Skip Links

IETF explores new working group on identity management in the cloud

Cisco, SalesForce, Google among the backers of SCIM protocol for cloud-to-cloud provisioning

By , Network World
March 09, 2012 06:09 AM ET

Network World - Proponents of a common scheme for managing user identity in cloud-based applications will pitch their idea to the Internet's premier standards-setting body at a meeting in Paris later this month.

A specification already exists for Simple Cloud Identity Management (SCIM) that is supported by security software vendors including Cisco, Courion, Ping Identity, UnboundID and SailPoint. SCIM also has support from key cloud vendors, including Salesforce, Google and VMware.

JOBS: Big Data creating big career opportunities for IT pros

At issue is whether SCIM will become an IETF-approved working group and eventually an industry standard.

The IETF is hosting a meeting to discuss the proposed SCIM working group on March 29. In January, the IETF created a mailing list to discuss SCIM.

Proponents of SCIM say the protocol will make it easier for companies to control access to data stored in popular cloud-based applications like Salesforce, Workday, Taleo, Box and others.

Background: Identity management in the cloud emerges as hot-button issue for CIOs

Gartner backs the idea of SCIM as a simpler method of provisioning and de-provisioning employees from cloud applications - a process that's currently handled manually in most corporations. Mark Diodati, a research vice president with Gartner, wrote in late February "it appears that SCIM remains on track."

One vendor that's a strong proponent of SCIM is UnboundID, which sells identity management infrastructure software for service providers.

"There is no meaningful way to sling identities from cloud to cloud or from cloud to premises applications," explained UnboundID's CEO Steve Shoaff. "UnboundID is one of the only vendors shipping a commercial version that allows you to broadcast SCIM events and receive SCIM events. It's a modern protocol and a way to share identities between cloud providers. We're building our entire portfolio around SCIM to really build the identity economy."

Proponents say that what's good about SCIM compared with previous identity standards such as SPML is that SCIM is lightweight, it doesn't try to do too many functions, and it uses a Web services approach.

The alternative to SCIM is the proliferation of proprietary APIs for each cloud application. This situation requires security software vendors like Courion and SailPoint to create custom connectors to provision each cloud-based application.

Instead, SCIM would provide a standard way to move identity data from premises-based to cloud applications and from one cloud application to another.

"We're seeing a lot of interest" in SCIM, says Patrick Harding, CTO of Ping Identity. "We haven't had strong standards in that space. All the vendors developed their own APIs. That's where we've been working for the last year with all the major [software-as-a-service] vendors to standardize on an API mechanism to automate the account management."

More: 5 signs you’ve lost control over your cloud apps

Version 1.0 of the SCIM specification was approved in December.

Our Commenting Policies
Latest News
rssRss Feed
View more Latest News