Are we looking for network management for identity?

Opinion
Nov 3, 20043 mins

* What if software, apps and services had their own management information base for audit controls?

Last week I met with David Frogel and Deb Pappas from Courion, along with Mark Ford from Deloitte & Touche’s Enterprise Risk Services practice. We were talking about the recent joint agreement (which I mentioned last issue) to bring about a very close working relationship between the two organizations. In particular, Frogel talked about how Courion’s PasswordCourier and ComplianceCourier products brought a lot of value to D&T’s enterprise identity management offerings. Ford and Pappas, of course, just wanted to talk about the Red Sox. (That’s humor, folks. Really!)

In expanding on the benefits of the Courion offerings, Ford said that it was like “network management for identity.” I paused for a second or two, and then asked if he was suggesting that what we need is something like SNMP, traps, monitors and MIBs for identity. Alas, Ford isn’t an old network manager like I am, so he simply looked quizzical. But when I explained Simple Network Management Protocol (SNMP), trapping and Management Information Bases (MIB) he began to understand. (MIB is a database of managed objects accessed by network management protocols. An SNMP MIB is a set of parameters that an SNMP management station can query or set in the SNMP agent of a network device, such as a router.)

Much of the identity management activity these days involves regulatory compliance, logs and auditing. Reading through audit logs is brain-numbing activity. Companies such as Courion (with its ComplianceCourier), Thor and Oblix are enabling the automated searching of audit logs, as well as providing agents that audit services and applications on their own.

But suppose software, applications and services had their own “management information base” for audit controls. Who better to know what and how to audit than the vendor that creates the service or application?

Likewise, who better than the vendor to realize which activities should be trapped, flagged, logged and identified to security or compliance personnel? The MIB, though, would allow each organization to determine the prioritization of the trappable activities.

This would let identity management vendors, such as Courion, concentrate on building the hardened, secure management consoles needed to monitor and control the activities of users, apps and services to judge compliance and to signal problems.

This isn’t something that one vendor (or one newsletter writer, for that matter) can launch on its own. It’ll require cooperation from identity management vendors, as well as those whose products need to be monitored for regulatory compliance. Still, the need is great and the deadlines are near. Non-compliance can mean real penalties – up to and including jail time – for those who are covered by the regulations, which is just about everyone except subsistence farmers.

The IETF process takes too long. The OASIS method leaves much to be desired. Perhaps an ad-hoc group such as the Liberty Alliance is what’s needed. Not, I hasten to add, that Liberty should take on the task (it has a number of changes to assimilate as it is, which I’ll cover next week) but that a new group of vendors, regulated industries and software creators that need to be audited should come together and forge a standard.

I’ll come back to this in a couple of weeks to give you the time to offer your suggests, comments or criticisms. Let the e-mails roll!