<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : diversity</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/diversity/default.aspx</link><description>Tags: diversity</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Identity Management and the IT Monoculture </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/05/identity-management-and-the-it-monoculture.aspx</link><pubDate>Wed, 04 Mar 2009 17:55:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88190</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/05/identity-management-and-the-it-monoculture.aspx#comments</comments><description>&lt;p&gt;A recent &lt;a href="http://www2.computer.org/portal/c/document_library/get_file?uuid=a9f8e91d-30f5-4420-9c3f-e1ac4bed7f9a&amp;amp;groupId=53319"&gt;article&lt;/a&gt; (called &amp;quot;IT Monoculture: Security Risks and Defenses&amp;quot;) published by the IEEE Security and Privacy magazine, discusses pros and cons of having an IT Monoculture, i.e. where no diversity is introduced for specific IT solutions deployed within organizations.&lt;/p&gt;
&lt;p&gt;Quite interestingly this applies also for Identity Management. On one side deploying the same Identity Management (IAM) solutions across an organization increases efficiency, central control and uniformity. On the other hand, it might potentially increases the exposure of the organization to threats and related risks.&lt;/p&gt;
&lt;p&gt;I guess that, at the end, it is a matter of economics, involving trade-offs between involved costs, security and productivity. &lt;/p&gt;
&lt;p&gt;This is an area where modeling and simulation (see Security and &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;&amp;nbsp;Identity Analytics&lt;/a&gt;) might be of some help, to explore, predict and identify the most suitable approach for an organization, given the organization profile and the underlying threat environment.&lt;/p&gt;
&lt;p&gt;Just wondering if there is any recent, official study (I have not yet found it ...) exploring the current level of &amp;quot;IAM-diversity&amp;quot; within organizations. Any pointer/link would be welcome ... &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88190" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAM/default.aspx">IAM</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IT+monoculture/default.aspx">IT monoculture</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/diversity/default.aspx">diversity</category></item></channel></rss>