RSA looks to identity management

Opinion
Jan 22, 20073 mins

* On the eve of the RSA Conference

The RSA conference (Feb. 5-9 in San Francisco) is fast approaching, and that could be why I’ve just received Toffer Winslow’s identity management predictions for 2007. Winslow is VP, product management and marketing at RSA and he’s been busy, what with the conference upcoming and the acquisition by EMC recently closing, but he’s also a deliberate thinker – not one to rashly rush to judgment.

Winslow starts off with a prediction I hadn’t come across elsewhere. He feels that regulatory compliance programs have mostly been rolled out (or, at least, have started to be rolled out) and this year “many organizations will seek new ways to drive costs out of their overall compliance program. Currently, a large portion of many companies’ IT budgets are spent on labor-intensive methods of implementing and demonstrating compliance. Now that many organizations have demonstrated that they can meet the challenges of getting compliant, they will increasingly turn to new tools and processes to make their compliance efforts more cost-effective.” I will say that compliance programs do seem to have been implemented with less regard for cost than other identity management projects. This seems like a winner to me.

His second point regards the security of our data: “There is a growing realization that much of the spending on Information Security does relatively little to secure information itself. We have strong perimeters and secure corporate networks, but the reality is that information moves across these boundaries all the time into less secure (or completely insecure) environments. That same information is also subject to misuse by supposedly authorized users. In 2007, forward-thinking companies will start to adopt a new way of thinking about the challenge of securing information and will begin to develop strategies to protect information throughout its lifecycle and wherever it may travel, rather than focusing exclusively on perimeter, desktop, network, and/or identity security.” Sounds good, also, as I’ve said before that if the network no longer has a border then perimeter security is useless.

Finally, Winslow believes that the replacement of username/password authentication will accelerate this year as will the incidence of built-in security and identity rather than having it bolted-on as an afterthought. This should continue trends we saw last year with an accelerated rate of implementation and acceptance. Again, no argument from me.

I don’t think Toffer’s gone out on a limb here, but I do think he’s identified what will be happening in the corporate identity marketplace this year. And if you go to the RSA Conference and look at the trade show exhibits I think you’ll find many vendors in agreement.