<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5297101820232184490</id><updated>2011-11-07T10:46:54.935-08:00</updated><category term='Oracle Access Manager OAM Bio-Key Biometric Strong Authentication Tokens RSA Vasco Extended Identity Management Ecosystem'/><category term='Identity Access Governance Oracle Sun Simeio IdM Identity Management SaaS IdMaaS Cloud Security Services Symplified'/><category term='Oracle Daon Bio-Metric Public Sector Government'/><category term='Forrester PricewaterhouseCoopers PwC Rex Thorton Gary Loveland Bill Brenner CIO Magazine CISO CSO data security risk'/><category term='Cloud Appliance Data security Information security Privileged user management Baby New Year Ball Champagne Toast New Year Resolution Nasa Nebula Pentagon'/><category term='BeyondTrust Cyber-Ark Cloakware Symark Oracle Identity Access IAM Enterprise Security PowerKeeper Compliance Privileged Password PAM PUM Unix/Linux Databases IBM zSeries Mainframes AD/LDAP'/><category term='Novell Virtualization Security Network World Ellen Messmer Identity Management Provisioning DirXML'/><category term='Oracle Quatum Secure Physical Logical Security Provisioning Gartner Burton Fraud Identity Theft Microsoft SAP IBM HP Sun Siemens'/><category term='F5 OAM BigIp'/><category term='DLP Cloud Security DLP SaaS AV Symantec Vordel Sophos McAfee IRM Oracle End-point security desktop security antivirus malware'/><category term='ArcSight IdentityView Oracle Identity Manager OIM ESM SIEM'/><category term='IDology KBA Oracle Adaptive Access Manager OAAM'/><category term='Oracle Identity Management SaaS Software as a service cloud security  Simeio DirectAXs Wipro Managed Identity Service Symplified Enterprise On-Demand'/><category term='Inifinite Identities Network World Facebook Linkedin twitter  Bill Snyder CIO CSO Why'/><category term='Provisioning GoogleApps Cloud SOA Aegis Oracle Sun Identity Management IAM SOA Security Google SaaS'/><category term='Oracle Sun Identity Managament Access Management Identity Appliance'/><category term='Oracle Qualcomm State of Delaware Green Identity Management Access Management F5 Big-IP Load balancer Symantec DLP  11g OIF OID Directory Services'/><category term='Cloakware Priveleged User PAM PUM'/><category term='Cloud Security Government Public Sector Oracle IBM Google CA Space Camp Nasa Nebula Apps.gov Obama Navy CANES US Energy Magellan NBC G-Cloud UK EU Reservoir  Virtualization Canada Japan Kasumigaseki'/><category term='CA SiteMinder Oracle Access Manager IAM OAM Persistent Systems ORCL migration ROI Enterprise Security Web Single Sign-On'/><category term='Fraud Identity Theft statistics Hacker Des Powley Oracle 7 secrets'/><category term='Oracle PwC Deloitte Accenture Pricewaterhouse Data Security Identity DLP IDM IAM risk governance compliance'/><category term='Quova OAAM Access Fraud Adaptive geolocation'/><category term='Extended Identity Management Ecosystem Update'/><category term='Vordel SOA Cloud Service Broker Google Apps Amazon EC2'/><category term='Oracle IRM Symantec DLP 11g Data Loss Prevention DRM information rights management'/><category term='OAAM StrikeForce Adaptive Out-of-Band ProtectID Oracle Adaptive Access Manager'/><category term='Oracle Open World Liebsoft Priveleged Account Manager F5  Load Balancer Big-IP NetworkWorld'/><title type='text'>Infinite Identities</title><subtitle type='html'>Chronicling innovation and game changing developments in Enterprise Security through partnerships with Oracle and other industry leaders.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>35</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-921761482745423414</id><published>2010-06-17T12:24:00.000-07:00</published><updated>2010-06-17T12:25:41.583-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle Access Manager OAM Bio-Key Biometric Strong Authentication Tokens RSA Vasco Extended Identity Management Ecosystem'/><title type='text'>Giving Authentication the Finger</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: large;"&gt;Having recently broken the thumb of my dominant hand it has become painfully clear that thumbs/fingers are an intricate part of who we are and something we take everywhere … even when they are a big PAIN.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_gn9hq2pkgmk/TBp0ailCBWI/AAAAAAAAAIE/gJMSmS0yN9o/s1600/bio-key+sore-thumb.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" qu="true" src="http://1.bp.blogspot.com/_gn9hq2pkgmk/TBp0ailCBWI/AAAAAAAAAIE/gJMSmS0yN9o/s320/bio-key+sore-thumb.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-size: large;"&gt;&lt;strong&gt;Why bring it up?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Like many enterprise users, my corporate laptop comes equipped with a fingerprint scanner, and I have linked it to my desktop sign-on.&lt;/li&gt;&lt;li&gt;While the advantages to me were not obvious at first, losing the ability to authenticate this way makes me realize what a substantial usability advantage it is to me daily.&lt;/li&gt;&lt;li&gt;But the security advantages combined with cost savings on provisioning/replacing tokens is much greater.&lt;/li&gt;&lt;li&gt;Leveraging Oracle IdM &amp;amp; BIO-Key bio-metric authentication solutions offers Enterprise better security gives customers an substantially improved user experience. &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_gn9hq2pkgmk/TBp0stE4R4I/AAAAAAAAAIM/cnblTgmhhX0/s1600/biokey-logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="136" qu="true" src="http://3.bp.blogspot.com/_gn9hq2pkgmk/TBp0stE4R4I/AAAAAAAAAIM/cnblTgmhhX0/s200/biokey-logo.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;strong&gt;&lt;span style="font-size: large;"&gt;How Does it Help?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Tokens &amp;amp; Passwords have limitations &lt;/strong&gt;- Passwords have and token security policies have limitations are either ineffective or become a nightmare for both IT staff and users to manage from productivity and cost perspective. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Give me an Example &lt;/strong&gt;- The &lt;em&gt;&lt;a href="http://www.gwumc.edu/"&gt;George Washington Medical Center&lt;/a&gt; &lt;/em&gt;in Washington DC recognized that doctors and staff were becoming increasingly frustrated with having to remember and periodically reset their passwords in order to meet security requirements. So in May of 2007 the IT staff and Allscripts successfully integrated fingerprint identification software from BIO-key International into the Enterprise EHR Solution to protect access to patient medical records.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;What was the result? &lt;/strong&gt;- Privacy of patient records was vastly improved; Doctors quickly and conveniently now access needed information; System security is enhanced.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;How does it work? - &lt;/strong&gt;BIO-key International’s ID Director integrates with &lt;strong&gt;&lt;em&gt;&lt;a href="http://www.oracle.com/technology/products/id_mgmt/coreid_acc/index.html"&gt;Oracle Access Manager&lt;/a&gt;&lt;/em&gt;&lt;/strong&gt;&amp;nbsp; to enable user authentication to OAM protected Applications, based on fingerprint biometrics. This provides a more convenient, secure and cost effective alternative to passwords and tokens to establish an individual’s identity. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;For more information &lt;/strong&gt;- &lt;a href="http://www.bio-key.com/fingerprintbiometrics/ID_Director.asp"&gt;click here&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_gn9hq2pkgmk/TBp1VcaON_I/AAAAAAAAAIU/IxH3wFIMzgY/s1600/cut_finger.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" qu="true" src="http://4.bp.blogspot.com/_gn9hq2pkgmk/TBp1VcaON_I/AAAAAAAAAIU/IxH3wFIMzgY/s200/cut_finger.gif" width="187" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;strong&gt;&lt;span style="font-size: large;"&gt;What about Identity Theft?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;While it seems everyday in spy movies and gag shops, in reality cutting off someone’s finger and using it for authentication is far less likely to impact the Enterprise then tokens left in a taxi/plane.&lt;/li&gt;&lt;li&gt;Comparatively, the rises in traditional and emerging forms of identity theft highlight the current deficiencies of passwords and tokens used to establish user’s identity when accessing your databases and applications. &lt;/li&gt;&lt;li&gt;An article published in January, by the &lt;em&gt;&lt;a href="http://www.idtheftcenter.org/"&gt;Identity Theft Resource Center&lt;/a&gt;&lt;/em&gt; states “The meteoric rise in social media use has also created a launch pad for identity thieves.” &lt;/li&gt;&lt;li&gt;The article predicts an increase in ID theft crimes and victims over the next two years unless significant changes are made in information security. &lt;/li&gt;&lt;li&gt;The article goes on to say “Our most important asset is our identity. And we are functioning under a completely antiquated system of identification.” &lt;/li&gt;&lt;li&gt;BIO-key International’s ID Director for Oracle Access Manager Applications, based on fingerprint biometrics, provides a more convenient, secure and cost effective alternative to passwords and tokens to establish an individual’s identity. &lt;/li&gt;&lt;li&gt;For more information- &lt;a href="http://www.bio-key.com/fingerprintbiometrics/ID_Director.asp"&gt;click here&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;span style="font-size: large;"&gt;Learn more about Bio-Key ID Director for Oracle Access Manager visit &lt;/span&gt;&lt;a href="http://www.bio-key.com/fingerprintbiometrics/ID_Director.asp"&gt;&lt;span style="font-size: large;"&gt;the solution page&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-921761482745423414?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/921761482745423414'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/921761482745423414'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2010/06/giving-authentication-finger.html' title='Giving Authentication the Finger'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gn9hq2pkgmk/TBp0ailCBWI/AAAAAAAAAIE/gJMSmS0yN9o/s72-c/bio-key+sore-thumb.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-3156463939363129825</id><published>2010-03-12T14:22:00.000-08:00</published><updated>2010-03-12T14:22:38.547-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle PwC Deloitte Accenture Pricewaterhouse Data Security Identity DLP IDM IAM risk governance compliance'/><title type='text'>Leaky pipes, call a plumber.  Leaky data, call PwC &amp; Oracle</title><content type='html'>&lt;meta content="text/html; charset=utf-8" http-equiv="Content-Type"&gt;&lt;/meta&gt;&lt;meta content="Word.Document" name="ProgId"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Generator"&gt;&lt;/meta&gt;&lt;meta content="Microsoft Word 12" name="Originator"&gt;&lt;/meta&gt;&lt;link href="file:///C:%5CDOCUME%7E1%5Cbmozinsk%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml" rel="File-List"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CDOCUME%7E1%5Cbmozinsk%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx" rel="themeData"&gt;&lt;/link&gt;&lt;link href="file:///C:%5CDOCUME%7E1%5Cbmozinsk%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml" rel="colorSchemeMapping"&gt;&lt;/link&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:DontVertAlignCellWithSp/&gt;    &lt;w:DontBreakConstrainedForcedTables/&gt;    &lt;w:DontVertAlignInTxbx/&gt;    &lt;w:Word11KerningPairs/&gt;    &lt;w:CachedColBalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face	{font-family:Wingdings;	panose-1:5 0 0 0 0 0 0 0 0 0;	mso-font-charset:2;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:0 268435456 0 0 -2147483648 0;}@font-face	{font-family:Wingdings;	panose-1:5 0 0 0 0 0 0 0 0 0;	mso-font-charset:2;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:0 268435456 0 0 -2147483648 0;}@font-face	{font-family:Calibri;	panose-1:2 15 5 2 2 2 4 3 2 4;	mso-font-charset:0;	mso-generic-font-family:swiss;	mso-font-pitch:variable;	mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal	{mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-parent:"";	margin-top:0in;	margin-right:0in;	margin-bottom:10.0pt;	margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-fareast-font-family:Calibri;	mso-bidi-font-family:"Times New Roman";}a:link, span.MsoHyperlink	{mso-style-priority:99;	color:blue;	text-decoration:underline;	text-underline:single;}a:visited, span.MsoHyperlinkFollowed	{mso-style-noshow:yes;	mso-style-priority:99;	color:purple;	mso-themecolor:followedhyperlink;	text-decoration:underline;	text-underline:single;}.MsoChpDefault	{mso-style-type:export-only;	mso-default-props:yes;	font-size:10.0pt;	mso-ansi-font-size:10.0pt;	mso-bidi-font-size:10.0pt;	mso-ascii-font-family:Calibri;	mso-fareast-font-family:Calibri;	mso-hansi-font-family:Calibri;}@page Section1	{size:8.5in 11.0in;	margin:1.0in 1.0in 1.0in 1.0in;	mso-header-margin:.5in;	mso-footer-margin:.5in;	mso-paper-source:0;}div.Section1	{page:Section1;} /* List Definitions */ @list l0	{mso-list-id:47190068;	mso-list-type:hybrid;	mso-list-template-ids:-1935499212 2018805950 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l0:level1	{mso-level-start-at:0;	mso-level-number-format:bullet;	mso-level-text:•;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;	font-family:"Arial","sans-serif";	mso-fareast-font-family:Calibri;}@list l1	{mso-list-id:690422636;	mso-list-type:hybrid;	mso-list-template-ids:-577964430 2018805950 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l1:level1	{mso-level-start-at:0;	mso-level-number-format:bullet;	mso-level-text:•;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;	font-family:"Arial","sans-serif";	mso-fareast-font-family:Calibri;}@list l2	{mso-list-id:1253592148;	mso-list-type:hybrid;	mso-list-template-ids:-478663180 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l2:level1	{mso-level-number-format:bullet;	mso-level-text:;	mso-level-tab-stop:none;	mso-level-number-position:left;	text-indent:-.25in;	font-family:Symbol;}@list l3	{mso-list-id:1585919072;	mso-list-template-ids:-309841176;}@list l3:level1	{mso-level-number-format:bullet;	mso-level-text:;	mso-level-tab-stop:.5in;	mso-level-number-position:left;	text-indent:-.25in;	mso-ansi-font-size:10.0pt;	font-family:Symbol;}@list l4	{mso-list-id:2126120499;	mso-list-type:hybrid;	mso-list-template-ids:-1236767150 -1003343880 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l4:level1	{mso-level-start-at:3;	mso-level-number-format:bullet;	mso-level-text:;	mso-level-tab-stop:none;	mso-level-number-position:left;	margin-left:.75in;	text-indent:-.25in;	font-family:Symbol;	mso-fareast-font-family:Calibri;	mso-bidi-font-family:Arial;}ol	{margin-bottom:0in;}ul	{margin-bottom:0in;}--&gt;&lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt; /* Style Definitions */ table.MsoNormalTable	{mso-style-name:"Table Normal";	mso-tstyle-rowband-size:0;	mso-tstyle-colband-size:0;	mso-style-noshow:yes;	mso-style-priority:99;	mso-style-qformat:yes;	mso-style-parent:"";	mso-padding-alt:0in 5.4pt 0in 5.4pt;	mso-para-margin:0in;	mso-para-margin-bottom:.0001pt;	mso-pagination:widow-orphan;	font-size:10.0pt;	font-family:"Calibri","sans-serif";}&lt;/style&gt; &lt;![endif]--&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt; text-align: center;"&gt;&lt;span style="font-size: x-large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Enterprises are moving from “&lt;i style="color: red;"&gt;Who has access to what?&lt;/i&gt;” to “&lt;i style="color: red;"&gt;What are they doing with it?&lt;/i&gt;” &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt; text-align: center;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Data &amp;amp; Identity theft has a potentially enormous financial impact on the enterprise through damage to brand reputation, regulatory penalties, and competitive theft.&lt;span&gt;&amp;nbsp; &lt;/span&gt;But protecting against misuse of resources is an increasingly challenging issue in a world of Cloud Applications, globally dispersed teams, and networks open to multiple devices, contractors, and Web 2.0 applications.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: lime; line-height: normal; margin-bottom: 0.0001pt; text-align: center;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;"&lt;i&gt;A small leak can sink a great ship.&lt;/i&gt;" - Benjamin Franklin&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_gn9hq2pkgmk/S5q98g4aquI/AAAAAAAAAHk/W-qL20epQ4w/s1600-h/Plumber12.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_gn9hq2pkgmk/S5q98g4aquI/AAAAAAAAAHk/W-qL20epQ4w/s320/Plumber12.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Is this really a problem?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;u&gt;Trust me &lt;/u&gt;– According to &lt;a href="http://en.wikipedia.org/wiki/White_Hat"&gt;Wikipedia &lt;/a&gt;,      an Ethical Hacker, or White Hat is “the &lt;a href="http://en.wikipedia.org/wiki/Hero" title="Hero"&gt;&lt;span style="color: windowtext; text-decoration: none;"&gt;hero&lt;/span&gt;&lt;/a&gt;      or good guy, especially in computing slang, where it refers to an ethical      hacker or &lt;a href="http://en.wikipedia.org/wiki/Penetration_tester" title="Penetration tester"&gt;&lt;span style="color: windowtext; text-decoration: none;"&gt;penetration tester&lt;/span&gt;&lt;/a&gt; who focuses on      securing and protecting &lt;a href="http://en.wikipedia.org/wiki/Information_Technology" title="Information Technology"&gt;&lt;span style="color: windowtext; text-decoration: none;"&gt;IT&lt;/span&gt;&lt;/a&gt; systems.” While the concept is reassuring,      90% of test by White Hats succeed in getting sensitive information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;The FTC puts the annual business loss from ID/Data      Theft near $50 billion.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Over one-quarter      said the incident resulted in brand/reputation damage.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;With growing profits, sophisticated techniques, lagging      international laws, and the migration from a basement hobby to an      organized crime syndicate – this is an area of growing opportunity which      is increasingly hard to prosecute.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Identifying and protecting sensitive data requires a      deliberate process of understanding your existing risk and “plugging the      leaks”.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;This is NOT just an IT issue, it is an overall business      issue.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Why have we missed this?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Why?&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; - While      portable/accessible &lt;span&gt;information is      crucial to fast moving collaborative businesses; sharing data can lead to      unintended consequences.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;What      is it?&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; - Sensitive or regulated information including      Intellectual Property (“IP”), Personally Identifiable Information (“PII”),      trade secrets, sales/customer data, and payment card data are all open to      be misused or compromised.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;What is the impact?&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – Beyond the obvious risk of fines and lawsuits, breaches can lead      to a long term impact on brand reputation, competitiveness, and financial      well-being.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Is this a growing problem?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;These      thefts are increasingly driven by organized, motivated, and sophisticated groups      that are well compensated for their success.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;In a      down economy with growing layoff’s and fears of unemployment, employee      loyalty is the Enterprise equivalent of a unicorn.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Global      businesses rely on international collaboration networks, distributing information      through a variety of methods—potentially leaving companies more exposed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;IP      loss leads to counterfeiting, fraud, and from there loss of revenue with lasting      negative effects on brand value and corporate reputation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Existing      IP protection is not designed to detect targeted hacking or electronic      espionage activities.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Standards      such as Payment Card Industry (“PCI”) or Sarbanes-Oxley (“SARBOX”) &lt;span&gt;&amp;nbsp;&lt;/span&gt;create a false sense of security as they      are very finite in scope&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;What did we do before?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Ignorance is Bliss&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – Most felt, “This will never happen to us.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;i&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;The Gong Show&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – Historically attackers were driven by outsiders which were disorganized amateurs working from their parents basements.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Not my job&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; - “This is an IT issue.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Risk Reward Ratio&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – Previously the impact was neglibilbe compared to the cost of solving the problem&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Unicorns ARE real&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – “We trust our employees to secure our information.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Who Care’s&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – “We passed our audit, so we’re safe.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;What should we be thinking about now?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Enterprises, regardless of their size vertical, or location; need to confront a real and growing risk from data and identity theft.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Data loss is from organized groups, internal employees, and comes from physical loss, data exchanges, fraud, and human error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Corporate data losses open the door for employees and customers to experience fraud and personal identity theft.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Employees and collaboration networks are the most common data leak sources.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;•&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Data protection is not just a C-Level issue, it is a CEO-level concern.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: large;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;What do I do about it?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Data Security Audit&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – Understand where      your sensitive data is, where your leaks are and what your options are for      plugging the leaks with the help of PwC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Data Loss Protection (“DLP”)&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt; – Leveraging integrated      tools from Oracle partners including &lt;a href="http://www.mcafee.com/us/enterprise/products/data_protection/data_loss_prevention/host_data_loss_prevention.html"&gt;McAfee&lt;/a&gt;&amp;nbsp;      and &lt;a href="http://www.symantec.com/business/theme.jsp?themeid=vontu%20%20"&gt;Symantec&lt;/a&gt; ; Enterprises have the tools to look at data on the network or inflight to      understand how sensitive it is and allow the enterprise to respond.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;a href="http://www.oracle.com/technology/products/content-management/irm/index.html"&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Oracle Information Rights Management (“IRM”)&lt;/span&gt;&lt;/u&gt;&lt;/a&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&amp;nbsp;      - Provides a uniquely efficient response to sensitive data highlighted by      DLP products.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Oracle IRM allows      Enterprises to continue to share sensitive data while protecting it from      misuse or theft&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;a href="http://www.oracle.com/identity/"&gt;Oracle Identity &amp;amp; Access Management      (“IAM”)&amp;nbsp;&lt;/a&gt;&lt;a href="http://www.oracle.com/identity/"&gt;&lt;/a&gt;&amp;nbsp;      &lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;- Extends the standard provisioning      of access rights and roles for applications to data and content by working      closely with Oracle IRM.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Why &lt;a href="http://www.pwc.com/us/en%20"&gt;PricewaterhouseCoopers (PwC)&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;cite&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.pwc.com/us/en"&gt;&lt;span style="font-style: normal;"&gt;&lt;/span&gt;&lt;/a&gt; &lt;/span&gt;&lt;/cite&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Founded in      1998 with the merger of Price Waterhouse and Coopers &amp;amp; Lybrand, their      client history dates back to the nineteenth century combining a global      perspective with a local focus and deep understanding of US national      issues. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Originating      in London in the mid-1800s, PwC has 16 industry sector concentrations with      unique expertise in assurance, tax, human resources, transactions,      performance improvement and crisis management help to resolve complex      client and stakeholder issues worldwide. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Driving      innovation from global financial services and public sector or military to      non- profits, and relief agencies their collaborative model to create      innovative solutions to today's most complex business issues.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span style="font-size: large;"&gt;For more information:&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.75in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: Symbol; font-size: 12pt;"&gt;&lt;span&gt;·&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;PwC’s &lt;a href="http://www.pwc.com/us/en/10minutes/data-identity-theft.jhtml"&gt;“10 Minutes on data and identity theft”&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.75in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: Symbol; font-size: 12pt;"&gt;&lt;span&gt;·&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-size: 7pt; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;Contact: &lt;a href="http://www.pwc.com/en_GX/webadmin/forms/contactUs.jhtml?CIF=ACD&amp;amp;localeOverride=en_US&amp;amp;CN=Gary+Loveland&amp;amp;CD=99FE8262B3E57A4F802575C5007A3158&amp;amp;C=US&amp;amp;L=en&amp;amp;I=ALL&amp;amp;color_stylesheet=aubergine" target="_self" title="Gary Loveland"&gt;Gary Loveland&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;`&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Principal, National security practice leader&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Tel:&amp;nbsp;+1 (949) 437 5380&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-3156463939363129825?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/3156463939363129825/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2010/03/leaky-pipes-call-plumber-leaky-data.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3156463939363129825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3156463939363129825'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2010/03/leaky-pipes-call-plumber-leaky-data.html' title='Leaky pipes, call a plumber.  Leaky data, call PwC &amp; Oracle'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gn9hq2pkgmk/S5q98g4aquI/AAAAAAAAAHk/W-qL20epQ4w/s72-c/Plumber12.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-3347367772851240624</id><published>2010-02-25T15:28:00.001-08:00</published><updated>2010-02-26T08:06:39.799-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Identity Access Governance Oracle Sun Simeio IdM Identity Management SaaS IdMaaS Cloud Security Services Symplified'/><title type='text'>Identity &amp; Access Governance hits the Big Time!!!</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0; mso-font-charset:2; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:0 268435456 0 0 -2147483648 0;}@font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0; mso-font-charset:2; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:0 268435456 0 0 -2147483648 0;}@font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:""; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-fareast-font-family:Calibri; mso-bidi-font-family:"Times New Roman";}a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; mso-themecolor:hyperlink; text-decoration:underline; text-underline:single;}a:visited, span.MsoHyperlinkFollowed {mso-style-noshow:yes; mso-style-priority:99; color:purple; mso-themecolor:followedhyperlink; text-decoration:underline; text-underline:single;}.MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; font-size:10.0pt; mso-ansi-font-size:10.0pt; mso-bidi-font-size:10.0pt; mso-ascii-font-family:Calibri; mso-fareast-font-family:Calibri; mso-hansi-font-family:Calibri;}@page Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;}div.Section1 {page:Section1;} /* List Definitions */ @list l0 {mso-list-id:44182042; mso-list-type:hybrid; mso-list-template-ids:-415319298 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l0:level1 {mso-level-number-format:bullet; mso-level-text:; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;}@list l1 {mso-list-id:163326556; mso-list-type:hybrid; mso-list-template-ids:2028224528 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l1:level1 {mso-level-number-format:bullet; mso-level-text:; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;}@list l2 {mso-list-id:267474171; mso-list-type:hybrid; mso-list-template-ids:-946146276 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l2:level1 {mso-level-number-format:bullet; mso-level-text:; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;}@list l3 {mso-list-id:1399934177; mso-list-type:hybrid; mso-list-template-ids:908593090 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}@list l3:level1 {mso-level-number-format:bullet; mso-level-text:; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;}ol {margin-bottom:0in;}ul {margin-bottom:0in;}--&gt;&lt;/style&gt;&lt;span style="font-size: x-large;"&gt;Combining &lt;a href="http://bit.ly/cKpiO2"&gt;Oracle+Sun IdM&lt;/a&gt; &amp;amp; GRC&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-large;"&gt;products with cutting edge partners&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-large;"&gt; like&lt;a href="http://www.simeiosolutions.com/"&gt; Simeio Solutions&lt;/a&gt;,&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-large;"&gt;Identity and Access Governance&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size: x-large;"&gt;are center stage in IdM today.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_gn9hq2pkgmk/S4cGRadlCRI/AAAAAAAAAHc/aY-50UKuACA/s1600-h/simeio_solutions_logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_gn9hq2pkgmk/S4cGRadlCRI/AAAAAAAAAHc/aY-50UKuACA/s320/simeio_solutions_logo.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:""; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-fareast-font-family:Calibri; mso-bidi-font-family:"Times New Roman";}.MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; font-size:10.0pt; mso-ansi-font-size:10.0pt; mso-bidi-font-size:10.0pt; mso-ascii-font-family:Calibri; mso-fareast-font-family:Calibri; mso-hansi-font-family:Calibri;}@page Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;}div.Section1 {page:Section1;}--&gt;&lt;/style&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; line-height: 115%;"&gt;&lt;/span&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;“Whenever the people are well-informed, they can be trusted with their own [governance].” &amp;nbsp;- Thomas Jefferson&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Even back in his day Thomas Jefferson noted that good government, like good governance, was ability being informed and more and more these days Enterprises are looking to their IT resources to not only enable business functions but to provide greater visibility into those functions/applications.&amp;nbsp; Through Oracle’s applications and the expertise of partners like Simeio Solutions, Oracle is helping deliver this visibility for Identity and Access Governance.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;So, who is Simeio?&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal"&gt;Leaders with IAM and Role      Management deployments&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Reach&lt;/u&gt;&lt;/b&gt;:&amp;nbsp; Global      Customer Base with a presence in NY, LA, Atlanta, Dallas, Canada,      Australia, and India Canada (2008), ASPAC (Established in Sydney and      Mumbai , 2009), EMEA (2010 Planned, UK Q1) &lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Focus&lt;/u&gt;&lt;/b&gt;: Solving critical business needs through IAM,      ITGRC and Cloud Computing Fortune 100-1000 as reference-able clients&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Biz/Tech Capabilities&lt;/u&gt;&lt;/b&gt;: &amp;nbsp;Simeio has experienced resources able to      deliver IAM and IT-GRC consulting projects based on the following areas      Simeio has developed quick-start assessment and rapid deployment models      allowing for shortened project delivery timelines using both fixed fee and      time and materials based contracts; resources across the company, multiple      trained across Oracle’s security portfolio (User Provisioning, Role      Management and Compliance)&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Services Capabilities&lt;/u&gt;&lt;/b&gt;: &amp;nbsp;Simeio has a diversified set of services      to differentiate from our competition and be seen as a leader in Identity      and Access Management and IT-GRC; Simeio meets with industry analysts      (Burton, Gartner, Forrester) on a regular basis to keep a pulse on      industry trends and ensure our services align with customer needs; Simeio      meets with vendor Product Engineering and Management on a monthly basis&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Value&lt;/u&gt;&lt;/b&gt;: Strong team that has a reference-able base of      customers for Simeio to discuss Oracle Identity Management; Up-sell Oracle      Identity and Access Governance suite to existing and new customers&lt;/li&gt;&lt;li class="MsoNormal"&gt;Strong position in the      market with deep understanding on Identity, Role and Compliance Management&lt;/li&gt;&lt;li class="MsoNormal"&gt;Allows for Oracle to have      a dedicated team to go into Oracle accounts and discuss and implement      these solutions as a replacement to other role management and identity      products and continue to expand Oracle’s footprint within the account&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;Where do they come from?&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Enterprise Software Experience&lt;/u&gt;&lt;/b&gt;: Collective team comes      from the Vaau (prior to acquisition by Sun)&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Deployment Experience:&lt;/u&gt;&lt;/b&gt; 90% or more of Sun Role Manage (“SRM”),      now Oracle Identity Analytics (“OIA”) deployments done by Simeio&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Migration Experience&lt;/u&gt;&lt;/b&gt;: Provide a deployment /migration      path from other Role Management &amp;amp; Identity solutions to Oracle IdM; example      Sun Identity Manager (“SIM”) to Oracle Identity Manager (“OIM”)&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Competitive Experience&lt;/u&gt;&lt;/b&gt;: Knowledge and experience has      led to key wins against competitors such as Aveksa, SailPoint &amp;amp; CA&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Field Experience&lt;/u&gt;&lt;/b&gt;: Work with field and development      around POC’s and beta testing&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Product Experience&lt;/u&gt;&lt;/b&gt;:&amp;nbsp; Simeio Developed &lt;a href="http://wikis.sun.com/display/Srm503Docs/Home%20%20"&gt;SRM 5.0 Documentation&lt;/a&gt; and was an integral part of the SRM 5.0 release&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Unique IP&lt;/u&gt;&lt;/b&gt;: Simeio Solutions has Intellectual Property      around integrating and fast tracking deployments of SIM/OIM: Packaged 2      step approval workflow built for quick deployment; Package for quick      integration between SIM-SRM and OIM-SRM; Packaged custom reports providing      immediate business value; Expertise in developing custom connectors for      home-grown applications&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Unique Approach&lt;/u&gt;&lt;/b&gt;: Skilled resources out of our center of      excellence for custom development; “zero-day” rule based provisioning      solution; Quick ROI and value to the business; 7 day manual process      reduced to 5 minute automated provisioning&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;How do they help with IdM Governance?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;To borrow a phrase, they have their own dog in this hunt&lt;/u&gt;&lt;/b&gt;:      Simeio Solutions Intellectual Property such as DirectAXs &amp;nbsp;and offer services in the cloud for      Provisioning, Single Sign-on and Access Request&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Compliance &amp;amp; Role Management&lt;/u&gt;: &amp;nbsp;&lt;/b&gt;Simeio Solutions Intellectual      Property around integrating and fast tracking deployments of SRM; best      practices SoD library&lt;b&gt;; &lt;/b&gt;plus&lt;b&gt; &lt;/b&gt;160 Business Rules and thousands      of technical rules&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;u&gt;&lt;b&gt;Well Published&lt;/b&gt;&lt;/u&gt;: Authored multiple independent white papers      published in Role and Compliance Management&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;u&gt;&lt;b&gt;Well Respected&lt;/b&gt;&lt;/u&gt;:&amp;nbsp; Already      published in several technology analyst papers&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Role Management for the Enterprise (RME) &amp;amp; GRC&lt;/u&gt;&lt;/b&gt;: &amp;nbsp;Best of breed practices for IT-GRC      consulting projects Simeio is currently seen as the leader with the most      Sun Role Manager deployments Simeio has developed quick start packages and      delivered numerous projects with both Sun and Oracle Identity Solutions      Simeio has reference-able deployments to Fortune 100-1000 clients&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;What exactly do they offer On Demand?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="margin-top: 0in;" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;ROMAXs&lt;/u&gt;&lt;/b&gt; - Role Engineering, Role Management&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;ICOMAXs&lt;/u&gt;&lt;/b&gt; - Access Re-Certification, Identity Auditing&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;GRCAXs&lt;/u&gt;&lt;/b&gt; - Policy Management, Controls Testing, Risk      Assessment&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;IAMAXs&lt;/u&gt;&lt;/b&gt; - User Provisioning, Self Service&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;SSOAXs&lt;/u&gt;&lt;/b&gt; - Web Single Sign-On, Federation, Web Access      Control, and Role Mining/Management&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The alternative to flexible infrastructure that allows dynamic access to business resources BUT gives visibility is protection through limiting access:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;“The best government is a benevolent tyranny tempered by an occasional assassination.” – Voltaire&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;While this might have worked for Voltaire most modern Enterprises are looking for IT infrastructure that enables business innovation and growth; Oracle and its partners like Simeio are poised to deliver this.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-3347367772851240624?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/3347367772851240624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2010/02/identity-access-governance-hits-big.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3347367772851240624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3347367772851240624'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2010/02/identity-access-governance-hits-big.html' title='Identity &amp; Access Governance hits the Big Time!!!'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_gn9hq2pkgmk/S4cGRadlCRI/AAAAAAAAAHc/aY-50UKuACA/s72-c/simeio_solutions_logo.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-7396351356701769605</id><published>2010-01-27T17:49:00.000-08:00</published><updated>2010-01-27T18:30:30.190-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle Sun Identity Managament Access Management Identity Appliance'/><title type='text'>Identity Management as an Appliance by AegisUSA</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-family:georgia;"&gt;In light of the Oracle/Sun acquisition closing today, AegisUSA existing solution demonstrates the power of Sun/Oracle Identity Management delivered as a hardware appliance.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.oracle.com/us/sun/index.html"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 373px; height: 88px;" src="http://2.bp.blogspot.com/_gn9hq2pkgmk/S2D0nSPuqgI/AAAAAAAAAHU/1OYoEKSNlNc/s400/sun-orcl-complete+1-27-10.JPG" alt="" id="BLOGGER_PHOTO_ID_5431610106358704642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;a style="font-weight: bold;" href="http://www.aegisusa.com/"&gt;Who is AegisUSA?&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;IAM  solution provider&lt;/li&gt;&lt;li&gt;Over 60 clients nationwide&lt;/li&gt;&lt;li&gt;Created IAM IP over last 5 years&lt;/li&gt;&lt;li&gt;Built IAM products focused on specific solutions&lt;/li&gt;&lt;li&gt;Market focus&lt;/li&gt;&lt;li&gt;Mid Market&lt;/li&gt;&lt;li&gt;Higher Ed&lt;/li&gt;&lt;li&gt;Healthcare&lt;/li&gt;&lt;li&gt;State and Local Government&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;What is the challenge with the traditional approach?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Small Identity Customer = $500K Project&lt;/li&gt;&lt;li&gt;$50-150K Software License&lt;/li&gt;&lt;li&gt;$200K PS&lt;/li&gt;&lt;li&gt;$50K Hardware&lt;/li&gt;&lt;li&gt;1000-3000 Employees&lt;/li&gt;&lt;li&gt;3-6 month deployment&lt;/li&gt;&lt;li&gt;Organizations with 1000 users and below may be priced out of both the solution and the suite and therefore may not be good opportunities to prospect&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;What is the benefit of AegisUSA Appliance?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Small Identity Customer can’t afford $500K&lt;/li&gt;&lt;li&gt;$50-150K Software&lt;/li&gt;&lt;li&gt;$50-75K Solution&lt;/li&gt;&lt;li&gt;30 Day Deployment&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;What is it?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Appliance Solution&lt;/li&gt;&lt;li&gt;Hardware – 2 Sun Fire x4150 Servers&lt;/li&gt;&lt;li&gt;Sun Identity Management Software Suite&lt;/li&gt;&lt;li&gt;Identity Manager&lt;/li&gt;&lt;li&gt;OpenSSO&lt;/li&gt;&lt;li&gt;Directory Server&lt;/li&gt;&lt;li&gt;Supporting Sun Software&lt;/li&gt;&lt;li&gt;MySQL, Solaris 10, Open MQ, Glassfish&lt;/li&gt;&lt;li&gt;Professional Services to Install, Connect, and Configure&lt;/li&gt;&lt;li&gt;Appliance Support&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gn9hq2pkgmk/S2DyU-74cjI/AAAAAAAAAHM/0FIHOfHxfUc/s1600-h/aegis-image.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 212px;" src="http://2.bp.blogspot.com/_gn9hq2pkgmk/S2DyU-74cjI/AAAAAAAAAHM/0FIHOfHxfUc/s400/aegis-image.jpg" alt="" id="BLOGGER_PHOTO_ID_5431607592914285106" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What are the benefits of the Appliance approach?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Foundation for Further Expansion&lt;/li&gt;&lt;li&gt;Differentiator from other “point” solutions.&lt;/li&gt;&lt;li&gt;Open Architecture &lt;/li&gt;&lt;li&gt;Easy to Understand, Implement, and Support&lt;/li&gt;&lt;li&gt;Requires Minimal Professional Services to Deploy&lt;/li&gt;&lt;li&gt;Solves “Low hanging fruit” identity problems&lt;/li&gt;&lt;li&gt;Provides Quick wins&lt;/li&gt;&lt;li&gt;Increases Visibility for IAM Initiative&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;IdM includes a broad set of use cases, so where did they start?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Password Management&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Account Discovery (3-5 apps – 1 Authoritative)&lt;/li&gt;&lt;li&gt;Change Password&lt;/li&gt;&lt;li&gt;Forgot Password&lt;/li&gt;&lt;li&gt;Change Authentication Questions&lt;/li&gt;&lt;li&gt;Password Policy Configuration&lt;/li&gt;&lt;li&gt;Help Desk Admin&lt;/li&gt;&lt;li&gt;Password Reset&lt;/li&gt;&lt;li&gt;Change Password&lt;/li&gt;&lt;li&gt;User Audit Report&lt;/li&gt;&lt;li&gt;Standard auditing and reporting&lt;/li&gt;&lt;li&gt;Branding&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Federated Identity&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Infrastructure to join InCommon Federation&lt;/li&gt;&lt;li&gt;Leverage existing AuthN (LDAP)&lt;/li&gt;&lt;li&gt;OpenSSO with Shib SAML Profile&lt;/li&gt;&lt;li&gt;Documentation Package for clients&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Single Sign On&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Initial Loader and Existing Directory Integration&lt;/li&gt;&lt;li&gt;SSO Object Class Updater&lt;/li&gt;&lt;li&gt;Policy and Rule Configuration&lt;/li&gt;&lt;li&gt;IDM Authentication&lt;/li&gt;&lt;li&gt;Application Authentication and Simple Authorization&lt;/li&gt;&lt;li&gt;Session Persistence&lt;/li&gt;&lt;li&gt;Request SSO Access.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Google Apps Provisioning&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Leverage existing ‘directory’&lt;/li&gt;&lt;li&gt;Well defined set of rules for provisioning accounts&lt;/li&gt;&lt;li&gt;Allow for sponsored/guest account creation&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;This is a great example of how Oracle/Sun Identity Management software can be delivered as a hardware device to increase customer success and reduce implementation cost.  We look forward to see further innovations that come from Oracle/Sun + Partners!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-7396351356701769605?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/7396351356701769605/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2010/01/identity-management-as-appliance-by.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/7396351356701769605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/7396351356701769605'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2010/01/identity-management-as-appliance-by.html' title='Identity Management as an Appliance by AegisUSA'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gn9hq2pkgmk/S2D0nSPuqgI/AAAAAAAAAHU/1OYoEKSNlNc/s72-c/sun-orcl-complete+1-27-10.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-4211043931038815871</id><published>2010-01-20T17:36:00.000-08:00</published><updated>2010-01-20T17:52:07.193-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud Security Government Public Sector Oracle IBM Google CA Space Camp Nasa Nebula Apps.gov Obama Navy CANES US Energy Magellan NBC G-Cloud UK EU Reservoir  Virtualization Canada Japan Kasumigaseki'/><title type='text'>Government is going to the clouds...</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gn9hq2pkgmk/S1eyesu0f0I/AAAAAAAAAHE/UV8DDEzQzcc/s1600-h/cloud-gov-blog+1-7-10.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 266px;" src="http://4.bp.blogspot.com/_gn9hq2pkgmk/S1eyesu0f0I/AAAAAAAAAHE/UV8DDEzQzcc/s400/cloud-gov-blog+1-7-10.JPG" alt="" id="BLOGGER_PHOTO_ID_5429004116291780418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;style type="text/css"&gt;  &lt;!--   @page { margin: 0.79in }   P { margin-bottom: 0.08in }   A:link { so-language: zxx }  --&gt;  &lt;/style&gt;   &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-style: italic; font-weight: bold; color: rgb(51, 255, 51);font-size:180%;" &gt;“The government's living in its own cloud cuckoo land...”&lt;/span&gt;  - Bob Brown&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;For reasons ranging from cost savings to real time collaboration and innovation or job growth; increasingly government agencies around the globe are racing to roll out cloud services.  And like most IT departments there are areas of major overlap where various groups are competing for budget and influence.&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Like an awards show, below I have highlighted some of the more notable Cloud Initiatives in progress within the Public Sector, starting here in the United States:&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;My Favorite Cloud (Being a &lt;a href="http://www.spacecamp.com/"&gt;&lt;i&gt;Space Camp &lt;/i&gt;&lt;span style="color:#000080;"&gt;&lt;span lang="zxx"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;graduate): &lt;a href="http://nebula.nasa.gov/"&gt;Nasa Nebula&lt;/a&gt; &lt;/span&gt;&lt;span style="font-size:130%;color:#000080;"&gt;&lt;span lang="zxx"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;According to &lt;a href="http://en.wikipedia.org/wiki/Nebula"&gt; Wikipedia&lt;/a&gt; "A nebula is an  interstellar cloud of dust, hydrogen gas, helium gas and plasma."&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-weight: normal;"&gt;The  pun-intended pilot program is &lt;/span&gt;under development at NASA Ames  Research Center and is primarily based on open-source components and  provides a virtualized dynamically scalable computing infrastructure  .... hence a cloud.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Today it is used for public  outreach primarily but theoretically for scientific collaboration  and mission support.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;As we see with Enterprises,  innovation out paces infrastructure and NASA researchers see Nebula  as a way to dynamically share discoveries to rapidly iterate on  theories to more quickly lead to scientific discovery.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;As with any organization with high  value IP, data handling, privacy, and access requirements are  critical so security is fundamental as well as the need to comply  with agency and federal policies such as the Federal Information  Security Management Act (FISMA).&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Nebula's  Infrastructure-as-a-Service leverages &lt;span style="color:#000080;"&gt;&lt;span lang="zxx"&gt;&lt;u&gt;&lt;a href="http://open.eucalyptus.com/" target="_blank"&gt;Eucalyptus&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;,  a cloud management system from UC Santa Barbara that is compatible  with Amazon's &lt;span style="color:#000080;"&gt;&lt;span lang="zxx"&gt;&lt;u&gt;&lt;a href="http://aws.amazon.com/ec2/" target="_blank"&gt;EC2  web service&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;However Nasa assures us that  sensitive information is NOT being stored on Nebula&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Obama's Favorite Cloud: &lt;a href="http://apps.gov/"&gt;Apps.gov&lt;/a&gt; &lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;u&gt;Goal&lt;/u&gt; - Per the launch  announcement, “to lower the cost of government operations while  driving innovation within the government.”&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="color:#000080;"&gt;&lt;span lang="zxx"&gt;&lt;u&gt;&lt;a href="https://apps.gov/"&gt;Apps.gov&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;  is an online storefront for federal agencies to quickly browse and  purchase cloud-based IT services, for productivity, collaboration,  and efficiency.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Breaking from their historical  challenges we saw before 911 leading to the creation of the  Department of Homeland Security, where data (+apps) were hosted by  individual agencies and on fenced off devices&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;As the Fed spends north of $75  billion annually on IT, the potential benefit from even minimal  optimization is enormous&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Additionally, for anyone who has  gone through a Fed procurement process, it is painfully clear that  glaciers of molasses in January move faster.  Enabling a more  dynamic model of sharing resources could, theoretically, enable  Federal agencies to roll out new services much more quickly saving  time, money (on people), and be more effective .. more upside.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Peter Mell of NIST succinctly put  it, "&lt;span style="color:#000080;"&gt;&lt;span lang="zxx"&gt;&lt;u&gt;&lt;a href="http://twitter.com/kevin_jackson"&gt;2010  will be the year of the cloud computing pilot&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;."  I look forward to continuing this exciting conversation with you  all!&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Most Seafaring Cloud: Navy's CANES Initiative&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;u&gt;Why it's cool&lt;/u&gt; – Like any cloud initiative, it seeks  to make data and applications shared resources accessible by  users/apps  ... but the Navy makes it accessible by Sea.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;The Consolidated Afloat Network Enterprise System (“CANES”),  as you might suspect, consolidates hardware/software for centralized  access which will deliver a common hosted computing environment for  the entire fleet ... freeing up the ships to focus on their day job,  protecting us from the bad guys ... sounds like a great idea to  me!!!&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;The Navy is also looking at their own version of a Virtual  Private Cloud for the individual boats (ok, they prefer the term  vessel) called "grey clouds"&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Toughest Cloud: &lt;a href="http://www.disa.mil/"&gt;DISA Cloud Initiative &lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;The Defense Information Systems Agency (“DISA”) is  currently putting together several Cloud services for the US  Department of Defence (“DoD”).    &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;These include &lt;a href="http://forge.mil/"&gt;Forge.mil&lt;/a&gt;, an open source  initiative (Thanks for supporting the US software industry) which is  a group of SaaS applications that support the DoD IT community.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Started in October 2008, Forge.mil is a DISA-led activity  that theoretically delivers operational efficiency, cost savings,  and would help protect the operational environment from potentially  harmful systems and services   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Another example is &lt;a href="http://www.disa.mil/nces/product_lines/gcds.html"&gt;GIG Content Delivery Services (“GCDS”)&lt;/a&gt; which is actually not owned by the Public/Federal Sector , and this  computing platform is shared/deployed across the &lt;a href="https://www.intelink.gov/wiki/DISN" target="_blank"&gt;DISN&lt;/a&gt;  (&lt;a href="https://www.intelink.gov/wiki/NIPRNET" target="_blank"&gt;NIPRnet&lt;/a&gt;  &amp;amp; &lt;a href="https://www.intelink.gov/wiki/SIPRNET" target="_blank"&gt;SIPRnet&lt;/a&gt;).&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;GCDS is designed to focus on delivering applications/data in  a secure and reliable fashion no matter the state (or location) of  the network or end points.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Some interesting advantages of GCDS include localized caching  anywhere, global redundancy and fail-over, multi-vector scaling,  defense in depth protection, edge level data and network control,  rapid implementation, and neurologically based network security.&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Most Empowered Cloud: US Department of Energy's Magellan&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;u&gt;If you can't run with the big  dog's stay on the porch&lt;/u&gt; - Funded by the American Recovery and  Reinvestment Act through the US Department of Energy (DOE), the aim  is really to test if cloud computing is all it is cracked up to be  or another passing trend (What, CORBA won't change the world?)   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;The DOE centers at the Argonne  Leadership Computing Facility (ALCF) in Illinois and the National  Energy Research Scientific Computing Center (NERSC) in California  are installing basic but comparable systems as a test bed to assess  the effectiveness of cloud computing from the perspective of energy  efficiency.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;u&gt;What's in a name?&lt;/u&gt; - Viewed  as an exploration of the next frontier in IT, Magellan is named (no  surprise here) in honor of the Portuguese explorer whose voyage was  noted as the first to circumnavigate the globe.  Also the “clouds  of Magellan”, 2 galaxies were named after him so it gets even more  cute.&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;The Most Pail Cloud: &lt;/span&gt;&lt;a style="font-weight: bold;" href="http://www.nbc.gov/"&gt;Department of the Interior's NBC Cloud Initiative&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;The Department of the Interior's National Business Center  (“NBC”) is planning a set of cloud services to be offered to the  broader community of federal agencies.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Having historically operated as a service provider, NBC (no  peacock included) was originally established to be a shared services  provider for what those of us in the commericial sector might think  of as G&amp;amp;A activities such as accounting, HR, etc.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Starting in 2004, NBC took on the role of being the US  government wide service provider under the Information Security  Systems Line of Business and in so doing quickly stumbled into the  typical issues/requirements of multi-tenancy we see in the  commercial space.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Today NBC (still no peacock) is planning to start with 6  cloud solutions: NBCGrid (IaaS), NBCFiles (Cloud Storage), NBCStage  (PaaS), NBC Hybrid Cloud, NBCApps (SaaS Marketplace), &amp;amp; NBCAuth.   &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size: 16pt;font-size:130%;" &gt;&lt;b&gt;Around the World&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-style: italic; color: rgb(51, 255, 51);"&gt;“Behind every cloud is another cloud.”&lt;/span&gt; - Judy Garland  &lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;James Bond's Favorite Cloud: The UK's &lt;span style="font-style: italic;"&gt;G-Cloud&lt;/span&gt; Initiative (it even sounds classy)&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; text-decoration: none;"&gt;Announced  by Great Britain's Federal CIO, this onshore and private initiative  by the government is aimed at delivering a middleware platform for  delivering data and applications as shared services in a  &lt;span style="font-weight: bold; font-style: italic;"&gt;iTunes.gov.uk &lt;/span&gt;like application store.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; text-decoration: none;"&gt;Initiated  with a study/investigation into the effectiveness of Cloud Computing  and Virtualization, the apparent success of their test results  turned into a full blow IT initiative&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; text-decoration: none;"&gt;As in the  US, the goal is to empower UK government agencies to benefit from  the costs savings and efficiencies of a shared computing environment  while also maintaining the appropriate levels of security,  accountability and control required government programs.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; text-decoration: none;"&gt;Having  previously kept such efforts within specialized teams/groups, this  is the first effort to bring IT innovation directly under the  responsibility of their operating agencies (or for those of use from  the private sector think business owners not IT).&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;The Cloud with the most painful acronym: &lt;a href="http://www.reservoir-fp7.eu/"&gt;The EU's RESERVOIR project&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.reservoir-fp7.eu/"&gt;&lt;cite&gt;&lt;/cite&gt;&lt;cite&gt;&lt;/cite&gt;&lt;/a&gt;&lt;cite&gt;  &lt;/cite&gt; &lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p&gt;While Government agencies are known for their use of  acronym's the EU (already an acronym) takes the cake with the  Resources and Services Virtualization without Barriers Project  (“RESERVOIR”).&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;As in the US and the UK, the project is designed to provide  cost savings, efficiency, and scalability across a shared pool of IT  resources and geographies.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;With On-Demand resource provisioning and Web 2.0 use of  applications as a services and networks as platforms to expedite  time to market for new government resources to help the EU compete  on the global stage&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;The EU hopes to leverage RESERVOIR to enhance the  competitiveness of their economy and bring about a powerful ICT  infrastructure for the reliable and effective delivery of services  as utilities.   &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="font-weight: bold;"&gt;&lt;span style="font-size:180%;"&gt;Most Friendly Cloud: Canada's Cloud Initiative&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p&gt;The inititaive was essentially otlined in a paper from the  Canadian Government's CTO of Public Works as a strategy for helping  diminish the negative impact of IT on the Environment&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;It also suggests that leverage the inherent cooling  advantages of the geography of Canada make the country an ideal  location for hosting world wide cloud initiatives&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Looking at this from the perspective of a traveler, Canadians  are possibly the most generally likable travelers and hosting high  value infrastructure there might make it safer from unintended  terrorist attacks.&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;The Sunniest Cloud: Japan's Kasumigaseki Cloud Initiative  &lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p&gt;Dubbed the ICT Hatoyama Plan as outlined by the Digital Japan  Creation Project, Japan’s Ministry of Internal Affairs and  Communications has released plans to deliver a massive cloud  computing infrastructure to support all of the government’s IT  systems.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Tentatively named Kasumigaseki after Japan's first high rise  building (1&lt;sup&gt;st&lt;/sup&gt; building in the clouds) the plan is to  deliver the infrastructure in stages with full role out by 2015.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;As seen in other countries the goal is IT efficiency for cost  savings and speed of rolling out new solutions and services&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p&gt;Japan’s Ministry of Internal Affairs and Communications  (MIC) anticipates that the project will boost the economy    &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-4211043931038815871?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/4211043931038815871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2010/01/government-is-going-to-clouds.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4211043931038815871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4211043931038815871'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2010/01/government-is-going-to-clouds.html' title='Government is going to the clouds...'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_gn9hq2pkgmk/S1eyesu0f0I/AAAAAAAAAHE/UV8DDEzQzcc/s72-c/cloud-gov-blog+1-7-10.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-6278534239192320610</id><published>2009-12-31T08:59:00.001-08:00</published><updated>2009-12-31T09:22:33.946-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud Appliance Data security Information security Privileged user management Baby New Year Ball Champagne Toast New Year Resolution Nasa Nebula Pentagon'/><title type='text'>Security’s Baby New Years for 2010</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;As the ball drops on the 1st decade of the new millennium…&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0);font-size:180%;" &gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0);font-size:180%;" &gt;&lt;span style="font-weight: bold;"&gt;What will represent the Baby New Year of 2010 for Information Security?  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-size:130%;"&gt; &lt;span style="font-weight: bold;"&gt;Will our 2010 resolutions mitigate the threats or fall inevitably short? &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gn9hq2pkgmk/SzzZKjSJcdI/AAAAAAAAAG8/4NNc7gBcf6k/s1600-h/Baby-New-Year.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 233px; height: 297px;" src="http://2.bp.blogspot.com/_gn9hq2pkgmk/SzzZKjSJcdI/AAAAAAAAAG8/4NNc7gBcf6k/s400/Baby-New-Year.jpg" alt="" id="BLOGGER_PHOTO_ID_5421446826740511186" border="0" /&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Baby_New_Year"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Wikipedia defines Baby New Year&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;as a “male baby wearing nothing more than a diaper, a top hat and a sash across his torso that shows the year he is representing. Sometimes he is holding an hourglass or is otherwise associated with one”.&lt;br /&gt;&lt;br /&gt;Not too ominous at face value but this icon represents the anticipation, excitement, and uncertainty everyone feels in facing a new era.  On the eve for 2010, the likely evolutions in Information Security (those foreseen and those yet unimagined) are certain to bring out the same feelings in CSO’s, CISO’s, CIO’s, CEO’s across the public and private sector.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;Step 1: Learning from the past attacks&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;"Among all forms of mistake, prophecy is the most gratuitous.”  - &lt;span style="font-style: italic;"&gt;George Eliot&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;What was expected? &lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Early predictions this decade anticipated that information security would be much better, more efficient, less complicated, with fewer attacks.&lt;/li&gt;&lt;li&gt;Popular thinking was that vulnerabilities would flatten/decline, and so would breaches.&lt;/li&gt;&lt;li&gt;Applications were expected to get simplified, smaller, less interdependent and less extensible&lt;/li&gt;&lt;li&gt;Some even suggest that by 2010, a security Martin Luther would lead us through a class-action lawsuit that sparks a full-blown security reformation.&lt;/li&gt;&lt;li&gt;In 1991, D. James Bidzos, then president of RSA created the buzz phrase “digital Pearl Harbor”; referring to a global InfoSec attack compounded by disrupted backup systems and leading to cascading failures and worldwide panic where the origin is later pinpointed to an avoidable vulnerability.&lt;/li&gt;&lt;li&gt;Viruses and data breaches were seen as mischievous acts of disruptive individuals rather, not criminal enterprises.&lt;/li&gt;&lt;li&gt;PKI was seen as the imminent solution to all authentication problems&lt;/li&gt;&lt;li&gt;Reformers such as SEI’s Watts Humphrey, proposed solutions to software vulnerabilities through formalized software engineering best practices and requiring professional licensing, as within the medical field, to minimize threats by heightening quality and consistency.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-style: italic;"&gt;“Whoops there it is!” - The Fresh Prince of Bel-Air&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What wasn't expect?  &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Hoaxes &lt;/span&gt;- For example, the &lt;a style="font-style: italic; font-weight: bold;" href="http://www.mcafee.com/us/threat_center/default.asp"&gt;Baby New Year Hoax&lt;/a&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt; &lt;/span&gt;of 2007 claimed a Baby New Year Virus had infected up to 42 million computers worldwide.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Complexity &lt;/span&gt;- Instead of being simplified applications became more complicated, architectures more sophisticated through SOA, virtualization, SaaS, etc.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Out Sourcing &lt;/span&gt;- Rather than becoming a highly regulated, licensed profession software development moved to an out sourcing model where vendors and customers build solutions through composite teams world wide&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Abstraction &lt;/span&gt;- Information Security moved to an abstraction model with shared/standard components across applications for authentication, authorization, provisioning, roles management, etc.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Protocol flaws- &lt;/span&gt;For example, researcher Marsh Ray of PhoneFactor discovered a hole within SSL/TLS that allowed man-in-the-middle attacks.&lt;/li&gt;&lt;li&gt;Security as a Facade – For example, &lt;a style="font-style: italic;" href="http://www.security2010.com/"&gt;&lt;span style="font-weight: bold;"&gt;Security2010 &lt;/span&gt;&lt;/a&gt;offering dummy security cameras and solar powered dummy security cameras&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Social Networking &lt;/span&gt;– 10 years ago we struggled with AOL IM, Yahoo Webmail, and peer-to-peer networks like Napster and focused on server port 80; but by the end of the decade, the top concerns were Facebook, Twitter, and other Web 2.0 applications.&lt;/li&gt;&lt;li&gt;Worms – Unlike Oscar the Grouch friend Slimey, the 2005 Samy worm on MySpace or Facebook’s Koobface, demonstrated the risks in opening the web to malware contributions from users, innocent or malicious.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Get Shorty &lt;/span&gt;- Twitter fans love of mini-URL’s lead to vulnerabilities of their own&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Mafiaboy to Organized Crime&lt;/span&gt; – The Feb 2000 Denial of Service attack from the Canadian teenage named Mafiaboy temporarily brought down sites including CNN, Dell, eBay, and Yahoo but by the close of the decade attacks were lead by well organized and funded criminals to produce data breaches at Dave &amp;amp; Busters, Hannaford Brothers, Heartland Payment Systems, and TJX and &lt;a href="http://english.aljazeera.net/news/americas/2009/12/2009121801911884934.html"&gt;Iraq Shia fighters hijacking the security camera’s in drone airplanes&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Gone Phishing&lt;/span&gt; – Clever con artists leveraging fast flux to rapidly switch domains locations and sites that felt like known banking sites successfully extracted PII from users trying to log-in, update, or review their accounts.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;Step 2:  Anticipating  future threats&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-style: italic;"&gt;“Never assume the obvious is true.” - William Safire &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What can we foresee now?  &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Jail Bait &lt;/span&gt;– Apple’s restrictive policies on “approving” applications and limiting user control of the device has lead to a large &amp;amp; growing sub-culture of “jailbroken” phones.  While this gives the user more access it opens the device to vulnerabilities.  Conversely security vendors like Symantec, McAfee, Sophos, etc. cannot develop antivirus applications for the iPhone as Apple blocks necessary low-level access to the device.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Rock’m Sock’m Androids &lt;/span&gt;- Google's Android is a natural attack for 2010, as Google is more open in allowing applications, but this is open to abuse by seemingly desirable applications functioning as malware.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Hey! You! Get off of my cloud &lt;/span&gt;– Cyber-criminals combining stolen credit cards and hosting cloud services like Amazon’s EC2 have already started to use the new platform for Bots-as-a-Service or Malware-as-a-Service.  Not to mention the legal liability facing cloud services around protected data from PII to pornography being stored on their servers unbenounced to them.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;It’s getting blurry &lt;/span&gt;- As public and private organizations extend their use of smartphones, web 2.0, and social media to interact with clients, employees, and contractors, they blur the perimeters of the network.  Organizations will need to shift the focus towards data protection beyond network/infrastructure security as the question shifts from “Who has access to what?” to “What are they doing with it?”&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;MyCloud.gov &lt;/span&gt;- Government agencies are increasingly moving data and services of low or moderate risk to cloud services to attain cost savings, such as Nasa’s Nebula http://www.cloudbook.net/nebula-gov or from the Pentagon http://www.networkworld.com/news/2009/100509-pentagon-cloud-computing.html?page=2&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Enough is Enough &lt;/span&gt;– As with the recent bombing attempt, the continuous evolution towards heightened security at airports and long, uncomfortable security screenings for most passengers will likely lead to biometrics finally making it to prime time.  Consumers will be willing to compromise privacy and bear the cost to simplify their life with everything from air travel to eliminating the 100+ passwords they have to remember or keep in a file on their computer or sitting on the desk.  &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;“No question is so difficult to answer as that to which the answer is obvious.” - George Bernard Shaw&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What can’t we anticipate?   &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Greatest Thing Since Sliced Bread &lt;/span&gt;– As we have seen throughout the evolution of enterprise software, there seems to be a never ending flow of revolutionary architectures changing how we build products, deploy solution, and conduct business.  This includes CORBA, P2P, SOA, SaaS, Virtualization, and Cloud Services just to name a few.  As each new platform emerges there will be new vulnerabilities associated with them.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;What’s Old is New Again &lt;/span&gt;– Appliances keep coming back as vendors like Intel and AMD seek to drive high-use functions into the chip set and organizations look to reduce the cost and risk associated with major deployments through the use of packaged solutions.  However each new wave of appliances has its own associated risks.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;The Perfect storm &lt;/span&gt;– Who knows, perhaps the combination of social networking, smart phones, and cloud services will lead to the “digital Pearl Harbor” that was predicted in 1991&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: center; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;How did we do compared to our predecessors projections, how will we be judged by those who come after us?  Only time will tell.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-6278534239192320610?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/6278534239192320610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/securitys-baby-new-years-for-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6278534239192320610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6278534239192320610'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/securitys-baby-new-years-for-2010.html' title='Security’s Baby New Years for 2010'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gn9hq2pkgmk/SzzZKjSJcdI/AAAAAAAAAG8/4NNc7gBcf6k/s72-c/Baby-New-Year.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-3578718967626372204</id><published>2009-12-16T16:38:00.000-08:00</published><updated>2009-12-16T16:47:39.460-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLP Cloud Security DLP SaaS AV Symantec Vordel Sophos McAfee IRM Oracle End-point security desktop security antivirus malware'/><title type='text'>The Next Cloud Security Frontier: DLP for the Cloud</title><content type='html'>&lt;span style="font-size:180%;"&gt;While there is a growing consensus that security is the keystone to successfully leveraging Cloud Services and Composite Applications, filtering and securing the data being exchanged is a BIG problem facing us ahead.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Viruses and Malware are the &lt;span style="font-weight: bold; font-style: italic;"&gt;STD's of the Internet&lt;/span&gt; and &lt;span style="font-weight: bold; font-style: italic;"&gt;Identity Theft is the equivalent of virtual counterfeiting&lt;/span&gt; so as with every other issue/requirement that faces user interactions, SOA interactions face the same challenges.&lt;br /&gt;&lt;br /&gt;Existing Cloud Security solutions have focused on authentication, entitlements, which is where Identity &amp;amp; Access Management for users started.  However the next generation will need to address the “STD's” and Counterfeiting risks as well like Symantec, McAfee, Sophos, and others have done with DLP and desktop security.&lt;br /&gt;&lt;br /&gt;Vordel has recognized this emerging requirement and started addressing it with DLP functionality in their recently announced &lt;a href="http://www.vordel.com/news/press/05_11_09a.html"&gt;Cloud Service Broker product &lt;/a&gt;that will allow customers to analyze content and act on it whether it is flowing into or out of their environment.&lt;br /&gt;&lt;br /&gt;There are already legal precedents and implications which, if called into play, could have substantially negative financial and reputation effects on Cloud Service provides like SalesForce.com, Google Apps, and Oracle On-Demand as well as their clients.  One example outlined in&lt;a href="http://www.workplaceprivacyreport.com/2009/12/articles/monitoring-1/employers-dont-put-your-heads-in-the-sand-you-may-be-required-to-monitor-investigate-and-report-employees-accessing-child-pornography/"&gt; this article   &lt;/a&gt;outlines how storage as a service introduces legal implications based on  unchecked content within a packet containing personally identifiable information (PII) or other regulated data creates a liability for organizations that receive it.&lt;br /&gt;&lt;br /&gt;Network World even references this as part of a likely growth trend for &lt;a href="http://www.networkworld.com/columnists/2009/121609antonopoulos.html?hpg1=bn"&gt;Enterprise Security in 2010 &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;So how do we get ahead of the 8-Ball on this one?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;What is the risk?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;All content sent to Cloud services must be analyzed for leaked data, in order to enable Data Loss Prevention.&lt;/li&gt;&lt;li&gt;Content-level threats (viruses, malware, PII, MIIA, etc.) need to be identified and blocked, including application-level attacks at the API and payload level. &lt;/li&gt;&lt;li&gt;It is not enough to know “Who has access to what?”; Enterprises need to know, and be able to demonstrate, what they are doing with it?  Leaking PII or any regulated data creates a substantial risk to the enterprise.&lt;/li&gt;&lt;li&gt;Receiving PII, ranging from social security numbers or unencrypted credit card accounts to child pornography creates just as much liability as leaking that data.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;How should we address it?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Architecture &lt;/span&gt;- Look for flexible SOA Security solutions and XML Gateway's that allow for seamless integration with content filtering and protection services.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Don't spread STD's i.e. Viruses/Malware &lt;/span&gt;– Leverage proven tools for content inspection connected to active research labs to analyze the content of packets while it is open to minimize risk AND latency.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Stop Counterfeiting i.e. Data Protection&lt;/span&gt; – Leverage the content analysis tools found in proven DLP solutions to review, quarantine, delete, protect, or stop information during the same packet inspection.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Protect against Internal Threat with IRM&lt;/span&gt; – The same risks that exist with users are shared here for services.  Lock it down with IRM to seal sensitive or regulated data before it goes out the door but still allowing business processes and services to function effectively.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;As enterprises host and share data via software-as-a-service (SaaS) and Composite Applications with Public/Private Cloud services, they need to \consider the use of DLP, AV, and IRM technologies to protect themselves and the information being exchanged.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-3578718967626372204?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/3578718967626372204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/next-cloud-security-frontier-dlp-for.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3578718967626372204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3578718967626372204'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/next-cloud-security-frontier-dlp-for.html' title='The Next Cloud Security Frontier: DLP for the Cloud'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-490339284297151310</id><published>2009-12-10T10:05:00.000-08:00</published><updated>2009-12-16T15:11:42.292-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fraud Identity Theft statistics Hacker Des Powley Oracle 7 secrets'/><title type='text'>7 Secrets of Fraud &amp; Identity Theft</title><content type='html'>&lt;span style="font-size:180%;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-size:100%;"&gt;Between the media attention and ever increasing security &amp;amp; audit requirements, here are some interesting points on what is behind all this.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;font-size:180%;" &gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;#1 -- How broad is the impact?&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;10 million of US Citizens (1 in 10) were victims of ID Theft in 2008 (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;U.S. fraud totaled $31 billion in 2008 (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;Across the world businesses lost $221 billion a year due to identity theft (Aberdeen Group).&lt;/li&gt;&lt;li&gt;Average vicitims lost $851 and $1,378 out-of-pocket trying to resolve identity theft (ITRC Aftermath Study, 2004).&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;# 2  -- How hard &lt;/span&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;is &lt;/span&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;it to fix?&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Almost 20% of victims don't learn that their identity has been stolen for four or more years (Identity Theft Resource Center Aftermath Study, 2004).&lt;/li&gt;&lt;li&gt;50.2 million Americans were using a credit monitoring service as of September 2008 (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;Taking up to almost 6,000 hours (Average 330), the equivalent of the time working 2 full-time jobs for a year, to correct the damage from ID theft (ITRC Aftermath Study, 2004).&lt;/li&gt;&lt;li&gt;25.9 million Americans carry identity theft insurance (as of September 2008, from Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;After suffering identity theft, 46% of victims installed antivirus, anti-spyware, or a firewall on their computer. 23% switched their primary bank or credit union, and 22% switched credit card companies (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;# 3 -- What are the Common Sense ways to avoid it?&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;One of these things doesn't belong &lt;/span&gt;– Check your bills, question things that don't make sense and question charges or bills that are missing. &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;WHY?  &lt;/span&gt;Thieves may make a charge and reverse it just to test that the number is valid before stealing it.  Also if you did not get the bill, it might be going to someone else that hijacked your account.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Don't call us...&lt;/span&gt; - Never give out identity data to someone who called or emailed you, if your bank or credit provider needs info contact them on a known-good phone number or  website&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;WHY?&lt;/span&gt;  Odds are they wouldn't ask if they knew, many thieves go on phising trips over the phone, web, or email often telling you they are from your bank and “here to help”.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Pick up the phone &lt;/span&gt;– Frequently service providers will request that you write down and mail your credit card information, give it to them by phone instead.  &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;WHY? &lt;/span&gt; How hard is it for someone in the mail room to copy them.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Somebody is watching you &lt;/span&gt;– They put those mirrors on ATM machines for a reason, watch out for someone looking over your shoulder in the real world or online.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;WHY?&lt;/span&gt;  Ever take a Quiz on Facebook like “Which cat would I be?  These can be loaded with questions that are also used as your secret questions to retrieve passwords with banks, credit cards, etc.  Take a quiz, get your id hijacked.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;#4 -- How are &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;we &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;getting attacked&lt;/span&gt;?&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Stolen wallets and physical paperwork accounts for almost half (43%) of all identity theft (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;Web/email attacks account for only 11% (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;Credit/Debit cards were stolen from 38% of victims (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;Social Security number were stolen from 37% (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;Name and phone for 36% (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;Financial account for 24% (Javelin Strategy and Research, 2009).&lt;/li&gt;&lt;li&gt;35 million+ records were compromised in corporate breaches in 2008 (ITRC).&lt;/li&gt;&lt;li&gt;Racking up your phone bill with long distance calls, and not let you know until it's too late.&lt;/li&gt;&lt;li&gt;Getting a replacement for your credit card just by making a phone call&lt;/li&gt;&lt;li&gt;Starting a new life under a dead person's identity.&lt;/li&gt;&lt;li&gt;Sell your home, or take out a mortgage against it, without your knowledge.&lt;/li&gt;&lt;li&gt;Use up electricity and leave you with the bill.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;# 5 -- Does Ice make it feel better?&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Freezing your credit report won't always stop many ways of committing&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;# 6 -- Is there a Conference for this?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Starting on the 19th of January 2010, will be &lt;a href="http://www.blogger.com/post-edit.g?blogID=5297101820232184490&amp;amp;postID=490339284297151310#%20http://www.iir-events.com/IIR-conf/AuditRisk/EventView.aspx?EventID=1869"&gt;the 12th annual IIR Fraud World conference &lt;/a&gt;&lt;/li&gt;&lt;li&gt;Opening &amp;amp; Chairing the event will be Oracle's own &lt;span style="font-weight: bold;"&gt;Des Powley&lt;/span&gt;; &lt;span style="font-style: italic;"&gt;Technology Director, Security &amp;amp; Identity for  Oracle UK, Ireland, &amp;amp; Israel&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Des will also be delivering a session on “The Importance of Delivering Enhanced Identity Management, Fraud Detection &amp;amp; Risk Management”&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;#7 -- Can you watch the movie instead?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;The 2008 documentary &lt;a href="http://www.amazon.com/Hackers-Are-People-Ashley-Schwartau/dp/0962870080/ref=sr_1_1?ie=UTF8&amp;amp;s=dvd&amp;amp;qid=1260466809&amp;amp;sr=8-1"&gt;"HACKERS ARE PEOPLE TOO"&lt;/a&gt;  takes an honest look at the subculture and it original origin and the hijacking of the term “hacker”. &lt;/li&gt;&lt;li&gt;The more theatrical version directed by Iain Softley from 1995 “&lt;a href="http://www.amazon.com/Hackers-Jonny-Lee-Miller/dp/6305047456/ref=pd_cp_d_1"&gt;Hackers&lt;/a&gt;”  is also enjoyable.&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-490339284297151310?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/490339284297151310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/7-secrets-of-fraud-identity-theft.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/490339284297151310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/490339284297151310'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/7-secrets-of-fraud-identity-theft.html' title='7 Secrets of Fraud &amp; Identity Theft'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-5808542325252852759</id><published>2009-12-08T14:01:00.000-08:00</published><updated>2009-12-08T14:14:54.923-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle Identity Management SaaS Software as a service cloud security  Simeio DirectAXs Wipro Managed Identity Service Symplified Enterprise On-Demand'/><title type='text'>Are Enterprises ready for Identity Management as a Service (IMaaS) ?</title><content type='html'>&lt;span style="font-size:180%;"&gt;While solutions are available and the economics of the solution are desirable it is still early days.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;Is the technology available?&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;Recently Simeio Solutions launched their new version of &lt;a href="http://www.simeiosolutions.com/images/DirectAXspressreleasefinalapproved.pdf"&gt;DirectAXs software-as-a-service (SaaS) &lt;/a&gt;suite. &lt;/li&gt;&lt;li&gt;In 2007, &lt;a href="http://www.oracle.com/corporate/press/2007_jun/managed-identity-service.html"&gt;Oracle &amp;amp; Wipro announced Managed Identity Service&lt;/a&gt;&lt;/li&gt;&lt;li&gt;If you do a &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=identity+management+SaaS"&gt;Google search&lt;/a&gt; there is a seemingly endless list of options including startups looking to change the game such as  &lt;a href="http://symplified.com/"&gt;“Symplified”&lt;/a&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;So why is it desirable?&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Pricing/Packaging&lt;/span&gt; - Pay-as-you-go or subscription pricing allows organizations to measure the direct ROI on an quarterly basis plus delivers lower upfront costs and assured service levels&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Deployment&lt;/span&gt; - Historically IAM implementations have been labor-intensive and create organizational headaches with change control and process engineering which can be costly.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Integration &lt;/span&gt;- Disjointed products from multiple vendors, suites, or coming into an Enterprise through various acquisitions create incompatibilities but can be challenging to unwire/replace or merge.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Governance&lt;/span&gt; - Provides an immediate/direct combination of identity and access management (IAM) with governance, risk and compliance (GRC) capabilities&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Hosting&lt;/span&gt; - Solutions can be fully hosted and remotely managed or on premise and managed externally managed&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Administration&lt;/span&gt; – Provides a centralized/unified management of IAM and GRC capabilities for a streamlined user experience with integrated reporting&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;So what is the problem?&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Multi-tenancy&lt;/span&gt; – Existing solutions/architectures require enhanced features for multiple customers to access the same console, provide for data partitioning, and filtering to prevent unauthorized data access. &lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Converging Suites&lt;/span&gt; - As Identity Management becomes increasingly application centric the drive is towards suites that weave IAM into the fabric of the application framework as Oracle and SAP are moving towards&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Security Concerns&lt;/span&gt; - Heightened compliance and security regulations make identity and access management a critical component of today's enterprise, too sensitive to manage externally&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;1-Cloud-to-many-Applications&lt;/span&gt; - Enterprise deployments require 20-100 applications to be individually integrated into the IAM suite, connecting user provisioning, single sign on, role management and compliance to the single point of the cloud, across the web with each application creates throttling, latency, and SLA-priority challenges and diminishes the performance of the underlying applications and users.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:130%;" &gt;The march towards dynamic, composite applications architectures is definite but the rate is uncertain and the challenges and risks for the early adopters are high.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-5808542325252852759?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/5808542325252852759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/are-enterprises-ready-for-identity.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5808542325252852759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5808542325252852759'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/are-enterprises-ready-for-identity.html' title='Are Enterprises ready for Identity Management as a Service (IMaaS) ?'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-6173851909750823073</id><published>2009-12-07T10:27:00.000-08:00</published><updated>2009-12-07T10:34:15.066-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Novell Virtualization Security Network World Ellen Messmer Identity Management Provisioning DirXML'/><title type='text'>Is Novell changing the game with Virtualization Security?</title><content type='html'>&lt;span style="font-size:130%;"&gt;In an intriguing Network World Article today, &lt;a href="http://bit.ly/4RFxS7"&gt;“Novell grabs for big role in virtualization security”&lt;/a&gt;, &lt;span style="font-style: italic;"&gt;Ellen Messmer&lt;/span&gt; previews Novell's plans to capture a big piece of the Virtualization “hype” by building on their established leadership in Identity Management, Linux, and Network Management.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:180%;"&gt;But can they pull it off?  I doubt it and here is why:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Identity and Access Management&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;As arguably the inventor of modern Application User Provision with DirXML, a key tenant of Novell's strategy is leveraging their IAM leadership and hardwiring the technology into the VM Management and virtual appliance deployment.&lt;/li&gt;&lt;li&gt;Having been closely involved in the early adoption of IAM technologies like SiteMinder at Netegrity and Entitlements at BEA, and User Provisioning at Oracle it is very clear that IAM technologies are highly sticky.  &lt;/li&gt;&lt;li&gt;Even when customers want to migrate solutions it is often too expensive, painful, or risky to do so.  Therefore convincing non-Novell customers to move to their IAM suite will be challenging.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Building Virtual Appliances&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The initial product targeted for release is called “&lt;span style="font-style: italic;"&gt;Workshop&lt;/span&gt;” to build/deploy workloads for Linux or Windows environments.&lt;/li&gt;&lt;li&gt;However there has been an industry building these “micro kernels” for several years now, including much more comprehensive solutions for patch updates, live monitoring, etc. from players like &lt;a href="www.rpath.com/"&gt;rPath&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Even within the realm of SUSE Linux there is an existing solution &lt;a href="http://en.opensuse.org/SUSE_Studio_General_FAQs"&gt;“SUSE Studio”&lt;/a&gt;, called a quick/easy appliance builder&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Change Management&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Novell's strategy also includes solutions PlateSpin "&lt;span style="font-style: italic;"&gt;Bluestar&lt;/span&gt;" for to address requirements for physical server change and configuration management across platforms with monitoring&lt;/li&gt;&lt;li&gt;However between CA, HP, and even BMC, there are well established solutions with large footprints and existing innovation on Virtualization&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Market Share:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;While Zen VM has broad appeal and adoption, VMware continues to enjoy significant marketshare, tight relationships with Intel &amp;amp; Cisco.&lt;/li&gt;&lt;li&gt;Additionally Microsoft and Oracle's position's within the Enterprise give them technical and sales advantages in addressing this market against Novell&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-style: italic;"&gt;I have great respect for Novell and their role as an innovator across the industry and across decades can not be over stated, however they have substantial barriers here.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-6173851909750823073?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/6173851909750823073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/is-novell-changing-game-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6173851909750823073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6173851909750823073'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/is-novell-changing-game-with.html' title='Is Novell changing the game with Virtualization Security?'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-2912342218966133785</id><published>2009-12-04T08:48:00.000-08:00</published><updated>2009-12-04T09:06:57.209-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BeyondTrust Cyber-Ark Cloakware Symark Oracle Identity Access IAM Enterprise Security PowerKeeper Compliance Privileged Password PAM PUM Unix/Linux Databases IBM zSeries Mainframes AD/LDAP'/><title type='text'>BeyondTrust Suite for Privileged Password Management</title><content type='html'>&lt;span style="font-style: italic;font-size:180%;" &gt;You need to have strong security for privileged accounts too?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;While good security practices dictate complex password rules that change frequently to protect the users, their accounts, and systems; we have collectively ignored the issue for our most sensitive accounts.  Worse, since these accounts are frequently shared we have no forensics on who is doing what.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Why was this ignored?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Databases, operating systems, ERP applications, etc. all have privileged or administrative accounts for “power users”.&lt;/li&gt;&lt;li&gt;But these “Power Users” frequently are a group, sharing the accounts and dealing with changing responsibilities, projects, roles, locations, etc.&lt;/li&gt;&lt;li&gt;Also these accounts are frequently needed for applications and they get hard coded into the application or its configuration and change management or industry certification requirements make it nearly impossible to update them.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;So how do you address it?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;BeyondTrust PowerKeeper provides Automatic Password Management (APM) to any operating system, database or device via SSH/Telnet&lt;/li&gt;&lt;li&gt;The solution addresses entitlements of users sharing the account with Automatic Authentication and Authorization (AAA) &lt;/li&gt;&lt;li&gt;PowerKeeper is offered as a hardened physical appliance or as a secure virtual appliance &lt;/li&gt;&lt;li&gt;PowerKeeper users and permissions from the enterprise’s LDAP or active Directory (AD) through group membership &lt;/li&gt;&lt;li&gt;Automatically discovers and brings under management any computers found within Active Directory &lt;/li&gt;&lt;li&gt;The solution prevents any direct access to the operating system and has FIPS-140-2 validated components for all encryption &lt;/li&gt;&lt;li&gt;Includes support for single/two-factor authentication using LDAP, AD, Secure ID, and Safeword &lt;/li&gt;&lt;li&gt;And detailed logging and reporting to directly address compliance requirements related to User/Approver/Requestor activities, Password maintenance activities, User and file entitlement (Rights), Internal diagnostics &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Here is a visual to give you the idea:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gn9hq2pkgmk/Sxk_1Xkkq2I/AAAAAAAAAG0/w3LM0sxEmPo/s1600-h/BeyondTrust.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://1.bp.blogspot.com/_gn9hq2pkgmk/Sxk_1Xkkq2I/AAAAAAAAAG0/w3LM0sxEmPo/s400/BeyondTrust.bmp" alt="" id="BLOGGER_PHOTO_ID_5411426613355391842" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To learn more check out:&lt;br /&gt;&lt;a href="http://www.beyondtrust.com/"&gt;www.beyondtrust.com &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-2912342218966133785?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/2912342218966133785/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/beyondtrust-suite-for-privileged.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2912342218966133785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2912342218966133785'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/12/beyondtrust-suite-for-privileged.html' title='BeyondTrust Suite for Privileged Password Management'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gn9hq2pkgmk/Sxk_1Xkkq2I/AAAAAAAAAG0/w3LM0sxEmPo/s72-c/BeyondTrust.bmp' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-2380155980735571487</id><published>2009-11-13T15:02:00.000-08:00</published><updated>2009-11-13T15:09:33.827-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Forrester PricewaterhouseCoopers PwC Rex Thorton Gary Loveland Bill Brenner CIO Magazine CISO CSO data security risk'/><title type='text'>Forrester &amp; PwC show where Information Security is going</title><content type='html'>&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:180%;"&gt;Compelling reasons for focusing on Enterprise Security from independent analysts &lt;span style="font-style: italic;"&gt;Forrester&lt;/span&gt; &amp;amp; &lt;span style="font-style: italic;"&gt;PricewaterhouseCoopers&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;p style="margin-bottom: 0in;"&gt;As illustrated recently in the CIO magazine article &lt;a href="http://www.cio.com/article/504837/Why_Security_Matters_Now"&gt;“Why Security Matters Now”&lt;/a&gt; By &lt;span style="font-style: italic;"&gt;Bill Brenner&lt;/span&gt;, PwC's CIO Survey illustrates that while IT departments, CFO's, and CEO's are looking carefully for any opportunity to cut costs, they are still reluctant to slow spending increases in Information Security.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;So why can't they curb spending growth on IT Security?&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;With the explosive growth in adoption of Social Networking sites/tools and Cloud Computing Services there is an ever growing threat for security risk and data security leak.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;While these are the most compelling, innovative, and revenue driving technologies … they cause the biggest heart burn.  Twitter, Facebook and LinkedIn drive collaboration, help organizations connect with customers, partners, etc. … But they also simplify fraud, data &amp;amp; identity theft, or just make it easier to make mistakes.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;While leveraging virtualization &amp;amp; cloud services allows organizations to cut costs and simplify their physical IT infrastructure, it also opens up the pandora's box of new security and management issues.   Driving your infrastructure towards the cloud has left you vulnerable to attacks and professional hackers have redoubled their endeavors to use these weaknesses against the big names like Google, Yahoo, etc. but also their enterprise customers.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;So where is the good news?&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Despite the arguably worst economic down turn in decades, organizations are spending more on in-house security solutions.  Security budgets are holding steady, and more organizations are employing a chief security officer (CSO) and/or chief information security officer (CISO).&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;PwC's 7&lt;sup&gt;th&lt;/sup&gt; annual survey including input from nearly 7,300 executives worldwide across industried including financial services, health care, retail, government, and so on.  The result was a clear indication that organizations are investing in data protection and authentication including:&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      1. Biometrics&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      2. Web content filters&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      3. Data leakage prevention&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      4. Disposable passwords/smart cards/tokens&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      5. Reduced or single-sign-on software&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      6. Voice-over-IP security&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      7. Web 2.0 security&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      8. Identity management&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;      9. Encryption of removable media&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;So who are they turning to?&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;According to Forrester Research and their recently updated Wave Report on IAM, there is a clear preference for Oracle as the leader and innovator in the the space.&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: arial;"&gt;&lt;span style="font-size:100%;"&gt;Their positioning of Oracle was driven by their leadership in product functionality/depth but also overall depth of the suite.  They highlight how Oracle is the only &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-size: 11pt;"&gt;vendor that has adopted an externalized Entitlements Solution and continues to deliver on it through Oracle Entitlements Server (OES), Formerly BEA AquaLogic Enterprise Security (ALES).  Also the commitment to Risk-Based Authentication through Oracle Adaptive Access Manager (OAAM) and the integrated  solution for Data Security, Oracle Information Rights Management (OIRM).&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;To see the CIO article&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.cio.com/article/504837/Why_Security_Matters_Now"&gt;http://www.cio.com/article/504837/Why_Security_Matters_Now&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;To get the full PwC survery&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.pwc.com/gx/en/information-security-survey/index.jhtml"&gt;http://www.pwc.com/gx/en/information-security-survey/index.jhtml&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;To read the Forrester’s IAM Wave Report&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.oracle.com/corporate/analyst/reports/infrastructure/sec/forrester-wave-iam.pdf"&gt;http://www.oracle.com/corporate/analyst/reports/infrastructure/sec/forrester-wave-iam.pdf&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-2380155980735571487?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/2380155980735571487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/forrester-pwc-show-where-information.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2380155980735571487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2380155980735571487'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/forrester-pwc-show-where-information.html' title='Forrester &amp; PwC show where Information Security is going'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-3651242023793528474</id><published>2009-11-13T10:11:00.000-08:00</published><updated>2009-11-13T10:45:50.337-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle Qualcomm State of Delaware Green Identity Management Access Management F5 Big-IP Load balancer Symantec DLP  11g OIF OID Directory Services'/><title type='text'>What's Up Doc?</title><content type='html'>&lt;span style="font-size:180%;"&gt;Highlights from Oracle's 56th IDM Newsletter "&lt;span style="font-style: italic;"&gt;News You Can Use&lt;/span&gt;"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;Innovation Awards&lt;/span&gt;&lt;p&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Awards honor innovative use of Oracle IAM at Cisco and Visa&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.oracle.com/us/corporate/press/022542"&gt;http://www.oracle.com/us/corporate/press/022542  &lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://www.oracle.com/us/corporate/press/022542"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt; &lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Oracle Magazine salutes Information Secured&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.oracle.com/technology/oramag/oracle/09-sep/o59secure.html"&gt;http://www.oracle.com/technology/oramag/oracle/09-sep/o59secure.html     &lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Oracle Identity Federation (OIF) Wins 2009 Iddy Award&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Oracle, along with NRI, and NTT have won an IDDY in the POC category for an application that demonstrates the possibility and practicality of achieving policy interoperability between OpenID and SAML.  See the press release here for complete details.&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Featured Partner&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;As noted in this blog&lt;a href="http://infinite-identities.blogspot.com/2009/10/symantec-announces-dlp-powered-by.html"&gt;, Oracle Information Rights Management and&lt;span style="font-style: italic;"&gt; Symantec DLP&lt;/span&gt; version 10 integration announced&lt;/a&gt;, taking data protection to the next level by combining data discovery with policy-based application of Oracle IRM.   &lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Oracle Identity Management 11g&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Oracle was pleased to announce the release of the first phase of Oracle Identity Management 11g this past summer, including enhancements to Oracle Identity Federation, Oracle Internet Directory, and Oracle Virtual Directory:&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.oracle.com/us/corporate/press/020724"&gt;http://www.oracle.com/us/corporate/press/020724   &lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Oracle  Identity Federation 11g&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;OIF 11g introduces the flexibility, performance and manageability enterprises require from federation solutions.  Building on the FMW frameworks for audit, logging, monitoring and credential storage, OIF puts Oracle's first-class compliance, diagnostic and security tools at the administrator's fingertips.  &lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Oracle Virtual Directory and Identity Publisher&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;OVD allows Identity Publisher feature for PeopleSoft HR, Siebel and Oracle Customer Hubs to make it possible to access identity information stored in these Oracle applications easily, in real-time without any additional synchronization.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Oracle Enterprise Single Sign-On Anywhere&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;ESSO Anywhere is the first comprehensive offering from a major vendor that lets enterprises host single tenant ESSO in a private cloud to provide users with secure access to heterogeneous enterprise resources from anywhere, anytime.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.oracle.com/us/corporate/press/035509"&gt;http://www.oracle.com/us/corporate/press/035509 &lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;F5 BIG-IP access solutions to be integrated with Oracle Access Manager&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://infinite-identities.blogspot.com/2009/10/identity-management-partners-making.html"&gt;As noted on this Blog&lt;/a&gt;, solution will enable customers to centralize and unify application access control services across diverse network environments.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Qualcomm Discusses The Next-Generation Identity Management Solutions&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Oracle Identity Management 11g provides the next level of cohesive management and deployment within a common console by allowing administrators to manage multiple parts of the stack.  Watch the video to see more about how Qualcomm is using Oracle Identity Management.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.oracle.com/us/products/middleware/identity-management/index.htm?section=VO&amp;amp;uid=8103894&amp;amp;refid=id_VO_8103894"&gt;http://www.oracle.com/us/products/middleware/identity-management/index.htm?section=VO&amp;amp;uid=8103894&amp;amp;refid=id_VO_8103894&lt;/a&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;State Of Delaware Goes "Green" By Implementing Oracle Identity Management  &lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;The State of Delaware provides online services to their citizens and employees.  They selected Oracle Identity Management based on flexibility, security, and auditing capabilities.  Please visit the link below to see the State of Delaware video.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.oracle.com/us/products/middleware/identity-management/index.htm?section=VO&amp;amp;uid=8103899&amp;amp;refid=id_VO_8103899"&gt;http://www.oracle.com/us/products/middleware/identity-management/index.htm?section=VO&amp;amp;uid=8103899&amp;amp;refid=id_VO_8103899&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Marc Chanliau discusses Security as a Service&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Director Product Management, Marc Chanliau, discusses how “&lt;span style="font-style: italic;"&gt;Oracle Fusion Middleware is highly predicated on service-oriented architecture (SOA) environments.&lt;/span&gt;”&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;To get the full details of the newsletter&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://ias.us.oracle.com/pls/portal/url/ITEM/77B4AF6E7C9AAFAAE040E50AE8AB2E15"&gt;In PDF format&lt;/a&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://ias.us.oracle.com/pls/portal/url/ITEM/77B4AF6E7C9DAFAAE040E50AE8AB2E15"&gt;In DOC format&lt;/a&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-3651242023793528474?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/3651242023793528474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/whats-up-dock.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3651242023793528474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3651242023793528474'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/whats-up-dock.html' title='What&apos;s Up Doc?'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-2623736844192568171</id><published>2009-11-12T09:59:00.000-08:00</published><updated>2009-11-13T11:33:36.337-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Provisioning GoogleApps Cloud SOA Aegis Oracle Sun Identity Management IAM SOA Security Google SaaS'/><title type='text'>Provisioning Cloud Services like Google Apps</title><content type='html'>&lt;p style="margin-bottom: 0in; font-style: italic;"&gt;&lt;span style="font-size:180%;"&gt;“You must not blame me if I do talk to the clouds.”&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;Henry David Thoreau&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;While SaaS/Cloud/SOA services … pick your buzz word, are great alternatives for small to medium size organizations (SMB), using them requires Provisioning &amp;amp; Federated Security which are challenges even for large Info Sec departments in Fortune 100 organizations.&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;In particular Google Apps™  provide small businesses, universities, schools, and other organizations the option to outsource collaboration tools, etc. for low- or no-cost.  But the issue of managing user access to those applications is still the responsibility of the organization.&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;So what is the solution?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;The Aegis Provisioning Appliance  for Google Apps delivers the tools needed to automatically add,  modify, and delete accounts by expanding organizations existing  directory services and provisioning infrastructure.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;The appliance provides a full set  of account management tools through real-time secure interfaces to  Google Apps.&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;How does it work?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Automates the creation, update,  deleting of accounts based on actions in an organizations existing  directory service (e.g. Microsoft Active Directory or LDAP)&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Provides delegated administration  for defined users to add, update, delete accounts   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Creates predefines web-based  workflows including approval chains&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Supports future expiration dates  or renewal approvals&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Simplifies the use of contractor  or guest accounts with access registration/sponsorship forms&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;What is the compliance impact?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;The Aegis Appliance ensures that  account creation, updates, deletes are done in line with the  organization’s policy.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Rules can be easily applied (and  demonstrated) so a contractor needing access to Gmail for one week  and then automatically disabled.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Allows organizations to start with  Google Apps and scale into a full enterprise IAM deployment from  Oracle&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;So how do I deal with the security issues?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;The Aegis Provisioning Appliance  can be combined with the either Aegis Password Management Appliance  or the Aegis SSO Appliance&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;This provides users with a  seamless login experience to their new Google accounts through  either synchronization of passwords to Google, or web-based SSO.&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Why are appliances beneficial to SMB's?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;AegisUSA Appliances are a  revolutionary approach to IAM, providing enterprise-level  functionality in an appliance form factor&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;The 80/20 rule - This reduces cost  through simplicity, removing the complexity by focusing on the most  common use cases&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Higher time-to-value for an  identity solution through lower implementation costs&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Provides a fully configured HW/SW  environment, leveraging enterprise-class components&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;This is part of a broader evolution of IAM as SMB's are becoming a growing consumer of IAM technology which is the driver behind the AegisUSA strategy.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gn9hq2pkgmk/SvxvLEWa52I/AAAAAAAAAGs/CPf9ii_IhAU/s1600-h/aegis-image.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 212px;" src="http://1.bp.blogspot.com/_gn9hq2pkgmk/SvxvLEWa52I/AAAAAAAAAGs/CPf9ii_IhAU/s400/aegis-image.jpg" alt="" id="BLOGGER_PHOTO_ID_5403315888874776418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:130%;"&gt;After all there are only more Cloud based services to come.  As Judy Garland put it "&lt;span style="font-style: italic;"&gt;Behind every cloud is another cloud.”&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;To learn more visit &lt;a href="http://www.aegisusa.com/identity_management_solutions/appliance_point/google_apps_provisioning.php"&gt;Aegis USA&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.aegisusa.com/identity_management_solutions/appliance_point/google_apps_provisioning.php"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-2623736844192568171?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/2623736844192568171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/provisioning-cloud-service-like-google.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2623736844192568171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2623736844192568171'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/provisioning-cloud-service-like-google.html' title='Provisioning Cloud Services like Google Apps'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gn9hq2pkgmk/SvxvLEWa52I/AAAAAAAAAGs/CPf9ii_IhAU/s72-c/aegis-image.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-2265828394924174276</id><published>2009-11-10T16:59:00.000-08:00</published><updated>2009-11-12T09:45:44.784-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle Quatum Secure Physical Logical Security Provisioning Gartner Burton Fraud Identity Theft Microsoft SAP IBM HP Sun Siemens'/><title type='text'>Bridging Physical and Logical Security</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(0, 0, 0);font-size:180%;" &gt;&lt;span style="font-family:Arial,sans-serif;"&gt;OK, so I secured the applications but who walked into the building???&lt;/span&gt;&lt;/span&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/p&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: bold;"&gt; &lt;span style="color: rgb(0, 0, 0);font-size:130%;" &gt;&lt;span style="font-family:Arial,sans-serif;"&gt;Why do I care?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Same  old reasons Audit &amp;amp; Compliance – Difficult to obtain &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Legal  mandates (FDA, DEA, SOX, SAS70 etc..) &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Cardholder  Access Rights and Global visit records &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;duplicate  records, not accepted by auditors - Multiple records in multiple  Physical Access Control Systems (PACS) &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Ghost  &amp;amp; Orphan accounts &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Managing  “PACS &amp;amp; Access Changes” is Complex &amp;amp; Costly &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;High  Operational Cost - multiple manual processes  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Card  Issue, Card De-activation, Lost or Stolen card &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Temporary  cards, Visitor management &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;New  Hire, Termination, Changes in Role, Title, Department, Location,  etc… &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Time  &amp;amp; Attendance, Asset Check in/Check-out, etc. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Multiple  Silos of Physical Access Control Systems (PACS) &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Configurations  in PACS are all different &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Different  Door names, Access Privileges, Clearances, &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Concept  of Global “Role or Groups” missing across PACS &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;No  Self-Service Console, No Global Administration &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;  &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Manually  Driven &amp;amp; Error Prone process increases Cost &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gn9hq2pkgmk/SvoNgEKhkdI/AAAAAAAAAGk/yfj05kY_uRM/s1600-h/Quantuam-why--hard.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 258px;" src="http://2.bp.blogspot.com/_gn9hq2pkgmk/SvoNgEKhkdI/AAAAAAAAAGk/yfj05kY_uRM/s400/Quantuam-why--hard.bmp" alt="" id="BLOGGER_PHOTO_ID_5402645547509191122" border="0" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: bold;"&gt; &lt;span style="color: rgb(0, 0, 0);font-size:130%;" &gt;&lt;span style="font-family:Arial,sans-serif;"&gt;Not convinced yet?  Here are the metrics...&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: normal;"&gt;ROI  Calculator Based on a large multinational organization&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: normal;"&gt;Current   system cost: &gt; $25yr per person on maintenance&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: normal;"&gt;Porting cost for acquisitions: &gt; $35/yr per person&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;b&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: normal;"&gt;Result: Over $20MM in savings, ROI in under 1 year!&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;But that is just on the physical security&lt;span style="font-weight: bold; font-style: italic;"&gt;.  Complexity costs, simplicity saves!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: bold;"&gt; &lt;span style="color: rgb(0, 0, 0);font-size:130%;" &gt;&lt;span style="font-family:Arial,sans-serif;"&gt;To learn more about this solution please check out their site:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt; &lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.quantumsecure.com/"&gt;http://www.quantumsecure.com/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-style: normal; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-2265828394924174276?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/2265828394924174276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/bridging-physical-and-logical-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2265828394924174276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2265828394924174276'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/bridging-physical-and-logical-security.html' title='Bridging Physical and Logical Security'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gn9hq2pkgmk/SvoNgEKhkdI/AAAAAAAAAGk/yfj05kY_uRM/s72-c/Quantuam-why--hard.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-2149243662722970634</id><published>2009-11-10T12:34:00.000-08:00</published><updated>2009-11-10T13:52:14.290-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Inifinite Identities Network World Facebook Linkedin twitter  Bill Snyder CIO CSO Why'/><title type='text'>Infinite Identities</title><content type='html'>&lt;span style="font-size:180%;"&gt;What's with the title, "Infinite Identities"?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gn9hq2pkgmk/SvngOwBGbsI/AAAAAAAAAGc/_qxEL2iFdVQ/s1600-h/infinity+mirror.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 266px;" src="http://1.bp.blogspot.com/_gn9hq2pkgmk/SvngOwBGbsI/AAAAAAAAAGc/_qxEL2iFdVQ/s400/infinity+mirror.jpg" alt="" id="BLOGGER_PHOTO_ID_5402595772019928770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Ok, so mostly it was selected because it was available and sounded catchy.  But the &lt;a href="http://www.networkworld.com/news/2009/110909-drowning-in-passwords-tips-to.html?hpg1=bn"&gt;Network World article&lt;/a&gt; today, "&lt;span style="font-style: italic; font-weight: bold;"&gt;Drowning in Passwords&lt;/span&gt;", really speaks to the origin of the name and the key challenges we all face as individuals and organizations trying to manage our seemingly infinite number of identities.&lt;br /&gt;&lt;br /&gt;While we mostly talk about security and compliance, IAM is truly a management problem.  Both in the real world and in the virtual one we all play many roles:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Father, husband, brother, son, grandson, friend, son-in-law&lt;/li&gt;&lt;li&gt;Litter Box cleaner, leaf raker, toilet plunger, bug-killer&lt;/li&gt;&lt;li&gt;Surfing-buddy, lunch-meeting-friend&lt;/li&gt;&lt;/ul&gt;With matrixed organizations, overlapping projects, evolving priorities, and dynamic timeslines we equally have a complex identity in the office:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Manager, employee, co-worker, partner, customer&lt;/li&gt;&lt;li&gt;Internally as a client of HR, procurement, legal,  expenses&lt;/li&gt;&lt;li&gt;Externally as a client of the healthcare provider, 401k, gym, etc.&lt;/li&gt;&lt;li&gt;Selling to customers, selling with/to partners or partners selling to you&lt;/li&gt;&lt;li&gt;The lead on a FY  planning project, contributor on a new product strategy, listener on a new marketing program&lt;/li&gt;&lt;/ul&gt;Each one of these roles has a unique identity, not just by itself but also in all their interactions.  This makes the number of not only accounts and password endless, but truly makes our entitlements infinite.&lt;br /&gt;&lt;br /&gt;The challenge is only further complicated when you layer in social networking, from blogs to Facebook and Twitter, our 1:1 interactions in one role gets mixed with our identities in another.  For example many have learned to keep their work "friends" on linkedin and their personal "friends" on Facebook, and their family ... on email.&lt;br /&gt;&lt;br /&gt;This increasing web of complexity fuels the continous need for new innovations, solutions, and ultimately integrations to address it.&lt;br /&gt;&lt;br /&gt;With this Blog, Infinite Identities, we will look to highlight and promote the best practices and best solutions being driven by innovative partnerships in IAM.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks for reading!&lt;br /&gt;Brian&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-2149243662722970634?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/2149243662722970634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/infinite-identities.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2149243662722970634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/2149243662722970634'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/infinite-identities.html' title='Infinite Identities'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gn9hq2pkgmk/SvngOwBGbsI/AAAAAAAAAGc/_qxEL2iFdVQ/s72-c/infinity+mirror.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-5897591513292970234</id><published>2009-11-09T14:42:00.000-08:00</published><updated>2009-11-09T16:08:20.589-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IDology KBA Oracle Adaptive Access Manager OAAM'/><title type='text'>Identity Proofing with IDology and Oracle Adaptive Access Manager (OAAM)</title><content type='html'>&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:180%;"&gt;Do you know who I am?   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;You may think so, but what if someone has hijacked my account, my identity, my computer, my web browser, my session, etc.  With high impact/value transactions, this “What if?” can have major consequences.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;Richard M. Nixon famously said &lt;i&gt;“I know you believe you understand what you think I said, but I am not sure you realize that what you heard is not what I meant.”&lt;/i&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;The point here being, even when you believe you know the user you may not?  In an era where accounts, machines, and identities are taken hostage there is a need for a technology that can verify that you are who you say you are.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;When do I need this?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;Someone is trying to open a  new bank or credit card account&lt;/u&gt;&lt;/i&gt; - stolen identities can be  translated into thousands of dollars in lost merchandise, hurt your  brand, and increase insurance or credit card rates.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;Bank Transfers&lt;/u&gt;&lt;/i&gt; –  Hijacked accounts from malware/viruses can leverage existing  legitimate sessions to transfer money out of customer accounts.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;Car Lease/purchase &lt;/u&gt;&lt;/i&gt;–  Imagine someone walks off the lot with a car, but under a false  identity. The retailers is unlikely to ever see the vehicle again.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;Cell Phone&lt;/u&gt;&lt;/i&gt; – Using  stolen identities or credit cards, thieves can rack up thousands in  international phone bills&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;Medical Records &lt;/u&gt;&lt;/i&gt;–  Employers could leverage inside information on potential employees  to make hiring decisions based on potential health insurance cost  from pre-existing conditions&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;Customer Data&lt;/u&gt;&lt;/i&gt; –  Sales person walks away from their desk and a soon-to-be-leaving  employee downloads current pipeline information or customer data to  bring to their future employer.&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;The list of examples is endless and applies across all types of organizations, from public sector to higher education, from Fortune 500 enterprises to financial services and health care.&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;So how does this work?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Based on policy, type of  transaction, or probability of Fraud calculated by OAAM's risk  scoring engine in real time, users can be promoted to join an  “Authentication Session”.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Users will be asked a series of  questions such as “Which one of these is a street you grew up on?”  or “What is the make/model of your first car?&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Unlike traditional &lt;i&gt;Knowledge  Based Authentication (KBA) &lt;/i&gt;with &lt;i&gt;&lt;b&gt;IDology &lt;/b&gt;&lt;/i&gt;questions  and answers are generated dynamically based on a combination of  public/private data sources.  This is called &lt;i&gt;&lt;b&gt;Dynamic KBA&lt;/b&gt;&lt;/i&gt;.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;Based on the users answers IDology  creates a fraud score, and OAAM determines, based on the  organizations defined policy, if it will allow the user to continue  with the transaction.&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;OAAM can also used other context  information such as Geo Location data, or require secondary or  step-up authentication from something like StrikeForce SMS,  ActivIdentity, or Verisign VIP.&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;You want to see it in action:&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://lp.idology.com/Website_OracleDemo.html"&gt;Demo&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://lp.idology.com/Website_OracleDemo.html"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-5897591513292970234?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/5897591513292970234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/identity-proofing-with-idology-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5897591513292970234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5897591513292970234'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/identity-proofing-with-idology-and.html' title='Identity Proofing with IDology and Oracle Adaptive Access Manager (OAAM)'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-5658906288716394384</id><published>2009-11-09T12:56:00.000-08:00</published><updated>2009-11-09T13:13:28.457-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ArcSight IdentityView Oracle Identity Manager OIM ESM SIEM'/><title type='text'>Oracle / ArcSight – Providing Real Time Oversight of User Behavior</title><content type='html'>&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style=";font-family:Arial,sans-serif;font-size:180%;"  &gt;When IT infrastructure generates millions of events/logs daily, how do you do you know if there is an issue and who is causing it?&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gn9hq2pkgmk/SviD4q9R4UI/AAAAAAAAAGM/IJ0bdYlLRpM/s1600-h/arcsight1.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 229px;" src="http://2.bp.blogspot.com/_gn9hq2pkgmk/SviD4q9R4UI/AAAAAAAAAGM/IJ0bdYlLRpM/s400/arcsight1.bmp" alt="" id="BLOGGER_PHOTO_ID_5402212762658136386" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Traditionally SIEM (System Information &amp;amp; Event Management) products track events by what resources are employed, when, by whom and for what result.  Unfortunately the “who” part changes in real time based on the process being used and for what purpose. But with &lt;i&gt;&lt;b&gt;IdentityView&lt;/b&gt;&lt;/i&gt;, &lt;b&gt;ArcSight &lt;/b&gt;transfers identity and role information from &lt;b&gt;Oracle Identity Manager &lt;/b&gt;into its Enterprise Security Manager so that it can correlate all the identity markers and privileges of a specific user.  &lt;/span&gt;&lt;/span&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Armed with this proverbial identity matrix, ArcSight ESM can then associate events with a specific person, independent of the various identities that he or she employs. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style=";font-family:Arial,sans-serif;font-size:130%;"  &gt;So why do we need this?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;To  automate the correlation of compliance and policy violations with  specific users &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;To  understand how your key users (admins to accountants) are using IT  infrastructure&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Increase  accuracy/productivity of your role engineering and provisioning  process &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Respond  to security and compliance issues before they damage the  organization&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Provide  business owners with information about policy and security  violations in terms that they understand and can act on&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Provide  visibility and assurance to C-level executives that policies are  being enforced to conform with compliance regulations such as  Sarbanes-Oxley, PCI, HIPAA, etc. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style=";font-family:Arial,sans-serif;font-size:130%;"  &gt;What are the benefits?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Leverages  the investment in OIM by linking users and roles to security  problems, compliance violations, etc.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Faster  identification of security and compliance issues resulting in more  rapid response and remediation &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Control/monitor  access rights &amp;amp; IT usage (services, apps, data, etc.) requires  correlating millions of real time alerts and logs with specific user  activity &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Provide  auditors with proof that controls are in place and effective &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Visibility  into violations of corporate policies covering customer, employee  and business-sensitive data &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Improved  productivity via automation of required reports, summaries and  auditor requests for information  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_gn9hq2pkgmk/SviEOXljx9I/AAAAAAAAAGU/dsjI63M1kjU/s1600-h/arcsight2.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 259px;" src="http://3.bp.blogspot.com/_gn9hq2pkgmk/SviEOXljx9I/AAAAAAAAAGU/dsjI63M1kjU/s400/arcsight2.bmp" alt="" id="BLOGGER_PHOTO_ID_5402213135415494610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style=";font-family:Arial,sans-serif;font-size:130%;"  &gt;So why now?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;&lt;b&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;You  already have this covered&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;&lt;/ul&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Many organizations have invested in home-grown event monitoring  solutions, but the challenge is that problem continues to get  bigger, with every new system (applications, devices, Cloud/SaaS  solutions) added to the environment.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;ArcSight  cleanly replaces those solutions and delivers more functionality at  a lower cost. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;&lt;b&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;You  can't face this now, maybe in the future&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;SIEM  solutions are now considered standard “due care” for auditors  concerned with SOX compliance.  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;PCI  DSS #10 explicitly requires monitoring of the relevant IT  infrastructure.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;i&gt;&lt;u&gt;&lt;b&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;You  don't have the resources &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/u&gt;&lt;/i&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;Budgeting  for security and compliance is difficult but by combining ArcSight  with Oracle Identity Manager, organizations can “double up” on  their return on investment based on the synergy between the  products.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;SIEM  alone provides multiple solutions for the security group, compliance  group, risk management, etc. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style=";font-family:Arial,sans-serif;font-size:130%;"  &gt;To learn more:&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial,sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.arcsight.com/products/products-identity/"&gt;http://www.arcsight.com/products/products-identity/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-5658906288716394384?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/5658906288716394384/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/oracle-arcsight-providing-real-time.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5658906288716394384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5658906288716394384'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/oracle-arcsight-providing-real-time.html' title='Oracle / ArcSight – Providing Real Time Oversight of User Behavior'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gn9hq2pkgmk/SviD4q9R4UI/AAAAAAAAAGM/IJ0bdYlLRpM/s72-c/arcsight1.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-4740047488227858586</id><published>2009-11-06T06:57:00.000-08:00</published><updated>2009-11-06T08:13:04.847-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vordel SOA Cloud Service Broker Google Apps Amazon EC2'/><title type='text'>Vordel Launches Cloud Service Broker</title><content type='html'>&lt;style type="text/css"&gt;  &lt;!--   @page { margin: 0.79in }   P { margin-bottom: 0.08in }   A:link { so-language: zxx }  --&gt;  &lt;/style&gt;    &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:180%;"&gt;&lt;span style="color:#000000;"&gt;With the Cloud Service Broker, Vordel pledges to bring trust and reliability to Cloud Computing &lt;/span&gt;&lt;/span&gt; &lt;/p&gt;   &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:130%;"&gt;So what does this mean?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;The  solution aggregates multi-domain services across their enterprise,  partners and 3&lt;sup&gt;rd&lt;/sup&gt; party cloud services such as Amazon EC2  and Google Apps&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;Through  bringing the services together, the Broker enables organisations to  consistently define and manage policy across these services and  report on them&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;Through  the Broker, composite applications can be built seamless while  offering full visibility, trust and control". &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:130%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;So why do we need this?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;Organizations  using Cloud services in conjunction with their own on-premises SOA  face major issues related to reliability and trustworthiness.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;Very  difficult to bring together services from across domains (i.e.  on-premises, Public and Private Clouds, and B2B) into coherent  composite services and applying policies to them. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: normal; font-style: italic;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;Vordel CEO, Vic Morris, said "Many organizations see the value of incorporating Cloud Services into their IT infrastructure, but they also have concerns about the reliability and performance of these services outside their domain of control. The Vordel Cloud Service Broker addresses these issues by providing a trustworthy “&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:130%;"&gt;So how does it work?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;The  Broker solves this problem by registering services from all three  domains into a single repository, enabling monitoring, management  and policy enforcement. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;Plus  the Vordel Cloud Service Broker offers value added services like  caching, acceleration, and transformation, delivering enterprises  savings in time and money. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:130%;"&gt;What is under the covers?&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Multi-Domain  Registry Repository (MDRR)&lt;/span&gt; – This is where the Broker registers  aggregated services across domains.  This one-stop-shopping for  compliance to Service Level Agreements, privacy and security  mandates. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Analytics&lt;/span&gt; – Providing the visibility through an &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;i&gt;independent  &lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;audit  trail including raw usage information, service quality, patterns of  usage over time, and identity of users. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Content  Analysis &lt;/span&gt;– Content is analyzed to enable Data Loss Prevention  (DLP), content-level threats, and application-level attacks at the  API and payload level. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Caching&lt;/span&gt;  – Protecting against latency from the Cloud service, saving money  by allowing some requests to be serviced by the broker itself.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Composition  &lt;/span&gt;– Allowing developers to link together local apps with  Cloud-hosted apps via Web Services interfaces, database, or message  schemes like MQ or JMS. &lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Content  transformation &lt;/span&gt;– Accelerated transformation for mediation between  different applications or between REST API interfaces and SOAP, &lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;JMS,  COBOL, etc. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;SLA  Monitoring&lt;/span&gt; - Comprehensive monitoring of response time of Cloud  services, and the entire transaction throughput time. &lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Traffic  Throttling&lt;/span&gt; – Vordel refers to this as the &lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;“surge  protector”, protecting against apps making a high number of calls  to a Cloud service by deflecting a portion to a back-up service,  newly provisioned for this purpose. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Event  Alerting&lt;/span&gt; – Notification of events like Cloud outages so that  remedial measures can be put into place. &lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Extensibility  to 3rd Party Valued Added Services&lt;/span&gt; – Traditionally very  difficult/costly with non standard API's from competing solutions,  but is made easy &amp;amp; pluggable here. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;/p&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: bold;"&gt;&lt;span style="font-family:Arial, sans-serif;font-size:130%;"&gt;For more information: &lt;/span&gt; &lt;/p&gt;&lt;br /&gt;&lt;a href="http://www.vordel.com/scripts/downloadA.pl?downloadfile=VordelCloudServiceBroker.pdf"&gt;View the PDF&lt;/a&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.vordel.com/solutions/cloud.html"&gt;Product Page&lt;/a&gt; &lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;a href="http://www.vordel.com"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style="font-style: normal;"&gt;Company &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; &lt;/p&gt;   &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;a href="http://www.reuters.com/article/pressRelease/idUS130253+05-Nov-2009+BW20091105"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;Press Release&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;a href="http://www.reuters.com/article/pressRelease/idUS130253+05-Nov-2009+BW20091105"&gt;&lt;span style="font-family:Arial, sans-serif;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-weight: normal;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-4740047488227858586?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/4740047488227858586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/vordel-launches-cloud-service-broker.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4740047488227858586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4740047488227858586'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/vordel-launches-cloud-service-broker.html' title='Vordel Launches Cloud Service Broker'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-7550230900005032145</id><published>2009-11-05T06:27:00.000-08:00</published><updated>2009-11-05T12:51:55.530-08:00</updated><title type='text'>One More Time!  Oracle Tops Gartners Provisioning List</title><content type='html'>&lt;span style="font-size:130%;"&gt;Oracle Announced this morning that they were again named the leader in Gartner's "Magic Quadrant for User Provisioning".&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;The Gartner Magic Quadrant ranks vendors based on their completeness of vision and their ability to execute on that vision. This is indicative of a dramatic evolution in the Identity &amp;amp; Access Management Market over the nearly 5 years since &lt;em&gt;CA announced their &lt;/em&gt;acquisition of &lt;a href="http://news.cnet.com/CA-to-buy-Netegrity-for-430-million/2100-1014_3-5398932.html"&gt;Netegrity.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The move sparked a shift from focusing on Web Single Sign-On to end-to-end suites for Identity and Access Management and lead to the spending spree at Oracle which put together this leading suite of products and market vision. In total, &lt;strong&gt;&lt;em&gt;Oracle brought together technology from 9 IAM innovators&lt;/em&gt;&lt;/strong&gt; to develop this market leading technology suite:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Phaos&lt;/em&gt; - Now &lt;strong&gt;Oracle Identity Federation&lt;/strong&gt; &lt;em&gt;(OIF)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;Oblix&lt;/em&gt; - Now &lt;strong&gt;Oracle Access Manager &lt;/strong&gt;&lt;em&gt;(OAM)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;Confluent &lt;/em&gt; - Now &lt;strong&gt;Oracle Web Services Manager &lt;/strong&gt;&lt;em&gt;(OWSM)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;Thor&lt;/em&gt; - Now &lt;strong&gt;Oracle Identity Manager&lt;/strong&gt; &lt;em&gt;(OIM)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;Bridgestream&lt;/em&gt; - &lt;strong&gt;Now Oracle Role Manager&lt;/strong&gt; &lt;em&gt;(ORM)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;Bharosa&lt;/em&gt; - Now &lt;strong&gt;Oracle Adaptive Access Manager&lt;/strong&gt; &lt;em&gt;(OAAM)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;PassLogix&lt;/em&gt; OEM - Now &lt;strong&gt;Oracle Enterprise SSO &lt;/strong&gt;&lt;em&gt;(OESSO)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;BEA ALES  &lt;/em&gt;- Now &lt;strong&gt;Oracle Entitlements Server&lt;/strong&gt; &lt;em&gt;(OES)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;em&gt;BEA WebLogic Security Services&lt;/em&gt; - Now &lt;em style="font-weight: bold;"&gt;OPSS&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;One of the pioneers in this evolution had this comment on the announcement; &lt;/p&gt;&lt;p&gt;&lt;em&gt;"With roles, rules and policies continually evolving within the enterprise, organizations need strong user provisioning solutions to streamline security, achieve increasing levels of automation and efficiency and ensure sustainable compliances," said Amit Jasuja, vice president, Oracle Identity Management. "We are pleased to be recognized as a leader in Gartner's Magic Quadrant for User Provisioning, and remain committed to delivering the most secure, comprehensive and scalable solutions to customers." &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Looking at the full &lt;a href="http://us.lrd.yahoo.com/_ylt=ArO2ptsG493Tdz0Owm4ppKytcq9_;_ylu=X3oDMTE2dWpuM21wBHBvcwMzBHNlYwNuZXdzQXJ0Qm9keQRzbGsDbWFnaWNxdWFkcmFu/SIG=12k26b517/**http%3A//www.oracle.com/go/%3F%26Src=6811200%26Act=415%26pcode=WWMK09047377MPP020"&gt;Magic Quadrant for User Provisioning &lt;/a&gt;it is interesting to note that with Sun in the top 3 as well it is clear that this market is heading for further evolution but more importantly innovation that will directly benefit customers and technology providers leveraging an increasingly mature, standardized, IAM suite across each layer of the application stack regardless of the deployment model.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Here is the link to the&lt;br /&gt;&lt;a href="http://finance.yahoo.com/news/Oracle-Named-a-Leader-in-iw-1868935534.html?x=0&amp;amp;.v=1"&gt;press release.&lt;/a&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-7550230900005032145?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/7550230900005032145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/one-more-time-oracle-tops-gartners.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/7550230900005032145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/7550230900005032145'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/one-more-time-oracle-tops-gartners.html' title='One More Time!  Oracle Tops Gartners Provisioning List'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-7932499375399631127</id><published>2009-11-04T12:52:00.000-08:00</published><updated>2009-11-06T06:55:51.299-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CA SiteMinder Oracle Access Manager IAM OAM Persistent Systems ORCL migration ROI Enterprise Security Web Single Sign-On'/><title type='text'>Persistent helps organizations say Bye-Bye to CA SiteMinder</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;span style="font-size:180%;"&gt;Persistent Systems delivers a packaged so&lt;/span&gt;&lt;span style="font-size:180%;"&gt;lution for migrating from CA &lt;span style="font-style: italic;"&gt;SiteMinder &lt;/span&gt;to &lt;span style="font-style: italic;"&gt;Oracle Access Manager (OAM)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;So why do we need a solution for this? &lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;u&gt;Accelerated&lt;/u&gt; – Save time (i.e. $ on implementation)&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;u&gt;Lower Risk &lt;/u&gt;– Repeatable solution reduces project risk &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;u&gt;Proven&lt;/u&gt; – Well laid path by existing reference customers&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;u&gt;Turnkey&lt;/u&gt; – OOTB solution&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;Why do organizations want to migrate?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; CA SiteMinder has a &lt;i style=""&gt;&lt;u&gt;very large &amp;amp; dissatisfied&lt;/u&gt;&lt;/i&gt; install base because of &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;b style=""&gt;&lt;u&gt;Poor investment in Dev and Support&lt;/u&gt;&lt;/b&gt; – There are substantially less engineers building/supporting SiteMinder then when it was part of Netegrity, while Oracle has increased the dev team on OAM&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;b style=""&gt;&lt;u&gt;Costly Support&lt;/u&gt;&lt;/b&gt; – CA support pricing model creates painfully high pricing (disproportionate with the rest of the market) in the mind of many organizations.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Stack Limitations:&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; As a &lt;u&gt;stack&lt;/u&gt;, the Oracle IdM suite has dramatically out paced CA in completing the picture and innovating towards the future.&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;So who should consider this? &lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; SiteMinder users &lt;i style=""&gt;with Oracle products&lt;/i&gt; (DB, EBS, Apps, IdM…….) – i.e. those that will benefit from the Oracle IAM Suite and the broader Oracle Suite&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Customers who use &lt;i style=""&gt;both SiteMinder and OAM&lt;/i&gt; for different applications or business units – i.e. those hungry for actual SSO&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Customers who have &lt;i style=""&gt;SiteMinder environments through acquisitions&lt;/i&gt; – i.e. cost savings&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Anyone with a SiteMinder deployment&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;So why now?&lt;span style=""&gt;  &lt;/span&gt;Why was this not done already? &lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;u&gt;Legacy&lt;/u&gt; – SSO environments constitute several years of work/investment&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;u&gt;Perception&lt;/u&gt; – Migrations are seen as long, effort-intensive, expensive and risky&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;u&gt;Time&lt;/u&gt; – Typically ROI is too far away, but not in this case&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;Persistent Systems' SM2OAM solution addresses all these challenges!&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in; font-weight: bold;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: italic; font-weight: normal;"&gt;Case in Point &lt;/span&gt;–&lt;/span&gt; At a large public technology provider (not ORCL), the migration time from SM to OAM was brought down from 24 months to 6 months!&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;OK, so how do we do this?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Option 1 - Fully outsourced&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Turnkey Persistent solution includes ‘acceleration plus services’&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; All phases delivered by Persistent&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Direct, subcontract and fixed fee options available&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Option 2 - Joint solution&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Persistent provides ‘acceleration’ for existing services team&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Phases in blue delivered by partner, rest delivered jointly by Persistent&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.75in; text-indent: -0.25in;"&gt; &lt;span style=";font-family:&amp;quot;;" &gt;&lt;span style=""&gt;o&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Fixed fee, markup and shared revenue options available&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gn9hq2pkgmk/SvNRs-kXaGI/AAAAAAAAAF8/oCcD9iIj5v0/s1600-h/Persistent+SiteMinder1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 307px; height: 132px;" src="http://4.bp.blogspot.com/_gn9hq2pkgmk/SvNRs-kXaGI/AAAAAAAAAF8/oCcD9iIj5v0/s400/Persistent+SiteMinder1.png" alt="" id="BLOGGER_PHOTO_ID_5400750211298977890" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;So who is Persistent Systems?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Over a decade working on the backend doing OAM engineering&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in; font-weight: bold;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Over 140 person years of engineering experience with Oracle IAM stack&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in; font-weight: bold;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Ongoing implementation efforts – 20+ marquee customers &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in; font-weight: bold;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; Winner of Oracle's partner &lt;i&gt;‘Challenge’ &lt;/i&gt;– OID 2 billion benchmark, &lt;i&gt;‘last-mile’ &lt;/i&gt;solutions&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in; font-weight: bold;"&gt; &lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; 20 years old, profitable, 5K people, hundreds of customers, Thousands of product releases&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.25in; text-indent: -0.25in;"&gt; &lt;span style="font-weight: bold;font-family:Symbol;" &gt;&lt;span style=""&gt;·&lt;span style=";font-family:&amp;quot;;font-size:7;"  &gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;b&gt;&lt;span style="font-weight: bold;"&gt;Global presence – North America, Europe, UK and Asia&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style=""&gt;&lt;span style="font-size:16;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;b style=""&gt;To get started contact:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;Muneer Taskar&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="mailto:muneer_taskar@persistentsys.com" target="_parent"&gt;muneer_taskar@persistentsys.com&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="mailto:sameer_karmarkar@persistent.co.in" target="_parent"&gt;&lt;/a&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-7932499375399631127?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/7932499375399631127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/persistent-helps-organizations-say-bye.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/7932499375399631127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/7932499375399631127'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/persistent-helps-organizations-say-bye.html' title='Persistent helps organizations say Bye-Bye to CA SiteMinder'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_gn9hq2pkgmk/SvNRs-kXaGI/AAAAAAAAAF8/oCcD9iIj5v0/s72-c/Persistent+SiteMinder1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-8204385919650418716</id><published>2009-11-03T16:02:00.000-08:00</published><updated>2009-11-03T16:07:56.460-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OAAM StrikeForce Adaptive Out-of-Band ProtectID Oracle Adaptive Access Manager'/><title type='text'>StrikeForce Technologies ProtectID® provides step-up two factor “Out-of-Band” authentication to OAAM</title><content type='html'>&lt;p&gt;Using &lt;strong&gt;OAAM&lt;/strong&gt; and &lt;strong&gt;ProtectID&lt;/strong&gt;® together, companies can defend against the latest online threats, including account takeover schemes and man-in-the-middle attacks to restore trust in Internet transactions. The combined offering utilizes advanced authentication and fraud prevention to evaluate risk and alert organizations in real-time to potential fraud threats. In addition, the &lt;strong&gt;OAAM/ProtectID® &lt;/strong&gt;solution enables companies to employ a range of security options, including “Out-of-Band” phone authentication, to meet diverse user requirements or upgrade to higher levels of protection as threats increase without reinvesting in infrastructure. Enterprise Security Officers prefer two-factor authentication all the time. Consumers are happy with simple ID/Password authentication, thereby finding a workable solution has been a challenge for companies.&lt;br /&gt;&lt;br /&gt;The &lt;strong&gt;Oracle Adaptive Access Manager (OAAM) &lt;/strong&gt;combined with &lt;strong&gt;StrikeForce’s ProtectID®,&lt;/strong&gt; meets this challenge. Heightened regulatory requirements (e.g. FFIEC and The Red Flags) recommend adopting strong two-factor authentication for the higher risk transactions. &lt;em&gt;Gartner&lt;/em&gt; recommends “Out-of-Band” authentication as a necessary layer to prevent Identity Theft. The regulations explicitly discuss the use of One Time Passwords (OTP) delivered via phones or similar devices in addition to utilizing “Out-of-Band” strong authentication. The ProtectID® strong authentication platform provides these services (which is the reason the partnership with StrikeForce was developed). Many of these enterprises also want two-factor authentication for their employees (which OAAM and ProtectID® also solves in combination and separately).&lt;br /&gt;&lt;br /&gt;The ProtectID® platform is an implementation or “Cloud Service” of the OOB Authentication methodology providing strong authentication via a number of different authentication technologies. Currently the platform supports the following strong authentication methodologies:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;“Out-of-Band” methodologies: &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Entering a fixed PIN in a phone &lt;/li&gt;&lt;li&gt;Entering One Time Password (OTP) in a phone &lt;/li&gt;&lt;li&gt;Sending an OTP to a phone via SMS &lt;/li&gt;&lt;li&gt;Sending an OTP to a phone via text to speech &lt;/li&gt;&lt;li&gt;Sending an OTP via email&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Token methodologies: &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Hard Token OTP (key fob that displays OTP when a button is pressed) &lt;/li&gt;&lt;li&gt;Soft Token OTP (OATH compliant software) that can reside on a PC or a Black Berry or PDA or J2ME compliant cell phone.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Value of ProtectID® to OAAM &lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;A ProtectID® and OAAM combined solution delivers an advanced security proposition to combat the growing threat of consumer identity theft and fraud on the Internet. The combination of OAAM’s real-time fraud prevention and ProtectID’s real-time two-factor “Out-of-Band” authentication platform, provides financial institutions, online retailers, health care companies and other businesses with a robust arsenal of security tools for protecting consumers from fraud, for accurate identification of employee access, and all while complying with industry security guidance’s and regulations.&lt;br /&gt;&lt;br /&gt;Therefore, with the combination of OAAM and ProtectID®, the client benefits from a Return On Investment (ROI) and compliancy with regulatory requirements (FFIEC, Red Flags and others), with minimal inconvenience to the most important person, the end user. The majority of transactions authenticated should pass the OAAM fraud prevention process. For those transactions that are detected and flagged as potentially fraudulent, OAAM would then automatically invoke ProtectID® to perform a two-factor strong authentication for the consumer, which minimizes the expensive help desk process and thereby provides greater satisfaction and cost savings. This total fraud prevention solution is a win/win for the company and its clients. ProtectID® could also be used for password resets, high dollar value online transactions, remote log on, etc.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Interfacing ProtectID® with OAAM&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;ProtectID® appears as a web service to a web site that implements both OAAM and ProtectID® and allows for step-up or other requests for strong 2-factor “Out-of-Band” authentication based on the risk level determined by the Company and or OAAM.&lt;br /&gt;&lt;br /&gt;OAAM only employs step-up authentication when it’s truly needed so end users are not being inconvenienced.&lt;br /&gt;&lt;br /&gt;Following is a link to allow you to test “Big Bank” showing an example of how ProtectID® can be integrated with OAAM for the best all around total solution (fraud mitigation with 2-factor “Out-of-Band authentication) with options and flexibility. Just sign on with a user name and it will ask you to register and allow you to test the Best complete compliant authentication solution available and all from Oracle:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://d.oobauth.com:8888/sample/"&gt;http://d.oobauth.com:8888/sample/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more information please contact:&lt;br /&gt;&lt;br /&gt;Mark L. Kay, CEO&lt;br /&gt;StrikeForce Technologies, Inc.&lt;br /&gt;&lt;a href="mailto:marklkay@strikeforcetech.com"&gt;marklkay@strikeforcetech.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.strikeforcetech.com/"&gt;www.strikeforcetech.com&lt;/a&gt;&lt;br /&gt;(o) 732-661-9641 &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-8204385919650418716?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/8204385919650418716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/strikeforce-technologies-protectid.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/8204385919650418716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/8204385919650418716'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/strikeforce-technologies-protectid.html' title='StrikeForce Technologies ProtectID® provides step-up two factor “Out-of-Band” authentication to OAAM'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-9189361000638757085</id><published>2009-11-02T09:53:00.000-08:00</published><updated>2009-11-02T14:52:48.981-08:00</updated><title type='text'>No More Tokens!!!</title><content type='html'>&lt;span style="font-size:180%;"&gt;&lt;strong&gt;Juniper says "&lt;em&gt;Good Bye Tokens&lt;/em&gt;" with Oracle Adaptive Access Manager (OAAM)&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;As the #1 SSL VPN provider with 92% of Fortune 100 and 8 of top 10 commercial banks plus 47 of 50 US State Governments, odds are you have used a Juniper SSL VPN to connect to your employer, partner, or service provider … and odds are you had to use a hardware security token. &lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt; &lt;/p&gt;&lt;p&gt;While tokens like&lt;em&gt; RSA BSAFE&lt;/em&gt; provide an accepted alternative to passwords, they are clunky, costly, and not secure from many potential attacks like man-in-the-middle or man-in-the-browser.&lt;br /&gt;&lt;br /&gt;Looking to help customers overcome these challenges, Juniper partnered with Oracle to integrate the Oracle Adaptive Access Manager (OAAM) which not only provides a software alternative to tokens, greatly improving the user experience and dramatically lowering TCO, it also saves hard dollars and protects the organization’s reputation with real-time fraud detection.&lt;br /&gt;&lt;br /&gt;More specifically OAAM provides: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Strong, multi-factor authentication for secure access control &lt;/li&gt;&lt;li&gt;Seamless interoperability with hetergenous App Servers (IBM, BEA, SAP, etc.) &lt;/li&gt;&lt;li&gt;Enforces access at the protected resources thru web plug-ins &lt;/li&gt;&lt;li&gt;Delegates authentication and authorization decisions to a central authority&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Which compliments the existing features and security of Juniper SA SSL VPN such as: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Provides secure, encrypted communication channel for all remote users from anywhere and from any device&lt;/li&gt;&lt;li&gt;Enforces Oracle’s policy based authentication and authorization policies at perimeter &lt;/li&gt;&lt;li&gt;Provide 3 different levels of connectivity, going beyond just web support, including Layer 3 VPN connectivity for fat clients, VoIP, streaming, FTP, and more &lt;/li&gt;&lt;li&gt;Performs comprehensive “Host-Checking” to ensure end-point integrity &lt;/li&gt;&lt;li&gt;Enables coordinated identity based threat response and prevention with other products&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The benefits include: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Lower cost and complexity of authenticating users &lt;/li&gt;&lt;li&gt;Eliminates non-user friendly, expensive gadgets, tokens or proprietary software downloads &lt;/li&gt;&lt;li&gt;Host checker + real-time fraud prevention provides greatest overall access security &lt;/li&gt;&lt;li&gt;Low-cost, flexible way for enteprises to extend strong authentication to partners, suppliers, contractors, and non-employees accessing critical applications &lt;/li&gt;&lt;li&gt;Native integration eliminates need for OAAM’s UIO option&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="font-size:180%;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="color:#009900;"&gt;How does this really save me money?&lt;/span&gt;&lt;/em&gt;   -  &lt;span style="color:#ff0000;"&gt;Good question! Here is how it works:&lt;/span&gt;&lt;/strong&gt;&lt;span style="color:#ff0000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Lower Hardware Costs &lt;/strong&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;ul&gt;&lt;li&gt;&lt;blockquote&gt;&lt;/blockquote&gt;Mitigates need to provide SSL on each Web / App Server; fewer servers &lt;/li&gt;&lt;li&gt;Single appliance scales to thousands of simultaneous users &lt;/li&gt;&lt;li&gt;Carrier-class reliability and HA features &lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Lower Management Costs&lt;/strong&gt; &lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Seamlessly leverage and instantly extend I&amp;amp;AM policies to remote users &lt;/li&gt;&lt;li&gt;Eliminate need to duplicate policies across servers and networks &lt;/li&gt;&lt;li&gt;Plug ‘n play integration – deployment guides and Oracle reference architectures &lt;/li&gt;&lt;li&gt; Leverage combined audit and log data for compliance &lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Lower Business Risk&lt;/span&gt; &lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Moves OAM policy enforcement point out to network perimeter, increasing security &lt;/li&gt;&lt;li&gt;Coordinated identity-based threat response to attacks &lt;/li&gt;&lt;li&gt;Comprehensive identity based access logs &lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;To download the data sheet: &lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.juniper.net/us/en/local/pdf/solutionbriefs/3510251-en.pdf"&gt;http://www.juniper.net/us/en/local/pdf/solutionbriefs/3510251-en.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;For more information on the Juniper Oracle Partnership:&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;a href="http://www.juniper.net/solutions/information_technology_topics/accelerating_oracle_business/index.html"&gt;http://www.juniper.net/solutions/information_technology_topics/accelerating_oracle_business/index.html&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;To learn more about OAAM:&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;a href="http://www.oracle.com/technology/products/id_mgmt/oaam/index.html"&gt;http://www.oracle.com/technology/products/id_mgmt/oaam/index.html&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Don’t believe me, ask Juniper:&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;David Colodny&lt;br /&gt;&lt;a href="mailto:dcolodny@juniper.net"&gt;dcolodny@juniper.net&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-9189361000638757085?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/9189361000638757085/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/no-more-tokens.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/9189361000638757085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/9189361000638757085'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/11/no-more-tokens.html' title='No More Tokens!!!'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-4182287349100283246</id><published>2009-10-28T11:34:00.001-07:00</published><updated>2009-10-28T12:00:35.632-07:00</updated><title type='text'>Oracle OPN Days - Virtual Event</title><content type='html'>&lt;span style="font-size:180%;"&gt;Much more the "virtually helpful"...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://events.unisfair.com/index.jsp?eid=491&amp;amp;seid=26&amp;amp;code=OPNDaysVEOracleMailSignature"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 134px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5397721206228235042" border="0" alt="" src="http://4.bp.blogspot.com/_gn9hq2pkgmk/SuiO1rXTsyI/AAAAAAAAAFk/hEFD06kEJmA/s320/OPN+Days+Virtual+Event+12-nov.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:180%;"&gt;What are Virtual Days?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;Somewhat of a hybrid between web conferencing and social networking these events offer a unique opportunity to gather subject matter experts from around the world with industry thought leaders have dynamic discussions about technology, architecture, but most importantly ... &lt;em&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;How do you make your organization more successful?&lt;/span&gt;&lt;/strong&gt;&lt;/em&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Challenges with a traditional conference:&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;We have all been to many large conference halls from the San Francisco Moscone Center to the Venetian Hotel &amp;amp; Conference Center in Vegas or the Orlando Florida Conference Center.  While the face time to build relationships is important there are many draw backs, for example consider these scenarios we have all experienced:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;You make it to the booth of someone you need to connect with but the expert on your topic won't be here until tomorrow.&lt;/li&gt;&lt;li&gt;A key customer approaches but Jim Thompson who runs product management just went to the bathroom&lt;/li&gt;&lt;li&gt;Despite being at the event, Tom Jones the architect whose advice is highly valued by the CIO and decision maker is too shy to approach face to face so you never knew they were there or could find Tom.&lt;/li&gt;&lt;li&gt;You are talking to a potentially large customer but they are interested in a new product or partnership and the collateral did not make it to the show.&lt;/li&gt;&lt;li&gt;You agree to share content on a pressing issue but the action items get scribbled on a conference flyer and get lost.&lt;/li&gt;&lt;li&gt;You finally connect with the right people and you can't find a place to sit and talk or hear one another over the crowd&lt;/li&gt;&lt;li&gt;You get cards from everyone you meet but it would take another week to index then and store the information virtually and it becomes difficult to follow up.&lt;/li&gt;&lt;li&gt;You get to the booth in the morning but your technical sales manager was out with a client the night before and did not make it to the booth in time to meet another key client&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Instead with a Virtual Event you can:&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Dynamically grab the content you need and provide it electronically&lt;/li&gt;&lt;li&gt;Pull in experts from anywhere in any language instantly &lt;/li&gt;&lt;li&gt;Digitally share contact information and action items&lt;/li&gt;&lt;li&gt;Avoid the high cost of traveling to conferences&lt;/li&gt;&lt;li&gt;Save your feet and time running between sessions&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Why the Oracle OPN Days?&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Support for 9 languages&lt;/li&gt;&lt;li&gt;Product, alliance, and sales experts in 1 place&lt;/li&gt;&lt;li&gt;Information across Oracle database, middleware, and applications&lt;/li&gt;&lt;li&gt;This event is focused on partners and how they can be successful with Oracle and benefit from our many sales and marketing programs.&lt;/li&gt;&lt;li&gt;Rapidly navigate the ~85,000 Oracle organization&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;To learn more visit the site:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://events.unisfair.com/index.jsp?eid=491&amp;amp;seid=26&amp;amp;code=OPNDaysVEOracleMailSignature"&gt;http://events.unisfair.com/index.jsp?eid=491&amp;amp;seid=26&amp;amp;code=OPNDaysVEOracleMailSignature&lt;/a&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-4182287349100283246?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/4182287349100283246/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/oracle-opn-days-virtual-event.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4182287349100283246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4182287349100283246'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/oracle-opn-days-virtual-event.html' title='Oracle OPN Days - Virtual Event'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_gn9hq2pkgmk/SuiO1rXTsyI/AAAAAAAAAFk/hEFD06kEJmA/s72-c/OPN+Days+Virtual+Event+12-nov.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-64735935722453925</id><published>2009-10-27T12:28:00.000-07:00</published><updated>2009-10-30T13:21:18.557-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Extended Identity Management Ecosystem Update'/><title type='text'>Updated Oracle IDM Ecosystem</title><content type='html'>&lt;strong&gt;&lt;span style="font-size:130%;"&gt;The Oracle IDM Ecosystem is strong and growing!&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Oracle announced the Extended IDM Ecosystem in &lt;em&gt;June 2007&lt;/em&gt; to unify security islands, as Organizations commonly have multiple security systems in place—one technology to secure physical access, another to secure legacy applications, and yet another to secure network access. To cope with these "silo'd" solutions, Oracle partnered with best-of-breed ISVs to offer a central and effective means to enforce security policy across all enterprise resources.&lt;br /&gt;&lt;br /&gt;Today the mission continues to be the same while the technology landscape and customer requirements have evolved. Since I took it over the leadership of the Ecosystem in June of 2008 we have added several new categories including:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;SOA Security &amp;amp; Governance&lt;/strong&gt; – Enforcing and managing message level security, throttling, and acceleration for the Oracle SOA Suite &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Identity Assurance&lt;/strong&gt; - Certified solutions for fraud prevention combining &lt;em&gt;Oracle Adaptive Access Manager (OAAM)&lt;/em&gt; with solutions spanning Identity Proofing, Internet Geolocation, Out-of-Band Authentication, Secure Remote Access, and more.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Data Loss Prevention&lt;/strong&gt; – Partnering with the leaders in end point security and data protection to identify the flow of sensitive information and protect it through IRM, and IDM policy reconciliation. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Priveleged User Management&lt;/strong&gt; – Extending the management of application accounts, users, and credentials to provision, secure, and monitor privileged/shared accounts by users or applications.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The core benefits, that extend to these new categories as well, include: &lt;/p&gt;&lt;li&gt;&lt;strong&gt;Reduces deployment risk&lt;/strong&gt;—Certified and proven interoperability significantly reduces time to deployment, costs, and risks of deployment&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Strengthens security and compliance&lt;/strong&gt;—Central management of disparate resources and identities improves enterprise security and enhances regulatory compliance&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improves operational efficiencies&lt;/strong&gt;—Linking identity across systems and providing a central authentication interface greatly improves operational efficiencies and user productivity&lt;br /&gt;&lt;/li&gt;&lt;br /&gt;&lt;p&gt;The current list of partners includes:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Authentication &amp;amp; Identity Management&lt;/strong&gt;—Arcot Systems, ArcSight, Daon, Entrust, F5 Networks, Giesecke &amp;amp; Devrient, Juniper Networks, Quantum Secure, RSA&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Identity Assurance&lt;/strong&gt;—ActivIdentity, BIO-key, IDology, Juniper Networks, Quantum Secure, Quova, StrikeForce, Vasco&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;SOA Security &amp;amp; Governance&lt;/strong&gt; – &lt;a href="http://www.vordel.com/"&gt;Vordel &lt;/a&gt;, &lt;a href="http://www.layer7tech.com/"&gt;Layer7 &lt;/a&gt;, &lt;a href="http://www.intelforfusion.com/"&gt;Intel &lt;/a&gt;, and &lt;a href="http://www.sonoasystems.com/"&gt;Sonoa Systems &lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Loss Prevention&lt;/strong&gt; – &lt;a href="http://www.mcafee.com/us/enterprise/products/data_protection/data_loss_prevention/host_data_loss_prevention.html"&gt;McAfee&lt;/a&gt;, &lt;a href="http://www.symantec.com/en/uk/business/theme.jsp?themeid=dlp"&gt;Symantec, &lt;/a&gt;&amp;amp; &lt;a href="http://www.controlguard.com/"&gt;ControlGuard &lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Priveleged Account Management&lt;/strong&gt; – &lt;a href="http://www.cloakware.com/cloakware-ds/products/password-authority.php"&gt;Cloakware&lt;/a&gt;, &lt;a href="http://www.blogger.com/www.cyber-ark.com/"&gt;Cyber-Ark&lt;/a&gt;, &lt;a href="http://www.liebsoft.com/"&gt;Liebsoft&lt;/a&gt;, and &lt;a href="http://www.beyondtrust.com/"&gt;BeyondTrust (formerly Symark) &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;As always you can learn about the Ecosystem on Oracle.com&lt;br /&gt;&lt;a href="http://www.oracle.com/products/middleware/identity-management/ecosystem.html"&gt;http://www.oracle.com/products/middleware/identity-management/ecosystem.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To learn more about becoming an Oracle Partner please visit the Oracle Partner Network:&lt;br /&gt;&lt;a href="http://www.oracle.com/partners/index.html"&gt;http://www.oracle.com/partners/index.html&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-64735935722453925?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/64735935722453925/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/updated-oracle-idm-ecosystem.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/64735935722453925'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/64735935722453925'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/updated-oracle-idm-ecosystem.html' title='Updated Oracle IDM Ecosystem'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-6733631608100974136</id><published>2009-10-27T10:29:00.000-07:00</published><updated>2009-10-28T11:02:24.743-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle IRM Symantec DLP 11g Data Loss Prevention DRM information rights management'/><title type='text'>Symantec announces DLP powered by Oracle IRM</title><content type='html'>&lt;div id="container"&gt;&lt;div id="container-inner" class="pkg"&gt;&lt;div id="pagebody"&gt;&lt;div id="pagebody-inner" class="pkg"&gt;&lt;div id="alpha"&gt;&lt;div id="alpha-inner" class="pkg"&gt;&lt;h2 id="archive-title"&gt;Oracle IRM and Symantec DLP integration announced&lt;/h2&gt;&lt;div id="entry-15220" class="entry"&gt;&lt;div class="entry-content"&gt;&lt;div class="entry-body"&gt;&lt;p&gt;&lt;img alt="Symantec" src="http://blogs.oracle.com/irm/images/symantec.gif" width="326" height="37" /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.symantec.com/about/news/release/article.jsp?prid=20091027_02" target="_blank"&gt;Launching&lt;/a&gt; their latest release of &lt;a href="http://www.symantec.com/business/products/family.jsp?familyid=data-loss-prevention" target="_blank"&gt;data loss prevention&lt;/a&gt; (DLP), Symantec focused on the new functionality in version 10 allowing customers to directly leverage the benefits or &lt;strong&gt;&lt;em&gt;Oracle IRM&lt;/em&gt;&lt;/strong&gt; to protect their sensitive data.&lt;/p&gt;&lt;p&gt;Symantec is the leader in DLP technology and organizations world wide leverage their solution for discovery and monitoring of enterprise network traffic and perimeters to detect the flow of information that needs to be protected for privacy, compliance, or from competitors. When DLP detects something that is deemed confidential it can take some action upon it, typically this is in the form of blocking the information from continuing to be transmitted or removing it from the file servers.&lt;/p&gt;&lt;p&gt;However combining &lt;a href="http://blogs.oracle.com/irm/2008/11/oracle_irm_and_data_loss_preve.html" target="_blank"&gt;DLP with IRM&lt;/a&gt; means you don't have to restrict the end user or impede the business by blocking their attempts to collaborate. Instead you directly enable the organization to interact securely and teach best practices. Oracle IRM technology will encrypt and protect the document or email so that it can be shared. IRM ensures only authorized users have access and provides advanced security controls such as revocation to the information, even after it has left the control of your enterprise networks.&lt;/p&gt;&lt;p&gt;Oracle and Symantec have been working closely together over the past months to build an integration between Oracle IRM and DLP based on direct input from customers and implementation partners. The combined solution offers the most innovative, use-case driven security solution of any IRM and DLP combination. &lt;/p&gt;&lt;p&gt;Oracle IRM is the leading rights management solution for enterprise-scale document and email security and Oracle is the leader in Enterprise Identity &amp;amp; Access Management according to Gartner, Burton and Forrester. Combining this innovative technology and thought leaders for Access Management and Content Security means customers can now have rich monitoring and detection capabilities. &lt;/p&gt;&lt;p&gt;Instead of blocking attempts to share valuable data, this solution allows it to happen securely. We first demonstrated this capability at Oracle Open World and if you were not able to attend, we've uploaded some video demonstrations to our &lt;a href="http://www.youtube.com/oracleirm/" target="_blank"&gt;YouTube channel&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;If you want to learn more about using Oracle IRM and DLP together &lt;a href="mailto:irm_evaluation_request_ww@oracle.com?subject=IRM%20and%20DLP%20evaluation%20request%20from%20the%20IRM%20Blog"&gt;contact us&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;object width="480" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/2T-HkUMwdB8&amp;amp;hl=en&amp;amp;fs=1&amp;amp;color1=0x5d1719&amp;amp;color2=0xcd311b&amp;amp;hd=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/2T-HkUMwdB8&amp;hl=en&amp;fs=1&amp;color1=0x5d1719&amp;color2=0xcd311b&amp;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;object width="480" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/HVXrzpo8jxs&amp;amp;hl=en&amp;amp;fs=1&amp;amp;color1=0x5d1719&amp;amp;color2=0xcd311b&amp;amp;hd=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/HVXrzpo8jxs&amp;hl=en&amp;fs=1&amp;color1=0x5d1719&amp;color2=0xcd311b&amp;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;/center&gt;&lt;/p&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="comments" class="comments"&gt;&lt;form onsubmit="if (this.bakecookie.checked) rememberMe(this)" method="post" name="comments_form" action="http://blogs.oracle.com/mt/mt-comments.cgi"&gt;&lt;div id="comments-open" class="comments-open"&gt;&lt;div class="comments-open-content"&gt;&lt;br /&gt;&lt;br /&gt;&lt;p id="comments-open-text"&gt;&lt;strong&gt;&lt;span style="font-size:180%;"&gt;Oracle IRM resources&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/form&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="beta"&gt;&lt;div id="beta-inner" class="pkg"&gt;&lt;div class="module-welcome module"&gt;&lt;a href="http://irm-download.oracle.com/" target="_blank"&gt;&lt;img src="http://blogs.oracle.com/irm/images/free_download_140x40.gif" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;h2 class="module-header"&gt;&lt;a href="http://www.oracle.com/goto/irm/" target="_blank"&gt;IRM at oracle.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="javascript:void" toolbar="no,location=no,directories=no,menubar=no,scrollbars=no,resizable=yes,width=1060,height=900')&amp;quot;"&gt;Online demonstration&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.oracle.com/technology/software/products/content-management/index_irm.html" target="_blank"&gt;Downloads on OTN&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.oracle.com/technology/products/content-management/irm/IRM-technical-whitepaper.pdf" target="_blank"&gt;Technical white paper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.oracle.com/products/middleware/content-management/docs/securing-and-tracking-business-information.pdf" target="_blank"&gt;Business white paper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The official Oracle IRM Blog is available &lt;a href="http://blogs.oracle.com/irm/"&gt;here&lt;/a&gt; or by looking through &lt;a href="http://blogs.oracle.com/irm/archives.html"&gt;the archives&lt;/a&gt;.&lt;/h2&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-6733631608100974136?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/6733631608100974136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/symantec-announces-dlp-powered-by.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6733631608100974136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6733631608100974136'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/symantec-announces-dlp-powered-by.html' title='Symantec announces DLP powered by Oracle IRM'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-3791777104363077858</id><published>2009-10-21T13:21:00.000-07:00</published><updated>2009-11-06T11:25:09.251-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle Open World Liebsoft Priveleged Account Manager F5  Load Balancer Big-IP NetworkWorld'/><title type='text'>Identity Management Partners making news at Oracle Open World</title><content type='html'>While Oracle Open World is traditionally dominated by Database and Applications, this year &lt;strong&gt;&lt;em&gt;Identity Management made waves and made press&lt;/em&gt;&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Network World's Dave Kearns similarly noted the shows focus but reported on some of the highlights for Information Security in his Column&lt;br /&gt;&lt;a href="http://www.networkworld.com/newsletters/dir/2009/101909id2.html?hpg1=bn"&gt;http://www.networkworld.com/newsletters/dir/2009/101909id2.html?hpg1=bn&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Particularly he noted the innovative solution for Privileged Account Management offered by Liebsoft and highly tuned and integrated to work with Oracle products:&lt;br /&gt;&lt;div&gt;&lt;a href="http://www.liebsoft.com/common.aspx?id=3103"&gt;http://www.liebsoft.com/common.aspx?id=3103&lt;/a&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Also of interest to Dave was the unique Enterprise SSO Anyware offering Oracle brought to market through their alliance with PassLogix:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.oracle.com/us/corporate/press/035509"&gt;http://www.oracle.com/us/corporate/press/035509&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Though Dave did not mention what many feel is one of the most innovative architectural solutions for Web Access Management announced by F5 to reduce the complexity of agent deployments, updates, and management by moving them to the load balancer with their industry leading Big-IP product.&lt;br /&gt;&lt;a href="http://www.f5.com/news-press-events/press/2009/20091006.html"&gt;http://www.f5.com/news-press-events/press/2009/20091006.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-3791777104363077858?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/3791777104363077858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/identity-management-partners-making.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3791777104363077858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3791777104363077858'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/identity-management-partners-making.html' title='Identity Management Partners making news at Oracle Open World'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-5521675777994621560</id><published>2009-10-21T12:09:00.000-07:00</published><updated>2009-10-21T13:19:14.926-07:00</updated><title type='text'>What is Consumer SOA? "COSA"</title><content type='html'>&lt;strong&gt;&lt;span style="font-size:130%;"&gt;So what is Consumer Oriented Service Architecture (COSA)? &lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;SOA is a well known and established technology area with innovation driven by technology vendors like BEA/Oracle and SoftwareAG for leveraging/wrapping legacy applications and rapidly integrating technology across platforms, partners, and customers but COSA is a new concept.&lt;br /&gt;&lt;br /&gt;The term itself was coined by &lt;em&gt;Oracle Product Manager Vikas Jain&lt;/em&gt; in his blog&lt;br /&gt;&lt;a href="http://ws-security.blogspot.com/2009/10/consumer-oriented-service-architecture.html"&gt;http://ws-security.blogspot.com/2009/10/consumer-oriented-service-architecture.html&lt;/a&gt;&lt;br /&gt;But the idea is well established and was driven by those delivering services not by technology vendors.&lt;br /&gt;&lt;br /&gt;As Vikas points out "&lt;em&gt;While SOA concentrated on how to make the service architecture better, it left out on the consumer focus. The consumer focus becomes especially important when services are exposed to partners."&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Vikas goes on to define the key challenges and requirements for a COSA solution such as Consumer Identification, Throttling so that the right customers get the right SLA, Contracts &amp;amp; Policies, Reporting, and Provisioning.&lt;br /&gt;&lt;br /&gt;Today media vendors and social media vendors are leading the charge and paving the road with innovative technology vendors like Vordel, Sonoa Systems, Layer7,  and Intel.&lt;br /&gt;&lt;br /&gt;MTV Networks is a great example with their work with Sonoa Systems:&lt;br /&gt;&lt;a href="http://www.sonoasystems.com/about-us/news-and-events/mtv-networks-selects-sonoa-for-api-infrastrcture-feed-management"&gt;http://www.sonoasystems.com/about-us/news-and-events/mtv-networks-selects-sonoa-for-api-infrastrcture-feed-management&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It is also demonstrated by the participation of Steve Riley, Evangelist and Strategy for Amazon at the Vordel User Conference.&lt;br /&gt;&lt;a href="http://www.vordel.com/news/press/16_09_09.html"&gt;http://www.vordel.com/news/press/16_09_09.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Intel is targeting Oracle Fusion customers with &lt;a href="http://www.intelforfusion.com/"&gt;http://www.intelforfusion.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Layer7 is also making waves with their announcement around integrating Oracle Service Bus with their hardware XML Gateway.  &lt;a href="http://www.layer7tech.com/main/products/osba.html"&gt;http://www.layer7tech.com/main/products/osba.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-5521675777994621560?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/5521675777994621560/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/what-is-consumer-soa-cosa.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5521675777994621560'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5521675777994621560'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/what-is-consumer-soa-cosa.html' title='What is Consumer SOA? &quot;COSA&quot;'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-5792685544433243311</id><published>2009-10-06T09:53:00.000-07:00</published><updated>2009-10-19T10:01:50.878-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='F5 OAM BigIp'/><title type='text'>F5 Announces Plans to Unify Access Management for Web Applications</title><content type='html'>Solution Will Combine F5`s BIG-IP System with Oracle Access Manager to Enhance&lt;br /&gt;Single Sign-on Capabilities and Simplify Access Control&lt;br /&gt;&lt;br /&gt;SEATTLE--(Business Wire)-- F5 Networks, Inc. (NASDAQ:FFIV), the global leader in Application Delivery Networking (ADN), today announced that it plans to integrate F5 BIG-IP access solutions with Oracle Identity Management software to centralize web application authentication and authorization services, streamline access management, and reduce infrastructure costs.&lt;br /&gt;&lt;br /&gt;Details&lt;br /&gt;Advantages of combining F5 and Oracle solutions will include:&lt;br /&gt;&lt;br /&gt;* Tight integration of the F5 BIG-IP system with Oracle Access Manager, enabling reduced TCO, lowered deployment risk, and streamlined operational efficiencies for customers.&lt;br /&gt;* Integration with Oracle Access Manager Single Sign-On (SSO) to promote a superior end-user experience and enhanced user productivity. This integration will enable organizations to adopt an access management and SSO strategy that allows rapid ROI.&lt;br /&gt;* A unified point of enforcement to simplify auditing and control changes in configuring application access settings.&lt;br /&gt;&lt;br /&gt;F5, a member of the Oracle PartnerNetwork, will provide additional information about the planned solution in Booth #1421 at Oracle OpenWorld, taking place October 11-15 at the Moscone Convention Center in San Francisco. To learn more about F5`s presence at Oracle OpenWorld and other industry events, please visit &lt;a href="http://www.f5.com/news-press-events/events"&gt;www.f5.com/news-press-events/events&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Availability&lt;br /&gt;The combined solution is expected to be available within the first half of CY 2010.&lt;br /&gt;&lt;br /&gt;Supporting Quotes&lt;br /&gt;"Ease of implementation and TCO are very important to Oracle and its customers," said Brian Mozinski, Director, Product Management, Identity Management and Security at Oracle. "By integrating functionality from Oracle Access Manager and F5`s BIG-IP system, customers can further streamline their deployments of the Oracle Fusion Middleware 11g Identity Management Suite."&lt;br /&gt;&lt;br /&gt;"Our goal is to help businesses maximize the value of their technology investments," said Muneer Taskar, Director, Sales at Persistent Systems, a technology company specializing in software product development services. "Integration and interoperability from vendors like Oracle and F5 make customer deployments simpler and less costly to deploy and manage. We look forward to adding this new access management solution to our product portfolio."&lt;br /&gt;&lt;br /&gt;"Close working relationships with key identity and access management vendors like Oracle are very important to F5," said Jason Needham, Sr. Director of Product Management at F5. "Together, we can deliver significant value to our joint customers by enabling them to centralize and unify application access control services across increasingly diverse network environments. F5 is committed to providing innovative access management solutions and edge services-such as SSL VPN, acceleration, and other managed services-to maximize IT agility and deliver enhanced functionality, security, and ROI to customers."&lt;br /&gt;&lt;br /&gt;About F5 Networks&lt;br /&gt;F5 Networks is the global leader in Application Delivery Networking (ADN), focused on ensuring the secure, reliable, and fast delivery of applications. F5`s flexible architectural framework enables community-driven innovation that helps organizations enhance IT agility and dynamically deliver services that generate true business value. F5`s vision of unified application and data delivery offers customers an unprecedented level of choice in how they deploy&lt;br /&gt;ADN solutions. It redefines the management of application, server, storage, and network resources, streamlining application delivery and reducing costs. Global enterprise organizations, service and cloud providers, and Web 2.0 content providers trust F5 to keep their business moving forward. For more information, go to www.f5.com.&lt;br /&gt;&lt;br /&gt;About the Oracle PartnerNetwork&lt;br /&gt;Oracle PartnerNetwork is a global business network of more than 21,000 companies that deliver innovative software solutions based on Oracle software. Through access to Oracle`s premier products, education, technical services, marketing and sales support, the Oracle PartnerNetwork program provides partners with the resources they need to be successful in today`s global economy. Oracle partners are able to offer their customers leading-edge solutions backed by Oracle`s position as the world's largest business software company. Partners who are able&lt;br /&gt;to demonstrate superior product knowledge, technical expertise and a commitment to doing business with Oracle qualify for the Certified Partner levels. For more information, go to http://oraclepartnernetwork.oracle.com.&lt;br /&gt;&lt;br /&gt;F5 and BIG-IP are trademarks or service marks of F5 Networks, Inc., in the U.S. and other countries. Oracle is a registered trademark of Oracle Corporation and/or its affiliates. All other product and company names herein may be trademarks of their respective owners.&lt;br /&gt;&lt;br /&gt;This press release may contain forward-looking statements relating to future events or future financial performance that involve risks and uncertainties. Such statements can be identified by terminology such as "may," "will," "should," "expects," "plans," "anticipates," "believes," "estimates," "predicts," "potential," or "continue," or the negative of such terms or&lt;br /&gt;comparable terms. These statements are only predictions and actual results could differ materially from those anticipated in these statements based upon a number of factors including those identified in the company's filings with the SEC.&lt;br /&gt;&lt;br /&gt;F5 Networks, Inc.&lt;br /&gt;Alane Moran, 206-272-6850&lt;br /&gt;a.moran@f5.com&lt;br /&gt;or&lt;br /&gt;Connect Public Relations&lt;br /&gt;Holly Hagerman, 801-373-7888&lt;br /&gt;hollyh@connectpr.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-5792685544433243311?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5792685544433243311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5792685544433243311'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/10/f5-announces-plans-to-unify-access.html' title='F5 Announces Plans to Unify Access Management for Web Applications'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-180005682135892658</id><published>2009-09-30T13:23:00.000-07:00</published><updated>2009-11-02T08:43:40.509-08:00</updated><title type='text'>Symark is now BeyondTrust</title><content type='html'>&lt;div align="left"&gt;&lt;span style="font-size:180%;"&gt;&lt;strong&gt;BeyondTrust PowerBroker® Joins Oracle Extended Identity Management Ecosystem&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;“ONLY 47% OF COMPANIES&lt;br /&gt;IMPLEMENT AN IT REGULATORY&lt;br /&gt;COMPLIANCE PROGRAM.”&lt;br /&gt;- DELOITTE SURVEY, 2009 &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Information technology and intellectual property are the lifeblood of a typical enterprise&lt;br /&gt;these days. Safeguarding these precious assets is imperative to every organization, and&lt;br /&gt;the number one priority needs to be protecting the organization from itself. Specifically,&lt;br /&gt;protecting administrative, database and superuser passwords, such as root, on Unix/&lt;br /&gt;Linux servers represents the most critical access points to business-critical IT assets and&lt;br /&gt;resources at their most fundamental level. Addressing this dilemma, in addition to the&lt;br /&gt;time consuming tasks of managing multiple identity management solutions, can be an&lt;br /&gt;impossible task for enterprises. That is why BeypndTrust chose to partner with Oracle, in&lt;br /&gt;order to offer a single source solution for all enterprise identity management needs.&lt;br /&gt;BeyondTrust PowerBroker, now part of the Oracle® Extended Identity Management&lt;br /&gt;Ecosystem, provides enterprises with a comprehensive privileged access control application&lt;br /&gt;to implement highly flexible policy language to enforce across multiple Unix/Linux&lt;br /&gt;platforms and operations throughout the enterprise. Features include:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;strong&gt;SELECTIVELY DELEGATE ROOT &amp;amp; OTHER SPECIAL ACCOUNT PRIVILEGES &lt;/strong&gt;&lt;br /&gt;PowerBroker enables users to perform specified administrative tasks without disclosing the&lt;br /&gt;account password to them, dramatically strengthening enterprise security. Additionally,&lt;br /&gt;PowerBroker secures and manages third-party application account privileges, such as Oracle&lt;br /&gt;database accounts, which commonly store business critical information.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;strong&gt;HIGHLY CONFIGURABLE SECURITY &amp;amp; ENFORCEMENT POLICIES &lt;/strong&gt;&lt;br /&gt;PowerBroker offers a dynamic policy scripting language to arm administrators with the tools&lt;br /&gt;to create and manage detailed policies seamlessly, which grant specific access to perform&lt;br /&gt;tasks. Enterprises can granularly restrict per user, group, netgroup, host, day/date/time, to/&lt;br /&gt;from specified hosts, and based upon AD, NIS, NIS+ or LDAP data.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;strong&gt;SECURELY LOG, REPORT &amp;amp; PRODUCE RELIABLE AUDIT TRAILS &lt;/strong&gt;&lt;br /&gt;PowerBroker logs every requested task, including all environmental information, and&lt;br /&gt;encrypts logs to prevent modification. PowerBroker protects enterprises from common&lt;br /&gt;violations of many U.S. and Canadian government compliance regulations and industry&lt;br /&gt;standards such as SOX, PCI, HIPAA, GLBA and FISMA.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;strong&gt;QUICK DEPLOYMENT &amp;amp; NON-INTRUSIVE &lt;/strong&gt;&lt;br /&gt;PowerBroker provides reliable, highly secure operations with minimal impact to existing&lt;br /&gt;systems and network architectures. There are no required changes to the Unix/Linux kernel&lt;br /&gt;or operating system or system reboots after installation. PowerBroker sessions are similar to&lt;br /&gt;telnet sessions, requiring minimal system resources.&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_gn9hq2pkgmk/Su8LSm60ZhI/AAAAAAAAAFs/7Xz38AMb1_Q/s1600-h/BeyondTrust.bmp"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 414px; DISPLAY: block; HEIGHT: 300px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5399546892553315858" border="0" alt="" src="http://4.bp.blogspot.com/_gn9hq2pkgmk/Su8LSm60ZhI/AAAAAAAAAFs/7Xz38AMb1_Q/s400/BeyondTrust.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;To learn more visit:&lt;/div&gt;&lt;br /&gt;&lt;div align="left"&gt;&lt;a href="http://www.beyondtrust.com/"&gt;http://www.beyondtrust.com/&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-180005682135892658?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/180005682135892658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/09/symark-is-now-beyondtrust.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/180005682135892658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/180005682135892658'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/09/symark-is-now-beyondtrust.html' title='Symark is now BeyondTrust'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_gn9hq2pkgmk/Su8LSm60ZhI/AAAAAAAAAFs/7Xz38AMb1_Q/s72-c/BeyondTrust.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-4504644346234856452</id><published>2009-08-27T09:49:00.000-07:00</published><updated>2009-10-27T09:53:03.459-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Quova OAAM Access Fraud Adaptive geolocation'/><title type='text'>Location, Location, Location!!!</title><content type='html'>&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Why IP Intelligence (Geo Location Data) is important for Authentication?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;In the growing area of risk based authentication where organizations from banks to governmental departments are looking to share more information and services with people there is a much greater risk/fear of fraud.&lt;br /&gt;&lt;br /&gt;Information Security vendors such as Oracle, RSA, Verisign, and others have complimented their existing Web Access Control technologies like &lt;em&gt;&lt;strong&gt;Oracle Access Manager (OAM)&lt;/strong&gt;&lt;/em&gt; with Risk Based Authentication solutions such as &lt;strong&gt;&lt;em&gt;Oracle Adaptive Access Manager (OAAM)&lt;/em&gt;&lt;/strong&gt; which assess the risk of fraud at the moment of a transaction and, based on policy, respond by allowing/denying the transaction or requiring secondary or “&lt;em&gt;Step-up Authentication&lt;/em&gt;”.&lt;br /&gt;&lt;br /&gt;In these scenarios, the more context available to the transaction the better risk analysis. Knowing that a banking customer who lives in Oslo, Norway is trying to send a wire transfer out of the account is actually logging in from Seattle, WA gives makes it simple to understand the potential risk.&lt;br /&gt;&lt;br /&gt;IP data enables core risk assessments made within OAAM including; website visitor location (i.e. block high risk locations), network characteristice (i.e. is the visitor connected through an anonymzing proxy—intentionally masking their location), IP data provides an “IP fingerprint” of a visitor.&lt;br /&gt;&lt;br /&gt;To help deliver this intelligence to customers Oracle partners with Quova as the preferred IP provider for OAAM. They provide specific ROI advantages over competitors.. Quova’s unmatched accuracy and depth of proxy intelligence data result in increased fraud catch and lower false positive escalations.&lt;br /&gt;&lt;br /&gt;And Quova is the only provider that subjects its research process and data quality to annual independent audit by PricewaterhouseCoopers. Quova is widely recognized as the market leader and is in use throughout the anti-fraud marketplace. Quova for OAAM customers include; Monster.com, DFCU, ICICI Bank, National City Corporation.&lt;br /&gt;&lt;br /&gt;To Learn more about Quova:&lt;br /&gt;Contact Jon Heintschel&lt;br /&gt;650-528-3739 or &lt;a href="mailto:jheintschel@quova.com"&gt;jheintschel@quova.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To Learn more about OAAM&lt;br /&gt;&lt;a href="http://www.oracle.com/technology/products/id_mgmt/oaam/index.html"&gt;http://www.oracle.com/technology/products/id_mgmt/oaam/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Or to learn about the Oracle Access Suite:&lt;br /&gt;&lt;a href="http://www.oracle.com/products/middleware/identity-management/access-management-suite.html"&gt;http://www.oracle.com/products/middleware/identity-management/access-management-suite.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-4504644346234856452?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/4504644346234856452/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/08/location-location-location.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4504644346234856452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/4504644346234856452'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/08/location-location-location.html' title='Location, Location, Location!!!'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-3524366887302767903</id><published>2009-08-01T07:33:00.000-07:00</published><updated>2009-11-05T08:00:46.050-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Oracle Daon Bio-Metric Public Sector Government'/><title type='text'>Why the Public Sector needs Bio-Metric Solutions and how ORCL + Daon can help</title><content type='html'>&lt;span style="font-size:180%;"&gt;Combing Oracle IDM Products with Best-of-Breed Biometric Infrastructure from &lt;a href="http://www.daon.com/"&gt;Daon &lt;/a&gt;enables successful deployments across the Public Sector&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Why are government organizations looking for this?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Stronger security to mitigate fraud &amp;amp; ID theft &lt;em&gt;(more details below)&lt;/em&gt;&lt;/li&gt;&lt;li&gt;Strong Authentication without tokens &lt;em&gt;(more details below)&lt;/em&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Why has it not been adopted already? &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Requirements for end-points to capture &amp;amp; verify biometrics &lt;/li&gt;&lt;li&gt;Complexity of provisioning &amp;amp; sharing biometrics across platforms and regions&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;So how can we be successful now? &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Provisioning credentials &amp;amp; enabling cross platform SSO &lt;/li&gt;&lt;li&gt;Managing roles and fine grain entitlements&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;What is the real scoop on Fraud: &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;eCommerce Fraud Losses Projected to Grow to $3.6 Billion in 2008 &lt;/li&gt;&lt;li&gt;Merchants estimate that 1.4% of their online sales will line the pockets of fraudsters&lt;br /&gt;&lt;em&gt;Source: CyberSource eCommerce Fraud Survey, 2007 &lt;/em&gt;&lt;/li&gt;&lt;li&gt;Société Générale €5 billion in trading loss due to unauthorized trades &lt;/li&gt;&lt;li&gt;Trader executed €50 billion of unauthorized trades and attempted to cover over his losses. When the bank discovered the fraud it had to unwind the position in 3 days, resulting in €5 billion in loss and triggering a world wide financial market sell-off.&lt;br /&gt;&lt;em&gt;Source: CNN, January 2008 &lt;/em&gt;&lt;/li&gt;&lt;li&gt;$17 Million remediation cost for 45 million stolen credit card numbers&lt;br /&gt;Breach of TJ Maxx’s IT systems led to the lost of 45 million credit and debit card numbers over a period of 18 months. Estimated revenue impact from negative press coverage was $4.5 billion.&lt;br /&gt;&lt;em&gt;Source: Information Week, May 2007 &lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;So why is Strong Authentication not enough?&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Tokens &amp;amp; Smart Cards require the device to be present, credentials still can be stolen and subject to man in the middle attacks and other Phishing or Virus/Malware breaches &lt;/li&gt;&lt;li&gt;Conversly, Biometric Credentials can not be stolen or replicated, user does not have to carry/track additional tools.&lt;/li&gt;&lt;li&gt;They can be verified for uniqueness against state, local, federal &amp;amp; international databases&lt;br /&gt;Rapidly identify potential threats or risky persons.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;This is where it gets tricky&lt;/strong&gt; &lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Capturing &amp;amp; Storing Credentials &lt;/li&gt;&lt;li&gt;High cost of having devices at the end-points to capture data &lt;/li&gt;&lt;li&gt;Tremendous disparity in capture/read devices &amp;amp; algorithms &lt;/li&gt;&lt;li&gt;It is difficult to future proof your deployment when devices, algorithms, and infrastructure continuously evolving &lt;/li&gt;&lt;li&gt;Risk of being out of date by the time of production deployment &lt;/li&gt;&lt;li&gt;Challenging to provisioning credentials and synchronize biometrics with apps &amp;amp; infrastructure &lt;/li&gt;&lt;li&gt;Challenge for using single biometric authentication for SSO&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;So how do you maximize the ROI?&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Govt. &amp;amp; Ent. require solutions that compliment &amp;amp; enhance entire IT IDM infrastructure to justify investment. &lt;/li&gt;&lt;li&gt;Oracle IDM Solutions Provisioning Credentials &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Oracle Identity Manager &lt;/strong&gt;(OIM) enables automated provisioning or revocation of accounts based on biometric auth/enrolment &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Oracle Role Manager&lt;/strong&gt; (ORM) ties biometric attributes to user roles &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Oracle Entitlements Server &lt;/strong&gt;(OES) richly defines fine-grain applications entitlements to grant/limit access to specific functions, data sets, or transactions based on level of authentication, roles, and credentials. &lt;/li&gt;&lt;li&gt;Gain seamless authentication across applications with &lt;strong&gt;Oracle eSSO&lt;/strong&gt; (OESSO) &lt;/li&gt;&lt;li&gt;Replaces name/pwd with a a single biometric authentication to increase security level &amp;amp; create single sign-on across web &amp;amp; desktop applications. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Oracle Adaptive Access Manager &lt;/strong&gt;(OAAM) Ties biometric authentication with broader authentication context (like device identification and location) to validate the entire transaction and identify anomalies or malicious behavior over time.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span style="font-size:130%;"&gt;&lt;em&gt;Here is how the Daon solution fits in...&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt;&lt;/em&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;&lt;a href="http://2.bp.blogspot.com/_gn9hq2pkgmk/SvLx_v3rUiI/AAAAAAAAAF0/xm1nf5iCCi0/s1600-h/Daon.bmp"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 285px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5400644980654690850" border="0" alt="" src="http://2.bp.blogspot.com/_gn9hq2pkgmk/SvLx_v3rUiI/AAAAAAAAAF0/xm1nf5iCCi0/s400/Daon.bmp" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;For more information on &lt;a href="http://www.blogger.com/www.daon.com"&gt;Daon&lt;/a&gt; please visit their website.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-3524366887302767903?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/3524366887302767903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/08/why-public-sector-needs-bio-metric.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3524366887302767903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3524366887302767903'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/08/why-public-sector-needs-bio-metric.html' title='Why the Public Sector needs Bio-Metric Solutions and how ORCL + Daon can help'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gn9hq2pkgmk/SvLx_v3rUiI/AAAAAAAAAF0/xm1nf5iCCi0/s72-c/Daon.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-5573443874809372381</id><published>2009-07-01T11:59:00.000-07:00</published><updated>2009-10-27T14:07:21.321-07:00</updated><title type='text'>Security solutions for misuse of information &amp; entitlements</title><content type='html'>&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;After "Who has access to what?” the question is “What are they doing with it?”&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Information security has followed a similar path of information technology. First it was about storing and organizing information in databases and securing that information. Then as applications and middleware evolved to deliver that information and application entitlements to users, Identity and Access management suites developed to securily enable access to them.&lt;br /&gt;&lt;br /&gt;But once information and entitlements are in the hands of users it is open for misuse. There are many examples of this:&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Accidentally emailing confidential information about M&amp;amp;A to the wrong internal user with the same name like &lt;a href="mailto:John.Waters@xyzcorp.com"&gt;John.Waters@xyzcorp.com&lt;/a&gt; instead of &lt;a href="mailto:Jon.Waters@xyzcorp.com"&gt;Jon.Waters@xyzcorp.com&lt;/a&gt;.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Copying sensitive financial or personal information out of a protected application into a file and posting it on an open file share or SharePoint portal&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Sales person leaving the company who emails a list of accounts and contacts to themselves before going to work for a competitor.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;NT Admin who misues the shared account because they know they are 1 of 30 people with the password and nobody knows who did what with it.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Former employees hacking into a company database because the password never changes as it is hard coded into applications. &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 512px; DISPLAY: block; HEIGHT: 306px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5397387068700775602" border="0" alt="" src="http://1.bp.blogspot.com/_gn9hq2pkgmk/Sude8UEyVLI/AAAAAAAAAFE/qWMu0ANxGkM/s400/DLP-PAM-problem.bmp" /&gt; &lt;p&gt;&lt;br /&gt;The list of potential risks/attacks goes on and on. To help customers identify these and address them, Oracle has once again expanded the &lt;strong&gt;&lt;em&gt;Extended Identity Management Ecosystem &lt;/em&gt;&lt;/strong&gt;to include: &lt;/p&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Privileged Account Management (PAM)&lt;/strong&gt; – manage shared and cached credentials for privileged accounts &lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Data Loss Prevention (DLP)&lt;/strong&gt; – network and endpoint content-aware monitoring, discovery and blocking&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Which is complimented by Oracle IAM solutions that provide consistent Security Services &amp;amp; Policy across layers for &lt;/p&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Compliance – Fine-grained entitlements and identity analytics based on consistent user roles &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Reconciliation – Closed loop implementation &amp;amp; verification of policies across layers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 602px; DISPLAY: block; HEIGHT: 399px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5397387531220735026" border="0" alt="" src="http://2.bp.blogspot.com/_gn9hq2pkgmk/SudfXPGI1DI/AAAAAAAAAFM/pmy8g_QHaV0/s400/DLP-PAM-solution.bmp" /&gt; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Our DLP partners (including &lt;a href="http://www.mcafee.com/us/enterprise/products/data_protection/data_loss_prevention/host_data_loss_prevention.html"&gt;McAfee&lt;/a&gt;, &lt;a href="http://www.symantec.com/en/uk/business/theme.jsp?themeid=dlp"&gt;Symantec, &lt;/a&gt;&amp;amp; &lt;a href="http://www.controlguard.com/"&gt;ControlGuard &lt;/a&gt;) integrate with Oracle IRM to: &lt;/p&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Discover, classify, quarantine and seal (IRM-encrypt) &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Intercept file copies to removable media, classify, quarantine, seal (IRM-encrypt) &amp;amp; release&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;DLP integration with Oracle IAM will enable : &lt;/p&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;DLP policies via OID or OVD group membership &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Provision/de-provision DLP policies via OIM (groups) &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Feedback/tuning of IAM&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Similiarly Oracle PAM partners including &lt;a href="http://www.cloakware.com/cloakware-ds/products/password-authority.php"&gt;Cloakware&lt;/a&gt;, &lt;a href="http://www.blogger.com/www.cyber-ark.com/"&gt;Cyber-Ark&lt;/a&gt;, &lt;a href="http://www.liebsoft.com/"&gt;Liebsoft&lt;/a&gt;, and &lt;a href="http://www.opentrust.com/"&gt;OpenTrust (formerly Symark) &lt;/a&gt;, deliver integrations that allows customers to: &lt;/p&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Leverage OID/OVD as identity/credential store &lt;/li&gt;&lt;br /&gt;&lt;li&gt;PAM policies via OID/OVD groups &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Provision/de-provision policies via OIM (groups) &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Leverage Oracle database as secure policy store &lt;/li&gt;&lt;br /&gt;&lt;li&gt;Secure caching of credentials for unattended application restarts &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;To learn more about these partners please visit their page on OPN or click on their name above to reach their website directly.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="color:#ff0000;"&gt;{NOTE: Please click on the above images to see the slides in full size for reading the details}&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-5573443874809372381?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/5573443874809372381/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/07/security-solutions-for-misuse-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5573443874809372381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/5573443874809372381'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/07/security-solutions-for-misuse-of.html' title='Security solutions for misuse of information &amp; entitlements'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gn9hq2pkgmk/Sude8UEyVLI/AAAAAAAAAFE/qWMu0ANxGkM/s72-c/DLP-PAM-problem.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-6185842065125475333</id><published>2009-06-30T10:25:00.000-07:00</published><updated>2009-10-28T11:07:30.074-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloakware Priveleged User PAM PUM'/><title type='text'>Cloakware and Oracle Work to Integrate Cloakware Password Authority with Oracle Identity and Access Management</title><content type='html'>&lt;strong&gt;Integration Strengthens Access Rights Security with Privileged Password Management&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Cloakware, the leading provider of privileged password management solutions announced today that it is working with Oracle to extend their suite of Identity Management solutions with Cloakware's flagship product, Password Authority. By combining these two best-in-class products, Oracle is now able to enhance their customers' security management, with a comprehensive solution to manage, protect and monitor access to vital data.&lt;br /&gt;&lt;br /&gt;As more and more high-profile data breaches come to light, companies are realizing they need increasingly robust solutions to protect their vital data. A study conducted in January 2009 by the Identity Theft Resource Center of San Diego found that the percentage of breaches attributed to current or former employees more than doubled from 2007 to 2008. In light of findings like this, companies are struggling to balance individuals' access rights to secure information against risk and compliance requirements. Cloakware's patented white-box cryptographic techniques ensure defense-in-depth for end-to-end security of data and keys, especially where insiders have access to the execution environment. Working with Cloakware enables Oracle to offer its customers a solution to securely store and manage privileged passwords for human administrators and runtime applications without changes to the customer's existing infrastructure.&lt;br /&gt;&lt;br /&gt;"Extending the Oracle Identity and Access Management Suite with third party platforms provides enhanced efficiency, a higher level of integration and increased effectiveness in terms of application-centric security and risk management," said Ron Huddleston, vice president, North America Technology Channel Sales, at Oracle. "Cloakware's Password Authority is a key part of this eco-system, augmenting our identity management suite."&lt;br /&gt;&lt;br /&gt;Password Authority leverages multiple integration points into the Oracle Identity and Access Management Suite, including:&lt;br /&gt;&lt;br /&gt;- Oracle Internet Directory (OID) - Password Authority can manage the passwords for accounts held in OID as well as for service accounts that authenticate against OID.&lt;br /&gt;&lt;br /&gt;- Oracle Identity Manager (OIM) - Password Authority ensures that password management is synchronized with roles and access rules.&lt;br /&gt;&lt;br /&gt;- Oracle WebLogic Server - Password Authority automates the run-time replacement of current passwords in connection strings/connection pools and the management of WebLogic administrator accounts.&lt;br /&gt;&lt;br /&gt;- Oracle Database 11g Real Application Cluster (RAC) - Password Authority makes use of the Oracle database as its secure repository for all passwords, and is capable of supporting a geographically distributed database installation. Password Authority is also capable of maintaining and releasing Oracle Database passwords to humans and applications.&lt;br /&gt;&lt;br /&gt;"Companies are now starting to understand the importance of employing strict standards to manage access to critical information and protect digital assets; the risks are too high to ignore," said David Canellos, senior vice president, sales and marketing at Irdeto and Cloakware. "By integrating Cloakware Password Authority with Oracle's Identity and Access Management Suite, customers will have a single solution to proactively address security deficiencies and reduce cost and risk in their IT infrastructure."&lt;br /&gt;&lt;br /&gt;The combined solution will be demonstrated in Oracle's Hospitality Suite during the Burton Catalyst Conference in San Diego, July 27-31, 2009. The demonstration will highlight how Cloakware's latest product version, Password Authority 4.1, secures password storage, access and lifecycle management for shared privileged administrator and programmatic passwords within the Oracle Identity and Access Management Suite. For more information, please visit http://datacenter.cloakware.com.&lt;br /&gt;&lt;br /&gt;Cloakware is a member of the Oracle PartnerNetwork.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;About the Oracle PartnerNetwork&lt;br /&gt;Oracle PartnerNetwork is a global business network of more than 20,000 companies who deliver innovative software solutions based on Oracle software. Through access to Oracle's premier products, education, technical services, marketing and sales support, the Oracle PartnerNetwork program provides partners with the resources they need to be successful in today's global economy. Oracle partners are able to offer their customers leading-edge solutions backed by Oracle's position as the world's largest enterprise software company. Partners who are able to demonstrate superior product knowledge, technical expertise and a commitment to doing business with Oracle qualify for the Certified Partner levels. http://oraclepartnernetwork.oracle.com&lt;br /&gt;&lt;br /&gt;About Cloakware&lt;br /&gt;&lt;br /&gt;Cloakware, an Irdeto company and part of the Naspers group, provides innovative, secure, proven software technology solutions that enable customers to protect business and digital assets in enterprise, consumer and government markets. Cloakware's two main product lines include: Cloakware Datacenter Solutions which help organizations meet governance, risk management and compliance (GRC) objectives for privileged password management while ensuring business continuity and the security of mission-critical data and IT infrastructure. Cloakware Consumer Product Solutions protect software and content on PCs, set-top boxes, mobile phones and media players. Protecting more than one billion deployed applications, Cloakware is the security cornerstone of many of the world's largest, most recognizable and technologically advanced companies. Headquartered in Vienna, VA and Ottawa, Canada, Cloakware has regional sales offices worldwide. &lt;a href="http://www.cloakware.com/"&gt;http://www.cloakware.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Trademarks&lt;br /&gt;Oracle is a registered trademark of Oracle Corporation and/or its affiliates.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Datasheet:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.oracle.com/products/middleware/identity-management/docs/cloakware-datasheet.pdf"&gt;http://www.oracle.com/products/middleware/identity-management/docs/cloakware-datasheet.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="474" height="388" class="BLOG_video_class" id="BLOG_video-15396d75b33118e5" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v3.nonxt7.googlevideo.com/videoplayback?id%3D15396d75b33118e5%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329917791%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D814384FEB9E9EC2C89DFA0206EA1283AA9A3CE54.70092BEB05E86B4239E283343C210892E21F24F5%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D15396d75b33118e5%26offsetms%3D5000%26itag%3Dw160%26sigh%3DjiiASwAKneoDfhtIj4Seu7XMXmo&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="474" height="388" bgcolor="#FFFFFF"flashvars="flvurl=http://v3.nonxt7.googlevideo.com/videoplayback?id%3D15396d75b33118e5%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329917791%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D814384FEB9E9EC2C89DFA0206EA1283AA9A3CE54.70092BEB05E86B4239E283343C210892E21F24F5%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D15396d75b33118e5%26offsetms%3D5000%26itag%3Dw160%26sigh%3DjiiASwAKneoDfhtIj4Seu7XMXmo&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-6185842065125475333?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infinite-identities.blogspot.com/feeds/6185842065125475333/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://infinite-identities.blogspot.com/2009/06/cloakware-and-oracle-work-to-integrate.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6185842065125475333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/6185842065125475333'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2009/06/cloakware-and-oracle-work-to-integrate.html' title='Cloakware and Oracle Work to Integrate Cloakware Password Authority with Oracle Identity and Access Management'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5297101820232184490.post-3230746408582637267</id><published>2008-09-22T07:17:00.000-07:00</published><updated>2009-10-20T07:34:31.997-07:00</updated><title type='text'>Oracle Forms Oracle Identity Assurance Partner Alliance</title><content type='html'>&lt;span style="color:#ff0000;"&gt;&lt;strong&gt;Initiative to Provide Comprehensive, Proactive Identity Fraud Prevention Solutions&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#666666;"&gt;Oracle OpenWorld, San Francisco – September 22, 2008&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;News Facts&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Further extending its leading Identity and Access Management solution offering that helps organizations combat online fraud and improve overall enterprise security, Oracle today launched the Oracle Identity Assurance Partner Alliance. &lt;/li&gt;&lt;li&gt;Through the alliance, Oracle and members of the alliance plan to deliver solutions that pre-integrate Oracle’s Identity Management Suite with partner technologies to offer capabilities such as identity proofing, Internet geolocation, multi-factor authentication, out-of-band authentication, endpoint security and secure remote access. &lt;/li&gt;&lt;li&gt;Oracle plans to test and deliver unified solutions which are designed to help enable organizations utilize their existing infrastructure investments with new authentication technologies to create a broad-reaching view of transactions, users and their environment. Additionally, the integrations are intended to enable customers to more easily detect areas of risk and respond through secondary authentication measures. &lt;/li&gt;&lt;li&gt;These authentication and security solutions work in a heterogeneous environment including Oracle and non-Oracle information systems and Enterprise Applications. They will also be pre-integrated with Oracle’s data, Fusion Middleware and Business Applications. &lt;/li&gt;&lt;li&gt;Members of the alliance include: ActivIdentity, Bio-Key, IDology, Juniper Networks, Quantum Secure, Quova, StrikeForce Technologies and VASCO, all members of Oracle PartnerNetwork, Oracle’s global partner program. &lt;/li&gt;&lt;li&gt;Pre-built integrations from Juniper and Quova are available today.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Context-Aware Security&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Unlike traditional security solutions that only examine user roles and privileges to grant access, Oracle Adaptive Access Manager provides context-aware security that guarantees fraud protection using a variety of identifying information, including the identity of a user’s machine, IP address, geographic location and historical transaction information. &lt;/li&gt;&lt;li&gt;By unifying identity assurance and enhancing the context of a transaction to drive risk-based decisions from the desktop to the perimeter of the enterprise and into the business application infrastructure, Oracle and its partners plan to deliver improved security and superior convenience to end users. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Supporting Quotes &lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;“With the increasing sophistication of security threats, rising online fraud and growing regulations governing online data privacy, organizations need robust end-to-end security solutions,” said Amit Jasuja, vice president, Oracle Identity Management. “However, critical systems that enable fraud protection by linking multiple aspects of a user's identity are often siloed or part of a security infrastructure that is operated in stand-alone fashion. By unifying complementary technologies, the Oracle Identity Assurance Partner Alliance aims to improve overall enterprise security by offering better protection from identity theft and stronger controls to safeguard intellectual property.” &lt;/li&gt;&lt;li&gt;“ActivIdentity is delighted to join the Oracle Identity Assurance Partner Alliance,” said Jerome Becquart, vice president of Products and Services at ActivIdentity. “As an established leader in the identity assurance space, we welcome Oracle’s initiative to further enhance interoperability in the identity ecosystem.” &lt;/li&gt;&lt;li&gt;“Oracle's strategy of bringing industry leading solutions together to provide real-time ID theft prevention solutions delivers a higher value for Enterprise customers," said John Dancu, CEO and president of IDology, Inc. "We are excited to be a part of this network."&lt;br /&gt;“Juniper is delighted to be a member of the Oracle Identity Assurance Partner Alliance,” said Sanjay Beri, vice president, Access Solutions, Juniper Networks. “The reality of today's extended enterprise is a workforce that is not only increasingly mobile, but one that includes non-employees such as partners, suppliers and contractors. Ensuring high productivity requires providing granular access to key mission-critical applications anytime, anywhere, and from any device for these diverse constituencies. Securing this access and preventing fraud and ID theft is a huge challenge that Juniper and Oracle are addressing to deliver greater value to customers.” &lt;/li&gt;&lt;li&gt;“We are proud to be a member of the Oracle Identity Assurance Partner Alliance and are excited to be part of this distinguished group of companies that are dedicated to enterprise security,” said Bill Varga, executive vice president of Business Development at Quova.&lt;br /&gt;“StrikeForce Technologies is excited to participate in Oracle’s Identity Assurance Partner Alliance. Our participation is expected to help Oracle and StrikeForce customers further prevent identity theft – an ever increasing problem for all,” said Mark L. Kay, CEO, StrikeForce Technologies Inc. “Our participation in the alliance should better enable us to provide organizations with a fully integrated authentication solution that meets several mandates.” &lt;/li&gt;&lt;li&gt;“VASCO Data Security is excited to join the Oracle Identity Assurance Partner Alliance and bring its experience and expertise in strong authentication to this group,” said Adam Dolby, director, Strategic Alliances, VASCO. “VASCO's continuous efforts in raising awareness and public education about secure authentication practices such as one-time passwords and electronic signatures fit very well into the Oracle Alliance. We are proud to be part of this group in its endeavor to create a comprehensive real time solution for proactive fraud prevention."&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Supporting Resources &lt;/strong&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.oracle.com/products/middleware/identity-management/resource-library.html"&gt;Identity Management Resource Library&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.oracle.com/technology/products/id_mgmt/pdf/serv_oriented_sec.pdf"&gt;Service-Oriented Security: An Application-Centric Look at Identity Management&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.oracle.com/products/middleware/identity-management/adaptive-access-manager.html"&gt;Oracle Adaptive Access Manager&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.oracle.com/products/middleware/identity-management/access-management-suite.html"&gt;Oracle Access Management Suite&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://feeds.feedburner.com/~r/OracleOfmRadio/~3/247675366/6344645_Strong_Auth.mp3"&gt;Webcast: &lt;/a&gt;&lt;a href="http://streaming.oracle.com/ebn/hosted/techtarget/071213/index.html"&gt;The Brave New World of Consumer Authentication with Burton Group&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.oracle.com/corporate/analyst/reports/index.html"&gt;Independent Analyst Reports Regarding Oracle Software&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.oracle.com/technology/software/index.html"&gt;Download Oracle Software&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;About Oracle &lt;/strong&gt;&lt;br /&gt;Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. For more information about Oracle, please visit our Web site at &lt;a href="http://www.oracle.com/"&gt;http://www.oracle.com/&lt;/a&gt;.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Trademarks &lt;/strong&gt;&lt;br /&gt;Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners.&lt;br /&gt;This document is for informational purposes only and may not be incorporated into a contract or agreement.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5297101820232184490-3230746408582637267?l=infinite-identities.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3230746408582637267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5297101820232184490/posts/default/3230746408582637267'/><link rel='alternate' type='text/html' href='http://infinite-identities.blogspot.com/2008/09/oracle-forms-oracle-identity-assurance.html' title='Oracle Forms Oracle Identity Assurance Partner Alliance'/><author><name>Brian Mozinski</name><uri>http://www.blogger.com/profile/14760645887366815339</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
