* Combining network security with physical security
endif; ?>I’ve often said that if a company could do one thing well, it would be a successful business. Of course, you need to leverage that one thing. Take Google, for example. At bottom it’s merely a search and catalog company but it has leveraged its search engine and cataloging skills so that Google permeates online life. In identity management, the same could be said of Imprivata.
Imprivata is justly famous for its OneSign appliance, a simplified sign-on (SSO) device that controls authentication and access. It does that very well. Now, though, it wants expand on that and has launched a full-scale effort to converge logical access (through the SSO device) with physical access (doors, buildings, etc.).
CEO Omar Hussain and VP of Marketing Communications Molly Galetto got on the phone with me recently to explain that after the company joined the Open Security Exchange (OSE) – a cross-industry forum dedicated to merging physical and IT security solutions throughout an enterprise – last fall it didn’t rest on its press release. It went full bore to implement a convergence solution. You can read more about this in Imprivata’s white paper, “Bridging the Great Divide: The Convergence of Physical and Logical Security”.
Imprivata isn‘t doing the physical security; that’s not its forte. Instead it’s partnering with just about every provider of electronic physical access to create a converged solution for its clients. That’s excellent leverage when you consider that most folks interested in converged solutions already have the physical security in place and probably wouldn’t want to have to replace all of their door locks just to make some administrator’s job easier.
While we were chatting about convergence, Hussain mentioned in passing something that was really impressive to me: OneSign will now support contextual authentication – it will pass the context of the authentication transaction (the who, when, where, how of the transaction) on to your rules engine which can then make decisions about access and authorization based on the context. For example, different access can be allowed to someone signing on from their desktop, their home machine or an Internet café. This is important if any of your users have access to sensitive or protected data.
Imprivata is successfully leveraging its strength to provide new services for its clients all built on its successful “engine.” Hussain is hoping it’s as successful for his company as it was for Google.




