Why have the BBB and ANSI set up an identity management group?

Kommentar
Sep 20, 20062 Minuten

* What's the point of the Identity Theft Prevention and Identity Management Standards Panel?

When you think about identity management, which standards body and trade group do you think would be at the forefront of activity – OASIS, Liberty Alliance, the IETF? How about the Better Business Bureau and the American National Standards Institute? Me neither.

Yet just last week the BBB and ANSI jointly announced the Identity Theft Prevention and Identity Management Standards Panel (IDSP). This new group is, according to the organizations: “…a cross-sector coordinating body whose objective is to facilitate the timely development, promulgation and use of voluntary consensus standards and guidelines that will equip and assist the private sector, government and consumers in minimizing the scope and scale of identity theft and fraud.” (Notice there’s no mention of identity management in that statement.)

The areas that the group will explore “…include managing access, storage and disposal of customer and employee data, personnel qualifications and training for the handling of sensitive data, criteria for selecting data contractors.” This will be done with a two-pronged attack:”First, it [IDSP] will endeavor to identify and catalogue in one place any existing, broadly-applicable identity theft and fraud prevention standards and guidelines. Second, it will identify areas where updated or new standards are needed. The panel’s recommendations for revised or additional standards shall serve as a call to action for further work by the standards development community.”Nowhere in any of the group’s documents is there anything related to identity management! There’s lots of talk about data management – protecting data files, that is. You know, those that keep getting stolen along with someone’s laptop.

But, as we’ve noted before, no case of so-called “identity theft” has ever been traced to an electronic data breach. None. The information needed to commit what is better called “identity fraud” – but is in actuality a verification failure – still comes mostly from old-fashioned dumpster diving, desk drawer snooping, and simple conversation with unwitting people. No amount of standards collating is going to fix that. The only thing a standards body could do is to find better ways to ensure that the validation process is managed more strictly by imposing more onerous terms on banks, credit card companies, public utilities, brokerages and anyone else who deals in money, securities or articles that have value. Now that’s something the BBB should be doing – policing its members about their validation processes.