Dot Net Factory aims to simplify SharePoint permission management; Uniloc strengthens SCADA systems

Opinion
Mar 5, 20083 mins

* Dot Net Factory releases EmpowerID Role Enforcer for SharePoint; Uniloc unveils StrongPoint client-server system for SCADA

Today I want to tell you about two new releases, from two different vendors. One covers a traditional market, the other a non-traditional one. Both, though, have to do with authentication and authorization with one designed to protect your data while the other works to protect the infrastructure.

Dublin, Ohio’s Dot Net Factory still cares about Active Directory and leveraging its features, a novel concept in a day when most vendors merely pay lip service to directory structures. That doesn’t keep Dot Net Factory from being forward looking, though. Just this week, in fact, it released EmpowerID Role Enforcer for Microsoft Office SharePoint Server 2007 as an optional component of the EmpowerID v4 Suite. Role Enforcer hopes to simplify SharePoint permission management by providing a single, centralized, management tool that consistently applies a unified roles-based access control (RBAC) framework. This flexible RBAC system leverages Active Directory (of course), but also HR systems, and other directories to control access and make policy decisions based upon a user’s current job function and/or the location in which they work. Role Enforcer’s aim is to simplify SharePoint permission management while delivering in three areas:

* Visibility – by controlling access and making policy decisions based upon a user’s current job function and “organizational zone.” by automating permission management as user’s change job duties or move between departments and locations in an organization. by providing instant enterprise-wide reporting and attestation for all levels of compliance and audit.

* Auditability –

* Enforcement –

Take a look and see if it can help you.

The more non-traditional market announcement came from Uniloc. You may remember its last visit to this space when I talked about pcandme.com, its entry into the “protecting minors online” niche (see “Identity, security – and children”). Now it wants to protect the traffic lights.

SCADA, Supervisory Control And Data Acquisition, is the generic term which covers many infrastructures devices – industrial processes including manufacturing, production, power generation, fabrication, and refining; infrastructure processes such as water treatment and distribution, wastewater collection and treatment, oil and gas pipelines, electrical power transmission and distribution, and large communication systems. A lot of the systems that we take for granted. They are monitored and controlled most often these days via the public IP network – the Internet. According to the U.S. National Research Council: “Today’s SCADA systems are built from off-the-shelf components and are based on operating systems that are known to be insecure. Compounding the difficulty is the fact that information about these vulnerabilities is so readily available.” Uniloc wants to do something about that.

Uniloc’s StrongPoint client-server system is designed to create security where none exists in these SCADA systems by enforcing positive device identity (through “fingerprinting” the device) over secure VPN networks. It’s an important step, but in an area that only a few of you have a direct interest in, so I’ll simply point you to more information at Uniloc’s Web site where you’ll find all the details.

Finally, a pointer to something I did. Each year, Network World awards “Category Breaker” accolades to products and services in various areas. This year’s Identity Category Breaker is discussed in a podcast featuring Editor Beth Schultz and myself. Enjoy!