Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Compliance pushing identity management in new directions

Trend given rise to identity-based risk management, auditing and policy enforcement tools from vendors such as Aveksa, Sailpoint and Vaau
By John Fontana , Network World , 09/27/2007

SAN FRANCISCO – Compliance issues are moving the focus of identity management from administration of users and shifting it more toward access control and authorization to meet regulatory mandates.

The recognition of that shift was one of the highlights of this week’s Digital ID World conference, which is put on by Network World parent company IDG.

Identity management has not finished cutting its teeth on password synchronization, single sign-on, provisioning and privileges, but it is now more aligned with supporting access control, management, verification and authorization, according to Jamie Lewis, CEO of the Burton Group, who delivered a keynote presentation on the second day of the conference.

The evolution of identity
The identity management landscape is taking on a new focus as company's scramble to find tools to comply with regulatory mandates. Here's a comparative put together by the Burton Group that looks at the changing focus of identity over the years.

1995: Directory, White Pages, Synchronization, Attributes
2000: Password synchronization, Provisioning, Single Sign-on, Privileges
2007: Access control, management, verification, Authorization
Click to see: The evolution of identity

“Compliance has changed the landscape; it has changed enterprise identity management,” says Lewis. He says the foundation of identity management remains business processes and a supporting infrastructure but that the current trends suggest that users are focused on using those foundational elements for identity-based access control to systems and resources in accordance with company policies. In other words, to lock down access and log and audit such things as who is using their systems, when and what data they are accessing.

The trend has given rise to identity-based risk management, auditing and policy enforcement tools from vendors such as Aveksa, Sailpoint and Vaau.

Some users say the changes are contributing to a slowdown in the evolution of identity technology, which they say is not living up to original expectations, especially around federation.

Compliance is part of the slowdown, users say, but it is also caused by new user-centric identity models, which are fostering questions around where the true value lies in identity projects.

“We’re still at the beginning four or five years after we started,” said one IT architect for a Fortune 500 company who requested anonymity. “Progress is slower than anticipated and there is a lot of uncertainty. By this time we thought federation would be commonplace.”

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

IBM spent all that money on a mass rollout of PGP Whole Disk Encryption, just when its discovered that...- Anonymous

Join the Discussion