Skip Links

Network World

  • Social Web 
  • Email 
  • Close

There's more to identity than security

Identity is a rich platform
Security: Identity Management Alert By Dave Kearns , Network World , 04/24/2006
Kearns
Sign up for this newsletter now!

Dave Kearns provides the information you need to evaluate, install and maintain your corporate identity management system.

  • Share/Email
  • Comment
  • Print

I'm feeling somewhat disillusioned because of some conversations I had last week, but before getting to that I have a follow-up to the last newsletter.

Last time, you'll recall, I was talking about the release of SPML 2 and commented that the Provisioning Services Technical Committee Web pages seemed a bit out of date. I did hear from the committee co-chair, BMC's Jeff Bohren, who pled "guilty as charged with not keeping our TC [technical committee] home page up-to-date. Raj Sohdi (the other co-chair) and I are working with OASIS to try to get that resolved." I'll keep my eye on it to make sure that happens!

Last week, I visited with Sai Allavarpu, director, product management and marketing of HP's identity and security management, and Jonathan Martin, chief marketing officer of PortWise. I also listened to Novell CEO, Jack Messman during the announcement of his company's acquisition of e-Security. What I heard from all three was what caused the disillusionment.

PortWise's Martin seemed to equate identity management with authentication. Messman called identity a "subset" of security. Allavarpu - who does understand identity and its uses - told me that he's hearing from customers that identity is simply a part of their security infrastructure. Even the group of "personal identity" evangelists known as the "Identity Gang" often seem to think that authentication is the be-all and end-all of identity.

You and I know that that's not the case and that identity is a rich platform not only for enabling security but also for enabling individualization and personalization of the complete online experience. Single sign-on isn't primarily about security; it's about ease of use and reduction of help desk expense. Federation deals with authentication, it's true, but only as a means of furthering ease of use between organizations and among their personnel. Provisioning is primarily facilitating a user's productivity from day one in the enterprise. And those are just the well-known uses of identity.

Just as good public relations people know exactly which stories I'd be interested in hearing - and, especially, which ones I wouldn't - so too do Web sites like Amazon, American Airlines, Land's End, the Sunnyvale Public Library, OpenTable.com, and even Google News know what things I'd be interested in and, hopefully, which ones I'm not interested in. It's all about knowing me, my preferences, my choices - my identity.

Dave Kearns is a consultant and editor of IdM, the Journal of Identity Management.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed