Tuesday, November 10, 2009

Infinite Identities

What's with the title, "Infinite Identities"?



Ok, so mostly it was selected because it was available and sounded catchy. But the Network World article today, "Drowning in Passwords", really speaks to the origin of the name and the key challenges we all face as individuals and organizations trying to manage our seemingly infinite number of identities.

While we mostly talk about security and compliance, IAM is truly a management problem. Both in the real world and in the virtual one we all play many roles:
  • Father, husband, brother, son, grandson, friend, son-in-law
  • Litter Box cleaner, leaf raker, toilet plunger, bug-killer
  • Surfing-buddy, lunch-meeting-friend
With matrixed organizations, overlapping projects, evolving priorities, and dynamic timeslines we equally have a complex identity in the office:
  • Manager, employee, co-worker, partner, customer
  • Internally as a client of HR, procurement, legal, expenses
  • Externally as a client of the healthcare provider, 401k, gym, etc.
  • Selling to customers, selling with/to partners or partners selling to you
  • The lead on a FY planning project, contributor on a new product strategy, listener on a new marketing program
Each one of these roles has a unique identity, not just by itself but also in all their interactions. This makes the number of not only accounts and password endless, but truly makes our entitlements infinite.

The challenge is only further complicated when you layer in social networking, from blogs to Facebook and Twitter, our 1:1 interactions in one role gets mixed with our identities in another. For example many have learned to keep their work "friends" on linkedin and their personal "friends" on Facebook, and their family ... on email.

This increasing web of complexity fuels the continous need for new innovations, solutions, and ultimately integrations to address it.

With this Blog, Infinite Identities, we will look to highlight and promote the best practices and best solutions being driven by innovative partnerships in IAM.


Thanks for reading!
Brian

Monday, November 9, 2009

Identity Proofing with IDology and Oracle Adaptive Access Manager (OAAM)

Do you know who I am?

You may think so, but what if someone has hijacked my account, my identity, my computer, my web browser, my session, etc. With high impact/value transactions, this “What if?” can have major consequences.


Richard M. Nixon famously said “I know you believe you understand what you think I said, but I am not sure you realize that what you heard is not what I meant.”


The point here being, even when you believe you know the user you may not? In an era where accounts, machines, and identities are taken hostage there is a need for a technology that can verify that you are who you say you are.


When do I need this?

  • Someone is trying to open a new bank or credit card account - stolen identities can be translated into thousands of dollars in lost merchandise, hurt your brand, and increase insurance or credit card rates.

  • Bank Transfers – Hijacked accounts from malware/viruses can leverage existing legitimate sessions to transfer money out of customer accounts.

  • Car Lease/purchase – Imagine someone walks off the lot with a car, but under a false identity. The retailers is unlikely to ever see the vehicle again.

  • Cell Phone – Using stolen identities or credit cards, thieves can rack up thousands in international phone bills

  • Medical Records – Employers could leverage inside information on potential employees to make hiring decisions based on potential health insurance cost from pre-existing conditions

  • Customer Data – Sales person walks away from their desk and a soon-to-be-leaving employee downloads current pipeline information or customer data to bring to their future employer.


The list of examples is endless and applies across all types of organizations, from public sector to higher education, from Fortune 500 enterprises to financial services and health care.


So how does this work?

  • Based on policy, type of transaction, or probability of Fraud calculated by OAAM's risk scoring engine in real time, users can be promoted to join an “Authentication Session”.

  • Users will be asked a series of questions such as “Which one of these is a street you grew up on?” or “What is the make/model of your first car?

  • Unlike traditional Knowledge Based Authentication (KBA) with IDology questions and answers are generated dynamically based on a combination of public/private data sources. This is called Dynamic KBA.

  • Based on the users answers IDology creates a fraud score, and OAAM determines, based on the organizations defined policy, if it will allow the user to continue with the transaction.

  • OAAM can also used other context information such as Geo Location data, or require secondary or step-up authentication from something like StrikeForce SMS, ActivIdentity, or Verisign VIP.


You want to see it in action:

Demo



Oracle / ArcSight – Providing Real Time Oversight of User Behavior

When IT infrastructure generates millions of events/logs daily, how do you do you know if there is an issue and who is causing it?


Traditionally SIEM (System Information & Event Management) products track events by what resources are employed, when, by whom and for what result. Unfortunately the “who” part changes in real time based on the process being used and for what purpose. But with IdentityView, ArcSight transfers identity and role information from Oracle Identity Manager into its Enterprise Security Manager so that it can correlate all the identity markers and privileges of a specific user.


Armed with this proverbial identity matrix, ArcSight ESM can then associate events with a specific person, independent of the various identities that he or she employs.


So why do we need this?

  • To automate the correlation of compliance and policy violations with specific users

  • To understand how your key users (admins to accountants) are using IT infrastructure

  • Increase accuracy/productivity of your role engineering and provisioning process

  • Respond to security and compliance issues before they damage the organization

  • Provide business owners with information about policy and security violations in terms that they understand and can act on

  • Provide visibility and assurance to C-level executives that policies are being enforced to conform with compliance regulations such as Sarbanes-Oxley, PCI, HIPAA, etc.


What are the benefits?

  • Leverages the investment in OIM by linking users and roles to security problems, compliance violations, etc.

  • Faster identification of security and compliance issues resulting in more rapid response and remediation

  • Control/monitor access rights & IT usage (services, apps, data, etc.) requires correlating millions of real time alerts and logs with specific user activity

  • Provide auditors with proof that controls are in place and effective

  • Visibility into violations of corporate policies covering customer, employee and business-sensitive data

  • Improved productivity via automation of required reports, summaries and auditor requests for information






So why now?

    You already have this covered

  • Many organizations have invested in home-grown event monitoring solutions, but the challenge is that problem continues to get bigger, with every new system (applications, devices, Cloud/SaaS solutions) added to the environment.

  • ArcSight cleanly replaces those solutions and delivers more functionality at a lower cost.

    You can't face this now, maybe in the future

  • SIEM solutions are now considered standard “due care” for auditors concerned with SOX compliance.

  • PCI DSS #10 explicitly requires monitoring of the relevant IT infrastructure.

    You don't have the resources

  • Budgeting for security and compliance is difficult but by combining ArcSight with Oracle Identity Manager, organizations can “double up” on their return on investment based on the synergy between the products.

  • SIEM alone provides multiple solutions for the security group, compliance group, risk management, etc.



To learn more:

http://www.arcsight.com/products/products-identity/



Friday, November 6, 2009

Vordel Launches Cloud Service Broker

With the Cloud Service Broker, Vordel pledges to bring trust and reliability to Cloud Computing


So what does this mean?

  • The solution aggregates multi-domain services across their enterprise, partners and 3rd party cloud services such as Amazon EC2 and Google Apps

  • Through bringing the services together, the Broker enables organisations to consistently define and manage policy across these services and report on them

  • Through the Broker, composite applications can be built seamless while offering full visibility, trust and control".


So why do we need this?

  • Organizations using Cloud services in conjunction with their own on-premises SOA face major issues related to reliability and trustworthiness.

  • Very difficult to bring together services from across domains (i.e. on-premises, Public and Private Clouds, and B2B) into coherent composite services and applying policies to them.


Vordel CEO, Vic Morris, said "Many organizations see the value of incorporating Cloud Services into their IT infrastructure, but they also have concerns about the reliability and performance of these services outside their domain of control. The Vordel Cloud Service Broker addresses these issues by providing a trustworthy “


So how does it work?

  • The Broker solves this problem by registering services from all three domains into a single repository, enabling monitoring, management and policy enforcement.

  • Plus the Vordel Cloud Service Broker offers value added services like caching, acceleration, and transformation, delivering enterprises savings in time and money.


What is under the covers?

  • Multi-Domain Registry Repository (MDRR) – This is where the Broker registers aggregated services across domains. This one-stop-shopping for compliance to Service Level Agreements, privacy and security mandates.

  • Analytics – Providing the visibility through an independent audit trail including raw usage information, service quality, patterns of usage over time, and identity of users.

  • Content Analysis – Content is analyzed to enable Data Loss Prevention (DLP), content-level threats, and application-level attacks at the API and payload level.

  • Caching – Protecting against latency from the Cloud service, saving money by allowing some requests to be serviced by the broker itself.

  • Composition – Allowing developers to link together local apps with Cloud-hosted apps via Web Services interfaces, database, or message schemes like MQ or JMS.

  • Content transformation – Accelerated transformation for mediation between different applications or between REST API interfaces and SOAP, JMS, COBOL, etc.

  • SLA Monitoring - Comprehensive monitoring of response time of Cloud services, and the entire transaction throughput time.

  • Traffic Throttling – Vordel refers to this as the “surge protector”, protecting against apps making a high number of calls to a Cloud service by deflecting a portion to a back-up service, newly provisioned for this purpose.

  • Event Alerting – Notification of events like Cloud outages so that remedial measures can be put into place.

  • Extensibility to 3rd Party Valued Added Services – Traditionally very difficult/costly with non standard API's from competing solutions, but is made easy & pluggable here.


For more information:


View the PDF

Product Page

Company

Press Release



Thursday, November 5, 2009

One More Time! Oracle Tops Gartners Provisioning List

Oracle Announced this morning that they were again named the leader in Gartner's "Magic Quadrant for User Provisioning".

The Gartner Magic Quadrant ranks vendors based on their completeness of vision and their ability to execute on that vision. This is indicative of a dramatic evolution in the Identity & Access Management Market over the nearly 5 years since CA announced their acquisition of Netegrity.

The move sparked a shift from focusing on Web Single Sign-On to end-to-end suites for Identity and Access Management and lead to the spending spree at Oracle which put together this leading suite of products and market vision. In total, Oracle brought together technology from 9 IAM innovators to develop this market leading technology suite:

  • Phaos - Now Oracle Identity Federation (OIF)
  • Oblix - Now Oracle Access Manager (OAM)
  • Confluent - Now Oracle Web Services Manager (OWSM)
  • Thor - Now Oracle Identity Manager (OIM)
  • Bridgestream - Now Oracle Role Manager (ORM)
  • Bharosa - Now Oracle Adaptive Access Manager (OAAM)
  • PassLogix OEM - Now Oracle Enterprise SSO (OESSO)
  • BEA ALES - Now Oracle Entitlements Server (OES)
  • BEA WebLogic Security Services - Now OPSS


One of the pioneers in this evolution had this comment on the announcement;

"With roles, rules and policies continually evolving within the enterprise, organizations need strong user provisioning solutions to streamline security, achieve increasing levels of automation and efficiency and ensure sustainable compliances," said Amit Jasuja, vice president, Oracle Identity Management. "We are pleased to be recognized as a leader in Gartner's Magic Quadrant for User Provisioning, and remain committed to delivering the most secure, comprehensive and scalable solutions to customers."

Looking at the full Magic Quadrant for User Provisioning it is interesting to note that with Sun in the top 3 as well it is clear that this market is heading for further evolution but more importantly innovation that will directly benefit customers and technology providers leveraging an increasingly mature, standardized, IAM suite across each layer of the application stack regardless of the deployment model.

Here is the link to the
press release.

Wednesday, November 4, 2009

Persistent helps organizations say Bye-Bye to CA SiteMinder

Persistent Systems delivers a packaged solution for migrating from CA SiteMinder to Oracle Access Manager (OAM)


So why do we need a solution for this?

· Accelerated – Save time (i.e. $ on implementation)

· Lower Risk – Repeatable solution reduces project risk

· Proven – Well laid path by existing reference customers

· Turnkey – OOTB solution



Why do organizations want to migrate?

· CA SiteMinder has a very large & dissatisfied install base because of

o Poor investment in Dev and Support – There are substantially less engineers building/supporting SiteMinder then when it was part of Netegrity, while Oracle has increased the dev team on OAM

o Costly Support – CA support pricing model creates painfully high pricing (disproportionate with the rest of the market) in the mind of many organizations.

· Stack Limitations:

o As a stack, the Oracle IdM suite has dramatically out paced CA in completing the picture and innovating towards the future.



So who should consider this?

· SiteMinder users with Oracle products (DB, EBS, Apps, IdM…….) – i.e. those that will benefit from the Oracle IAM Suite and the broader Oracle Suite

· Customers who use both SiteMinder and OAM for different applications or business units – i.e. those hungry for actual SSO

· Customers who have SiteMinder environments through acquisitions – i.e. cost savings

· Anyone with a SiteMinder deployment


So why now? Why was this not done already?

· Legacy – SSO environments constitute several years of work/investment

· Perception – Migrations are seen as long, effort-intensive, expensive and risky

· Time – Typically ROI is too far away, but not in this case


Persistent Systems' SM2OAM solution addresses all these challenges!


Case in Point – At a large public technology provider (not ORCL), the migration time from SM to OAM was brought down from 24 months to 6 months!



OK, so how do we do this?

· Option 1 - Fully outsourced

o Turnkey Persistent solution includes ‘acceleration plus services’

o All phases delivered by Persistent

o Direct, subcontract and fixed fee options available

· Option 2 - Joint solution

o Persistent provides ‘acceleration’ for existing services team

o Phases in blue delivered by partner, rest delivered jointly by Persistent

o Fixed fee, markup and shared revenue options available


So who is Persistent Systems?

· Over a decade working on the backend doing OAM engineering

· Over 140 person years of engineering experience with Oracle IAM stack

· Ongoing implementation efforts – 20+ marquee customers

· Winner of Oracle's partner ‘Challenge’ – OID 2 billion benchmark, ‘last-mile’ solutions

· 20 years old, profitable, 5K people, hundreds of customers, Thousands of product releases

· Global presence – North America, Europe, UK and Asia


To get started contact:

Muneer Taskar

muneer_taskar@persistentsys.com

Tuesday, November 3, 2009

StrikeForce Technologies ProtectID® provides step-up two factor “Out-of-Band” authentication to OAAM

Using OAAM and ProtectID® together, companies can defend against the latest online threats, including account takeover schemes and man-in-the-middle attacks to restore trust in Internet transactions. The combined offering utilizes advanced authentication and fraud prevention to evaluate risk and alert organizations in real-time to potential fraud threats. In addition, the OAAM/ProtectID® solution enables companies to employ a range of security options, including “Out-of-Band” phone authentication, to meet diverse user requirements or upgrade to higher levels of protection as threats increase without reinvesting in infrastructure. Enterprise Security Officers prefer two-factor authentication all the time. Consumers are happy with simple ID/Password authentication, thereby finding a workable solution has been a challenge for companies.

The Oracle Adaptive Access Manager (OAAM) combined with StrikeForce’s ProtectID®, meets this challenge. Heightened regulatory requirements (e.g. FFIEC and The Red Flags) recommend adopting strong two-factor authentication for the higher risk transactions. Gartner recommends “Out-of-Band” authentication as a necessary layer to prevent Identity Theft. The regulations explicitly discuss the use of One Time Passwords (OTP) delivered via phones or similar devices in addition to utilizing “Out-of-Band” strong authentication. The ProtectID® strong authentication platform provides these services (which is the reason the partnership with StrikeForce was developed). Many of these enterprises also want two-factor authentication for their employees (which OAAM and ProtectID® also solves in combination and separately).

The ProtectID® platform is an implementation or “Cloud Service” of the OOB Authentication methodology providing strong authentication via a number of different authentication technologies. Currently the platform supports the following strong authentication methodologies:

“Out-of-Band” methodologies:

  • Entering a fixed PIN in a phone
  • Entering One Time Password (OTP) in a phone
  • Sending an OTP to a phone via SMS
  • Sending an OTP to a phone via text to speech
  • Sending an OTP via email

Token methodologies:

  • Hard Token OTP (key fob that displays OTP when a button is pressed)
  • Soft Token OTP (OATH compliant software) that can reside on a PC or a Black Berry or PDA or J2ME compliant cell phone.

Value of ProtectID® to OAAM

A ProtectID® and OAAM combined solution delivers an advanced security proposition to combat the growing threat of consumer identity theft and fraud on the Internet. The combination of OAAM’s real-time fraud prevention and ProtectID’s real-time two-factor “Out-of-Band” authentication platform, provides financial institutions, online retailers, health care companies and other businesses with a robust arsenal of security tools for protecting consumers from fraud, for accurate identification of employee access, and all while complying with industry security guidance’s and regulations.

Therefore, with the combination of OAAM and ProtectID®, the client benefits from a Return On Investment (ROI) and compliancy with regulatory requirements (FFIEC, Red Flags and others), with minimal inconvenience to the most important person, the end user. The majority of transactions authenticated should pass the OAAM fraud prevention process. For those transactions that are detected and flagged as potentially fraudulent, OAAM would then automatically invoke ProtectID® to perform a two-factor strong authentication for the consumer, which minimizes the expensive help desk process and thereby provides greater satisfaction and cost savings. This total fraud prevention solution is a win/win for the company and its clients. ProtectID® could also be used for password resets, high dollar value online transactions, remote log on, etc.


Interfacing ProtectID® with OAAM

ProtectID® appears as a web service to a web site that implements both OAAM and ProtectID® and allows for step-up or other requests for strong 2-factor “Out-of-Band” authentication based on the risk level determined by the Company and or OAAM.

OAAM only employs step-up authentication when it’s truly needed so end users are not being inconvenienced.

Following is a link to allow you to test “Big Bank” showing an example of how ProtectID® can be integrated with OAAM for the best all around total solution (fraud mitigation with 2-factor “Out-of-Band authentication) with options and flexibility. Just sign on with a user name and it will ask you to register and allow you to test the Best complete compliant authentication solution available and all from Oracle:

http://d.oobauth.com:8888/sample/

For more information please contact:

Mark L. Kay, CEO
StrikeForce Technologies, Inc.
marklkay@strikeforcetech.com
www.strikeforcetech.com
(o) 732-661-9641