Feeds

Identity management bandwagon on a roll

You can't do that

  • alert
  • submit to reddit

3 Big data security analytics techniques

Comment Who does what with an enterprise IT system can be quite important. This is even more the case given the glut of new regulations and laws governing how businesses are run in a post-Enron/Worldcom world, even if it only means that the right company director can be taken outside and shot. So knowing which people should have access to what systems and trapping the meddlers –whether malicious or incompetent – is now a core component of sound compliance management.

That is one reason why Identity Management systems are now getting to be big business. Earlier this month HP announced a new ID management module as part of OpenView, following the announcement of specialist ID Management system vendor, Trustgenix. IBM has expanded its offerings here with a new module for its infrastructure management system, Tivoli, known as Tivoli Access Manager. This sets out to create what the company calls an `all in one audit centre’ which captures data on all applications accesses by every user and compares them to access approval data. From this, access compliance reports can be automatically generated.

If it is then combined with the existing Tivoli Federated Identity Manager, companies can then extend this capability to monitor and report on the level of access to services that have been generated by third parties such as business partners and suppliers.

It all marks another trend in infrastructure management which applications developers must learn to accommodate. To fit into an enterprise infrastructure these days, applications will need to integrate into management environments such as Tivoli and OpenView in order to report on activity such as the ID of users that have accessed the application. With compliance to legislation and regulations now a core responsibility for IT and business managers – with seriously significant penalties attached that may be exercised with extreme prejudice – knowing who is allowed to access applications and data, and stopping those who shouldn’t, is now an important trick.

And as it grows in importance, so the major vendors of infrastructure solutions will be looking for technology to incorporate in their offerings. So if any developers out there have good ideas in the ID arena, now is the time to start advertising themselves. They might well sell some product – better still they might even sell the company. ®

SANS - Survey on application security programs

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Oh no, Joe: WinPhone users already griping over 8.1 mega-update
Hang on. Which bit of Developer Preview don't you understand?
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
Ditch the sync, paddle in the Streem: Upstart offers syncless sharing
Upload, delete and carry on sharing afterwards?
Microsoft TIER SMEAR changes app prices whether devs ask or not
Some go up, some go down, Redmond goes silent
Batten down the hatches, Ubuntu 14.04 LTS due in TWO DAYS
Admins dab straining server brows in advance of Trusty Tahr's long-term support landing
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.