<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Oracle Identity Management</title>
	<atom:link href="http://blog.talkingidentity.com/category/oracle-identity-management/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>BT wins European Identity Award for Fraud Service powered by Oracle</title>
		<link>http://blog.talkingidentity.com/2011/05/bt-wins-european-identity-award-for-fraud-service-powered-by-oracle.html</link>
		<comments>http://blog.talkingidentity.com/2011/05/bt-wins-european-identity-award-for-fraud-service-powered-by-oracle.html#comments</comments>
		<pubDate>Wed, 18 May 2011 21:38:08 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[BT]]></category>
		<category><![CDATA[EIC11]]></category>
		<category><![CDATA[European Identity Award]]></category>
		<category><![CDATA[European Identity Conference]]></category>
		<category><![CDATA[Fraud Prevention]]></category>
		<category><![CDATA[Identity Proofing]]></category>
		<category><![CDATA[Managed Fraud Reduction]]></category>
		<category><![CDATA[OAAM]]></category>
		<category><![CDATA[Oracle Adaptive Access Manager]]></category>
		<category><![CDATA[Oracle Service Bus]]></category>
		<category><![CDATA[Oracle_IDM]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1189</guid>
		<description><![CDATA[Another year, another European Identity Award for an Oracle customer. At last weeks European Identity Conference, KuppingerCole gave their coveted award in the Governance, Risk Management and Compliance category to BT for their Managed Fraud Reduction service. The BT MFR service provides a real time risk assessment of online transactions, thus providing customers the ability [...]]]></description>
			<content:encoded><![CDATA[<p>Another year, another <strong>European Identity Award</strong> for an Oracle customer. At last weeks <a href="http://www.id-conf.com/eic2011" target="_blank">European Identity Conference</a>, KuppingerCole gave their coveted award in the <em>Governance, Risk Management and Compliance</em> category to <strong>BT</strong> for their <strong>Managed Fraud Reduction</strong> service. The <a href="http://bit.ly/mqdMHq" target="_blank"><strong>BT MFR</strong> service</a> provides a real time risk assessment of online transactions, thus providing customers the ability to incorporate an extensible fraud detection tool into their environment at minimal cost.</p>
<div id="attachment_1190" class="wp-caption aligncenter" style="width: 550px"><a href="http://www.kuppingercole.com/gallery/eic2011/IMG_5656.JPG.html" target="_blank"><img class="size-full wp-image-1190" title="award_oracle_eic2011" src="http://blog.talkingidentity.com/wp-content/uploads/2011/05/award_oracle_eic2011.jpg" alt="BT and Oracle accepting a European Iidentity Award" width="540" height="360" /></a><p class="wp-caption-text">BT (Robert McCausland &amp; Peter Boyle) and Oracle (the ever dapper Christian Patrascu) accepting the European Identity Award from Martin Kuppinger &amp; Tim Cole</p></div>
<h3>The Solution</h3>
<p>BT MFR brings together a comprehensive suite of fraud reduction  capabilities under a single service. Device recognition, location  recognition, behavior recognition and comprehensive policy enforcement  through a customizable ruleset (powered by Oracle Adaptive Access  Manager) provide granular risk assessments, returned in real-time so  that even digital services requiring instantaneous delivery can be risk  assessed for suspected fraud.</p>
<p>This functionality is all strung together and orchestrated by an  Oracle Service Bus and accessed via web service calls. The routing and  transformation layer that OSB provides allows for the  augmentation of  all the transaction data presented which can subsequently be  used in a  much richer risk assessment. The sources of such checks could be  external  URU or internal to the enterprise based on intelligence  they&#8217;ve built up over  years.</p>
<p>Risk assessments from multiple services can thus be aggregated to  provide a single response to the protected application, containing all  the information required to determine whether any transaction should  continue forward.</p>
<p><img class="aligncenter size-full wp-image-1192" title="BT MFR Arch" src="http://blog.talkingidentity.com/wp-content/uploads/2011/05/BT-MFR-Arch.jpg" alt="BT MFR Arch" width="550" height="252" /></p>
<p>Thanks to this unique design the service is also able to evolve, with new services integrated into the overall risk assessment procedure as they become required or available, without impacting the single web service call that the customer needs to access this battery of anti-fraud protection.</p>
<h3>The Benefits</h3>
<p>BTs Managed Fraud Reduction service has brought together a unique set of capabilities that address online fraud in ways that adapt to the organizations specific needs:</p>
<ul>
<li>Most online retailers cannot afford to issue password generating tokens to a fickle and ever-changing user-base. so a risk assessment based on transaction parameters such as device recognition and location provides a different way to achieve greater security.</li>
<li>Online retailers providing digital goods or services cannot wait until shipping to review transactions (as delivery is immediate) so a system based on real-time assessment is greatly beneficial.</li>
<li>Financial service providers need to assure funds transfers and payments within increasingly short windows (due to regulations such as ‘Faster Payments’) so real-time responses are essential.</li>
<li>Gaming and leisure services are reliant on age-verification, so require identity verification score aggregated with the normal risk assessment. MFR allows the integration of such additional web services and will launch with BT’s URU identity verification available as an option.</li>
<li>With the BT MFR service in place, customers can demonstrate to auditors that fraud prevention strategies are in operation and as a cloud service allows them to demonstrate this at a fraction of the cost compared to a self build strategy.</li>
<li>With a robust fraud solution in place, customers can demonstrate to merchant acquiring banks that liability has been reduced.</li>
<li>The architecture removes the need for the customer to contract separately with multiple vendors providing identity and fraud related services.</li>
</ul>
<p>Addressing all market sectors and territories, fully customizable and simple to use, BT Managed Fraud Reduction service is an evolving one-stop solution to the ever-changing challenge of online fraud. And Oracle is proud to be a part of the solution.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/bt" rel="tag">BT</a>, <a href="http://blog.talkingidentity.com/tag/eic11" rel="tag">EIC11</a>, <a href="http://blog.talkingidentity.com/tag/european-identity-award" rel="tag">European Identity Award</a>, <a href="http://blog.talkingidentity.com/tag/european-identity-conference" rel="tag">European Identity Conference</a>, <a href="http://blog.talkingidentity.com/tag/fraud-prevention" rel="tag">Fraud Prevention</a>, <a href="http://blog.talkingidentity.com/tag/identity-proofing" rel="tag">Identity Proofing</a>, <a href="http://blog.talkingidentity.com/tag/managed-fraud-reduction" rel="tag">Managed Fraud Reduction</a>, <a href="http://blog.talkingidentity.com/tag/oaam" rel="tag">OAAM</a>, <a href="http://blog.talkingidentity.com/tag/oracle-adaptive-access-manager" rel="tag">Oracle Adaptive Access Manager</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-service-bus" rel="tag">Oracle Service Bus</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/05/bt-wins-european-identity-award-for-fraud-service-powered-by-oracle.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Identity Intelligence to Drive Business Objectives</title>
		<link>http://blog.talkingidentity.com/2011/05/identity-intelligence-to-drive-business-objectives.html</link>
		<comments>http://blog.talkingidentity.com/2011/05/identity-intelligence-to-drive-business-objectives.html#comments</comments>
		<pubDate>Mon, 02 May 2011 06:19:58 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Gartner IAM Summit]]></category>
		<category><![CDATA[Identity Analytics]]></category>
		<category><![CDATA[Identity and Access Intelligence]]></category>
		<category><![CDATA[Identity Intelligence]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1175</guid>
		<description><![CDATA[As I pointed out in my answer to Ema&#8217;s question about the recent Gartner IAM Summit in London, the overwhelming theme of the conference was Identity &#38; Access Intelligence. The main driver for this shift in focus being discussed at the conference was around the core idea of driving down costs in identity management projects, [...]]]></description>
			<content:encoded><![CDATA[<p>As I pointed out in <a href="http://bit.ly/k3lpVu" target="_blank">my answer to Ema&#8217;s question</a> about the recent <strong>Gartner IAM Summit</strong> in London, the overwhelming theme of the conference was <em>Identity &amp; Access Intelligence</em>. The main driver for this shift in focus being discussed at the conference was around the core idea of driving down costs in identity management projects, and making them more manageable. But as I tried to explain in my talk, the rise of identity intelligence is about a lot more. Today’s CISO&#8217;s face pressure to demonstrate the link between their identity management programs and business objectives, crucial in measuring how well IT supports the business and manages risk. This means making sense of technical identity data and transforming it into insightful, business-friendly information that is actionable.</p>
<p>In this adaptation of the talk I gave at the Gartner Summit, I lay out how identity management, data mining, business processing and analytics come together as <strong>Identity Intelligence</strong> to address enterprise needs for greater transparency, compliance, risk management and business decision support. Check out the slidecast, which clocks in at a comfortable 20 minutes or so, and learn how we are bridging the divide between IT and the Business, and making security smarter.</p>
<div id="__ss_7799277" style="width: 510px;"><strong style="display:block;margin:12px 0 4px"><a title="Identity Intelligence for Business" href="http://www.slideshare.net/NishantKaushik/identity-intelligence-for-business">Identity Intelligence to Drive Business Objectives</a></strong> <object id="__sse7799277" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="510" height="426" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=identityintelligenceforbusiness-upload-110502003852-phpapp01&amp;stripped_title=identity-intelligence-for-business&amp;userName=NishantKaushik" /><param name="name" value="__sse7799277" /><param name="allowfullscreen" value="true" /><embed id="__sse7799277" type="application/x-shockwave-flash" width="510" height="426" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=identityintelligenceforbusiness-upload-110502003852-phpapp01&amp;stripped_title=identity-intelligence-for-business&amp;userName=NishantKaushik" name="__sse7799277" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="padding:5px 0 12px">View more <a href="http://www.slideshare.net/">webinars</a> from <a href="http://www.slideshare.net/NishantKaushik">Nishant Kaushik</a></div>
</div>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/gartner-iam-summit" rel="tag">Gartner IAM Summit</a>, <a href="http://blog.talkingidentity.com/tag/identity-analytics" rel="tag">Identity Analytics</a>, <a href="http://blog.talkingidentity.com/tag/identity-and-access-intelligence" rel="tag">Identity and Access Intelligence</a>, <a href="http://blog.talkingidentity.com/tag/identity-intelligence" rel="tag">Identity Intelligence</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/05/identity-intelligence-to-drive-business-objectives.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An Entitlement-Centric Approach to Security</title>
		<link>http://blog.talkingidentity.com/2011/04/an-entitlement-centric-approach-to-security.html</link>
		<comments>http://blog.talkingidentity.com/2011/04/an-entitlement-centric-approach-to-security.html#comments</comments>
		<pubDate>Tue, 05 Apr 2011 20:40:13 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Entitlement Management]]></category>
		<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Security Architecture]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1134</guid>
		<description><![CDATA[Last week, I gave a well-received talk to a group of CxO and high-level IT managers on a new way to think about security built around entitlements. The premise of the talk was that with the de-perimiterization of the enterprise, the modern enterprise has already become entitlement-based; we in the security industry just haven&#8217;t caught [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, I gave a well-received talk to a group of CxO and high-level IT managers on a new way to think about security built around entitlements. The premise of the talk was that with the de-perimiterization of the enterprise, the modern enterprise has already become entitlement-based; we in the security industry just haven&#8217;t caught up with this yet. And unless our tools catch up with this change, we are going to keep burdening our customers with costly integration and compliance burdens. Entitlements is a common language that can help change the way identity is used as the foundation for defining holistic security policies and managing risk in the enterprise.</p>
<p>The deck I presented (with audio) is below. Check it out and leave me your comments.</p>
<div id="__ss_7523051" style="width: 510px;"><strong style="display:block;margin:12px 0 4px"><a title="An Entitlement-Centric Approach to Security" href="http://www.slideshare.net/NishantKaushik/an-entitlementcentric-approach-to-security">An Entitlement-Centric Approach to Security</a></strong> <object id="__sse7523051" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="510" height="426" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=cso2011nyckaushikslideshare-110405094157-phpapp02&amp;stripped_title=an-entitlementcentric-approach-to-security&amp;userName=NishantKaushik" /><param name="name" value="__sse7523051" /><param name="allowfullscreen" value="true" /><embed id="__sse7523051" type="application/x-shockwave-flash" width="510" height="426" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=cso2011nyckaushikslideshare-110405094157-phpapp02&amp;stripped_title=an-entitlementcentric-approach-to-security&amp;userName=NishantKaushik" name="__sse7523051" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="padding:5px 0 12px">View more <a href="http://www.slideshare.net/">webinars</a> from <a href="http://www.slideshare.net/NishantKaushik">Nishant Kaushik</a></div>
</div>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/entitlement-management" rel="tag">Entitlement Management</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/security-architecture" rel="tag">Security Architecture</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/04/an-entitlement-centric-approach-to-security.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Join Us (Me) at the Oracle Security Online Forum (Feb 24)</title>
		<link>http://blog.talkingidentity.com/2011/02/join-us-me-at-the-oracle-security-online-forum-feb-24.html</link>
		<comments>http://blog.talkingidentity.com/2011/02/join-us-me-at-the-oracle-security-online-forum-feb-24.html#comments</comments>
		<pubDate>Mon, 07 Feb 2011 22:11:11 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Enterprise Identity]]></category>
		<category><![CDATA[Identity Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1104</guid>
		<description><![CDATA[On Thursday, February 24, Oracle will be holding an online mini conference focusing on security &#8211; the Oracle Security Online Forum. This live joint event with Accenture will last from 12:00-4:00pm ET, and will feature a great line-up of speakers and sessions focusing on security trends, best practices, and proven solutions for your business. It&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>On Thursday, February 24, Oracle will be holding an online mini conference focusing on security &#8211; <a href="http://bit.ly/hEg8Wz" target="_blank">the <strong>Oracle Security Online Forum</strong></a>. This live joint event with Accenture will last from 12:00-4:00pm ET, and will feature a great line-up of speakers and sessions focusing on security trends, best practices, and  proven solutions for your business. It&#8217;s a unique opportunity for security professionals, IT executives, IT architects, identity management and database specialists, data architects, IT administrators and auditors to hear from some of the experts in their respective fields.</p>
<p>I&#8217;ll be kicking off things alongside Vipin Samar and Jeff Margolies on the keynote panel &#8220;<strong>2011: Information Security Trends for the Next Decade</strong>&#8220;. And throughout the event, Oracle security solution experts will be on live chat event to answer your toughest questions. I&#8217;m only going to stay on for a little while after the keynote finishes, so be sure to join on time if you want to grill me.</p>
<p><a href="http://bit.ly/hEg8Wz" target="_blank">Register to attend</a> this online event and find out how you can take a proactive approach to secure your enterprise.</p>
<p><a href="http://bit.ly/hEg8Wz"><img class="alignnone size-full wp-image-1105" title="Compliance_Header" src="http://blog.talkingidentity.com/wp-content/uploads/2011/02/Compliance_Header.jpg" alt="Compliance_Header" width="550" height="209" /></a></p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/conference" rel="tag">Conference</a>, <a href="http://blog.talkingidentity.com/tag/enterprise-identity" rel="tag">Enterprise Identity</a>, <a href="http://blog.talkingidentity.com/tag/identity-management" rel="tag">Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/02/join-us-me-at-the-oracle-security-online-forum-feb-24.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>When &#8220;Trust&#8221; Is Not Enough</title>
		<link>http://blog.talkingidentity.com/2011/01/when-trust-is-not-enough.html</link>
		<comments>http://blog.talkingidentity.com/2011/01/when-trust-is-not-enough.html#comments</comments>
		<pubDate>Fri, 28 Jan 2011 00:47:05 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Adaptive Risk Manager]]></category>
		<category><![CDATA[Audit Vault]]></category>
		<category><![CDATA[Database Security]]></category>
		<category><![CDATA[Fraud Prevention]]></category>
		<category><![CDATA[Identity Analytics]]></category>
		<category><![CDATA[Oracle Adaptive Access Manager]]></category>
		<category><![CDATA[Privileged Account Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1094</guid>
		<description><![CDATA[Computerworld has an interesting article &#8216;Security fail: When trusted IT people go bad&#8216; with the even more interesting subtitle &#8220;One rogue IT employee can do more damage than an army of hackers&#8220;. It&#8217;s well worth a read, if only to get a feel for the nightmarish scenarios CIO&#8217;s can be faced with. The 3 case [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Computerworld</strong> has an interesting article &#8216;<a href="http://bit.ly/hGE1Og" target="_blank">Security fail: When trusted IT people go bad</a>&#8216; with the even more interesting subtitle &#8220;<em>One rogue IT employee can do more damage than an army of hackers</em>&#8220;. It&#8217;s well worth a read, if only to get a feel for the nightmarish scenarios CIO&#8217;s can be faced with.</p>
<p><img class="alignright size-full wp-image-1097" title="SysAdmin Fraud" src="http://blog.talkingidentity.com/wp-content/uploads/2011/01/SysAdminFraud.jpg" alt="SysAdmin Fraud" width="315" height="268" />The 3 case studies presented deal with one issue: Privileged IT Administrators who have complete access to systems, and use it to either systematically abuse your trust or wreak havoc when provoked. In every case, the damage to the organization was substantial, and the steps needed to recover were extreme (I especially liked one companies solution to their potential hostage crisis: put the guy on a cross country flight, and use those 5+ hours to change all the passwords).</p>
<p>It has been well understood for years that insider fraud is a far bigger threat to organizations than anything that could be done from the outside (barring specific domains like national security). Not only do system administrators usually have complete access, but they can move around your network with impunity &#8211; no auditing, no oversight, no accountability. In effect, the IT environment that you spend so much time locking down has a wide open backdoor that can be exploited by a small but highly skilled populace to do significant damage. And when you broaden your view a bit, you find that this goes beyond just the system administrators to other &#8220;trusted&#8221; users as well &#8211; employees that use shared, highly privileged accounts to execute transactions that are sensitive and crucial to the business, but could also be abused.</p>
<p>Organizations that take a comprehensive and holistic approach to identity and access management can protect themselves against the possibility of these sort of nightmare scenarios playing out. While the article outlines some basic HR type steps that organizations can take, like better background checks, it doesn&#8217;t go into any specifics about how a properly defined identity management program can help in mitigating these risks. So how can IdM address some of the issues brought out by the article? Let&#8217;s review.</p>
<h3>1) Strengthen Your Core</h3>
<p>The core of identity management &#8211; SSO, identity administration, provisioning (including de-provisioning) &#8211; is obviously essential. Within that, it&#8217;s important to realize that one reason shared accounts proliferate is due to its convenience and expediency, because no one wants  the overhead and pain of getting properly privileged accounts. But a well designed <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-identity-manager/index.html" target="_blank">access request system</a>, with intuitive self-service, adequate workflow and policy controls and the right level of automation will help organizations avoid slipping into shared account hell &#8211; by empowering users without sacrificing security.</p>
<h3>2) Avoid Excessive Privilege Accumulation</h3>
<p>The article points to classic &#8220;privilege escalation&#8221; as a culprit, where users are given additional privileges to deal with short term project needs, but then those privileges are never taken away after the need goes away. Over time the user accumulates a large set of privileges that not only allow them to continue to do things long after they should no longer be able to, but can can create a toxic combinations of privileges that gives them the ability to take actions that should never be allowed by policy.</p>
<p>There are a few things you can do to address this problem. First, your identity administration system should support <strong>time or context bound privilege escalations</strong>. If a user is being given additional privileges because of a specific need, make that grant role-based or time-bound. That way, when the conditions that led to the privilege escalation expire, those privileges get taken away and are not left with the user. Second, make sure to leverage <strong>Separation of Duties (SoD) policies</strong>, so that you can detect and therefore prevent situations where a privilege grant is going to result in the user having an undesirable combination of entitlements that could be abused. This would be leveraged not only during the initial privilege grant to alert someone with oversight responsibilities (like a manager), but also during an entitlement review, which is the third mitigating control. <strong>Periodic entitlement reviews</strong> are now essential to combat privilege accumulation and also prove compliance. And entitlement reviews that get triggered when events such as privilege escalation occur not only help in keeping people focused on the problem (instead of it getting buried in the details), but also let your people know that they are being monitored. Getting <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-identity-analytics/index.html" target="_blank">in-depth and comprehensive insight</a> into your IT environment is key to managing excessive privilege accumulation.</p>
<h3>3) Make your Access Context-Aware</h3>
<p>This is where we think the future of identity management is headed. Two of the scenarios outlined in the article describe situations where the privileged employee decided that they were going to take drastic action to inflict maximum damage on the company. By profiling the behavior of the user, and comparing the users actions to established patterns, you can detect anomalies that would indicate that some kind of fraudulent activity is underway. The article also talks about &#8220;Sally&#8221; taking her laptop home and still being able to use high-level privileges. But if your access management system can leverage environmental variables like device IDs, network profiles and IP geo-location as part of its authorization context, then it can limit the use of elevated privileges when the right conditions are not met.</p>
<p>In all these cases, the IdM system, having detected potential fraud, now has the ability to initiate corrective action, like elevating the monitoring of the user activity, up-leveling the assurance of the identity in play by asking additional authentication questions or presenting 3rd party or application data that only the correct user could verify, and even outright denying the user access. By monitoring the full picture of what is actually occurring in real-time, you can detect or prevent fraud. And you can do it without negatively impacting the user experience. In effect, the <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-ada-access-mgr/index.html" target="_blank">access adapts dynamically</a> to the user behavior and the risk level of the transactions.</p>
<h3>4) Protect Your Keys to the Kingdom</h3>
<p>The article points out that &#8220;threats from privilege-laden IT employees are especially hard to detect. For one thing, staffers&#8217; nefarious activities can look the same as their regular duties&#8221;. And when you have multiple people in the IT staff who know how to utilize these system accounts, it&#8217;s hard to pinpoint the exact perpetrator of the actions. That&#8217;s why using a <a href="http://bit.ly/eaZePV"><strong>Privileged Account Management</strong></a> system is so important. By putting a control system around the most sensitive and powerful accounts that an organization has, you can make sure that you are never going to be in the situation where an <a href="http://bit.ly/evTE5q" target="_blank">employee can hold you hostage</a>. Administrators can no longer go in and change the passwords without the organization knowing, all their activity can be monitored and traced, and their access to the privileged accounts can be cut off in one fell swoop (instead of having to put them on a plane ride to California).</p>
<h3>5) Protect Your Data</h3>
<p>Sounds obvious, right? But the fact that the current state of affairs means that your DBA can go in and &#8220;download 400 customer credit card numbers from your e-commerce server&#8221; is all too common. Your <a href="http://www.oracle.com/us/products/database/security/index.html" target="_blank">database cannot be overlooked</a> in your access management strategy. Organizations need to ensure that their privileged users and DBAs are restricted from accessing sensitive application data, despite having high-level privileges on the database. They need to implement controls to enforce separation of duties and also use solutions like transparent encryption to protect data against unauthorized access by OS level users. And they need to monitor their database configuration on a continuous basis, and audit their users to know who did what and when for accountability.</p>
<h3>The Right Tools Make the Plan</h3>
<p>The article correctly points out that technology is not enough. &#8220;It&#8217;s a combination of technical safeguards and human observation that offers the best protection, says CERT&#8217;s Cappelli&#8221;. On the identity management side of things, however, there are a number of things that organizations should be doing that they don&#8217;t. And by putting in place this kind of comprehensive identity management program, with the right controls that constantly optimize and enforce policies that mitigate risk, an organization can help the people in charge be informed, aware, alert and in control. And that sounds like a plan.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/adaptive-risk-manager" rel="tag">Adaptive Risk Manager</a>, <a href="http://blog.talkingidentity.com/tag/audit-vault" rel="tag">Audit Vault</a>, <a href="http://blog.talkingidentity.com/tag/database-security" rel="tag">Database Security</a>, <a href="http://blog.talkingidentity.com/tag/fraud-prevention" rel="tag">Fraud Prevention</a>, <a href="http://blog.talkingidentity.com/tag/identity-analytics" rel="tag">Identity Analytics</a>, <a href="http://blog.talkingidentity.com/tag/oracle-adaptive-access-manager" rel="tag">Oracle Adaptive Access Manager</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/privileged-account-management" rel="tag">Privileged Account Management</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/01/when-trust-is-not-enough.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Future in the Clouds? How About Some ESSO-To-Go?</title>
		<link>http://blog.talkingidentity.com/2011/01/future-in-the-clouds-how-about-some-esso-to-go.html</link>
		<comments>http://blog.talkingidentity.com/2011/01/future-in-the-clouds-how-about-some-esso-to-go.html#comments</comments>
		<pubDate>Mon, 10 Jan 2011 21:55:37 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Authentication Management]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[ESSO]]></category>
		<category><![CDATA[Oracle ESSO]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1075</guid>
		<description><![CDATA[There is little doubt any more that the cloud revolution is in full swing. Enterprises today are adopting cloud-based and hosted solutions for everything from CRM to personal productivity applications to business intelligence. Enterprises want the user experience of accessing SaaS applications to be secure, but transparent. This pretty much mandates an approach based on [...]]]></description>
			<content:encoded><![CDATA[<p>There is little doubt any more that the cloud revolution is in full swing. Enterprises today are adopting cloud-based and hosted solutions for everything from CRM to personal productivity applications to business intelligence. Enterprises want the user experience of accessing SaaS applications to be secure, but transparent. This pretty much mandates an approach based on <strong>single sign-on</strong> technology &#8211; one that extends the single login experience that exists within the enterprise to all these third party resources.</p>
<p>But there is a catch. One of the benefits that enterprises frequently consider when going with a SaaS application is the fact that the user does not have to be within the corporate network to access these systems. These systems can be accessed from any computing device, so long as it has an internet connection. It could be the computer in the hotel business center, or a laptop borrowed from a friend. But in an SSO-protected world, no one knows their application specific passwords any more (by design). So how can a user access the SaaS application if they do not know their password?</p>
<p>Yes, I know that we want to kill passwords (multiple passwords, to be precise. And I am all for it). But the day when enterprise will allow users to come in and use their own OpenIDs is  still somewhere in the murky future, and we need a more practical solution pretty much right now.</p>
<h3>Single Sign-on From Anywhere, To Anywhere</h3>
<p>December was a heavy travel month for me, between work travel and vacation, and I actually encountered this problem a couple of times. So I thought I&#8217;d use my first post of 2011 to highlight this very real challenge that enterprises are starting to face, and describe a little known solution we have (thanks to the Passlogix acquisition). <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-enterprise-sso/index.html" target="_blank"><strong>Oracle Enterprise Single Sign-On Suite Plus</strong></a> or <strong>Oracle ESSO </strong>(formally <em>Passlogix v-GO</em>) provides seamless SSO to a wide range of enterprise resources through the use of a <strong>desktop agent</strong> that manages all of the user’s account names and passwords on their behalf. Applications, including SaaS and Web resources, are recognized when they are launched based on their unique attributes, and the correct access credentials are supplied to each as required, transparent to the user.</p>
<p>Oracle ESSO solves the specific challenge posed above through <em>on-demand</em> functionality called <strong>Oracle ESSO Anywhere</strong>. When deployed, ESSO users can download a transient version of the agent by clicking on a website link. The user is now able to access the SaaS applications with the same protections afforded by the permanently installed agent inside the enterprise. An added benefit is that this also helps protect against users exposing passwords to threats that capture input directly from the keyboard (keyloggers). When the agent is shut down, the on-demand software removes all traces of the ESSO application and the user’s application credentials, ensuring that security is maintained.</p>
<div id="attachment_1078" class="wp-caption aligncenter" style="width: 560px"><img class="size-full wp-image-1078" title="ESSO_Anywhere" src="http://blog.talkingidentity.com/wp-content/uploads/2011/01/ESSO_Anywhere.jpg" alt="ESSO_Anywhere" width="550" height="235" /><p class="wp-caption-text">Oracle ESSO Anywhere</p></div>
<p>Cool, right? I wish there was a personal edition of this that I could use for all my web-based services. This also highlights another aspect of identity management that is top of my mind as we start a new year. Enterprise environments are evolving rather rapidly, so it&#8217;s important to make sure that the solutions you deploy can adapt to your changing environment. As access to your resources evolves beyond the desktop to the myriad of computing devices (smartphones, tablets like the iPad, etc) &#8220;infiltrating&#8221; your enterprise, we&#8217;re going to see significant changes to traditional IdM. And that&#8217;s a good thing.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/authentication-management" rel="tag">Authentication Management</a>, <a href="http://blog.talkingidentity.com/tag/cloud-security" rel="tag">Cloud Security</a>, <a href="http://blog.talkingidentity.com/tag/esso" rel="tag">ESSO</a>, <a href="http://blog.talkingidentity.com/tag/oracle-esso" rel="tag">Oracle ESSO</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/01/future-in-the-clouds-how-about-some-esso-to-go.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking at Oracle Federal Forum on Oracle IdM &amp; ICAM</title>
		<link>http://blog.talkingidentity.com/2010/10/speaking-at-oracle-federal-forum-on-oracle-idm-icam.html</link>
		<comments>http://blog.talkingidentity.com/2010/10/speaking-at-oracle-federal-forum-on-oracle-idm-icam.html#comments</comments>
		<pubDate>Tue, 19 Oct 2010 04:31:13 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[FICAM]]></category>
		<category><![CDATA[ICAM]]></category>
		<category><![CDATA[Oracle Federal Forum]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1066</guid>
		<description><![CDATA[The 4th annual Oracle Federal Forum is being held this Wednesday (Oct 20th) in Washington, DC. It&#8217;s a thought leadership day focused on the concerns of the transforming Federal government, where you&#8217;ll hear some real-world best practices and lessons from agencies, industry strategists and thought leaders. Oracle also uses this forum to provide an update [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>4th annual Oracle Federal Forum</strong> is being held this Wednesday (Oct 20th) in Washington, DC. It&#8217;s a thought leadership day focused on the concerns of the transforming Federal government, where you&#8217;ll hear some real-world best practices and lessons from agencies, industry strategists and thought leaders. Oracle also uses this forum to provide an update on our vision across all our product areas (which as you know, is pretty vast now).</p>
<p>Somehow, I&#8217;ve been added to the agenda, to speak about Oracle Identity Management and how it can be used to meet the requirements of the Federal ICAM initiative. It&#8217;s a topic that I&#8217;d love to do a deeper dive on, and this session has provided me the opportunity to get a little more familiar with it.</p>
<p>There is still time to register for the event, taking place at the <a href="http://bit.ly/90zUxE" target="_blank"><strong>Washington Marriott Wardman Park</strong></a>. Just <a href="http://bit.ly/9Ag4JJ" target="_blank">click here</a> to see the details and register. And if you&#8217;ll be there and want to connect, then just drop me a line/tweet/comment/email.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/ficam" rel="tag">FICAM</a>, <a href="http://blog.talkingidentity.com/tag/icam" rel="tag">ICAM</a>, <a href="http://blog.talkingidentity.com/tag/oracle-federal-forum" rel="tag">Oracle Federal Forum</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/10/speaking-at-oracle-federal-forum-on-oracle-idm-icam.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multi-Factor Authentication going Mainstream</title>
		<link>http://blog.talkingidentity.com/2010/09/multi-factor-authentication-going-mainstream.html</link>
		<comments>http://blog.talkingidentity.com/2010/09/multi-factor-authentication-going-mainstream.html#comments</comments>
		<pubDate>Tue, 28 Sep 2010 19:09:39 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Authentication Management]]></category>
		<category><![CDATA[Google Apps]]></category>
		<category><![CDATA[Multi-Factor Authentication]]></category>
		<category><![CDATA[One Time Password]]></category>
		<category><![CDATA[Oracle Adaptive Access Manager]]></category>
		<category><![CDATA[Strong Authentication]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1054</guid>
		<description><![CDATA[Some recent moves by major players could have a significant impact on the perception of multi-factor authentication technologies. Google recently introduced two-factor authentication for Google Apps. The mechanism they chose to employ relies on a one-time password token delivered to a cell phone either by an SMS text message or a call to the phone [...]]]></description>
			<content:encoded><![CDATA[<p>Some recent moves by major players could have a significant impact on the perception of multi-factor authentication technologies.</p>
<ul>
<li>Google recently introduced <a href="http://bit.ly/aBEGcC" target="_blank">two-factor authentication for Google Apps</a>. The mechanism they chose to employ relies on a one-time password token delivered to a cell phone either by an    SMS text message or a call to the phone (anyone that has signed up for Google Voice and tried to add a phone number will be familiar with the call-based mechanism). Google combines the OTP mechanism with device authentication (&#8220;trusted&#8221; devices like a desktop computer won&#8217;t require the second factor, while a work laptop that can get stolen, and therefore misused, will). So enterprise use of Google Apps just got a lot more secure.</li>
<li>Meanwhile, Windows Live has <a href="http://bit.ly/duSu5w" target="_self">introduced essentially the same mechanisms</a> in their account recovery process for Hotmail accounts.</li>
</ul>
<p>These recent developments provide very good proof-points for how multi-factor authentication can easily be incorporated into IdM programs in a user-friendly manner. As part of the Oracle Identity Management suite, <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-ada-access-mgr/index.html" target="_blank"><strong>Oracle Adaptive Access Manager</strong></a> provides enterprises the capability to roll out the same features (among many others) as part of their access management program, giving them the ability to leverage two-factor authentication in a simple form factor.</p>
<div id="attachment_1059" class="wp-caption aligncenter" style="width: 560px"><img class="size-full wp-image-1059" title="OAAM_Features" src="http://blog.talkingidentity.com/wp-content/uploads/2010/09/OAAM_Features.jpg" alt="OAAM Support for Multi-Factor Authentication" width="550" height="432" /><p class="wp-caption-text">OAAM Support for Multi-Factor Authentication</p></div>
<p>In fact, the ability to step up authentication using different channels as part of a risk-based identity management program that takes device identities into account was a major component of a demo we did last week at OpenWorld. The demo, in IdM VP Amit Jasuja&#8217;s session on &#8220;Oracle IdM 11g Review &amp; Future Directions&#8221;, highlighted the potential for identity to power the next-generation mobile workplace. The basic idea was that any time a transaction is identified as being high risk (a user modifying core privileges of a role, doing an in-application privilege elevation request, or accessing the application from a previously unused computer), the access management system can force the user to re-authenticate to the system using a mechanism that is distinct from what they used initially (like logging in using SSO).</p>
<p>The key differentiator here is &#8220;<em>risk-based</em>&#8220;. While OAAM can provide enterprises a cost-effective alternative to hardware token based MFA, it doesn&#8217;t stop there. It also allows enterprises to bring in advanced real-time risk analytics, proactive actions, investigation  tools and robust customizable reporting. The result is a comprehensive tool for managing security and risk as part of your enterprise&#8217;s overall identity management and governance programs.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/authentication-management" rel="tag">Authentication Management</a>, <a href="http://blog.talkingidentity.com/tag/google-apps" rel="tag">Google Apps</a>, <a href="http://blog.talkingidentity.com/tag/multi-factor-authentication" rel="tag">Multi-Factor Authentication</a>, <a href="http://blog.talkingidentity.com/tag/one-time-password" rel="tag">One Time Password</a>, <a href="http://blog.talkingidentity.com/tag/oracle-adaptive-access-manager" rel="tag">Oracle Adaptive Access Manager</a>, <a href="http://blog.talkingidentity.com/tag/strong-authentication" rel="tag">Strong Authentication</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/09/multi-factor-authentication-going-mainstream.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Building a Strong Foundation for Your Cloud with Identity Management</title>
		<link>http://blog.talkingidentity.com/2010/09/building-a-strong-foundation-for-your-cloud-with-identity-management.html</link>
		<comments>http://blog.talkingidentity.com/2010/09/building-a-strong-foundation-for-your-cloud-with-identity-management.html#comments</comments>
		<pubDate>Mon, 27 Sep 2010 06:01:44 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[The Cloud Identity Series]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Identity Model]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[OOW10]]></category>
		<category><![CDATA[OpenWorld]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1045</guid>
		<description><![CDATA[That was the topic of my talk at OpenWorld this year. Fitting, I think, considering the emphasis that was put on Cloud Computing at OOW this year, starting with Larry&#8217;s opening keynote on Sunday. In my session, I talked about how, thanks in large part to the emergence of cloud computing, enterprises are moving towards [...]]]></description>
			<content:encoded><![CDATA[<p>That was the topic of my talk at OpenWorld this year. Fitting, I think, considering the emphasis that was put on Cloud Computing at OOW this year, starting with Larry&#8217;s opening keynote on Sunday.</p>
<p>In my session, I talked about how, thanks in large part to the emergence of cloud computing, enterprises are moving towards a borderless IT infrastructure that is going to change how security is done. The traditional mechanisms of security that are built on topology are going to have to be replaced by a security architecture built on the constant that can actually flow across domain boundaries &#8211; identity.</p>
<p>Yoda himself made an appearance to make the point.</p>
<p><img class="alignnone" title="Yoda on Identity-based Cloud Security" src="http://farm5.static.flickr.com/4126/5015994636_a2dd944377.jpg" alt="" width="500" height="375" /></p>
<p>My presentation was divided into a few parts:</p>
<ul>
<li>I revisited the issue of security in cloud computing, in particular highlighting specific areas that need to be addressed.</li>
<li>I talked about the foundational elements to building an identity-based security model for your cloud environment, and how to evolve that into a full-fledged platform for your cloud applications.</li>
<li>I also talked about the products and capabilities available in the Oracle Identity Management 11g suite, and some of our future plans aimed at specifically addressing the cloud.</li>
</ul>
<p>You can check out the presentation below (I hope to add the session audio to it at some point).</p>
<div id="__ss_5294105" style="width: 550px;"><object id="__sse5294105" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="550" height="460" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s317276-foundationforcloudusingidm-100926233432-phpapp01&amp;rel=0&amp;stripped_title=s317276-foundation-for-cloud-using-id-m&amp;userName=NishantKaushik" /><param name="name" value="__sse5294105" /><param name="allowfullscreen" value="true" /><embed id="__sse5294105" type="application/x-shockwave-flash" width="550" height="460" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=s317276-foundationforcloudusingidm-100926233432-phpapp01&amp;rel=0&amp;stripped_title=s317276-foundation-for-cloud-using-id-m&amp;userName=NishantKaushik" name="__sse5294105" allowscriptaccess="always" allowfullscreen="true"></embed></object></div>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/cloud-identity-model" rel="tag">Cloud Identity Model</a>, <a href="http://blog.talkingidentity.com/tag/cloud-security" rel="tag">Cloud Security</a>, <a href="http://blog.talkingidentity.com/tag/oow10" rel="tag">OOW10</a>, <a href="http://blog.talkingidentity.com/tag/openworld" rel="tag">OpenWorld</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/09/building-a-strong-foundation-for-your-cloud-with-identity-management.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Introducing Oracle Security Governor for Healthcare</title>
		<link>http://blog.talkingidentity.com/2010/09/introducing-oracle-security-governor-for-healthcare.html</link>
		<comments>http://blog.talkingidentity.com/2010/09/introducing-oracle-security-governor-for-healthcare.html#comments</comments>
		<pubDate>Tue, 21 Sep 2010 18:57:44 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Healthcare IT]]></category>
		<category><![CDATA[Healthcare Security]]></category>
		<category><![CDATA[Identity Analytics]]></category>
		<category><![CDATA[Identity Governance]]></category>
		<category><![CDATA[OOW10]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>
		<category><![CDATA[Oracle Security Governor]]></category>
		<category><![CDATA[Oracle Security Governor for Healthcare]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1029</guid>
		<description><![CDATA[At OpenWorld today, Oracle announced the release of Oracle Security Governor for Healthcare, a unique and comprehensive security governance solution that helps healthcare organizations with proactive detection and prevention of security and privacy breaches (click here for the press release). Oracle Security Governor becomes the second product we have in the identity governance space, taking [...]]]></description>
			<content:encoded><![CDATA[<p>At OpenWorld today, Oracle announced the release of <strong>Oracle Security Governor for Healthcare</strong>, a unique and comprehensive security governance solution that helps healthcare organizations with proactive detection and prevention of security and privacy <img class="alignright size-full wp-image-1036" title="OSGfH Icon" src="http://blog.talkingidentity.com/wp-content/uploads/2010/09/OSGfH-Icon.jpg" alt="OSGfH Icon" width="200" height="222" />breaches (<a href="http://bit.ly/cmF6Iu" target="_blank">click here</a> for the press release). Oracle Security Governor becomes the second product we have in the identity governance space, taking its place alongside <strong>Oracle Identity Analytics</strong> in the Oracle IAM Suite.</p>
<p>Oracle Security Governor for Healthcare is a governance solution that is aimed specifically at healthcare organizations, where the introductions of various regulations globally and the transformation of healthcare IT has created a number of challenges in the area of patient confidentiality that need to be addressed.</p>
<ul>
<li>VIP record snooping</li>
<li>Medical identity theft and fraud</li>
<li>Healthcare data theft and fraud</li>
<li>Coworker, family member and neighbor record snooping</li>
</ul>
<p><strong>Oracle Security Governor for Healthcare</strong> addresses these concerns by providing a solution that helps proactively protect and prevent privacy and security breaches, insider snooping and medical identity theft in an organization. The solution is based on some key features:</p>
<ul>
<li><em>Rapid Incident Detection</em>: Criteria based automated reporting functionality that allows rapid incident detection, case management and investigations.</li>
<li><em>Automated Privacy Audits</em>: Allows audits on activities of various entities accessing the applications and reports suspicious activities.</li>
<li><em>Accelerated Enterprise-wide Data Retrieval</em>: Allows rapid integration with existing systems.</li>
</ul>
<h3>Architecture</h3>
<p>Oracle Security Governor is built on some key products in Oracle&#8217;s portfolio, enhanced with some healthcare specific intelligence and artifacts.</p>
<div id="attachment_1031" class="wp-caption alignnone" style="width: 560px"><img class="size-full wp-image-1031" title="Oracle Security Governor for Healthcare Architecture" src="http://blog.talkingidentity.com/wp-content/uploads/2010/09/OSGfH-Architecture.jpg" alt="Oracle Security Governor for Healthcare Architecture" width="550" height="332" /><p class="wp-caption-text">Oracle Security Governor for Healthcare Architecture</p></div>
<ul>
<li>Oracle Security Governor for Healthcare leverages the <strong><a href="http://www.oracle.com/us/technologies/soa/soa-suite-066466.html" target="_blank">Oracle SOA Suite</a> Adapters</strong> (like Database, Log and HL7 adapters) to pull data in from virtually any data source into a central data warehouse.</li>
<li>In-database data mining and predictive analytics built using <a href="http://www.oracle.com/technetwork/database/options/odm/index.html" target="_blank"><strong>Oracle Data Mining</strong></a> is used to detect anomalies and suspicious activity that may have taken place in the past.</li>
<li>The solution also uses an advanced risk assessment engine (based on <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-ada-access-mgr/index.html" target="_blank"><strong>Oracle Adaptive Access Manager</strong></a>), which has been pre-loaded with healthcare specific risk and fraud rules to proactively detect incidents.</li>
<li><a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-entitlements-server/index.html" target="_blank"><strong>Oracle Entitlement Server</strong></a> provides unique risk-aware fine grained authorization on record and data access, cutting down the possibility of unauthorized activity and fraud.</li>
<li>Finally, <a href="http://www.oracle.com/technetwork/middleware/bi-publisher/overview/index.html" target="_blank"><strong>Oracle Business Intelligence Publisher</strong></a> is used to provide insight into all of this through risk analytics, reports and alerts.</li>
</ul>
<h3>Benefits</h3>
<p>Oracle Security Governor helps deliver significant benefits to a healthcare organization. Some of these benefits include:</p>
<ul>
<li><em>Historical Detection</em>: that can be used as audit trails and for detection of suspicious activities related to access, privacy, fraud and security breaches, that have taken place in the past.</li>
<li><em>Real Time Detection</em>: Oracle Security Governor can also be used to detect suspicious and fraudulent activity, in the real time.</li>
<li><em>Real Time Prevention</em>: Oracle Security Governor can prevent suspicious activities, in the real time. The activities detected as anomalous or suspicious can either be completely blocked or the end-user can be alerted or required to meet additional security requirements, depending on the deployment needs.</li>
</ul>
<div id="attachment_1032" class="wp-caption alignnone" style="width: 560px"><img class="size-full wp-image-1032" title="OSGfH Benefits" src="http://blog.talkingidentity.com/wp-content/uploads/2010/09/OSGfH-Benefits.jpg" alt="Oracle Security Governor for Healthcare Benefits" width="550" height="268" /><p class="wp-caption-text">Oracle Security Governor for Healthcare Benefits</p></div>
<h3>Looking Ahead</h3>
<p>Oracle Security Governor for Healthcare is just the beginning. In the future, Oracle hopes to use the Oracle Security Governor framework to build more solutions that address challenges faced in other verticals besides healthcare. But that doesn&#8217;t mean you have to wait &#8211; you can leverage the products mentioned above to build your own security and privacy solutions. Just ask us how.</p>
<p>You can find more information about Oracle Security Governor for Healthcare <a href="http://bit.ly/aGQs1o" target="_blank">here on the product page</a>.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/healthcare-it" rel="tag">Healthcare IT</a>, <a href="http://blog.talkingidentity.com/tag/healthcare-security" rel="tag">Healthcare Security</a>, <a href="http://blog.talkingidentity.com/tag/identity-analytics" rel="tag">Identity Analytics</a>, <a href="http://blog.talkingidentity.com/tag/identity-governance" rel="tag">Identity Governance</a>, <a href="http://blog.talkingidentity.com/tag/oow10" rel="tag">OOW10</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a>, <a href="http://blog.talkingidentity.com/tag/oracle-security-governor" rel="tag">Oracle Security Governor</a>, <a href="http://blog.talkingidentity.com/tag/oracle-security-governor-for-healthcare" rel="tag">Oracle Security Governor for Healthcare</a>, <a href="http://blog.talkingidentity.com/tag/privacy" rel="tag">Privacy</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/09/introducing-oracle-security-governor-for-healthcare.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

