New laws put new rules on ID management
Computerworld -
Identity management is more than just granting and revoking user access to business systems. With the introduction of new auditing practices and regulations by the federal government, businesses are being held accountable for the security of their users' personal information.
Identity management now needs to manage how personal information, such as names, addresses, Social Security numbers and salaries, is changed and distributed while also ensuring that the individual's privacy is protected.
In addition, if digital security is to truly move beyond a cost-center mentality, it needs to deliver time and cost savings by addressing the real source of IT security concerns. Password management, account data and data management issues account for about 50% of all help desk calls -- an attention-grabber in themselves. However, it's change requests to personal or profile information, which is unique to each individual, that require the most time, effort and money to manage.
Identity management -- the policies, processes and technologies that establish and maintain governance over the access, use and storage of personal information -- now takes an evolutionary step forward by managing the permission and the personal or profile-based information that directly affects compliance with legislation, auditing practices and return on investment.
Permission- vs. profile-based information
![]()

![]()
Bill Malik is chief technology officer at Austin, Texas-based Waveset Technologies Inc., where he is responsible for the strategic direction of the company's identity management products. A 25-year veteran of the security technologies industry, he most recently was director of KPMG's Risk and Advisory Services practice and was also vice president at Gartner Inc. He has written more than 150 research reports on security and long-range technology futures.
In contrast, profile-based identity information -- which includes an individual's home and business addresses, office location, telephone numbers, employment history, medical history, payroll records, financial information and related roles, and rules concerning the individual's interaction with various applications -- lies both within and across organizational boundaries. When a person moves, he needs to update his profile data -- specifically his mailing address -- with many different departments to ensure that he receives his paycheck (finance), his expense check (accounting), his health insurance information (human resources) and his 401(k) information
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

