Sun Identity Auditor addresses regulatory compliance

Opinion
Feb 2, 20052 mins

* Sun prepares Identity Auditor for launch in March

Last issue, I shared with you the fearless forecasts of Sara Gates, Sun’s Vice President of Identity, who gave us her predictions for the identity management space over the coming year.

What Gates really wanted to talk about, though, was compliance and auditing. She and Tamara Rezler, director of Identity Product Management at Sun double-teamed me to tell me about the upcoming release of Sun Identity Auditor.

Sun Identity Auditor, due out in early March, is a response to the needs of business to comply with the ever increasing number of government (and non-government) regulations affecting their companies. Compliance auditing isn’t brand new, but it has only been a separate product category since the middle of last year when this newsletter introduced you to auditing products from Thor, Courion and Oblix. The interesting thread here is that all the companies are best known for their work in the identity provisioning space. That’s also true of Sun. You may remember that the bulk of Sun’s identity management products (and the people who create, market and design them) were acquired a couple of years ago when Sun purchased Waveset – perhaps the premier provisioning company at the time.

Gates described compliance auditing as “provisioning on steroids.” That does appear to be the case, as the provisioning apps and services are the ones already touching all the business applications as well as the identity stores so they’re in an ideal place to know who is doing what to which data and when it is occurring.

Rezler told the story of one of Sun’s clients, a Fortune 50 transportation company, with 35 applications identified as needing compliance auditing for Sarbanes-Oxley regulations. It took the company 50 man-months to audit the apps. Using a beta version of Sun’s Identity Auditor, the same work was completed in a single day. That’s the power of provisioning technology when applied to regulatory compliance.

Gates assures me that Sun took the time to get auditing right rather than to rush to market simply because others had announced first. You’ll be able to judge how well by going to the RSA Security Conference in San Francisco later this month (https://2005.rsaconference.com/us/) where Identity Auditor will be on display, and where Gates’ will be delivering a session on its use and benefits. I’ll be there to see it and I hope you will be, as well.