Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Identity Governance Framework sprints to the finish line

IETF completes market requirements documents for IGF
Security: Identity Management Alert By Dave Kearns , Network World , 07/30/2007
Kearns
Sign up for this newsletter now!

Setting a pace that the IETF and other slow-moving standards bodies could envy, the Liberty Alliance announced last week the completion of market requirements document (MRD) for the Identity Governance Framework (IGF). It also announced that development of technical specifications to meet use case requirements is now occurring both within Liberty's Technology Expert Group (TEG) and at openLiberty.org (home of open source tools to further the use of Liberty protocols).

The IGF, you may remember, was first proposed late last fall by Liberty Alliance member Oracle and turned over to the Liberty Alliance during the winter. For the IGF to complete the MRDs in less than six months is commendable. (The IETF can take years just deciding if they want to pursue a particular protocol.)

IGF is a programmatic framework designed to help organizations meet regulatory requirements such as the European Data Protection Initiative, Gramm-Leach-Bliley Act, PCI Security Standard and Sarbanes-Oxley. According to Liberty spokesman Russ DeVieu, “With the MRD now completed, work can progress rapidly on the creation of the technical specifications and open source implementations required to speed the development of standards-based end-to-end auditing and governance solutions.”

The framework defines what could be called a series of “contracts” between applications and sources of identity data. There are four key components of IGF:

* Client Attribute Requirement Markup Language (CARML) – an XML-based declarative contract defined by application developers that informs deployment managers and service providers about the attribute usage requirements of an application.

* Attribute Authority Policy Markup Language (AAPML) – a set of policy rules regarding the use of identity-related information from an identity source that allow these sources to specify constraints on use of provided data by consuming applications.

* CARML API – an API that makes it easier for developers to write applications that consume and use identity-related data in a way that conforms to policies set around the use of such information.

* Identity Service – a policy-secured service for accessing identity-related data from multiple identity sources.

You can download the IGF MRDs and view a Webcast review of the IGF developments on Aug. 15. Registration and more information about the Webcast, “An Overview of the Identity Governance Framework: Putting Privacy and Regulatory Compliance First”, is available at the Liberty Alliance Web site.

Recent Award: Verisign’s David Recordon was recently presented with the Google-O'Reilly Open Source Award as Best Strategist for his work on OpenID. Congratulations from all of us, David.

Editor's Note: Starting Aug. 13, this newsletter will be renamed "Security: Identity Management" to better reflect the focus of the newsletter. We thank you for reading Network World newsletters!

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

All you guys are fighting about is the fact you can reset the routers. This was childs point. He created...- Daniel

Join the Discussion