* The cart before the horse
endif; ?>My friend Howard Ting, senior director, product management and marketing at Securent, had an interesting commentary on my recent newsletter about the path your identity management services should follow (see “The long road to identity services”). He wrote:
“Interestingly, the push to deploy [entitlement management] is coming as much from the application developers and line-of-business [LoB] owners as it is from the security and compliance departments. In fact, I believe this is the primary source of our difference in viewpoints. While I agree to do “enterprise-wide” EM may require provisioning and role management to be in place, many LoB owners and developers simply can’t wait for their enterprise security teams to get their act together. They have new applications or services to roll out (or existing ones that need to be retrofitted) and they are buying EM solutions to secure access to these applications faster, cheaper, and easier. In these cases, the existence of an enterprise provisioning or role management solution is clearly not a pre-requisite.”
This hadn’t occurred to me, and I’m troubled to hear it. The phrase “cart before the horse” does occur to me. Now, I’m not expecting that Securent (or Aveksa, Sailpoint, Jericho or any of their other competitors) would object to going into an organization which doesn’t have normalized and synchronized identities, an electronic provisioning workflow and at least the rudiments of a role management system. But I would expect that those in the organization charged with the identity management task would raise some issues.
I’m not saying that there couldn’t be a positive effect, but it does seem like installing gold-plated faucets before actually running the plumbing from the city’s water line. You could install an open tank on the roof to catch rainwater, then use gravity to draw the water down through tubing to your beautiful faucet, but you’d be subject to periodic outages (when it didn’t rain) and the “product” might be too dirty to use at other times.
Trying to install entitlement management without the necessary and sufficient prerequisites and precursors will more than likely end up costing you additional money, additional time (to do manually that which should be automated), and – possibly – additional security holes. It really isn’t worth it.
Upcoming Events:
* Digital Identity Systems Workshop, Sept. 20, Polytechnic University, Brooklyn, N.Y.RSA Conference, Oct. 22–24, London, U.K.Interop, Oct. 22–26, New York, N.Y.
*
*
Check the upcoming events calendar at the Identity Management Journal and let me know of any I’ve overlooked.




