of the organization to threats and related risks.&lt;/p&gt;
&lt;p&gt;I guess that, at the end, it is a matter of economics, involving trade-offs between involved costs, security and productivity. &lt;/p&gt;
&lt;p&gt;This is an area where modeling and simulation (see Security and &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;&amp;nbsp;Identity Analytics&lt;/a&gt;) might be of some help, to explore, predict and identify the most suitable approach for an organization, given the organization profile and the underlying threat environment.&lt;/p&gt;
&lt;p&gt;Just wondering if there is any recent, official study (I have not yet found it ...) exploring the current level of &amp;quot;IAM-diversity&amp;quot; within organizations. Any pointer/link would be welcome ... &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88190" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAM/default.aspx">IAM</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IT+monoculture/default.aspx">IT monoculture</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/diversity/default.aspx">diversity</category></item><item><title>IAM and top IT initiatives in 2009 </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/02/19/iam-and-top-it-initiatives-in-2009.aspx</link><pubDate>Wed, 18 Feb 2009 23:23:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:87976</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/02/19/iam-and-top-it-initiatives-in-2009.aspx#comments</comments><description>&lt;p&gt;This &lt;a href="http://computerworld.co.nz/news.nsf/scrt/F53EE9A6133F149FCC25755C0010AEFC"&gt;article&lt;/a&gt;, called &amp;quot;Encryption top IT Security Initiatives in 2009&amp;quot;, provides an overview of a recent Forrester&amp;#39;s report, about IT security spending in 2009:&lt;/p&gt;
&lt;p&gt;&amp;quot;Full-disk encryption was cited as the top client security technology ...&lt;/p&gt;
&lt;p&gt;The survey&amp;#39;s respondents also indicated interest in deploying identity and access-management (IAM) technologies, particularly single sign-on, unified monitoring of users&amp;#39; rights and activities and provisioning. The main reason given for adopting IAM was security and governance along with regulatory compliance. Among the technologies least anticipated to be piloted or adopted is application lockdown for endpoint control&amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=87976" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAM/default.aspx">IAM</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IT+security+spending/default.aspx">IT security spending</category></item><item><title>Article: Changing business landscape makes IAM key to IT Security</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/20/article-changing-business-landscape-makes-iam-key-to-it-security.aspx</link><pubDate>Wed, 19 Nov 2008 17:24:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86687</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/20/article-changing-business-landscape-makes-iam-key-to-it-security.aspx#comments</comments><description>&lt;p&gt;Here is a recent, interesting article, called &amp;quot;&lt;a href="http://blogs.zdnet.com/Gardner/?p=2758"&gt;Changing business landscape makes identity and access management key to IT security&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;In an age of significant layoffs and corporate restructuring, the burgeoning problem of identity and access management for IT operations and data centers has escalated into a critical security issue. Managing who gets access to which resources for how long - and under what circumstances - has become a huge and thorny problem. Improper and overextended access to sensitive data and powerful applications can cause massive risk as many employees find themselves in flux.&amp;quot;&lt;/p&gt;
&lt;p&gt;This article provides some excerpts from a discussion with Dan Rueckert (worldwide practice director for security and risk management in HP&amp;#39;s Consulting and Integration group); Archie Reed (distinguished technologist in HP&amp;#39;s security office in the Enterprise Storage and Server Group), and Mark Tice (vice president of identity management at Oracle).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86687" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAM/default.aspx">IAM</category></item></channel></rss>