<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity ! Nishant Kaushik&#039;s Look at the World of Identity Management &#187; Risk Management</title>
	<atom:link href="http://blog.talkingidentity.com/tag/risk-management/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Sat, 06 Mar 2010 03:32:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Rogue Accounts &#8211; Now Legally Challenging As Well</title>
		<link>http://blog.talkingidentity.com/2010/02/rogue-accounts-now-legally-challenging-as-well.html</link>
		<comments>http://blog.talkingidentity.com/2010/02/rogue-accounts-now-legally-challenging-as-well.html#comments</comments>
		<pubDate>Thu, 25 Feb 2010 19:46:35 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Audit & Compliance]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Deprovisioning]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Rogue Accounts]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=780</guid>
		<description><![CDATA[The impact that judicial courts are having on the world of tech has been in the news recently, whether it be an Italian judge ruling that content sites are liable for user uploaded content, or the class action lawsuit that Google Buzz faces over privacy issues. But another legal opinion was brought to my attention [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-782" title="legal_opinion" src="http://blog.talkingidentity.com/wp-content/uploads/2010/02/legal_opinion.jpg" alt="legal_opinion" width="204" height="200" />The impact that judicial courts are having on the world of tech has been in the news recently, whether it be <a href="http://bit.ly/dvWMlB" target="_blank">an Italian judge ruling</a> that content sites are liable for user uploaded content, or the <a href="http://bit.ly/aIuNuW" target="_blank">class action lawsuit that Google Buzz faces</a> over privacy issues. But another legal opinion was brought to my attention (thanks to <a href="http://twitter.com/ashmotiwala" target="_blank">Ashraf Motiwala</a>) that has implications for anyone trying to run an IdM program at an enterprise.</p>
<p>Kurt Johnson at Courion <a href="http://bit.ly/axJ7ji" target="_blank">blogged about a ruling</a> in a case (<a href="http://bit.ly/c1Yfo8" target="_blank">LVRC Holdings v. Brekka</a>) regarding wrongful use of enterprise accounts by an employee after being terminated. Read <a href="http://bit.ly/axJ7ji" target="_blank">his post</a> for a more detailed description of the case and the ruling, but it basically boils down to this: It is the employer&#8217;s responsibility to terminate access, and therefore the (terminated) employee did no wrong by using it since their access was not taken away.</p>
<p>I&#8217;ll stay out of the moral/ethical implications here, but what this means to a business is that making sure you take away access from your employees/contractors when they shouldn&#8217;t have it any more has suddenly become a much higher priority. Because if that person uses their accounts to do anything when you no longer want them to, it is not their fault, it&#8217;s yours. Ensuring prompt revocation of access was always good business practice, but now it becomes a business imperative because your legal protections (employee contract be damned) are greatly weakened.</p>
<p>When compliance became a bigger driver for IAM than IT efficiency, the approach to rolling out identity management projects did evolve to reflect this kind of thinking. But this case is as good a reason as any to reiterate what we have been preaching for years now &#8211; that your IAM deployment <span style="text-decoration: underline;">must</span> have both <em>proactive </em>and <em>detective controls</em> in place to ensure compliance. The proactive control in this instance is <strong>Deprovisioning</strong>, while the detective control is <strong>Attestation</strong>.</p>
<p>A common best practice staged approach (thought not the only one) to IAM projects that incorporates this idea is:</p>
<ul>
<li>Start by building up your <em>Who-Has-What</em> database (either in your <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-identity-manager/index.html" target="_blank">provisioning product</a> or in your <a href="http://www.oracle.com/us/products/middleware/identity-management/oracle-identity-analytics/index.html" target="_blank">identity governance product</a>)</li>
<li>Put in place a periodic attestation process to force review and sign-off of user access by those in the know (managers, application owners)</li>
<li>Create a deprovisioning project. Start off with manual processes that are triggered off your HR and Contractor management systems. Evolve to an automated process over time, which should include linking your attestation process to your deprovisioning process for handling rogue accounts</li>
<li>Start rolling out request-based provisioning for application access. Start with manual processes and evolve to automated processes in a phased manner</li>
<li>Start working on a role management project as a way to implement role-based provisioning. Again, follow a phased approach.</li>
</ul>
<p>The stakes in the IAM game just got a little bit harder. Make sure your project has these goals in its sights.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/attestation" rel="tag">Attestation</a>, <a href="http://blog.talkingidentity.com/tag/audit-compliance" rel="tag">Audit &amp; Compliance</a>, <a href="http://blog.talkingidentity.com/tag/compliance" rel="tag">Compliance</a>, <a href="http://blog.talkingidentity.com/tag/deprovisioning" rel="tag">Deprovisioning</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a>, <a href="http://blog.talkingidentity.com/tag/rogue-accounts" rel="tag">Rogue Accounts</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%26amp%3Btitle%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well%26amp%3Bbodytext%3DThe%2520impact%2520that%2520judicial%2520courts%2520are%2520having%2520on%2520the%2520world%2520of%2520tech%2520has%2520been%2520in%2520the%2520news%2520recently%252C%2520whether%2520it%2520be%2520an%2520Italian%2520judge%2520ruling%2520that%2520content%2520sites%2520are%2520liable%2520for%2520user%2520uploaded%2520content%252C%2520or%2520the%2520class%2520action%2520lawsuit%2520that%2520Google%2520Buzz%2520faces%2520over%2520priv';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%26amp%3Bt%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%26amp%3Btitle%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%26amp%3Btitle%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well%26amp%3Bannotation%3DThe%2520impact%2520that%2520judicial%2520courts%2520are%2520having%2520on%2520the%2520world%2520of%2520tech%2520has%2520been%2520in%2520the%2520news%2520recently%252C%2520whether%2520it%2520be%2520an%2520Italian%2520judge%2520ruling%2520that%2520content%2520sites%2520are%2520liable%2520for%2520user%2520uploaded%2520content%252C%2520or%2520the%2520class%2520action%2520lawsuit%2520that%2520Google%2520Buzz%2520faces%2520over%2520priv';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%26amp%3Btitle%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well%26amp%3Bnotes%3DThe%2520impact%2520that%2520judicial%2520courts%2520are%2520having%2520on%2520the%2520world%2520of%2520tech%2520has%2520been%2520in%2520the%2520news%2520recently%252C%2520whether%2520it%2520be%2520an%2520Italian%2520judge%2520ruling%2520that%2520content%2520sites%2520are%2520liable%2520for%2520user%2520uploaded%2520content%252C%2520or%2520the%2520class%2520action%2520lawsuit%2520that%2520Google%2520Buzz%2520faces%2520over%2520priv';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%26amp%3Btitle%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%26amp%3Bh%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html%2520Rogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DRogue%2520Accounts%2520-%2520Now%2520Legally%2520Challenging%2520As%2520Well%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2010%252F02%252Frogue-accounts-now-legally-challenging-as-well.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/02/rogue-accounts-now-legally-challenging-as-well.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Kuppinger Cole&#8217;s free Virtual Conference on Access Governance</title>
		<link>http://blog.talkingidentity.com/2009/12/kuppinger-coles-free-virtual-conference-on-access-governance.html</link>
		<comments>http://blog.talkingidentity.com/2009/12/kuppinger-coles-free-virtual-conference-on-access-governance.html#comments</comments>
		<pubDate>Tue, 08 Dec 2009 05:59:34 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Access Governance]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Identity Governance]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Separation of Duties]]></category>
		<category><![CDATA[SoD]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=731</guid>
		<description><![CDATA[The identity management analyst team over at Kuppinger Cole is organizing a free virtual conference on Enterprise Access Governance over the next two days (December 8 and 9). They&#8217;ll be putting forward their thoughts on what constitutes a complete access governance program, and what is the best, most optimal way to go about managing your [...]]]></description>
			<content:encoded><![CDATA[<p>The identity management analyst team over at Kuppinger Cole is organizing a <strong>free</strong> <a href="http://bit.ly/6Y3JKf" target="_blank">virtual conference on Enterprise Access Governance</a> over the next two days (December 8 and 9). They&#8217;ll be putting forward their thoughts on what constitutes a complete access governance program, and what is the best, most optimal way to go about managing your risk and security needs.</p>
<p>I&#8217;ll be taking part in two of their panel discussions, one on the topic of <strong>Separation of Duties</strong> (SoD), and the other on the topic of <strong>Attestation </strong>(or re-certification). Both are on <strong>Wednesday, December 9th</strong>:</p>
<ul>
<li><strong>How to Efficiently Implement SoD Controls: Which Level Works?</strong>
<ul>
<li>11am EST| 8am PST | 5pm CET</li>
</ul>
</li>
<li><strong>How to Start: Recertification or Active Access Controls First?</strong>
<ul>
<li>12pm EST | 9am PST | 6pm CET</li>
</ul>
</li>
</ul>
<p>Both panels will be focused on determining the right approach to rolling out these solutions, and where they should fit into your overall IdM program. This sometimes become a vendor driven conversation, so the opportunity for fireworks is always there.</p>
<p>Check out <a href="http://bit.ly/6Y3JKf" target="_blank">the conference</a> if you have time. It&#8217;s virtual, so you can do it from the comfort of your home/office (which is always good in the winter). And it&#8217;s free (you can&#8217;t beat that)! Should be an interesting discussion.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/access-governance" rel="tag">Access Governance</a>, <a href="http://blog.talkingidentity.com/tag/attestation" rel="tag">Attestation</a>, <a href="http://blog.talkingidentity.com/tag/conference" rel="tag">Conference</a>, <a href="http://blog.talkingidentity.com/tag/identity-governance" rel="tag">Identity Governance</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a>, <a href="http://blog.talkingidentity.com/tag/separation-of-duties" rel="tag">Separation of Duties</a>, <a href="http://blog.talkingidentity.com/tag/sod" rel="tag">SoD</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%26amp%3Btitle%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance%26amp%3Bbodytext%3DThe%2520identity%2520management%2520analyst%2520team%2520over%2520at%2520Kuppinger%2520Cole%2520is%2520organizing%2520a%2520free%2520virtual%2520conference%2520on%2520Enterprise%2520Access%2520Governance%2520over%2520the%2520next%2520two%2520days%2520%2528December%25208%2520and%25209%2529.%2520They%2527ll%2520be%2520putting%2520forward%2520their%2520thoughts%2520on%2520what%2520constitutes%2520a%2520complete%2520ac';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%26amp%3Bt%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%26amp%3Btitle%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%26amp%3Btitle%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance%26amp%3Bannotation%3DThe%2520identity%2520management%2520analyst%2520team%2520over%2520at%2520Kuppinger%2520Cole%2520is%2520organizing%2520a%2520free%2520virtual%2520conference%2520on%2520Enterprise%2520Access%2520Governance%2520over%2520the%2520next%2520two%2520days%2520%2528December%25208%2520and%25209%2529.%2520They%2527ll%2520be%2520putting%2520forward%2520their%2520thoughts%2520on%2520what%2520constitutes%2520a%2520complete%2520ac';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%26amp%3Btitle%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance%26amp%3Bnotes%3DThe%2520identity%2520management%2520analyst%2520team%2520over%2520at%2520Kuppinger%2520Cole%2520is%2520organizing%2520a%2520free%2520virtual%2520conference%2520on%2520Enterprise%2520Access%2520Governance%2520over%2520the%2520next%2520two%2520days%2520%2528December%25208%2520and%25209%2529.%2520They%2527ll%2520be%2520putting%2520forward%2520their%2520thoughts%2520on%2520what%2520constitutes%2520a%2520complete%2520ac';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%26amp%3Btitle%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%26amp%3Bh%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html%2520Kuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DKuppinger%2520Cole%2527s%2520free%2520Virtual%2520Conference%2520on%2520Access%2520Governance%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F12%252Fkuppinger-coles-free-virtual-conference-on-access-governance.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/12/kuppinger-coles-free-virtual-conference-on-access-governance.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Executive IdM Session at OpenWorld: It&#8217;s All About Managing Risk</title>
		<link>http://blog.talkingidentity.com/2009/10/executive-idm-session-at-openworld-its-all-about-managing-risk.html</link>
		<comments>http://blog.talkingidentity.com/2009/10/executive-idm-session-at-openworld-its-all-about-managing-risk.html#comments</comments>
		<pubDate>Thu, 29 Oct 2009 18:13:24 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Identity Assurance]]></category>
		<category><![CDATA[Identity Controls]]></category>
		<category><![CDATA[OOW09]]></category>
		<category><![CDATA[Oracle OpenWorld]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=698</guid>
		<description><![CDATA[One of the things I did at OpenWorld this year was attend an Executive IdM Session that brought together folks from the IdM team and some of our best customers to share information and talk about the future direction of identity management at Oracle. It was an interesting gathering with lots of good discussion that [...]]]></description>
			<content:encoded><![CDATA[<p>One of the things I did at OpenWorld this year was attend an <strong>Executive IdM Session</strong> that brought together folks from the IdM team and some of our best customers to share information and talk about the future direction of identity management at Oracle. It was an interesting gathering with lots of good discussion that resulted in the session running well over its allotted time of 3 hours. As you can see from the picture below, it was a full room (what you don&#8217;t see is those of us who had to stand in the peanut gallery at the back of the room).</p>
<p><a href="http://img169.imageshack.us/my.php?image=nt6.jpg"><img class="alignnone" title="Executive IdM Session" src="http://img169.imageshack.us/img169/5779/nt6.jpg" alt="" width="640" height="480" /></a></p>
<p>The session had a nice flow to it, starting with a vendor presentation (Oracle, of course), followed by an analyst presentation (Bob Blakley and Lori Rowland from the Burton Group) and concluding with a customer presentation (our old friend Ramin Safai from Barclays Capital). Getting to discuss identity management from all points of view was quite a valuable exercise, and I gleaned lots of useful nuggets.</p>
<h3>Security Inside Out</h3>
<p><a href="http://www.oracle.com/security"><img class="alignright size-full wp-image-704" title="Security Inside Out" src="http://blog.talkingidentity.com/wp-content/uploads/2009/10/SecurityInsideOut.jpg" alt="Security Inside Out" width="200" height="102" /></a>Amit Jasuja (who heads up the Identity Management team at Oracle) kicked off the day by talking about &#8220;<strong>Security Inside Out</strong>&#8220;, Oracle&#8217;s new message on putting together a complete security practice by bringing together <em>Database Security</em>, <em>Identity Management</em> and <em>Information Rights Management</em>. Weaving all of these elements together allows an enterprise to get a complete handle on the nature of their security risk across all tiers &#8211; database, middleware and application &#8211; and in all contexts &#8211; data at rest or in motion, internal users vs. external users, and so on. This led to a lot of discussion on moving towards risk-based identity management, which can be more adaptive to an enterprise&#8217;s needs and allow identity management to be a business enabler, not a hindrance.</p>
<p><img class="alignleft size-full wp-image-709" title="breakglass" src="http://blog.talkingidentity.com/wp-content/uploads/2009/10/breakglass.jpg" alt="breakglass" width="200" height="107" />One of the concepts I particularly liked was using identity management to enable &#8220;<strong>Break The Glass</strong>&#8221; scenarios that allow for contextual security decisions. In such a scenario, a user who ordinarily does not have access is allowed to get access but with added controls (like heightened audit, approval and attestation) to address the unique, emergency-like situation that presents itself. Being able to adapt to sensitive contextual situations without sacrificing on security and compliance is a powerful message that resonates in the enterprise world. Another topic that proved fertile for conversation was for risk-based IdM to leverage One-Time Passwords delivered via SMS or over land-line phones in order to implement higher levels of identity assurance (LOA). As two-factor authentication goes, enterprises increasingly view this as an attractive way to increase levels of assurance without having to invest in tokens and biometrics.</p>
<h3>Complete Security</h3>
<p>The Burton Group team talked about the state of identity management in the market today, especially emerging trends and hot-button topics. Lori validated <a href="http://bit.ly/2S0Ren">my observation</a> that cloud computing is going to have a huge impact on the future of identity management, and gave a nice shout out to <a href="http://bit.ly/3AqANC">my OpenWorld session</a> on the topic. One of the interesting takeaways from their talk was this point that Bob made about achieving <strong>complete security</strong>: An enterprise needs to have <em>preventive controls</em> that allow business to be conducted as usual but flush the bad guys into the open, where <em>detective controls</em> can identify them and their activities, which would then allow <em>responsive controls</em> (aka the cops) to take action.</p>
<h3>Down In The Trenches</h3>
<p>Ramin then gave a customers perspective on implementing identity management &#8211; from &#8220;down in the trenches&#8221;, as he called it. There were a lot of good lessons in his talk &#8211; about scoping the project correctly and dividing it into small, achievable mini projects that demonstrate ROI, about the processes and architecture they put in place to ensure success of the project, and some of the achievements they had with their IdM implementation, especially when Barclays acquired Lehman Brothers. One of the major points made in the room during discussion was that security within the enterprise needs to be driven top down by an &#8220;Executive Governance Board&#8221; in order to achieve  consistency and completeness. It cannot be done piecemeal at the IT level.</p>
<p>I love taking part in sessions like these, as it is great to be able to hear so many different perspectives. And thanks to Greg Belanger from the Apollo Group for giving me a shout out during the analyst discussion on Oracle&#8217;s differentiators in the identity management area. The point he was making about Oracle demonstrating vision in IdM is an important one that we are very serious about here, and I am glad to be a small part of that.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/identity-assurance" rel="tag">Identity Assurance</a>, <a href="http://blog.talkingidentity.com/tag/identity-controls" rel="tag">Identity Controls</a>, <a href="http://blog.talkingidentity.com/tag/oow09" rel="tag">OOW09</a>, <a href="http://blog.talkingidentity.com/tag/oracle-openworld" rel="tag">Oracle OpenWorld</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a></p>


Share This:


	<a rel="nofollow" id="twitter" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%3Fstatus%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%2520-%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="digg" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bbodytext%3DOne%2520of%2520the%2520things%2520I%2520did%2520at%2520OpenWorld%2520this%2520year%2520was%2520attend%2520an%2520Executive%2520IdM%2520Session%2520that%2520brought%2520together%2520folks%2520from%2520the%2520IdM%2520team%2520and%2520some%2520of%2520our%2520best%2520customers%2520to%2520share%2520information%2520and%2520talk%2520about%2520the%2520future%2520direction%2520of%2520identity%2520management%2520at%2520Oracle.';" title="Digg"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" id="facebook" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Bt%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="Facebook"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a>
	<a rel="nofollow" id="stumbleupon" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="StumbleUpon"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" id="google" href="javascript:window.location='http%3A%2F%2Fwww.google.com%2Fbookmarks%2Fmark%3Fop%3Dedit%26amp%3Bbkmk%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bannotation%3DOne%2520of%2520the%2520things%2520I%2520did%2520at%2520OpenWorld%2520this%2520year%2520was%2520attend%2520an%2520Executive%2520IdM%2520Session%2520that%2520brought%2520together%2520folks%2520from%2520the%2520IdM%2520team%2520and%2520some%2520of%2520our%2520best%2520customers%2520to%2520share%2520information%2520and%2520talk%2520about%2520the%2520future%2520direction%2520of%2520identity%2520management%2520at%2520Oracle.';" title="Google Bookmarks"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow" id="identi.ca" href="javascript:window.location='http%3A%2F%2Fidenti.ca%2Fnotice%2Fnew%3Fstatus_textarea%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Identi.ca"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/identica.png" title="Identi.ca" alt="Identi.ca" class="sociable-hovers" /></a>
	<a rel="nofollow" id="del.icio.us" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bnotes%3DOne%2520of%2520the%2520things%2520I%2520did%2520at%2520OpenWorld%2520this%2520year%2520was%2520attend%2520an%2520Executive%2520IdM%2520Session%2520that%2520brought%2520together%2520folks%2520from%2520the%2520IdM%2520team%2520and%2520some%2520of%2520our%2520best%2520customers%2520to%2520share%2520information%2520and%2520talk%2520about%2520the%2520future%2520direction%2520of%2520identity%2520management%2520at%2520Oracle.';" title="del.icio.us"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" id="reddit" href="javascript:window.location='http%3A%2F%2Freddit.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Btitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="Reddit"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" id="technorati" href="javascript:window.location='http%3A%2F%2Ftechnorati.com%2Ffaves%3Fadd%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Technorati"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow" id="newsvine" href="javascript:window.location='http%3A%2F%2Fwww.newsvine.com%2F_tools%2Fseed%26amp%3Bsave%3Fu%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%26amp%3Bh%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="NewsVine"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/newsvine.png" title="NewsVine" alt="NewsVine" class="sociable-hovers" /></a>
	<a rel="nofollow" id="slashdot" href="javascript:window.location='http%3A%2F%2Fslashdot.org%2Fbookmark.pl%3Ftitle%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Burl%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="Slashdot"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>
	<a rel="nofollow" id="techmeme" href="javascript:window.location='http%3A%2F%2Ftwitter.com%2Fhome%2F%3Fstatus%3Dtip%2520%40Techmeme%2520http%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html%2520Executive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk';" title="Suggest to Techmeme via Twitter"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/techmeme.png" title="Suggest to Techmeme via Twitter" alt="Suggest to Techmeme via Twitter" class="sociable-hovers" /></a>
	<a rel="nofollow" id="email" href="javascript:window.location='mailto%3A%3Fsubject%3DExecutive%2520IdM%2520Session%2520at%2520OpenWorld%253A%2520It%2527s%2520All%2520About%2520Managing%2520Risk%26amp%3Bbody%3Dhttp%253A%252F%252Fblog.talkingidentity.com%252F2009%252F10%252Fexecutive-idm-session-at-openworld-its-all-about-managing-risk.html';" title="E-mail this story to a friend!"><img src="http://blog.talkingidentity.com/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/10/executive-idm-session-at-openworld-its-all-about-managing-risk.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
