<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Alwyn Van Niekerk &#187; IDM</title>
	<atom:link href="http://www.alwynvanniekerk.com/tag/idm/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.alwynvanniekerk.com</link>
	<description></description>
	<lastBuildDate>Tue, 26 Jan 2010 19:44:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Identity Management Solution</title>
		<link>http://www.alwynvanniekerk.com/2008/the-identity-management-solution/</link>
		<comments>http://www.alwynvanniekerk.com/2008/the-identity-management-solution/#comments</comments>
		<pubDate>Mon, 19 May 2008 10:00:26 +0000</pubDate>
		<dc:creator>Alwyn</dc:creator>
				<category><![CDATA[IDM]]></category>
		<category><![CDATA[Tech Leader]]></category>

		<guid isPermaLink="false">http://www.alwynvanniekerk.com/?p=40</guid>
		<description><![CDATA[In my first article I described the requirement for an Identity management (IdM) solution. In this article I will highlight some of the ways in which a properly implemented IdM solution can meet those requirements.
One of the very first deliverables in an IdM project is to establish the single view of an identity. Your IdM [...]]]></description>
			<content:encoded><![CDATA[<p>In my first <a href="http://www.alwynvanniekerk.com/?p=38" target="_blank">article</a> I described the requirement for an Identity management (IdM) solution. In this article I will highlight some of the ways in which a properly implemented IdM solution can meet those requirements.</p>
<p>One of the very first deliverables in an IdM project is to establish the single view of an identity. Your IdM solution will integrate with all the authoritative sources for each identity attribute and bring them together in a central location to provide a single view of all the identities within your organization.</p>
<p>With the single view established your IdM solution will ensure that it remains consistent across the organization by syncing all relevant changes to all the interested systems. Once the single view of an identity becomes consistent across the organization the entire identity life cycle becomes extremely efficient.</p>
<p>New users are only captured once in the system and all changes will be propagated automatically, or by using workflow processes where approval is required to ensure that the new user has everything they need (pc, desk, telephone, access rights, accounts, etc) to start working on the very first day they arrive for duty.</p>
<p>A good IdM solution will provide a user self-service facility, enabling the user to eliminate their interactions with support staff throughout the change phase of the life cycle. Statistics prove that roughly 40% of all help desk calls are password related, and a self service facility will enable the users to reset their passwords themselves in a secure, authenticated manner without involving the help desk staff &#8211; thereby greatly reducing the help desk load.</p>
<p>Once the user hands in their resignation (or gets fired) the IdM solution will ensure that all accounts are disabled and deleted where required, and can integrate with your asset management systems to ensure that all equipment used by the staff will be collected and taken back to the stores. Not only does this reduce the security risk of dormant accounts, but also enables greater asset management by ensuring that everybody stays in the loop.</p>
<p>Legislative requirements around auditing are increasing and most good IdM solutions will provide end-to-end auditing straight out the box, with a select few solutions providing the capability to audit the auditor, giving you complete visibility of the changes that effect the identities and their security profiles in the organization. This will enable you to have clear visibility of the triggers that caused a user to have the access rights and privileges they have, and how they came about it.</p>
<p>The above are some of the benefits almost every organization can realize from implementing an IdM solution. In my next article I will discuss some of the pitfalls and problems you should be aware of when going through an IdM project.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alwynvanniekerk.com/2008/the-identity-management-solution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Case for Identity Management</title>
		<link>http://www.alwynvanniekerk.com/2008/the-case-for-identity-management/</link>
		<comments>http://www.alwynvanniekerk.com/2008/the-case-for-identity-management/#comments</comments>
		<pubDate>Wed, 14 May 2008 15:12:11 +0000</pubDate>
		<dc:creator>Alwyn</dc:creator>
				<category><![CDATA[IDM]]></category>
		<category><![CDATA[Tech Leader]]></category>
		<category><![CDATA[People & Process]]></category>

		<guid isPermaLink="false">http://www.alwynvanniekerk.com/?p=38</guid>
		<description><![CDATA[Identity management (IdM) has become a buzz phrase in the industry surrounded by more confusion than facts and experience. So what exactly is an identity and why do we need to manage it?
An identity consists of attributes describing a person — typically name, surname, ID number, email address, etc. IdM concerns itself with the management [...]]]></description>
			<content:encoded><![CDATA[<p>Identity management (IdM) has become a buzz phrase in the industry surrounded by more confusion than facts and experience. So what exactly is an identity and why do we need to manage it?</p>
<p>An identity consists of attributes describing a person — typically name, surname, ID number, email address, etc. IdM concerns itself with the management of these attributes of a person as it travels through a typical life cycle, in this example an employee in a company.</p>
<p>Consider the usual HR process when a person joins a new company. The person completes forms specifying his particulars, which will be captured into the HR system, which is typically not integrated with any other system. The form is then sent on to the PABX and Windows administrators to arrange the new employee’s phone, system account and email address — and so the process continues until the new employee can do their daily work activities.</p>
<p>This is the start of the identity life cycle, inevitably followed by change. People’s details change (e.g. surname changes) and typically employees are firstly oblivious of these multiple systems in which they exist, and secondly exactly which one of the weird IT guys to speak with to have their details updated. Given that these systems aren’t integrated, they have to repeat this process until they have finally updated all the systems.</p>
<p>In a company, most systems attach digital and physical access privileges to a person’s position and place in the company’s organisational structure. As people move around within a company and change position, there is an even bigger requirement to manage their access privileges &#8211; firstly by avoiding any security risks by removing the previous set of privileges that they no longer need, and secondly to assign their new access rights so that they experience no breaks in productivity.</p>
<p>Scaling up the above scenario to a company with thousands of employees and numerous stand–alone systems breeds a management and security nightmare with a complete lack of end–to–end traceability of the changes made to a person’s identity and security profile over time.</p>
<p>The end of this identity life cycle is when the employee resigns. All accounts, rights and privileges must be revoked immediately so as not to leave any dormant accounts in the systems which could potentially be used in a security breach. Data breaches are becoming more and more common and countries like the USA are moving to get legislation in place to hold the company accountable for these breaches.</p>
<p>The above example illustrates a very real scenario in most organisations today. IdM has never received the attention it requires to ensure the automated end–to–end management of these identities while providing full auditing and traceability required for numerous regulatory requirements, which is becoming a reality for almost all companies maintaining customer data.</p>
<p>In this article I’ve detailed a typical scenario that requires proper IdM focus. In my next article I will illustrate how IdM tools and technologies can address and successfully manage these everyday problems.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alwynvanniekerk.com/2008/the-case-for-identity-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2nd Annual Identity &amp; Access Management Forum</title>
		<link>http://www.alwynvanniekerk.com/2008/2nd-annual-identity-access-management-forum/</link>
		<comments>http://www.alwynvanniekerk.com/2008/2nd-annual-identity-access-management-forum/#comments</comments>
		<pubDate>Mon, 21 Apr 2008 18:36:19 +0000</pubDate>
		<dc:creator>Alwyn</dc:creator>
				<category><![CDATA[IDM]]></category>
		<category><![CDATA[Conference]]></category>

		<guid isPermaLink="false">http://www.alwynvanniekerk.com/?p=26</guid>
		<description><![CDATA[The morning started off with a session by Allison Singh from Novell SA. I&#8217;ve had a quite few interactions with Allison since I started using Novell products and he was as always on top of his game despite being seriously jet lagged. Interesting things mentioned today (from all the sessions):

 US laws being introduced that [...]]]></description>
			<content:encoded><![CDATA[<p>The morning started off with a session by Allison Singh from Novell SA. I&#8217;ve had a quite few interactions with Allison since I started using Novell products and he was as always on top of his game despite being seriously jet lagged. Interesting things mentioned today (from all the sessions):</p>
<ul>
<li> US laws being introduced that 	assigns responsibility to companies in the event of data theft. One of the trends stemming from this would be keeping a reduced identity footprint.</li>
<li> RBAC is becoming quite the trend. This is clearly an abstraction layer aimed at providing greater agility in an Identity and access management system. To me this loosely translates to entitlements in Novell speak &#8211; something I&#8217;ve built in from day 1.</li>
</ul>
<p>One topic I was &#8216;introduced&#8217; to today that has been lingering in my mind for the last while and which was perfectly brought to life today was the concept of end-to-end architecture. My primary interest being using security events from your authentication systems (a user swiping their access card at the building entrance) and using these as triggers to disable the specific user&#8217;s accounts until that user enters the building again.</p>
<p>This is very fine grained access control utilizing the IDM infrastructure but delivering very concrete benefits. Combining physical access control with your digital access control systems provides the complete end-to-end solution which eliminates the majority of potential security breaches (e.g. hijacking an unlocked PC when the user leaves their desk)</p>
<p>Another very interesting discussion today was using the IDM synchronization engine to administer business specific attributes which you won&#8217;t traditionally find in the classic IDM attribute set. Personally I&#8217;ve refused this practice as users are very quick to request something like this once they realize the efficiencies of a successful IDM implementation. I believe you&#8217;ll have to decide for yourself how far you want to go given your existing business application solution, but once your security events become input and triggers for business events then the line becomes very gray indeed.</p>
<p>There were quite a few delegates from Africa at the conference, and it was extremely interesting to hear the challenges faced by these private companies and government IT departments. Of particular interest was a discussion of the Botswana government, who also doubles as an ISP for all government institutions (schools included). You can only imagine how complicated the solution becomes with implementing identity and access management across such a distributed model.</p>
<p>It was obvious from today that a lot of people and companies are talking about doing IDM, but there are very few instances where a company has walked a 2 -3 year path with IDM and are willing to share the lessons learned. I had a few discussions with people who are investigating IDM and it&#8217;s clearly a chaotic landscape of new jargon and massive infrastructure which very few newcomers have managed to get their heads around. I&#8217;d guess that there are probably only just over a handful proper IDM solutions in South Africa at this point in time, but it&#8217;s growing and people are waking up to the need they all have but just didn&#8217;t quite know &#8211;  yet&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.alwynvanniekerk.com/2008/2nd-annual-identity-access-management-forum/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
