IETF explores new working group on identity management in the cloud
Network World - Proponents of a common scheme for managing user identity in cloud-based applications will pitch their idea to the Internet's premier standards-setting body at a meeting in Paris later this month.
A specification already exists for Simple Cloud Identity Management (SCIM) that is supported by security software vendors including Cisco, Courion, Ping Identity, UnboundID and SailPoint. SCIM also has support from key cloud vendors, including Salesforce, Google and VMware.
At issue is whether SCIM will become an IETF-approved working group and eventually an industry standard.
The IETF is hosting a meeting to discuss the proposed SCIM working group on March 29. In January, the IETF created a mailing list to discuss SCIM.
Proponents of SCIM say the protocol will make it easier for companies to control access to data stored in popular cloud-based applications like Salesforce, Workday, Taleo, Box and others.
Gartner backs the idea of SCIM as a simpler method of provisioning and de-provisioning employees from cloud applications - a process that's currently handled manually in most corporations. Mark Diodati, a research vice president with Gartner, wrote in late February "it appears that SCIM remains on track."
One vendor that's a strong proponent of SCIM is UnboundID, which sells identity management infrastructure software for service providers.
"There is no meaningful way to sling identities from cloud to cloud or from cloud to premises applications," explained UnboundID's CEO Steve Shoaff. "UnboundID is one of the only vendors shipping a commercial version that allows you to broadcast SCIM events and receive SCIM events. It's a modern protocol and a way to share identities between cloud providers. We're building our entire portfolio around SCIM to really build the identity economy."
Proponents say that what's good about SCIM compared with previous identity standards such as SPML is that SCIM is lightweight, it doesn't try to do too many functions, and it uses a Web services approach.
The alternative to SCIM is the proliferation of proprietary APIs for each cloud application. This situation requires security software vendors like Courion and SailPoint to create custom connectors to provision each cloud-based application.
Instead, SCIM would provide a standard way to move identity data from premises-based to cloud applications and from one cloud application to another.
"We're seeing a lot of interest" in SCIM, says Patrick Harding, CTO of Ping Identity. "We haven't had strong standards in that space. All the vendors developed their own APIs. That's where we've been working for the last year with all the major [software-as-a-service] vendors to standardize on an API mechanism to automate the account management."
- SIP Migration: Addressing CIOs' Concerns Recent data from IDG Research shows that many IT executives are counting on SIP to help them meet employee efficiency and customer experience...
- City Solved Network Mystery - Saves $30K The City of Jacksonville put their hunch to work and not only solved a mystery, but found a new and innovative use for...
- Using Video to Gain a Competitive Advantage: A Business Strategy for Mid-Market Companies The insights provided in this white paper are based on industry analysts and 30+ years of experience from the Video Collaboration Group at...
- Comprehensive Advanced Threat Defense The hot topic in the information security industry these days is "Advanced Threat Defense" (ATD). This paper describes a comprehensive, network-based approach to...
- On-demand webinar - 7 Keys to Service Catalog Implementation Success Watch this webinar to learn 7 crucial keys to make your service catalog a success!
- Transform Your IT Service Management Watch this webinar, to learn how EasyVista can increase IT productivity & efficiency and deliver streamlined & integrated IT Service & Asset Mgmt. All Network Security White Papers | Webcasts