A new-school way of monitoring identity management

Opinion
Nov 17, 20043 mins

* What links healthcare with identity management?

We’re looking at possibilities for standardizing the management of typical audit log data especially in the areas of authorization and authentication. It’s a scheme that was suggested to me by Deloitte & Touche’s Mark Ford in a conversation with me last month at the Digital ID World conference (see link below).

Ford broached the idea of a Simple Network Management Protocol (SNMP) for identity. Last issue, I present an idea from Ranjeet Vidwans of Thor Technologies who described a standard SNMP Management Information Base (MIB) for provisioning apps that could feed into existing SNMP monitors and consoles. It has the benefit of not needing modifications to either the identity stores or the applications and services that are provisioned while using the very mature technology of SNMP monitoring tools. Tentatively, we’ll call this the “old school” approach. That implies, of course, that there’s a “new school” approach – and there is.

The Healthcare Information and Management Systems Society (HIMSS) is the sponsor (along with the Radiological Society of North America and the American College of Cardiology) of Integrating the Healthcare Enterprise (IHE). IHE is a multi-year initiative that creates the framework for passing vital health information seamlessly – from application to application, system to system, and setting to setting – across the entire healthcare enterprise. IHE does not create new standards, but rather drives the adoption of standards to address specific clinical needs.

According to initiative member John Moehrke, “This year we profiled the need for Security Audit Logs to have a standardized format, well understood triggers, and centralized analysis. We were not satisfied with any standards in use at the time, so we had to encourage some standards work. In the end we produce an XML schema that describes the security event and published it as an RFC (RFC 3881).” That’s right – an IETF Request for Comment (RFC) – one of the oldest methods of establishing a computer standard, but using XML, one of the lynchpins of the ultra-modern “Web services” technology. Not a bad combination.

RFC 3881 uses the syslog protocol to transmit event-notification messages. As Moehrke sums it up: “In the end we end up with coded messages that can be centrally analyzed by people who do that for a living. Thus allowing us healthcare vendors to get back to saving lives.”

I wondered why I hadn’t heard of this initiative before this, and Moehrke admitted that there was a bit of push back from the more entrenched syslog community. Seems they feel that syslog should be short text lines suitable to be displayed directly to the user. Acording to Moehrke, “They don’t like our coded XML message, and don’t like its size. We have tried to get them to recognize that SYSLOG MTU limitations are unreasonable and unnecessary (a problem SNMP has as well).”

If you’re at all interested in a standardized way to monitor identity management, especially in terms of authorization and authentication for regulatory compliance issues, you should read RFC 3881. This might be something that an OASIS working group could be inspired by, or that any group working with Web services, SOAP and XML might consider adapting. As always, let me know your thoughts and I’ll try to facilitate the conversation.