<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity ! Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Burton Catalyst Conference</title>
	<atom:link href="http://blog.talkingidentity.com/tag/burton-catalyst-conference/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Sat, 06 Mar 2010 03:32:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Burton Catalyst 2009: There are Lessons to Learn</title>
		<link>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-there-are-lessons-to-learn.html</link>
		<comments>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-there-are-lessons-to-learn.html#comments</comments>
		<pubDate>Tue, 11 Aug 2009 20:09:04 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Breach Remediation]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Catalyst09]]></category>
		<category><![CDATA[Identity Governance]]></category>
		<category><![CDATA[Ladder Framework for Privacy]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Audits]]></category>
		<category><![CDATA[Virtual Directory]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=613</guid>
		<description><![CDATA[After a good start to the conference, I went into day 2 thinking that there was going to be more opportunity for me to blog while in the session room because the content would be fairly familiar. But there were lots of good nuggets of information spread throughout the talks, enough to generate a generous [...]]]></description>
			<content:encoded><![CDATA[<p>After <a href="http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-waiting-for-the-world-to-change.html">a good start to the conference</a>, I went into day 2 thinking that there was going to be more opportunity for me to blog while in the session room because the content would be fairly familiar. But there were lots of good nuggets of information spread throughout the talks, enough to generate <a href="http://blog.talkingidentity.com/downloads/my-catalyst-2009-tweet-stream">a generous tweet stream</a> for the day.</p>
<h3>Day 2: Lets get back to basics</h3>
<p>The first half of Thursday was focused on enterprises looking for ways to <em>achieve efficiencies and ROI</em> through their IdM deployments, an outcome that had lost its relevance in the rush to achieve compliance objectives. But the current economic climate, and the slew of M&amp;As (mainly As) and layoffs has brought this to the forefront once again, and sustained market interest in IAM when other initiatives are being pared back.</p>
<p>The day was a very good one for hearing about how customers were leveraging their IdM deployments in creative ways.</p>
<ul>
<li>I heard some interesting use cases of how Virtual Directory was being used to achieve efficiencies.
<ul>
<li>Companies are using Virtual Directory to expose the same identity data in different forms for different use cases.</li>
<li>The presenter from Sony talked about using Virtual Directory on top of geographically local LDAP servers to provide global access to data while satisfying their data compliance needs.</li>
</ul>
</li>
<li>There were a couple of sessions on managing UNIX infrastructure via AD (which is when I ducked into the cloud computing track).</li>
<li>Wendy Booker of SunTrust Banks described how they used the cost savings (which they had to demonstrate and prove) from their IdM deployment to self-fund their project, which was a story I am sure more than a few attendees were interested in.</li>
</ul>
<p>What I found really great was that a lot of the sessions were presented by organizations that had moved on to the 2nd or 3rd phases of their identity management program rollouts. This is quite different from all the previous conferences (Catalyst and others) I have been to, and speaks to the maturity of the market and some of these deployments.</p>
<p>The second half of the day was focused on <em>identity transparency and governance</em>. One of the most important points of the conference was made by Chris Howarth in his excellent kickoff talk, when he said that <em>identity management must facilitate both hierarchical organizations that are necessary to implement enterprise controls, and social networks that are necessary for collaboration to take place</em>. A lot of the discussion in the following talks were focused on the need to increase transparency with respect to how identity data is used, managed and secured to allow for accurate risk assessment and compliance to take place (echoing what was discussed in the cloud computing SIG). And increased transparency only works when complexity is reduced (preventing opacity from just being replaced by obscurity), an architectural requirement that aligns nicely with the identity services vision discussed on day 2.</p>
<p>Day 2 ended with the second night of hospitality suites, including Oracle. We got such a crowd in the Oracle suite that I barely managed to leave it for a few minutes to meet up with some old friends and colleagues in the other suites. And I made some good friends that day (and into the night &#8211; not a topic for this blog). I will say that celebrating <a href="http://www.tuesdaynight.org/" target="_blank">Ian Glazer</a>&#8217;s birthday at a speakeasy called Prohibition was very cool, even if they didn&#8217;t ask me for the password.</p>
<h3>Day 3: Identity and Privacy are Blood Brothers</h3>
<p>Day 3, while just a half day, still packed a solid punch with lots of intellectually stimulating discussion on the topic of privacy. Ian Glazer made a good point at the start of the conference when he said that the identity community is uniquely qualified to deal with the emerging privacy issues. And the sessions on Friday laid out exactly why. The key point made was that <strong>Security</strong> (making it difficult to get to something you shouldn&#8217;t have access to) should not be confused with <strong>Privacy</strong> (making it easy to get to something you should have access to). They are related, but not the same thing.</p>
<p><a href="http://futureidentity.blogspot.com/" target="_blank">Robin Wilton</a> gave an inspiring talk in which he laid out a framework for having productive privacy discussions with the multiple stake-holders involved. He arrived at this framework by analyzing the results of a series of round table discussions held around the globe as part of the Liberty Alliance Privacy Summit to get contextual understanding of privacy. Robin laid out a &#8220;Ladder&#8221; framework <strong>(Philosophy | Strategy | Implementation | Technology)</strong> that helps the parties involved focus on the use cases and issues to resolve. I hope he makes his presentation publicly available in some format in the future, because really is a great piece of work.</p>
<p>Bob Mocny, Director of the <a href="http://www.dhs.gov/files/programs/content_multi_image_0006.shtm" target="_blank">US-VISIT program</a>, talked about some of the identity and privacy issues involved in running the single largest biometric authentication program in the world. One of the key takeaways from his and the follow-up sessions was the need for organizations to implement privacy audits as separate programs from their IT-Security audits.</p>
<p>Heidi Wachs, Directory of IT Policy and Privacy Officer at Georgetown Univ, gave an interesting talk about the lessons learned during <a href="http://www.educause.edu/EDUCAUSE+Review/EDUCAUSEReviewMagazineVolume43/OutoftheBreachandintotheFire/163171" target="_blank">Georgetown&#8217;s efforts to  handle a privacy breach</a>. What I found fascinating was how they went about trying to create and enforce a policy on the use, collection and retention of SSNs. Their findings on how far the data was &#8220;leaking&#8221;, how hard it was to track down all the possible data flows, and how users went to great lengths to hide their mistakes were a lesson that every enterprise should be aware of. It also highlighted the challenges the extended enterprise, working with business and IT partners and services providers, faces in locking down privacy issues.</p>
<p>The day ended with Google talking about how they protect the privacy of their users. It may have only been a half-day, but the quality of content made it a fitting way to end a thought provoking conference. Look forward to what the next one has to bring.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/breach-remediation" rel="tag">Breach Remediation</a>, <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/catalyst09" rel="tag">Catalyst09</a>, <a href="http://blog.talkingidentity.com/tag/identity-governance" rel="tag">Identity Governance</a>, <a href="http://blog.talkingidentity.com/tag/ladder-framework-for-privacy" rel="tag">Ladder Framework for Privacy</a>, <a href="http://blog.talkingidentity.com/tag/privacy" rel="tag">Privacy</a>, <a href="http://blog.talkingidentity.com/tag/privacy-audits" rel="tag">Privacy Audits</a>, <a href="http://blog.talkingidentity.com/tag/virtual-directory" rel="tag">Virtual Directory</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn%26amp%3Bbodytext%3DAfter%2520a%2520good%2520start%2520to%2520the%2520conference%252C%2520I%2520went%2520into%2520day%25202%2520thinking%2520that%2520there%2520was%2520going%2520to%2520be%2520more%2520opportunity%2520for%2520me%2520to%2520blog%2520while%2520in%2520the%2520session%2520room%2520because%2520the%2520content%2520would%2520be%2520fairly%2520familiar.%2520But%2520there%2520were%2520lots%2520of%2520good%2520nuggets%2520of%2520information%2520spr';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%26amp%3Bt%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn%26amp%3Bannotation%3DAfter%2520a%2520good%2520start%2520to%2520the%2520conference%252C%2520I%2520went%2520into%2520day%25202%2520thinking%2520that%2520there%2520was%2520going%2520to%2520be%2520more%2520opportunity%2520for%2520me%2520to%2520blog%2520while%2520in%2520the%2520session%2520room%2520because%2520the%2520content%2520would%2520be%2520fairly%2520familiar.%2520But%2520there%2520were%2520lots%2520of%2520good%2520nuggets%2520of%2520information%2520spr';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn%26amp%3Bnotes%3DAfter%2520a%2520good%2520start%2520to%2520the%2520conference%252C%2520I%2520went%2520into%2520day%25202%2520thinking%2520that%2520there%2520was%2520going%2520to%2520be%2520more%2520opportunity%2520for%2520me%2520to%2520blog%2520while%2520in%2520the%2520session%2520room%2520because%2520the%2520content%2520would%2520be%2520fairly%2520familiar.%2520But%2520there%2520were%2520lots%2520of%2520good%2520nuggets%2520of%2520information%2520spr';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%26amp%3Bh%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html%2520Burton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DBurton%2520Catalyst%25202009%253A%2520There%2520are%2520Lessons%2520to%2520Learn%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-there-are-lessons-to-learn.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-there-are-lessons-to-learn.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Burton Catalyst 2009: Waiting for the World to Change</title>
		<link>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-waiting-for-the-world-to-change.html</link>
		<comments>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-waiting-for-the-world-to-change.html#comments</comments>
		<pubDate>Mon, 10 Aug 2009 20:52:56 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Catalyst09]]></category>
		<category><![CDATA[Entitlement Management]]></category>
		<category><![CDATA[Role Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=606</guid>
		<description><![CDATA[In my last post, I talked about the SIG meetings that I attended prior to the conference actually starting. There was lots of good content and discussion, which continued on into the actual sessions. I had thought of splitting my time between the Identity and Cloud Computing (new to Catalyst this year) tracks. But the [...]]]></description>
			<content:encoded><![CDATA[<p>In <a href="http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-the-twisted-web-we-weave.html">my last post</a>, I talked about the SIG meetings that I attended prior to the conference actually starting. There was lots of good content and discussion, which continued on into the actual sessions. I had thought of splitting my time between the Identity and Cloud Computing (new to Catalyst this year) tracks. But the content in the IdPS track was compelling enough that I found myself only able to attend a couple of CC sessions.</p>
<h3>Day 1: A focus on IdM evolution</h3>
<p>I don&#8217;t know if this was par for the whole conference, but at least in the IdPS track, each half day was devoted to a particular theme. The first half of day 1 was a landscape update as usual, and focused on some of the interesting developments in the space, like Oracle&#8217;s pending acquisition of Sun (that&#8217;s all I&#8217;m going to say on that topic), the <a href="http://blog.ianyip.com/2009/01/identity-and-data-security-go-hand-in.html" target="_blank">integration of DLP (data leakage prevention) with IdM</a> programs, and the emergence of some commercial Identity Oracles.</p>
<p>I especially liked Bob Blakley&#8217;s discussion on <strong>Identity Services</strong>, since it resonated with a lot of what I have been <a href="http://blog.talkingidentity.com/tag/identity-services">talking about on this blog</a> and the work I have been doing at Oracle. In his talk on the subject, Bob pointed out that cloud-based identity services will challenge the fundamental architectural notions of IdM infrastructure. The large blocks of IdM functionality that we are used to &#8211; access management, provisioning etc &#8211; will get broken down into smaller, modular pieces &#8211; like identity proofing, enrollment, identity risk assessment, breach remediation &#8211; that can interplay within enterprise environments as required. This is pushing the market towards smaller, specialist vendors that handle specific services rather than the large IdP that is a one stop shop for all identity needs. And these services have to work in concert with each other to provide the enterprise the value they are looking for. The vendors that have emerged in this space are delivering their services via various deployment models &#8211; ranging from on-premise SaaS to cloud-based services &#8211; but mostly stick with the per-user/per-transaction billing model. And all of them are going to get a big push when some of the cloud security issues currently holding enterprises back get resolved.</p>
<p>The second half of the day focused on a big part of IdM&#8217;s evolution &#8211; the <strong>mainstreaming of role management</strong> and the ascending discussion on the <strong>nature of Entitlement Management</strong>. Role Management is now widely accepted as an important part of any comprehensive identity management practice, and Kevin Kampman&#8217;s talk on the subject highlighted the importance of positioning it as a business problem instead of a technical problem. In discussing the results of a survey Burton conducted with customers that did role management projects, Kevin laid out the premise that the tools are actually secondary when it comes to implementing role management. First and foremost is the need for customers to understand the business processes that impact the design and use of roles, and document the same so that a practice could be built around them.</p>
<p>And as role management has taken hold in the conscious of IdM practitioners everywhere, <a href="http://blog.talkingidentity.com/2009/05/entitlement-management-more-than-meets-the-eye.html">entitlement management</a> is rearing its head as a disruptive topic. In what was a theme for the conference, Burton laid out a terminology issue that exists around the term &#8220;entitlement management&#8221;, which is often used to describe tools that deal with runtime evaluation of fine-grained authorization decisions (like what Oracle Entitlement Server does), and neglects the lifecycle management practice around entitlements and their assignments. As customers dig deeper into their role management projects, they are finding that what they really want to do is entitlement management. And the tools to help with the lifecycle side of this equation are just not there.</p>
<p>The day finished at the hospitality suites, where a lot of the evolution being discussed here was on display. There was also a very successful <a href="http://identityblog.burtongroup.com/bgidps/2009/07/cloud-sso-interop-demonstration.html">interoperability event demonstrating SSO for cloud-based applications</a>, a first step towards management of the extended cloud-based enterprise by enterprise IdM deployments. All in all, day 1 was quite satisfying. But the best was yet to come.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/catalyst09" rel="tag">Catalyst09</a>, <a href="http://blog.talkingidentity.com/tag/entitlement-management" rel="tag">Entitlement Management</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/role-management" rel="tag">Role Management</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change%26amp%3Bbodytext%3DIn%2520my%2520last%2520post%252C%2520I%2520talked%2520about%2520the%2520SIG%2520meetings%2520that%2520I%2520attended%2520prior%2520to%2520the%2520conference%2520actually%2520starting.%2520There%2520was%2520lots%2520of%2520good%2520content%2520and%2520discussion%252C%2520which%2520continued%2520on%2520into%2520the%2520actual%2520sessions.%2520I%2520had%2520thought%2520of%2520splitting%2520my%2520time%2520between%2520the%2520Ide';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%26amp%3Bt%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change%26amp%3Bannotation%3DIn%2520my%2520last%2520post%252C%2520I%2520talked%2520about%2520the%2520SIG%2520meetings%2520that%2520I%2520attended%2520prior%2520to%2520the%2520conference%2520actually%2520starting.%2520There%2520was%2520lots%2520of%2520good%2520content%2520and%2520discussion%252C%2520which%2520continued%2520on%2520into%2520the%2520actual%2520sessions.%2520I%2520had%2520thought%2520of%2520splitting%2520my%2520time%2520between%2520the%2520Ide';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change%26amp%3Bnotes%3DIn%2520my%2520last%2520post%252C%2520I%2520talked%2520about%2520the%2520SIG%2520meetings%2520that%2520I%2520attended%2520prior%2520to%2520the%2520conference%2520actually%2520starting.%2520There%2520was%2520lots%2520of%2520good%2520content%2520and%2520discussion%252C%2520which%2520continued%2520on%2520into%2520the%2520actual%2520sessions.%2520I%2520had%2520thought%2520of%2520splitting%2520my%2520time%2520between%2520the%2520Ide';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%26amp%3Bh%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html%2520Burton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DBurton%2520Catalyst%25202009%253A%2520Waiting%2520for%2520the%2520World%2520to%2520Change%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-waiting-for-the-world-to-change.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-waiting-for-the-world-to-change.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Burton Catalyst 2009: The Twisted Web We Weave</title>
		<link>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-the-twisted-web-we-weave.html</link>
		<comments>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-the-twisted-web-we-weave.html#comments</comments>
		<pubDate>Wed, 05 Aug 2009 20:02:09 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Authorization]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Catalyst09]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[eBay]]></category>
		<category><![CDATA[Kantara Initiative]]></category>
		<category><![CDATA[Oracle_IDM]]></category>
		<category><![CDATA[Project Concordia]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=581</guid>
		<description><![CDATA[I&#8217;m finally settling back into work after a wonderful week out in sunny San Diego at Burton Group&#8217;s annual Catalyst Conference. And it wasn&#8217;t just the weather outside that was wonderful. Inside you could find some thought-provoking sessions, inspiring discussions and great people. It&#8217;s given me way too much to blog about, and I hope [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m finally settling back into work after a wonderful week out in sunny San Diego at <strong>Burton Group</strong>&#8217;s annual <strong>Catalyst Conference</strong>. And it wasn&#8217;t just the weather outside that was wonderful. Inside you could find some thought-provoking sessions, inspiring discussions and great people. It&#8217;s given me way too much to blog about, and I hope to be able to put some of it out here. But if you are interested, I have captured <a href="http://blog.talkingidentity.com/downloads/my-catalyst-2009-tweet-stream">my tweet stream from the conference</a> (since Twitter search only goes back a few days), though it can be rough reading. But as Dave Kearns <a href="http://vquill.com/2009/07/dearth-of-blogging.html" target="_blank">tried to remind us tweeters</a>, we shouldn&#8217;t forget the value of a well written blog post (or two).</p>
<h3>The SIG Meetings</h3>
<p>For me, the conference was divided into two parts. Monday and Tuesday I attended a few SIG meetings on topics that were varied yet highly interconnected. Monday was a meeting of the Concordia Workshop, which is now a <a href="http://kantarainitiative.org/confluence/display/concordia/Home" target="_blank">discussion group</a> under the new Kantara Initiative. The focus of the meeting was <em><strong>Use Cases driving Identity in Enterprise 2.0: The Consumerization of IT</strong></em>. The ever intrepid Eve Maler has <a href="http://projectconcordia.org/index.php/Catalyst_pre-conference_workshop_agenda#Agenda" target="_blank">posted materials from the day</a> to the Concordia site, so you can check them out yourself. While the individual discussions covered all manner of areas, the connecting thread throughout was <strong>Authorization</strong>. There was a morning discussion where a panel talked about the progress made in the authorization space, from the <a href="http://lists.oasis-open.org/archives/xacml/200907/msg00019.html" target="_blank">XACML API contributed to the TC</a> by Oracle and Cisco, to the emergence of AuthZ as the critical service in the identity services reference architecture being developed in the Burton Group ISWG (which I have been participating in and writing about). <a href="http://twitter.com/MikeG514" target="_blank">Mike Gotta</a> and Alice Wang gave an excellent talk on the emerging concerns regarding social tools in the enterprise, and a lot of those concerns again boil down to authorization issues, in this case regarding data and information. Eve talked about <a href="http://www.xmlgrrl.com/blog/categories/protectserve/" target="_blank">her work on the ProtectServe protocol</a> that enables authorized data sharing from a user perspective. And the day finished with a talk on Levels of Assurance, a critical piece in allowing for partners to make informed authorization decisions.</p>
<p>Tuesday started with a meeting on <em><strong>Cloud Computing Security and Identity Management</strong></em>. As readers of my blog/twitter know, I have been saying for a while that cloud computing is going to have a major impact on the identity management business, in much the same way that compliance concerns did a few years ago. It is probably a sign of the immaturity of the market that the discussion was focused on describing the challenges to be solved rather than any solutions.</p>
<p>The meeting included a deep dive presentation by Liam Lynch, Ebay&#8217;s Chief Security Strategist, on how the auction giant tackles their internal cloud computing needs. There were a few points made during his presentation that I found interesting:</p>
<ul>
<li>eBay is into cloud computing as a provider, not a consumer, since they allow 3rd party developers to create their own auction sites on eBay infrastructure using a development kit called eBox</li>
<li>As such, eBay feels that security considerations have to be made inherent in cloud architecture as they cannot rely on these 3rd party developers to not make mistakes</li>
<li>eBay uses contextual behavior and reputation, including biometric analysis, as the underpinnings of its identity management strategy. Reputation and behavior analysis generate (over time) dynamic identity claims that then get used in access control decisions</li>
<li>eBay found RBAC to be a bad match for their performance requirements, and shifted to a claims-based model for authorization. In this model, claims are attached to the data object being accessed itself (sort of a next-generation ACL). The access then compares the claims the actor has at runtime with these to make an authorization decision.</li>
<li>Liam made the point that managing access through roles was a bad model for them, which is why they went claims-based. I understand the performance concerns that arise when evaluating RBAC at runtime, but for managing the grants of access, nothing beats a role-based model. So I was a little surprised by his statement. When I dug deeper, it turned out that they simply replaced RBAC with Organization-based AC, and not because of performance reasons but because of compliance reasons since the org change has approval attached while the role change did not. So it wasn&#8217;t really an issue with RBAC, just the implementation they had in-house.</li>
<li>Liam pointed out that a move to the cloud can be an opportunity to fix broken internal processes, since the cloud will amplify any issues you may have</li>
</ul>
<p>The meeting also had Nils Puhlmann, co-founder of the <a href="http://www.cloudsecurityalliance.org/" target="_blank"><strong>Cloud Security Alliance</strong></a>, speaking to the participants on the need to come up with a practical security checklist that all Cloud Service Providers could be measured against, so that enterprise customers can make accurate assessments of the risk with using a particular CSP. He called for greater vendor involvement and focus on the cloud, since the cost dynamics of the cloud make adoption inevitable. And that CSPs need to be more transparent about their security controls and policies.</p>
<p>Later that afternoon I attended the next meeting of the <em><strong>Identity Services Working Group</strong></em> that I&#8217;ve been participating in. There were a lot of new folks in the audience, so it was a good opportunity to recruit new blood into the effort. As Kevin Kampman presented the work that had been done previously on the Authentication service and laid out the effort lying ahead on the Authorization service, we got into highly spirited, and productive, discussions on the nature of the services architecture. One of the points made repeatedly (and which was echoed later in the week during the sessions) was the terminology issue that plagues the identity community, in this case around words like Policy (vs. policy). There was a strong sentiment from the group that policy management needs to be made part of the overall framework for it to work properly. And there was also a strong push from the group to try and condense the best of the prior efforts at defining AuthZ services into our vision.</p>
<p>While on the surface all of these SIGs were on different topics, I found them to be highly intertwined. Identity concerns in cloud computing are tied in directly to the need for an identity services architecture that allows cloud services to leverage enterprise identity (and therefore security) apparatus, thus reducing risk for the enterprise and providing compliance with both internal and regulatory controls. And Enteprise 2.0 is mostly about the intrusion of  cloud-based services like social media into the enterprise environment (or the extrusion of the enterprise into commercialized IT services, depending on how you want to look at it), where concerns about consistency of identity and controls are foremost in the minds of CIOs and CISOs everywhere. So while the discussion is still somewhat fragmented (as it probably should be at this time), I look forward to all of this coming together nicely in the future (maybe even at a future Catalyst conference).</p>
<p>I think I need to do a better job breaking these posts into smaller, more readable chunks. My next post(s) will focus on the sessions themselves.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/authorization" rel="tag">Authorization</a>, <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/catalyst09" rel="tag">Catalyst09</a>, <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/ebay" rel="tag">eBay</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/kantara-initiative" rel="tag">Kantara Initiative</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a>, <a href="http://blog.talkingidentity.com/tag/project-concordia" rel="tag">Project Concordia</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave%26amp%3Bbodytext%3DI%2527m%2520finally%2520settling%2520back%2520into%2520work%2520after%2520a%2520wonderful%2520week%2520out%2520in%2520sunny%2520San%2520Diego%2520at%2520Burton%2520Group%2527s%2520annual%2520Catalyst%2520Conference.%2520And%2520it%2520wasn%2527t%2520just%2520the%2520weather%2520outside%2520that%2520was%2520wonderful.%2520Inside%2520you%2520could%2520find%2520some%2520thought-provoking%2520sessions%252C%2520inspirin';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%26amp%3Bt%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave%26amp%3Bannotation%3DI%2527m%2520finally%2520settling%2520back%2520into%2520work%2520after%2520a%2520wonderful%2520week%2520out%2520in%2520sunny%2520San%2520Diego%2520at%2520Burton%2520Group%2527s%2520annual%2520Catalyst%2520Conference.%2520And%2520it%2520wasn%2527t%2520just%2520the%2520weather%2520outside%2520that%2520was%2520wonderful.%2520Inside%2520you%2520could%2520find%2520some%2520thought-provoking%2520sessions%252C%2520inspirin';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave%26amp%3Bnotes%3DI%2527m%2520finally%2520settling%2520back%2520into%2520work%2520after%2520a%2520wonderful%2520week%2520out%2520in%2520sunny%2520San%2520Diego%2520at%2520Burton%2520Group%2527s%2520annual%2520Catalyst%2520Conference.%2520And%2520it%2520wasn%2527t%2520just%2520the%2520weather%2520outside%2520that%2520was%2520wonderful.%2520Inside%2520you%2520could%2520find%2520some%2520thought-provoking%2520sessions%252C%2520inspirin';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%26amp%3Btitle%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%26amp%3Bh%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html%2520Burton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DBurton%2520Catalyst%25202009%253A%2520The%2520Twisted%2520Web%2520We%2520Weave%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F08%252Fburton-catalyst-2009-the-twisted-web-we-weave.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/08/burton-catalyst-2009-the-twisted-web-we-weave.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Change We Need</title>
		<link>http://blog.talkingidentity.com/2008/12/change-we-need.html</link>
		<comments>http://blog.talkingidentity.com/2008/12/change-we-need.html#comments</comments>
		<pubDate>Tue, 02 Dec 2008 03:56:22 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[BurtonGroupCatalyst08]]></category>
		<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[ISWG]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=136</guid>
		<description><![CDATA[It&#8217;s been a long time since I have been able to post. A lot conspired to make it difficult for me to keep up with my blogging, not the least of which has been a number of interesting, but under wrap, developments within the IdM group at Oracle (if you follow me on Twitter, you [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a long time since I have been able to post. A lot conspired to make it difficult for me to keep up with my blogging, not the least of which has been a number of interesting, but under wrap, developments within the IdM group at Oracle (if you <a href="http://twitter.com/NishantK">follow me</a> on Twitter, you may know what I am talking about). I‘ve been knee-deep in meetings planning our development projects for next year, so stay tuned to this space for a look ahead.<br />
My last post was just before I headed to Prague to participate in a panel on <strong>Identity Services</strong> at Burton’s <strong>Catalyst Europe</strong> conference. I could make some jokes about how it has taken me this long to recover from the craziness in Prague, and it would be partly true. But I wouldn’t even begin to know how to describe all of it, so this is me moving swiftly on.<br />
<img src="http://farm4.static.flickr.com/3166/2966670311_0e072ee77a.jpg" alt="" /><br />
During the panel discussion (thanks to Oracle’s own Dennis MacNeil for taking the photograph above), we talked about the work we’ve been doing in Burton’s Identity Services Working Group (ISWG). Kevin preceded the panel with a presentation outlining the results of the first phase of our work, which has focused on the basic services in an identity services architecture – <em>attributes</em>, <em>authentication</em> and <em>authorization</em>.  I can’t really share the results of the work here, because of the rules we work under as part of the working group (I’ll try and talk Kevin into letting me share some of it). However, I will say that one of the interesting developments from the many meetings we had, and which informed the approach taken in this phase of the project, was the group adopting the thought that “<strong>Authentication is simply an Obligation in an Authorization process</strong>” (think about it). As a result, we have come up with an interesting take on the role of <em>PEPs</em>, <em>PDPs</em> and <em>Claims</em> in the architecture.<br />
The bulk of the panel discussion focused on explaining the drivers for the work being done in the ISWG. The fact that all the folks on the panel were either vendors or financial industry folks meant that the talk was about creating efficiencies, standardizing deployment architectures, maintenance and upgrade headaches and freedom from vendor lock-in. All good reasons to keep in mind when understanding how identity services needs to evolve and get used.<br />
But one of the things that didn’t come up was the fact that our industry as a whole is headed towards a seismic shift in how we deal with identity, and that having a good identity services story is crucial to being able to weather the storm. Change is definitely in the air, and not just because the recent election cycle or recession fears have put that word firmly in our conscious. You can sense this by doing a quick scan of the blogosphere. Rapid advancements in the area of Information Cards and OpenID, Microsoft’s recent work encapsulated in <a href="http://www.identityblog.com/?p=1019">the Geneva announcement</a>, our own work on <a href="http://blogs.oracle.com/talkingidentity/2008/08/the_frameworks_are_coming.html">the IDx project</a> and the emerging talk of <a href="http://therealmccrea.com/2008/09/19/joseph-smarr-at-web-20-on-the-new-open-stack/">the “Open Stack” for identity</a> are all key developments to follow to understand where we are headed as an industry. There is a lot of work still to be done in these initiatives, but one can already see the far-ranging implications of all these projects. And identity services will be the backbone that allows enterprises and applications to adapt in a scalable manner.<br />
Much needed change is on the way, so buckle up.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/burtongroupcatalyst08" rel="tag">BurtonGroupCatalyst08</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/iswg" rel="tag">ISWG</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DChange%2520We%2520Need%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%26amp%3Btitle%3DChange%2520We%2520Need%26amp%3Bbodytext%3DIt%2527s%2520been%2520a%2520long%2520time%2520since%2520I%2520have%2520been%2520able%2520to%2520post.%2520A%2520lot%2520conspired%2520to%2520make%2520it%2520difficult%2520for%2520me%2520to%2520keep%2520up%2520with%2520my%2520blogging%252C%2520not%2520the%2520least%2520of%2520which%2520has%2520been%2520a%2520number%2520of%2520interesting%252C%2520but%2520under%2520wrap%252C%2520developments%2520within%2520the%2520IdM%2520group%2520at%2520Oracle%2520%2528if%2520yo';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%26amp%3Bt%3DChange%2520We%2520Need';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%26amp%3Btitle%3DChange%2520We%2520Need';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%26amp%3Btitle%3DChange%2520We%2520Need%26amp%3Bannotation%3DIt%2527s%2520been%2520a%2520long%2520time%2520since%2520I%2520have%2520been%2520able%2520to%2520post.%2520A%2520lot%2520conspired%2520to%2520make%2520it%2520difficult%2520for%2520me%2520to%2520keep%2520up%2520with%2520my%2520blogging%252C%2520not%2520the%2520least%2520of%2520which%2520has%2520been%2520a%2520number%2520of%2520interesting%252C%2520but%2520under%2520wrap%252C%2520developments%2520within%2520the%2520IdM%2520group%2520at%2520Oracle%2520%2528if%2520yo';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%26amp%3Btitle%3DChange%2520We%2520Need%26amp%3Bnotes%3DIt%2527s%2520been%2520a%2520long%2520time%2520since%2520I%2520have%2520been%2520able%2520to%2520post.%2520A%2520lot%2520conspired%2520to%2520make%2520it%2520difficult%2520for%2520me%2520to%2520keep%2520up%2520with%2520my%2520blogging%252C%2520not%2520the%2520least%2520of%2520which%2520has%2520been%2520a%2520number%2520of%2520interesting%252C%2520but%2520under%2520wrap%252C%2520developments%2520within%2520the%2520IdM%2520group%2520at%2520Oracle%2520%2528if%2520yo';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%26amp%3Btitle%3DChange%2520We%2520Need';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%26amp%3Bh%3DChange%2520We%2520Need';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DChange%2520We%2520Need%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html%2520Change%2520We%2520Need';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DChange%2520We%2520Need%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F12%252Fchange-we-need.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/12/change-we-need.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Evolving the Identity Services architecture</title>
		<link>http://blog.talkingidentity.com/2008/10/evolving_the_identity_services.html</link>
		<comments>http://blog.talkingidentity.com/2008/10/evolving_the_identity_services.html#comments</comments>
		<pubDate>Sat, 18 Oct 2008 00:12:18 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[Identity Hub]]></category>
		<category><![CDATA[Identity Services]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=135</guid>
		<description><![CDATA[The last 3 months or so has been really good to my work defining our vision for Identity Services. I&#8217;ve gotten valuable input from my colleagues in the IdM business, and my participation in Project Fusion and Burton&#8217;s Identity Services Working Group has helped crystallize some key aspects of the architecture. Below is the latest [...]]]></description>
			<content:encoded><![CDATA[<p>The last 3 months or so has been really good to my work defining our vision for Identity Services. I&#8217;ve gotten valuable input from my colleagues in the IdM business, and my participation in Project Fusion and Burton&#8217;s <strong>Identity Services Working Group</strong> has helped crystallize some key aspects of the architecture. Below is the latest architecture diagram for the <strong>Identity Services Platform</strong>.</p>
<p><a href="http://blog.talkingidentity.com/wp-content/uploads/2008/10/idsp_arch_thumb_1.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" src="http://blog.talkingidentity.com/wp-content/uploads/2008/10/idsp_arch_thumb_1.jpg" border="0" alt="IdSP_Arch" width="600" height="400" /></a></p>
<p>It doesn&#8217;t look remarkably different from what I have presented previously on this blog, but it do want to point out some of the evolving ideas captured in the diagram above:</p>
<ul>
<li>Some of the ongoing discussions that I have <a href="http://blogs.oracle.com/talkingidentity/2008/05/talking_about_the_identity_bus.html" target="_blank">blogged about previously</a> have led to a clearer definition of the service called the <strong>Identity Hub</strong> . In fact, we just put out an <a href="http://www.oracle.com/technology/products/id_mgmt/pdf/tackling%20identity%20data%20with%20identity%20hub1.pdf" target="_blank">Oracle whitepaper</a> talking about the Identity Hub in detail.</li>
<li>It has become clear that the <strong>API Interfaces</strong> that the applications rely on to consume these services should be coming from the container that the applications are built on.</li>
<li>The provider model by which various IdM products plug into the architecture as <strong>Service Providers</strong> (within the container) is starting to take shape, thanks to good discussion happening in the standards and vendor communities. Consuming applications will not know or care about the specifics of the deployment. This also provides a way for the existing IdM investments to be leveraged (provided we can get all IdM vendors to agree to the requirements of being an <em>Identity Service Provider</em>).</li>
<li>Authentication and Authorization are both going to have to support <em>contextual</em> and <em>risk-based</em> decisions. This will require greater communication from the applications into the services, and vice-versa.</li>
</ul>
<p>You can check out a <a href="http://blogs.oracle.com/talkingidentity/Building%20an%20Identity%20Services%20Layer%20with%20Oracle%20IAM.pdf" target="_blank">presentation</a> I have put together on how the various IdM products in Oracle Identity Management can be used to create an initial version of this Identity Services Platform. This is an adaptation of my OpenWorld presentation that I will be using in discussions with some customers that are interested in working with us to define their identity services strategy. As always, input and feedback is welcome. And feel free to tell me specific portions that I should talk about in detail in this blog.</p>
<p>Remember, you can find all my published materials (the presentation referenced above, all the Oracle whitepapers on Identity Services, and more) on the <a href="http://www.talkingidentity.com/downloads.htm" target="_blank">downloads page</a> of my blog.</p>
<h3>Spreading the Word on Identity Services at Catalyst Europe</h3>
<p>My exciting fall season continues as I head to Europe next week. My trip starts with a brief stopover in London for some meetings, after which I head to Prague for the Europe edition of Burton Group&#8217;s <a href="http://www.catalyst.burtongroup.com/EU08/index.html" target="_blank">Catalyst Conference</a>. I&#8217;ve been to Prague before (for pleasure, not business), and I absolutely love that city. So that is as good a reason to go as any.</p>
<p>My participation in <strong>Catalyst Europe</strong> is to continue to spread the gospel of Identity Services. On Thursday, Kevin Kampman will be presenting the results of the work that has been done so far in the ISWG. Following that, I will be on stage as part of a panel discussion involving both customers (TD Bank, BT, Credit Suisse) and vendors (IBM, Novell, Sun and of course Oracle) that are part of the ISWG.</p>
<blockquote><p><strong>Title: </strong>Identity Services Roundtable: Aligning Vendor Strategies with Customer Needs<br />
<strong>Date: </strong>Thursday, 23 October 2008<br />
<strong>Start time: </strong>11:55 am<br />
<strong>End time: </strong>12:45 pm<br />
<strong>Room: </strong>Congress Hall 2</p></blockquote>
<p>Should be an interesting discussion. We&#8217;ve had some very good workshops in the working group, and we are anxious to put the results out there for people to see and comment on. It is very much a work-in-progress, so lots of feedback is expected. If you are going to be at Catalyst Europe, then please stick around for this roundtable (unfortunately, it is scheduled as the last session in the conference) and participate. And remember to follow me on <a href="http://twitter.com/NishantK">Twitter</a> for real-time updates on my Europe trip and the proceedings at Catalyst Europe.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/identity-hub" rel="tag">Identity Hub</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DEvolving%2520the%2520Identity%2520Services%2520architecture%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%26amp%3Btitle%3DEvolving%2520the%2520Identity%2520Services%2520architecture%26amp%3Bbodytext%3DThe%2520last%25203%2520months%2520or%2520so%2520has%2520been%2520really%2520good%2520to%2520my%2520work%2520defining%2520our%2520vision%2520for%2520Identity%2520Services.%2520I%2527ve%2520gotten%2520valuable%2520input%2520from%2520my%2520colleagues%2520in%2520the%2520IdM%2520business%252C%2520and%2520my%2520participation%2520in%2520Project%2520Fusion%2520and%2520Burton%2527s%2520Identity%2520Services%2520Working%2520Group%2520';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%26amp%3Bt%3DEvolving%2520the%2520Identity%2520Services%2520architecture';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%26amp%3Btitle%3DEvolving%2520the%2520Identity%2520Services%2520architecture';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%26amp%3Btitle%3DEvolving%2520the%2520Identity%2520Services%2520architecture%26amp%3Bannotation%3DThe%2520last%25203%2520months%2520or%2520so%2520has%2520been%2520really%2520good%2520to%2520my%2520work%2520defining%2520our%2520vision%2520for%2520Identity%2520Services.%2520I%2527ve%2520gotten%2520valuable%2520input%2520from%2520my%2520colleagues%2520in%2520the%2520IdM%2520business%252C%2520and%2520my%2520participation%2520in%2520Project%2520Fusion%2520and%2520Burton%2527s%2520Identity%2520Services%2520Working%2520Group%2520';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%26amp%3Btitle%3DEvolving%2520the%2520Identity%2520Services%2520architecture%26amp%3Bnotes%3DThe%2520last%25203%2520months%2520or%2520so%2520has%2520been%2520really%2520good%2520to%2520my%2520work%2520defining%2520our%2520vision%2520for%2520Identity%2520Services.%2520I%2527ve%2520gotten%2520valuable%2520input%2520from%2520my%2520colleagues%2520in%2520the%2520IdM%2520business%252C%2520and%2520my%2520participation%2520in%2520Project%2520Fusion%2520and%2520Burton%2527s%2520Identity%2520Services%2520Working%2520Group%2520';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%26amp%3Btitle%3DEvolving%2520the%2520Identity%2520Services%2520architecture';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%26amp%3Bh%3DEvolving%2520the%2520Identity%2520Services%2520architecture';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DEvolving%2520the%2520Identity%2520Services%2520architecture%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html%2520Evolving%2520the%2520Identity%2520Services%2520architecture';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DEvolving%2520the%2520Identity%2520Services%2520architecture%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F10%252Fevolving_the_identity_services.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/10/evolving_the_identity_services.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Next Attempt at Controversy: Roles and the (ir)relevance of NIST</title>
		<link>http://blog.talkingidentity.com/2008/07/my_next_attempt_at_controversy.html</link>
		<comments>http://blog.talkingidentity.com/2008/07/my_next_attempt_at_controversy.html#comments</comments>
		<pubDate>Wed, 09 Jul 2008 21:29:42 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[BurtonGroupCatalyst08]]></category>
		<category><![CDATA[NIST RBAC]]></category>
		<category><![CDATA[RBAC]]></category>
		<category><![CDATA[Relationship-Based RBAC]]></category>
		<category><![CDATA[Role Management]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=114</guid>
		<description><![CDATA[Well, I think I am done talking about directories now, especially after reading Ian Yip&#8217;s hilarious recap of the debate, as it were. Having now appeared as a significant bit player in this drama, I have decided to leave it in the hands of more capable people like Clayton and am moving on to familiar [...]]]></description>
			<content:encoded><![CDATA[<p>Well, I think I am done talking about directories now, especially after reading Ian Yip&#8217;s <a href="http://blog.ianyip.com/2008/07/metaphysical-directory-virtual-storm.html" target="_blank">hilarious recap</a> of the debate, as it were. Having now appeared as a significant bit player in this drama, I have decided to leave it in the hands of more capable people like <a href="http://blogs.oracle.com/clayton/2008/07/is_connecting_to_multiple_dire.html" target="_blank">Clayton</a> and am moving on to familiar (and hopefully fertile) ground.</p>
<p>Day 2 of the Catalyst Conference turned towards the more pragmatic topics of role management and provisioning. It was with a great deal of interest that I heard <strong>Tim Weil</strong> discuss a standards effort he is leading to promote the implementation and interoperability of RBAC components. As I understood it, the goal is to make it easy for roles defined in one system (say ORM or SailPoint) to be used in another system (OIM or Sun IM), without having to do massive integration projects. Burton&#8217;s Kevin Kampman has <a href="http://bgidps.typepad.com/bgidps/2008/07/the-elephant-pa.html" target="_blank">blogged about this</a> if you are interested.</p>
<p>Tim&#8217;s perspective on this is very relevant, having dealt with such practical issues through numerous implementation projects while at Booz Allen Hamilton. It was this very perspective that I wanted to tap into by asking him a question that vexes me a lot, but he gracefully sidestepped since it wasn&#8217;t directly related to the talk he was giving. However during a Twitter exchange with <a href="http://www.tuesdaynight.org/" target="_blank">Ian Glazer</a> I promised to explain my side fully in a blog post, so here goes.</p>
<p><strong>My Question To Tim</strong></p>
<p>Is the NIST RBAC standard fundamentally flawed, given that it is missing a key element in access control decisions &#8211; relationships, the very thing that Burton spent day 1 of the conference stating was the missing link for IdM to tackle?</p>
<p><strong>My Thesis</strong></p>
<p>It is, and companies looking to the NIST RBAC standard as the template for how to approach role management are going to end up missing the boat.</p>
<p><strong>My Rationale</strong></p>
<p>In a conversation later with Ian and Lori, I illustrated my case with the following access control examples:</p>
<p><span style="text-decoration: underline;">Scenario A</span></p>
<p><a href="http://csrc.nist.gov/rbac/sandhu-ferraiolo-kuhn-00.pdf" target="_blank"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/hierarchicalrbac_3.jpg" border="0" alt="HierarchicalRBAC" width="240" height="117" align="right" /></a> A doctor wants to enter a hospital he is assigned to, presumably using a physical access device like a Honeywell card. In order for the doctor to get into a hospital, all he needs is for his identity in the system to have a &#8220;Doctor&#8221; role that is checked for when he enters the hospital. This is a simple scenario that the NIST RBAC standard can easily take care of.</p>
<p><span style="text-decoration: underline;">Scenario B</span></p>
<p><a href="http://blogs.oracle.com/talkingidentity/WindowsLiveWriter/MyNextAttemptatControversyRolesandtheirr_D418/DrReadingChart_2.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 5px 5px 0px; border-right-width: 0px" src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/drreadingchart.jpg" border="0" alt="DrReadingChart" width="154" height="240" align="left" /></a> However, in order for that doctor, Dr. X, to view the medical charts (electronically) of a particular patient, Patient Y, the good doctor not only needs to have a &#8220;Doctor&#8221; role, but also needs to have the &#8220;Attending Doctor&#8221; role WITH RESPECT TO Patient Y. In other words, the Access Control around the medical charts is based on a specific relationship established between Dr. X and Patient Y, that could be expressed as a relationship-based role. NIST RBAC seems to be wholly unequipped to handle this use case.</p>
<p>NIST RBAC is an important tool to any discussion on role structures. But it should not be treated as complete by any means, merely a start. The use case illustrated in Scenario B is rapidly becoming the more common use case, as Fine-Grained Authorization needs and Data Security come front-and-center in the discussion around Access Control. Yet work on resolving such scenarios is currently excluded from discussions on RBAC and left up to the ABAC (Attribute-Based Access Control) crowd. Having two different mechanisms to implement security (often in the same systems) will surely lead to more holes than a chunk of swiss cheese.</p>
<p>Those that feel this is promotion for our ORM (formerly Bridgestream) product should know that it is not, since the relationship-based roles concept that they created has so far been limited to approval use cases, and has not made its way into any access control discussions. One reason I feel this isn&#8217;t happening is because it seems no one has figured out how to express this in an XACML policy, which can easily handle ABAC, but not Relationship-based RBAC. This led to the next controversial question I asked at Catalyst, which I will bring up in a later post.</p>
<p>I&#8217;d love to hear other perspectives on this, so leave me some comments.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/burtongroupcatalyst08" rel="tag">BurtonGroupCatalyst08</a>, <a href="http://blog.talkingidentity.com/tag/nist-rbac" rel="tag">NIST RBAC</a>, <a href="http://blog.talkingidentity.com/tag/rbac" rel="tag">RBAC</a>, <a href="http://blog.talkingidentity.com/tag/relationship-based-rbac" rel="tag">Relationship-Based RBAC</a>, <a href="http://blog.talkingidentity.com/tag/role-management" rel="tag">Role Management</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%26amp%3Btitle%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST%26amp%3Bbodytext%3DWell%252C%2520I%2520think%2520I%2520am%2520done%2520talking%2520about%2520directories%2520now%252C%2520especially%2520after%2520reading%2520Ian%2520Yip%2527s%2520hilarious%2520recap%2520of%2520the%2520debate%252C%2520as%2520it%2520were.%2520Having%2520now%2520appeared%2520as%2520a%2520significant%2520bit%2520player%2520in%2520this%2520drama%252C%2520I%2520have%2520decided%2520to%2520leave%2520it%2520in%2520the%2520hands%2520of%2520more%2520capabl';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%26amp%3Bt%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%26amp%3Btitle%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%26amp%3Btitle%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST%26amp%3Bannotation%3DWell%252C%2520I%2520think%2520I%2520am%2520done%2520talking%2520about%2520directories%2520now%252C%2520especially%2520after%2520reading%2520Ian%2520Yip%2527s%2520hilarious%2520recap%2520of%2520the%2520debate%252C%2520as%2520it%2520were.%2520Having%2520now%2520appeared%2520as%2520a%2520significant%2520bit%2520player%2520in%2520this%2520drama%252C%2520I%2520have%2520decided%2520to%2520leave%2520it%2520in%2520the%2520hands%2520of%2520more%2520capabl';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%26amp%3Btitle%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST%26amp%3Bnotes%3DWell%252C%2520I%2520think%2520I%2520am%2520done%2520talking%2520about%2520directories%2520now%252C%2520especially%2520after%2520reading%2520Ian%2520Yip%2527s%2520hilarious%2520recap%2520of%2520the%2520debate%252C%2520as%2520it%2520were.%2520Having%2520now%2520appeared%2520as%2520a%2520significant%2520bit%2520player%2520in%2520this%2520drama%252C%2520I%2520have%2520decided%2520to%2520leave%2520it%2520in%2520the%2520hands%2520of%2520more%2520capabl';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%26amp%3Btitle%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%26amp%3Bh%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html%2520My%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DMy%2520Next%2520Attempt%2520at%2520Controversy%253A%2520Roles%2520and%2520the%2520%2528ir%2529relevance%2520of%2520NIST%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fmy_next_attempt_at_controversy.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/07/my_next_attempt_at_controversy.html/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Information Cards gets its own Foundation</title>
		<link>http://blog.talkingidentity.com/2008/07/information_cards_gets_its_own.html</link>
		<comments>http://blog.talkingidentity.com/2008/07/information_cards_gets_its_own.html#comments</comments>
		<pubDate>Sat, 05 Jul 2008 02:13:11 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Personal Identity Management]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[BurtonGroupCatalyst08]]></category>
		<category><![CDATA[Information Card Foundation]]></category>
		<category><![CDATA[Information Cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[User-Centric Identity]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=111</guid>
		<description><![CDATA[One of the big announcements at Catalyst that I twittered about was the formation of the Information Card Foundation (take that,  OpenID). The purpose of the non-profit foundation is to promote the use of information cards as a secure way to present personal identity information on the web. The foundation has a power-packed set [...]]]></description>
			<content:encoded><![CDATA[<p>One of the big announcements at Catalyst that <a href="http://twitter.com/NishantK/statuses/843431104" target="_blank">I twittered about</a> was the formation of the <strong>Information Card Foundation</strong> (take that, <img style="margin: 5px 0px 0px 5px" src="http://informationcard.net/uploads/images/Infocard_icon.gif" alt="" align="right" /> OpenID). The purpose of the non-profit foundation is to promote the use of information cards as a secure way to present personal identity information on the web. The foundation has a power-packed set of companies as steering members (<strong>Oracle</strong> is in there along with <strong>Google</strong>, <strong>Novell</strong>, <strong>Paypal</strong>, <strong>Equifax</strong> and, of course, <strong>Microsoft</strong>) and a great Board providing direction with people like <a href="http://www.identityblog.com/" target="_blank">Kim Cameron</a>, <a href="http://eternaloptimist.wordpress.com/" target="_blank">Pamela Dingle</a>, Patrick Harding, <a href="http://www.links.org/" target="_blank">Ben Laurie</a> and Drummond Reed (among others) leading the way.</p>
<p>Information Cards try to mirror the familiar, real-world experience of presenting cards to prove identity and provide information in the online world, and aims to do so in a safe, secure manner that is resistant to phishing, pharming and MITM attacks. Despite having been put into the wild a few years ago, and despite the tireless efforts of people like Kim Cameron and Pam Dingle to make it accessible, there are scant few web sites (of any note, anyway) that actually allow people to use information cards. The ICF (much like the OpenID foundation, which also <a href="http://blogs.oracle.com/talkingidentity/2008/02/big_news_for_openid.html" target="_blank">kicked into high gear</a> a few months ago) is looking to put some weight behind the effort to evangelize the technology and expand its adoption in the marketplace. As it states on the ICF Web site, the foundations purpose is to</p>
<blockquote><p>Advance the use of the Information Card metaphor as a key component of an open, interoperable, royalty-free, user-centric identity layer spanning both the enterprise and the Internet.</p></blockquote>
<p>It will be very interesting to see how the ICF goes about doing this, and when results will start to show. But this is undoubtedly the beginning of something big. For all of us.</p>
<p>Links:</p>
<ul>
<li><a href="http://www.marketwire.com/press-release/Information-Card-Foundation-872467.html" target="_blank">Press Release announcing the ICF</a></li>
<li><a href="http://www.nytimes.com/2008/06/24/technology/24card.html?_r=1&amp;ref=technology&amp;oref=slogin" target="_blank">New York Times article</a></li>
<li><a href="http://www.scmagazineuk.com/Google-Microsoft-lead-efforts-to-spur-the-adoption-of-digital-identities/article/111633/" target="_blank">SC Magazine coverage</a></li>
</ul>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/burtongroupcatalyst08" rel="tag">BurtonGroupCatalyst08</a>, <a href="http://blog.talkingidentity.com/tag/information-card-foundation" rel="tag">Information Card Foundation</a>, <a href="http://blog.talkingidentity.com/tag/information-cards" rel="tag">Information Cards</a>, <a href="http://blog.talkingidentity.com/tag/openid" rel="tag">OpenID</a>, <a href="http://blog.talkingidentity.com/tag/personal-identity-management" rel="tag">Personal Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/user-centric-identity" rel="tag">User-Centric Identity</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%26amp%3Btitle%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation%26amp%3Bbodytext%3DOne%2520of%2520the%2520big%2520announcements%2520at%2520Catalyst%2520that%2520I%2520twittered%2520about%2520was%2520the%2520formation%2520of%2520the%2520Information%2520Card%2520Foundation%2520%2528take%2520that%252C%2520%2520OpenID%2529.%2520The%2520purpose%2520of%2520the%2520non-profit%2520foundation%2520is%2520to%2520promote%2520the%2520use%2520of%2520information%2520cards%2520as%2520a%2520secure%2520way%2520to%2520present%2520';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%26amp%3Bt%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%26amp%3Btitle%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%26amp%3Btitle%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation%26amp%3Bannotation%3DOne%2520of%2520the%2520big%2520announcements%2520at%2520Catalyst%2520that%2520I%2520twittered%2520about%2520was%2520the%2520formation%2520of%2520the%2520Information%2520Card%2520Foundation%2520%2528take%2520that%252C%2520%2520OpenID%2529.%2520The%2520purpose%2520of%2520the%2520non-profit%2520foundation%2520is%2520to%2520promote%2520the%2520use%2520of%2520information%2520cards%2520as%2520a%2520secure%2520way%2520to%2520present%2520';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%26amp%3Btitle%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation%26amp%3Bnotes%3DOne%2520of%2520the%2520big%2520announcements%2520at%2520Catalyst%2520that%2520I%2520twittered%2520about%2520was%2520the%2520formation%2520of%2520the%2520Information%2520Card%2520Foundation%2520%2528take%2520that%252C%2520%2520OpenID%2529.%2520The%2520purpose%2520of%2520the%2520non-profit%2520foundation%2520is%2520to%2520promote%2520the%2520use%2520of%2520information%2520cards%2520as%2520a%2520secure%2520way%2520to%2520present%2520';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%26amp%3Btitle%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%26amp%3Bh%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html%2520Information%2520Cards%2520gets%2520its%2520own%2520Foundation';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DInformation%2520Cards%2520gets%2520its%2520own%2520Foundation%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Finformation_cards_gets_its_own.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/07/information_cards_gets_its_own.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Real World: Catalyst Conference Edition</title>
		<link>http://blog.talkingidentity.com/2008/07/the_real_world_catalyst_confer.html</link>
		<comments>http://blog.talkingidentity.com/2008/07/the_real_world_catalyst_confer.html#comments</comments>
		<pubDate>Thu, 03 Jul 2008 03:05:19 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[BurtonGroupCatalyst08]]></category>
		<category><![CDATA[GRC]]></category>
		<category><![CDATA[Identity Assurance Framework]]></category>
		<category><![CDATA[Identity Governance Framework]]></category>
		<category><![CDATA[Identity Oracle]]></category>
		<category><![CDATA[Identity Proofing]]></category>
		<category><![CDATA[IGF]]></category>
		<category><![CDATA[Nick Leeson]]></category>
		<category><![CDATA[Relationship Management]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=110</guid>
		<description><![CDATA[ Another Catalyst conference has come and gone, leaving us with a lot of material to chew on and ponder. Burton always forces us to think about what we are doing, especially those of us that have products to deliver. And it&#8217;s always interesting to see all the new companies that are popping up in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.catalyst.burtongroup.com/NA08/ConferenceElements.html" target="_blank"><img src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/catalystlogo08.jpg" border="0" alt="" align="right" /></a> Another Catalyst conference has come and gone, leaving us with a lot of material to chew on and ponder. Burton always forces us to think about what we are doing, especially those of us that have products to deliver. And it&#8217;s always interesting to see all the new companies that are popping up in the space (Lori&#8217;s slide this year showing all the identity management companies looked like it needed a magnifying glass to read).</p>
<p>I&#8217;m not going to recap all the interesting sessions that I attended. If you followed my <a href="http://summize.com/search?q=BurtonGroupCatalyst08+NishantK">twitter postings</a> (and a big &#8220;Hi and Thank You&#8221; to everyone who tripled my following last week by connecting, including some folks who signed up for Twitter just to follow me), you got a sense of what was being talked about, and my thoughts on the same. For some great reporting on the key sessions, read Mark Dixon&#8217;s blog postings (<a href="http://blogs.sun.com/identity/entry/catalyst_conference_recap" target="_blank">this post</a> is a map to the various posts he has written covering the conference).</p>
<p>I&#8217;ll simply present what I saw as the theme of the conference: <strong>Reality Hits The World Of Identity</strong>. People are realizing that the only way this identity stuff is going to work is if the online experience and constructs mirror how we operate in the real world. And this opens up a whole set of new areas to explore.</p>
<p><strong>You Complete Me<br />
</strong><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/relationships.jpg" border="0" alt="relationships" width="260" height="141" align="right" /> A key realization that is taking hold is that <strong>relationships</strong> must be made a key part of the fabric of identity, and that relationships can form the trust basis for identity related transactions. While I don&#8217;t completely agree with Jamie&#8217;s assertion that a lot of work in the real world happens before any contracts are drawn up (no contractor can even begin work for Oracle until a contract is signed; similarly I can&#8217;t work for Oracle and get access to systems till an employment agreement is in place), I do recognize that the value proposition of transactions is a continuum, along which are different levels that require different levels of assurance. Assurance can be built up over time as a function of relationships (user is related to this company, user has X friends, user is certified by this identity provider, etc). <a href="http://www.xmlgrrl.com/blog/archives/2008/06/27/relationships-are-complicated/" target="_blank">Eve Maler</a> gave a very interesting talk on how relationships can be nurtured and made available in the online world, and connected it to some of the work being done on <a href="http://wiki.eclipse.org/R-Card" target="_blank">R-Cards</a> and <a href="http://cyber.law.harvard.edu/projectvrm/Main_Page" target="_blank">Project VRM</a>.</p>
<p><strong>I Need An Authority Figure<br />
</strong><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/authenticity_seal_oval.jpg" border="0" alt="authenticity_seal_oval" width="260" height="163" align="right" />Another sign that real world concepts are seeping into the online world was the increased discussion on the topic of <strong>Identity Proofing</strong>, and the externalization of <strong>Authoritative Identity Providers</strong>. Just like in the real world, companies are realizing that in order to scale  and distribute liability, they would like someone else to be responsible for vetting identity data and providing a validated, trustworthy identity into their environments. This is the first sign of a legitimate market emerging for the <strong>Identity Oracle</strong> that Bob Blakely <a href="http://notabob.blogspot.com/2006/07/meta-identity-system.html" target="_blank">has defined</a>, and that I have discussed so often in the context of Identity Services. The Liberty Alliance has <a href="http://www.projectliberty.org/liberty/strategic_initiatives/identity_assurance" target="_blank">jumped in here</a> to help out by proposing an <strong>Identity Assurance Framework</strong> (our old friend Frank Villavicencio is co-chair of the effort) that can define a trust language in this context. And everyone knows that I consider the work being done on the IGF a critical part of such an infrastructure.</p>
<p><strong>I Got Your GRC Right Here (Not!)<br />
</strong><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/croc-bathing-at-your-risk.jpg" border="0" alt="croc-bathing-at-your-risk" width="220" height="221" align="right" /> Burton decided to take the IAM vendors to task for using GRC as a crutch to sell all manner of products. Referring to GRC as a four letter word, Bob attempted to blow up the myths surrounding GRC and posited that all the bluster around GRC has made companies lose sight of what they really need to address. He stated that each discipline conflated within GRC should be looked at independently by businesses with regards to its objectives, and that tools and processes should be put in place that address the specific needs identified. The message was clear &#8211; there is no such thing as a GRC product; instead there are a multitude of products that provide tools for addressing specific problems that fall under one of these disciplines, and enterprises should take a fresh look at what GRC means to them and how to approach it.</p>
<p>For me, the highlight of the conference was the talk by <strong>Nick Leeson</strong>, the securities trader who brought down <strong>Barings Bank</strong>. Not a technical talk at all, his explanation of how his actions exploited failings in the areas of governance and compliance drove home the point about process and tools being complementary parts of the puzzle.</p>
<p>The rest of the conference had some interesting announcements and decent discussions on the usual topics of <em>Authentication</em>, <em>Provisioning</em> and <em>Role Management</em>. I did what little I could to break the monotony and generate some controversy, but I&#8217;ll cover all of these in my upcoming posts.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/burtongroupcatalyst08" rel="tag">BurtonGroupCatalyst08</a>, <a href="http://blog.talkingidentity.com/tag/grc" rel="tag">GRC</a>, <a href="http://blog.talkingidentity.com/tag/identity-assurance-framework" rel="tag">Identity Assurance Framework</a>, <a href="http://blog.talkingidentity.com/tag/identity-governance-framework" rel="tag">Identity Governance Framework</a>, <a href="http://blog.talkingidentity.com/tag/identity-oracle" rel="tag">Identity Oracle</a>, <a href="http://blog.talkingidentity.com/tag/identity-proofing" rel="tag">Identity Proofing</a>, <a href="http://blog.talkingidentity.com/tag/igf" rel="tag">IGF</a>, <a href="http://blog.talkingidentity.com/tag/nick-leeson" rel="tag">Nick Leeson</a>, <a href="http://blog.talkingidentity.com/tag/relationship-management" rel="tag">Relationship Management</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%26amp%3Btitle%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition%26amp%3Bbodytext%3D%2520Another%2520Catalyst%2520conference%2520has%2520come%2520and%2520gone%252C%2520leaving%2520us%2520with%2520a%2520lot%2520of%2520material%2520to%2520chew%2520on%2520and%2520ponder.%2520Burton%2520always%2520forces%2520us%2520to%2520think%2520about%2520what%2520we%2520are%2520doing%252C%2520especially%2520those%2520of%2520us%2520that%2520have%2520products%2520to%2520deliver.%2520And%2520it%2527s%2520always%2520interesting%2520to%2520se';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%26amp%3Bt%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%26amp%3Btitle%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%26amp%3Btitle%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition%26amp%3Bannotation%3D%2520Another%2520Catalyst%2520conference%2520has%2520come%2520and%2520gone%252C%2520leaving%2520us%2520with%2520a%2520lot%2520of%2520material%2520to%2520chew%2520on%2520and%2520ponder.%2520Burton%2520always%2520forces%2520us%2520to%2520think%2520about%2520what%2520we%2520are%2520doing%252C%2520especially%2520those%2520of%2520us%2520that%2520have%2520products%2520to%2520deliver.%2520And%2520it%2527s%2520always%2520interesting%2520to%2520se';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%26amp%3Btitle%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition%26amp%3Bnotes%3D%2520Another%2520Catalyst%2520conference%2520has%2520come%2520and%2520gone%252C%2520leaving%2520us%2520with%2520a%2520lot%2520of%2520material%2520to%2520chew%2520on%2520and%2520ponder.%2520Burton%2520always%2520forces%2520us%2520to%2520think%2520about%2520what%2520we%2520are%2520doing%252C%2520especially%2520those%2520of%2520us%2520that%2520have%2520products%2520to%2520deliver.%2520And%2520it%2527s%2520always%2520interesting%2520to%2520se';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%26amp%3Btitle%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%26amp%3Bh%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html%2520The%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DThe%2520Real%2520World%253A%2520Catalyst%2520Conference%2520Edition%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F07%252Fthe_real_world_catalyst_confer.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/07/the_real_world_catalyst_confer.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Follow me at Catalyst</title>
		<link>http://blog.talkingidentity.com/2008/06/follow-me-at-catalyst.html</link>
		<comments>http://blog.talkingidentity.com/2008/06/follow-me-at-catalyst.html#comments</comments>
		<pubDate>Thu, 19 Jun 2008 22:05:55 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[BurtonGroupCatalyst08]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=108</guid>
		<description><![CDATA[I&#8217;ll be at the Catalyst conference next week, looking to share and learn. I expect Catalyst to be the usual source of inspiration, news and ideas. And I look forward to meeting up with fellow identirati like Ian, Mark and of course, the good folks from Burton.
Unfortunately, a quirk of timing means that a long [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.catalyst.burtongroup.com/NA08/ConferenceElements.html"><img src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/catalystlogo08.jpg" alt="" align="right" /></a>I&#8217;ll be at the Catalyst conference next week, looking to share and learn. I expect Catalyst to be the usual source of inspiration, news and ideas. And I look forward to meeting up with fellow identirati like <a href="http://www.tuesdaynight.org/">Ian</a>, <a href="http://blogs.sun.com/identity/">Mark</a> and of course, the good folks from Burton.</p>
<p>Unfortunately, a quirk of timing means that a long awaited upgrade of the Oracle blogs system is also taking place next week, freezing all of our blogs. Those that follow my blog know that the current system <a href="http://blogs.oracle.com/talkingidentity/2007/03/help_debug_my_blog.html">leaves something to be desired</a> in terms of features and stability. And the commenting system was totally unhelpful in enabling any kind of conversation with my readers. While I welcome the upgrade, I hate the fact that I won&#8217;t be able to post during the week.</p>
<p><a href="http://twitter.com/NishantK"><img src="http://assets2.twitter.com/images/twitter.png" alt="" align="left" /></a>I will post some wrap-up posts the week after Catalyst, summarizing my experiences and thoughts. But if you are really interested in keeping up with my Catalyst experience, there is an option. I use <span style="font-weight: bold;">Twitter</span>, that quirky micro-blogging platform that is all the rage, fairly regularly. And I plan on posting fairly regularly from San Diego. To make things easier, I will be prefacing all my Catalyst related postings with &#8220;BurtonCatalyst08:&#8221; (unless Burton has something else going). So If you are on Twitter, you can choose to <a href="http://twitter.com/NishantK">follow me</a> and keep up with the going-ons. If you don&#8217;t want to sign up for <span style="font-style: italic;">yet another social whatever</span>, then you can subscribe to an RSS feed of my twitter postings <a href="http://twitter.com/statuses/user_timeline/8237722.rss">here</a>.</p>
<p>If you plan on being at Catalyst and want to meet up, either email me or join us at the <span style="font-weight: bold;">Oracle Hospitality Suite</span> on the evening of June 25th (<span style="font-style: italic;">Wednesday</span>). I&#8217;ll be around. And the following sessions might be of interest to you if you want to learn more about Oracle Identity Management:</p>
<ul>
<li>Role Management and Provisioning: Coexistence or Convergence? A Roundtable discussion including Oracle&#8217;s Jeff Shukis &#8211; <span style="font-style: italic;">Thurs at 4.10pm</span></li>
<li>Selecting and Implementing a COTS-based IdM Solution at Boeing: A Case Study &#8211; <span style="font-style: italic;">Thurs at 5.20pm</span></li>
</ul>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/burtongroupcatalyst08" rel="tag">BurtonGroupCatalyst08</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DFollow%2520me%2520at%2520Catalyst%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%26amp%3Btitle%3DFollow%2520me%2520at%2520Catalyst%26amp%3Bbodytext%3DI%2527ll%2520be%2520at%2520the%2520Catalyst%2520conference%2520next%2520week%252C%2520looking%2520to%2520share%2520and%2520learn.%2520I%2520expect%2520Catalyst%2520to%2520be%2520the%2520usual%2520source%2520of%2520inspiration%252C%2520news%2520and%2520ideas.%2520And%2520I%2520look%2520forward%2520to%2520meeting%2520up%2520with%2520fellow%2520identirati%2520like%2520Ian%252C%2520Mark%2520and%2520of%2520course%252C%2520the%2520good%2520folks%2520fr';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%26amp%3Bt%3DFollow%2520me%2520at%2520Catalyst';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%26amp%3Btitle%3DFollow%2520me%2520at%2520Catalyst';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%26amp%3Btitle%3DFollow%2520me%2520at%2520Catalyst%26amp%3Bannotation%3DI%2527ll%2520be%2520at%2520the%2520Catalyst%2520conference%2520next%2520week%252C%2520looking%2520to%2520share%2520and%2520learn.%2520I%2520expect%2520Catalyst%2520to%2520be%2520the%2520usual%2520source%2520of%2520inspiration%252C%2520news%2520and%2520ideas.%2520And%2520I%2520look%2520forward%2520to%2520meeting%2520up%2520with%2520fellow%2520identirati%2520like%2520Ian%252C%2520Mark%2520and%2520of%2520course%252C%2520the%2520good%2520folks%2520fr';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%26amp%3Btitle%3DFollow%2520me%2520at%2520Catalyst%26amp%3Bnotes%3DI%2527ll%2520be%2520at%2520the%2520Catalyst%2520conference%2520next%2520week%252C%2520looking%2520to%2520share%2520and%2520learn.%2520I%2520expect%2520Catalyst%2520to%2520be%2520the%2520usual%2520source%2520of%2520inspiration%252C%2520news%2520and%2520ideas.%2520And%2520I%2520look%2520forward%2520to%2520meeting%2520up%2520with%2520fellow%2520identirati%2520like%2520Ian%252C%2520Mark%2520and%2520of%2520course%252C%2520the%2520good%2520folks%2520fr';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%26amp%3Btitle%3DFollow%2520me%2520at%2520Catalyst';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%26amp%3Bh%3DFollow%2520me%2520at%2520Catalyst';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DFollow%2520me%2520at%2520Catalyst%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html%2520Follow%2520me%2520at%2520Catalyst';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DFollow%2520me%2520at%2520Catalyst%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Ffollow-me-at-catalyst.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/06/follow-me-at-catalyst.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Concordia tackles Entitlements and Policy Management</title>
		<link>http://blog.talkingidentity.com/2008/06/concordia_tackles_entitlements.html</link>
		<comments>http://blog.talkingidentity.com/2008/06/concordia_tackles_entitlements.html#comments</comments>
		<pubDate>Wed, 11 Jun 2008 01:49:21 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Burton Catalyst Conference]]></category>
		<category><![CDATA[BurtonGroupCatalyst08]]></category>
		<category><![CDATA[Entitlement Management]]></category>
		<category><![CDATA[Identity Services]]></category>
		<category><![CDATA[Project Concordia]]></category>

		<guid isPermaLink="false">http://talkingidentity.com/blog/?p=105</guid>
		<description><![CDATA[Burton Group&#8217;s Catalyst Conference is coming up at the end of the month, which means that the work going on in the identity management world kicked up a few notches last month. One of the things that is becoming a fixture at Catalyst is a meeting of the folks involved in Project Concordia. Anyone who [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.catalyst.burtongroup.com/NA08/ConferenceElements.html"><img src="http://blog.talkingidentity.com/wp-content/uploads/2008/07/catalystlogo08.jpg" alt="" align="right" /></a>Burton Group&#8217;s <span style="font-weight: bold;">Catalyst Conference</span> is coming up at the end of the month, which means that the work going on in the identity management world kicked up a few notches last month. One of the things that is becoming a fixture at Catalyst is a meeting of the folks involved in Project Concordia. Anyone who reads my blog knows that I am <a href="http://blogs.oracle.com/talkingidentity/search/?q=Concordia&amp;searchThisSiteOnly=true">a big supporter of their efforts</a> to bring real-world use cases to bear on the creation of practical solutions.</p>
<p>This year, their session will be focused on the area of <a href="http://projectconcordia.org/index.php/Main_Page#Policy_and_Entitlements_Management">entitlement and policy management</a>. If you are going to be at Catalyst, it is a great way to spend a day, listening to representatives from companies like Boeing, Cisco, Micron and The US Army share their<br />
insights, experiences and requirements for standards based policy and<br />
entitlement management.</p>
<p>Unfortunately, I won&#8217;t be getting into San Diego in time to attend, but Prateek Mishra from Oracle will be there, and of course, Roger Sullivan will be leading the charge as the host. It&#8217;s free to attend, all you have to do is register <a href="http://projectconcordia.org/index.php/Policy_and_Entitlements_Management_workshop_register">here</a>. Do it, and let me know what you learn.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/burton-catalyst-conference" rel="tag">Burton Catalyst Conference</a>, <a href="http://blog.talkingidentity.com/tag/burtongroupcatalyst08" rel="tag">BurtonGroupCatalyst08</a>, <a href="http://blog.talkingidentity.com/tag/entitlement-management" rel="tag">Entitlement Management</a>, <a href="http://blog.talkingidentity.com/tag/identity-services" rel="tag">Identity Services</a>, <a href="http://blog.talkingidentity.com/tag/project-concordia" rel="tag">Project Concordia</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%26amp%3Btitle%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management%26amp%3Bbodytext%3DBurton%2520Group%2527s%2520Catalyst%2520Conference%2520is%2520coming%2520up%2520at%2520the%2520end%2520of%2520the%2520month%252C%2520which%2520means%2520that%2520the%2520work%2520going%2520on%2520in%2520the%2520identity%2520management%2520world%2520kicked%2520up%2520a%2520few%2520notches%2520last%2520month.%2520One%2520of%2520the%2520things%2520that%2520is%2520becoming%2520a%2520fixture%2520at%2520Catalyst%2520is%2520a%2520meeting%2520of%2520';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%26amp%3Bt%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%26amp%3Btitle%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%26amp%3Btitle%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management%26amp%3Bannotation%3DBurton%2520Group%2527s%2520Catalyst%2520Conference%2520is%2520coming%2520up%2520at%2520the%2520end%2520of%2520the%2520month%252C%2520which%2520means%2520that%2520the%2520work%2520going%2520on%2520in%2520the%2520identity%2520management%2520world%2520kicked%2520up%2520a%2520few%2520notches%2520last%2520month.%2520One%2520of%2520the%2520things%2520that%2520is%2520becoming%2520a%2520fixture%2520at%2520Catalyst%2520is%2520a%2520meeting%2520of%2520';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%26amp%3Btitle%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management%26amp%3Bnotes%3DBurton%2520Group%2527s%2520Catalyst%2520Conference%2520is%2520coming%2520up%2520at%2520the%2520end%2520of%2520the%2520month%252C%2520which%2520means%2520that%2520the%2520work%2520going%2520on%2520in%2520the%2520identity%2520management%2520world%2520kicked%2520up%2520a%2520few%2520notches%2520last%2520month.%2520One%2520of%2520the%2520things%2520that%2520is%2520becoming%2520a%2520fixture%2520at%2520Catalyst%2520is%2520a%2520meeting%2520of%2520';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%26amp%3Btitle%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%26amp%3Bh%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html%2520Concordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DConcordia%2520tackles%2520Entitlements%2520and%2520Policy%2520Management%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2008%252F06%252Fconcordia_tackles_entitlements.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2008/06/concordia_tackles_entitlements.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
