<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Insight IdM</title>
	<atom:link href="http://blog.talkingidentity.com/category/insight-idm/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Getting Your IAM Program Ready for 2012</title>
		<link>http://blog.talkingidentity.com/2011/12/getting-your-iam-program-ready-for-2012.html</link>
		<comments>http://blog.talkingidentity.com/2011/12/getting-your-iam-program-ready-for-2012.html#comments</comments>
		<pubDate>Thu, 22 Dec 2011 21:56:25 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[IAM Metrics]]></category>
		<category><![CDATA[Identity Governance]]></category>
		<category><![CDATA[SCUID]]></category>
		<category><![CDATA[SCUID Operations]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1370</guid>
		<description><![CDATA[It’s that time of year, when everyone does their best Carnac the Magnificent impression and rolls out their prognostications and top 10 lists. Here at Identropy, we’re not so sure about trying to predict the future, but we do know a thing or two about helping customers succeed in meeting the goals of their IAM [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1371" title="Carnac" src="http://blog.talkingidentity.com/wp-content/uploads/2011/12/Carnac.jpg" alt="Carnac" width="250" height="249" /></p>
<p>It’s that time of year, when everyone does their best <em>Carnac the Magnificent</em> impression and rolls out their prognostications and top 10 lists. Here at Identropy, we’re not so sure about trying to predict the future, but we do know a thing or two about helping customers succeed in meeting the goals of their IAM programs. So if you’re looking to make a new year resolution, we’re here to remind you of some steps you can take to truly set your IAM program up for success.</p>
<p>First, <strong>create an IAM governance body</strong>. Without establishing a governance body, your organization is not going to be able to overcome the roadblocks, complexities and sometimes personalities that often derail even the best planned IAM project. Proper governance is also crucial in making sure that the project adjusts properly to the continuously evolving business and policy environment that IAM needs to operate within. Our CTO, Ash Motiwala, recently wrote <a href="http://bit.ly/rSGovC" target="_blanks">an article for SC Magazine</a> on how to go about setting up your IAM governance body.</p>
<p>Next, you’ll need an <strong>IAM Roadmap</strong> (if you don’t have one already – naughty list). If you have more than a few identity related problems that you are trying to solve, an Identity Management Roadmap will be critical to ensure that you tackle it as a program, with various phases that are sequenced in the appropriate priority order and have tangible business benefits and “wins” along each step of the way.  We’ve published a series of <a href="http://bit.ly/vZG4pc" target="_blank">blog articles</a> on developing an IAM roadmap that can help you think through how you may want to approach your own situation.</p>
<p>Of course, in order for the governance body to know how the program is progressing and make good decisions, they need good information. To address that, you need to take the final step of <strong>using metrics</strong> to help measure the effectiveness of your IAM program and identify inefficiencies and issues. Our very own Frank Villavicencio wrote for CSO Online earlier this year about <a href="http://bit.ly/oBpOuh" target="_blanks">the 10 IAM Metrics that matter</a>. Even if you don’t use a tool like our own <a href="http://bit.ly/q8lEZA" target="_blank">SCUID Operations</a>, there are simple reports and analysis you can do on a periodic basis to get some visibility into how your IAM tools and processes are doing against the business objectives laid out by the governance body. It’s a worthwhile investment that can often pay for itself in terms of the improvements it can help identify.</p>
<p>So take some time to figure out how to put in place the support structure your IAM program needs to truly achieve its potential and deliver on the objectives you laid out for it.</p>
<p>And Happy Holidays from the Identropy family to yours!</p>
<p>[Cross posted from the <a href="http://bit.ly/vbCKjU" target="_blank">Identropy Blog</a>]</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/best-practices" rel="tag">Best Practices</a>, <a href="http://blog.talkingidentity.com/tag/iam-metrics" rel="tag">IAM Metrics</a>, <a href="http://blog.talkingidentity.com/tag/identity-governance" rel="tag">Identity Governance</a>, <a href="http://blog.talkingidentity.com/tag/scuid" rel="tag">SCUID</a>, <a href="http://blog.talkingidentity.com/tag/scuid-operations" rel="tag">SCUID Operations</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/12/getting-your-iam-program-ready-for-2012.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join Quest and Identropy for an IAM Lunch and Learn</title>
		<link>http://blog.talkingidentity.com/2011/09/join-quest-and-identropy-for-an-iam-lunch-and-learn.html</link>
		<comments>http://blog.talkingidentity.com/2011/09/join-quest-and-identropy-for-an-iam-lunch-and-learn.html#comments</comments>
		<pubDate>Fri, 09 Sep 2011 14:25:17 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Identropy]]></category>
		<category><![CDATA[Lessons Learned]]></category>
		<category><![CDATA[Quest One Identity Solution]]></category>
		<category><![CDATA[Quest Software]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1345</guid>
		<description><![CDATA[[Cross posted from the Identropy blog here] Want to get a deep dive on how to achieve success with your identity and access management program? Then join us for a lunch and learn where Quest Software and Identropy will share insight on the key technologies and best practices that can help you improve your security [...]]]></description>
			<content:encoded><![CDATA[<p>[Cross posted from the Identropy blog <a href="http://bit.ly/oqGSs9" target="_blank">here</a>]</p>
<p>Want to get a deep dive on how to achieve success with your identity and access management program? Then join us for a lunch and learn where<img class="alignright" title="Quest Software" src="http://www.identropy.com/Portals/40850/images/quest-software.jpg" alt="" width="213" height="37" /> <a href="http://www.quest.com/identity-management/" target="_blank"><strong>Quest Software</strong></a> and <a href="http://www.identropy.com" target="_blank"><strong>Identropy</strong></a> will share insight on the key technologies and best practices that can help you improve your security and compliance posture while maximizing your ROI and avoiding common pitfalls that doom these projects. During the Identropy session, we&#8217;ll be sharing insights we&#8217;ve gathered from well over a 100 implementations. Plus you get to network with your peers and some really cool people from both Quest and Identropy (and me!). Space is limited, so register now (locations, dates and registration links below).<strong><a href="http://www.identropy.com" target="_blank"><strong><img class="alignright size-full wp-image-1280" title="identropy_logo" src="http://blog.talkingidentity.com/wp-content/uploads/2011/07/identropy_logo.gif" alt="identropy_logo" width="207" height="78" /></strong></a></strong></p>
<p><strong>Boston, MA<br />
</strong></p>
<ul>
<li><em>Date: </em>Wednesday, September 14, 2011 at 11:45 a.m.</li>
<li><em>Location: </em>Davio&#8217;s Northern Italian Steakhouse</li>
<li><em>Identropy Speaker: </em>Ashraf Motiwala, CTO</li>
<li><a href="http://bit.ly/orZWAg" target="_blank">Register Today</a></li>
</ul>
<p><strong>Livingston, NJ<br />
</strong></p>
<ul>
<li><em>Date: </em>Wednesday, September 21, 2011 at 11:45 a.m.</li>
<li><em>Location: </em>Strip House Steakhouse</li>
<li><em>Identropy Speaker: </em>Nishant Kaushik, Chief Architect</li>
<li><a href="http://bit.ly/nWyXrl" target="_blank">Register Today</a></li>
</ul>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/best-practices" rel="tag">Best Practices</a>, <a href="http://blog.talkingidentity.com/tag/identity-management" rel="tag">Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/identropy" rel="tag">Identropy</a>, <a href="http://blog.talkingidentity.com/tag/lessons-learned" rel="tag">Lessons Learned</a>, <a href="http://blog.talkingidentity.com/tag/quest-one-identity-solution" rel="tag">Quest One Identity Solution</a>, <a href="http://blog.talkingidentity.com/tag/quest-software" rel="tag">Quest Software</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/09/join-quest-and-identropy-for-an-iam-lunch-and-learn.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When Will We Stop Taping Up Our Windows?</title>
		<link>http://blog.talkingidentity.com/2011/08/when-will-we-stop-taping-up-our-windows.html</link>
		<comments>http://blog.talkingidentity.com/2011/08/when-will-we-stop-taping-up-our-windows.html#comments</comments>
		<pubDate>Mon, 29 Aug 2011 15:10:54 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Theater]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1327</guid>
		<description><![CDATA[It was an interesting weekend, to say the least. I&#8217;ve never had to prepare for a hurricane before, so going through the exercise was a revelation in so many ways. You discover what you consider really &#8220;valuable&#8221; (like when I actually packed my external hard drive that has 10 years worth of digital images and [...]]]></description>
			<content:encoded><![CDATA[<p>It was an interesting weekend, to say the least. I&#8217;ve never had to prepare for a hurricane before, so going through the exercise was a revelation in so many ways. You discover what you consider really &#8220;valuable&#8221; (like when I actually packed my external hard drive that has 10 years worth of digital images and home videos alongside our passports and insurance policies, despite it being backed up online). You also discover how much stuff you have just lying around to clean up.</p>
<div class="wp-caption alignright" style="width: 255px"><img title="Windows Taped Up" src="http://farm7.static.flickr.com/6063/6092632323_f12f1053cf.jpg" alt="Is This Your Security Solution?" width="245" height="500" /><p class="wp-caption-text">Is This Your Security Solution?</p></div>
<p>And then there was the notice we got from our building management asking us to tape up our windows. It had very specific instructions on the  pattern in which to lay down the tape. And of course they had tape for sale in case we didn&#8217;t have our own. Looking around, we could see a number of other windows where tape had been put up. So, following instructions and the trend, I started the exercise. After one window, I stood back and questioned the wisdom of doing this. It really didn&#8217;t seem like this tape was going to do much against any force strong enough to shatter the double-paned glass we had. A quick check on the web turned up enough &#8220;myth-shattering&#8221; articles (especially from <a href="http://www.fema.gov/kids/knw_hur.htm" target="_blank">official sources</a>) to make me and my wife realize that the exercise was pointless. It was patently obvious that the tape was not going to prevent the glass from shattering, or keep the shattered pieces from flying around the room.</p>
<p>Yet all around us, people were spending precious time putting up tape. Why? Because they felt like they were doing <em>something</em> &#8211; something that would keep them safe, something they could point to and say &#8220;well, at least I tried&#8221;.</p>
<p>The analogy with how security and risk management goes in IT is laughably obvious. It&#8217;s classic <strong>security theater</strong> &#8211; getting a false sense of security for having done something that is of no benefit whatsoever, but which (literally) helps you sleep better at night. The real issue here is not the waste of good tape, but the fact that doing something like this actually <em>increases</em> your risks. Believing you&#8217;ve actually reinforced the windows could lead you to make the mistake of actually sleeping close to a window and putting yourself in harms way. And feeling that this option exists keeps you from actually analyzing the situation properly and taking the steps you really should take, like putting up hurricane shutters or installing hurricane proof glass. Keep in mind that you need to assess your risk accurately instead of going overboard, because while installing hurricane shutters may be a tad too much in an area like ours where hurricanes are (gratefully) a rare occurrence, it really should be top of mind if you&#8217;re down in Florida.</p>
<p>It&#8217;s also important to understand the psychology underlying these wasted efforts. All too often, &#8220;tape jobs&#8221; are last minute efforts that stem from a lack of planning. If you analyze your threats proactively, you have time to properly measure your windows and install hurricane shutters. But if you push things out and end up reacting to the news that a hurricane is coming &#8211; well, then you&#8217;ve run out of time to do a good job, the store is probably out of shutters and even plywood, and there&#8217;s little you can do at that point except retreat. How many times have we come across organizations that are under the gun to evaluate software, deploy and get a recertification process done in a completely unmanageable timeline because they failed an audit?</p>
<p>So if you&#8217;ve been pushing out that risk assessment, get on it now. Or you might just end up standing in a long line at the neighbourhood hardware store buying a roll of tape that will do absolutely nothing for your reality.</p>
<p>[Cross-posted from the <a href="http://bit.ly/pNb5Xy" target="_blank">Identropy blog</a>]</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/best-practices" rel="tag">Best Practices</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a>, <a href="http://blog.talkingidentity.com/tag/security" rel="tag">Security</a>, <a href="http://blog.talkingidentity.com/tag/security-theater" rel="tag">Security Theater</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/08/when-will-we-stop-taping-up-our-windows.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Purpose Driven IAM Life</title>
		<link>http://blog.talkingidentity.com/2011/08/the-purpose-driven-iam-life.html</link>
		<comments>http://blog.talkingidentity.com/2011/08/the-purpose-driven-iam-life.html#comments</comments>
		<pubDate>Mon, 01 Aug 2011 15:44:40 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Access Governance]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Identity Governance]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Provisioning]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1304</guid>
		<description><![CDATA[[Cross-posted from the Identropy blog, where I will be contributing some posts from now on] Another Catalyst conference (now Gartner Catalyst) has come to an end with the former Burton Group analysts challenging us once more to do better as an industry. It&#8217;s an unfortunate reality that cost overruns, unrealized benefits and missed objectives still [...]]]></description>
			<content:encoded><![CDATA[<p>[Cross-posted from the <a href="http://bit.ly/riJ1sM" target="_blank">Identropy blog</a>, where I will be contributing some posts from now on]</p>
<p>Another <strong>Catalyst conference</strong> (now Gartner Catalyst) has come to an end with the former Burton Group analysts challenging us once more to do better as an industry. It&#8217;s an unfortunate reality that cost overruns, unrealized benefits and missed objectives still plague most customers of identity management solutions. While there are still things we need to do on the technology side of the equation (most notably, moving towards a pull-based identity architecture in our application and platform layers), there is much more we can do in a more immediate fashion on the business and deployment side of identity management. And since any new proposal must be accompanied by an appropriate buzzword, here&#8217;s the one I took away from Catalyst &#8211; <strong>fit-for-purpose</strong> (<a href="http://bit.ly/rhFnxD" target="_blank">putting $1</a> in the Bob Blakley piggybank).</p>
<p>For a while now, it&#8217;s been fashionable to bash provisioning. But to me, this was always misguided anger. Yes, it&#8217;s true that many provisioning projects suffer from missed deadlines and budget woes. But that was never because of the technology, which did exactly what it was supposed to (though there is still <a href="http://bit.ly/h6JhYi">much we can do</a> to improve it&#8217;s maturity and stability). It was always because of the way it was sold, deployed and mismanaged. How often did we hear massive provisioning projects being drafted to achieve regulatory compliance, only to find out that it wasn&#8217;t a sufficient control? How many connector development projects were defined to automate provisioning to many 100s of targets, without any ROI calculations ever being done to determine it&#8217;s value to the business (though it&#8217;s value to the implementing SI was all too obvious)?</p>
<div id="attachment_1305" class="wp-caption aligncenter" style="width: 510px"><a href="http://blog.talkingidentity.com/wp-content/uploads/2011/08/software-engineering-explained.png" target="_blank"><img class="size-full wp-image-1305" title="software-engineering-explained - 500W" src="http://blog.talkingidentity.com/wp-content/uploads/2011/08/software-engineering-explained-500W.png" alt="Look Familiar" width="500" height="375" /></a><p class="wp-caption-text">Look Familiar</p></div>
<p>The angst has gone so far as to create a whole new market &#8211; <strong>Identity &amp; Access Governance</strong> (IAG) &#8211; and marketing terms like &#8220;next generation provisioning&#8221;. But there is nothing revolutionary (or even evolutionary) about the model of automating provisioning to your most sensitive and/or high volume targets, while only setting up approval workflows and manual provisioning for the rest. You could do this with <strong>Thor&#8217;s Xellerate</strong> provisioning product (now <em>Oracle Identity Manager</em>) back in 2003, when we created full fledged functionality for manual provisioning that included email notifications and a provisioning task list (with detailed data and instructions) for your IT admins. Through all the noise and FUD, what is actually coming to the fore is the deeper and more relevant concept of understanding exactly what your use cases are for your IAM deployment, and focusing the features, design and deployment on meeting those use cases.</p>
<p>The most successful IAM projects have always done exactly this, with plans that classified their applications into tiers corresponding to the controls they wanted to put in place, creating role management projects that emphasized defining only the higher value business roles instead of trying to blanket everyone in the enterprise, and finding the right blend of automated controls, manual decision-making and oversight mechanisms. The defining characteristic in these projects was always an attitude of rational, measured response to the risk involved &#8211; in other words, an emphasis on making sure that any solution rolled out was fit-for-purpose.</p>
<p>This is the philosophical approach to IAM that attracted me to <strong>Identropy</strong>, where it exists both in the advisory and implementation aspect of our business, and in our approach to designing <strong>SCUID Lifecycle</strong>. Lifecycle is not meant to be all things to all people. It&#8217;s meant to be exactly what is needed for the majority of customers out there. We&#8217;ve used our years (decades?) of expertise in this space to come up with just that measured set of features and use cases, and will continue to refine them in conjunction with our customers. That is the part that excites me most about this new journey I&#8217;ve started. And I&#8217;m glad that Lori, Bob and the rest of the Catalyst gang validated our core belief for us.</p>
<div class="wp-caption aligncenter" style="width: 510px"><img title="Identropy Crew" src="http://farm7.static.flickr.com/6016/5988930837_1f66805b73.jpg" alt="These Guys Are Here To Help" width="500" height="375" /><p class="wp-caption-text">These Guys Are Here To Help</p></div>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/access-governance" rel="tag">Access Governance</a>, <a href="http://blog.talkingidentity.com/tag/best-practices" rel="tag">Best Practices</a>, <a href="http://blog.talkingidentity.com/tag/identity-governance" rel="tag">Identity Governance</a>, <a href="http://blog.talkingidentity.com/tag/identity-management" rel="tag">Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/provisioning" rel="tag">Provisioning</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/08/the-purpose-driven-iam-life.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>And Now For Something Completely Different</title>
		<link>http://blog.talkingidentity.com/2011/07/and-now-for-something-completely-different.html</link>
		<comments>http://blog.talkingidentity.com/2011/07/and-now-for-something-completely-different.html#comments</comments>
		<pubDate>Mon, 25 Jul 2011 06:31:00 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[CIS11]]></category>
		<category><![CDATA[CIS2011]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Identity Summit]]></category>
		<category><![CDATA[Federated Provisioning]]></category>
		<category><![CDATA[JIT Provisioning]]></category>
		<category><![CDATA[Just-In-Time Provisioning]]></category>
		<category><![CDATA[Monty Python]]></category>
		<category><![CDATA[Provisioning]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1293</guid>
		<description><![CDATA[At the Cloud Identity Summit last week, one thing was patently obvious &#8211; the agenda was filled with super interesting talks from very talented speakers. So given that I was talking about the riveting (not!) topic of user provisioning, I knew I had to pique peoples curiosity to draw them in. To that end, I [...]]]></description>
			<content:encoded><![CDATA[<p>At the<a href="http://bit.ly/n0zeMP" target="_blank"> <strong>Cloud Identity Summit</strong></a> last week, one thing was patently obvious &#8211; the agenda was filled with super interesting talks from very talented speakers. So given that I was talking about the riveting (<em>not!</em>) topic of <strong>user provisioning</strong>, I knew I had to pique peoples curiosity to draw them in. To that end, I enlisted the help (so to speak) of those most curious of entertainers, the incomparable <strong>Monty Python</strong>, in a talk entitled &#8220;<em>And Now For Something Completely Different &#8211; Identity Provisioning and the Cloud</em>&#8220;. You can check out the slides and recording below.</p>
<div id="__ss_8666165" style="width: 510px;"><object id="__sse8666165" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="510" height="426" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=cis-identityprovisioningandthecloud-110722140735-phpapp01&amp;stripped_title=and-now-for-something-completely-different-8666165&amp;userName=NishantKaushik" /><param name="name" value="__sse8666165" /><param name="allowfullscreen" value="true" /><embed id="__sse8666165" type="application/x-shockwave-flash" width="510" height="426" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=cis-identityprovisioningandthecloud-110722140735-phpapp01&amp;stripped_title=and-now-for-something-completely-different-8666165&amp;userName=NishantKaushik" name="__sse8666165" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<p>The central idea of the presentation was that the cloud has caused the seemingly well-understood, albeit reviled, discipline of user provisioning to splinter (<em>SPLITTER!</em>) into 3 different factions &#8211; the <strong>Traditionalists</strong>, the <strong>Progressives</strong> and the <strong>New Age Thinkers</strong>. You&#8217;ll have to listen to my talk to understand it in more detail, but the reviews of my talk on Twitter seemed to be &#8220;<a href="http://bit.ly/rrkJBB" target="_blank">certified fresh</a>&#8220;. While Ian Glazer <a href="http://bit.ly/oGnAGl" target="_blank">pondered</a>:</p>
<blockquote><p>This  JIT + Pull model that @NishantK proposes in a new age wrapper on a  traditional core &#8211; externalized authZ fixes some problems #cis2011</p></blockquote>
<p>I did have Paul Madsen <a href="http://bit.ly/qeovBZ" target="_blank">raving</a>:</p>
<blockquote><p>I declare @nishantk Python theme for #cis2011 prez a success. And am reconciled to seeing it over and over for next 3 years</p></blockquote>
<p>All in all, I think I accomplished my goal of edutaining the folks at CIS on the continued existence of user provisioning, and its future prospects. Because the account CRUD problem will continue to be a weight around the neck of enterprise cloud adoption unless we put in place the right solutions.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cis11" rel="tag">CIS11</a>, <a href="http://blog.talkingidentity.com/tag/cis2011" rel="tag">CIS2011</a>, <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-summit" rel="tag">Cloud Identity Summit</a>, <a href="http://blog.talkingidentity.com/tag/federated-provisioning" rel="tag">Federated Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/jit-provisioning" rel="tag">JIT Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/just-in-time-provisioning" rel="tag">Just-In-Time Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/monty-python" rel="tag">Monty Python</a>, <a href="http://blog.talkingidentity.com/tag/provisioning" rel="tag">Provisioning</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/07/and-now-for-something-completely-different.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>From The End Spring New Beginnings</title>
		<link>http://blog.talkingidentity.com/2011/07/from-the-end-spring-new-beginnings.html</link>
		<comments>http://blog.talkingidentity.com/2011/07/from-the-end-spring-new-beginnings.html#comments</comments>
		<pubDate>Mon, 18 Jul 2011 15:59:20 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Identropy]]></category>
		<category><![CDATA[Identropy Identity Management]]></category>
		<category><![CDATA[Managed Identity Services]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[SCUID]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1278</guid>
		<description><![CDATA[As I posted on Friday, I decided it was time to close the chapter on my career at Thoracle (by the way, the positive wishes in response from all of you has been quite gratifying). But it wasn’t without knowing what the next chapter was going to bring. It’s going to be a busy July [...]]]></description>
			<content:encoded><![CDATA[<p>As I <a href="http://bit.ly/p0a95m" mce_href="http://bit.ly/p0a95m">posted on Friday</a>, I decided it was time to close the chapter on my career at Thoracle (by the way, the positive wishes in response from all of you has been quite gratifying). But it wasn’t without knowing what the next chapter was going to bring. It’s going to be a busy July in Identity, as <a href="http://bit.ly/ngvMKB" mce_href="http://bit.ly/ngvMKB">I talked about earlier</a>, and I wasn’t about to show up at <b>Cloud Identity Summit</b> and then <b>Catalyst</b> as a free agent (though it would have been interesting to see what would have happened).</p>
<p>I’m not a Lebron James, so I can’t really drag this out for an unnecessary 5 paragraphs (though I do feel like I am joining an All-Star team). So here it is. Starting today, I am going to take my <i>talents</i> (be what they may) to Moonachie NJ and join <b><a href="http://www.identropy.com" mce_href="http://www.identropy.com" target="_blank">Identropy</a></b>.</p>
<p><a href="http://www.identropy.com" mce_href="http://www.identropy.com"><img class="alignright size-full wp-image-1280" title="identropy_logo" src="http://blog.talkingidentity.com/wp-content/uploads/2011/07/identropy_logo.gif" mce_src="http://blog.talkingidentity.com/wp-content/uploads/2011/07/identropy_logo.gif" alt="identropy_logo" height="78" width="207"></a>For a while now I’ve been wanting to get back into startup mode, to really tackle the identity management problem the way I want to. These are interesting times we are living in, as they say, and there is a real opportunity to turn this space on its head. And I’m going to get that chance now, as <b>Chief Architect</b> in a company that has all the necessary elements in place – a crackerjack team, innovative thinking and an unwavering focus on the needs of the customer. They’ve already had one incredible and unique solution – <b><a href="http://bit.ly/q8lEZA" mce_href="http://bit.ly/q8lEZA" target="_blank">SCUID Operations</a></b> – come out of that approach, and I’m excited to see what I can bring to the party.</p>
<p>Like I said in my <a href="http://bit.ly/p0a95m" mce_href="http://bit.ly/p0a95m">farewell post</a>, the number one thing for me is <a href="http://bit.ly/lwgxK8" mce_href="http://bit.ly/lwgxK8" target="_blank">the team</a>, and <b>Identropy</b> is an incredibly talented and passionate group of individuals working towards one vision. I’ve worked with some of these guys in the past (and didn’t hold it against them when making the decision to join), and have interacted with others over the years in this little community of ours. I’ve always had a deep respect for their expertise and commitment, and love that they’re the kind of people you want to go out and have a beer with at the end of a hard day. The relationships they have built with their customers are enviable by all standards. And they have an open, collaborative culture that should be fun to work in.</p>
<div class="mceTemp">
<dl id="" class="wp-caption alignnone" style="width: 510px">
<dt class="wp-caption-dt"><img title="Incredible" src="http://farm7.static.flickr.com/6148/5950494207_24aeb998c4.jpg" mce_src="http://farm7.static.flickr.com/6148/5950494207_24aeb998c4.jpg" alt="My first contribution to Identropy - A Gapingvoid print that captures why I joined" height="375" width="500"></dt>
<dd class="wp-caption-dd">My first contribution to Identropy &#8211; A Gapingvoid print that captures why I joined</dd>
</dl>
</div>
<p>I am really looking forward to what we can accomplish together. It should be one hell of a ride. Of course, all my other nonsense – <a href="http://twitter.com/NishantK" mce_href="http://twitter.com/NishantK" target="_blank">Twitter</a>, this <a href="http://blog.talkingidentity.com" mce_href="http://blog.talkingidentity.com">blog</a>, the conference circuit rounds – will continue as before without interruption. I’ve only just scratched the surface of what I’ll be working on, and will definitely be sharing more in the coming weeks. But if you want an in-person take, grab me in Keystone or in San Diego. Be warned though – you may have to be the one buying the round (I am back in startup mode, after all). See you there.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-security" rel="tag">Cloud Security</a>, <a href="http://blog.talkingidentity.com/tag/identity-management" rel="tag">Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/identropy" rel="tag">Identropy</a>, <a href="http://blog.talkingidentity.com/tag/identropy-identity-management" rel="tag">Identropy Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/managed-identity-services" rel="tag">Managed Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/personal" rel="tag">Personal</a>, <a href="http://blog.talkingidentity.com/tag/scuid" rel="tag">SCUID</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/07/from-the-end-spring-new-beginnings.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>As They Say, All Good Things Must Come To An End</title>
		<link>http://blog.talkingidentity.com/2011/07/as-they-say-all-good-things-must-come-to-an-end.html</link>
		<comments>http://blog.talkingidentity.com/2011/07/as-they-say-all-good-things-must-come-to-an-end.html#comments</comments>
		<pubDate>Fri, 15 Jul 2011 13:17:18 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Thor Technologies]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1256</guid>
		<description><![CDATA[Today is my last day at Oracle, ending an era of my life that began over 10 years ago at Thor Technologies. Back then, I had no idea about the scope of the journey I was embarking on. I had no idea I was entering a space that was going to become so hot and [...]]]></description>
			<content:encoded><![CDATA[<p>Today is my last day at Oracle, ending an era of my life that began over 10 years ago at <strong>Thor Technologies</strong>. Back then, I had no idea about the scope of the journey I was embarking on. I had no idea I was entering a space that was going to become so hot and scrutinized, alternating between being loved and hated (with a passion). They didn’t even call it “identity management” back then.</p>
<div class="wp-caption alignright" style="width: 250px"><a href="http://www.flickr.com/photos/demerzel/3846991999/"><img class=" " title="View of East River from WTC 87" src="http://farm3.static.flickr.com/2635/3846991999_8e93ec2c4a_m.jpg" alt="" width="240" height="159" /></a><p class="wp-caption-text">View from my cube at Thor WTC</p></div>
<p>No, back then I was just a wide-eyed youngster (with a lot more hair) that stepped into an office on the 87th floor of the <strong>World Trade Center</strong>, met an energetic team roaring to go, saw an amazing view from an empty (and available) cubicle and decided that he wanted to work there, because it would be cool. And it was cool, but not for the reasons I imagined.</p>
<p>It has been a wild, roller coaster ride. The stars in my eyes at working in the WTC were replaced by the bags under my eyes as we tried to salvage our future out of the rubble of 9/11. Weeks spent decompiling demo systems trying to recover lost code (no one ever questioned off-site backups again) gave way to a relentless cycle of <em>code, build, demo</em>. I’ll never forget one hellish 80 hour stretch that involved no sleep, non-stop coding even as I crossed the Atlantic on a flight to Heathrow, going straight from the airport to an office and giving the demo of a lifetime. Getting customers was never easy, but it did get easier (though never more fruitful) than the months negotiating requirements leading up to our first customer win (<em>RIP, Lehman Brothers</em>). Temporary office space on Park Avenue gave way to the most amazing office in the Meatpacking District, well before it was cool to be there. Long, drawn out and painful POCs transformed into great relationships with customers that would explode into a frenzy every year at TAC. It was <a href="http://bit.ly/oDDx0q" target="_blank">an unforgettable experience</a> that helped define me and my career.</p>
<div class="wp-caption alignnone" style="width: 510px"><a href="http://www.flickr.com/photos/demerzel/5938751025/"><img title="Thor Farewell Party" src="http://farm7.static.flickr.com/6139/5938751025_02d0469ded.jpg" alt="" width="500" height="375" /></a><p class="wp-caption-text">The Thor Crew At The Farewell Party</p></div>
<p>And then came the acquisition by <strong>Oracle</strong>. A new journey started, one which took us from underdog in the space to the undisputed King Kong  of identity management. The problems got richer and more complex. The discussions got more intriguing and part of a larger tapestry. The community got bigger and more raucous. And the bar tabs got progressively more impressive.</p>
<div class="wp-caption alignnone" style="width: 510px"><a href="http://www.flickr.com/photos/demerzel/5010421953"><img title="Oracle Crew" src="http://farm5.static.flickr.com/4087/5010421953_de601db86f.jpg" alt="" width="500" height="375" /></a><p class="wp-caption-text">Almost on the mound at AT&amp;T Park</p></div>
<p>None of this would have been possible without a good band of merry men and women, and I certainly had that. These are the folks that taught me about true professionalism and dedication. They showed me just how much can be accomplished, and how much fun it can be, when done with camaraderie, enthusiasm and good humor. From them I learnt that what matters most is the team you work with, a mantra that I have taken to heart and hope to replicate any place I go.</p>
<p>It’s been a great journey. I worked very hard, played even harder, and enjoyed every moment of it. Along the way I felt like I was able to contribute to some great accomplishments.  I learnt a lot &#8211; about technology, about teamwork, and about myself. And I met and worked with some inspiring people. All of which I am eternally grateful for.</p>
<p>As for what I am doing next? Well, that’s for another blog post…</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/personal" rel="tag">Personal</a>, <a href="http://blog.talkingidentity.com/tag/thor-technologies" rel="tag">Thor Technologies</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/07/as-they-say-all-good-things-must-come-to-an-end.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Time To Put Your Thinking Caps On</title>
		<link>http://blog.talkingidentity.com/2011/07/time-to-put-your-thinking-caps-on.html</link>
		<comments>http://blog.talkingidentity.com/2011/07/time-to-put-your-thinking-caps-on.html#comments</comments>
		<pubDate>Tue, 12 Jul 2011 12:54:18 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Cat11]]></category>
		<category><![CDATA[Catalyst11]]></category>
		<category><![CDATA[CIS11]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[Cloud Identity Summit]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Federated Provisioning]]></category>
		<category><![CDATA[Gartner Catalyst Conference]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1251</guid>
		<description><![CDATA[Mike Neuenschwander has dubbed July as Identity Conference Month. And he should know, given that so many of his signature moments were on stage at the Catalyst conference that will be returning at the end of this month (July 26-29 in San Diego). Catalyst is always the most thought-provoking identity event of the year, but [...]]]></description>
			<content:encoded><![CDATA[<p>Mike Neuenschwander has dubbed July as <a href="http://bit.ly/noIEZA" target="_blank">Identity Conference Month</a>. And he should know, given that so many of his signature moments were on stage at the <a href="http://bit.ly/q3TjM1" target="_blank">Catalyst conference</a> that will be returning at the end of this month (July 26-29 in San Diego). Catalyst is always the most thought-provoking identity event of the year, but there is added intrigue this year, as a lot of us recurring *characters* are wondering what impact the Gartner takeover of the event (last years was still run by the Burton folk) will have on its ethos. I&#8217;ll be dropping in as always to learn, converse, incite and, of course, party.</p>
<p>The week before that, the <a href="http://bit.ly/n0zeMP" target="_blank">Cloud Identity Summit</a> (July 18-21) will once again be warming us up for Catalyst by hosting an impressive gathering of subject matter experts and thought leaders talking about the intertwined worlds of identity and the cloud. And this year, I&#8217;ll be there too, giving a talk on <strong>the future of identity provisioning</strong> (<em>July 20 at 12:00pm</em>). Following up on the talks I gave last year at <a href="http://bit.ly/d5aEZw">Gluecon</a> and at <a href="http://bit.ly/9xLC0N">Catalyst</a>, I&#8217;ll be bringing <a href="http://bit.ly/n28jdI" target="_blank">my cred as a provisioning expert</a> to bear in examining if identity provisioning even has a future in the pull-based future of identity (<em>spoiler alert: it does</em>), and what it might look like, given recent developments in the space and advancements in cloud architectures. In an unfortunate scheduling mishap, I will be going up against Pamela Dingle&#8217;s session on identity and mobility, which I would have loved to sit in on myself. I&#8217;m sure she&#8217;ll be peppering her session with cuteness in the form of cats or cuddly toys, so I&#8217;m going to have to up the game and incorporate something bad-ass into my session, like <em>Transformers</em> or <em>Angry Birds</em> (<em>Iron Man</em> was so <a href="http://bit.ly/9xLC0N">last year</a>). Pam, you&#8217;re going down <img src='http://blog.talkingidentity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Two weeks. Two great conferences. And me at both. So be there or be square!</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/cat11" rel="tag">Cat11</a>, <a href="http://blog.talkingidentity.com/tag/catalyst11" rel="tag">Catalyst11</a>, <a href="http://blog.talkingidentity.com/tag/cis11" rel="tag">CIS11</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-summit" rel="tag">Cloud Identity Summit</a>, <a href="http://blog.talkingidentity.com/tag/conference" rel="tag">Conference</a>, <a href="http://blog.talkingidentity.com/tag/federated-provisioning" rel="tag">Federated Provisioning</a>, <a href="http://blog.talkingidentity.com/tag/gartner-catalyst-conference" rel="tag">Gartner Catalyst Conference</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/07/time-to-put-your-thinking-caps-on.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FFIEC Updates Their Guidance. And The Winner Is&#8230;</title>
		<link>http://blog.talkingidentity.com/2011/06/ffiec-updates-their-guidance-and-the-winner-is.html</link>
		<comments>http://blog.talkingidentity.com/2011/06/ffiec-updates-their-guidance-and-the-winner-is.html#comments</comments>
		<pubDate>Wed, 29 Jun 2011 13:32:37 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Federated Identity]]></category>
		<category><![CDATA[FFIEC]]></category>
		<category><![CDATA[Identity Context]]></category>
		<category><![CDATA[Multi-Factor Authentication]]></category>
		<category><![CDATA[Online Banking]]></category>
		<category><![CDATA[Oracle Adaptive Access Manager]]></category>
		<category><![CDATA[Passwords Must Die]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Architecture]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1240</guid>
		<description><![CDATA[In my last post, I mentioned that the FFIEC was preparing an update to their 2005 guidance on internet banking authentication. Well, that update is out, and Anil John couldn&#8217;t wait to let me know about it (:)). The update, entitled &#8216;Supplement to Authentication in an Internet Banking Environment&#8216; recognizes both the growth in online [...]]]></description>
			<content:encoded><![CDATA[<p>In my <a href="http://bit.ly/iXqtpH" target="_blank">last post</a>, I mentioned that the FFIEC was preparing an update to their 2005 guidance on internet banking authentication. Well, that update is out, and Anil John <a href="http://bit.ly/mKs2Ui" target="_blank">couldn&#8217;t wait to let me know about it</a> (:)). The update, entitled &#8216;<a href="http://bit.ly/k6T0kw" target="_blank">Supplement to Authentication in an Internet Banking Environment</a>&#8216; recognizes both the growth in online banking and the dramatic change in the nature of internet threats it faces. The supplement stresses three key areas:</p>
<ol>
<li>the need for financial institutions to perform risk assessments against an ever-evolving threat landscape,</li>
<li>the need to implement and constantly adjust a layered security strategy to mitigate the identified risks, and</li>
<li>the requirement to raise customer awareness of potential risks through education programs.</li>
</ol>
<p>The most telling aspect of the enhanced guidance seems to be its recognition of the fact that the threat landscape is not just different from what existed in 2005, but <em>constantly evolving</em>. Without actually stating this explicitly, the guidance attempts to make the point that this constant evolution means that any guidance put forth will become defunct pretty quickly, and places responsibility on financial institutions to make the effort in understanding the risks they face (through <strong>periodic risk assessments</strong>) and continuously improving their security posture in response. Personally, I would have liked to have seen them be much more explicit and take a much harder line on this, because multiple case studies and anecdotal evidence suggests that far too many banks put in the minimal effort necessary to simply comply with the letter of the 2005 guidance without attempting to be true to its intent.</p>
<h3>An Emphasis on Risk-Based Authentication</h3>
<p>The guidance brings out the need for financial institutions to create a more accurate and granular model of their risks based on a much wider variety of factors than <img class="alignright size-full wp-image-1247" title="risk-O-meter" src="http://blog.talkingidentity.com/wp-content/uploads/2011/06/risk-O-meter.jpg" alt="risk-O-meter" width="234" height="244" />previously described &#8211; the evolving threat landscape, the changes in the nature of their customer base and the kinds of transactions being done online. A more accurate calculation of the transactions risk must then be mapped to appropriate security controls, both at the time of the initial authentication (logon) and at the time of the transaction itself. The supplement (smartly) brings out the need to factor in <strong>contextual information</strong> &#8211; from <em>environment variables</em> like device identification and time of day to detection of anomalies in behavior patterns &#8211; in any risk calculation. Interestingly, both <strong>anomaly detection</strong> and <strong>privileged account management </strong>are emphasized in the security architecture.</p>
<h3>Calling Out Outdated Techniques</h3>
<p>Both <strong>device identification</strong> (through cookies) and <strong>challenge questions</strong> are called out as having to be enhanced from their previous &#8220;simple&#8221; models to more sophisticated, or &#8220;complex&#8221; models. While the enhancements recommended in both cases are improvements, I don&#8217;t believe they go far enough. In the case of challenge questions, for instance, it recommends</p>
<ol>
<li>increasing the number of challenge questions asked (without actually giving a number, so in theory just increasing from 1 to 2 is good enough),</li>
<li>avoiding challenge questions that can be answered by mining the users information through online searches and social networks,</li>
<li>including a &#8220;red herring&#8221; question that a fraudster would attempt to answer but a legitimate user would not (huh?), and</li>
<li>using only a random subset of the challenge questions that the user has provided answers for in a single session.</li>
</ol>
<p>This guidance fails to take into account that this is actually hard to implement without neutering its effectiveness. Forcing users to set up more challenge questions usually leads to selection of easily guessable answers, and more helpdesk calls. The 2nd item above is very subjective, and the harder you make the questions, the more likely the legitimate user will mess them up too. And I don&#8217;t even know how the 3rd item is supposed to work.</p>
<p>Also of note, the guidance does point out the decreased effectiveness of <strong>multi-factor authentication</strong> (even though it was probably drafted before the RSA breach compromised SecurID tokens). It does however advocate it&#8217;s use as one of the many controls in a layered model. Out-of-band authentication mechanisms (like those delivering One Time Passwords over SMS) get a fair amount of time in this paper as a practical solution.</p>
<h3>Whats Missing</h3>
<p>I was disappointed that the guidance didn&#8217;t talk more clearly about <strong>passwords</strong>, and the need to really educate consumers about both better policies and their inherent ineffectiveness. And I think the fact that there was not a single mention of <strong>federated identity</strong>, especially in the context of &#8220;Business/Commercial Banking&#8221;, was a real missed opportunity for the FFIEC to move the discussion towards a better security architecture. I&#8217;m sure <a href="http://www.twitter.com/Steve_Lockstep" target="_blank">Stephen Wilson</a> is not surprised by that, though.</p>
<h3>Looking Forward</h3>
<p>The guidance will go into effect starting January 2012, so there will probably be some banks scrambling to understand what the implications are for the controls they have already deployed. Smarter institutions that have been paying attention to the security landscape all along will probably find that they are in good shape, but a lot who did the bare minimum and want to meet these guidelines will face some serious work. I predict an uptick in the interest that risk-based security products like <strong>Oracle Adaptive Access Manager</strong> will garner in the market. The emphasis on staying up to date with the ever evolving threat landscape will create a requirement for more dynamic security products that aid not just in enforcing stronger controls, but in assisting with the periodic risk assessments (Identity Intelligence, anyone?).</p>
<p>But the fact that this is guidance and not regulatory mandates means that a lot of institutions will continue to pay lip service to it. Which is why the real emphasis needs to be on changing the fundamental security architecture underlying (and infiltrating) enterprise IT. The consumerization of IT will probably play a far bigger role in driving this change than the FFIEC guidance will. Time will tell.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/federated-identity" rel="tag">Federated Identity</a>, <a href="http://blog.talkingidentity.com/tag/ffiec" rel="tag">FFIEC</a>, <a href="http://blog.talkingidentity.com/tag/identity-context" rel="tag">Identity Context</a>, <a href="http://blog.talkingidentity.com/tag/multi-factor-authentication" rel="tag">Multi-Factor Authentication</a>, <a href="http://blog.talkingidentity.com/tag/online-banking" rel="tag">Online Banking</a>, <a href="http://blog.talkingidentity.com/tag/oracle-adaptive-access-manager" rel="tag">Oracle Adaptive Access Manager</a>, <a href="http://blog.talkingidentity.com/tag/passwords-must-die" rel="tag">Passwords Must Die</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a>, <a href="http://blog.talkingidentity.com/tag/security-architecture" rel="tag">Security Architecture</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/06/ffiec-updates-their-guidance-and-the-winner-is.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>So What Does Constitute &#8220;Reasonable&#8221; Security?</title>
		<link>http://blog.talkingidentity.com/2011/06/so-what-does-constitute-reasonable-security.html</link>
		<comments>http://blog.talkingidentity.com/2011/06/so-what-does-constitute-reasonable-security.html#comments</comments>
		<pubDate>Thu, 23 Jun 2011 13:01:57 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[FFIEC]]></category>
		<category><![CDATA[Identity Context]]></category>
		<category><![CDATA[Multi-Factor Authentication]]></category>
		<category><![CDATA[Online Banking]]></category>
		<category><![CDATA[Passwords Must Die]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Architecture]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1227</guid>
		<description><![CDATA[A couple of weeks ago, I tweeted about what I called a must-read article by Brian Krebs. Fellow identirati Anil John lamented yesterday that we hadn&#8217;t discussed this more in the community, and on second glance I can see why. The article covers a court case where the magistrate was basically asked to decide what [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of weeks ago, I <a href="http://bit.ly/lcWoMz" target="_blank">tweeted about</a> what I called a <a href="http://bit.ly/k8yFpl" target="_blank">must-read article</a> by Brian Krebs. Fellow identirati Anil John <a href="http://bit.ly/mJPTr7" target="_blank">lamented yesterday</a> that we ha<img class="alignright size-full wp-image-782" title="legal_opinion" src="http://blog.talkingidentity.com/wp-content/uploads/2010/02/legal_opinion.jpg" alt="legal_opinion" width="204" height="200" />dn&#8217;t discussed this more in the community, and on second glance I can see why. The article covers a court case where the magistrate was basically asked to decide what constitutes &#8220;commercially reasonable&#8221; security. While most of our collective ire seems to have focused on the seemign unfairness of the ruling, and the implication that &#8220;passwords + challenge questions = multi-factor authentication&#8221; (as prescribed by the FFIEC guidelines), there is much more to learn from the story.</p>
<p>As the article described, part of the banks security infrastructure included <strong>risk-based security</strong> based on RSA&#8217;s Cyota product, which &#8220;rates the riskiness of transactions by using several factors, such as the location of a user’s Internet address, when and how often the user logs in, and how the customer navigates the site&#8221;. This actually provides a much better layer of protection than simply authenticating the user based on passwords. Context-based security is a key element in the multi-layered security architecture that is the future of enterprise security, as<a href="http://slidesha.re/jD5xhF" target="_blank"> I laid out in my recent talk</a>.</p>
<p>But the bank actually made a big mistake in it&#8217;s implementation. As the article describes, the bank reduced the threshold for kicking in the 2nd factor (challenge questions) to $1, effectively eliminating that component from their security architecture. They might as well have not had it, because they were completely ignoring any kind of risk calculation that was being done.</p>
<p>In other words, all they had was &#8220;password+challenge questions&#8221;!</p>
<p>And as we have talked about ad nauseam, in this day and age this is simply not enough. Passwords and challenge questions are nowhere near what I would call adequate security for an environment that would include high risk transactions (like bank transfers). And while there will be great resistance to any (strong authentication) solution that would appear to increase friction for the user in executing their transactions (witness the continued lack of pins for credit cards in the US), I think the tides are changing with respect to users understanding the risks and wanting more from their online security.</p>
<p>Risk based security models also need to involve monitoring and alerts, even denial of access, for exception conditions (like a new device ID being used). And the 2nd (or 3rd, or&#8230;) factors employed must be commensurate with the nature of the online transactions. Challenge questions may be fine when we&#8217;re talking about a low risk consumer site like a gaming site (though even they have <a href="http://on.fb.me/kjtdMb" target="_blank">gone beyond these</a>). Higher risk sites should employ more sophisticated factors like out of band challenges (the occasional SMS based challenge, or voice-based identification, for instance), so long as it is used with the correct risk scoring to trigger it. And despite the naysayers, I do believe externalized identity providers could help serve this market.</p>
<p>Crucially to all this, the FFIEC seems to recognize that security threats have evolved dramatically since their guidance was issued in 2005, and are <a href="http://bit.ly/m3pgT2" target="_blank">preparing an update</a>. From all indications, it would seem to put much more responsibility on the shoulders of financial institutions, asking them to put in place greater measures based on layered security to address fraud and attack vectors like Man-in-the-X attacks, and much more. Unfortunately, it will be too late to help Patco Construction. Let&#8217;s just hope other businesses are paying attention and getting ahead of the curve.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/ffiec" rel="tag">FFIEC</a>, <a href="http://blog.talkingidentity.com/tag/identity-context" rel="tag">Identity Context</a>, <a href="http://blog.talkingidentity.com/tag/multi-factor-authentication" rel="tag">Multi-Factor Authentication</a>, <a href="http://blog.talkingidentity.com/tag/online-banking" rel="tag">Online Banking</a>, <a href="http://blog.talkingidentity.com/tag/passwords-must-die" rel="tag">Passwords Must Die</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a>, <a href="http://blog.talkingidentity.com/tag/security-architecture" rel="tag">Security Architecture</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/06/so-what-does-constitute-reasonable-security.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

