<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : identity management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx</link><description>Tags: identity management</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Research on Security and Identity Management   </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116411.aspx</link><pubDate>Fri, 09 Oct 2009 17:22:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:116411</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/10/10/116411.aspx#comments</comments><description>&lt;p&gt;The time has come to update the topic (and focus) of this blog. &lt;/p&gt;
&lt;p&gt;In the last few years my R&amp;amp;D work and research at HP Labs has been involving a variety of aspects, including security, identity management and privacy.&lt;/p&gt;
&lt;p&gt;Most of my posts have actually been reflecting this - hence my decision to update my blog. Hope this will further increase the community of people that are interested and follow my blog.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=116411" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/security/default.aspx">security</category></item><item><title>EEMA e-Identity: Presentation on the Future of the Identity in the Cloud </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92647.aspx</link><pubDate>Mon, 29 Jun 2009 22:30:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92647</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92647.aspx#comments</comments><description>&lt;p&gt;I recently attended the &lt;a href="http://www.revolutionevents.plus.com/eema/index.htm"&gt;EEMA e-Identity Conference&lt;/a&gt;, in London, 25-26 June 2009. There have been interesting presentation and good talks.&lt;/p&gt;
&lt;p&gt;I also gave a presentation on &amp;quot;&lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Documents/Papers/HPL-IdentityCloud%20-%20EEMA-%20marcocasassamont.ppt"&gt;The Future of Identity in the Cloud: Requirements, Risks and Opportunities&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;This presentation aims at: setting the context about Identity in the Cloud; discussing related identity management issues along with core requirements (coming from users and organisations); illustrating, from an HP Labs&amp;#39; perspective, future possible models, approaches and IT infrastructures to handle Identity in the Cloud.&lt;/p&gt;
&lt;p&gt;The introduction of the presentation sets some background: it gives an overview of Cloud Computing and its implications, in terms of service provisioning, security, privacy and identity management. In particular it discusses the paradigm shift from a close &amp;amp; controlled approach (within enterprises) to potentially, on-the-fly composable and customisable services, in the Cloud. &lt;/p&gt;
&lt;p&gt;Use cases are introduced to illustrate &amp;quot;common&amp;quot; usage and management tasks involving Identity in the Cloud - from both user and organisational perspectives, including the implications of having to deal with Identity in composable and dynamic services. New emerging, related threats and risks are briefly discussed, such as the potential growth of bogus service providers, targeted attacks to the weakest points in the service provisioning chain and identity thefts.&lt;/p&gt;
&lt;p&gt;This will lead to a discussion of key requirements, determined by new interaction models and service-provisioning paradigms in the Cloud, including: control of identity flows and management of distributed user accounts; trust and reputation about service providers in the Cloud; identity assurance; transparency about security practices; privacy (including consent and revocation). &lt;/p&gt;
&lt;p&gt;I will then discuss current (categories of) identity management solutions and approaches that deal with aspects of Identity in the Cloud (such as identity federation, identity brokering, Identity 2.0, etc.), along with their pros and cons and failures to address some of the core requirements (such as assurance, trust and privacy control).&lt;/p&gt;
&lt;p&gt;The final part of this presentation challenges current assumptions and approaches and illustrates future directions, by presenting HP Labs&amp;#39; medium and long-term vision about how the underlying Cloud infrastructure is going to evolve along with its implication in terms of Identity and Identity Management. This includes the paradigm shifts introduced by the usage of trusted virtualisation, remote attestation of platform capabilities (Trusted Computing Platforms) and identity-driven computational environment (coming from the cloud) that could run on local systems (e.g. at the user side); new emerging identity management models driven by identity-aware platforms and policy-driven delegation of credentials; the role that Security and Identity Analytics can play, by using modelling and simulation, to help organisations to evaluating and predicting the consequences of using services in the Cloud, based on assumptions made on the underlying identity management model and existing threats.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92647" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Twitter and its Privacy and Identity Management Implications</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx</link><pubDate>Thu, 12 Mar 2009 09:33:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88332</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx#comments</comments><description>&lt;p&gt;I recently started using Twitter (my link: &lt;a href="http://twitter.com/MCasassaMont"&gt;http://twitter.com/MCasassaMont&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Twitter it getting more and more popular within (and across) organisations in particular for geographically distributed teams, to share their activities and whereabouts.&lt;/p&gt;
&lt;p&gt;I am interested to better understand this tool, in particular in terms of its identity and privacy implications and long term repercussions for individuals and organisations. &lt;/p&gt;
&lt;p&gt;I see some interesting research to be potentially carried out in the context of the &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics R&amp;amp;D project&lt;/a&gt; at HP Labs and &lt;a href="http://www.encore-project.info/"&gt;UK TSB EnCoRe project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88332" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Twitter/default.aspx">Twitter</category></item><item><title>2009-2010: Predictions about Identity and Privacy Management </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/30/2009-2010-predictions-about-identity-and-privacy-management.aspx</link><pubDate>Mon, 29 Dec 2008 16:02:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:87309</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/30/2009-2010-predictions-about-identity-and-privacy-management.aspx#comments</comments><description>&lt;p&gt;During the next two years (2009-2010), the Identity and Privacy Management areas are going to be subject to the consolidation and cost cutting trends that are already happening in security and, more in general, in IT.&lt;/p&gt;
&lt;p&gt;In my view investments in Identity Management (IdM) are going to be very pragmatic, also driven by the need to: manage a very &amp;quot;variable&amp;quot; workforce; cope with an increase of internal enterprise reorganizations and consolidations; deal with an increased number of identity thefts and related attacks.&lt;/p&gt;
&lt;p&gt;As such I believe that the IdM areas that will get most of the market attentions are going to be in the areas of:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Entitlement management (and automated user provisioning)&lt;/li&gt;
&lt;li&gt;Enterprise SSO&lt;/li&gt;
&lt;li&gt;Authentication strategies&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;I don&amp;#39;t believe that client-based federated identity management and advanced authorization solutions will be driving the Identity Management space, during this period of time.&lt;/p&gt;
&lt;p&gt;From a Privacy Management perspective, I still believe that most of the action will happen in R&amp;amp;D contexts.&lt;/p&gt;
&lt;p&gt;Of course, this is my view, based on some evidence and intuitions. I would be interested in getting your opinions.&lt;/p&gt;
&lt;p&gt;I am also planning to compile a list of world-wide R&amp;amp;D projects and (industrial/university-based) R&amp;amp;D activities in the space of Identity and Privacy Management. I will post information about this. Of course, feel free to send me your input and relevant URLs.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=87309" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category></item><item><title>Article: Changing business landscape makes IAM key to IT Security</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/20/article-changing-business-landscape-makes-iam-key-to-it-security.aspx</link><pubDate>Wed, 19 Nov 2008 17:24:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86687</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/20/article-changing-business-landscape-makes-iam-key-to-it-security.aspx#comments</comments><description>&lt;p&gt;Here is a recent, interesting article, called &amp;quot;&lt;a href="http://blogs.zdnet.com/Gardner/?p=2758"&gt;Changing business landscape makes identity and access management key to IT security&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;In an age of significant layoffs and corporate restructuring, the burgeoning problem of identity and access management for IT operations and data centers has escalated into a critical security issue. Managing who gets access to which resources for how long - and under what circumstances - has become a huge and thorny problem. Improper and overextended access to sensitive data and powerful applications can cause massive risk as many employees find themselves in flux.&amp;quot;&lt;/p&gt;
&lt;p&gt;This article provides some excerpts from a discussion with Dan Rueckert (worldwide practice director for security and risk management in HP&amp;#39;s Consulting and Integration group); Archie Reed (distinguished technologist in HP&amp;#39;s security office in the Enterprise Storage and Server Group), and Mark Tice (vice president of identity management at Oracle).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86687" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/risk+management/default.aspx">risk management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAM/default.aspx">IAM</category></item><item><title>Part II: On Applying Modelling and Simulation Techniques to Identity Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/14/part-ii-on-applying-modelling-and-simulation-techniques-to-identity-management.aspx</link><pubDate>Fri, 14 Nov 2008 09:13:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86608</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/14/part-ii-on-applying-modelling-and-simulation-techniques-to-identity-management.aspx#comments</comments><description>&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&lt;font face="Times New Roman" size="3"&gt;
&lt;p&gt;Thanks to the readers that sent comments to me (interestingly, by email ...), about my previous post on &amp;quot;&lt;a href="http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx"&gt;Applying Modeling and Simulation techniques to Identity Management&lt;/a&gt;&amp;quot;. Feel also free to post your comments directly on the blog.&lt;/p&gt;
&lt;p&gt;An interesting question I received was about the overall scope of the R&amp;amp;D work on Identity Analytics, i.e. if it only strictly applies to the Identity Management space. &lt;/p&gt;
&lt;p&gt;I would say that the scope is wide. The goal is to include also economics aspects, people&amp;#39;s behaviours, privacy and privacy management elements along with any IT and business aspects of relevance for the analysed scenario/case study. Our models and simulations indeed represent the (risk mitigation) effects of identity controls: they do it in the context of the scenario of interest, by including the representation of involved processes, data storage, information flows along with relevant applications and services.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;The outcomes of our models can vary, depending on the questions we want to answer, such as ROIs in using specific IdM solutions, trade-offs in investments, impact of controls and security on usability, etc. &lt;/p&gt;
&lt;p&gt;Hope this answer the question.&lt;/p&gt;
&lt;p&gt;Please have also a look at the Demos2k model attached to our recent HP Labs Technical Report &lt;a class="" title="OLE_LINK4" name="OLE_LINK4"&gt;&lt;/a&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-186.html"&gt;HPL-2008-186&lt;/a&gt;, for a few illustrative examples of the above points.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;/font&gt;&lt;font face="Times New Roman" size="3"&gt;&lt;/font&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86608" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>On Applying Modelling and Simulation Techniques  to Identity Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx</link><pubDate>Fri, 07 Nov 2008 15:15:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86538</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/07/on-applying-modelling-and-simulation-techniques-to-identity-management.aspx#comments</comments><description>&lt;p&gt;At HP Labs, within the &amp;quot;Identity Analytics&amp;quot; project, we are researching how to apply modeling and simulation techniques to the domain of Identity Management, to explore and predict:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the consequences of potential decisions made by decision makers (e.g. in terms of strategic policies and adoption of controls) on key aspects such as security risks, costs, impact on reputation, etc.; &lt;/li&gt;
&lt;li&gt;the impact of identity management solutions on IT infrastructures, people and business contexts;&lt;/li&gt;
&lt;li&gt;the implications of people behaviours on security and privacy aspects.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;The aim is to help decision makers to assess the consequences of their decisions and explore investment trade-offs. In particular, assessing the impacts on security risks and costs is very important: given the current global financial situation, the &amp;quot;cost&amp;quot; dimension is going to play more and more a key role. &lt;/p&gt;
&lt;p&gt;We published a few HP Labs Technical Reports to provide an overview of our R&amp;amp;D work, including &lt;a class="" title="OLE_LINK4" name="OLE_LINK4"&gt;&lt;/a&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-186.html"&gt;HPL-2008-186&lt;/a&gt; and&amp;nbsp;&amp;nbsp; &lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;HPL-2008-84&lt;/a&gt;. In particular, the most recent &lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-186.html"&gt;HPL-2008-186&lt;/a&gt; report provides and example of a model (based on the Demos2K simulation framework) we used to carry out our simulations and trade-off analysis in a &amp;quot;data sharing collaborative scenario&amp;quot;.&lt;/p&gt;
&lt;p&gt;Many case studies can potentially be explored with our approach, including Web 2.0 collaborative services, access and protection of critical business applications and services, user account lifecycle management processes, data flows and lifecycle management, identity theft scenarios, etc. &lt;/p&gt;
&lt;p&gt;I would be interested in discussing this topic with this community, in particular about related work and exploring any specific requirement or case study you might have in this space. &lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86538" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Research Study: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/05/research-study-huge-amount-of-sensitive-data-still-on-redundant-computer-hard-disk.aspx</link><pubDate>Wed, 05 Nov 2008 15:35:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86504</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/11/05/research-study-huge-amount-of-sensitive-data-still-on-redundant-computer-hard-disk.aspx#comments</comments><description>&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;
&lt;p&gt;This interesting &lt;a href="http://www.sciencedaily.com/releases/2008/11/081105083549.htm"&gt;article&lt;/a&gt;, called &amp;quot;Identity Theft Risks: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk&amp;quot; provides an overview of a research study to be published soon - warning about the risk of data left on devices to be decommissioned:&lt;/p&gt;
&lt;p&gt;&amp;quot;Ongoing research to be published in the International Journal of Liability and Scientific Enquiry suggests that there is a huge amount of sensitive data still on redundant computer hard disks. These devices are often disposed of or sold into the second-hand market by corporations, organizations, and individuals with the data intact. The report&amp;#39;s authors say that this data represents a significant level of risk for commercial sabotage, identity theft, and even political compromise, and suggest that better education is essential to reduce the risk of harm. ...&lt;/p&gt;
&lt;p&gt;The 2007 study is being made available in its entirety through the International Journal of Liability and Scientific Enquiry. The team is now completing the 2008 analysis and will announce those results shortly as well. However, the initial results for the 2008 study show that there is still a long way to go regarding the decommissioning of computer hard disk drives. The team expects that the complete 2008 study will be made available for publication by the end of the year.&amp;quot;&lt;/p&gt;
&lt;p&gt;This is an area where &amp;quot;classic&amp;quot; identity management (based on control points) shows its limits. The explicit management of IdM strategic policies, related processes and risks should be a key part of &amp;quot;identity management&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.hpl.hp.com/techreports/2008/HPL-2008-84.html"&gt;&amp;quot;Identity Analytics&amp;quot;&lt;/a&gt; could also be of some help here, to understand the implications of policies and possible strategic decisions (given specific IT and IdM frameworks), along with exploring investment trade-offs.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;/span&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86504" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Data+Privacy/default.aspx">Data Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category></item><item><title>Identity Management in the Cloud</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/10/02/identity-management-in-the-cloud.aspx</link><pubDate>Thu, 02 Oct 2008 08:27:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:85995</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>4</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/10/02/identity-management-in-the-cloud.aspx#comments</comments><description>&lt;p&gt;This article, called &amp;quot;&lt;a href="http://www.networkworld.com/podcasts/com/2008/092908com-cloud-id-mgmt.html?tc=sec"&gt;ID Management In the World of Cloud Services&lt;/a&gt;&amp;quot; (and a related podcast) is quite interesting, as it is thought provoking.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The advent of cloud services and services on demand is indeed likely to change the identity management landscape: most of current identity management solutions are focused on the enterprise and/or a very controlled, static environment. User-centric identity management solutions (such as various federated identity management) also make some assumptions on the involved parties (e.g. SP, IdP parties) and their related services.&lt;/p&gt;
&lt;p&gt;In a world where services are offered on demand, in the cloud and they can continuously evolve, some of these models are going to be challenged, for example, in terms of trust assumptions, privacy implications and operational aspects of authentication and authorization.&lt;/p&gt;
&lt;p&gt;Is anybody aware of studies in this space? What is your view?&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=85995" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/cloud/default.aspx">cloud</category></item><item><title>Announcing EnCoRe (Ensuring Consent and Revocation): a new UK IT Collaborative Project</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/20/announcing-encore-ensuring-consent-and-revocation-a-new-uk-it-collaborative-project.aspx</link><pubDate>Fri, 19 Sep 2008 16:23:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84822</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/20/announcing-encore-ensuring-consent-and-revocation-a-new-uk-it-collaborative-project.aspx#comments</comments><description>&lt;p&gt;A new UK IT collaborative project has been officially announced: &lt;a href="http://www.encore-project.info/"&gt;EnCoRe&lt;/a&gt; - Ensuring Consent and Revocation (some initial press releases: &lt;a href="http://uk.news.yahoo.com/vdunet/20080912/ttc-encore-project-aims-to-boost-user-pr-6315470.html"&gt;here&lt;/a&gt; and &lt;a href="http://www2.warwick.ac.uk/fac/sci/wmg/mediacentre/wmgnews/uk_academics_turn/"&gt;here&lt;/a&gt;):&lt;/p&gt;
&lt;p&gt;&amp;quot;As more and more personal information flows from individuals to organisations when they interact online, people are becoming more and more concerned that they can not effectively control what this information is used for, with which other organisations it is shared, and where it is stored. They may have given their consent, often in vague terms and implicitly, for its use, sharing and storage, but they have no real control over the specifics of these, nor the ability to revoke their consent and be sure that their wish is respected. In summary, they are not able to control where their personal information flows to, and this makes them uneasy about interacting online.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;The overall vision of this project is to make giving consent as reliable and easy as turning on a tap, and revoking that consent as reliable and easy as turning it off again.&amp;quot;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;This &lt;span style="FONT-SIZE:12pt;FONT-FAMILY:&amp;#39;Times New Roman&amp;#39;;mso-fareast-font-family:&amp;#39;Times New Roman&amp;#39;;mso-ansi-language:EN-GB;mso-fareast-language:EN-GB;mso-bidi-language:AR-SA;"&gt;£3.6m&lt;/span&gt; project consortium is multi-disciplinary, spanning across a number of IT and social science specialisms. The project partners are Hewlett-Packard Laboratories, HW Communications, QinetiQ, the London School of Economics, the Ethox Centre of the University of Oxford and the University of Warwick. &lt;/p&gt;
&lt;p&gt;The EnCoRe project runs from June 2008 to November 2011. It receives funding from the &lt;a href="http://www.innovateuk.org/"&gt;UK Government&amp;#39;s Technology Strategy Board&lt;/a&gt;, &lt;a href="http://www.esrc.ac.uk/ESRCInfoCentre/index.aspx"&gt;Economic &amp;amp; Social Research Council &lt;/a&gt;and &lt;a href="http://www.epsrc.ac.uk/default.htm"&gt;Engineering &amp;amp; Physical Sciences Research Council&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84822" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/revocation/default.aspx">revocation</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/consent/default.aspx">consent</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category></item><item><title>On Gartner’s Magic Quadrant for Identity Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/11/on-gartner-s-magic-quadrant-for-identity-management.aspx</link><pubDate>Thu, 11 Sep 2008 11:54:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84703</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/09/11/on-gartner-s-magic-quadrant-for-identity-management.aspx#comments</comments><description>&lt;p&gt;You might be interested in having a look at Gartner&amp;#39;s Magic Quadrants for Identity Management. In particular, a recent article (15 August 2008) published by Earl Perkins and Perry Carpenter focused on the &amp;quot;&lt;a href="http://mediaproducts.gartner.com/reprints/oracle/article35/article35.html"&gt;Magic Quadrant for User Provisioning&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;User provisioning delivers capabilities to manage users&amp;#39; identities across systems, applications and resources. Driven by compliance (security effectiveness) and security efficiency, the market is maturing, but identity governance and role-based access concerns raise new issues for customers.&amp;quot;&lt;/p&gt;
&lt;p&gt;On one hand this kind of reports provides good insights about the current state of the art (in this case about user provisioning). On the other hand, some criticisms have been given about the overall evaluation of current IdM solutions and their positioning in the &amp;quot;magic quadrant&amp;quot;. For example, have a look at &lt;a href="http://www.networkworld.com/newsletters/dir/2008/090808id2.html?t51hb"&gt;this article by Dave Kearns&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84703" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category></item><item><title>Coming Digital ID World Conference 2008, 8-10 September 2008 </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/26/coming-digital-id-world-conference-2008-8-10-september-2008.aspx</link><pubDate>Tue, 26 Aug 2008 14:34:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84448</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/26/coming-digital-id-world-conference-2008-8-10-september-2008.aspx#comments</comments><description>&lt;p&gt;The &lt;a href="http://public.cxo.com/conferences/index.html?conferenceID=24"&gt;Digital ID World Conference 2008&lt;/a&gt; is going to take place in Anaheim, California on 8-10 September 2008. A complete agenda is available online. Some of the Keynotes include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identity Assurance: A Backbone for the Identity Marketplace, Peter Alterman, Assistant CIO for E-Authentication and Chair, &lt;em&gt;US Federal PKI Policy&lt;/em&gt;&lt;em&gt; Authority, National Institutes of Health&lt;/em&gt;; Andrew Nash, Senior Director, Information and Risk Management, &lt;em&gt;PayPal&lt;/em&gt;; Frank Villavicencio, Director, &lt;em&gt;Citigroup&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Making Identity Work End to End, Craig Wittenberg, Architect, &lt;em&gt;Microsoft &lt;/em&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;State of the Industry, Jamie Lewis, CEO &amp;amp; Research Chair, &lt;em&gt;Burton Group&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Have I Seen You Before? An Industry Discussion About User-Centric Identity, Kim Cameron, Chief Architect of Identity, &lt;em&gt;Microsoft&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;On VRM and Identity, Doc Searls, Fellow, Berkman Center, &lt;em&gt;Harvard&lt;/em&gt;&lt;em&gt; Law School&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84448" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category></item><item><title>New UK TSB Project: Developing the Next Generation of Identity Management Systems </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/22/new-uk-tsb-project-developing-the-next-generation-of-identity-management-systems.aspx</link><pubDate>Thu, 21 Aug 2008 17:28:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84383</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/22/new-uk-tsb-project-developing-the-next-generation-of-identity-management-systems.aspx#comments</comments><description>&lt;p&gt;As announced by this &lt;a href="http://www.publicservice.co.uk/news_story.asp?id=6846"&gt;article&lt;/a&gt;, a new UK government-founded project is going to start in October, aiming at developing the next generation of identity management systems:&lt;/p&gt;
&lt;p&gt;&amp;quot;A research project will see a team of experts team up for three years to develop the next generation of identity management systems. &lt;br /&gt;&lt;br /&gt;The government-funded project will launch in October and will include academics from Cranfield University, Royal Holloway University of London, Salford University, Consult Hyperion and Sunderland City Council. &lt;br /&gt;&lt;br /&gt;The research team will look at topics of privacy and consent for identity management, with the aim of helping people and organisations make well-informed judgements about their choice of online services, how they use them, and what information they give out.&lt;br /&gt;&lt;br /&gt;&amp;quot;There is a concern that people aren&amp;#39;t really clear about the value of their unique identity,&amp;quot; said Debi Ashenden, Cranfield&amp;#39;s lead researcher. &amp;quot;Our research will engage people in current debates about privacy and consent issues, find out how they think about their identity and what decisions they make. We hope the discussions will provide invaluable information to help develop new identity management tools.&amp;quot;&lt;br /&gt;&lt;br /&gt;The funding for the project is part of a £5.5m investment by the Technology Strategy Board (TSB), Engineering and Physical Sciences Research Council (EPSRC), and Economic and Social Research Council (ESRC). Two other identity management related projects will also be funded by the investment. &lt;br /&gt;&lt;br /&gt;Andrew Tyrer, the TSB&amp;#39;s lead for its network security innovation platform said this research will be key to &amp;quot;ensuring that the hardware and software required will meet public expectations about these important issues&amp;quot;.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84383" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/TSB/default.aspx">TSB</category></item><item><title>An Essential Guide to Identity Management for IT Professionals</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/19/an-essential-guide-to-identity-management-for-it-professionals.aspx</link><pubDate>Tue, 19 Aug 2008 09:14:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:84344</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/08/19/an-essential-guide-to-identity-management-for-it-professionals.aspx#comments</comments><description>&lt;p&gt;Ian Grant has recently published an article on ComputerWeekly.com, called &amp;quot;&lt;a href="http://www.computerweekly.com/Articles/2008/08/18/231838/identity-management-an-essential-guide-for-it-professionals.htm"&gt;Identity Management: An Essential Guide for IT Professionals&lt;/a&gt;&amp;quot;.&lt;/p&gt;
&lt;p&gt;It is actually an overview of some IdM initiatives and related aspects (thanks for mentioning my blog when referring to HP&amp;#39;s initiatives in the IdM space).&lt;/p&gt;
&lt;p&gt;Is anybody aware of an online &amp;quot;Complete and Up-to-Date&amp;quot; Guide to Identity Management and various related initiatives?&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=84344" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Guide/default.aspx">Guide</category></item><item><title>Survey: Only Eight Percent of American are “Very Confident” their Personal Data is Properly Managed</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/17/survey-only-eight-percent-of-american-are-very-confident-their-personal-data-is-properly-managed.aspx</link><pubDate>Wed, 16 Jul 2008 16:08:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83830</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/17/survey-only-eight-percent-of-american-are-very-confident-their-personal-data-is-properly-managed.aspx#comments</comments><description>&lt;p&gt;This is the outcome of a recent survey by The Strategic Counsel, at least based on the overview provided by this article (called &amp;quot;&lt;a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&amp;amp;newsId=20080716005159&amp;amp;newsLang=en"&gt;Only Eight Percent of Americans are &amp;#39;Very Confident&amp;#39; Their Personal Data is Safe With Retailers, Banks and Governments&lt;/a&gt;&amp;quot;):&lt;/p&gt;
&lt;p&gt;&amp;quot;Only an average of eight percent of Americans say they are very confident in the ability of U.S. retailers, government and banks to protect their personal information, according to a national survey commissioned by CA, Inc., and conducted by The Strategic Counsel. The CA 2008 Security and Privacy Survey was done as in follow-up to the 2006 survey. Additionally, the consumer survey indicated that an average of 79 percent of American consumers cite loss of trust and confidence, damage to reputation, and reduced customer satisfaction as consequences of major security and privacy breaches suffered by the business or government organizations that they deal with.&amp;quot; &lt;/p&gt;
&lt;p&gt;Even more interesting is this statement, mentioned by the above article:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;quot;Businesses used to worry about the hackers and thieves launching denial of service attacks from outside the firewall, now they recognize that their greatest danger lurks within the organization. The good news is that increasingly businesses are turning to identify and access management solutions to ensure that confidential data is safeguarded and available only to the people within the organization who genuinely need to have it.&amp;quot;&lt;/p&gt;
&lt;p&gt;Well, I just partially agree with the final part of this statement. Turning to identity and access management solutions is indeed important, but this is just one step towards really ensuring that personal and confidential data is managed according to legislation and users&amp;#39; preferences. &lt;/p&gt;
&lt;p&gt;First of all, most of current IdM solutions are not really privacy-aware and/or do not provide privacy enhancing capabilities (e.g. privacy-aware access control) - aspects that are at the base for preventing that PII data is accessed and used beyond agreed purposes and for the wrong intents ... Secondly, IdM solutions can address the problem till at one point if accidents, social engineering, actions by traitors/insiders, and the effects of bad processes and practices can still happen ... &lt;/p&gt;
&lt;p&gt;So, the other part of the story, for the enterprise, is putting in place proper &amp;quot;data governance processes&amp;quot; and dealing (upfront and periodically) with the necessary risk assessment and management steps. These steps (that should be carried out before deploying any &amp;quot;control point&amp;quot; in the IT infrastructure) are much, much harder to achieve and maintain than simply deploying IdM solutions ...&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83830" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/survey/default.aspx">survey</category></item></channel></rss>