About Us

Read More >>

Briefs

Identity Crisis: 7 Steps to Better Identity Management

Ely, Adam | 05/06/10
 (0 ratings) | 1Comments  


Managing the access rights, identities and passwords of employees and other IT users has never been easy. In recent years, it's gotten more complicated as companies expand their use of outsourced services and software as a service.

As a result, IT has expanded the concept of federated identity management beyond the corporate walls and been left asking how best to provision, manage and revoke access, not just to enterprise and custom applications, but also third-party hosted apps?

Many IT managers ask this question after things have fallen apart--once they can no longer manage accounts, understand what users have access to and support logons of third-party services. A lot of heartache could be avoided by following the seven steps outlined in this report. This process will give you a deeper understanding of how identity management works in your IT environment, and what you can do to improve it.

These steps include: Identifying the technologies in your company that require identity management, where your users' accounts live and what your master authentication system is; evaluating whether you need a central authentication system; finding out what SaaS services are being used in your company; making sure you understand all workflows and determining how much IDM your organization can handle; and finally, picking a system if, indeed, that's what you need.

Table of Contents

    3 Author's Bio
    4 Executive Summary
    5 The Identity Management Challenge
    5 Figure 1: Permit External Assets on Network
    6 Know What You're Managing
    6 Federated IDM: What It Can Manage and Advantages
    7 Know Where All the Accounts Are
    8 Figure 2: State of Identity Management Use
    8 Evaluate a Central Authentication System
    9 Look Outward
    10 Figure 3: Number of Employee Authentication Factors
    11 Understand Workflows
    12 Figure 4: Flow Chart Example
    12 Know Your Limits
    13 Picking a System

About the Author

Research: Software Protection

Adam Ely is director of security for TiVo. As an InformationWeek Reports contributor, he has authored multiple research reports on data and code security. He previously led a software development group at Walt Disney Co., where he implemented secure coding standards and source code analysis processes.

Adam gained extensive experience with enterprise and cloud security while supporting applications and services for clients such as AmEx, Citi and Expedia as manager of information security with TRX. He has published numerous security vulnerabilities and papers and conducts security research with leading firms to advance threat analysis and protections.

Adam currently serves as a member of the Journal Editorial Review Committee for ISACA and sits on the advisory board for an information security consulting firm. Adam has released numerous application vulnerability advisories, authored and contributed to open source security applications, and is the co-author of the Center for Internet Security Tomcat Benchmark.

He holds an MBA from Florida State University; a BS in information technology from Capella University; and multiple certifications, including CISSP, CISA, NSA IAM and MCSE.

DId Novell get into the Identity Space after May 2010?Comment by rseepaulr3g Dec-13,2010 4:36:53 PMJust Wondering if these links appeared After May 2010http://www.novell.com/products/identitymanager/technical-information/http://www.novell.com/products/compliancemanagementplatform/http://www.novell.com/products/accessgovernancesuite/technical-information/Reply

Register Now Close

Making the right technology choices is a challenge for IT pros everywhere. Whether it’s sorting through vendor claims, justifying new projects or implementing new systems, there's no substitute for the help and guidance of experienced peers. InformationWeek Reports connects you with thousands of your peers. They’ll help you pick the right technologies, ask the right questions and avoid pitfalls. Registration includes:

  • Thousands of research reports that tell you why and how your peers are adopting emerging technologies. Key annual surveys track how technology use changes from year to year
  • Strategy sessions and best practice reports that help you chart a path for successful technology adoption
  • Salary surveys and professional development guides that help you find and improve your place in the market
  • All written by your most trusted source for information - your peers

Registration Already Registered? Login

Related Reports

So, you think you know who your real online friends are? You could be just a few short hops away from a cybercriminal in today's social networks.

The Seven Deadliest Social Networking Hacks

So, you think you know who your real online friends are? You could be just a few short hops away from a cybercriminal in today's social networks.

Continue Reading >>

Database activity monitoring helps eliminate blind spots.

Who's in Your Database?

Database activity monitoring helps eliminate blind spots.

Continue Reading >>

There's a storm of change brewing. For those charged with information security, the challenge is to maintain visibility and guide our organizations to a sane balance among cost, access and safety. In this report, we analyze results of our poll of more than 500 business technology professionals and explain how to minimize risk when a third party is managing your data or providing mission-critical services.

Research: Cloud Risk

There's a storm of change brewing. For those charged with information security, the challenge is to maintain visibility and guide our organizations to a sane balance among cost, access and safety. In this report, we analyze results of our poll of more than 500 business technology professionals and explain how to minimize risk when a third party is managing your data or providing mission-critical services.

Continue Reading >>

You can't measure what you can't see. So how is IT supposed to evaluate the risk of moving critical services or data into an opaque cloud?

Cloud Computing Risks

You can't measure what you can't see. So how is IT supposed to evaluate the risk of moving critical services or data into an opaque cloud?

Continue Reading >>

We've weathered years of stagnant budgets and personnel cuts. Could proof of a massive, sophisticated network of organized attackers formidable enough to drive Google out of China finally open management's eyes to just what it will take to protect our data in the coming decade?

Research: 2010 Strategic Security Survey

We've weathered years of stagnant budgets and personnel cuts. Could proof of a massive, sophisticated network of organized attackers formidable enough to drive Google out of China finally open management's eyes to just what it will take to protect our data in the coming decade?

Continue Reading >>

Enabling People and Organizations to Harness the Transformative Power of Technology

svn