Wednesday, November 4, 2009

Persistent helps organizations say Bye-Bye to CA SiteMinder

Persistent Systems delivers a packaged solution for migrating from CA SiteMinder to Oracle Access Manager (OAM)


So why do we need a solution for this?

· Accelerated – Save time (i.e. $ on implementation)

· Lower Risk – Repeatable solution reduces project risk

· Proven – Well laid path by existing reference customers

· Turnkey – OOTB solution



Why do organizations want to migrate?

· CA SiteMinder has a very large & dissatisfied install base because of

o Poor investment in Dev and Support – There are substantially less engineers building/supporting SiteMinder then when it was part of Netegrity, while Oracle has increased the dev team on OAM

o Costly Support – CA support pricing model creates painfully high pricing (disproportionate with the rest of the market) in the mind of many organizations.

· Stack Limitations:

o As a stack, the Oracle IdM suite has dramatically out paced CA in completing the picture and innovating towards the future.



So who should consider this?

· SiteMinder users with Oracle products (DB, EBS, Apps, IdM…….) – i.e. those that will benefit from the Oracle IAM Suite and the broader Oracle Suite

· Customers who use both SiteMinder and OAM for different applications or business units – i.e. those hungry for actual SSO

· Customers who have SiteMinder environments through acquisitions – i.e. cost savings

· Anyone with a SiteMinder deployment


So why now? Why was this not done already?

· Legacy – SSO environments constitute several years of work/investment

· Perception – Migrations are seen as long, effort-intensive, expensive and risky

· Time – Typically ROI is too far away, but not in this case


Persistent Systems' SM2OAM solution addresses all these challenges!


Case in Point – At a large public technology provider (not ORCL), the migration time from SM to OAM was brought down from 24 months to 6 months!



OK, so how do we do this?

· Option 1 - Fully outsourced

o Turnkey Persistent solution includes ‘acceleration plus services’

o All phases delivered by Persistent

o Direct, subcontract and fixed fee options available

· Option 2 - Joint solution

o Persistent provides ‘acceleration’ for existing services team

o Phases in blue delivered by partner, rest delivered jointly by Persistent

o Fixed fee, markup and shared revenue options available


So who is Persistent Systems?

· Over a decade working on the backend doing OAM engineering

· Over 140 person years of engineering experience with Oracle IAM stack

· Ongoing implementation efforts – 20+ marquee customers

· Winner of Oracle's partner ‘Challenge’ – OID 2 billion benchmark, ‘last-mile’ solutions

· 20 years old, profitable, 5K people, hundreds of customers, Thousands of product releases

· Global presence – North America, Europe, UK and Asia


To get started contact:

Muneer Taskar

muneer_taskar@persistentsys.com

Tuesday, November 3, 2009

StrikeForce Technologies ProtectID® provides step-up two factor “Out-of-Band” authentication to OAAM

Using OAAM and ProtectID® together, companies can defend against the latest online threats, including account takeover schemes and man-in-the-middle attacks to restore trust in Internet transactions. The combined offering utilizes advanced authentication and fraud prevention to evaluate risk and alert organizations in real-time to potential fraud threats. In addition, the OAAM/ProtectID® solution enables companies to employ a range of security options, including “Out-of-Band” phone authentication, to meet diverse user requirements or upgrade to higher levels of protection as threats increase without reinvesting in infrastructure. Enterprise Security Officers prefer two-factor authentication all the time. Consumers are happy with simple ID/Password authentication, thereby finding a workable solution has been a challenge for companies.

The Oracle Adaptive Access Manager (OAAM) combined with StrikeForce’s ProtectID®, meets this challenge. Heightened regulatory requirements (e.g. FFIEC and The Red Flags) recommend adopting strong two-factor authentication for the higher risk transactions. Gartner recommends “Out-of-Band” authentication as a necessary layer to prevent Identity Theft. The regulations explicitly discuss the use of One Time Passwords (OTP) delivered via phones or similar devices in addition to utilizing “Out-of-Band” strong authentication. The ProtectID® strong authentication platform provides these services (which is the reason the partnership with StrikeForce was developed). Many of these enterprises also want two-factor authentication for their employees (which OAAM and ProtectID® also solves in combination and separately).

The ProtectID® platform is an implementation or “Cloud Service” of the OOB Authentication methodology providing strong authentication via a number of different authentication technologies. Currently the platform supports the following strong authentication methodologies:

“Out-of-Band” methodologies:

  • Entering a fixed PIN in a phone
  • Entering One Time Password (OTP) in a phone
  • Sending an OTP to a phone via SMS
  • Sending an OTP to a phone via text to speech
  • Sending an OTP via email

Token methodologies:

  • Hard Token OTP (key fob that displays OTP when a button is pressed)
  • Soft Token OTP (OATH compliant software) that can reside on a PC or a Black Berry or PDA or J2ME compliant cell phone.

Value of ProtectID® to OAAM

A ProtectID® and OAAM combined solution delivers an advanced security proposition to combat the growing threat of consumer identity theft and fraud on the Internet. The combination of OAAM’s real-time fraud prevention and ProtectID’s real-time two-factor “Out-of-Band” authentication platform, provides financial institutions, online retailers, health care companies and other businesses with a robust arsenal of security tools for protecting consumers from fraud, for accurate identification of employee access, and all while complying with industry security guidance’s and regulations.

Therefore, with the combination of OAAM and ProtectID®, the client benefits from a Return On Investment (ROI) and compliancy with regulatory requirements (FFIEC, Red Flags and others), with minimal inconvenience to the most important person, the end user. The majority of transactions authenticated should pass the OAAM fraud prevention process. For those transactions that are detected and flagged as potentially fraudulent, OAAM would then automatically invoke ProtectID® to perform a two-factor strong authentication for the consumer, which minimizes the expensive help desk process and thereby provides greater satisfaction and cost savings. This total fraud prevention solution is a win/win for the company and its clients. ProtectID® could also be used for password resets, high dollar value online transactions, remote log on, etc.


Interfacing ProtectID® with OAAM

ProtectID® appears as a web service to a web site that implements both OAAM and ProtectID® and allows for step-up or other requests for strong 2-factor “Out-of-Band” authentication based on the risk level determined by the Company and or OAAM.

OAAM only employs step-up authentication when it’s truly needed so end users are not being inconvenienced.

Following is a link to allow you to test “Big Bank” showing an example of how ProtectID® can be integrated with OAAM for the best all around total solution (fraud mitigation with 2-factor “Out-of-Band authentication) with options and flexibility. Just sign on with a user name and it will ask you to register and allow you to test the Best complete compliant authentication solution available and all from Oracle:

http://d.oobauth.com:8888/sample/

For more information please contact:

Mark L. Kay, CEO
StrikeForce Technologies, Inc.
marklkay@strikeforcetech.com
www.strikeforcetech.com
(o) 732-661-9641

Monday, November 2, 2009

No More Tokens!!!

Juniper says "Good Bye Tokens" with Oracle Adaptive Access Manager (OAAM)

As the #1 SSL VPN provider with 92% of Fortune 100 and 8 of top 10 commercial banks plus 47 of 50 US State Governments, odds are you have used a Juniper SSL VPN to connect to your employer, partner, or service provider … and odds are you had to use a hardware security token.

While tokens like RSA BSAFE provide an accepted alternative to passwords, they are clunky, costly, and not secure from many potential attacks like man-in-the-middle or man-in-the-browser.

Looking to help customers overcome these challenges, Juniper partnered with Oracle to integrate the Oracle Adaptive Access Manager (OAAM) which not only provides a software alternative to tokens, greatly improving the user experience and dramatically lowering TCO, it also saves hard dollars and protects the organization’s reputation with real-time fraud detection.

More specifically OAAM provides:

  • Strong, multi-factor authentication for secure access control
  • Seamless interoperability with hetergenous App Servers (IBM, BEA, SAP, etc.)
  • Enforces access at the protected resources thru web plug-ins
  • Delegates authentication and authorization decisions to a central authority

Which compliments the existing features and security of Juniper SA SSL VPN such as:

  • Provides secure, encrypted communication channel for all remote users from anywhere and from any device
  • Enforces Oracle’s policy based authentication and authorization policies at perimeter
  • Provide 3 different levels of connectivity, going beyond just web support, including Layer 3 VPN connectivity for fat clients, VoIP, streaming, FTP, and more
  • Performs comprehensive “Host-Checking” to ensure end-point integrity
  • Enables coordinated identity based threat response and prevention with other products

The benefits include:

  • Lower cost and complexity of authenticating users
  • Eliminates non-user friendly, expensive gadgets, tokens or proprietary software downloads
  • Host checker + real-time fraud prevention provides greatest overall access security
  • Low-cost, flexible way for enteprises to extend strong authentication to partners, suppliers, contractors, and non-employees accessing critical applications
  • Native integration eliminates need for OAAM’s UIO option

How does this really save me money? - Good question! Here is how it works:

Lower Hardware Costs

  • Mitigates need to provide SSL on each Web / App Server; fewer servers
  • Single appliance scales to thousands of simultaneous users
  • Carrier-class reliability and HA features

Lower Management Costs

  • Seamlessly leverage and instantly extend I&AM policies to remote users
  • Eliminate need to duplicate policies across servers and networks
  • Plug ‘n play integration – deployment guides and Oracle reference architectures
  • Leverage combined audit and log data for compliance

Lower Business Risk

  • Moves OAM policy enforcement point out to network perimeter, increasing security
  • Coordinated identity-based threat response to attacks
  • Comprehensive identity based access logs

To download the data sheet:
http://www.juniper.net/us/en/local/pdf/solutionbriefs/3510251-en.pdf

For more information on the Juniper Oracle Partnership:
http://www.juniper.net/solutions/information_technology_topics/accelerating_oracle_business/index.html


To learn more about OAAM:
http://www.oracle.com/technology/products/id_mgmt/oaam/index.html


Don’t believe me, ask Juniper:
David Colodny
dcolodny@juniper.net

Wednesday, October 28, 2009

Oracle OPN Days - Virtual Event

Much more the "virtually helpful"...











What are Virtual Days?
Somewhat of a hybrid between web conferencing and social networking these events offer a unique opportunity to gather subject matter experts from around the world with industry thought leaders have dynamic discussions about technology, architecture, but most importantly ... How do you make your organization more successful?


Challenges with a traditional conference:
We have all been to many large conference halls from the San Francisco Moscone Center to the Venetian Hotel & Conference Center in Vegas or the Orlando Florida Conference Center. While the face time to build relationships is important there are many draw backs, for example consider these scenarios we have all experienced:
  • You make it to the booth of someone you need to connect with but the expert on your topic won't be here until tomorrow.
  • A key customer approaches but Jim Thompson who runs product management just went to the bathroom
  • Despite being at the event, Tom Jones the architect whose advice is highly valued by the CIO and decision maker is too shy to approach face to face so you never knew they were there or could find Tom.
  • You are talking to a potentially large customer but they are interested in a new product or partnership and the collateral did not make it to the show.
  • You agree to share content on a pressing issue but the action items get scribbled on a conference flyer and get lost.
  • You finally connect with the right people and you can't find a place to sit and talk or hear one another over the crowd
  • You get cards from everyone you meet but it would take another week to index then and store the information virtually and it becomes difficult to follow up.
  • You get to the booth in the morning but your technical sales manager was out with a client the night before and did not make it to the booth in time to meet another key client

Instead with a Virtual Event you can:

  • Dynamically grab the content you need and provide it electronically
  • Pull in experts from anywhere in any language instantly
  • Digitally share contact information and action items
  • Avoid the high cost of traveling to conferences
  • Save your feet and time running between sessions

Why the Oracle OPN Days?

  • Support for 9 languages
  • Product, alliance, and sales experts in 1 place
  • Information across Oracle database, middleware, and applications
  • This event is focused on partners and how they can be successful with Oracle and benefit from our many sales and marketing programs.
  • Rapidly navigate the ~85,000 Oracle organization

To learn more visit the site:

http://events.unisfair.com/index.jsp?eid=491&seid=26&code=OPNDaysVEOracleMailSignature

Tuesday, October 27, 2009

Updated Oracle IDM Ecosystem

The Oracle IDM Ecosystem is strong and growing!

Oracle announced the Extended IDM Ecosystem in June 2007 to unify security islands, as Organizations commonly have multiple security systems in place—one technology to secure physical access, another to secure legacy applications, and yet another to secure network access. To cope with these "silo'd" solutions, Oracle partnered with best-of-breed ISVs to offer a central and effective means to enforce security policy across all enterprise resources.

Today the mission continues to be the same while the technology landscape and customer requirements have evolved. Since I took it over the leadership of the Ecosystem in June of 2008 we have added several new categories including:

  • SOA Security & Governance – Enforcing and managing message level security, throttling, and acceleration for the Oracle SOA Suite

  • Identity Assurance - Certified solutions for fraud prevention combining Oracle Adaptive Access Manager (OAAM) with solutions spanning Identity Proofing, Internet Geolocation, Out-of-Band Authentication, Secure Remote Access, and more.

  • Data Loss Prevention – Partnering with the leaders in end point security and data protection to identify the flow of sensitive information and protect it through IRM, and IDM policy reconciliation.

  • Priveleged User Management – Extending the management of application accounts, users, and credentials to provision, secure, and monitor privileged/shared accounts by users or applications.

The core benefits, that extend to these new categories as well, include:

  • Reduces deployment risk—Certified and proven interoperability significantly reduces time to deployment, costs, and risks of deployment
  • Strengthens security and compliance—Central management of disparate resources and identities improves enterprise security and enhances regulatory compliance
  • Improves operational efficiencies—Linking identity across systems and providing a central authentication interface greatly improves operational efficiencies and user productivity

  • The current list of partners includes:

    As always you can learn about the Ecosystem on Oracle.com
    http://www.oracle.com/products/middleware/identity-management/ecosystem.html

    To learn more about becoming an Oracle Partner please visit the Oracle Partner Network:
    http://www.oracle.com/partners/index.html

    Symantec announces DLP powered by Oracle IRM

    Oracle IRM and Symantec DLP integration announced

    Symantec

    Launching their latest release of data loss prevention (DLP), Symantec focused on the new functionality in version 10 allowing customers to directly leverage the benefits or Oracle IRM to protect their sensitive data.

    Symantec is the leader in DLP technology and organizations world wide leverage their solution for discovery and monitoring of enterprise network traffic and perimeters to detect the flow of information that needs to be protected for privacy, compliance, or from competitors. When DLP detects something that is deemed confidential it can take some action upon it, typically this is in the form of blocking the information from continuing to be transmitted or removing it from the file servers.

    However combining DLP with IRM means you don't have to restrict the end user or impede the business by blocking their attempts to collaborate. Instead you directly enable the organization to interact securely and teach best practices. Oracle IRM technology will encrypt and protect the document or email so that it can be shared. IRM ensures only authorized users have access and provides advanced security controls such as revocation to the information, even after it has left the control of your enterprise networks.

    Oracle and Symantec have been working closely together over the past months to build an integration between Oracle IRM and DLP based on direct input from customers and implementation partners. The combined solution offers the most innovative, use-case driven security solution of any IRM and DLP combination.

    Oracle IRM is the leading rights management solution for enterprise-scale document and email security and Oracle is the leader in Enterprise Identity & Access Management according to Gartner, Burton and Forrester. Combining this innovative technology and thought leaders for Access Management and Content Security means customers can now have rich monitoring and detection capabilities.

    Instead of blocking attempts to share valuable data, this solution allows it to happen securely. We first demonstrated this capability at Oracle Open World and if you were not able to attend, we've uploaded some video demonstrations to our YouTube channel.



    If you want to learn more about using Oracle IRM and DLP together contact us.














    Oracle IRM resources

    Wednesday, October 21, 2009

    Identity Management Partners making news at Oracle Open World

    While Oracle Open World is traditionally dominated by Database and Applications, this year Identity Management made waves and made press.

    Network World's Dave Kearns similarly noted the shows focus but reported on some of the highlights for Information Security in his Column
    http://www.networkworld.com/newsletters/dir/2009/101909id2.html?hpg1=bn

    Particularly he noted the innovative solution for Privileged Account Management offered by Liebsoft and highly tuned and integrated to work with Oracle products:
    Also of interest to Dave was the unique Enterprise SSO Anyware offering Oracle brought to market through their alliance with PassLogix:


    Though Dave did not mention what many feel is one of the most innovative architectural solutions for Web Access Management announced by F5 to reduce the complexity of agent deployments, updates, and management by moving them to the load balancer with their industry leading Big-IP product.
    http://www.f5.com/news-press-events/press/2009/20091006.html