<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : Identity Analytics</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx</link><description>Tags: Identity Analytics</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Good R&amp;D Progress in the Space of Identity (and Security) Analytics</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104920.aspx</link><pubDate>Tue, 25 Aug 2009 12:11:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:104920</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/08/25/104920.aspx#comments</comments><description>&lt;p&gt;Good progress has been&amp;nbsp;made in the R&amp;amp;D space of Identity Analytics at HP Labs (in the broader context of Security Analytics).&lt;/p&gt;
&lt;p&gt;Various IAM case studies have been explored, investigating how event-driven probabilistic modelling, coupled with economic studies, can be used to help decision makers&amp;nbsp; to make decision on investments, identify suitable metrics &amp;amp; policies, better understand the impact of choices, trade-offs and risk implications.&lt;/p&gt;
&lt;p&gt;We got a few papers accepted in international conferences, in particular at IEEE Policy 2009 Symposium, Trust Economics 2009 Workshop and IEEE MetriSec 2009 - covering various IAM aspects.&lt;/p&gt;
&lt;p&gt;A few HP Labs Technical Reports are now publicly available:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-173.html"&gt;HPL-2009-173&lt;/a&gt; &lt;i&gt;Adrian Baldwin, Marco Casassa Mont, David Pym, Simon Shiu &lt;/i&gt;- System Modelling for Economic Analysis of Security Investments: A Case Study in Identity and Access Management&amp;nbsp;- HPL-2009-173&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-142.html"&gt;HPL-2009-142&lt;/a&gt; &lt;i&gt;Yolanta Beres, Marco Casassa Mont, Jonathan Griffin, Simon Shiu &lt;/i&gt;- Using Security Metrics Coupled with Predictive Modelling and Simulation to Assess Security Processes&amp;nbsp;- HPL-2009-142&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-138.html"&gt;HPL-2009-138&lt;/a&gt; &lt;i&gt;Anna Squicciarini, Marco Casassa Mont, &lt;/i&gt;&lt;i&gt;Sathya Dev Rajasekaran - &lt;/i&gt;Towards an Analytic Approach to Evaluate Enterprises&amp;#39; Risk Exposure to Social Networks&amp;nbsp;- HPL-2009-138&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-57.html"&gt;HPL-2009-57&lt;/a&gt; &lt;i&gt;Marco Casassa Mont, Adrian Baldwin, Simon Shiu &lt;/i&gt;- Identity Analytics - User provisioning Case Study: Using Modelling and Simulation for Policy Decision Support - HPL-2009-57, 2009 &lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-56.html"&gt;HPL-2009-56&lt;/a&gt; &lt;i&gt;Adrian Baldwin, Marco Casassa Mont, Simon Shiu &lt;/i&gt;- Using Modelling and Simulation for Policy Decision Support in Identity Management - HPL-2009-56, 2009 &lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;HPL-2008-&lt;/a&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;84&lt;/a&gt; &lt;i&gt;Marco Casassa Mont, Adrian Baldwin, Simon Shiu &lt;/i&gt;- On Identity Analytics: Setting the Context- HPL-2008-84, 2008&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I am looking for input and feedback, in particular additional case studies where to apply our approach and techniques. &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=104920" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>New HP Labs Technical Report – “Systems Modelling for Economic Analyses of Security Investments: A Case Study in Identity and Access Management”</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/07/22/96054.aspx</link><pubDate>Wed, 22 Jul 2009 10:53:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:96054</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/07/22/96054.aspx#comments</comments><description>&lt;p&gt;A new HP Labs Technical Report has been released, in the area of Security and Identity Analytics, called &lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-173.html"&gt;&amp;quot;Systems Modelling for Economic Analyses of Security Investments: A Case Study in Identity and Access Management&amp;quot;&lt;/a&gt; by Adrian Baldwin, Marco Casassa Mont,&amp;nbsp; David Pym and Simon Shiu:&lt;/p&gt;
&lt;p&gt;&amp;quot;Identity and Access Management (IAM) is a key issue for systems security managers such as CISOs. More specifically, it is a difficult problem to understand how different investments in people, process, and technology affect the intended security outcomes. We position this problem within the framework of optimal control models in macroeconomics, and use a process model to understand the dynamics of the utility of possible trade-offs between investment, access, and security incidents (breaches). A utility function is used to express the security manager&amp;#39;s IAM preferences, and the functional behaviour of its components is described via a process model. Executing our process model as Monte Carlo simulations, we illustrate the behaviour of the utility function for varying levels of investment and threat, and so provide the beginnings of a decision-support tool for systems security managers.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=96054" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>EEMA e-Identity: Presentation on the Future of the Identity in the Cloud </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92647.aspx</link><pubDate>Mon, 29 Jun 2009 22:30:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92647</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92647.aspx#comments</comments><description>&lt;p&gt;I recently attended the &lt;a href="http://www.revolutionevents.plus.com/eema/index.htm"&gt;EEMA e-Identity Conference&lt;/a&gt;, in London, 25-26 June 2009. There have been interesting presentation and good talks.&lt;/p&gt;
&lt;p&gt;I also gave a presentation on &amp;quot;&lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Documents/Papers/HPL-IdentityCloud%20-%20EEMA-%20marcocasassamont.ppt"&gt;The Future of Identity in the Cloud: Requirements, Risks and Opportunities&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;This presentation aims at: setting the context about Identity in the Cloud; discussing related identity management issues along with core requirements (coming from users and organisations); illustrating, from an HP Labs&amp;#39; perspective, future possible models, approaches and IT infrastructures to handle Identity in the Cloud.&lt;/p&gt;
&lt;p&gt;The introduction of the presentation sets some background: it gives an overview of Cloud Computing and its implications, in terms of service provisioning, security, privacy and identity management. In particular it discusses the paradigm shift from a close &amp;amp; controlled approach (within enterprises) to potentially, on-the-fly composable and customisable services, in the Cloud. &lt;/p&gt;
&lt;p&gt;Use cases are introduced to illustrate &amp;quot;common&amp;quot; usage and management tasks involving Identity in the Cloud - from both user and organisational perspectives, including the implications of having to deal with Identity in composable and dynamic services. New emerging, related threats and risks are briefly discussed, such as the potential growth of bogus service providers, targeted attacks to the weakest points in the service provisioning chain and identity thefts.&lt;/p&gt;
&lt;p&gt;This will lead to a discussion of key requirements, determined by new interaction models and service-provisioning paradigms in the Cloud, including: control of identity flows and management of distributed user accounts; trust and reputation about service providers in the Cloud; identity assurance; transparency about security practices; privacy (including consent and revocation). &lt;/p&gt;
&lt;p&gt;I will then discuss current (categories of) identity management solutions and approaches that deal with aspects of Identity in the Cloud (such as identity federation, identity brokering, Identity 2.0, etc.), along with their pros and cons and failures to address some of the core requirements (such as assurance, trust and privacy control).&lt;/p&gt;
&lt;p&gt;The final part of this presentation challenges current assumptions and approaches and illustrates future directions, by presenting HP Labs&amp;#39; medium and long-term vision about how the underlying Cloud infrastructure is going to evolve along with its implication in terms of Identity and Identity Management. This includes the paradigm shifts introduced by the usage of trusted virtualisation, remote attestation of platform capabilities (Trusted Computing Platforms) and identity-driven computational environment (coming from the cloud) that could run on local systems (e.g. at the user side); new emerging identity management models driven by identity-aware platforms and policy-driven delegation of credentials; the role that Security and Identity Analytics can play, by using modelling and simulation, to help organisations to evaluating and predicting the consequences of using services in the Cloud, based on assumptions made on the underlying identity management model and existing threats.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92647" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>New HP Labs Technical Report: Towards an Analytic Approach to Evaluate Enterprises’ Risk Exposure to Social Networks </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92644.aspx</link><pubDate>Mon, 29 Jun 2009 22:22:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92644</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92644.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;
&lt;p&gt;A new HP Labs Technical Report has been recently released, called &lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-138.html"&gt;&amp;quot;Towards an Analytic Approach to Evaluate Enterprises&amp;#39; Risk Exposure to Social Networks&amp;quot; &lt;/a&gt;(authors: Anna Squicciarini, Marco Casassa Mont, Sathya Dev Rajasekaran):&lt;/p&gt;
&lt;p&gt;&amp;quot;This paper aims at exploring the impact on enterprises of the adoption of Social Networks by employees. It analyses the risks that enterprises could face and suggests a methodology to answer questions, such as: what are the actual risks for an organization, given a specific context? How to assess these risks? What are the most significant approaches that can be taken to mitigate them? What are the financial and organizational implications for an organization in implementing any of the possible approaches?&amp;quot; &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92644" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Twitter and its Privacy and Identity Management Implications</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx</link><pubDate>Thu, 12 Mar 2009 09:33:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88332</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx#comments</comments><description>&lt;p&gt;I recently started using Twitter (my link: &lt;a href="http://twitter.com/MCasassaMont"&gt;http://twitter.com/MCasassaMont&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Twitter it getting more and more popular within (and across) organisations in particular for geographically distributed teams, to share their activities and whereabouts.&lt;/p&gt;
&lt;p&gt;I am interested to better understand this tool, in particular in terms of its identity and privacy implications and long term repercussions for individuals and organisations. &lt;/p&gt;
&lt;p&gt;I see some interesting research to be potentially carried out in the context of the &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics R&amp;amp;D project&lt;/a&gt; at HP Labs and &lt;a href="http://www.encore-project.info/"&gt;UK TSB EnCoRe project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88332" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Twitter/default.aspx">Twitter</category></item><item><title>Identity Analytics: from a compliance-based to a risk-based approach</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/18/identity-analytics-from-a-compliance-based-to-a-risk-based-approach.aspx</link><pubDate>Thu, 18 Dec 2008 15:45:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:87212</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/18/identity-analytics-from-a-compliance-based-to-a-risk-based-approach.aspx#comments</comments><description>&lt;p&gt;Here is a recent, interesting article called &amp;quot;&lt;a href="http://www.banktech.com/risk-management/showArticle.jhtml?articleID=212500925"&gt;Banks Need to Take Risk-Based Approach to Data Management&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;Banks need to approach their data privacy and security from a risk point of view, according to experts with New York-based Deloitte. The firm held a webcast Tuesday that discussed how financial institutions can transform themselves from being compliance-driven organizations to risk-driven organizations, two models that are distinct, Edward Powers, a principal with the firm&amp;#39;s security and privacy practice, said. &lt;/p&gt;
&lt;p&gt;Over the last six to eight months, Powers said he has seen a continued sensitive to risk among financial institutions. &amp;quot;At the same time, I&amp;#39;ve seen significant moves to downsize budgets and human resources. This is creating strain. Most organizations are now optimizing around the things that are most urgent.&amp;quot;&amp;quot; &lt;/p&gt;
&lt;p&gt;Interestingly, this reiterates a trend and approach that I have been describing for a while, especially from a security and identity management perspective. I would extend this not only to Banks (and the FI sector), but also to enterprises and Government Agencies.&lt;/p&gt;
&lt;p&gt;I believe that, from an identity and privacy perspective, modeling and simulation (coupled with social science and economics) can provide additional support to help decision makers to better understand the consequences of their risk posture along with explaining and predicting the impact of their choices. &lt;/p&gt;
&lt;p&gt;Further information about our vision, based on &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt;, has been &amp;nbsp;provided in a few recent blog posts of mine (&lt;a href="http://www.communities.hp.com/online/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=163&amp;amp;postid=87129"&gt;here&lt;/a&gt;, &lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx"&gt;here&lt;/a&gt;), where I also discussed our view towards strategic decision support for Identity Management (and privacy ...).&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=87212" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Identity Analytics: Providing Strategic Decision Support for Identity Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/15/identity-analytics-providing-strategic-decision-support-for-identity-management.aspx</link><pubDate>Mon, 15 Dec 2008 13:45:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:87129</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/15/identity-analytics-providing-strategic-decision-support-for-identity-management.aspx#comments</comments><description>&lt;p&gt;I believe that &amp;quot;Enterprise Identity Management&amp;quot; is quickly maturing and, in some way, commoditizing, at least from a product and solution perspective. In this context, thinking about Identity Management (IdM) purely from a technical perspective is showing its limitations.&lt;/p&gt;
&lt;p&gt;Decisions on IdM aspects are increasingly made at the strategic level, as outsourcing, cost saving, balancing security with enterprise agility and usability are becoming the main drivers. &amp;nbsp;Strategic discussions on IdM include understanding the implications of new emerging scenarios and risks, such as the adoption of web 2.0 technologies within enterprises, new identity attacks (phishing, whaling, etc.), increased numbers of M&amp;amp;A and workforce reorganizations, IdM Outsourcing and adopting IdM as a Service.&lt;/p&gt;
&lt;p&gt;Key decision makers in this space, i.e. CIOs/CISOs, are driven by business needs and risk management. Some of the questions we have been exposed to include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What is the trade-off between reducing risk in tightening the access to critical applications vs. the loss in productivity as access rights are more limited and time taken to gain these access rights will increase?&lt;/li&gt;
&lt;li&gt;Is it better to spend a limited budget on user education or implementing a given technical control, such as automating user provisioning/deprovisioning or providing two-factor authentication?&lt;/li&gt;
&lt;li&gt;Should users and business units be allowed to run their own IT solutions or is it better to have centrally managed services?&lt;/li&gt;
&lt;li&gt;What is the impact of emerging collaboration technologies such as blogging, Wikis and second life?&lt;/li&gt;
&lt;li&gt;Do changes to working patterns such as greater mobility lead to additional risks? &lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;In a few recent blog posts of mine (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx"&gt;here&lt;/a&gt;) I discussed our view and approach towards strategic decision support for Identity Management, based on &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Your input is always welcome, in particular in terms of providing additional case studies and IdM areas we could apply our approach to.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=87129" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Part II: On Applying Modelling and Simulation Techniques to Identity Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/14/part-ii-on-applying-modelling-and-simulation-techniques-to-identity-management.aspx</link><pubDate>Fri, 14 Nov 2008 09:13:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86608</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/14/part-ii-on-applying-modelling-and-simulation-techniques-to-identity-management.aspx#comments</comments><description>&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&lt;font face="Times New Roman" size="3"&gt;
&lt;p&gt;Thanks to the readers that sent comments to me (interestingly, by email ...), about my previous post on &amp;quot;&lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx"&gt;Applying Modeling and Simulation techniques to Identity Management&lt;/a&gt;&amp;quot;. Feel also free to post your comments directly on the blog.&lt;/p&gt;
&lt;p&gt;An interesting question I received was about the overall scope of the R&amp;amp;D work on Identity Analytics, i.e. if it only strictly applies to the Identity Management space. &lt;/p&gt;
&lt;p&gt;I would say that the scope is wide. The goal is to include also economics aspects, people&amp;#39;s behaviours, privacy and privacy management elements along with any IT and business aspects of relevance for the analysed scenario/case study. Our models and simulations indeed represent the (risk mitigation) effects of identity controls: they do it in the context of the scenario of interest, by including the representation of involved processes, data storage, information flows along with relevant applications and services.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The outcomes of our models can vary, depending on the questions we want to answer, such as ROIs in using specific IdM solutions, trade-offs in investments, impact of controls and security on usability, etc. &lt;/p&gt;
&lt;p&gt;Hope this answer the question.&lt;/p&gt;
&lt;p&gt;Please have also a look at the Demos2k model attached to our recent HP Labs Technical Report &lt;a class="" title="OLE_LINK4" name="OLE_LINK4"&gt;&lt;/a&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-186.html"&gt;HPL-2008-186&lt;/a&gt;, for a few illustrative examples of the above points.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;/font&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86608" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>On Applying Modelling and Simulation Techniques  to Identity Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx</link><pubDate>Fri, 07 Nov 2008 15:15:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86538</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx#comments</comments><description>&lt;p&gt;At HP Labs, within the &amp;quot;Identity Analytics&amp;quot; project, we are researching how to apply modeling and simulation techniques to the domain of Identity Management, to explore and predict:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the consequences of potential decisions made by decision makers (e.g. in terms of strategic policies and adoption of controls) on key aspects such as security risks, costs, impact on reputation, etc.; &lt;/li&gt;
&lt;li&gt;the impact of identity management solutions on IT infrastructures, people and business contexts;&lt;/li&gt;
&lt;li&gt;the implications of people behaviours on security and privacy aspects.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;The aim is to help decision makers to assess the consequences of their decisions and explore investment trade-offs. In particular, assessing the impacts on security risks and costs is very important: given the current global financial situation, the &amp;quot;cost&amp;quot; dimension is going to play more and more a key role. &lt;/p&gt;
&lt;p&gt;We published a few HP Labs Technical Reports to provide an overview of our R&amp;amp;D work, including &lt;a class="" title="OLE_LINK4" name="OLE_LINK4"&gt;&lt;/a&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-186.html"&gt;HPL-2008-186&lt;/a&gt; and&amp;nbsp;&amp;nbsp; &lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;HPL-2008-84&lt;/a&gt;. In particular, the most recent &lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-186.html"&gt;HPL-2008-186&lt;/a&gt; report provides and example of a model (based on the Demos2K simulation framework) we used to carry out our simulations and trade-off analysis in a &amp;quot;data sharing collaborative scenario&amp;quot;.&lt;/p&gt;
&lt;p&gt;Many case studies can potentially be explored with our approach, including Web 2.0 collaborative services, access and protection of critical business applications and services, user account lifecycle management processes, data flows and lifecycle management, identity theft scenarios, etc. &lt;/p&gt;
&lt;p&gt;I would be interested in discussing this topic with this community, in particular about related work and exploring any specific requirement or case study you might have in this space. &lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86538" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Research Study: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/05/research-study-huge-amount-of-sensitive-data-still-on-redundant-computer-hard-disk.aspx</link><pubDate>Wed, 05 Nov 2008 15:35:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86504</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/05/research-study-huge-amount-of-sensitive-data-still-on-redundant-computer-hard-disk.aspx#comments</comments><description>&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;
&lt;p&gt;This interesting &lt;a href="http://www.sciencedaily.com/releases/2008/11/081105083549.htm"&gt;article&lt;/a&gt;, called &amp;quot;Identity Theft Risks: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk&amp;quot; provides an overview of a research study to be published soon - warning about the risk of data left on devices to be decommissioned:&lt;/p&gt;
&lt;p&gt;&amp;quot;Ongoing research to be published in the International Journal of Liability and Scientific Enquiry suggests that there is a huge amount of sensitive data still on redundant computer hard disks. These devices are often disposed of or sold into the second-hand market by corporations, organizations, and individuals with the data intact. The report&amp;#39;s authors say that this data represents a significant level of risk for commercial sabotage, identity theft, and even political compromise, and suggest that better education is essential to reduce the risk of harm. ...&lt;/p&gt;
&lt;p&gt;The 2007 study is being made available in its entirety through the International Journal of Liability and Scientific Enquiry. The team is now completing the 2008 analysis and will announce those results shortly as well. However, the initial results for the 2008 study show that there is still a long way to go regarding the decommissioning of computer hard disk drives. The team expects that the complete 2008 study will be made available for publication by the end of the year.&amp;quot;&lt;/p&gt;
&lt;p&gt;This is an area where &amp;quot;classic&amp;quot; identity management (based on control points) shows its limits. The explicit management of IdM strategic policies, related processes and risks should be a key part of &amp;quot;identity management&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;&amp;quot;Identity Analytics&amp;quot;&lt;/a&gt; could also be of some help here, to understand the implications of policies and possible strategic decisions (given specific IT and IdM frameworks), along with exploring investment trade-offs.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;/span&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86504" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Part II: Risk Management for Unstructured Data in Enterprises</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/04/part-ii-risk-management-for-unstructured-data-in-enterprises.aspx</link><pubDate>Thu, 04 Sep 2008 13:09:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84600</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/04/part-ii-risk-management-for-unstructured-data-in-enterprises.aspx#comments</comments><description>&lt;p&gt;In a recent post published on the &lt;a href="http://sgciam.wordpress.com/2008/09/04/risk-management-and-information/"&gt;Netweaver Identity Manager Weblog&lt;/a&gt;, the author&amp;nbsp; has made a few comments about my post on &lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/02/risk-management-for-unstructured-data-in-enterprises.aspx"&gt;&amp;quot;Risk Management for Unstructured Data in Enterprises&amp;quot;&lt;/a&gt; (well, actually the published URL to my post is apparently broken ...). &lt;/p&gt;
&lt;p&gt;Thanks for this input, in particular about three main points that I (tried to) summarise as it follows:&lt;/p&gt;
&lt;p&gt;1) Meaning of unstructured data (or the fact that unstructured data does not exist by definition ...)&lt;/p&gt;
&lt;p&gt;2) Narrowness of perception of approaches and incompleteness of my list of required solutions&lt;/p&gt;
&lt;p&gt;3) Availability of comprehensive methodology for implementing enterprise wide risk management&lt;/p&gt;
&lt;p&gt;About point 1), this looks pretty much a philosophical discussion. No doubt that, at the end, we talk about information that has some sort of structure (well, an email has a header, a body with some texts and attachments; a document is made of paragraphs or lines of text; ...). However, the (maybe over-hyped) &amp;quot;unstructured data&amp;quot; term is currently used to (a) identify specific types of information and (b) contrast it against classic &amp;quot;structured data&amp;quot; (e.g. information stored in RDBMS repositories, etc.).&amp;nbsp; I think I will stick with this terminology ...&lt;/p&gt;
&lt;p&gt;Back to the key point, recent reports (including the Ponemon Institute&amp;#39;s survey on &amp;quot;Governance of Unstructured Data&amp;quot; and other market and research reports) indeed highlight that the management of unstructured data in enterprises is a raising concern for enterprises, both in terms of governance and risk management. I think this is what really matters - independently from the terminology.&lt;/p&gt;
&lt;p&gt;No doubt that classification of data is an important point, especially if you ever manage to &amp;quot;find&amp;quot; where this &amp;quot;unstructured data&amp;quot; is, within a complex enterprise environment ... I would say that, given the particular nature of &amp;quot;unstructured data&amp;quot;, a preliminary &amp;quot;data discovery&amp;quot; phase might be required, indeed followed by a classification and assessment of its value (considering though, that the value of some of this information might also come from aggregations and correlations ...).&lt;/p&gt;
&lt;p&gt;About point 2), by no means my post was meant to provide a definitive or comprehensive assessment and answer to the problem of information risk management or, more specifically, on &amp;quot;unstructured&amp;quot; information risk management. It was just a statement of some &amp;quot;desirable&amp;quot; properties and capabilities that I would like to see (and I know it would be of some help to customers ...).&lt;/p&gt;
&lt;p&gt;I am well aware of the complexity of the overall &amp;nbsp;(security) &amp;quot;enterprise risk assessment and management&amp;quot; problem, its extent and the fact that, when assessing and managing (security) risks, many factors are involved, including business goals, IT, other assets, people, processes, awareness/education, etc.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;(Security) risk assessment and management techniques/methodologies/frameworks and standards/etc. are indeed out there (e.g. ISO 27005/2700x, CoBIT, etc.). These &amp;quot;standards&amp;quot; provide guidelines and criteria to be carefully refined, grounded and contextualized in various &amp;quot;operational&amp;quot; realities, along with some good, common sense ...&lt;/p&gt;
&lt;p&gt;So, no doubt that there are already &amp;quot;comprehensive methodology for implementing enterprise wide risk management&amp;quot;, at least from a consulting perspective, but this was not my main point. &lt;/p&gt;
&lt;p&gt;My main point was not so focused on these methodologies but rather on the need to better understand and possibly improve the process of exploring, explaining and predicting the consequences and impacts of strategic (policy) choices and decisions in enterprise contexts and environments, in particular when dealing with security matters. &lt;/p&gt;
&lt;p&gt;An approach that we are currently exploring is based on modeling and simulation techniques in the security field, coupled with economic theory and social science. Please have a look at the &lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;HPL Technical Report on &amp;quot;Identity Analytics&amp;quot;&lt;/a&gt; that I mentioned a few times - to see what I mean, in more details (at least from an &amp;quot;IdM perspective&amp;quot;). &lt;/p&gt;
&lt;p&gt;Specifically, one of my R&amp;amp;D interests is in &amp;quot;(semi-) automation&amp;quot; tools and solutions in this space that can indeed help and support professional and consulting services in their risk assessment &amp;amp; management activities. This includes providing decision support and &amp;quot;what-if analysis&amp;quot;, involving modeling and simulation, providing trade-off analysis, etc. &lt;/p&gt;
&lt;p&gt;Given the complexity of this space, I deliberately focused on the aspect of &amp;quot;management of unstructured data&amp;quot; and the IdM perspective, well conscious this is just a part of the overall problem and space. &lt;/p&gt;
&lt;p&gt;I hope I clarified this point.&lt;/p&gt;
&lt;p&gt;About point 3), no doubt about this, as I mentioned above.&lt;/p&gt;
&lt;p&gt;However the statement that &amp;quot;comprehensive methodology for implementing enterprise wide risk management is done&amp;quot; sounds (at least to me) sounds a little bit abstract to me ... &lt;/p&gt;
&lt;p&gt;It would be of some interest to the readers of this blog if this statement could be elaborated (specifically in the space of IdM and information management) along with providing some recommendations/input/directions (hopefully beyond having to hire a consulting company ...:-)).&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84600" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Unstructured+Data/default.aspx">Unstructured Data</category></item><item><title>Risk Management for Unstructured Data in Enterprises</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/02/risk-management-for-unstructured-data-in-enterprises.aspx</link><pubDate>Mon, 01 Sep 2008 16:21:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84551</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/02/risk-management-for-unstructured-data-in-enterprises.aspx#comments</comments><description>&lt;p&gt;In the context of the HP Labs&amp;#39; Security and &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt; project I have been investigating the implications of &amp;quot;unstructured data&amp;quot; (i.e. emails, documents, multimedia files, pages in data sharing sites, messages exchanged with Instant Messaging tools, blog posts, data mash-ups, etc.) within organizations, along with how to explain and predict involved risks and explore the consequences of related security (policy) choices.&lt;/p&gt;
&lt;p&gt;Is &amp;quot;unstructured data&amp;quot; really a problem for organizations? If so, where is this problem? Well, the content of unstructured data (and/or an aggregation of it) can be confidential as it might include personal, financial and business-critical information. Because of the nature of unstructured data (and associated, emerging tools to handle and share it), there are many ways this data could leak and/or be misused, ranging from accidental disclosures to aggregations of information posted in public areas.&lt;/p&gt;
&lt;p&gt;The threat landscape (including threats to data confidentiality, integrity and availability) is potentially broad as many contextual elements, IT components, processes and behavioral aspects are involved.&lt;/p&gt;
&lt;p&gt;Most of the current approaches (I am aware of), that mitigate some of the involved risks, are based on traditional IT security and identity &amp;quot;control points&amp;quot; (such as access control, interception points, complex document lifecycle management tools, etc.), addressing &amp;quot;point problems&amp;quot;.&lt;/p&gt;
&lt;p&gt;I believe this is not enough. Solutions are required to help organizations (and decision makers) to: (1) fully understand the nature of the problem, based on their specific context and environment; (2) have a picture of their overall risk exposure; (3) make informed decisions on which approaches to follow, explain and predict the consequences and define appropriate policies; (3) explore trade-offs.&lt;/p&gt;
&lt;p&gt;So far I have found no comprehensive approach/solution providing these features. Is anybody aware of any? &lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84551" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Unstructured+Data/default.aspx">Unstructured Data</category></item><item><title>Part III: Identity Analytics and Unstructured Data Analysis</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/25/part-iii-identity-analytics-and-unstructured-data-analysis.aspx</link><pubDate>Fri, 25 Jul 2008 13:11:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84009</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/25/part-iii-identity-analytics-and-unstructured-data-analysis.aspx#comments</comments><description>&lt;p&gt;In previous posts of mine (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/13/on-identity-analytics-part-ii.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/09/on-identity-analytics-new-hp-labs-technical-report.aspx"&gt;here&lt;/a&gt;) I introduced our vision of Identity Analytics and the focus and purposes of our R&amp;amp;D activities.&lt;/p&gt;
&lt;p&gt;I received a few emails and queries asking to clarify the link between Identity Analytics and Unstructured Data, considering that this was mentioned in the &amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;On Identity Analytics: Setting the Context&lt;/a&gt;&amp;quot; HPL Technical Report.&lt;/p&gt;
&lt;p&gt;We believe that &amp;quot;Unstructured Data&amp;quot; is a possible, fertile and rich &amp;quot;case study&amp;quot;/scenario where to explore the concept of Identity Analytics, the applicability of our approach and potential limitations..&lt;/p&gt;
&lt;p&gt;The adoption of new &amp;quot;web 2.0&amp;quot; collaborative tools within organizations (TWiki, Sharepoint, IM, etc.) and social networks (Facebook, LinkedIn, del.icio.us, etc.) provides users with better ways to collaborate, create and share contents. At the same time this poses new threats and security risks, due to the nature of unstructured data, the fact that confidentiality issues could emerge from aggregated, simpler pieces of information and the difficulty to retain control on this data. This is where traditional Identity management solutions can show their limitations and where decision makers need to better understand the implications of their choices and/or the impact of defining new policies.&lt;/p&gt;
&lt;p&gt;Our R&amp;amp;D work in Identity Analytics really aims, in this context, to explore how modeling and simulation can help to explain and predict the impact of some of these decisions on the organizations (e.g. in terms of risks, reputation, costs, etc.) and explore options and &amp;quot;trade-offs&amp;quot; by providing &amp;quot;what-if&amp;quot; analysis.&lt;/p&gt;
&lt;p&gt;Of course the &amp;quot;unstructured data&amp;quot; scenario is just one of the various scenarios we are exploring. I would be interested in hearing from you about other areas you think the &amp;quot;Identity Analytics&amp;quot; approach could provide help and/or address (decision support) issues you might have.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84009" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Unstructured+Data/default.aspx">Unstructured Data</category></item><item><title>On Identity Analytics - Part II</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/13/on-identity-analytics-part-ii.aspx</link><pubDate>Sat, 12 Jul 2008 17:08:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83749</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/13/on-identity-analytics-part-ii.aspx#comments</comments><description>&lt;p&gt;In a previous post of mine I announced the release of a new HPL Technical Report, titled &amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;On Identity Analytics: Setting the Context&lt;/a&gt;&amp;quot; (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu), providing an overview of an HP Labs R&amp;amp;D project in the space of &amp;quot;Identity Analytics&amp;quot;. &lt;/p&gt;
&lt;p&gt;I received a few emails asking (among other things) about HP/HPL strategies in Identity Management and how Identity Analytics fits in all this. Some additional details follow, based on what I can publicly discuss.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.hpl.hp.co.uk/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt; is an HP Labs project, in the context of the Security Analytics project (&lt;a href="http://www.hpl.hp.com/research/systems_security.html"&gt;Systems Security Lab&lt;/a&gt;). The R&amp;amp;D goal of this project is to innovate in the space of Identity Management (in a broad sense, i.e. including also human, social and economic aspects) by moving from an approach purely based on operational Identity Management solutions to an approach that also takes into accounts the &amp;quot;strategic&amp;quot; needs and requirements of key decision makers (e.g. CIOs/CISOs).&lt;/p&gt;
&lt;p&gt;What is the impact on an organisation (e.g. in terms of costs, risks, reputation, trust, etc.) when making strategic decisions and/or defining policies in the space of Identity Management? Are current policies adequate based on current (business, security, etc.) objectives? How technical, educational, human, social and business aspects are going to affect the (economic, security and business) outcomes, based on choices and decisions made?&amp;nbsp; What are the relevant trade-offs that need to be analysed and how to evaluate them? How to provide strategic, forward-looking, &amp;quot;what-if&amp;quot; analysis to decision makers? These are some of the questions to be answered ...&lt;/p&gt;
&lt;p&gt;This is a green field, open to innovation. In this context, technical Identity Management solutions are just one aspect of the overall equation (and sometimes not the most important ...), that also includes costs, (security and business) risks, business priorities and economic aspects. &lt;/p&gt;
&lt;p&gt;I am confident that there are new business and market opportunities in this space, considering also the current shift (backed by key decision makers) from a pure &amp;quot;compliance-based&amp;quot; approach to a &amp;quot;risk-based&amp;quot; approach ...&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83749" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>On Identity Analytics: New HP Labs Technical Report</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/09/on-identity-analytics-new-hp-labs-technical-report.aspx</link><pubDate>Wed, 09 Jul 2008 09:35:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83657</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/09/on-identity-analytics-new-hp-labs-technical-report.aspx#comments</comments><description>&lt;p&gt;This community might be interested to a new HPL Technical Report, just released, titled &amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;On Identity Analytics: Setting the Context&lt;/a&gt;&amp;quot; (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu). &lt;/p&gt;
&lt;p&gt;This report reflects R&amp;amp;D work we are doing at HP Labs, &lt;a href="http://www.hpl.hp.com/research/systems_security.html"&gt;Systems Security Lab&lt;/a&gt;. I am very keen in getting your views and input. The abstract of this technical report follows:&lt;/p&gt;
&lt;p&gt;&amp;quot;This paper aims at setting the context for &amp;quot;Identity Analytics&amp;quot; within enterprises and paving the path towards new R&amp;amp;D opportunities. In our vision, Identity Analytics is about explaining and predicting the impact of identity and identity management (along with other related aspects, such as users&amp;#39; behaviours) on key factors of relevance to decision makers (e.g. CIOs, CISOs), in complex enterprise scenarios - based on their initial assumptions and investment decisions. &lt;/p&gt;
&lt;p&gt;Ultimately the goal is to provide rigorous techniques to help decision makers gain a better understanding of the investment trade-offs within the identity space (e.g. investing in technologies vs. changing processes vs. investing in users&amp;#39; education, etc.). This means providing &amp;quot;decision support&amp;quot; and &amp;quot;what-if analysis&amp;quot; capabilities to decision makers enabling them to explore these investment trade-offs, formulate new policies and/or justify existing ones. Our vision of &amp;quot;Identity Analytics&amp;quot; is introduced and discussed, along with the methodology that we intend to adopt. &lt;/p&gt;
&lt;p&gt;There are many research opportunities and challenges in this space: we believe that a scientific approach is required, involving the usage of modelling and simulation techniques, coupled with the understanding of involved technologies and processes, human behaviours and economic aspects. To ground some of the concepts discussed in this paper, we provide an illustration of Identity Analytics focusing on emerging &amp;quot;web 2.0 enterprise collaborative data sharing&amp;quot;, where unstructured information is created, stored and shared by people in collaborative contexts, within and across organisations. We demonstrate how trade-offs can be explored using the modelling approach hence allowing decision makers to explore the different impacts of policy choices.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83657" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CIO/default.aspx">CIO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/trade-offs/default.aspx">trade-offs</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/decision+support+system/default.aspx">decision support system</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/what-if+analysis/default.aspx">what-if analysis</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/decision+makers/default.aspx">decision makers</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/CISO/default.aspx">CISO</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/simulation/default.aspx">simulation</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/modelling/default.aspx">modelling</category></item></channel></rss>