* Webinar session highlights the need for a mix of authentication methods
I hope you had the opportunity to join me for the virtual identity conference last week. I hosted two great panels on Tuesday, and I’d like to talk about some of the issues they raised.
But first, I must apologize to those who tuned in on Wednesday hoping to hear my dulcet tones in a conversation with Kuppinger Cole’s Martin Kuppinger. Martin was there, so you got the best part of the discourse about enterprise simplified sign-on and how it could (and should) transform into a holistic authorization and authentication strategy. I, on the other hand, was at the middle of a “perfect storm”, a technological whirlpool getting sucked down deeper and deeper.
Somewhere between my computers (I tried four just to be sure) and gotomeeting.com some router decided we no longer needed to speak to each other. Try as we might (and Kuppinger Cole’s Levent Kara and Joerg Resch had lots of suggestions), there was no workaround. But once I’d abandoned the attempt (or, perhaps, because of the attempt) Microsoft Office decided to go on vacation. A number of rounds of repair, recover and re-install later (I’m writing this 36 hours after the event), I’ve at least got basic functionality back so I can write this (although Outlook is still hors de combat — Gmail to the rescue!).
All of the sessions were recorded so that you’ll be able to listen even if you weren’t there (and I will be listening to Kuppinger’s session) by going to the conference home page and choosing the session you wish to listen to. Click the “Watch Now” button to view the session.
In the session called “Versatile Authentication — One Layer of (Strong) Authentication” I was joined by Market Analyst Graham McCord from Entrust and Oracle Vice President Thomas Varghese. There wasn’t anything controversial in this session as we all agreed that stronger authentication, using a mix of methods, was needed by most organizations. We also agreed that authentication events need to be abstracted from applications into the “plumbing” of the network and that a standard for doing so needs to be developed. While we didn’t mention it during the discussion, the Liberty Alliance’s Identity Governance Framework (IGF) with its CARML (Client Attribute Requirement Markup Language) would be a good place to start on developing an authentication framework.
There were some interesting points raised in the “Provisioning and Access Governance Trends” session as well. I’ll get to those next time.
Upcoming Webinars of interest (from Journal of Identity Management):
Feb 24 — Assuring Access to Sensitive Data – Where IAM and DLP Meet
Feb 24 — Safe Side Compliance 201 CMR 17.00 Summit: A look at Massachusetts’ Mass Data Protection Act, which takes effect March 1.
Feb. 25 — The Power of Identity Management and Physical Security Integration
Feb. 25 — Addressing Cloud Security Challenges with Identity Management




