There’s a new book and a new white paper I want to tell you about today, and both should be of interest to most of you.
First, on the cloud computing front, is a new white paper from the folks at Cyber-Ark called “Secure Your Cloud and Outsourced Business with Privileged Identity Management”. Note that you will need to register to download and view the paper — but it’s worth it.
According to PR guru Liz Campbell (from Fama PR on behalf of Cyber-Ark): “As outsourcing and the various instantiations of cloud-based services become increasingly essential to business operations, enterprises need to find ways to exercise governance over their critical assets and operations by extending control over privilege, both internally and externally. Service providers, for their part, must be prepared to address their clients’ privilege/risk management requirements to maintain a strong competitive position in the market. This paper reviews the ’10 steps for securing the extended enterprise’.”It talks (in depth) about privileged access, how it’s incorporated (or should be) in the cloud and how to discover if your cloud service provider understands the benefits and problems of privileged account management and privileged user management. Very useful.
On the book front, my good friend Vittorio Bertocci (he’s a senior architect evangelist with Microsoft) has just released “Programming Windows Identity Foundation”. This is the book that corporate programmers, and IT code dabblers, need to bring identity services into their home-grown services and applications. As the blurb states: “Get hands-on guidance designed to help you put the newest .NET Framework component — Windows Identity Foundation, the identity and access logic for all on-premises and cloud development — to work.” And that’s true.
Peter Kron, who’s a principal software developer on the Windows Identity Foundation team (and admits to keeping a well-thumbed proof copy on his desk) said this:
“In this book, Vittorio takes the reader through basic scenarios and explains the power of claims. He shows how to quickly create a simple claims-based application using WIF. Beyond that, he systematically explores the extensibility points of WIF and how to use them to handle more sophisticated scenarios such as Single Sign-on, delegation, and claims transformation, among others.
“Vittorio goes on to detail the major classes and methods used by WIF in both passive browser-based applications and active WCF services. Finally he explores using WIF as your applications move to cloud-based Windows Azure roles and RIA futures.”
If you’re working with identity, services and applications in a Windows environment you need this book.




