<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>Research on Security and Identity Management (by Marco Casassa Mont) : privacy management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx</link><description>Tags: privacy management</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Twitter and its Privacy and Identity Management Implications</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx</link><pubDate>Thu, 12 Mar 2009 09:33:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88332</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/12/twitter-and-its-privacy-and-identity-management-implications.aspx#comments</comments><description>&lt;p&gt;I recently started using Twitter (my link: &lt;a href="http://twitter.com/MCasassaMont"&gt;http://twitter.com/MCasassaMont&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Twitter it getting more and more popular within (and across) organisations in particular for geographically distributed teams, to share their activities and whereabouts.&lt;/p&gt;
&lt;p&gt;I am interested to better understand this tool, in particular in terms of its identity and privacy implications and long term repercussions for individuals and organisations. &lt;/p&gt;
&lt;p&gt;I see some interesting research to be potentially carried out in the context of the &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics R&amp;amp;D project&lt;/a&gt; at HP Labs and &lt;a href="http://www.encore-project.info/"&gt;UK TSB EnCoRe project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88332" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Twitter/default.aspx">Twitter</category></item><item><title>2009-2010: Predictions about Identity and Privacy Management </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/30/2009-2010-predictions-about-identity-and-privacy-management.aspx</link><pubDate>Mon, 29 Dec 2008 16:02:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:87309</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/30/2009-2010-predictions-about-identity-and-privacy-management.aspx#comments</comments><description>&lt;p&gt;During the next two years (2009-2010), the Identity and Privacy Management areas are going to be subject to the consolidation and cost cutting trends that are already happening in security and, more in general, in IT.&lt;/p&gt;
&lt;p&gt;In my view investments in Identity Management (IdM) are going to be very pragmatic, also driven by the need to: manage a very &amp;quot;variable&amp;quot; workforce; cope with an increase of internal enterprise reorganizations and consolidations; deal with an increased number of identity thefts and related attacks.&lt;/p&gt;
&lt;p&gt;As such I believe that the IdM areas that will get most of the market attentions are going to be in the areas of:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Entitlement management (and automated user provisioning)&lt;/li&gt;
&lt;li&gt;Enterprise SSO&lt;/li&gt;
&lt;li&gt;Authentication strategies&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;I don&amp;#39;t believe that client-based federated identity management and advanced authorization solutions will be driving the Identity Management space, during this period of time.&lt;/p&gt;
&lt;p&gt;From a Privacy Management perspective, I still believe that most of the action will happen in R&amp;amp;D contexts.&lt;/p&gt;
&lt;p&gt;Of course, this is my view, based on some evidence and intuitions. I would be interested in getting your opinions.&lt;/p&gt;
&lt;p&gt;I am also planning to compile a list of world-wide R&amp;amp;D projects and (industrial/university-based) R&amp;amp;D activities in the space of Identity and Privacy Management. I will post information about this. Of course, feel free to send me your input and relevant URLs.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=87309" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category></item><item><title>Built-in Data Loss Prevention and Analogy with Privacy Management</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/05/built-in-data-loss-prevention-and-analogy-with-privacy-management.aspx</link><pubDate>Fri, 05 Dec 2008 13:51:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:86908</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/12/05/built-in-data-loss-prevention-and-analogy-with-privacy-management.aspx#comments</comments><description>&lt;p&gt;I have just read this interesting article, called &amp;quot;&lt;a href="http://www.channelinsider.com/c/a/Security/Microsoft-RSA-Partner-to-Develop-NextGen-Data-Loss-Prevention/"&gt;Microsoft, RSA Partner to Develop Next-Gen data Loss Prevention&lt;/a&gt;&amp;quot;, by Lawrence Walsh:&lt;/p&gt;
&lt;p&gt;&amp;quot;The alliance between Microsoft and RSA will move data loss prevention technology into the fabric of the IT infrastructure and improve protection by associating data with identities and classifications. Analysts are already calling the idea a &amp;quot;game changer.&amp;quot;&amp;quot;&lt;/p&gt;
&lt;p&gt;The main message I got is that we need to move away from bolt-on solutions, towards &amp;quot;built-in DLP approaches&amp;quot;. I tend to agree with this approach, despite being much harder to achieve.&lt;/p&gt;
&lt;p&gt;This has some interesting analogies with privacy and the way privacy management is currently carried out, at least with most of current privacy-enhancing technology (PET) approaches. I believe that we need to move toward built-in approaches too, that require deep understanding of the interconnections with the relevant &amp;quot;IT infrastructure fabric&amp;quot;, related business processes (and needs), along with involved risks and their potential impact. &lt;/p&gt;
&lt;p&gt;So, I believe this is something to consider very carefully, for example, in the context of the &amp;quot;Consent and Revocation Management&amp;quot; R&amp;amp;D area, within the &lt;a href="http://www.encore-project.info/"&gt;TSB EnCoRe project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=86908" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/EnCoRe/default.aspx">EnCoRe</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/built-in+approach/default.aspx">built-in approach</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/data+loss+prevention/default.aspx">data loss prevention</category></item><item><title>Survey: Only Eight Percent of American are “Very Confident” their Personal Data is Properly Managed</title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/17/survey-only-eight-percent-of-american-are-very-confident-their-personal-data-is-properly-managed.aspx</link><pubDate>Wed, 16 Jul 2008 16:08:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83830</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/07/17/survey-only-eight-percent-of-american-are-very-confident-their-personal-data-is-properly-managed.aspx#comments</comments><description>&lt;p&gt;This is the outcome of a recent survey by The Strategic Counsel, at least based on the overview provided by this article (called &amp;quot;&lt;a href="http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&amp;amp;newsId=20080716005159&amp;amp;newsLang=en"&gt;Only Eight Percent of Americans are &amp;#39;Very Confident&amp;#39; Their Personal Data is Safe With Retailers, Banks and Governments&lt;/a&gt;&amp;quot;):&lt;/p&gt;
&lt;p&gt;&amp;quot;Only an average of eight percent of Americans say they are very confident in the ability of U.S. retailers, government and banks to protect their personal information, according to a national survey commissioned by CA, Inc., and conducted by The Strategic Counsel. The CA 2008 Security and Privacy Survey was done as in follow-up to the 2006 survey. Additionally, the consumer survey indicated that an average of 79 percent of American consumers cite loss of trust and confidence, damage to reputation, and reduced customer satisfaction as consequences of major security and privacy breaches suffered by the business or government organizations that they deal with.&amp;quot; &lt;/p&gt;
&lt;p&gt;Even more interesting is this statement, mentioned by the above article:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;quot;Businesses used to worry about the hackers and thieves launching denial of service attacks from outside the firewall, now they recognize that their greatest danger lurks within the organization. The good news is that increasingly businesses are turning to identify and access management solutions to ensure that confidential data is safeguarded and available only to the people within the organization who genuinely need to have it.&amp;quot;&lt;/p&gt;
&lt;p&gt;Well, I just partially agree with the final part of this statement. Turning to identity and access management solutions is indeed important, but this is just one step towards really ensuring that personal and confidential data is managed according to legislation and users&amp;#39; preferences. &lt;/p&gt;
&lt;p&gt;First of all, most of current IdM solutions are not really privacy-aware and/or do not provide privacy enhancing capabilities (e.g. privacy-aware access control) - aspects that are at the base for preventing that PII data is accessed and used beyond agreed purposes and for the wrong intents ... Secondly, IdM solutions can address the problem till at one point if accidents, social engineering, actions by traitors/insiders, and the effects of bad processes and practices can still happen ... &lt;/p&gt;
&lt;p&gt;So, the other part of the story, for the enterprise, is putting in place proper &amp;quot;data governance processes&amp;quot; and dealing (upfront and periodically) with the necessary risk assessment and management steps. These steps (that should be carried out before deploying any &amp;quot;control point&amp;quot; in the IT infrastructure) are much, much harder to achieve and maintain than simply deploying IdM solutions ...&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83830" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/survey/default.aspx">survey</category></item><item><title>Liberty Alliance releases the Identity Assurance Framework (IAF) and Identity Governance Framework (IGF) Specifications </title><link>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/24/liberty-alliance-releases-the-identity-assurance-framework-iaf-and-identity-governance-framework-igf-specifications.aspx</link><pubDate>Mon, 23 Jun 2008 16:58:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83368</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2008/06/24/liberty-alliance-releases-the-identity-assurance-framework-iaf-and-identity-governance-framework-igf-specifications.aspx#comments</comments><description>&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;Today, Liberty Alliance has&lt;/font&gt;&lt;a href="http://www.projectliberty.org/liberty/news_events/press_releases/liberty_alliance_marks_policy_and_privacy_milestone_for_identity_enabled_enterprise_and_web_2_0_applications"&gt;&lt;font face="Times New Roman" size="3"&gt; publicly announced&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; the release of the&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Identity Assurance Framework (IAF) and Identity Governance Framework (IGF) Specifications:&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&amp;quot;Liberty Alliance, the global identity community working to build a more trust-worthy internet for consumers, governments and businesses worldwide, today announced an industry milestone in driving trust and privacy into enterprise and identity-enabled applications based on the release of the &lt;span style="COLOR:blue;"&gt;&lt;a href="http://projectliberty.org/liberty/strategic_initiatives/identity_assurance"&gt;Liberty Identity Assurance Framework&lt;/a&gt;&lt;/span&gt; (IAF) and the &lt;span style="COLOR:blue;"&gt;&lt;a href="http://projectliberty.org/liberty/strategic_initiatives/identity_governance"&gt;Liberty Identity Governance Framework&lt;/a&gt;&lt;/span&gt; (IGF). Today’s news is the result of the collaborative development of standardized frameworks and technologies designed to meet cross-industry requirements for policy-based security and privacy systems, with a focus on streamlining the establishment and management of identity and trust across user-driven applications and networks.&amp;quot;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;I believe this is a first, important steps towards providing a more systemic approach to assurance and privacy management in complex organisational (and cross-organisational) contexts.&lt;/font&gt;&lt;/p&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;More details can be found in the Liberty Alliance’s announcement, &lt;/font&gt;&lt;a href="http://www.projectliberty.org/liberty/news_events/press_releases/liberty_alliance_marks_policy_and_privacy_milestone_for_identity_enabled_enterprise_and_web_2_0_applications"&gt;&lt;font face="Times New Roman" size="3"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt;.&lt;/font&gt;&lt;/p&gt;&lt;span style="mso-ansi-language:EN-US;"&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0pt;"&gt;&lt;font face="Times New Roman" size="3"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/font&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;font face="Times New Roman" size="3"&gt;mirror blog&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83368" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IAF/default.aspx">IAF</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/privacy+management/default.aspx">privacy management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/assurance+management/default.aspx">assurance management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IGF/default.aspx">IGF</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Liberty+Alliance/default.aspx">Liberty Alliance</category></item></channel></rss>