The road to identity management: How to know who's who and what's what
Computerworld - Providing secure, efficient and controlled access to information is critical. Companies must be structured so the right people have easy access to the information required to make smart business decisions.
Corporate executives also must track and control who has access to what information in order to comply with demanding regulations like the Sarbanes-Oxley Act and the Health Insurance Portability and Accountability Act. Added to these security pressures is the fact that businesses are being required to do more with less to remain competitive while also ensuring high-quality customer service.
To address these challenges, executives are turning to identity management as a method for minimizing security risks, controlling costs and maintaining service levels while also sharing information with employees, customers and partners across the virtual enterprise.
As identity management increases its critical role within organizations, two emerging concepts are approaching their respective tipping points -- federated identity and radio frequency identification (RFID).
Federated Identity: Who Is It
Federated identity helps businesses establish a virtual network, or "circle of trust," through authentication (of an identity) and single sign-on across domains. The vision is that users and their identities are grouped and trusted across many boundaries such as those with partners, customers and third-party contractors.
Companies are looking at federated identity as a way to deploy new services for their customers quickly, easily and at a lower cost. For example, a mobile telecommunications company can offer its subscribers news, messaging, ring tones and games from multiple third-party providers. Federated identity authenticates and authorizes access to levels of content based on a subscriber's service contract. The potential results are new revenue opportunities and increased customer loyalty.
Deploying federated identity requires coordinated planning and execution to get the various identity management applications to exchange information correctly. As a result, federated identity faces several hurdles before it becomes widely deployed.
The technology is available to make federated identity a reality, but quite often the business policies to support it are not in place within an organization. The goal is for one company to be able to understand and trust information from another company, regardless of their identity management applications.
For example, a wireless service provider can share federated identity information with retail vendors, such as Starbucks, so that as a user travels on business, he can be alerted of nearby store locations through a cell phone. Another example is a health care network using federated identities across multiple companies, which includes the passing of private data.
These two examples have very different levels of security associated



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts