<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" version="2.0"> 
	<channel> 
		<title>Kuppinger Cole + Partner</title> 
		<link>http://www.kuppingercole.com</link> 
		<description>Kuppinger Cole + Partner</description> 
				<geo:lat>48.13</geo:lat><geo:long>11.56</geo:long><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/kuppingercole" type="application/rss+xml" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">kuppingercole</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2Fkuppingercole" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fkuppingercole" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2Fkuppingercole" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://feeds.feedburner.com/kuppingercole" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fkuppingercole" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fkuppingercole" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fkuppingercole" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item> 
			<pubDate>Sun, 22 Nov 2009 17:12:28 +0100</pubDate>
			<title>Identity Management by accident or design?</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/11/22/idenity-management-by-accident-of-design/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/11/22/idenity-management-by-accident-of-design/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I was talking recently with Joerg Mauz, the CIO of a small German company called Ansmann AG that makes batteries and chargers for laptops and mobile phones. They may be tiny by some standards, but they have a big global footprint, and their  300 people are distributed around the globe from Shanghai to Macau to Stockholm and soon the U.S. as well. I asked him whether he thought Identity Management was a big issue for small companies like his, and he laughed. &amp;#8220;They don&amp;#8217;t know what it is&amp;#8221;, he said, and then added: &amp;#8220;Even though they may be doing it themselves already.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Ansmann is a good case in point: They had been using software provided by Sun Microsystems for years, and their license included the Identity Manager product &amp;#8211; but they neither knew nor cared. &amp;#8220;We sort of started doing IdM by accident&amp;#8221;, he told me.&lt;/p&gt;
&lt;p&gt;But when Joerg Mauz decided he needed to start doing e-provisioning to handle the influx of new people in his fast-growing company, and seeing as how his boss wasn’t going to give him any additional budget anytime soon, he took another look at Identity Manager and decided he could get what he wanted more or less for free. All he had to do was ask his system house, Kogit in Darmstadt, to write a few lines of additional code (it eventually paid them for 35 man days), and suddenly he had a neat little workflow that could handle logical and physical assets, anything from mail accounts to company badges, laptops and company cars.&lt;/p&gt;
&lt;p&gt;He still doesn’t see himself as doing Identity Management. And if his story is any proof, then IdM vendors and providers would do good to stop trying to sell them something they don’t really understand and doesn’t terribly interested them in the first place.&lt;/p&gt;
&lt;p&gt;Instead, they should focus on solving the problems people really have. And they may go under completely different monikers. That applies especially to the German “Mittelstand”, the thousands of small and medium-sized companies that make up the backbone of the German economy.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/ns_Q3FJBTFc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 19 Nov 2009 15:36:57 +0100</pubDate>
			<title>Too many GRCs out there</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/11/19/too-many-grcs-out-there/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/11/19/too-many-grcs-out-there/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;One issue when dealing with GRC (Governance, Risk Management, Compliance) is that there is no single person which is responsible within organizations. And there is a simple reason for that: There are far too many GRCs out there. Vendors provide completely different offerings using the same acronym. That&amp;#8217;s not new, but in the case of GRC, there is even more uncertainty raised than usual in the IT industry.&lt;/p&gt;
&lt;p&gt;From my perspective, the solutions might be segmented into four layers:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The so called &amp;#8220;Enterprise GRC&amp;#8221; which should be better named &amp;#8220;Business GRC&amp;#8221; or something because the other technologies are as well around the &amp;#8220;Enterprise&amp;#8221; but sometimes more focused on IT. Vendors in that space are, amongst others, companies like OpenPages, Bwise, Mega. The focus is on business risks and business controls, a high level view and frequently mainly on manual controls.&lt;/li&gt;
&lt;li&gt;The layer which is best described with the term &amp;#8220;Continuous Controls Monitoring&amp;#8221;, which is about looking at specific IT systems and issues from a business perspective. Order processes, delivery status, and such things. Typically there is a mix of automated and manual controls, and some systems focus more on specific enterprise applications (billing,&amp;#8230;), whilst others focus more on the consistency of the entire process. Vendors here are, amongst others, companies like SAP (Process Control, Risk Control) and Oracle, mainly for their environments, and such ones like Approva.&lt;/li&gt;
&lt;li&gt;The layer which I&amp;#8217;d call &amp;#8220;specific/specialized GRCs&amp;#8221;, amongst which IAM-GRC solutions (sometimes called &amp;#8220;access governance&amp;#8221;) and SIEM solutions are the most popular ones, even while I&amp;#8217;d add several service management tools as well as long as they focus on service fulfillment and the service management process itself. These tools provide much more depth on specific controls, typically only a small subset of all IT controls. IAM-GRC for example focuses on roundabout 4 of 210 COBIT controls, the ones around identity and access. However, the level of automation is significantly higher and controls are much more specific. In each of the segments here we have a lot of vendors.&lt;/li&gt;
&lt;li&gt;System-level tools around operations management, system-level auditing, integration of system-level logs and that stuff &amp;#8211; tools which really do a deep dive into the access controls of file servers and shares and other aspects.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With a big picture like that, it becomes obvious, that we have several elements within a GRC strategy. Business and IT have to work closely together to define what is needed in which area and how these tools interfere and how they have to be integrated. With this view, the need for a single person as responsible one for GRC diminishes. There are at least two, one at the business and one at the IT level. And there are even more for different &amp;#8220;operational&amp;#8221; tools at the lower levels.&lt;/p&gt;
&lt;p&gt;If companies have defined their big pictures, it is easier for them to identify which tools they need to implement it. And it is easier for vendors to identify the persons to speak with.&lt;/p&gt;
&lt;p&gt;More important from my analyst perspective is the first aspect: Companies which don&amp;#8217;t have a clearly defined strategy on GRC will most likely end up with a mix of tools, non-integrated, not always providing the required features. Thus: A GRC roadmap and a GRC architectural blueprint are mandatory.&lt;/p&gt;
&lt;p&gt;More about the system-level aspects might be heared (for the ones who read this soon) at our &lt;a title="Kuppinger Cole Webinar" href="http://www.kuppingercole.com/events/n40066" target="_blank"&gt;webinar today&lt;/a&gt;. A &lt;a title="Kuppinger Cole Webinars" href="http://www.kuppingercole.com/webinars" target="_blank"&gt;replay&lt;/a&gt; will be available soon.&lt;/p&gt;
&lt;p&gt;Even more information about this topic and especially the IAM-GRC aspects (Access Governance) will be available at the &lt;a title="Kuppinger Cole Virtual Conference" href="http://www.kuppingercole.com/virtual/accessgovernance" target="_blank"&gt;Kuppinger Cole Virtual Conference&lt;/a&gt; on this topic December 8th to 9th. Registration for that conference is free.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/9NihJlXa97k" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 19 Nov 2009 11:28:17 +0100</pubDate>
			<title>Tim Cole: Show me your terrorists!</title> 
			<link>http://www.kuppingercole.com/articles/tc_show_terr_181109</link> 
			<guid>http://www.kuppingercole.com/articles/tc_show_terr_181109</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; I just came back from a meeting of the German chapter of IAPP, the International Association of Privacy Professionals, and the words of the chairman, Dr. Jyn Schultze-Melling, a lawyer with the firm Nörr, Stiefenhofer &amp; Lutz, still ring in my ears: We are sacrificing employee privacy on the altar of anti-terrorism.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/articles/tc_show_terr_181109"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/c5rddXw-JZc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 19 Nov 2009 00:00:00 +0100</pubDate>
			<title>Pass Your Next Compliance Audit With Confidence</title> 
			<link>http://www.kuppingercole.com/podcasts/pass_your_next_compliance_audit_with_confidence.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/pass_your_next_compliance_audit_with_confidence.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Bottom-Up or Top-Down or both? What is the appropriate approach to automate auditing on access and reporting on directories and identities and also on mail and file access? In This Webinar, Martin Kuppinger (Kuppinger Cole), Jackson Shaw and Reto Bachmann (both Quest Software) will discuss with you these questions and talk about best practices on how to integrate IT- and business views.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/pass_your_next_compliance_audit_with_confidence.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/5GYsAqmTvo8" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 11 Nov 2009 00:00:00 +0100</pubDate>
			<title>Single Sign On for SAP Environments</title> 
			<link>http://www.kuppingercole.com/podcasts/single_sign_on_for_sap_environments.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/single_sign_on_for_sap_environments.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; The identity management marketplace offers a number of different solutions enabling Active Directory-based single sign-on for SAP, making life for SAP endusers much easier and at the same time offering a good potential to reduce the costs of managing your IT infrastructure. In this webinar, Martin Kuppinger (Kuppinger Cole), will talk about the different concepts of SAP-SSO and why Kerberos is a real option in such an environment. Then, Jackson Shaw and Reto Bachmann (Quest Software) will pre...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/single_sign_on_for_sap_environments.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/f0NxGHuYPe4" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 09 Nov 2009 00:00:00 +0100</pubDate>
			<title>Product Report: Quest Single Sign-On solutions for SAP</title> 
			<link>http://www.kuppingercole.com/report/mk_pr_quest_ssosap_091109</link> 
			<guid>http://www.kuppingercole.com/report/mk_pr_quest_ssosap_091109</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;The two products discussed here, Quest Single Sign-On for SAP GUI and ABAP and Quest Single Sign-On for NetWeaver, are Quest&amp;rsquo;s offering in the market for Single Sign-On (SSO) between Active Directory-infrastructures and SAP-environments on the basis of Kerberos. Quest also offers a &amp;bdquo;classic&amp;ldquo; SSO solution called Quest Enterprise Single Sign-On as an option for infrastructures which do not run Kerberos.&lt;/p&gt;&lt;p&gt;Authenticating primarily via Active Directory which is standard...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/report/mk_pr_quest_ssosap_091109"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/hE4Ni4wpqHY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 08 Nov 2009 19:02:07 +0100</pubDate>
			<title>Sony VAIO VGN-Z series – finally with VT-support</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/11/08/sony-vaio-vgn-z-series-finally-with-vt-support/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/11/08/sony-vaio-vgn-z-series-finally-with-vt-support/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I recently bought a very expensive high-end Sony VAIO VGN-z31 and was more than surprised and downright angry, when I found out they had disabled the &amp;#8220;VT&amp;#8221;support of the Intel CPU, making it almost useless when it comes to virtualization with Virtual PC, VMware Workstation, Xen or what ever your favourite Hypervisor was.&lt;/p&gt;
&lt;p&gt;With their latest set of updates for their EFI (the new BIOS technology) now finally they gave in to the numerous customer complaints, all coming from power users and professionals, who were upset to just have spent 2.000 -3.000 €/$ on a machine, that was basically leaving them without support for virtualization.&lt;/p&gt;
&lt;p&gt;Vaio customers, rejoice! Check the update sources for your machine, and hopefully you will find a matching update. For all others: check out the &amp;#8220;reverse engineered&amp;#8221; hacks for activating VT&amp;#8230;&lt;br /&gt;
Happy VMwaring&lt;/p&gt;
&lt;p&gt;Sebastian&lt;br /&gt;
PS: off to get that SQL Server running&amp;#8230;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/fJG34lhagVI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 05 Nov 2009 11:56:30 +0100</pubDate>
			<title>Why cloud services will sell despite slowdowns in outsourcing and MSS growth</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/11/05/why-cloud-services-will-sell-despite-slowdowns-in-outsourcing-and-mss-growth/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/11/05/why-cloud-services-will-sell-despite-slowdowns-in-outsourcing-and-mss-growth/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Within the last few months, I&amp;#8217;ve read several news about slowdowns in the growth of the outsourcing business and particularly the MSS (Managed Security Services) business, at least compared to the high expectations raised in the years before. Does that mean that the cloud is dead before it really starts? I don&amp;#8217;t believe, for several reasons:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;There are different numbers regarding the status and grwoth of the MSS and outsourcing market. Some are much positiver than others &amp;#8211; and it is no surprise that the negative ones are cited most (even the IT press more and more acts in the yellow press way&amp;#8230;).&lt;/li&gt;
&lt;li&gt;In days of economic turmoil (and we are still in these days, despite the quick recovery of the bonus mentality in financial institutions), customers tend to first drop external services before they fire employees &amp;#8211; that affects MSS.&lt;/li&gt;
&lt;li&gt;Outsourcing is sort of a &amp;#8220;big beast&amp;#8221; which is diffcult to tame. It takes a long preparation, it is inflexible. Overall, it needs to adopt to become more flexibile and easier to use. Cloud Computing with its granularity of services is an approach to address the shortcomings of outsourcing.&lt;/li&gt;
&lt;li&gt;A feedback I had from multiple CISOs regarding MSS is that the quality of service and the level of contol frequently is insufficient &amp;#8211; thus it is about implementation and delivery of MSS, not the overall concept.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Two reasons why the Cloud (in my understanding of an approach for a flexible use of IT services with the ability to switch between and choose the best provider, internal or external &amp;#8211; e.g. much more about service than about external things from the Internet) will be successful shortly explained:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;If you think about a matrix like shown below with two axis, Outsourcing is just sort of the specialized approach to the cloud. And from our expectations, the sweet spot for most providers will be around &amp;#8220;community clouds&amp;#8221;, in the centre of this. That potential for industry clouds, community clouds, and point solutions isn&amp;#8217;t unveiled yet. Thus, there is much more in the cloud than is discussed today.&lt;/li&gt;
&lt;li&gt;The cloud is not new. It didn&amp;#8217;t just appear at the sky but grew over years. SaaS is out there for a while, service management as well. Not even to talk about outsourcing. The cloud is, from my perspective, just the result of an evolution from a tactical, opportunistic use of external services towards an strategic approach on how to best provide IT services (external vs. internal). We&amp;#8217;re at sort of the &amp;#8220;break-even&amp;#8221;, to use an analogy.&lt;/li&gt;
&lt;/ol&gt;
&lt;div id="attachment_228" class="wp-caption aligncenter" style="width: 1034px"&gt;&lt;a rel="attachment wp-att-228" href="http://blogs.kuppingercole.com/kuppinger/2009/11/05/why-cloud-services-will-sell-despite-slowdowns-in-outsourcing-and-mss-growth/blog-2009-11-05/"&gt;&lt;img class="size-large wp-image-228" title="Kuppinger Cole View of Cloud Segments" src="http://blogs.kuppingercole.com/kuppinger/wp-content/uploads/Blog-2009-11-05-1024x734.png" alt="Cloud Matrix" width="1024" height="734" /&gt;&lt;/a&gt;&lt;p class="wp-caption-text"&gt;Cloud Matrix&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;By the way: The biggest risk for the cloud is too much marketing. But that was the same with Client Server, the Internet, and many other things. None of them disappeared, but all big changes took years to become reality. The same is true for the cloud.&lt;/p&gt;
&lt;p&gt;I appreciate your feedback on that! And see you at&lt;a title="Kuppinger Cole Events" href="http://www.id-conf.com" target="_blank"&gt; EIC 2010 and Cloud 10&lt;/a&gt;, both to be held in Munich, May 4th to 7th, 2010.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/jPyBKhZ2eas" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 04 Nov 2009 15:50:17 +0100</pubDate>
			<title>Commenting Print: Welt Kompakt 4.11.2009</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/11/04/commenting-print-welt-kompakt-4-11-2009/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/11/04/commenting-print-welt-kompakt-4-11-2009/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I guess it became unpopular to read printed news in some societies but I really enjoy reading WELT KOMPAKT, a smaller printed formfactor of well-known daily WELT. Today, the more or less entertaining &amp;#8220;Internet&amp;#8221; section had a lead article called &amp;#8220;Safe in the Web 2.0&amp;#8243; or &amp;#8220;Sicher im Web 2.0&amp;#8243; by author Peter Zschunke. Eager to learn more about how &amp;#8220;the general public&amp;#8221; is informed about the dangers that lurk in the web, I read the mid-size article, featuring a James Bond-like shot of what seems to be Security Ops Center. My interest turned into surprise, ending in a sort of rage when I finished the article.&lt;br /&gt;
It takes quite some time and effort to make me angry, but I instantly &amp;#8211; for the first time in my life &amp;#8211; wrote a letter to the author and the editors, and went like this:&lt;br /&gt;
Sehr geehrte Damen und Herren, sehr geehrter Herr Zschunke!&lt;/p&gt;
&lt;p&gt;Ich habe anfangs mit Interesse, später mit zunehmender Verwunderung das gelesen, was die Welt Kompakt als redaktionellen Beitrag in der Internet Rubrik hat drucken lassen. Für mich klingt diese doch sehr einseitige, leider wenig von journalistischer Qualität sprechende Berichterstattung eher nach Advertorial, denn nach guter Recherche und umfassender Information. Dem Format und dem Umfang sei geschuldet, dass hier nur ein Bruchteil der Problematik von Datensicherheit und Datenschutz im Web 2.0 beleuchtet werden kann – aber dann ernsthaft dem Leser zu vermitteln, die Firma RSA hätte „die Lösung im Schrank“ und könne diese Probleme quasi „wegzaubern“ wenn sich die sozialen Netzwerker denn endlich mal aus dem Sessel bequemen würden? Das halte ich nicht nur für inkorrekt, ich halte es für gefährlich! Zumal „RSA“ nun wirklich nicht das Produkt sondern der Firmenname ist und Sie, wie ich annehme, eigentlich von einer Kombination der enVision Produktlinie mit anderen Werkzeugen sprechen. Zumindest die Nennung einiger vergleichbarer Technologien oder Anbieter wie Novell, ArcSight, CA etc. hätte der Neutralität gut getan…  Die Produkte und Lösungen der RSA sind sicher anerkannt und wirkungsvoll – sowohl bei der Analyse von (Fehl-)Verhalten als auch beim Zugriffsschutz und der Verschlüsselung. Aber, um es sinngemäß mit den Worten von Bruce Schneier zu sagen:&lt;br /&gt;
„Wer denkt, dass Technologie seine Probleme lösen kann, der hat weder die Technologie noch die Probleme verstanden.“&lt;/p&gt;
&lt;p&gt;Das Problem mit der sehr einseitigen Berichterstattung bleibt – es gilt eher am Konzept der sozialen Netzwerke, ihrer Datensammlung und Datenverwaltung zu arbeiten und den Anwender besser aufzuklären. Meiner Meinung nach steht Ihr Artikel der Aufklärung der Anwender eher im Weg, da hier ohne Sinn nach Technologie verlangt  wird obwohl der eigene Menschenverstand ein viel besseres Mittel zum Schutz vor Missbrauch wäre. Bei mir hinterlässt dieser Artikel einen sehr faden Beigeschmack.&lt;/p&gt;
&lt;p&gt;There is nothing wrong with a good advertorial or product related story, but this was so blatently single-sided, I just could not resist! I would love to discuss this with alll of you &amp;#8211; feel free to comment, mail or call me!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/2rG1ypNnElM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 29 Oct 2009 10:17:50 +0100</pubDate>
			<title>The German data protection law starts to bite</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/10/29/the-german-data-protection-law-starts-to-bite/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/10/29/the-german-data-protection-law-starts-to-bite/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;The Deutsche Bahn has been sentenced to a penalty of 1,1 Mio Euro for breaches of the German data protection law, e.g. the privacy regulations in Germany. That is the record penalty based on the BDSG (Bundesdatenschutzgesetz), how the law formally is called. The reason for that penalty were abusive analysis of employee data, to identify potential cases of corruption and fraud. Data of bank accounts of suppliers and employees were compared. That became public, there was a lot of public discussion about &amp;#8211; the topic was top in the news for several days. And the CEO, Hartmut Mehdorn, was (factually) fired.&lt;/p&gt;
&lt;p&gt;However, dealing with corruption and fraud is a must for the management of any corporation. Heinrich von Pierer, the former CEO of Siemens, had to leave the company because he didn&amp;#8217;t address corruption and fraud. Hartmut Mehdorn did it &amp;#8211; and lost as well. Obviously, there are regulations in conflict. The problem of both was that they had no valid concept of which regulations are relevant, which are in conflict and how to deal with these conflicts. The Bahn analyzed far too much data and didn&amp;#8217;t put that approach into a bigger concept, openly discussing it with the works council and so on.&lt;/p&gt;
&lt;p&gt;So one lesson which should be learned by everyone with responsibility for compliance regulations (and the BDSG is one of them) is: Analyze the relevant regulations, clearly define the valid approach to deal with, discuss it with the works council as far as employee data is affected, talk with your auditors &amp;#8211; in fact have a strategic approach on how to operationalize the regulations.&lt;/p&gt;
&lt;p&gt;The second interesting aspect around the &amp;#8220;Bahn&amp;#8221; case is that the penalty is a record penalty &amp;#8211; and only 1.1 million Euro, which is sort of paid out of the petty cash. Thus it hurt some people at the Bahn, loosing their jobs. But it is only a small penalty from the perspective of the large corporation. It seems that the BDSG is sort of a &amp;#8220;law that has no teeth&amp;#8221; (in German the saying is &amp;#8220;toothless tiger&amp;#8221;&amp;#8230;). But there is good news (from the perspective of enforcing privacy and data protection): The new amendments of the BDSG will change things fundamentally &amp;#8211; the tiger will get teeth.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/tPzPz8ZqprY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 29 Oct 2009 00:00:00 +0100</pubDate>
			<title>Cloud Vendor Report: Amazon</title> 
			<link>http://www.kuppingercole.com/report/mk_vrcloud_amazon291009</link> 
			<guid>http://www.kuppingercole.com/report/mk_vrcloud_amazon291009</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Amazon is widely known as online retailer, having expanded its bookstore business to many other areas over time. Some time ago Amazon has entered the Cloud Computing market. Amazon provides a broad set of services under their label Amazon Web Services (AWS), with the Amazon Elastic Compute Cloud (EC2) as the most popular one.&lt;br /&gt;&lt;br /&gt;Amazon&amp;rsquo;s strategy for providing web services based on their own experience in providing highly scalable and reliable services for relatively low cost...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/report/mk_vrcloud_amazon291009"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/wsR-GZJ7Odw" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 28 Oct 2009 17:42:51 +0100</pubDate>
			<title>#SAPTechEd – SAP Netweaver &amp; GRC Identity Management</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/10/28/sapteched-sap-netweaver-grc-identity-management/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/10/28/sapteched-sap-netweaver-grc-identity-management/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;#SAPTechEd &amp;#8211; SAP Netweaver &amp;#038; GRC Identity Management&lt;br /&gt;
During the last 30 month I was rather critical towards SAP´s approach on how to position and further develop the technology acquired from Norwegian MaXware in 2007. The visit to SAP TechEd 2009 in Vienna showed through several technical presentations and direct interviews with people such as Keith Grayson, that SAP did a really job in not only integrating MaXware into the Netweaver group but also coming up with a sound strategy on how to move forward with whole offering. Besides the fact that Business Objects GRC systems still has some valuable functionality as provisioning tool for complex environments, the capabilities regarding the “Netweaver to SAP application” provisioning can now safely be called “unparalled” in the market. If you have access to the SDN platform, make sure to get your hands on the numerous slides in the SIMxyz track of TechEd. You can learn how to easily implement SAP Netweaver Identity Management, integrate with SAP Business Objects GRC and much more. As pointed out above, the joint deployment of the “standard provisioning engine” and the GRC one does have some benefits, especially if the Compliant User Provisioning (CUP) features are needed due to strong GRC requirements. It has been stressed in the sessions, that such a design needs to be planned very carefully and that cross-competence teams should be in charge of this to get all requirements and stakeholders represented in the final architecture.&lt;br /&gt;
Regarding 3rd party system integration, the ongoing standardization plays into SAPs hands, as Keith and I discussed the growing relevance of SPML and SAML 2.0, which, by the way, has now been tested and certified to be working with  SAP ID management solutions and might find its way into the core product in the future. More and more provisioning targets become easier to integrate, as the corresponding ISVs now see openness towards IAM solution as a benefit.&lt;br /&gt;
To sum the impressions up: Keith and all the others did a great job in “turning around a skeptical analyst”. I am positive, that the current setup and strategy will result in a good position in the ever changing Enterprise Identity Management market for SAP.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/_QXC-DC8CHk" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 28 Oct 2009 17:14:52 +0100</pubDate>
			<title>#SAPTechEd – GRC cooperation between SAP and Novell</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/10/28/sapteched-grc-cooperation-between-sap-and-novell/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/10/28/sapteched-grc-cooperation-between-sap-and-novell/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I already pointed out my personal satisfaction about the recently announced cooperation between SAP and Novell in the GRC market. This morning I had the opportunity to discuss the whole approach with Jay Roxe of Novell and Ranga Bodla of the SAP GRC group, operating both out of the US.&lt;br /&gt;
Besides my enthusiasm about the materialization of something I suggested to be beneficial (every once in a while, analysts DO show that they are humans, too!), the discussion of business opportunities, market pull and demand for GRC in general were almost identical between the three of us.&lt;br /&gt;
First let´s check the market pull: both companies said they received multiple requests by existing customers to provide insight on how to couple the more business-GRC oriented SAP solutions and the more IT-GRC oriented SIEM tool Sentinel of Novell. As open APIs were already available and Novell had their products on the path to SAP certification, taking the next step and analyzing the related business opportunity was only a matter of weeks. The joint approach beyond using and testing the APIs was then tested by a large consulting and system integration company in their labs. Looks like when there is a proven market, everybody is interested in providing a solution.&lt;br /&gt;
Second, the demand for End-to-End GRC solutions: as KuppingerCole indicated during last year`s GRC event in Frankfurt, more general and broader oriented solution would be necessary and on offer soon. Only 10 month later, not a single-product but a joint solution IS available! SAP and Novell beat our projections and I guess it will take another 6-9 month before we either see another co-op or even a merger between two niche-players to offer a competing solution or product.&lt;br /&gt;
Third, the business opportunity: SAP being the Business Intelligence provider they are, quickly was able to provide Novell with numbers on SAP GRC customers and quite a few hundred of them were identified as possible candidates to be addressed for a joint deployment. Vice versa, existing Novell customers with SAP deployments turned out to be of a significant magnitude, thus both groups form a considerable target. We at KuppingerCole can only second, that both the identified customers and the remaining “white space” in the market would benefit from a joint and integrated deployment – the former generating added value almost instantly – the latter reaping the benefits from the then (expectedly) available best practices generated by the early adopters.&lt;br /&gt;
General perspective: KuppingerCole sees their own projections and analysis fulfilled ahead of time! SAP and Novell now have a considerable head-start in the market and thus have potential to counter offerings such from Enterprise GRC vendors such as BWise, OpenPages or Mega due to the breadth and depths of the combined solution.&lt;br /&gt;
If you like to receive further insight, which GRC approach now makes sense for you, feel free to contact us and make sure to attend our upcoming related webinars http://www.kuppingercole.com/webinars &lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/gC_adkVPnxg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 21:55:39 +0100</pubDate>
			<title>08.12.2009: 5 Golden Rules for Efficiently Implementing Access Governance</title> 
			<link>http://www.kuppingercole.com/events/n40074</link> 
			<guid>http://www.kuppingercole.com/events/n40074</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; How to do Access Governance right? Which are the key success factors you have to focus on for as well quick-wins as long-term success? This session explains how to solve the access governance needs best.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40074"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/tY1-rHakgcU" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 21:51:28 +0100</pubDate>
			<title>09.12.2009: How to Start: Recertification or Active Access Controls First?</title> 
			<link>http://www.kuppingercole.com/events/n40073</link> 
			<guid>http://www.kuppingercole.com/events/n40073</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; What is the best approach to do access governance? Should you start with attestation to understand where the problems are? Or should you first have a management infrastructure in place which allows to control access across different systems and use access governance approaches then to improve the state of your information security? Or is recertification sufficient? Kuppinger Cole analysts and different vendors discuss the strengths and weaknesses of different approaches?&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40073"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/yQ3D0oGfy0I" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 21:47:33 +0100</pubDate>
			<title>09.12.2009: How to Efficiently Implement SoD Controls: Which Level Works?</title> 
			<link>http://www.kuppingercole.com/events/n40072</link> 
			<guid>http://www.kuppingercole.com/events/n40072</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; SoD controls (Segregation of Duties) are a cornerstone of access governance. But how to efficiently implement them? Should they be based on roles, on activities, on granular entitlements? There are many different approaches to solve the problem. In this panel, different vendors and Kuppinger Cole analysts will discuss different approaches for SoD controls, with focus on their manageability and the required granularity.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40072"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/OSDR3fScd0A" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 21:38:36 +0100</pubDate>
			<title>09.12.2009: XACML: The Holy Grail of Access Governance?</title> 
			<link>http://www.kuppingercole.com/events/n40071</link> 
			<guid>http://www.kuppingercole.com/events/n40071</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; In this panel, the role XACML will and can play for access governance is discussed. Is XACML the solution? What is missing? How to manage policies and how to analyze these dynamic constructs? And how to avoid vendor lock-in? The strengths, shortcomings and needed improvements are discussed by different vendors and Kuppinger Cole analysts.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40071"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/lkdmRoSq2lI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 21:33:22 +0100</pubDate>
			<title>08.12.2009: Getting the Big Picture: How Access Governance fits into IT Governance and Risk Management</title> 
			<link>http://www.kuppingercole.com/events/n40070</link> 
			<guid>http://www.kuppingercole.com/events/n40070</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Access Governance is a key element in every strategy for information and system security as well as IT Governance. However, there are many different approaches from system-level access control management tools for ERP systems with some SoD support up to Enterprise GRC solutions which focus on the risk management and governance approaches from a high-level business perspective, sometimes without the interface to IT systems. And access-related controls are only part of that  4 of 210...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40070"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/3TM9MhCSIiM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 14:32:16 +0100</pubDate>
			<title>#SAPTechEd – Google Wave @ work // Enterprise 2.0?</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/10/27/sapteched-google-wave-work-enterprise-2-0/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/10/27/sapteched-google-wave-work-enterprise-2-0/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Communication &amp;#038; Collaboration &amp;#8211; that is what email is all about &amp;#8211; or should be.&lt;br /&gt;
The GoogleWave concept mimics the snail-mail and a wiki at the same time, while being a protocol and an application also.&lt;br /&gt;
The demo looks like a cooperative instant-message chat, but showing character by character, making an almost f2f chat impression&amp;#8230;&lt;br /&gt;
Who used OneNote online before, may be used to see the joint changes of multiple participants in one document &amp;#8211; but it is amazing to see even uploads of photos and other material into the wave in a blink of a eye.&lt;br /&gt;
To see somebody adding a Google-map into the wave and have it adjusted to show the right location IS amazing!&lt;/p&gt;
&lt;p&gt;Let us put it like this:&lt;br /&gt;
As a digital nomad and &amp;#8220;never in the own office&amp;#8221; worker, I want this, and I want it NOW!&lt;br /&gt;
Now for Enterprise 2.0:&lt;br /&gt;
adding a SAP Business Process Design tool Gravity to Wave enables cooperative work on new process designs inside the Wave.&lt;br /&gt;
Re-designing processes to adjust changes caused i.e. by Mergers &amp;#038; Acquisitions now becomes easier due to real-time collaboration between subject matter experts. Cool user experience&amp;#8230;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/lkmqFwaRvnc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 14:02:12 +0100</pubDate>
			<title>#SAPTechEd – Original1 against Product Piracy</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/10/27/sapteched-original1-against-product-piracy/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/10/27/sapteched-original1-against-product-piracy/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Again, sorry for bothering you with non-IAM information, but this is heavily interesting for those looking into Business-GRC.&lt;br /&gt;
Jut now, Nokia, SAP and Gieseke+Devrient announced the JointVenture calles Original1, which will offer SaaS solutions for anti-piracy and anti-conterfeiting projects.&lt;br /&gt;
Goal is to enable customs officers, supply-chain service providers and possible whole-sale customers to check and verify if a certain batch or delivery is actually original product or counterfeited merchandise.&lt;br /&gt;
The solution will leverage technology by all three vendors, comprising SAP ERP back-end information, Nokia mobile device extensions for on-site reading/scanning of products and Gi+De technology to secure the process steps and information. The company will be led by Claudia Alsdorf as CEO and will be located in Frankfurt, Germany. As to specific requirements, the solutions will be technology agnostic and available on devices and systems not offered by the contributing parties.&lt;br /&gt;
Target customers will be the brand-owners and vendors of high-value or high-risk products, e.g. luxury goods, pharmaceuticals or the like. &lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/8DmOoHIGmZI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 13:05:10 +0100</pubDate>
			<title>Q &amp; A from the XACML/ABAC Webinar</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/10/27/q-a-from-the-xacmlabac-webinar/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/10/27/q-a-from-the-xacmlabac-webinar/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;On the Webinar that Babak and I did on ABAC and XACML three weeks back, there were quite a few questions that popped up! Unfortunately we did not have time to answer all of them during the webinar, so we promised that we would collect them and answer them afterwards.&lt;/p&gt;
&lt;p&gt;BTW today there is another webinar on a related topic: &lt;a href="http://www.kuppingercole.com/events/n40068"&gt;The Critical Role of XACML in SOA Governance and Perimeter Web Service Security&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Q: Please, specify the major difference between role mining (role consolidation based on role attributes) and the privilege giving mining approach?&lt;/p&gt;
&lt;p&gt;A: (Babak) Role mining is about finding groups of permissions that can be bundled in terms of roles that can then be assigned to users. The idea of privilege-giving attribute mining is to find those attributes that affect permissions and use them to create access rules. Let’s take an example. In a business application, users may have been assigned permissions to Create and Release Purchase Orders, to Maintain Vendor Master data, Release Requisitions, Register Service Entry and Release etc. In a role mining project doing a bottom-up survey of permissions, an analysis of these permissions and how they are grouped into roles will be made. If a role called Purchasing combines all of the above permissions, we would probably identify a Segregation of Duties violation between the rights to Release Purchase Orders and the right to Maintain Vendor Master Data. As a result we would suggest remodeling of the Purchasing role to avoid the conflict. In a top-down approach, Role mining is about identifying a role in business critical processes that will need to be entitled with certain permissions in order to serve its purpose in that process. Role mining projects are typically about top-down and bottom-up combined, which in the end will lead to considerable efforts to map permissions to roles in such a way that everyone is able to do his or her job without acquiring excessive permissions – quite a daunting task.&lt;/p&gt;
&lt;p&gt;An Attribute Mining project would very much like the top-down approach in role mining start with business processes to define which RULES for access can be derived. Examples: Attestation of purchase orders exceeding the amount of $xx, can only be made by users who a) belong to the cost center charged and b) have a management level of 10 or higher. From this rule we can derive that the following attributes are privilege-giving: a) user profile’s cost center assignment, b) users management level, c) purchase orders cost center and d) purchase order’s amount. To verify, these attributes would allow a rule to be formalized like this: If user.costcenter = purchaseorder.costcenter and user.managementlevel&amp;gt;=10 and purchase.amount&amp;lt;=$xx then permit else deny.&lt;/p&gt;
&lt;p&gt;Q: Tell me more / define better what you mean when you talk about a missing context of the RBACs model?&lt;/p&gt;
&lt;p&gt;A: (Babak) What we argue is that RBAC is a static model which makes it difficult to capture the context that may affect an access decision.  If we try to capture the context for an access in terms of roles then we will easily get a role explosion. We may for instance need to differentiate permissions depending on time of day – some users have access only during normal business hours whereas others have 7*24 access. This could lead to the creation of two roles, one for normal business hours, one for extended access. Add other context-related conditions such as remote login, authentication strength, line encryption etc. and we end up with the need to capture very many different roles. It is worth noting that normal ERP systems typically need to handle very large numbers of roles (thousands) internally to capture all their user permissions. If a combined role structure from multiple ERP systems must be established with contextual aspects included, role explosion issues simply become unmanageable.&lt;/p&gt;
&lt;p&gt;Q:  I didn&amp;#8217;t quite get the difference between attribute based access control and rule based access control. can you elaborate?&lt;/p&gt;
&lt;p&gt;A: (Felix) In a nutshell, the main difference between ABAC and RBAC is that RBAC revolves around the concept of the role. ABAC can use any attributes (including the role) so it is much more flexible.&lt;/p&gt;
&lt;p&gt;A:  (Babak) Attribute based access control is not in conflict with rule based access control. Rule based access control is about creating rules defining access permissions, but if these rules are based on attributes then we have a type of attribute-based access control.&lt;/p&gt;
&lt;p&gt;Q: I understood there exists a better way in comparison to the RBAC model, but a language is not enough at all. You need a product which combines both. Is this the message you want to send out here?&lt;/p&gt;
&lt;p&gt;A: (Babak) Well, the purpose of the workshop is to present the concept of ABAC and how it solves some of the common and well-known issues with RBAC. But you are right that we also need products to support this new approach. Axiomatics has a complete product suite to support xacml policy life cycle management 360. Most vendors of business applications and IAM products also have more or less elaborate support for XACML built-in.&lt;/p&gt;
&lt;p&gt;Q: Is there a defined migration path from an established RBAC model to an ABAC model?&lt;/p&gt;
&lt;p&gt;A: The OASIS XACML committee has released an XACML Profile for Role Based Access Control (RBAC) which can be used as a basis for migration projects. That said, one naturally needs to be aware of the constraints given by the architecture of legacy systems – “converting” an existing RBAC-based business application to an ABAC-based model may require a considerable effort. In some instances it may be more attractive to implement connectors that can provision attribute-based rules from a Policy Administration Point to application specific rule configurations which in turn may be RBAC based.&lt;/p&gt;
&lt;p&gt;Q: How do you manage attribute based access to multiple resource? Traditionally, privilege attributes are bundled into roles and are assigned to users. If you have many attributes that control access to resources, doesn&amp;#8217;t that increase administrative burden?&lt;/p&gt;
&lt;p&gt;A: No, as we said in the presentation it will most likely be much less number of attributes needed to define access permissions than the number of roles. This is because we will define access rules based on the attributes rather than representing different set of permissions in terms of roles.&lt;/p&gt;
&lt;p&gt;Q: Sounds like this method will have significant application impact &amp;#8211; can you respond to this concern?&lt;/p&gt;
&lt;p&gt;A: Yes, we believe that many applications will in the future implement the XACML request-response protocol. Already today, most large vendors of Identity &amp;amp; Access Management products or applications that handle business critical data have some sort of “XACML story”.&lt;/p&gt;
&lt;p&gt;Q: Does ABAC related to Claim Based Authentication? Are they like corresponding concepts?&lt;/p&gt;
&lt;p&gt;A: (Babak) Yes, one way to see claims is as provisioning of attributes to the access control system, so these are definitely complementary technologies.&lt;/p&gt;
&lt;p&gt;A: (Felix) Authentication and authorisation are two different concepts, but of course they are related: authentication tells us who the user is, and then authorisation tells us whether the user is allowed to do something. The concept of Claim-based authentication is based on the fact that a &amp;#8220;Claim&amp;#8221; will already deliver attributes to an application. What happens then? These attributes could be made available to the authorisation engine.&lt;/p&gt;
&lt;p&gt;Q: Are there any good resources and real world examples to get started with ABAC?&lt;/p&gt;
&lt;p&gt;A:  (Babak) Well a good place to start with is the XACML TC page. Axiomatics has also a very informative website (&lt;a href="http://www.axiomatics.com/"&gt;www.axiomatics.com&lt;/a&gt;) with all introductory information regarding ABAC and XACML.&lt;/p&gt;
&lt;p&gt;A: (Felix) We also have recently released a &lt;a href="http://www.kuppingercole.com/report/fg_xacml_report"&gt;XACML Technology report&lt;/a&gt; that is available from our web site.&lt;/p&gt;
&lt;p&gt;Q: RBAC seems after implementation quite static in maintenance ABAC seems intensive in maintenance, since attribute values vary over time (daily, hourly etc) would it not make maintenance costs more expensive and more complex?&lt;/p&gt;
&lt;p&gt;A: (Babak) Well this is really the other way around. The idea is not to change the time attribute manually but to fetch the data from the right attribute source which is perhaps a clock.&lt;/p&gt;
&lt;p&gt;A: (Felix) To add to Babak&amp;#8217;s point there: ABAC will make use of information that already exists in an enterprise. The initial maintenance cost would be to deliver those attributes to the policy decision engine. And for that, good technology such as virtual directories already exist.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/T9ZQtXDECQs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 12:14:32 +0100</pubDate>
			<title>#sapteched: too much twittering.. ;-) – but not enough on IAM &amp; GRC</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/10/27/sapteched-too-much-twittering-but-not-enough-on-iam-grc/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/10/27/sapteched-too-much-twittering-but-not-enough-on-iam-grc/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Did you find yourself adding hash-tags in emails or &amp;#8220;old-fashioned&amp;#8221; blog posts recently?&lt;br /&gt;
Well, I think we are all tweeting quite a lot (except for me, I do not spend to much time on it) and organizing tweets that way is a good thing, for sure&amp;#8230;&lt;/p&gt;
&lt;p&gt;In between two Netweaver security tracks I just wanted to give you an update on the cool show, SAP put together once again! I already met so many friends and colleagues and usual suspects, I almost felt like visiting EIC &lt;img src='http://blogs.kuppingercole.com/rohr/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /&gt;  in Munich.&lt;br /&gt;
Novell made some great announcements recently and &amp;#8211; to no surprise for me &amp;#8211; their now combined SAP/Novell offering for end-to-end GRC does add a lot of value for customers of both companies.&lt;br /&gt;
Just a few weeks ago, doing an invited talk at the SAP Partner Port in Waldorf with Loren Heilig, Managing Director of IBSolutions, I claimed that SAP does have a big advantage when it comes to Business GRC, while they really lack the depth needed to control everything down to the system-level, aka &amp;#8220;more technically&amp;#8221;. As a complimentary solution vendor, I showed some Novell slides, and the reactions were pretty &amp;#8230; ambigious.&lt;br /&gt;
While the customer audience seemed to like the idea, the vendor representatives seemed a bit uncomfortable. Today, I find my self to be proven by reality &amp;#8211; my own little &amp;#8220;analyst crystal ball&amp;#8221; only had a &amp;#8220;warning period&amp;#8221; of roughly 4 month, though. Maybe I should get to London and place some bets, before making my next presentations&amp;#8230;&lt;br /&gt;
SAP and Novell: congratulations! You now offer the most complete GRC approach in the market today (at least from my humble perspective!)&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/U4RGOWfk324" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 11:56:14 +0100</pubDate>
			<title>08.12.2009: The Three Elements of Access Governance: Recertification/Attestation  Access Control  Privileged Access Management</title> 
			<link>http://www.kuppingercole.com/events/n40069</link> 
			<guid>http://www.kuppingercole.com/events/n40069</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Access Governance is commonly associated with recertification or attestation as approaches for a recurring review of existing access controls by the responsible managers in IT and business. But knowing the problems isnt sufficient  enforcing changes and implementing continuous processes for access controls is a key element. And, beyond that, many approaches mainly focus on standard access and not on the security sensitive privileged accounts. This session explains the elements for a...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40069"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/GwwHIAkLVm8" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 27 Oct 2009 00:00:00 +0100</pubDate>
			<title>The Critical Role of XACML in SOA Governance and Perimeter Web Service Security</title> 
			<link>http://www.kuppingercole.com/podcasts/xacml_in_soa_governance_and_perimeter_web_service_security.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/xacml_in_soa_governance_and_perimeter_web_service_security.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; SOA is far from dead but many organizations suffer from a severe SOA disease caused by too many enthusiastic deployments of isolated and siloed services. In this webinar, Martin Kuppinger will provide you with insights on SOA Governance, followed by Axiomatics and Intel showcasing their joint SOA security solution.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/xacml_in_soa_governance_and_perimeter_web_service_security.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/JcuXlj71Hso" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 25 Oct 2009 12:43:01 +0100</pubDate>
			<title>Windows 7 and SmartCard removal behaviour… no system lock?</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/10/25/windows-7-and-smartcard-removal-behaviour-no-system-lock/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/10/25/windows-7-and-smartcard-removal-behaviour-no-system-lock/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Ok, this should be a blog about insights to the general Identity &amp;#038; Access Management and Governance, Risk Management &amp;#038; Compliance Markets. Sorry to bother you guys with technology details (like the one about Win7 and 3G(UMTS) on netbooks, every once in a while, but I think one blog is enough to maintain and publish stuff to ;- )&lt;br /&gt;
So, who ever started using Win 7 in a secure environment may have come across the issue that smartcard log-in works like a breeze in these days, but you may be as puzzled as I was, when I pulled the card from the reader and the system did NOT lock itself&amp;#8230;&lt;br /&gt;
Well, as my friend Walter Hofer of IDpendant was kind enough to investigate the issue (and let me know right after he found out):&lt;br /&gt;
Even with a corresponding GPO in the AD set, Win 7 will refuse to lock the computer after the smartcard has been removed from the reader as Microsoft chose to create a new system service called Smartcard Removal Policy &amp;#8211; and it is set to MANUAL. Unless you look that service up in the &amp;#8220;Services&amp;#8221; menu and change its start behaviour to &amp;#8220;Auto&amp;#8221;, you will not get the expected results&amp;#8212;&lt;br /&gt;
Just to get you a faster solution if this should occur to you, too!&lt;br /&gt;
Keep up the safe&amp;#038;secure computinge experience!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/XgSKYzw5llU" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 25 Oct 2009 12:31:54 +0100</pubDate>
			<title>Vienna Calling</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/10/25/vienna-calling/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/10/25/vienna-calling/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Well, unlike Falco in his famous hit single, this time it is SAP, who´s calling the worlds´ERP elite to Austrias capital next week &amp;#8211; and I am happy enough to participate in this one-in-a-thousand events that really stand out. My very high expectations regarding the expertise I am planning to meet is only paralleled by the curiousity if (and if yes, who) there is gonna be a star like Zucchero performing as part of the event &lt;img src='http://blogs.kuppingercole.com/rohr/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /&gt;&lt;br /&gt;
Ok, back to the real issues, because there is lot of work to be done while I am at the event. First of all, I will try to get as much in-depth technology insight as possible and my agenda is bustling with activity around Netweaver Identity Management and SAP security. Especially the second, more general topic has some relevance as I am looking into the SAP and 3rd party audit and compliance solutions available today. Besides SAP´s own offering in the GRC arena, I am about to dive deeper into CheckAud of ibs Schreiber, a tool I came across in several Master´s thesis I have been advisor for. Next is &amp;#8220;mesaforte&amp;#8221; of Swiss Wikima4 AG and last not least the SAST System Audit and Security Toolkit, of Akquinet, especially since they now co-operate with my valued friends at Virtual Forge (some of my former Fraunhofer SIT colleagues are the founders).&lt;br /&gt;
Do you have expertise in one of those? Are you at TechEd in Vienna? Make sure to meet me over a cup of coffee or a Stiegl Bräu beer!&lt;br /&gt;
Looking forward to meet you in Vienna!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/UuGRav1P2PA" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 23 Oct 2009 00:00:00 +0200</pubDate>
			<title>Ein Passwort für alles - Enterprise Single Sign-on</title> 
			<link>http://www.kuppingercole.com/podcasts/ein_passwort_fuer_alles_enterprise_sso.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/ein_passwort_fuer_alles_enterprise_sso.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Es gibt kaum einen Anwender, der nicht schon einmal sein Passwort vergessen hat und das Helpdesk mit einem Passwort Reset beschäftigen musste. Die Arbeit des Helpdesk nimmt exponentiell zu, wenn die Anwender sich mehrere unterschiedliche Passwörter für unterschiedliche Anwendungen merken müssen, die auch noch mit unterschiedlichen Intervallen geändert werden müssen. Projekte, die sich der Vereinfachung der Authentifizierungsprozesse annehmen, sind  deshalb im Unternehmen sehr sichtbar, und ei...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/ein_passwort_fuer_alles_enterprise_sso.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/EB0s448BZ-E" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 22 Oct 2009 09:28:31 +0200</pubDate>
			<title>Social networks could be secure!</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/10/22/social-networks-could-be-secure/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/10/22/social-networks-could-be-secure/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Yesterday, I read an &lt;a title="Article on social network security" href="http://www.n-tv.de/technik/Crawler-greifen-alles-ab-article555109.html" target="_blank"&gt;article&lt;/a&gt; at a German news web-site about the recent security leaks found in the social network SchülerVZ. The article claims that social networks like SchülerVZ and Facebook (both are mentioned) don&amp;#8217;t have any chance to avoid crawlers accesing personal data which should be presented only to friends. &lt;strong&gt;Ridiculous!!!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Sorry, that is definitely nonsense!&lt;/p&gt;
&lt;p&gt;It is very simple. You have some data which is visible only to some specific persons. You have an authorization policy, which might be expressed in the form of ACLs or XACML or whatever. Some application (the regular frontend, a crawler, an administrative application,&amp;#8230;) tries to access data. You have done an authentication. You do the authorization by comparing the authentication information to the authorization information. You decide on whether access is allowed or not. That is done in millions of applications day-by-day. And that shouldn&amp;#8217;t work with social network sites? I don&amp;#8217;t see any real reason why!&lt;/p&gt;
&lt;p&gt;For sure there are two reasons why at least some social networks don&amp;#8217;t do that in this way:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Bad software architecture: Security has to be done by design, from the very beginning. Otherwise it is hard to implement it. Unfortunately, many developers don&amp;#8217;t design security in their products but add it at the end, as something painful they have to do at the minimum level.&lt;/li&gt;
&lt;li&gt;Performance considerations: For sure security will affect performance. For any access, you will have to do security checks. You will even have to provide stronger authentication features. But it can be done. Providers will probably require some more hardware to keep the performance level of their social networks. But security has its price.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But to be honest: These aren&amp;#8217;t valid reasons. Either you are able to deploy a social network in a secure way and fulfill the data protection laws. Or you should shut the entire thing down. Given that it is possible to secure social networks, the operators should be fully responsible for any security breach.&lt;/p&gt;
&lt;p&gt;By the way: Even the databases themselves can be fully secured. That depends a little on the database chosen and the additional technologies in place, like Oracle&amp;#8217;s Database Security products (to mention one of the more advanced solutions). OK, that will again cost you some performance and some money. But again it is about &amp;#8220;security first&amp;#8221;. If the providers of social networks can&amp;#8217;t afford the cost of security, their business model just doesn&amp;#8217;t work.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/-VUodWAEWVM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 22 Oct 2009 09:14:22 +0200</pubDate>
			<title>XACML – why it is so important</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/10/22/xacml-why-it-is-so-important/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/10/22/xacml-why-it-is-so-important/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;XACML (eXtensible Access Control Markup Language) gains an increasing attention as one of the core standards in the field of information security and thus IT security. Whilst standards like SAML (Security Assertion Markup Language) address the problem of authentication, XACML is about authorization &amp;#8211; the more complex threat. XACML allows the definition and exchange of authorization policies in a heterogeneous environment. Whether it is about cloud security and controlling the authorization policies of cloud services or about SOA security for internal applications: XACML supports the authorization management in such use cases.&lt;/p&gt;
&lt;p&gt;However, there is no such thing as a free lunch: XACML not only tools like XML/SOA Security Gateways which support that standard or cloud services with XACML support. There are two other important aspects:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;XACML in fact means a shift from a more static security approach like with ACLs (Access Control Lists) towards a dynamic approach, based on policies which are applied at runtime. These dynamic security concepts are more difficult to understand, to recertify, to audit and analyze in their real-world implications. Thus, the use of XACML requires not only the right tools but well-thought concepts for policy creation and management.&lt;/li&gt;
&lt;li&gt;XACML is just a foundation to express policies. Within a use case, policy concepts have to be defined. Over time, there should be higher level standards or defined use cases building on XACML and focusing on a standardization of the content of these policies.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Anyway, XACML is very useful. One of the most interesting areas for XACML is SOA Security. Currently, many SOA-based applications still lack a valid concept for authorization. Authorization still frequently is built into these applications. XACML can provide the policies to externalize the authorization management and thus add flexibility to SOA-based applications.&lt;/p&gt;
&lt;p&gt;Overall, it is &amp;#8211; from my perspective &amp;#8211; definitely worth to spend some time exploiting the potentials for XACML to improve the security of systems and applications. There are many areas where XACML can be used successfully today. However, like with any emerging technology, there will be a lot of improvements in the managing and consuming applications (and, hopefully, around the standards ore use cases building on XACML) over the next few years. Thus the step to XACML has to be considered carefully. The good thing is: It is about standards, thus the risk of lock-in isn&amp;#8217;t that big.&lt;/p&gt;
&lt;p&gt;We will talk more on depth in an upcoming &lt;a title="Kuppinger Cole Webinar" href="http://www.kuppingercole.com/events/n40068" target="_blank"&gt;webinar. Register for free!&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/1Spti6kDe9I" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 21 Oct 2009 14:37:59 +0200</pubDate>
			<title>Show me your terrorists!</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/10/21/show-me-your-terrorists/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/10/21/show-me-your-terrorists/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;How many terrorists work for your company? Dunno? Well, see you in jail, pal!&lt;/p&gt;
&lt;p&gt;I just came back from a meeting of the German chapter of IAPP, the International Association of Privacy Professionals, and the words of the chairman, Dr. Jyn Schultze-Melling, a lawyer with the firm Nörr, Stiefenhofer &amp;amp; Lutz, still ring in my ears: &amp;#8220;We are sacrificing employee privacy on the altar of anti-terrorism.&amp;#8221;&lt;/p&gt;
&lt;p&gt;It turns out that firms are required by law to check their employees names against lists of terrorism suspects published by the United Nations and the European Union. In Germany, §34 of AWG, the Foreign Trade Law, forbids companies aiding or abetting persons or organizations that endanger national security or the &amp;#8220;peaceful coexistence of peoples&amp;#8221; in any way &amp;#8211; like for instance paying them a salary. Failure to comply with this law carries heavy fines; up to 5 years in jail for the CEO, for instance.&lt;/p&gt;
&lt;p&gt;On the other hand, European data privacy laws prohibit routine scanning of personal data without due cause. So if nobody has done anything suspicious lately, running their names past the UN or EU lists is probably illegal in many countries.&lt;/p&gt;
&lt;p&gt;Of course, tell that to the families after some nut explodes a vest of dynamite in your company canteen and slaughters a few of your employees.&lt;/p&gt;
&lt;p&gt;So yes, companies have to screen their own people, but when exactly? On hiring? What if the employee has a change of heart two or three years later and signs up for the Muslim Brotherhood? Does that mean you have to scan periodically, maybe once or twice a year? And if you live in a country like Germany where the works committee has a big say in these matters, how do you ever hope to convince them?&lt;/p&gt;
&lt;p&gt;According to Schultze-Melling, there are loads of even more mundane problems to consider. For instance, Osama Bin Laden would hardly use his real name when joining your company, and probably not even one of the score or so aka’s he is also listed under in the UN list, but would chose an entirely new name instead. How about different spellings? After all, for an Arab speaker, Ahmed Gamdi, Ahmad Al Gamdi, Ahmet Gamdi, and Ahmed Al-gamdi could very well be one and the same guy. There are more than 32 spelling for Lybia&amp;#8217;s Colonel Gaddafi (or Qadhafi, Kadafi, Gadhafi, Qaddafi, etc.). Are you legally required to check them all?&lt;/p&gt;
&lt;p&gt;As ist that wasn&amp;#8217;t bad enough, you can try telling it the cops who come to arrest your boss because one of your employees gave to the local chapter of the Holy Land Foundation which funds Hamas or the National Development Front in India that finances Al-Qaeda. The UN and the EU, not to mention the US Department, publish lists of organizations they consider to be affiliates or fund raisers for international terrorists. Unfortunately, hardly any new employee mentions this in his hiring questionnaire, so what should you do? Periodically ask all your people whether they have joined a terrorist organization lately? Maybe hand them the list and ask them to make appropriate check marks. And what if they refuse &amp;#8212; do you fire them? Anyway, answering in the affirmative could constitute an act of self-incrimination, so requiring it would itself be  illegal in most civilized countries.&lt;/p&gt;
&lt;p&gt;Until now, most HR departments have dealt with these questions in the handiest possible way &amp;#8211; by ignoring them. Out of about 20 companies represented at the IAPP meeting, among them a few on the Fortune 100 list, only two raised their hands when I asked who has ever conducted a scan for terrorist suspects within their organizations.&lt;/p&gt;
&lt;p&gt;My feeling is that this illustrates the legislative confusion surrounding identity and privacy on the governmental level, but it also points out some tough questions that need to be answered by identity pros before we can hope to achieve anything like a balanced approach to the legitimate concerns of citizens, employees and consumers about how authorities and employers handle their personal data on the one hand, and the requirements of businesses, bureaucracies and, yes, terrorism fighters on the other.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/mDnu2iJlemk" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 19 Oct 2009 14:51:22 +0200</pubDate>
			<title>Martin Kuppinger: How to fight GRC Anarchy</title> 
			<link>http://www.kuppingercole.com/articles/mk_grc_anarchy191009</link> 
			<guid>http://www.kuppingercole.com/articles/mk_grc_anarchy191009</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; GRC (Governance, Risk Management, Compliance) has become a leading issue not only for IT professionals, but for senior management as well. However, it isnt always clear whos in charge. Responsibility for GRC is set to become a major issue in the coming months..&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/articles/mk_grc_anarchy191009"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/1J63OjdeaEU" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 16 Oct 2009 12:16:19 +0200</pubDate>
			<title>27.10.2009: The Critical Role of XACML in SOA Governance and Perimeter Web Service Security</title> 
			<link>http://www.kuppingercole.com/events/n40068</link> 
			<guid>http://www.kuppingercole.com/events/n40068</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; SOA is far from dead but many organizations suffer from a severe SOA disease caused by too many enthusiastic deployments of isolated and siloed services. In this webinar, Martin Kuppinger will provide you with insights on SOA Governance, followed by Axiomatics and Intel showcasing their joint SOA security solution.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40068"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/zk-fobJQbQg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 16 Oct 2009 11:02:42 +0200</pubDate>
			<title>19.11.2009: Pass Your Next Compliance Audit With Confidence</title> 
			<link>http://www.kuppingercole.com/events/n40066</link> 
			<guid>http://www.kuppingercole.com/events/n40066</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Bottom-Up or Top-Down or both? What is the appropriate approach to automate auditing on access and reporting on directories and identities and also on mail and file access? In This Webinar, Martin Kuppinger (Kuppinger Cole), Jackson Shaw and Reto Bachmann (both Quest Software) will discuss with you these questions and talk about best practices on how to integrate IT- and business views.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40066"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/WWHFJ0VbL0s" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 15 Oct 2009 15:18:03 +0200</pubDate>
			<title>11.11.2009: Single Sign-on for SAP Environments</title> 
			<link>http://www.kuppingercole.com/events/n40065</link> 
			<guid>http://www.kuppingercole.com/events/n40065</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; The identity management marketplace offers a number of different solutions enabling Active Directory-based single sign-on for SAP, making life for SAP endusers much easier and at the same time offering a good potential to reduce the costs of managing your IT infrastructure. In this webinar, Martin Kuppinger (Kuppinger Cole), will talk about the different concepts of SAP-SSO and why Kerberos is a real option in such an environment. Then, Jackson Shaw and Reto Bachmann (Quest Software) will...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40065"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/nOVPm7AED7E" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 14 Oct 2009 07:53:50 +0200</pubDate>
			<title>Another approach to IRM</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/10/14/another-approach-to-irm/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/10/14/another-approach-to-irm/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Last week I had a discussion with &lt;a title="Seclore" href="http://www.seclore.com" target="_blank"&gt;Seclore&lt;/a&gt;, a software company based in Mumbai, India. They are focusing on the area of Information Rights Management (IRM), one of my favourite research areas. I&amp;#8217;m interested in this topic mainly for two reasons:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Information Rights Management is one of the IT topics with the closest relation to the core business topic of Information Security/Protection (including Intellectual Property Rights, IPRs).&lt;/li&gt;
&lt;li&gt;Information Rights Management is the approach which allows the ongoing protection of information at rest, in move and in use &amp;#8211; compared to many other approaches which cover only one of these phases.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Most solutions in that market are based on plug-ins into existing applications which enforce the IRM policies. The policies are managed centrally, information (documents) are protected by encryption.&lt;/p&gt;
&lt;p&gt;Seclore&amp;#8217;s approach is different in that they not mandatorily rely on such plug-ins but mainly act &amp;#8220;below&amp;#8221; the application. The client component (which is required to access protected, e.g. encrypted, documents) tries to analyze the activities off the application like access to the file system. One impact of that approach is that a document might be opened with different applications supporting the specific document format.&lt;/p&gt;
&lt;p&gt;Even while I personally believe that implementing IRM functionality within the applications (the more common approach of vendors like Microsoft, Adobe and Oracle) allows a tighter control about the actions of a user and application on a document, the Seclore approach has some appeal. It is lightweight and works well today with different applications and in different environments, beyond the enterprise. As long as there is no common standard for the interactions of applications (the policy enforcement points) and the IRM backend systems across different vendors, this is a workaround. And once there is such a standard, Seclore is very likely to support it. Thus, not only looking at the big vendors but as well at Seclore makes sense in these early days of Information Rights Management.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/cVj7YYlvH7Y" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 14 Oct 2009 00:00:00 +0200</pubDate>
			<title>The Role of Entitlement Management in Governance, Risk and Compliance Management</title> 
			<link>http://www.kuppingercole.com/podcasts/entitlement_management_in_grc_management.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/entitlement_management_in_grc_management.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Modern IT infrastructures empower their users and thereby introduce new risks. The effectiveness and efficiency of control frameworks and GRC programs are therefore becoming an increasingly important focus area for IT and business managers alike. Yet, GRC initiatives tend to be reactive, striving to optimize monitoring, surveillance and auditing capabilities and the GRC overhead keeps growing. Instead we need risk-intelligence built into our IT-infrastructures. This is what Entitlement Manage...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/entitlement_management_in_grc_management.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/XaYbWLall4g" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 12 Oct 2009 00:00:00 +0200</pubDate>
			<title>Sicherheit mit automatisiertem Provisioning</title> 
			<link>http://www.kuppingercole.com/podcasts/sicherheit_mit_automatisiertem_provisioning.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/sicherheit_mit_automatisiertem_provisioning.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Nicht nur in grossen Unternehmen ist die Benutzerverwaltung durch ständige Änderungen und Ergänzungen eine ressourcenzehrende Herausforderung. Auch wenn die Prozesse für die Provisionierung von Benutzerkonten in den unterschiedlichen Anwendungen sauber definiert sind - manuelles Arbeiten birgt enorme Sicherheitsrisiken beispielsweise in Form verwaister Benutzerkonten. In diesem Webinar sprechen wir über die Möglichkeiten, diese Sicherheitsrisiken durch automatisiertes Provisioning zu minimieren.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/sicherheit_mit_automatisiertem_provisioning.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/WQXk6HP-YFg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 07 Oct 2009 09:35:01 +0200</pubDate>
			<title>Integration for the cloud</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/10/07/integration-for-the-cloud/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/10/07/integration-for-the-cloud/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;On Monday I&amp;#8217;ve met with Matthieu Hug from &lt;a title="RunMyProcess" href="http://www.runmyprocess.com" target="_blank"&gt;RunMyProcess&lt;/a&gt; in Paris, an interesting start-up company in the &amp;#8220;cloud&amp;#8221;. Their focus is pretty easy: Integrate the cloud &amp;#8211; with what you have internally and with other cloud services. At CeBIT 2008 I&amp;#8217;ve done a presentation about &amp;#8220;SaaS&amp;#8221; and related topics (we didn&amp;#8217;t use the term &amp;#8220;cloud&amp;#8221; at that point of time). One of the three major issues I&amp;#8217;ve discussed as threats in that area (and would mention nowadays as cloud threats) is integration. How do you integrate external cloud services with other external services or internal applications? Some of these services provide a set of web service interfaces. But even then, integration is a tough work.&lt;/p&gt;
&lt;p&gt;RunMyProcess now provides an external &amp;#8220;cloud&amp;#8221; service to do that integration. They provide pre-configured web services of a series of (external) cloud service providers, including Salesforce.com, SAP BusinessByDesign, and GoogleApps. And they allow to define processes which include one or more of these products. That allows to build integration between such services and existing internal applications. It as well allows to enhance cloud based services like GoogleApps. Matthieu told me that some of his customers are adding workflows to GoogleApps to replace Lotus Notes (even while I&amp;#8217;d recommend the customer to consider LotusLive as an option in that case&amp;#8230;). And there are some companies starting to create added-value services by integrating and enhancing cloud services, creating sort of &amp;#8220;industry clouds&amp;#8221; or &amp;#8220;community clouds&amp;#8221;.&lt;/p&gt;
&lt;p&gt;I like the approach of providing an integration platform in that way. It doesn&amp;#8217;t solve every problem (and more complex platforms built on top of classical application servers might provide some more functionality) but it is an answer to one of the biggest threats in the cloud. Thus it is definitely worth to have a look at that solution. And it is just another example of the amount of creativity unveiled by the cloud evolution.&lt;/p&gt;
&lt;p&gt;If you want to learn more about the cloud, you definitely should attend &lt;a title="Cloud 09" href="http://www.id-conf.com/cc09" target="_blank"&gt;Cloud 09&lt;/a&gt;, Dec 2nd-4th, Munich. And you should always have a look at the &lt;a title="Kuppinger Cole Webinars" href="http://www.kuppingercole.com/eventformats/webinar" target="_blank"&gt;Kuppinger Cole webinars&lt;/a&gt;. We do webinars on cloud topics frequently &amp;#8211; and there are many recordings of cloud webinars available.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/Ok3dEaJNCfI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 07 Oct 2009 00:00:00 +0200</pubDate>
			<title>Product Report: Quest Single Sign-On solutions for SAP</title> 
			<link>http://www.kuppingercole.com/report/pr_questsso_sap071009</link> 
			<guid>http://www.kuppingercole.com/report/pr_questsso_sap071009</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Mit den beiden Produkten Quest Single Sign-On for SAP GUI and ABAP und Quest Single Sign-On for NetWeaver bietet Quest eine marktf&amp;uuml;hrende L&amp;ouml;sung f&amp;uuml;r das Single Sign-On zwischen Active Directory-Infrastrukturen und SAP-Umgebungen auf Basis von Kerberos an. Als Option f&amp;uuml;r Infrastrukturen, in denen man keine Kerberos-basierende L&amp;ouml;sung einsetzen m&amp;ouml;chte, gibt es zudem noch Quest Enterprise Single Sign-On, eine klassische Enterprise Single Sign-On-L&amp;ouml;sung. &lt;p&gt;Der...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/report/pr_questsso_sap071009"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/aYuD_Vle_mo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 06 Oct 2009 18:55:05 +0200</pubDate>
			<title>Sebastian Rohr: Identity Management: Challenge Outsourcing</title> 
			<link>http://www.kuppingercole.com/articles/sr_outsourcing_061009</link> 
			<guid>http://www.kuppingercole.com/articles/sr_outsourcing_061009</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Outsourcing and offshoring are a fact of life in many companies, but for some, when it comes to managing user identities and access rights or enforcing rules on governance, risk management and compliance, these are still very early days indeed.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/articles/sr_outsourcing_061009"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/cYn91DPnL08" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 05 Oct 2009 00:00:00 +0200</pubDate>
			<title>Overview Report: A GRC Reference Architecture</title> 
			<link>http://www.kuppingercole.com/report/sp_overview_repo_grc_arch_051009</link> 
			<guid>http://www.kuppingercole.com/report/sp_overview_repo_grc_arch_051009</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Governance, Risk &amp;amp; Compliance - these three terms, in short &amp;quot;GRC&amp;quot; are pretty widely used in these days. Unfortunately, there is great confusion in how this term is used. The reason for this confusion is with high probability the fact that it allows to sell pretty easily all kind of technology under the umbrella of &amp;quot;Risk&amp;quot; and &amp;quot;Compliance&amp;quot; solutions. But there are very precise areas that GRC should cover, and other that it shouldn't, for example...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/report/sp_overview_repo_grc_arch_051009"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/RN-LUFe3Soc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 01 Oct 2009 13:25:20 +0200</pubDate>
			<title>Martin Kuppinger: GRC  a heavily segmented market</title> 
			<link>http://www.kuppingercole.com/articles/mk_grc_heavily_segmark011009</link> 
			<guid>http://www.kuppingercole.com/articles/mk_grc_heavily_segmark011009</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; GRC  Governance, Risk Management, Compliance. A typical buzzword, but well established right now. However, the problem of all emerging markets associated with a buzzword arises here as well: There are many different vendors with different types of offerings, all claiming to solve the GRC problem. But: The GRC problem has many facets and is (beyond we have to manage risk, we have to be compliant) largely undefined. Well publish a report these days on a GRC reference architecture followed...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/articles/mk_grc_heavily_segmark011009"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/JZe5Rmi6Rq8" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 01 Oct 2009 12:00:29 +0200</pubDate>
			<title>GRC – a heavily segmented market</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/10/01/grc-a-heavily-segmented-market/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/10/01/grc-a-heavily-segmented-market/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;GRC &amp;#8211; Governance, Risk Management, Compliance. A typical buzzword, but well established right now. However, the problem of all emerging markets associated with a buzzword arises here as well: There are many different vendors with different types of offerings, all claiming to solve the GRC problem. But: The GRC problem has many facets and is (beyond &amp;#8220;we have to manage risk, we have to be compliant&amp;#8221;) largely undefined. We&amp;#8217;ll publish a report these days on a GRC reference architecture followed by, probably in early November, a market segmentation report, placing vendors in one or more appropriate segments. Like every valid and successful emerging market, GRC will move from a large set of different solutions towards a market with some well defined segments of vendors.&lt;/p&gt;
&lt;p&gt;There are the so called &amp;#8220;Enterprise GRC&amp;#8221; vendors like Mega, OpenPages, or Bwise. But even between these there are significant differences. There are vendors working more at the level of CCM (Continuous Controls Monitoring), including companies like Approva. There are IAM-GRC vendors like Aveksa, BHOLD, Engiweb, Sailpoint, and several others. There are IAM solutions with added GRC capabilities &amp;#8211; in the meanthime most of them. There is GRC support in BSM (Business Service Management) applications. And, and, and&amp;#8230; I don&amp;#8217;t want to unveil to much from the upcoming reports which you will find at our &lt;a title="Kuppinger Cole Reports" href="http://www.kuppingercole.com/reports" target="_blank"&gt;website&lt;/a&gt; but like to focus on another aspect:&lt;/p&gt;
&lt;p&gt;Which GRC approach to choose?&lt;/p&gt;
&lt;p&gt;First of all, I believe that we have to use the potential of GRC for better interfacing Business and IT. There are business controls, there are IT controls. These have to be mapped. Thus, we should end with solutions which support as well the business as the IT requirements. That will never ever be a single solution, but a combination of some. High level controls and dashboards, CCM approaches and more specific solutions for different groups of IT controls. It should as well be an approach which isn&amp;#8217;t only &amp;#8220;detective&amp;#8221; or, more correct, &amp;#8220;reactive&amp;#8221; but finds the balance between proactive/preventive and reactive/detective.&lt;/p&gt;
&lt;p&gt;The big picture is relatively easy to describe, like we have done in our reference architecture.&lt;/p&gt;
&lt;p&gt;The way towards that is much more difficult. There are many influencing factors like the industry and size of the organization, the current organizational structure (especially around the responsibility for GRC issues), the process maturity of the organization, the maturity of IT management approaches, and so on. Thus there can be different (and more than one) starting points. But in any case, there should be a well agreed (but coarsely described) &amp;#8220;big picture&amp;#8221;, as the guideline for building a GRC roadmap.&lt;/p&gt;
&lt;p&gt;I personally believe that three factors are most important:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Providing quick wins&lt;/li&gt;
&lt;li&gt;Providing a business view which, from the beginning, starts in integrating with IT &amp;#8211; only manual controls are&amp;#8217;t sufficient, it is always about the appropriate mix of manual and automated controls&lt;/li&gt;
&lt;li&gt;Closing the loop &amp;#8211; don&amp;#8217;t focus only on the reactive part (like with pure &amp;#8220;access certification&amp;#8221;) but start acting on the results, for example by integrating provisioning to fix the detected problems&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These are some of the most important criteria to choose solutions in the GRC space.&lt;/p&gt;
&lt;p&gt;Have a look at our &lt;a title="Kuppinger Cole Events" href="http://www.kuppingercole.com/events" target="_blank"&gt;event website&lt;/a&gt; for upcoming events and webinars around GRC.&lt;/p&gt;
&lt;p&gt;And, for sure, don&amp;#8217;t hesitate to ask for our advice on building your GRC &amp;#8220;big picture&amp;#8221;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/5dnw3-P2ztE" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 30 Sep 2009 00:00:00 +0200</pubDate>
			<title>Beyond Role Based Access Control - the ABAC approach</title> 
			<link>http://www.kuppingercole.com/podcasts/beyond_role_based_access_control_the_abac_approach.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/beyond_role_based_access_control_the_abac_approach.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In this webinar we discuss the original ideas behind RBAC and why large RBAC projects often lead to role explosion  problems and therefore 
fail in their initial ambitions. We also introduce the concept of Attribute Based Access Control (ABAC) which overcomes some of the well-known problems with RBAC and enables a fine-grained and contextual (adaptive) access control. ABAC meets the requirements of modern 
IT-infrastructures where dynamically changing needs must be captured and dealt with i...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/beyond_role_based_access_control_the_abac_approach.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/CJoc0iWEAgQ" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 29 Sep 2009 00:00:00 +0200</pubDate>
			<title>Technology Report: XACML  Extensible Access Control Markup Language</title> 
			<link>http://www.kuppingercole.com/report/fg_xacml_report</link> 
			<guid>http://www.kuppingercole.com/report/fg_xacml_report</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; This report explains XACML, an evolving standard in the field of access control. Access control in IT is of vital importance. Companies use access control technology to protect sensitive systems and information, and to keep assets safe. &lt;p&gt;At the same time, compliance with external regulations and internal policies is very important and access control technology is key. We can think about access control doing two things:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;1. Identifying the users (who are you)&lt;/li&gt;&lt;li&gt;2. Allowing...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/report/fg_xacml_report"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/JmPeneIhCtI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 28 Sep 2009 13:01:13 +0200</pubDate>
			<title>Beyond RBAC</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/09/28/beyond-rbac/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/09/28/beyond-rbac/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Please join me tomorrow for a free Webinar on the topic &amp;#8220;&lt;a href="http://www.kuppingercole.com/events/n40063"&gt;Beyond Role Based Access Control &amp;#8211; the ABAC Approach&lt;/a&gt;&amp;#8220;.&lt;/p&gt;
&lt;p&gt;Many &amp;#8211; if not most &amp;#8211; organisations are not getting as much value as they thought from RBAC (role based access control). In fact, many RBAC projects start with high expectations, but quickly get bogged down due to many issues and problems. Eventually it turns out that the initial expectations were too ambitious. But why? Is RBAC making promises that are difficult to keep?&lt;/p&gt;
&lt;p&gt;Many in the industry (Babak and myself included) think that this is due to the fact that the real world just happens to be too complex to model efficiently with RBAC. This means that organisations must be realistic about what they can achieve with RBAC, and mitigate some of its shortcomings. But isn&amp;#8217;t there a better way? There certainly is, and that&amp;#8217;s what we&amp;#8217;ll be speaking about tomorrow. There&amp;#8217;s nothing wrong about roles per se, but we need to add more context to them. Then finally, we can reap the full benefits of agile access management, reach and even surpass the value that was expected from troubled RBAC projects.&lt;/p&gt;
&lt;p&gt;I am delighted to speak again on a Webinar with Babak Sadighi, CEO and one of the founders of Axiomatics. Babak and his colleagues are an extremely smart bunch of people who are very passionate about access control. They have researched the topic for many years. I&amp;#8217;ve interviewed Babak at the last European Identity Conference, which you &lt;a href="http://www.youtube.com/watch?v=XaYR3dlgQxc"&gt;can see here&lt;/a&gt;. So if you&amp;#8217;re interested in access and role management, &lt;a href="http://www.kuppingercole.com/events/n40063"&gt;please join us tomorrow&lt;/a&gt;, I promise that you will not be disappointed &lt;img src='http://blogs.kuppingercole.com/gaehtgens/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /&gt; &lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/kF6MkwsP-ew" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 24 Sep 2009 09:42:11 +0200</pubDate>
			<title>VeriSign VIP – back again?</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/09/24/verisign-vip-back-again/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/09/24/verisign-vip-back-again/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;It has been pretty quíet around the VIP (VeriSign Identity Protection) solution. I have played around with that solution some two years ago, when support for eBay and PayPal had been added. But after that I didn&amp;#8217;t see much of VIP (and didn&amp;#8217;t hear much of VeriSign, honestly). Until these days, when TriCipher and VeriSign announced a strong authentication solution for Google Apps. They call it &amp;#8220;triple-sec&amp;#8221; given that three different factors are used &amp;#8211; the two provided by TriCipher and an out-of-band authentication based on VeriSign VIP Access for Mobile.&lt;/p&gt;
&lt;p&gt;VeriSign VIP Accessfor Mobile is in fact an OTP (one time password) generator which runs on mobile phones. Overall, a strong authentication can be achieved that way for TriCipher&amp;#8217;s MyOneLogin service which is the tool used. MyOneLogin is a cloud-based SSO solution for other (external) cloud or SaaS services which uses SAML to provide authentication information to Google Apps Premier.&lt;/p&gt;
&lt;p&gt;The VIP support is offered for free for Google Apps Premier customers &amp;#8211; as long as they use the strong authentication only for Google Apps Premier. If they&amp;#8217;s like to extend this to other apps, it&amp;#8217;s not free anymore. Anyhow, this is at least an interesting solution for companies who rely on these cloud services and require an relatively easy strong authentication solution. For sure you&amp;#8217;d have to accept that you need your mobile phone in addition but the alternative would be to rely on some soft-token approach or to carry another token or device to support strong authentication.&lt;/p&gt;
&lt;p&gt;Besides the fact, that the &amp;#8220;for free&amp;#8221; doesn&amp;#8217;t last long in practice, given that most customers probably will secure other apps as well, the biggest question from my perspective is whether a cloud-SSO for cloud only (more or less) is the solution of choice. Customers which further rely heavily on internal (and non-web) applications might benefit more from a traditional E-SSO approach supporting internal as well as external applications of any type. However, integration of these tools with applications like Google Apps typically relies on traditional exchange of username/password in the background instead of the more advanced SAML approach provided for example by MyOneLogin. With other words: There are other options, but at least the TriCipher/VeriSign offering is an interesting approach worth to have a look at.&lt;/p&gt;
&lt;p&gt;To learn more about what&amp;#8217;s going on in the &amp;#8220;cloud&amp;#8221;: Attend the Kuppinger Cole &lt;a title="Cloud 09" href="http://www.id-conf.com/cc09" target="_self"&gt;Cloud 09 conference&lt;/a&gt;, December 2nd-4th, Munich.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/fTLb7c3ZqBE" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 23 Sep 2009 00:00:00 +0200</pubDate>
			<title>Business Report: Identity &amp; Security in the Cloud</title> 
			<link>http://www.kuppingercole.com/report/tc_br_tc_idmseccloud_230909</link> 
			<guid>http://www.kuppingercole.com/report/tc_br_tc_idmseccloud_230909</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Cloud Computing ist seit etwa zwei Jahren das Modewort schlechthin in der IT-Branche. Historisch geht Cloud Computing auf verschiedene Ans&amp;auml;tze zur externen Bereitstellung von Anwendungen oder Speicherplatz, um die Unternehmens-IT zu entlasten oder sogar ganz zu ersetzen. ASP (&amp;bdquo;Application Service Providing&amp;ldquo;) wurde bereits in den 90ern mit dem Aufkommen des Internet intensiv diskutiert, entsprechende Angebote scheiterten aber in der Regel an unzureichenden Bandbreiten,...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/report/tc_br_tc_idmseccloud_230909"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/n0OHl9uDQy8" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 22 Sep 2009 00:00:00 +0200</pubDate>
			<title>Identity Services and the Cloud</title> 
			<link>http://www.kuppingercole.com/podcasts/identity_services_and_the_cloud.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/identity_services_and_the_cloud.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; The reason companies are considering cloud computing is to avoid the expense involved in building or acquiring the infrastructure, and to some extent managing it. However, without paying attention to the security and governance implications, those cost savings will actually evaporate when they either try to retrofit their existing business policies and controls into the cloud environment, or when they have to deal with the fallout from a breach or issue. In This webinar, Nishant Kaushik (Orac...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/identity_services_and_the_cloud.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/W4AIcAB8hVg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 21 Sep 2009 00:00:00 +0200</pubDate>
			<title>Sicherheitsrichtlinien zuverlässig durchsetzen</title> 
			<link>http://www.kuppingercole.com/podcasts/sicherheitsrichtlinien_zuverlaessig_durchsetzen.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/sicherheitsrichtlinien_zuverlaessig_durchsetzen.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Auf dem Papier ist es in der Regel gar nicht so schwierig, durch entsprechende Richtlinien einen zufriedenstellenden Grad an Sicherheit zu erreichen. Jedoch zehren in der Praxis fehlende Ressourcen, enge Budgets und nicht zuletzt die immer komplexer werdende Infrastruktur an einer effizienten Um- und Durchsetzung dieser Richtlinien. In diesem Webinar beschreiben wir Ihnen in Zusammenarbeit mit Novell, welche Ansätze für eine automatisierte Überwachung der Sicherheit von IT-Systemen am Markt e...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/sicherheitsrichtlinien_zuverlaessig_durchsetzen.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/g0sWhZmClgs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 18 Sep 2009 10:41:03 +0200</pubDate>
			<title>Cloud Business Models – a threat for vendors</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/09/18/cloud-business-models-a-threat-for-vendors/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/09/18/cloud-business-models-a-threat-for-vendors/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;During the last months I had a number of conversations with vendors about the licensing and business models for their cloud offerings. And frequently the conclusion was that the models aren&amp;#8217;t really adequate for the cloud. Some might work today and for some period of time, but they are not likely to be successful on the longer term.&lt;/p&gt;
&lt;p&gt;One ob the obvious shortcomings are accounting periods which are too long and thus don&amp;#8217;t provide the required flexibility which is a key advantage of cloud services. Contracts which run at least 12 months or accounting periods which look at the peak use within a calendar month are not what we need for the cloud. Over time, customers will expect the ability to switch their provider quickly and to pay-per-use. For sure there are services where customers aren&amp;#8217;t that likely to move ever or on short-term (salesforce.com, SAP BusinessByDesign). But I&amp;#8217;ve seen that model as well at the platform and infrastructure level.&lt;/p&gt;
&lt;p&gt;But pay-per-use models can be critical as well. If there are either too many elements in or elements which can&amp;#8217;t be predicted, these models don&amp;#8217;t provide the advantage of reliable cost models which are as well a key advantage that cloud services can and should provide. That is the same like with ISPs in the past &amp;#8211; there will be a logical move to flatrate models. Noone likes to become bankrupt because he is too successful.&lt;/p&gt;
&lt;p&gt;The reason for these sometimes inadequate business models are obvious:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Many vendors in the cloud are experienced with classical, license-based business models and have no experience and sometimes little understanding of new cloud business models. They are insecure and have to learn.&lt;/li&gt;
&lt;li&gt;Customers currently frequently accept these business models &amp;#8211; but that will change.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;However it is very interesting to observe the change in these business models over time. In the cloud, business models are always under stress test. The impact of actions of other vendors is strong. For example, Microsoft in fact has defined an maximum price tag for hosted Exchange services with their own offering. Providers which want to earn more will have to very clearly show the added value to their customers.&lt;/p&gt;
&lt;p&gt;That will not automatically lead to a situation in which the cheapest provider wins. But for sure cloud service providers will have to react on what others are doing. Thus, flexible business models and an efficient production of cloud services are mandatory. Vendors who are not able to pick up the pace of these changes in business models are likely to disappear from the market.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/0vTvbKNKcU0" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 18 Sep 2009 00:00:00 +0200</pubDate>
			<title>Minimizing Business Risks through Enterprise SSO</title> 
			<link>http://www.kuppingercole.com/podcasts/minimizing_business_risks_through_enterprise_sso.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/minimizing_business_risks_through_enterprise_sso.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Receiving approval for project budgets has been difficult in these days, especially if there isn´t a very visible and almost immediate return on investment. Simplifying the way how users login to the applications they need for their daily business is an area, where plenty of low hanging fruits provide such immediate RoI i.e. through the reduction of password reset helpdesk calls. In this webinar, Joe Skocich from IBM and Martin Kuppinger talk about commonly overlooked considerations when eval...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/minimizing_business_risks_through_enterprise_sso.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/yHui6eFMXjM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 28 Aug 2009 09:43:40 +0200</pubDate>
			<title>13.10.2009: The Role of Entitlement Management in Governance, Risk and Compliance Management</title> 
			<link>http://www.kuppingercole.com/events/n40064</link> 
			<guid>http://www.kuppingercole.com/events/n40064</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Modern IT infrastructures empower their users and thereby introduce new risks. The effectiveness and efficiency of control frameworks and GRC programs are therefore becoming an increasingly important focus area for IT and business managers alike. Yet, GRC initiatives tend to be reactive, striving to optimize monitoring, surveillance and auditing capabilities and the GRC overhead keeps growing. Instead we need risk-intelligence built into our IT-infrastructures. This is what Entitlement...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40064"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/DCYW3hz-m3w" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 28 Aug 2009 09:34:04 +0200</pubDate>
			<title>29.09.2009: Beyond Role Based Access Control - the ABAC Approach</title> 
			<link>http://www.kuppingercole.com/events/n40063</link> 
			<guid>http://www.kuppingercole.com/events/n40063</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; In this webinar we discuss the original ideas behind RBAC and why large RBAC projects often lead to role explosion  problems and therefore 
fail in their initial ambitions. We also introduce the concept of Attribute Based Access Control (ABAC) which overcomes some of the well-known problems with RBAC and enables a fine-grained and contextual (adaptive) access control. ABAC meets the requirements of modern 
IT-infrastructures where dynamically changing needs must be captured and dealt with...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40063"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/SggYSCehH5g" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 26 Aug 2009 11:25:10 +0200</pubDate>
			<title>17.09.2009: Minimizing Business Risks through Enterprise Single Sign-on</title> 
			<link>http://www.kuppingercole.com/events/n40060</link> 
			<guid>http://www.kuppingercole.com/events/n40060</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com"&gt;Kuppinger Cole + Partner&lt;/a&gt;&lt;br&gt;&lt;br&gt; Receiving approval for project budgets has been difficult in these days, especially if there isn´t a very visible and almost immediate return on investment. Simplifying the way how users login to the applications they need for their daily business is an area, where plenty of low hanging fruits provide such immediate RoI i.e. through the reduction of password reset helpdesk calls. In this webinar, Joe Skocich from IBM and Martin Kuppinger talk about commonly overlooked considerations when...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/events/n40060"&gt;more&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/seHV_UXwmPY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 20 Aug 2009 00:00:00 +0200</pubDate>
			<title>Vereinfachung der Berechtigungsanalyse und -Verwaltung</title> 
			<link>http://www.kuppingercole.com/podcasts/vereinfachung_der_berechtigungsanalyse_und_verwaltung.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/vereinfachung_der_berechtigungsanalyse_und_verwaltung.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In diesem Webinar geht Martin Kuppinger zunächst auf die Notwendigkeit ein, konsistente Autorisierungsstrategien zu entwickeln, die bei minimiertem administrativen Aufwand einen durchgängigen Schutz von Informationen bieten  indem man sich auf das Wesentliche konzentriert und sich nicht in Punktlösungen verzettelt. Reto Bachmann von Quest Software wird daran anschliessend anhand von Praxisbeispielen beschreiben, wie sich das Berechtigungsmanagement unter Einsatz des Quest Access Managers ein...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/vereinfachung_der_berechtigungsanalyse_und_verwaltung.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/bxw-lflhThY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 18 Aug 2009 09:00:36 +0200</pubDate>
			<title>Social OX – changing the way we work with social networks</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/08/18/social-ox-changing-the-way-we-work-with-social-networks/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/08/18/social-ox-changing-the-way-we-work-with-social-networks/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Open-Xchange, a provider of open source messaging and groupware, has announced its concept of Social OX, OX standing for Open Xchange and the concept of a &amp;#8220;personal information hub&amp;#8221;. The idea is to provide an approach where someone can maintain its &amp;#8220;contacts&amp;#8221; centrally and exchange that information with social networks like LinkedIn, Plaxo, Xing, FaceBook, MySpace, and others. The idea is to consolidate, manage, and re-use personal and social network data.&lt;/p&gt;
&lt;p&gt;The concept supports publishing data to others and consuming shared data. In effect, that information will become exchangeable, in contrast to today&amp;#8217;s lock-in approach in most social networks. Data can be tagged and so on, allowing to use different data for different contexts. That even will allow companies to integrate (respecting the data protection/privacy laws) available contact aggregated from individual contacts of employees, as one of many use cases.&lt;/p&gt;
&lt;p&gt;Currently, HTTP and XML are the underlying concepts, allowing an easy adoption. But Open-Xchange considers approaches like information cards as well for the future. The focus is on a common semantics and standardized interfaces to exchange that information. And Open-Xchange claims that several large social network providers are starting to support that concept.&lt;/p&gt;
&lt;p&gt;Social OX is an interesting threat for providers of social networks, given that it opens them up. But will it also affect their &lt;a title="Rise and fall of social networks" href="http://blogs.kuppingercole.com/kuppinger/2007/12/21/the-rise-and-fall-of-social-networks/" target="_blank"&gt;business models&lt;/a&gt;? Currently, the lock-in is a part of the concepts. With approaches like Social OX (and the approach for exchanging social network information might be used by other vendors as well) that lock-in disappears, allowing to use platforms like Open-Xchange to read the data out and publish it to another social network. That will allow a faster and more easy switch between social networks.&lt;/p&gt;
&lt;p&gt;However, it is unlikely that leading social networks will disappear. They benefit from the number of users and they especially benefit from their other services around the personal information which could be exchanged using Social OX. However, it will become easier for new social networks (and other system relying on that information) to enter the market. Today, the value of new social network approaches is frequently low because there are too few users. That will become easier, even with the need of others to subscribe and import their data as well.&lt;/p&gt;
&lt;p&gt;Social OX has the potential to influence the way we work with social network data and personal information, with Open-Xchange (and maybe other vendors) acting as personal information hub. It might as well allow new business models (think about personalization). And it might lead to a world with more successful social networks than today, due to a lower market entry for newcomers. But as long as the market leaders focus on the added values for the network members and have a valid business model (which isn&amp;#8217;t necessarily true for all of them today), Social OX will not lead to their replacement. However, they will have to learn to exist without the lock-in of social network information of their customers.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/SdkOqb1ItNc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 17 Aug 2009 00:00:00 +0200</pubDate>
			<title>Zugriffsmanagement richtig gemacht</title> 
			<link>http://www.kuppingercole.com/podcasts/zugriffsmanagement_richtig_gemacht.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/zugriffsmanagement_richtig_gemacht.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In diesem kostenlosen Webinar gehen wir darauf ein, wie eine ideale Basis für ein konsistentes Access Management geschaffen werden kann und wie man dieses schrittweise weiterentwickelt.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/zugriffsmanagement_richtig_gemacht.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/roXBny-Wd0A" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 11 Aug 2009 15:55:41 +0200</pubDate>
			<title>Identity – Last Man Standing?</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/08/11/identity-%e2%80%93-last-man-standing/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/08/11/identity-%e2%80%93-last-man-standing/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Somehow the Hofbraeukeller in Munich, one of my favorite city’s nicest beer garden restaurants, seems to lend itself particularly well to long, meandering discussions of identity management. It’s the place the U.S. participants at the European Identity Conference regularly gather for their pre-conference pigs’ feet feast, and since it’s conveniently located around the corner from where I live, I often use it as a meeting place for visitors from all over the world. I mean, if you’re in Bavaria, by all means go to a Bavarian place for lunch instead of one of the ubiquitous sushi stalls.&lt;/p&gt;
&lt;p&gt;I thought my latest guest, Tom Stewart, CFO of MultiFactor Authentication out of Irvine, CA, would be thrilled, but it turns out he spent two years working for Intel in Munich, so he’s been there and done that. Which is okay, because it gave us more time to get down to basics about his company’s strategy and products.&lt;/p&gt;
&lt;p&gt;Tom is in the business of making security tokens obsolete. I know you’re going to hate this if you just gave a pile to RSA or Verisign, but MultiFactor believes that hardware-based strong authentication is poised to go the way of the dodo.&lt;/p&gt;
&lt;p&gt;Of course, software tokens have been around for quite awhile, but they are often considered to be weaker than hardware tokens, or else they require some fancy PKI architecture to make them safe enough for serious corporate use.&lt;/p&gt;
&lt;p&gt;Well, think again, Tom says. His “SecureAuth” system sits inside the firewall and handles full bidirectional X.509 authentication for apps and other systems without any tokens or PKI infrastructure and, more importantly, at a fraction of the cost. The system used to connect the client with your company network is proprietary, but it uses SAML or any other system you want to use to connect to outside applications or SaaS providers. Just how they do it and whether it really works the way they say it does is beside the point here, but readers are invited to visit their website at &lt;a href="http://www.multifa.com"&gt;www.multifa.com&lt;/a&gt; for a free online demo and as much nerdy prose as you can stomach. (Tom is a marketing guy, but he is apparently surrounded by a team of true, dyed-in-the-wool techies.)&lt;/p&gt;
&lt;p&gt;Personally, my attention perked up when Tom began to describe the way SecureAuth acts as a kind of gatekeeper for Active Directory (in 90 percent of cases, he says) or any other directory service you happen to be running.&lt;/p&gt;
&lt;p&gt;This seems especially exciting to me when you consider it in terms of Cloud Computing, where we are seeing a rash of new cloud-based identity services. Bob Blakley of Burton described what he calls the “ability to build a virtual identity provider using a multitude of different services”. At the Catalyst Conference in San Diego a few weeks ago, he expressed his surprise that, unlike what everyone was expecting, providing identity services for the Cloud wasn’t turning out to be “this big monolithic thing”. Instead, the market is building a set of small specialty firms that handle identity tasks and offer discrete billable units that companies can put together. Ping, for instance, integrates PingConnect with Google Apps so a user&amp;#8217;s Google ID can be used for single sign-on across some 60 online services.&lt;/p&gt;
&lt;p&gt;Sourcing your identity management may appear to make good business sense, but does it really? After all, companies are sourcing just about everything else related to their IT. But Tom believes, and I agree, that identity management is the last thing you want to see going out the door. “As long as you control the directory, you control everything”, he maintains. Letting external service providers make changes or allowing them to make copies of your directory, which some do, is simply asking for big trouble.&lt;/p&gt;
&lt;p&gt;My feeling, and it’s nothing more than that, is that companies will be very cautious in moving towards the cloud, choosing a step-by-step approach rather than taking the sudden plunge. As much as small and medium-sized enterprises would love to say goodbye to their IT and concentrate on their core business, they should draw the line at their directory, be it active or otherwise.&lt;/p&gt;
&lt;p&gt;In fact, you could probably make a case for keeping only your directory and sourcing everything else, but then what is the poor CIO to do? Anyway, directory services might actually prove to be the Last Man Standing as corporate IT gradually disappears into Cloud-cuckoo-land.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/8dRs7nhqFaE" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 11 Aug 2009 13:13:17 +0200</pubDate>
			<title>Is PAM (or PIM or PUM) moving into Provisioning?</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/08/11/is-pam-or-pim-or-pum-moving-into-provisioning/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/08/11/is-pam-or-pim-or-pum-moving-into-provisioning/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;These days I have been talking with Siemens on enhancements for their DirX Identity product, a provisioning tool (and, by the way, a pretty good one). Amongst the new features is some support for Privileged Account Management (PAM). That&amp;#8217;s interesting. I&amp;#8217;ve &lt;a title="Novell acquires Fortefi" href="http://blogs.kuppingercole.com/kuppinger/2009/02/20/novell-enters-pam-market-the-first-deal-in-the-next-wave-of-acquisitions-in-iam/" target="_blank"&gt;blogged some time ago&lt;/a&gt; about the possibility of provisioning vendors starting to acquire PAM vendors and adding these capabilities to their provisioning products.&lt;/p&gt;
&lt;p&gt;Siemens didn&amp;#8217;t acquire but implemented some own technology. They mainly focus on providing one-time passwords for the use of privileged accounts and re-setting these passwords after use. This is combined with strong authentication, using smartcards. In fact it is sort of a mix between product (resetting passwords and all that stuff) and project (adding strong authentication using other products). But finally they became a pioneer in integrating PAM with provisioning.&lt;/p&gt;
&lt;p&gt;There is no doubt that the leading PAM suites like the ones provided by &lt;a title="Cyber-Ark" href="http://www.cyber-ark.com" target="_blank"&gt;Cyber-Ark&lt;/a&gt; or &lt;a title="Lieberman Software" href="http://www.liebsoft.com" target="_blank"&gt;Lieberman Software&lt;/a&gt; provide a much broader feature set. However, integrating that with provisioning tools, identity lifecycles, and existing (self) service interfaces is a valid approach. I expect other vendors to follow, adding PAM support as well. However, the specialists will provide a more sophisticated solution at least for a pretty long period of time (unless they become acquired&amp;#8230;).&lt;/p&gt;
&lt;p&gt;But what Siemens has done proves my thesis on PAM moving into provisioning, servicing the specific requirements of customers. And it proves that PAM is moving from a niche topic towards a mainstream technology in the broader IAM market.&lt;/p&gt;
&lt;p&gt;Regarding the term PAM (or PIM or PUM): I prefer Privileged Account Management because it is about &lt;em&gt;accounts&lt;/em&gt; which are associated to a person and their digital &lt;em&gt;identity&lt;/em&gt;. The &lt;em&gt;user&lt;/em&gt; is sometimes associated with an account, sometimes more understood as a construct in between, e.g. a user-ID with some accounts associated and sometimes the situation that some person with one digital identity could have multiple user-IDs. For what is managed, PAM seems to be the most appropriate term, from my point of view.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/MUVKLPpxq7g" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 03 Aug 2009 14:53:35 +0200</pubDate>
			<title>Licensing for the cloud – the Skype case</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/08/03/licensing-for-the-cloud-the-skype-case/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/08/03/licensing-for-the-cloud-the-skype-case/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;These days, there were several articles in different media stating that eBay might discard its Skype service. The reason is that they haven&amp;#8217;t acquired the underlying P2P core technology. This is still owned by Joltid. And Joltid plans to terminate that license agreement. One doesn&amp;#8217;t need to be a prophet to guess that the real reason behind that situation is about money&amp;#8230;&lt;/p&gt;
&lt;p&gt;However, eBay definitely is in a difficult situation. They might find a deal with Joltid. They might discard the Skype service with its 16 million users &amp;#8211; which probably won&amp;#8217;t be that lucky about. They might develop an own P2P technology. Or they might replace the P2P technology. Given the limited time eBay has to solve the problem they the most likely options are that eBay either will find a new agreement with Joltid or will have to acquire another P2P technology. There are several P2P providers out there, some supporting phone capabilities, like &lt;a title="Collanos" href="http://www.collanos.com" target="_blank"&gt;Collanos&lt;/a&gt; Phone. There are Open Source projects like Gizmo. Thus there are some options. It will require some intense technical due diligence for eBay to choose the technology which allows to continue the Skype service with somewhat equal features and not too much of disruption for existing users. But there are solutions out there.&lt;/p&gt;
&lt;p&gt;It will be interesting to observe which option eBay chooses. Given that I&amp;#8217;m a Skype user, I&amp;#8217;m really interested in. I&amp;#8217;m as well interested from a perspective of an analyst for the Cloud Computing market, because the situation eBay is in shows the inherent complexity of Cloud Computing with many different relying parties. Think about a situation where, just as an example, a database isn&amp;#8217;t provided any more by the cloud computing platform it has been run on before, because the company providing the platform has terminated the agreement with the database vendor. That would be somewhat the same story. Thus, think about these dependencies and look at the potential problems&amp;#8230;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/meAmBrWFh40" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 03 Aug 2009 07:00:47 +0200</pubDate>
			<title>Microsoft: minimum disclosure about minimum disclosure</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/08/03/microsoft-minimum-disclosure-about-minimum-disclosure/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/08/03/microsoft-minimum-disclosure-about-minimum-disclosure/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;A good year ago, Microsoft acquired an innovative company called U-Prove. That company, founded by visionary Stephan Brandt, had come up with a privacy-enabling technology that effectively allows users to safely transmit the minimum required information about themselves when required to &amp;#8211; and for those receiving the information, a proof that the information is valid. For example: if a country issued a digital identification card, and a service provider would need to check whether the holder over 18 years of age, the technology would allow to do just that &amp;#8211; instead of having to transmit a full data set, including the age of birth. The technology works through a complex set of encryption and signing rules and is a win-win for both users who need to provide information as well as those taking it (also called “relying parties in geek speak”). With the acquisition of U-Prove, Microsoft now owns all of the rights to the technology &amp;#8211; and more importantly, the associated patents with it. Stephan Brandt is now part of Microsoft’s identity team, filled with top-notch brilliant minds such as Dick Hardt, Ariel Gordon, Mark Wahl, Kim Cameron and numerous others.&lt;/p&gt;
&lt;p&gt;Privacy advocates should (and are) happy about this technology because it effectively allows consumers to protect their information, instead of forcing them to give up unnecessary information to transact business. How many times have we needed to give up personal information for some type of service without any real need for this information? For example, if you’re not shipping anything to me… what’s the point of providing my home or address? If you are legally required to verify that I’m over 18 (or 21), why would you really need to know my credit card details and my home address? If you need to know that I am a customer of one of your partner banks, why would you also need to know my bank account number? Minimum disclosure makes transactions possible with exactly the right fit of personal details being exchanged. For those enterprises taking the data, this is also a very positive thing. Instead of having to “coax” unnecessary information out of potential customers, they can instead make a clear case of what information they do require for fulfilling the transaction, and will ultimately find consumers more willing to do business with them.&lt;/p&gt;
&lt;p&gt;So all of this is really great. And what’s even better, Microsoft’s chief identity architect, Kim Cameron has promised not to “hoard” this technology for Microsoft’s own products, but to actually contribute it to society in order to make the Internet a better place. But more than one year down the line, Microsoft has not made a single statement about what will happen to U-Prove: minimum disclosure about its minimum disclose technology (pun intended!). In a post that I made a year ago, I tried making the point that this technology is so incredibly important for the future of the Internet, that Microsoft should announce its plans what do with the technology (and the patents associated for it).&lt;/p&gt;
&lt;p&gt;Kim’s response was that Microsoft had no intentions of “hoarding” the technology for its own purposes. He highlighted however that it would take time to do this &amp;#8211; time for Microsoft’s lawyers, executives and technologists to irk out the details of doing this.&lt;/p&gt;
&lt;p&gt;Well &amp;#8211; it’s been a year, and the only “minimum disclosure” that we can see is Microsoft’s unwillingness to talk about it. The debate is heating up around the world about different governments’ proposals for electronic passports and ID cards. Combined with the growing dangers of identity theft and continued news about spectacular leaks and thefts of personal information, this would really make our days. Unless you’re a spammer or identity thief of course.&lt;/p&gt;
&lt;p&gt;So it’s about time Microsoft started making some statements to reassure all of us what is going to happen with the U-Prove technology, and &amp;#8211; more importantly &amp;#8211; with the patents. Microsoft has been reinventing itself and making a continuous effort to turn from the “bad guys of identity” a decade (in the old Hailstorm days with Microsoft Passport) into the “good guys” of identity with its open approach to identity and privacy protection and standardisation. At Kuppinger Cole we have loudly applauded the Identity Metasystem and Infocards as a ground-breaking innovation that we believe will transform the way we use the Internet in the years to come. Now is the time to really start off the transformative wave of innovation that comes when we finally address the dire need for privacy protection. Microsoft has the key in its hands, or rather, locked in a drawer. C’mon guys, when will that drawer finally be opened?&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/LdqmrCqSKHg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 31 Jul 2009 19:15:45 +0200</pubDate>
			<title>Finally: an open XACML API!</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/07/31/finally-an-open-xacml-api/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/07/31/finally-an-open-xacml-api/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Whilst at the Burton Group’s Catalyst 2009 conference, I ran into Prateek Mishra from Oracle who told me somewhere between the lines of our conversation that &lt;a href="http://www.oasis-open.org/committees/document.php?document_id=33416"&gt;a new XACML API that has just been posted to the OASIS XACML TC&lt;/a&gt;. It was a “soft launch” that was announced at the Kantara meetings on Monday at Burton Catalyst (which very unfortunately, I missed). When Prateek mentioned it to me, it stopped me dead in my tracks, because I find it really significant news – a very important step towards flexible access control policy based on XACML. Before I get in the details, let me step back a bit and explain what this is, why I find this so significant and why it got me so excited.&lt;/p&gt;
&lt;p&gt;XACML, the eXtensible Access Control Modeling Language is an XML-based standard for authorization and access control. It is based on the Attribute Based Access Control (ABAC) model that is hailed as the next generation of access control models. According to many, ABAC will ultimately replace RBAC (Role Based Access Control). Instead of only using a role as the determining factor whether to grant access or not, many attributes can be used. Of course roles can be used in ABAC as well – since ABAC can use multiple attributes to make access control decisions, the “Role” can be one of those attributes – so ABAC can emulate RBAC perfectly while adding many additional advantages. This means that it is possible to add context to the access control decisions and adds for a finer granularity, tighter controls and more flexibility for the business.&lt;/p&gt;
&lt;p&gt;Here’s an example: I might be authorised to make bank transfers from an application. In RBAC, this would usually mean that I would have a role enabled for my account, for example “Make_Transfers”. Simple, right? Well, perhaps not so. As the need for control gets tighter, I may be authorised only to make transfers up to a value of 2000 EUR without any approval. Anything else above that requires the approval of at least two of the financial supervisors. So how would you do this with RBAC? Not really so easy. And with ABAC? Piece of cake. With RBAC, the bank transfer application would have to have some hardwired piece of logic implementing the “max 2000 EUR without approval”. With ABAC, the policy could just express that if I have the role “Make_Transfers” and “transfer_amount &amp;lt;= 2000” the operation is approved. ALso approved is an operation if I have the role “Make_Transfers” and “transfer_amount &amp;lt;= 2000” and “valid_approvals &amp;gt;= 2”. Everything else is denied.&lt;/p&gt;
&lt;p&gt;So let me get back to the XACML API. There has been adoption by XACML, and I could even see it for myself here at Burton Catalyst 2009 just by meeting the sheer number of vendors that are actively supporting it and using it it for policy enforcement and access control. What has really been missing however was a ready-to-use API that would allow developers to make an access control request in their application and get a decision. Now we finally have an API that allows developers to do just that. I’ve spent over an hour yesterday hunched over my brand-new netbook with Prateek and Pat Patterson, poring over the API and can only say: thumbs up!&lt;/p&gt;
&lt;p&gt;So what can this API be used for? Is it easy enough for developers to jump on and enable their applications for externalised access control? Well, not really. XACML is a very powerful and expressive policy modeling language, and also defines a request/response protocol. This creates a certain level of complexity. Whilst of course it is possible for application developers to use this API in their applications, I think that higher-level authorisation APIs are still needed that make it “dead easy” for developers to externalise access control. For matters of comparison, I was very impressed at how easy it is to .NET developers to harness the Geneva Framework (which is now called WIF or Windows Identity Foundation). Microsoft has made it truly “dead easy” for developers to make their applications ready for externalised authentication and claims – with just a few lines of “plumbing code”. Externalising authorisation must be made just as simple. The XACML API is a great start to provide a foundation that can be used to connect simpler APIs and existing access control frameworks to XACML.&lt;/p&gt;
&lt;p&gt;Kudos for Cisco and Oracle for having contributed this. Great work, guys!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/v6tptnKk1Fo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 30 Jul 2009 12:41:26 +0200</pubDate>
			<title>About trademarks in the IAM business</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/07/30/about-trademarks-in-the-iam-business/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/07/30/about-trademarks-in-the-iam-business/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;These days I have learned that &lt;a title="Fischer International" href="http://www.fischerinternational.com" target="_blank"&gt;Fischer International Identity&lt;/a&gt; has trademarked to pretty generic terms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Identity as a Service (TM)&lt;/li&gt;
&lt;li&gt;IaaS (TM)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I wondered (and still wonder) about that. Fischer declared that they have invented that type of business (&amp;#8221;a services-based architecture built from the ground-up for the express purpose of cost-effectively delivering identity management capabilities via the Software as a Service (SaaS) model&amp;#8221;), built on a SOA architecture, supporting multi-tenancy, being able to work across firewalls. Honestly: Yes, they are an innovator in that space.&lt;/p&gt;
&lt;p&gt;Unfortunately, that isn&amp;#8217;t the only technology to which the terms mentioned above are applied. There are many different identity services. External identity providers for OpenID, strong authentication services, SSO for the cloud,&amp;#8230; &amp;#8211; to all these services the terms IaaS (TM) and Identity as a Service (TM) are frequently applied. And if you look at Application Security Infrastructures, then it is as well about providing identity services.&lt;/p&gt;
&lt;p&gt;Thus, I agree with Fischer that they are sort of a pioneer in providing &amp;#8220;provisioning as a service&amp;#8221; (which would be PaaS) but I don&amp;#8217;t agree with their view on that they have invented they entire market space for which these terms are used today. Anyhow, it is a little like Daimler having trademarks on &amp;#8220;car&amp;#8221;, &amp;#8220;Automobil&amp;#8221;, and other related terms, isn&amp;#8217;t it!?&lt;/p&gt;
&lt;p&gt;On the other side: Maybe I shouldn&amp;#8217;t bash on Fischer for trademarking (why not try to get them?), but the ones on the governmental side which have agreed to trademark these very common terms. What will be next? SaaS (TM)? Cloud Computing (TM)? I really can&amp;#8217;t understand that such common terms are trademarked (and I will use some related but somewhat different terms in the future). However, anyone who uses these terms has to attribute ownership of the mark to Fischer International Identity, like they have stated. Let&amp;#8217;s look how they deal with the trademarks in practice. And be careful when using these terms.&lt;/p&gt;
&lt;p&gt;To comply with the trademarking stuff: Identity as a Service (TM) and IaaS (TM) are trademarks owned by Fischer Internation Identity.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/o01W3moFCv4" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 24 Jul 2009 17:30:27 +0200</pubDate>
			<title>The blessings of 3G with Win 7</title> 
			<link>http://blogs.kuppingercole.com/rohr/2009/07/24/the-blessings-of-3g-with-win-7/</link> 
			<guid>http://blogs.kuppingercole.com/rohr/2009/07/24/the-blessings-of-3g-with-win-7/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/rohr"&gt;Sebastian Rohr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Asa tech savvy person and all-time traveller I recently acquired a mobile network data flat of one of the local German and international providers &amp;#8211; the one with pink logo. For every contract/subscription you sign, you usually get some perks, extra stuff, a mobile handset or &amp;#8211; in my case &amp;#8211; one of those netbooks. The Acer Aspire One 531 I was sent does feature an integrated 3G modem by OPTION Wireless ad comes with Windows XP Hometo my demise. Failing in preparing a proper backup (Acer gives you a backup software to burn media &amp;#8211; but a netbook does not have an optical drive, and maping the DVD burner in my home Vista machine is not acceptable use of the software &amp;#8211; and thus deactivated) I killed XP home anyway and installed Win 7 fresh of a 8 GB USB flash (see here for a geek howto, or here for the DAU help with prepping the USB stick). All worked well &amp;#8211; even a complete Office 2007 and  Visio2007 found its way on the device &amp;#8211; no driver problems, except&amp;#8230; for the 3G!&lt;/p&gt;
&lt;p&gt;I spent way too much time to figure this out, so here are the resources needed:&lt;br /&gt;
Driver handling &amp;#038; tweaking plus driver links&lt;br /&gt;
http://www.itgrl.de/2009/03/31/aspire-one-3g-treiber-fur-umts-modem/&lt;br /&gt;
Driver Links Acer&lt;br /&gt;
http://global-download.acer.com/GDFiles/Driver/3G/3G_Option_5.0.12.0_XPx86_A.zip?acerid=633776034442008284&amp;#038;Step1=Netbook&amp;#038;Step2=Aspire One&amp;#038;Step3=AO531h&amp;#038;OS=X01&amp;#038;LC=de&amp;#038;SC=EMEA_8&lt;br /&gt;
Driver Links Option (IMEI required!)&lt;br /&gt;
http://www.option.com/en/support/software-download/product-list/ &lt;/p&gt;
&lt;p&gt;After trying desperately to use the T-Mobile web´n´walk software for a while (even the EMBEDDED Version taken from the mysterious FTP server in Czech Republic) did always UNINSTALL the Option drivers leaving my netbook without connectivity.&lt;br /&gt;
Using the ACER Software DOES the trick though, but yu have to tweak it:&lt;br /&gt;
the Acer 3G Connection wil fail to connect (it finds the device, SIM is entered, network is acquired) but the it get stucks while &amp;#8220;connecting&amp;#8221; aka &amp;#8220;Verbinden&amp;#8230;&amp;#8221;.&lt;br /&gt;
Again, calling the friendly mobile provider support, we quickly analyzed that we are only one step away. Simple solution:&lt;br /&gt;
create a new modem connection with *99# as the number to be dialed and all works well suddenly!&lt;/p&gt;
&lt;p&gt;Now, back to real work&amp;#8230; message me if you have a working setup with w´n´w software on Win 7 and internal Option MOx40 cards&amp;#8230; or actual stand alone drivers for Win 7 that are NOT deleted when installing w´n´w &lt;img src='http://blogs.kuppingercole.com/rohr/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /&gt; &lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/8VjEmzuXyXg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 23 Jul 2009 00:00:00 +0200</pubDate>
			<title>Externalizing Identity to the Cloud</title> 
			<link>http://www.kuppingercole.com/podcasts/externalizing_identity_to_the_cloud.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/externalizing_identity_to_the_cloud.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Externalizing Identities from applications into a service oriented layer within the enterprise IT architecture has been discussed a lot within the last years, mainly in the light of reducing application development costs and to devolve all those identity silos captured in enterprise applications. With cloud computing and *aaS picking up momentum, the externalization of identity management into such a service layer finally seems to be rewarded with enough attention to move far up on many CIO´s...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/externalizing_identity_to_the_cloud.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/_2_IKCC5e_k" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 22 Jul 2009 14:20:31 +0200</pubDate>
			<title>Many test cases for German eID card</title> 
			<link>http://blogs.kuppingercole.com/kuppinger/2009/07/22/many-test-cases-for-german-eid-card/</link> 
			<guid>http://blogs.kuppingercole.com/kuppinger/2009/07/22/many-test-cases-for-german-eid-card/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/kuppinger"&gt;Martin Kuppinger&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Some days ago the German government announced a list of 30 companies with test cases for the upcoming eID card, which will be available starting November, 2010. The good news is that the BMI (Federal Ministry of the Interior) has managed to get a good number of test scenarios outside of eGovernment. The identification of flight passengers at airports, hotel check-in, online shops, and some use cases for age verification are on the &lt;a title="Test cases for German eID card (in German)" href="http://www.bmi.bund.de/SharedDocs/Pressemitteilungen/DE/2009/06/epa_anwendertest.html" target="_blank"&gt;list of published test cases&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For sure there are as well many eGovernment applications amongst these 30+ scenarios but the real important thing is that there are obviously many partners outside the eGovernment which are interested to use the eID card for identification (or age verification) purposes within their specific business use cases. If they succeed, there will be a lot more partners once the eID card is officially issued - and the more companies will use the eID card, the more momentum will be there for &amp;#8220;buying&amp;#8221; the eID card and switching to it from the current conventional ID card. That is about &amp;#8220;buying&amp;#8221; because the eID card is mandatory when renewing the current eID card (which is valid 10 years from the date of issuance). That fee will be accepted more likely when the card can be used for many use cases.&lt;/p&gt;
&lt;p&gt;Overall it appears that the German government is doing a good job in creating some interest in and momentum behind the eID card. And doing a broad test with many partners more than one year before the card is distributed widely is definitely important &amp;#8211; there will be many lessons learned. Anyhow, the biggest threat for the eID card still will be the acceptance. Test cases are one thing &amp;#8211; the other aspects are usability (make the eID card as easy to use as possible, even from home) and trust. There will be a lot of discussions around the eID card, and educating users about the security and privacy (which is pretty good in the eID card concept) is extremly important for the success of the German eID card. But there will be a lot of FUD (fear, uncertainty, doubt) raised around this issues, like &amp;#8220;the fingerprints aren&amp;#8217;t fully secure&amp;#8221;. Yes, in fact, there is some slight chance of abuse &amp;#8211; but what the eID card provides is a big step forward for most of the users. Thus, we should look at it more positive and understand it as an important improvement for security in the Internet &amp;#8211; with some shortcomings (national, time-to-market,&amp;#8230;).&lt;/p&gt;
&lt;p&gt;It will be definitely interesting to observe the different test cases and the lessons learned there. Despite all doubts, the German eID card has a good chance of becoming a successful project.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/e7Ha-UrNxYI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 21 Jul 2009 17:45:01 +0200</pubDate>
			<title>Virtual Directory Innovations</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/07/21/virtual-directory-innovations/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/07/21/virtual-directory-innovations/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;As someone actively covering directory services and virtual directories, several innovations have caught my attention. The players within the virtual directory space are (in alphabetical order) Optimal IDM, Oracle, SAP, Radiant Logic, Red Hat, and Symlabs. When it comes to product development and innovation within the last year, you can split those vendors right down the middle. &amp;#8211; Optimal IDM, Radiant Logic and Symlabs have been actively developing their product and churning out new features in new versions. The others have not been adding any features, but instead spent time changing logos, product names, default file locations and otherwise integrating the virtual directory products into the respective Oracle/RedHat/SAP identity management ecosystems. In fact, in some of the latter cases I ask myself whether it is likely to expect any virtual directory product innovations anymore.&lt;/p&gt;
&lt;p&gt;So what&amp;#8217;s new? Where&amp;#8217;s the innovation happening?&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.optimalidm.com"&gt;Optimal IDM&lt;/a&gt;: New connectors have been added for Microsoft SQL Server 2008, eDirectory. A special version for Microsoft Sharepoint integration has also been released, as well as &amp;#8220;automated compliance features&amp;#8221; that monitor for changes that violate definable rules and alert administrators.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.radiantlogic.com"&gt;Radiant Logic&lt;/a&gt;: Its flagship product, formerly Radiant VDS (Virtual Directory Server) has been split up into to new products: The VDS Proxy Edition and the VDS Context Edition. The former is a classical virtual directory product that falls into the same category than Oracle VDS and the Symlabs Virtual Directory products. The latter is a mix of meta-directory and virtual directory features. Radiant Logic has rewritten major parts of the virtual directory core to make it more efficient in order to overcome performance problems that used to be a weak point in the product.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.symlabs.com"&gt;Symlabs&lt;/a&gt;: A full virtual tree functionality has been added. This makes the product easier to configure. In the past, a virtual tree had to be constructed by manually configuring plugins to filter and route requests. This had made configuration more difficult compared to other virtual directory products. This used to be a weak point in their products, like the performance used to be a negative point in Radiant Logic&amp;#8217;s virtual directory server. Symlabs has also added a complete web-based remote administration interface that can be used instead of, or side-by-side with the local Java configuration interface.&lt;/p&gt;
&lt;p&gt;What else is new? The latest piece of news comes from Symlabs who have &lt;a href="http://symlabs.com/press/43"&gt;released a competitive benchmark&lt;/a&gt; paper that contains the results of a comprehensive benchmark of the virtual directory servers from Oracle, Radiant Logic and Symlabs. The numbers speak for themselves. Of course, comparative tests by vendors must always be taken with a grain of salt. In the report, Symlabs encourages companies to do their own benchmarks to verify the results in the Symlabs study. However, the numbers are credible and document what has already been known for some time. The Symlabs product comes out as the fastest virtual directory. This is unsurprising, due to a very efficient internal design and a small footprint that this translates to a level of efficiency that surpasses other virtual directory servers.&lt;/p&gt;
&lt;p&gt;At second place in the competitive benchmark comes Radiant Logic&amp;#8217;s VDS Proxy Edition server, which is also interesting. Until end of last year, Radiant Logic&amp;#8217;s virtual directory product was at the tail end of all performance benchmarks, beaten by both Oracle and Symlabs by &amp;#8211; at least &amp;#8211; a scale of magnitude. Radiant Logic has done some hard work last year to catch up, and it shows by surpassing the Oracle product in the benchmarks and coming in second place.&lt;/p&gt;
&lt;p&gt;The virtual directory segment continues to be innovative. This is good for customers that are increasingly adopting virtual directories as simple point solutions to solve integration issues between applications and directory servers. However, innovation does not happen everywhere. It has been very quiet around Red Hat&amp;#8217;s, SAP&amp;#8217;s and Oracle&amp;#8217;s virtual directory products for a long time &amp;#8211; up to now, little has happened with those products. Optimal IDM, Radiant Logic and Symlabs have done some serious enhancements to their products and compete head-on in the virtual directory arena. Remember the old stereotype that smaller companies tend to be much more innovative than the larger ones?&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/kjFAHZM5cMo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 15 Jul 2009 12:05:33 +0200</pubDate>
			<title>Lesser of two evils?</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/07/15/lesser-of-two-evils/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/07/15/lesser-of-two-evils/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;&lt;object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/v/9isKnDiJNPk&amp;amp;hl=de&amp;amp;fs=1&amp;amp;" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;embed type="application/x-shockwave-flash" width="560" height="340" src="http://www.youtube.com/v/9isKnDiJNPk&amp;amp;hl=de&amp;amp;fs=1&amp;amp;" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
More than 250.000 people have watched &amp;#8220;ethical hacker&amp;#8221; Chris Paget cruising the streets of San Francisco gathering RFID data from the new U.S. PASS cards and &amp;#8220;enhanced&amp;#8221; chipped drivers licenses. All it took him about $250 for a scanner and an antenna, as well as a piece of software he downloaded from the Internet. The new &amp;#8220;e-passports&amp;#8221; are now mandatory for U.S. citizens entering the United States from Canada, Mexico, Bermuda and the Caribbean, though conventional passports will be accepted as long as they are valid. Paget was able to read and clone the information of the chips within minutes. While only tag numbers were intercepted, not the personal data on the chip, this is enough to identify and track individuals, which brings us a step closer to my favorite nightmare scenario: As I leave the airport in, say, Tunis or Cairo on my way to a nice sunny vacation I am picked up and followed by jihadists bent on killing any American capitalist swine they can find.&lt;/p&gt;
&lt;p&gt;This may not be news to most of us, but what struck me was a comment by Gigi Zenk, a spokeswoman for the Washington state Department of Licensing, quoted in today’s edition of the &amp;#8220;International Herald Tribune&amp;#8221;, who believes that &amp;#8220;Americans aren&amp;#8217;t that concerned about RFID&amp;#8221; in a time when &amp;#8220;tracking an individual is much easier through a cellphone.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Is this simply a brainless bureaucrat talking twaddle, or is she being cynical? Then again, maybe she has a point: If people did care a lot about &amp;#8220;little brother&amp;#8221;, as the global surveillance web is now being referred to, wouldn&amp;#8217;t they do something about it? Like switch off their mobiles?There have been rpeorts of German tax dodgers being caught because they said they were at home when in fact their phones were in the offices of a bank in Zurich.&lt;/p&gt;
&lt;p&gt;In Germany, supposedly a country obsessed with privacy concerns and boasting the strictest data protection laws on the planet, a law calling for issuing RFID-enabled passports passed with hardly a murmur, and they are now gearing up to issue each and every one of their 80-some million citizens a mandatory personal ID card that will also carry a chip.&lt;/p&gt;
&lt;p&gt;Maybe cynicism does help. How about this: If everybody is naked, nobody will be bothered by nakedness. Just blend in with the crowd. Implant an RFID chip in every forehead. There&amp;#8217;s safety in numbers, after all. Or then again, maybe not&amp;#8230;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/oN0dLLu1BZY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 30 Jun 2009 22:26:03 +0200</pubDate>
			<title>New design</title> 
			<link>http://www.id-conf.com/blog/2009/06/30/new-design/</link> 
			<guid>http://www.id-conf.com/blog/2009/06/30/new-design/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;We would like to present a &amp;#8220;design refresh&amp;#8221; of our web sites: &lt;a href="http://www.kuppingercole.com" target="_blank"&gt;www.kuppingercole.com&lt;/a&gt;, &lt;a href="http://blogs.kuppingercole.com" target="_blank"&gt;blogs.kuppingercole.com&lt;/a&gt;, and &lt;a href="http://www.id-conf.com" target="_blank"&gt;www.id-conf.com&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We hope that a common header style will increase recognition and ease navigation between the sites.&lt;/p&gt;
&lt;p&gt;You are welcome to visit anytime, there is always something new waiting for you &lt;img src='http://www.id-conf.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /&gt; &lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/mv3nHwluqtk" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 27 Jun 2009 09:22:34 +0200</pubDate>
			<title>The flowering of the identity store</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/06/27/the-flowering-of-the-identity-store/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/06/27/the-flowering-of-the-identity-store/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;&lt;img class="alignnone size-full wp-image-74" title="datastore_diagram" src="http://blogs.kuppingercole.com/cole/wp-content/uploads/datastore_diagram.jpg" alt="datastore_diagram" width="595" height="398" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;The Personal Data Eco-System (diagram by Iain Henderson and Drummond Reed)&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Another reason I really love Twitter: It takes you places you might never have found on your own. Take a recent post by &lt;a href="http://twitter.com/xmlgrrl"&gt;xmlgrrl&lt;/a&gt;, a.k.a. Eve Maler of Sun Microsystems, a terse pointer to a posting by Iain Henderson of &lt;a href="mydex.org"&gt;Mydex &lt;/a&gt;on &lt;a href="http://www.rightsideup.net/?p=273"&gt;rightsideup.net&lt;/a&gt; entitled &amp;#8220;The Personal Data Eco-System&amp;#8221; which provides by far the best theoretical overview that I, at least, have seen on the true nature and function of personal data.&lt;/p&gt;
&lt;p&gt;The text is an abstract of a session Ian and his pal Drummond Reed of &lt;a href="http://www.cordance.net"&gt;Concordance&lt;/a&gt;, who is also a trustee of &lt;a href="http://www.idcommons.net"&gt;identitycommons&lt;/a&gt;, held at a recent &lt;a href="http://cyber.law.harvard.edu/projectvrm/VRM_West_Coast_Workshop_2009"&gt;West Coast VRM Workshop&lt;/a&gt; and which is also intended as an introduction to the &lt;a href="http://kantarainitiative.org"&gt;Kantara &lt;/a&gt;workgroup where they hope to explore these scenarios more deeply.   The focus of the piece is on what Iain and Drummond describe as &amp;#8220;Personal Data Stores&amp;#8221;, a slightly confusing term for a kind of data warehouse in which to store all the personal data available about me (or you) so that it can be used for anything from paying a credit card bill to scheduling a doctor&amp;#8217;s appointment or even planning a home move.&lt;/p&gt;
&lt;p&gt;But where it gets really exciting is when the two start to discuss what kind of data there is about me (or you) , what the relationship is between the different kinds of data and how they interact. Basically, they divide all personal data into five categories:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;My Data&lt;/strong&gt; (information about me that I, and only I, own and control)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Your Data&lt;/strong&gt; (information about me that someone else &amp;#8211; e.g. an organization or the government &amp;#8211; owns and controls)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Our Data&lt;/strong&gt; (information about me that is accessible to both me and them, e.g. buyer and seller)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Their Data&lt;/strong&gt; (information about me that is owned and sold by third parties such as a credit card company)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Everybody&amp;#8217;s Data&lt;/strong&gt; (information about me that is in the public domain, e.g. my postal address or an electoral roll)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Iain and Reed have created the absolutely fascinating flower-like Venn diagram pictured above explaining how and where these separate sorts of data intersect to create what they describe as a &amp;#8220;Basic Identifier Set&amp;#8221; in the middle. This for them is the &amp;#8220;core personal identity data and they believe it will enable a working &amp;#8220;personal identity eco-system&amp;#8221; for providing services and ensuring transactions sometime in the future, with the individual functioning as the &amp;#8220;un-knowing point of integration&amp;#8221; of data about themselves.&lt;/p&gt;
&lt;p&gt;They describe in detail the various dynamic flows of data between the different categories, such as from My Data to Your Data where individuals provide information about themselves under certain conditions (think the &amp;#8220;tick boxes&amp;#8221; on web forms indicating whether I want to receive your newsletter if I buy your product) or from Your Data to Their Data as an organization shares information about me with another organization, something which can happen legally (as in identity federation) or illegally (then it&amp;#8217;s called identity theft).&lt;/p&gt;
&lt;p&gt;I find the Henderson/Reed Diagram an extremely illuminating intellectual achievement since it illustrates the huge complexity involved in addressing issues of identity, both digital and analog. I&amp;#8217;m not so sure whether I agree with Iain&amp;#8217;s conclusion and forecast that over time (&amp;#8221;in 10 years&amp;#8221;) some 80% of customer management processes will be driven from a &amp;#8220;My Data&amp;#8221; perspective. He argues that the rush for user-generated content, as well as economic reasons, will cause organizations to move to a user-controlled model of identity management.&lt;/p&gt;
&lt;p&gt;Well, I&amp;#8217;ve been around long enough to know you can multiply a given prognosis involving a ten-year timeframe by a factor of between two and ten and still wind up way out in left field.  But I do think they are right in assuming that there is a business case for moving towards user-controlled identity. Whether it will be, as they suggest, that allowing a vendor to mine my Personal Data Store for my consumer habits, and especially my buying intentions, will be incentive enough, or whether the prevalent model will be a simple upfront deal &amp;#8211; give me your personal information and I will give you a rebate or cash in hand &amp;#8211; I don&amp;#8217;t know, but until we find out it might be a good idea to contenplate the wonderfully symmetric flower petals of the identity eco-system diagram and ponder it’s implications.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/Mlhu2t_Y8H4" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 25 Jun 2009 00:00:00 +0200</pubDate>
			<title>Get the Big Picture - Managing Access beyond SAP for Cross-Enterprise Identity Governance</title> 
			<link>http://www.kuppingercole.com/podcasts/managing_access_beyond_sap.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/managing_access_beyond_sap.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In this free webinar, youll learn how an integrated identity governance approach can more effectively improve your risk posture with enterprise-wide policy enforcement, access certifications and role management across all relevant systems. By having a single view into user access rights, you will greatly improve your visibility into risky or non-compliant areas and automate your processes for managing these risks.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/managing_access_beyond_sap.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/5hLWnsiVIFo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 18 Jun 2009 13:05:38 +0200</pubDate>
			<title>Parallels wants to bring SaaS to the masses</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/06/18/parallels/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/06/18/parallels/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Just got back from my favorite neighborhood watering hole in Munich, the Cafe Wienerplatz, where I met with Soeren von Varchmin, who recently moved in next door after spending a few years in Seattle.&lt;/p&gt;
&lt;p&gt;Soeren is VP SaaS at &lt;a href="http://www.parallels.com/"&gt;Parallels&lt;/a&gt;, a company that describes itself as &amp;#8220;worldwide leader in virtualization and automation software that optimizes computing for consumers, businesses and providers&amp;#8221;. His job is to bring together Internet Providers and Services Providers (ISVs) by providing a common plattform to provision, manage and integrate applications and services over the Internet. His vision is to create a large-scale cloud computing ecosystem where software vendors and cloud operators together deliver a wide variety of services to businesses and consumers.&lt;/p&gt;
&lt;p&gt;To achieve this goal, Parallels has written what they call the &amp;#8220;Application Packaging Standard&amp;#8221; (APS) which they describe as a new application packaging format designed to help implement a Software-as-a-Service (SaaS) business model. I guess you could call is &amp;#8220;SaaS 2.0&amp;#8243; (or maybe &amp;#8220;ASP x.0&amp;#8243;), because it enables almost all industry hosting providers &amp;#8211; Parallels&amp;#8217; traditional customer base &amp;#8211; to team up with almost any application provider to offer their apps as a rental web service.&lt;/p&gt;
&lt;p&gt;Once packaged in the APS format &amp;#8211; basically just an XML feed &amp;#8211; by a software vendor, an application can be easily &amp;#8220;plugged&amp;#8221; into an infrastructure of any hosting provider that implemented the standard &amp;#8220;socket&amp;#8221; for the APS applications.&lt;/p&gt;
&lt;p&gt;Soeren thinks this is a real win-win situation, since it gives hosting providers a new, higher-value business model while providing a new distribution channel for ISVs. Parallels is touting their standard as an open plattform, and rumor has it that they will be founding a non-profit organization to push the specification in the public domain., so check out their website at www.apsstandard.org for updates.&lt;/p&gt;
&lt;p&gt;&lt;span id="more-66"&gt;&lt;/span&gt;The reason I was interested in APS is that it contains full-fledged IdM capabilities, from Single Sign-on through provisioning, payment &amp;amp; billing, and since recently even license management, too. Since everybody is heading for the Cloud these days, I thought it would be intersting to know if APS might be a quick fix to the IdM problem in web-based applications. Soeren seems to think so. And technically, he may be right.  But of course, to make ASP a &amp;#8220;real&amp;#8221; standard he&amp;#8217;ll have to generate a lot more interest in the IdM community.&lt;/p&gt;
&lt;p&gt;Right now, Parallels is big in the provider and hosting market. Their boast is that, out of about 200 million domains in the world, between 30 and 40 million are powered by their software. Or putting it another way, just aboiut every major Internet Provider in the business is a customer of theirs. But simple hosting and plumbing isn&amp;#8217;t all that sexy anymore, and big cloud operators like Amazon, Google, 1&amp;amp;1 or Strato are on the lookout for extra sources of income. By hitching them up with ISVs and SaaS vendors like Salesforce et al. they could conceivably tap into some pretty substantial new revenue streams, especially SMEs who find it appealing to rent IT infrastructure and applications instead of buying.&lt;/p&gt;
&lt;p&gt;I asked Soeren if APS could also work as a platform for providing identity as a service, and he liked the idea. After all, if the platform can handle SSO and payment in a safe and scalable fashion, why not use it as a kind of universal identity provider for the Cloud instead of building IdM capability directly into the app?&lt;/p&gt;
&lt;p&gt;On the other hand, Parallels still has its work cut out for it convincing the thousands and thousands of ISVs out there to plug their existing solutions &amp;#8211; whether already SaaS-enabled or legacy &amp;#8211; into APS.&lt;/p&gt;
&lt;p&gt;Yeah, it makes sense businesswise, but anyone who has every tried to push a standard knows just how innovation-resistant people in the IT industry can be. But with Soeren living right around the corner now, I&amp;#8217;ll be able to check back every time we run across each other at Cafe Wienerplatz, so stay tuned.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/bCNF3l8g34A" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 17 Jun 2009 00:00:00 +0200</pubDate>
			<title>Messbare Vorteile für Sicherheit und Kosten durch Single Sign-On mit starker Authentifizierung</title> 
			<link>http://www.kuppingercole.com/podcasts/sso_mit_starker_authentifizierung.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/sso_mit_starker_authentifizierung.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In diesem Webinar wird auf den quantitativen und qualitativen Nutzen von Enterprise Single Sign-On-Projekten in Verbindung mit starker Authentifizierung eingegangen.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/sso_mit_starker_authentifizierung.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/gBHeW4uUUmM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 16 Jun 2009 20:47:41 +0200</pubDate>
			<title>Hooray, LDAPcon 2009 is coming up!</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/06/16/hooray-ldapcon-2009-is-coming-up/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/06/16/hooray-ldapcon-2009-is-coming-up/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I was delighted when I saw that &lt;a href="http://www.symas.com/ldapcon2009/"&gt;LDAPcon is happening again this year&lt;/a&gt;. I went to the first event in Cologne, Germany 2007, and was very impressed. When you have the &amp;#8220;creme de la creme&amp;#8221; from the LDAP community talking about their favourite topic, you&amp;#8217;re guaranteed an interesting and exhiliarating time &amp;#8211; assuming that LDAP and directories are your thing.&lt;/p&gt;
&lt;p&gt;I still remember last time how Howard Chu gave us a musical demonstration of how a well-performing directory should perform &amp;#8211; on the violin! I don&amp;#8217;t think anybody forgot that. We also got a very good overview of the different open source projects around directories, and about how to make good use of some of the LDAP extensions.&lt;/p&gt;
&lt;p&gt;This time, we&amp;#8217;ll also have two action-packed days, and the &lt;a href="http://www.symas.com/ldapcon2009/call-for-papers.shtml"&gt;call for papers&lt;/a&gt; is open. I encourage everybody to share their best practises, vision and thought and make this an unforgettable event as well. I&amp;#8217;ll be submitting for sure &lt;img src='http://blogs.kuppingercole.com/gaehtgens/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /&gt; &lt;/p&gt;
&lt;p&gt;LDAPcon takes place in Portland and starts on September 20, a day before LinuxCon. The second day will be shared with LinuxCon, it seems. Might as well stay for LinuxCon as well! This is a good event not just for directory vendors and project maintainers, but especially also for those who deploy and run LDAP directories in challenging environments, and those who develop software that talks to LDAP servers. Kudos to the Symas guys for helping organise it (and they are just helping to organise it &amp;#8211; it&amp;#8217;s not at all an OpenLDAP conference, if that what you&amp;#8217;re thinking). I&amp;#8217;m definitely looking forward to it!&lt;/p&gt;
&lt;p&gt;BTW I just saw that &lt;a href="http://blogs.sun.com/Ludo/entry/ldapcon_2009_call_for_papers"&gt;Ludo wrote about it as well&lt;/a&gt;, and even posted some photos from the 2007 event.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/0iyGEM7CVKo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 11 Jun 2009 16:59:11 +0200</pubDate>
			<title>UnboundID launches frontal attack on Sun – good idea??</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/06/11/unboundid-launches-frontal-attack-on-sun-good-idea/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/06/11/unboundid-launches-frontal-attack-on-sun-good-idea/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I recently received a press release from UnboundID announcing the availability of a new &amp;#8220;synchronization server&amp;#8221;. This software keeps two LDAP servers in sync (as the name suggests) &amp;#8211; bidirectionally. In theory very useful, and it&amp;#8217;s free too. But there&amp;#8217;s a small trick: the synchronization server supports both Sun&amp;#8217;s DSEE (Directory Server Enterprise Edition) and the new Unbound ID Directory Server. In the release, Unbound ID makes no secret of what this software should be used for: to migrate away from Sun&amp;#8217;s directory toward Unbound ID&amp;#8217;s competing solution.&lt;/p&gt;
&lt;p&gt;UnboundID is a start-up based out of Austin, TX. It was founded by several ex-Sun employees, including Neil Wilson, author of the &amp;#8220;slamd&amp;#8221; load generation engine, and formerly one of the key people behind Sun&amp;#8217;s OpenDS. I have already raved about their new LDAP SDK for Java, in my opinion the finest and most complete LDAP development kit for any language ever written.&lt;/p&gt;
&lt;p&gt;The company is going after the very lucrative Telco and large service provider market, and launched a frontal attack on Sun Microsystems, who is the market leader in that space. UnboundID is offering a 30-40% reduction in yearly maintenance costs if customers switch from DSEE to their solution. Of course there is the usual fine print, and this offer is limited to medium-sized directories with less than two million entries. Why should Sun customers switch from DSEE to UnboundID Directory? According to UnboundID, their server is faster, has less footprint and is supported on a wider platform range.&lt;/p&gt;
&lt;p&gt;It is not really obvious to me however why Telcos and large service providers would want to switch. For one, DSEE has been the de-facto market leader for massive-scale directory services, and customer satisfaction is high (not just if you believe the marketing &amp;#8211; I&amp;#8217;ve personally heard the same from Telcos using the product). A directory server running in a Telco is an absolutely super-critical component, and ripping it out and replacing it is akin to heart surgery. DSEE is very mature after having been around for many years and the kinks have been ironed out in many very large deployments a long time ago already (in fact, I was in one of those deployments in 2002 &amp;#8211; that was fun). UnboundID would obviously need to make a very good case and give organisations a high level of assurance for them to switch over. The Telco sector is much more innovative than others, and tends to be on the bleeding edge of technology &amp;#8211; but even so, there is a reluctance to switch from a very mature product that &amp;#8220;just works&amp;#8221; to a brand-new product.&lt;/p&gt;
&lt;p&gt;That&amp;#8217;s why UnboundID offers the &amp;#8220;synchronization server&amp;#8221; in order to try to entice organisations to run both directory servers next to each other for a longer period &amp;#8211; to evaluate and eventually become comfortable enough with the UnboundID server to make the switch. It seems that the &amp;#8220;synchronization server&amp;#8221; has been written specifically for this purpose.&lt;/p&gt;
&lt;p&gt;Which, personally speaking, I think is a bit of a pity, but hopefully UnboundID will realise the immense value that this synchronisation server could have once they&amp;#8217;ve gotten over their frontal attack on Sun. A generic synchronization server that would keep multiple directories from multiple vendors synchronised is a fantastic value proposition, and I&amp;#8217;m sure many organisations would jump at it. Especially when it comes from such brilliant minds like Neil Wilson&amp;#8217;s who is known for his awesome LDAP stuff.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/aylW9Y3eLv4" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 19 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Marina Walser, Novell</title> 
			<link>http://www.kuppingercole.com/podcasts/070509_interview_walser.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/070509_interview_walser.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Tim Cole interviews Marina Walser at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/070509_interview_walser.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/UUd-EEuWqs0" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 19 May 2009 00:00:00 +0200</pubDate>
			<title>EIC Impressions</title> 
			<link>http://www.kuppingercole.com/podcasts/070509_interview_impressions.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/070509_interview_impressions.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; A few short interviews from the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/070509_interview_impressions.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/cfXDvY54zc8" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 19 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Kim Cameron, Microsoft</title> 
			<link>http://www.kuppingercole.com/podcasts/070509_interview_cameron.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/070509_interview_cameron.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Tim Cole interviews Kim Cameron at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/070509_interview_cameron.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/RlVHujDv-8A" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 19 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Fulup Ar Foll, Sun Microsystems</title> 
			<link>http://www.kuppingercole.com/podcasts/070509_interview_arfoll.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/070509_interview_arfoll.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Tim Cole interviews Fulup Ar Foll at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/070509_interview_arfoll.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/lQgWnG4Hbjo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 18 May 2009 23:17:18 +0200</pubDate>
			<title>EIC impressions</title> 
			<link>http://www.id-conf.com/blog/2009/05/18/eic-impressions/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/18/eic-impressions/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;A few more short interviews from the conference&lt;br /&gt;
&lt;object width="425" height="344" data="http://www.youtube.com/v/u90aR4qQdnk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0" type="application/x-shockwave-flash"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/v/u90aR4qQdnk&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;/object&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/bMPDfX9i8Jo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 18 May 2009 17:34:55 +0200</pubDate>
			<title>Interview with Kim Cameron</title> 
			<link>http://www.id-conf.com/blog/2009/05/18/interview-with-kim-cameron/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/18/interview-with-kim-cameron/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Interview with Kim Cameron, Microsoft&lt;br /&gt;
&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/1hT3hfxuZRU&amp;#038;hl=en&amp;#038;fs=1&amp;#038;rel=0"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/1hT3hfxuZRU&amp;#038;hl=en&amp;#038;fs=1&amp;#038;rel=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/fH7aRPJGtgE" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 17 May 2009 05:43:02 +0200</pubDate>
			<title>The Lost Chapters of EIC</title> 
			<link>http://www.id-conf.com/blog/2009/05/17/the-lost-chapters-of-eic/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/17/the-lost-chapters-of-eic/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Today we&amp;#8217;ve been finally able to get our hands on a tape we almost believed to be lost forever. But thanks to our video technicians we can now present you a few more interviews from the EIC 2009.&lt;/p&gt;
&lt;p&gt;Interview with Marina Walser, Novell EMEA&lt;br /&gt;
&lt;object width="425" height="344" data="http://www.youtube.com/v/EQF4HnjJ1CY&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0" type="application/x-shockwave-flash"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/v/EQF4HnjJ1CY&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;Interview with Fulup Ar Foll, Sun Microsystems (yes, another one!)&lt;br /&gt;
&lt;object width="425" height="344" data="http://www.youtube.com/v/r1KvfEULBxw&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0" type="application/x-shockwave-flash"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/v/r1KvfEULBxw&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;Stay tuned for more.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/ev1eDmpy7to" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 15 May 2009 02:10:47 +0200</pubDate>
			<title>Keynote by Kim Cameron, Microsoft</title> 
			<link>http://www.id-conf.com/blog/2009/05/15/keynote-by-kim-cameron-microsoft/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/15/keynote-by-kim-cameron-microsoft/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;&lt;object width="480" height="385" data="http://www.youtube.com/p/AA5454357BD8AF31&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/p/AA5454357BD8AF31&amp;amp;hl=en&amp;amp;fs=1" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.id-conf.com/sessions/574" target="_blank"&gt;The Road to Claims: From Vision to Reality&lt;/a&gt;&lt;br /&gt;
Kim Cameron, Microsoft&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/NUx6lscsC-g" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 14 May 2009 19:30:25 +0200</pubDate>
			<title>Keynote by Marina Walser, Novell</title> 
			<link>http://www.id-conf.com/blog/2009/05/14/keynote-by-marina-walser-novell/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/14/keynote-by-marina-walser-novell/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;&lt;object width="480" height="385" data="http://www.youtube.com/p/19353F3BF092A44F&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/p/19353F3BF092A44F&amp;amp;hl=en&amp;amp;fs=1" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.id-conf.com/sessions/509" target="_blank"&gt;SAP-GRC-IdM &amp;#8211; What is the Problem?&lt;/a&gt;&lt;br /&gt;
Marina Walser, Novell EMEA&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/6vWB3SkJOWU" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 13 May 2009 21:53:08 +0200</pubDate>
			<title>Keynote by John Aisien, Oracle</title> 
			<link>http://www.id-conf.com/blog/2009/05/13/keynote-by-john-aisien-oracle/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/13/keynote-by-john-aisien-oracle/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;&lt;object width="480" height="385" data="http://www.youtube.com/p/C28FE0702A21C47F&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/p/C28FE0702A21C47F&amp;amp;hl=en&amp;amp;fs=1" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.id-conf.com/sessions/510" target="_blank"&gt;Enterprise IT-enabled Cost Avoidance &amp;amp; Reduction: The Role of Identity &amp;amp; Access Management&lt;/a&gt;&lt;br /&gt;
John Aisien, Oracle Corporation&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/tVEyqMpUoNc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 13 May 2009 16:02:47 +0200</pubDate>
			<title>Keynote by Eve Maler, Sun Microsystems</title> 
			<link>http://www.id-conf.com/blog/2009/05/13/keynote-by-eve-maler-sun-microsystems/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/13/keynote-by-eve-maler-sun-microsystems/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;We&amp;#8217;re planning to upload selected EIC 2009 keynotes to YouTube and here is the first one.&lt;/p&gt;
&lt;p&gt;&lt;object width="480" height="385" data="http://www.youtube.com/p/8CF44184B5C40205&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash"&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="allowscriptaccess" value="always" /&gt;&lt;param name="src" value="http://www.youtube.com/p/8CF44184B5C40205&amp;amp;hl=en&amp;amp;fs=1" /&gt;&lt;param name="allowfullscreen" value="true" /&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.id-conf.com/sessions/501" target="_blank"&gt;The Care and Feeding of Online Relationships&lt;/a&gt;&lt;br /&gt;
Eve Maler, Sun Microsystems&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/Q9QCYw_F4VE" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 16:08:46 +0200</pubDate>
			<title>EIC 2009 presentations and keynotes</title> 
			<link>http://www.id-conf.com/blog/2009/05/12/eic-2009-presentations-and-keynotes/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/12/eic-2009-presentations-and-keynotes/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Just like last year, registered participants of the EIC 2009 have access to all presentations and keynote videos in the special area of Kuppinger Cole web site.&lt;/p&gt;
&lt;p&gt;We have sent a personal direct link to that area in an e-mail to every participant, so please check your inbox!&lt;/p&gt;
&lt;p&gt;If you haven&amp;#8217;t received such an mail from Kuppinger Cole, it could be that we do not know your address yet. In this case please contact &lt;a href="mailto:lk@kuppingercole.com"&gt;Mr. Levent Kara&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/X53VVX2XWeA" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Dr. Babak Sadighi, Axiomatics AB</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_interview_sadighi.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_interview_sadighi.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Felix Gaehtgens interviews Dr. Babak Sadighi at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_interview_sadighi.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/eNQhxi6Tj7Y" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Identity Management in the Focus of eGovernment and Vertical Solutions</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_keynote_4_erlinghagen.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_keynote_4_erlinghagen.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Keynote at the European Identity Conference 2009&lt;/p&gt;&lt;p&gt;by &lt;strong&gt;Sabine Erlinghagen&lt;/strong&gt;, Siemens IT Solutions and Services &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_keynote_4_erlinghagen.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/-g-cvcYCLJs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Dr. Prateek Mishra, Oracle</title> 
			<link>http://www.kuppingercole.com/podcasts/070509_interview_mishra.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/070509_interview_mishra.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;a href="http://www.youtube.com/watch?v=4jQXSNkMc8I&amp;amp;feature=channel" title="Dr. Prateek Mishra Interview"&gt;&lt;/a&gt;Felix Gaehtgens interviews Dr. Prateek Mishra at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/070509_interview_mishra.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/L-8xIUdhXps" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Prof. Dr. Rob Fijneman, KPMG</title> 
			<link>http://www.kuppingercole.com/podcasts/070509_interview_fijneman.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/070509_interview_fijneman.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Tim Cole interviews Dr. Rob Fijneman at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/070509_interview_fijneman.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/JoF46NPfDDM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Berthold Kerl, Deutsche Bank</title> 
			<link>http://www.kuppingercole.com/podcasts/070509_interview_kerl.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/070509_interview_kerl.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Tim Cole interviews Berthold Kerl at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/070509_interview_kerl.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/iBT51Gwj1tw" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Is there a difference between the European way of doing IAM/GRC and the rest of the world?</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_keynote_2_panel.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_keynote_2_panel.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Keynote at the European Identity Conference 2009&lt;/p&gt; 												 												 												&lt;div&gt;by &lt;strong&gt;Paul Heiden&lt;/strong&gt;, BHOLD COMPANY BV,&lt;strong&gt; Prof. Dr. Audun Josang&lt;/strong&gt;, Queensland University of Technology, and Oslo University, &lt;strong&gt;Darran Rolls&lt;/strong&gt;, Sailpoint, &lt;strong&gt;Chris Harvison&lt;/strong&gt;, Scotiabank&lt;/div&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_keynote_2_panel.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/uVgUWJygad8" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Identity Management &amp; GRC 2009 - 2019</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_keynote_1_kuppinger.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_keynote_1_kuppinger.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Opening keynote at the European Identity Conference 2009&lt;/p&gt;&lt;p&gt;by &lt;strong&gt;Martin Kuppinger&lt;/strong&gt;, Kuppinger Cole + Partner &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_keynote_1_kuppinger.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/YDwBPeQ-39g" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>The Road to Claims: From Vision to Reality</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_keynote_3_cameron.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_keynote_3_cameron.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Keynote at the European Identity Conference 2009&lt;/p&gt;&lt;p&gt;by &lt;strong&gt;Kim Cameron&lt;/strong&gt;, Microsoft &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_keynote_3_cameron.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/b3_2DU6g8CE" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Dale Olds, Novell</title> 
			<link>http://www.kuppingercole.com/podcasts/060509_interview_olds.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/060509_interview_olds.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Felix Gaehtgens interviews Dale Olds at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/060509_interview_olds.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/r9b7X879oVg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Identity Management Systems as a Risk?</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_keynote_7_vonderhude.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_keynote_7_vonderhude.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Keynote at the European Identity Conference 2009&lt;/p&gt;&lt;p&gt;by &lt;strong&gt;Niels von der Hude&lt;/strong&gt;, Beta Systems Software &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_keynote_7_vonderhude.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/MwzrXVPA5lo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>The Care and Feeding of Online Relationships</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_keynote_8_maler.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_keynote_8_maler.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Keynote at the European Identity Conference 2009&lt;/p&gt;&lt;p&gt;by &lt;strong&gt;Eve Maler&lt;/strong&gt;, Sun Microsystems &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_keynote_8_maler.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/JNwi-slLoKQ" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Eve Maler, Sun Microsystems</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_interview_maler.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_interview_maler.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Felix Gaehtgens interviews Eve Maler at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_interview_maler.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/XbrzavWoCeY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Pat Patterson, Sun microsystems</title> 
			<link>http://www.kuppingercole.com/podcasts/050509_interview_patterson.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/050509_interview_patterson.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Felix Gaehtgens interviews Pat Patterson at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/050509_interview_patterson.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/UmJmu_QcRX0" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Anthony Nadalin, IBM</title> 
			<link>http://www.kuppingercole.com/podcasts/060509_interview_nadalin.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/060509_interview_nadalin.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Felix Gaehtgens interviews Anthony Nadalin at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/060509_interview_nadalin.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/E3H01J-f8CQ" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 12 May 2009 00:00:00 +0200</pubDate>
			<title>Interview with Fulup Ar Foll, Sun Microsystems</title> 
			<link>http://www.kuppingercole.com/podcasts/060509_interview_arfoll.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/060509_interview_arfoll.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Felix Gaehtgens interviews Fulup Ar Foll at the European Identity Conference 2009&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/060509_interview_arfoll.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/afUAZDbf5Vg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 11 May 2009 15:35:42 +0200</pubDate>
			<title>Kuppinger Cole on Twitter</title> 
			<link>http://www.id-conf.com/blog/2009/05/11/kuppinger-cole-on-twitter/</link> 
			<guid>http://www.id-conf.com/blog/2009/05/11/kuppinger-cole-on-twitter/</guid> 
			<description>In &lt;a href="http://www.id-conf.com/blog"&gt;European Identity Conference Blog&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;You can follow &lt;a href="http://twitter.com/kuppingercole" target="_blank"&gt;@kuppingercole&lt;/a&gt; on Twitter to get the latest news from Kuppinger Cole web site in real time.&lt;/p&gt;
&lt;p&gt;Or maybe you&amp;#8217;ll be interested to follow our employees&amp;#8217; own accounts: &lt;a href="http://twitter.com/TCole1066" target="_blank"&gt;@TCole1066&lt;/a&gt;, &lt;a href="http://twitter.com/balaganski" target="_blank"&gt;@balaganski&lt;/a&gt;, &lt;a href="http://twitter.com/Lefti09" target="_blank"&gt;@Lefti09&lt;/a&gt;, &lt;a href="http://twitter.com/joergresch" target="_blank"&gt;@joergresch&lt;/a&gt;, &lt;a href="http://twitter.com/BettinaButhmann" target="_blank"&gt;@BettinaButhmann&lt;/a&gt;. I&amp;#8217;m sure others will join soon &lt;img src='http://www.id-conf.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /&gt; &lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/tMidOdQxIQc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 09 May 2009 08:31:45 +0200</pubDate>
			<title>My Twitter Top Ten</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/05/09/my-twitter-top-ten/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/05/09/my-twitter-top-ten/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I know it&amp;#8217;s funny, but in fact it&amp;#8217;s me, by far the oldest guy at KCP, who is actually the greatest fan of Twitter. Perhaps if you don&amp;#8217;t have as much time left to waste as some of my younger colleagues you learn to appreciate abbreviation.&lt;/p&gt;
&lt;p&gt;Anyway, the European Identity Conference which ended yesterday here in Munich produced a bumper crop of Tweets which I have been browsing through this morning at my leisure (first time in a week I&amp;#8217;v had any), and I thought I would share a few with those of you who do not yet fully appreciate just how powerful this new medium actually is.&lt;/p&gt;
&lt;p&gt;Summing up of a large multinational conference like EIC running over many days and featuring some of the finest speakers in the industry, and doing this in a format that restricts the writer to 140 characters max, is a challenge, of course, but many of those present not only rose to it, but proved themselves past masters of terse, to-the-point, no nosense (well actually, sometimes a bit of nonsense) communication.&lt;/p&gt;
&lt;p&gt;&lt;span id="more-52"&gt;&lt;/span&gt;Kudos to Bavo de Ridder of Acerta, a Belgian IdM specialist, who ran away with the title &amp;#8220;Most Prolific Twitterer&amp;#8221; at EIC. Not only did he produce approximately twice as many Tweets as even I, no mean Twitterer myself, managed to thumb into my Palm Treo. We actually at times managed to engage in a twittered dialog, for instance when I posted &amp;#8220;Fulup Ar Foll (Sun): &amp;#8216;Roles will not fly in the Cloud&amp;#8217;&amp;#8221;, to which his immediate response was: &amp;#8220;@TCole1066 those cases where roles do fly (elegantly) are mostly those cases where roles have a simple attribute relation&amp;#8221;&lt;/p&gt;
&lt;p&gt;Sometimes our online conversations took a twirky turn, like when Martin Kuppinger gave his keynote and Bavo twittered. &amp;#8220;Attending &amp;#8220;Beyond the hype &amp;#8211; a strategical approach to cloud computing&amp;#8221; (I see hype in that title)&amp;#8221;, leading me to ponder on the &amp;#8220;Philosophical question: Is hyping hype a double positive or a double negative?&amp;#8221;.&lt;/p&gt;
&lt;p&gt;The runner up, by the way, was Heide Groshelle of Groshelle Communications, a San Francisco based PR consultancy who helped KCP get thge message about EIC out to the masses and who turns out to be at least equally at home in both the old media and the new.&lt;/p&gt;
&lt;p&gt;Tweets turned up from many of the &amp;#8220;big guns&amp;#8221; in our industry such as Sun&amp;#8217;s Eve Maler (&amp;#8221;@xmlgirl&amp;#8221;), Novel&amp;#8217;s Dale Olds (&amp;#8221;@daleolds&amp;#8221;) and Quest&amp;#8217;s Jackson Shaw (&amp;#8221;@jacksonshaw&amp;#8221;). And some like @vibronet, another non-stop Twitterer, chose to remain anonymous, which anyone is perfectly entitled to do on Twitter (one of the rapidly dwindling number of places on the Internet where you still are allowed to wear a mask in public).&lt;/p&gt;
&lt;p&gt;Anyway, for what it&amp;#8217;s worth, I give you here, dear reader, my personal list of favorites culled from 32 pages of conference postings as my very own&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Top Ten Tweets From EIC 09&lt;/strong&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;1.  &amp;#8220;not sure who of you is currently at #eic in munich, but it&amp;#8217;s the #1 identity conference in europe and def worth checking out.&amp;#8221;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
2.    &amp;#8221; Fulup &amp;#8220;user centric for me is a joke&amp;#8221; &amp;#8230; thank god Dick Hardt is not at this conference &amp;#8230; would have been a good fight though”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
3.    &amp;#8220;Falling cows are a huge risk since the outcome is fatal, but the probability is low. GRC is about weighing the two. Thanks Dave Kearns!&amp;#8221;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
4.    &amp;#8220;If personal information dealers would care about your consent they&amp;#8217;d ask &amp;#8211; they&amp;#8217;ve got my email&amp;#8230;&amp;#8221;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
5.    &amp;#8220;Can IdM create risk? Yes, says Niels v.d. Hude of Beta Sys. It&amp;#8217;s a single point of failure and itself should be monitored and audited&amp;#8221;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
6.    &amp;#8220;Kim Cameron states Microsoft will make Active Directory the &amp;#8220;motor&amp;#8221; for accepting and emitting claims via the Geneva STS server&amp;#8230;cool!&amp;#8221;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
7.    &amp;#8220;OMG, I&amp;#8217;ve been working on enterprise spaghetti for the last twenty years!&amp;#8221;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
8.    “Google mentioned in the keynote &amp;#8230; where is google in this conference ???”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
9.    “As long as compliance is treated as a burden, there is a systemic risk that will periodically result in (catastrophic) failures”&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;br /&gt;
10.    “Thanks all for a great #eic C u all next year!”&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/XMtyhRiP-rs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 04 May 2009 08:50:27 +0200</pubDate>
			<title>Where in the Cloud am I?</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/05/04/where-in-the-cloud-am-i/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/05/04/where-in-the-cloud-am-i/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Recently, at a press briefing by German IBM boss Stefan Jetter who waxed enthusiastic about Cloud Computing, an elderly journalist rose and asked him a show-stopper: “Where are my data when they’re out there in the Cloud?” Jetter did a double take, but my colleague pressed on: “I mean, physically, where are they?”&lt;/p&gt;
&lt;p&gt;Of course, the answer is: On some nameless server somewhere, anywhere in a grid farm in Ohio or Dublin or… In fact, the usual answer is : Who cares?&lt;/p&gt;
&lt;p&gt;Well, for one the German privacy protection agencies. Passing data across national boundaries can be a federal offense not only here. The &lt;a href="http://en.wikipedia.org/wiki/Data_Protection_Directive#Transfer_of_personal_data_to_third_countries"&gt;EU Data Protection Directive&lt;/a&gt; (officially Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data) mandates that personal data may only be transferred to third countries if that country provides an adequate level of protection – something the U.S., just to name one, does not, at least not according to European standards, especially since foreigners do not benefit from the US Privacy Act of 1974.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.crunchbase.com/person/martin-buhr"&gt;&lt;span id="more-43"&gt;&lt;/span&gt;Martin Buhr&lt;/a&gt;, the European head of Amazon&amp;#8217;s Web Services (@tallmartin on Twitter) and the champion of Amazon’s &lt;a href="http://aws.amazon.com/ec2/"&gt;Elastic Compute Cloud&lt;/a&gt; (EC2), with whom I shared a recent panel on Cloud Computing, has a pragmatic solution to the question of where to store data in the Cloud and whether or not location matters. Amazon operates separate Cloud Computing centers in the States and in Ireland, so problem solved. Or is it?&lt;/p&gt;
&lt;p&gt;Operating what are essentially two Clouds (called “Availability Zones”), each running on its own physically distinct, independent infrastructure, makes sense from a data center perspective. Common points of failures like generators and cooling equipment are not shared across AZs. This sounds similar to the common practice of data center redundancy, but normally this is done to ensure operational security. Data are mirrored back and forth constantly so if one center goes down, the other can pick up immediately. But in this case, at least theoretically, there is no redundancy since these are essentially two separate systems.&lt;/p&gt;
&lt;p&gt;Only, of course, they aren’t. So Amazon has added a system whereby EC2 assigns regional IP addresses to its customers, so presumably it is easy to determine which data can travel across the Atlantic and which can’t. I don’t want to get into a long discussion about IP spoofing and similar technologies developed to foil state-run censorship systems like the Great Firewall of China, but you get the general idea. Okay, they use IPv4, but Version 4 addresses are a scarce resource. And yes, they claim they have compliance options that will make hosting data in the Cloud both safe and legal.&lt;/p&gt;
&lt;p&gt;Maybe I’m cynical, but I’ve been around too long and heard too many tales of supposedly fail-safe systems being compromised by whiz-kids or Russian Mafiosi to really believe that quick fixes on the infrastructure level will hold out forever. I would prefer to see Amazon and others in the Cloud community discussing user-centric identity-based approaches to the problem instead of essentially saying: “Trust us” I’m pretty sure my elderly colleague won’t. He’d like to be able to check out for himself exactly where somebody put his data.&lt;/p&gt;
&lt;p&gt;PS: Maybe we&amp;#8217;ll hear more on this at &lt;a href="http://www.id-conf.com/eic2009"&gt;EIC 09 &lt;/a&gt;which starts tomorrow in Munich. If you&amp;#8217;re interested, stop by my panel on &amp;#8220;&lt;a style="text-decoration: none;" href="http://www.id-conf.com/tracks/77"&gt;(User Centric) Identity in the Cloud&lt;/a&gt;&amp;#8221; which is scheduled for 2 pm on Tuesday.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/XduqAPEdz1M" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 23 Apr 2009 00:00:00 +0200</pubDate>
			<title>Enterprise Single Sign-On in der Praxis</title> 
			<link>http://www.kuppingercole.com/podcasts/enterprise_sso_praxis.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/enterprise_sso_praxis.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Konfrontiert mit einer zunehmenden Flut an Passworten für Benutzerkonten in einer steigenden Zahl an Anwendungen, gewinnt das unternehmensweite Single Sign-on zunehmend an Bedeutung. Einerseits zur Steigerung der Produktivität und zur Reduzierung der Helpdesk-Kosten, andererseits aber auch für ein Mehr an Sicherheit. Lernen Sie in diesem praxisorientierten Webinar anhand konkreter Projektbeispiele, den Nutzen eines E-SSO Systems für Ihr Unternehmen optimal zu erschliessen.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/enterprise_sso_praxis.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/mlmTfiDVcGs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 22 Apr 2009 18:00:20 +0200</pubDate>
			<title>Sun integrates MySQL with IDM Offering</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/04/22/sun-integrates-mysql-with-idm-offering/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/04/22/sun-integrates-mysql-with-idm-offering/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Sun Microsystems has just announced at the annual MySQL Conference that it is adding extended support for MySQL into its Identity Management stack. That&amp;#8217;s great, but what does it mean? For one, MySQL is hugely popular &amp;#8211; starting off as an embedded open source database, and slowly but surely pushing into the enterprise RDBMS area over the years. Most enterprises use MySQL somewhere &amp;#8211; some of them use MySQL strategically (i.e.: if you need a database, consider MySQL as one of the option, or even as the default option).&lt;/p&gt;
&lt;p&gt;So what does this have to do with identity management? Most databases are used by applications, and many of these application have some user schema in their databases. This means that identity information is widely dispersed through very many different databases throughout the enterprise, like a mosaic. Identity management over the years has been making the promise to consolidate, bind together and manage identity information, and Sun Microsystems has an extensive identity management offering that does exactly that. Sun&amp;#8217;s added support for MySQL with their entire identity stack takes this to a new level by allowing organizations to bind together data regardless of whether it is stored in an classic directory or relational database.&lt;/p&gt;
&lt;p&gt;For one, Sun Microsystems has enhanced and strengthened the links between MySQL and the two directory servers: DSEE and OpenDS. DSEE (Directory Server Enterprise Edition) is Sun Microsystems&amp;#8217; flagship directory server that combines essential enterprise features with carrier class scalability. OpenDS started off as a project to be Sun&amp;#8217;s next generation directory product line, and is very successful as an embedded directory. In several years, OpenDS is due to replace Sun&amp;#8217;s current flagship directory server, DSEE (Directory Server Enterprise Edition).&lt;/p&gt;
&lt;p&gt;The enhanced integration brings numerous advantages to both enterprise and telco directory scenarios, and I&amp;#8217;ll go through them briefly. Let&amp;#8217;s start with the Telcos, as it is always impressive to talk about massive scalability, availability and speed. MySQL can be used as a back-end data store for OpenDS, Sun&amp;#8217;s open source directory server. According to an announcement made yesterday, OpenDS Standard edition can be integrated with MySQL Cluster.  When used together, the OpenDS provides the LDAP directory front-end to a rock-solid, clustered relational database. This is really interesting for Telcos, service providers and other very large directory users that need scalability and have very high availability requirements. Using a clustered relational database such as MySQL Cluster as a back-end for OpenDS allows administrators to gain extra flexibility for data management which comes in really handy when the amount of data is massive. It also give more options for providing a on-stop directory service. LDAP Directory servers are typically deployed as a set of equivalent multi-master servers &amp;#8211; each &amp;#8220;master&amp;#8221; managing an autonomous copy of the data set. A replication mechanism is then used to keep all masters in synch. Now add the clustering features, and the resulting mix is like a swiss army knife for those that need the ultimate flexibility and resilience in directory services.&lt;/p&gt;
&lt;p&gt;In fact after this integration, OpenDS and OpenLDAP are the only directory servers that allows users to choose either a &amp;#8220;traditional&amp;#8221; Berkeley DB based embedded backend or a relational database backend to be used. The former is great for enterprises that prefer a maintenance-free zero-administration back-end, and because of this many directory servers have traditionally used Berkeley DB. The latter, using a fully-fledged relational database as a back-end for directory servers opens up many possibilities in terms of data management, but is more difficult to manage. Traditionally, users had to choose a different product depending on whether the priority was ease of maintenance or sophisticated data management features when choosing a directory server. Now OpenDS have a choice with the same product. But not just OpenDS, Sun is actually licensing MySQL cluster as &amp;#8220;MySQL Cluster Carrier Grade Edition&amp;#8221; to be used either with OpenDS or OpenLDAP. I know quite a few LDAP directory administrators working in large Telcos, and I&amp;#8217;m sure they&amp;#8217;re thrilled.&lt;/p&gt;
&lt;p&gt;On the enterprise side, Sun has added virtual directory features to DSEE to easily link into MySQL databases. This means that data that used to be stashed away in MySQL databases can now be made easily through the LDAP protocol. Being an advanced feature of virtual directory servers, it shows Sun&amp;#8217;s  commitment to extend their virtual directory offering.&lt;/p&gt;
&lt;p&gt;But MySQL support has not just been enhanced in Sun&amp;#8217;s directory servers. Sun Identity Manager can read and provision identity data to and from any MySQL database schema, and can now even use MySQL as its primary internal data repository. Role Manager can use MySQL as its identity warehouse. OpenSSO can also use MySQL as an identity repository. In a way this was to be expected when Sun acquired MySQL a bit more than a year ago &amp;#8211; to start building on its acquired RDBMS platform and integrate it with its other offerings, in this case Identity Management. It is actually quite impressive how fast this integration has happened when compared to other vendors who take considerably longer &amp;#8220;digesting&amp;#8221; acquisitions and combining them to maximise value.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/hCUUNUz_3OY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 16 Apr 2009 00:00:00 +0200</pubDate>
			<title>Cloud Computing  Opportunities &amp; Risk</title> 
			<link>http://www.kuppingercole.com/podcasts/cloud_cumouting_opportunities_risk.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/cloud_cumouting_opportunities_risk.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Besides having been around as a buzzword for quite some time now, current economic challenges seem to strongly increase interest in leveraging cloud computing for the enterprise, finding new competitive advantages, and of course reducing investments into internal infrastructures. In this webinar, Martin Kuppinger will discuss with you Kuppinger Cole´s "Roadmap to the Cloud" - a guideline on how to prepare for cloudsourcing initiatives.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/cloud_cumouting_opportunities_risk.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/x22XAQLiLqI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 16 Apr 2009 00:00:00 +0200</pubDate>
			<title>Controlling the Impacts of Recession on IT Security</title> 
			<link>http://www.kuppingercole.com/podcasts/controlling_impacts_of_recession.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/controlling_impacts_of_recession.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; As the recession is severely hitting most industries, type and quality of security threats are changing quickly. In this webinar, Martin Kuppinger will describe these threats and their impact on Identity and Access Management, GRC, Privileged Account Management, Data Leakage Prevention, and Information Rights Management.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/controlling_impacts_of_recession.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/ishfe33ml9Q" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 05 Apr 2009 11:42:42 +0200</pubDate>
			<title>The Digital Knee</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/04/05/the-digital-knee/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/04/05/the-digital-knee/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Since &amp;#8220;Minority Report&amp;#8221;, where Tom Cruise toted a squishy bag full of spare eyeballs around to hold up in front of iris scanners, thus fooling the access systems, biometrics has been a buzzword, if only a minor one, but it has failed to catch on in a meaningful way. A few years back I speculated that this is because every existing biometric method has serious &lt;a href="http://www.kuppingercole.com/articles/biometrie_fingerabdruck"&gt;drawbacks&lt;/a&gt;. Fingerprints fade as you grow older, and some people don&amp;#8217;t have any because they are afflicted with a rare disease  called &amp;#8220;Naegeli syndrome&amp;#8221; or &lt;a href="http://en.wikipedia.org/wiki/Dermatopathia_pigmentosa_reticularis"&gt;&lt;em&gt;dermatopathia pigmentosa reticularis&lt;/em&gt;&lt;/a&gt; (DPR) that can cause vexing social problems. Recently, two identical twins were indicted for robbing the department store &lt;a href="http://www.nytimes.com/2009/02/21/world/europe/21germany.html"&gt;KdW in Berlin&lt;/a&gt;, but had to be released when the authorities found that it was impossible to determine which of them had been actually done the heist since they share the same DNA. And many people instinctively refuse to put their eye to an iris scanner because they worry that they may be blinded by a flash of light from a malfunctioning machine.&lt;/p&gt;
&lt;p&gt;&lt;span id="more-28"&gt;&lt;/span&gt;Now, the weekly newsmagazine &lt;em&gt;The Economist&lt;/em&gt; has come up with what may prove to be the perfect biometric identifier: &lt;a href="http://www.economist.com/science/displaystory.cfm?story_id=13403161"&gt;the human knee&lt;/a&gt;. According to the story, &lt;a href="mailto:shamirl@mail.nih.gov"&gt;Lior Shamir&lt;/a&gt;, a geneticist at the National Institutes of Health in Maryland, has developed a knee-analysing mathematical algorithm for medical use. Knees, it seems, are unique in each individual human. By exploring X-ray images of the general structure of various knees and then using their brand-new algorithm to look at them in greater detail, for instance by measuring the texture of the bone through monitoring differences in individual pixels, the researchers found that the best identification was possible by concentrating on a smaller image of the centre of the joint rather than the entire knee. &lt;span class="ver12blkht"&gt;The team also points out that the algorithm can correctly identify a given pair of knees and match it to a specific individual in the database even if the original X-ray were taken several years earlier. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;According to Mr Shamir, the success rate still needs to be improved. In the &lt;em&gt;International Journal of Biometrics&lt;/em&gt;, his team reports it achieved a correct match 34% of the time. It was also able to pick the ten closest matches to a particular knee 56% of the time &amp;#8211; still far from the degree of accuracy provided by established biometric systems. But as Shamir remarks, it&amp;#8217;s early days yet for the science of knee identity management, and given time (and grant money) they hope to get there.&lt;/p&gt;
&lt;p&gt;Naturally, this raises the question of how to build a viable world-wide identity infrastructure based on knee ID. Rumors have it that Samsung is secretly developing a &amp;#8220;deskbottom&amp;#8221; knee scanner (DKS) which fits comfortably under a table. Portable models can&amp;#8217;t be that far away, and we can easily imagine laptops with built-in knee scanners.&lt;/p&gt;
&lt;p&gt;Of course there are still numerous social issues which need attention. Baring one&amp;#8217;s knees in public is frowned on in some cultures, and it may prove akward in places like airplane seats or boardroom meetings. However, over time we can expect to see a shift in cultural biases, given the obvious advantages of knee-based recognition systems. In the end, the &lt;em&gt;Economist&amp;#8217;s &lt;/em&gt;tongue-in-cheek sum-up may well prove prescient: not the ayes (or eyes), but &amp;#8220;the knees have it&amp;#8221;&amp;#8230;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/TA3y45Md1Bk" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 04 Apr 2009 10:01:22 +0200</pubDate>
			<title>Is SSO the key to the desktop?</title> 
			<link>http://blogs.kuppingercole.com/cole/2009/04/04/is-sso-the-key-to-the-desktop/</link> 
			<guid>http://blogs.kuppingercole.com/cole/2009/04/04/is-sso-the-key-to-the-desktop/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/cole"&gt;Tim Cole&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;&lt;!--[if gte mso 10]&gt;&lt;br /&gt;
&lt;mce:style&gt;&lt;!   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Normale Tabelle"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin-top:0cm; 	mso-para-margin-right:0cm; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0cm; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} --&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN-US"&gt;I recently had a cup of coffee with a couple of interesting youngsters from Hamburg, Christian Evers and Philipp Spethmann, who have set themselves a truly impressive goal. They are out to wrest nothing less than the control of German desktops from giants like iGoogle, T-Online, Yahoo! &amp;amp; Co. And they believe the way to do this is by providing consumers a safe and simple way to log onto their favorite websites.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN-US"&gt;Their company, founded two years ago with money from Ammer Partners, one of Germany&amp;#8217;s big venture funds (yes, there still are functioning venture funds over here; many of them, in fact), is called &amp;#8220;&lt;/span&gt;&lt;a href="www.allyve.com"&gt;&lt;span lang="EN-US"&gt;allyve&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN-US"&gt;&amp;#8221; (pronounced &amp;#8220;alive&amp;#8221;), and they describe their product as &amp;#8220;the keyring of the Internet.&amp;#8221; What it boils down to is a set of widgets that provide single sign-on &amp;#8211; they prefer the term &amp;#8220;open authentication&amp;#8221; &amp;#8211; to a pre-defined list of favorite online sites. This in not the kind of OA that the OATH initiative is propounding; in fact allyve seems to be intent on doing things their own way instead of following the standards path (open or not). Good luck, I say. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN-US"&gt;&lt;span id="more-11"&gt;&lt;/span&gt;However, that is beside the point here. What I found fascinating was Christian and Philipp&amp;#8217;s approach to getting online authentication to market. Instead of trying to convince other vendors to help them spread the good word, they are putting their bucks (or rather, their venture capitalist friend’s bucks) into building up a partner network of big e-commerce companies. And they are actually going on national TV to plug their system &amp;#8211; something not even the behemoths of Identity Management have had the guts to do yet, at least in Germany. (&amp;#8221;Viral will only take you so far&amp;#8221;, Christian says.)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN-US"&gt;The partner deals are simple: You let us program a widget that gets your customers online with a single click directly from the allyve website, and we&amp;#8217;ll make sure they keep coming. Oh, and yes, it&amp;#8217;s free! You don&amp;#8217;t have to pay us a cent. We&amp;#8217;ll find another way to refinance ourselves, possibly through ad revenues, possibly by charging some kind of a premium user fee (we&amp;#8217;ll work out the details later; right now all we want is to achieve critical mass as quickly as possible).They also have plans to market a &lt;/span&gt;&lt;span lang="EN-US"&gt;licensed &lt;/span&gt;&lt;span lang="EN-US"&gt;B2B version of their system which will provide single-point authentication within Intranets and extended enterprize networks; Olympus already uses their system to log on 6,000 employees in Europe. However, the B2C space is where they are concentrating their efforts, and the one where they are achieving their greatest success.&lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN-US"&gt;That&amp;#8217;s probably why their list of partners is already so impressive. They have gone after the big social communities like Facebook, Myspace and Xing, dating services (parship, firend-scout24), big-name web commerce sites like eBay (they&amp;#8217;ll partner with anyone these days, it seems) and Amazon, and the leading German media companies and newspaper publishers like Axel Springer (&amp;#8221;Bild.de&amp;#8221;) and Spiegel-Online, as well as the leading customer bonus programs (&amp;#8221;Payback&amp;#8221;, &amp;#8220;Happy Digits&amp;#8221;) and the big German airline Lufthansa. These are all high-volume players in their respective fields, and joining allyve doesn&amp;#8217;t cost squat, so hey, why not? &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN-US"&gt;The result is that Christian and Philipp have more than 85.000 signed-up users, twice the number they had three months ago, and they plan to keep growing by double digits every month for the foreseeable future. They also have plans to grow outside of Germany. One of their first steps was to register patents on their key systems, one for the way that the user&amp;#8217;s personal data is aggregated and the second on their &amp;#8220;deep-link&amp;#8221; technology that takes users straight to the desired content page instead of simply logging them in on the operator&amp;#8217;s homepage. Negotiating the right to do this is the tricky part of each partner deal, but so far none of the big guys seems to be complaining. allyve has even managed to recruit providers like AOL, Yahoo!, 1&amp;amp;1, and Web.de who I would have assumed are competitors. No, says Philipp, they have other things to think about, and if someone wants to bring them oodles of eyeballs, who cares?&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN-US"&gt;Technically, what allyve is doing may be &amp;#8220;single sign-on lite&amp;#8221; (after all, its simply a bunch of widgets, each one individually programmed to fit the vendor&amp;#8217;s API), but the result is impressive. And these two young kids are way ahead of the pack in terms of market visibility. So maybe they&amp;#8217;re doing something right. Who knows? Time will tell.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt; &lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/t_2FZ7NliNY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 29 Mar 2009 19:38:45 +0200</pubDate>
			<title>The wild ride that was TEC 2009</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/03/29/the-wild-ride-that-was-tec-2009/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/03/29/the-wild-ride-that-was-tec-2009/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I just came back from this year&amp;#8217;s Expert conference, TEC 2009. Last year it was still called the &amp;#8220;Directory Expert&amp;#8217;s Conference&amp;#8221; (DEC). This year the conference has been extended to include training on Microsoft Exchange as well, hence the name change. And of course not to forget that Quest has taken over Netpro &amp;#8211; but has this really changed the scope or focus of TEC? Not at all, as was very immediately visible from the start, with a very funny introductory video. It started off just like a very glitzy marketing presentation that turned quickly into a hyperbole of fuzzy marketing buzzwords and photos of smiling executives. The initial bemusement turned into bewilderment, and quickly I could see some rolling eyes and frowns around me, just when the marketing fuzz stopped right in the middle of it, and into the video stepped the image of Gil Kirkpatrick, DEC&amp;#8217;s founder and Quest&amp;#8217;s Chief Architect who, looking annoyed, asked the marketing voice what all of this was about. Nothing at TEC was going to change from what DEC was &amp;#8211; this was no marketing trade show, but rather a place for people to learn and exchange experience about Microsoft products &amp;#8211; specifically Active Directory and Exchange. The video then stopped to make place for the real Gil Kirkpatrick coming on stage to a big applause and delivering the welcome speech.&lt;/p&gt;
&lt;p&gt;As a sign of the times, the conference was somewhat smaller as last year &amp;#8211; the organisers spoke about a difference of about 30% of attendees compared to last year&amp;#8217;s DEC. When Gil asked the audience who had to jump through extra hoops to get to TEC, several hands flew up. Those who went however, had an excellent, varied and carefully balanced programme waiting for them. As with all conferences, it can sometimes be a challenge picking a presentation to go to from multiple presentations going on at the same time. I was ver pleasantly surprised to see that some key presentations were given more than once so that I could attend them even though I had missed them the day before. Also, presentations were recorded this time and will soon be made available to attendees which especially for me is an additional value.&lt;/p&gt;
&lt;p&gt;The &amp;#8220;day before&amp;#8221; &amp;#8211; i.e. Sunday, several pre-conference workshops had already been given. This was a tough decision for me, as I was torn between going to Laura Hunter&amp;#8217;s workshop on ADFS and Bahram Rushenas&amp;#8217;s workshop on codeless provisioning with ILM 2. I chose ILM and the workshop turned out to be very informative, as it gave me a very good glimpse into codeless provisioning with ILM. I still felt sad to have missed Laura&amp;#8217;s ADFS workshop that has received high praises (which did not surprise me as Laura is an passioned expert on this topic, as well as a gifted speaker). But one can&amp;#8217;t have everything! &lt;img src='http://blogs.kuppingercole.com/gaehtgens/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /&gt; &lt;/p&gt;
&lt;p&gt;The second workshop was again on ILM. Dave Lundell, a DEC veteran and one of the most knowledgeable sources on ILM that I have met to date, presented on the topic &amp;#8220;Taming the Chaos – Building a Practical Lifecycle Mgt. Application in the ILM “2” Portal&amp;#8221;. I knew it was going to be good because I already attended (and raved about) his ILM 2 workshop last year at DEC. This one turned out to be a truly wild ride! Dave and his colleague Brad Turner from Ensynch pushed the envelope by demonstrating what I&amp;#8217;ve often heard but never really seen &amp;#8220;in action&amp;#8221;: that ILM 2 is more than just a provisioning tool, but in fact a whole platform that allows all kinds of lifecycle management for enterprise data. He took an excellent example out of the world of enterprise IT: the management of an OID (Object Identifier) management. Enterprises can receive an OID tree within the &amp;#8220;private enterprise&amp;#8221; branch by requesting it from IANA. This OID tree can then be used to number enterprise-specific schema extensions, SNMP objects and other things that need an OID and are used within an enterprise. The OID space should be properly managed in order to give it the correct structure and making sure that no OID is assigned twice. This unfortunately is very rarely done in any enterprise &amp;#8211; perhaps because of its technical nature and because the negative effects are usually not visible immediately when the OID tree space not managed properly &amp;#8211; and there are few who &amp;#8220;do it right&amp;#8221; and properly manage their OID space. Dave and Brad showed how to implement OID management with ILM 2. This was very interesting because it gave us participants a deep dive into the guts of ILM 2, its data structures and workflow possibilities. It also really pushed ILM 2 to its current limits. Ensynch has written several custom workflows and contributed them via the codeflow web site in order to get around some current limitations in ILM 2. Those guys continue to amaze me.&lt;/p&gt;
&lt;p&gt;Of course, the news about Microsoft&amp;#8217;s delaying ILM 2&amp;#8217;s official release for a whole year put a bit of a damper on the party. Disappointment was tangible from customers and vendors alike. I can certainly understand that although ILM 2&amp;#8217;s maturity has evolved since last year, Microsoft wants to play it safe and gain some more experience with deployments, and iron out some kinks that are still present in the current beta version. That however doesn&amp;#8217;t help those partners of Microsoft who have made a significant investment for ILM 2&amp;#8217;s supposed imminent release. Gemalto for example, was poised for a big launch and threw a big party that, well, was still a great party although with excitement rather muted because the cause for the celebration was gone. Attendees were also very disappointed, many of them having come to TEC specifically for the purpose of sharpening their skills in order to prepare for an imminent deployment of ILM 2.&lt;/p&gt;
&lt;p&gt;But back to positive aspects of TEC 2009, which were many &amp;#8211; an you obviously can&amp;#8217;t blame Quest or TEC for Microsoft delaying ILM 2! The first presentation I went to was Brian Puhl presenting on his experience over the last few years rolling out federation agreements. As one can expect from Brian, it was interesting, funny and thoughtful. Of the lot of information provided I especially liked Brian&amp;#8217;s experience with the entirely non-technical problem around creating trust agreements &amp;#8211; and the multiple iterations of procedures that Microsoft went through until they had a model that actually works. In the beginning, there was the list of the &amp;#8220;10 commandments&amp;#8221; &amp;#8211; you shall do this, you may not do that, and you must do it like this, and so on. The resulting list was probably bullet proof from the standpoint of mitigating every conceivable risk, but turned out to be so draconic that nobody, not even Microsoft&amp;#8217;s departments could comply with it. The next iteration was an extensive questionnaire about the state of security and management of identities that a partner had to fill out. The problem there was that many partners certainly did not want to divulge all this information about their internal controls and security subsystems that they thought were confidential. The next iteration then was a definition of a lowest common denominator &amp;#8220;bar&amp;#8221; that a partner had to jump over in order to qualify for federation. Three &amp;#8220;bars&amp;#8221; were defined with diffierent classifications for non-critical, medium-value and high-value and confidentiality content. To qualify, a partner had to vouch that certain criteria were met. Each criteria then had a point score, and the resulting total score would determine which &amp;#8220;bar&amp;#8221; the customer had reached, and hence qualified for within the federation agreement. This turned out to be very workable.&lt;/p&gt;
&lt;p&gt;Another TEC-veteran is Pamela Dingle, formerly of Calgary-based Nulli Secundus Identity Management consultancy. Pamela has just flown the coop and started a company called &amp;#8220;Bonzai Identity&amp;#8221; with the goal to help enterprises get to grips with identity management by carefully nurturing good practises, aligning business processes, making sure that data is correct, and helping organisations make the &amp;#8220;right decisions&amp;#8221; over time. She writes that &amp;#8220;It is like gardening; you will have much better luck making small adjustments throughout the life of your garden than you will allowing a wilderness to grow and then wading in with a machete&amp;#8221;. Her talk at TEC was entitled &amp;#8220;A survivalist&amp;#8217;s guide to identity management&amp;#8221; and focused on the business process shortcomings and warnings signs that can really bog down identity management projects. A great overview and invaluable compilation of experience that can avoid very costly traps and maximise the value of those projects.&lt;/p&gt;
&lt;p&gt;TEC is legendary for bringing out the best of Active Directory experts and get not just best practises from the real pros, but also hard-core technical info that you can&amp;#8217;t find in other places. There is a gang of &amp;#8220;usual suspects&amp;#8221; whose presentation I always try to attend because it doesn&amp;#8217;t get much better than that when you want to learn about Active Directory and dive deep into the technology. Apart from Brian Puhl, who is responsible for running AD in Microsoft&amp;#8217;s IT department, there are Laura Hunter, Joe Kaplan and Dmitri Gavrilov. Interestingly enough, those AD Gurus have become quite turned on by ADFS and federation, and (except for Dmitri) presenting on that topic.&lt;/p&gt;
&lt;p&gt;This has been the first time I&amp;#8217;ve had the honour to speak at this TEC, and even twice! My first presentation was on the subject of authorisation: once you&amp;#8217;ve authenticated the user, then what? How do, can and should applications decide how to allow (authorise) a user to do and see things? It is a subject that I&amp;#8217;ve focused on quite a bit over the last months and something that I am dedicating a whole track to on May 6th at our European Identity Conference in Munich. I couldn&amp;#8217;t help feeling that this particular presentation was a bit of an &amp;#8220;odd one&amp;#8221; at TEC, because I unfortunately could not just yet teach people how to use technology to do it: We are still early in the game because big vendors such as Microsoft and Sun have yet to commit to standards in this area, come up with frameworks and stipulate good practises. It&amp;#8217;s not completely satisfying when at the end of the presentation you have illustrated the problems and pain, but can&amp;#8217;t really point to a solution yet. However I see encouraging signs that vendors are taking this seriously and thinking about ways to tackle these problems. It is not just a lack of technology, but the fact that, well, there certainly is a lack of standardised technology and the current &amp;#8220;best practises&amp;#8221; that encourage application developers to just hardcode security into their applications just exacerbate the problem. I would obviously like to see more interaction between the vendors instead of everybody just thinking within their own box. At our European Identity Conference I am bringing some of the thought leaders, visionaries and experts together and will try to rally them into working together to find solutions together as an industry.&lt;/p&gt;
&lt;p&gt;My second presentation was on the TEC&amp;#8217;s equivalent of a &amp;#8220;Friday afternoon&amp;#8221; &amp;#8211; on the last day of the conference shortly before lunch. I was very excited about the topic because I was presenting about &amp;#8220;Cool LDAP Innovations&amp;#8221;. As TEC is about Active Directory I thought it was important to share a different perspecitve on what is happening outside of AD with other directory servers. Since AD world is essentially closed (you can&amp;#8217;t rip out AD from a windows network) there is no competition in this space, and in my opinion very little innovation. Compared to other directory servers, AD and ADAM has fallen behind in technology, so I felt a bit tongue-in-cheek, talking about some cool stuff that other vendors were doing. The evening before I managed to itercept Nathan Muggli and asked him if he&amp;#8217;d attend, and he kindly did. I finished early and a lively discussion started. After a few minutes I was delighted to see the whole thing starting to look like a BoF session and I decided to sit down in the middle with the other participants and we continued disussing.&lt;/p&gt;
&lt;p&gt;Kevin Kampman from the Burton Group (technically a competitor, but I prefer to see him and his co-workers as distant colleagues) gave a presentation entitled &amp;#8220;the case for identity services&amp;#8221;. Out of the pain points that he highlighted I could identity the same ones I talked about in the &amp;#8220;authorisation&amp;#8221; presentation the day before. It&amp;#8217;s great when a smart experienced guy like Kevin arrive at the same conclusion &amp;#8211; it means that we definitely have a case!&lt;/p&gt;
&lt;p&gt;I&amp;#8217;ve had to scramble after Kevin&amp;#8217;s presentation, grab a quick lunch and then hop into the car to drive back to Los Angeles where I came from this time. I had thought that the drive through the desert would have been more exciting, but I&amp;#8217;ve since been told that for things to get spectacular, Death Valley or Arizona would be the best option (both close, but I didn&amp;#8217;t have time for the detour). Just having gotten back to Europe this morning, I am still thinking back about this intense and englightening experience and am definitely looking forward to the next one!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/CXkAfuDb2QA" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 21 Mar 2009 17:54:07 +0100</pubDate>
			<title>Innovations in the world of LDAP</title> 
			<link>http://blogs.kuppingercole.com/gaehtgens/2009/03/21/innovations-in-the-world-of-ldap/</link> 
			<guid>http://blogs.kuppingercole.com/gaehtgens/2009/03/21/innovations-in-the-world-of-ldap/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/gaehtgens"&gt;Felix Gaehtgens&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;I&amp;#8217;ve recently been to Sun&amp;#8217;s directory labs in the the beautiful city of Grenoble, France to talk about what Sun has in store with their two directory servers: DSEE and OpenDS. I&amp;#8217;ve used many predecessors of DSEE (starting with the good old Netscape Directory Server) on several projects over the last decade and used to know it inside out. I&amp;#8217;ve grown quite fond of it, and so has everybody else I know who has used the product. I wasn&amp;#8217;t exactly sure why Sun embarked on its OpenDS project. Why reinvent from scratch what is already a perfectly great product? This question was on my mind, and I was eager to find out why.&lt;/p&gt;
&lt;p&gt;When it comes to directory servers, most analysts like to classify them according to the market segments they address. In no particular order, they are: operating system/network, telco and service provider, enterprise and embedded. When it comes to the operating system/network directory servers, Active Directory rules &amp;#8211; not necessarily because it is the best for this purpose (and just to be clear: it&amp;#8217;s not bad either!), but &amp;#8211; well &amp;#8211; it&amp;#8217;s so intrinsically linked to Windows that you don&amp;#8217;t really have a choice. When Novell Netware was around, NDS and e-Directory was another candidate in that area, but it&amp;#8217;s pretty much down to AD at this point in time. It&amp;#8217;s in the other segments where it gets really interesting because there is some very active development and strong competition.&lt;/p&gt;
&lt;p&gt;The Telco/Service provider directory segment is particularly interesting because only the highest scalable directory servers can even attempt to survive in this area. Sun has been very strong in this area for many years, and for a good reason: experience and continuous improvement. I&amp;#8217;ve been involved first hand in several very large deployments of Sun Directory Server 5.0 (I think it was during the time when Sun called it &amp;#8220;iPlanet Directory Server&amp;#8221;). At that time, in the early years of this millennium, we deployed the server for hosting several hundreds of millions of entries. Yes indeed, about 120 Million entries! This was 2002, and at the time the sheer scale was pushing the envelope quite a bit -  but it didn&amp;#8217;t just work, it actually worked quite well! Performance, Multi-master replication, and resilience were absolutely key for these types of installations. And sure &amp;#8211; in the early versions of 5.0 there were some kinks that had to be ironed out of the replication protocol, but even then it was quite amazing how scalable the directory was, and how well it could actually be managed with such an impressive number of entries. Over the last 7 years, the directory server evolved even further &amp;#8211; multimaster replication is rock solid and Sun has tinkered continously with the software to increase scalability way beyond what was already impressive in 2002. Nowadays, there are quite a few reference customers who run Sun directory server with literally billions of entries (incidentally, many of them in China &amp;#8211; why am I not surprised &lt;img src='http://blogs.kuppingercole.com/gaehtgens/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /&gt;  ), and this is considered perfectly normal.&lt;/p&gt;
&lt;p&gt;When it comes to reliability, a key to deploying very large directories is redundancy, and the possibility to balance loads and fail over between multiple instances. In the early days, load balancing appliances were used to do this (Alteon was really good at this in its days), but unless those applicances had specialised proxy features to handle the instrinsics of the LDAP protocol, this by itself wasn&amp;#8217;t a very good option for large deployments. Sun had acquired a company called Innosoft a decade ago, and with it came a product called &amp;#8220;DAR&amp;#8221; &amp;#8211; Directory Access Router &amp;#8211; a fully fledged LDAP proxy. Over the years, Sun has enhanced DAR and bundled its next generation into Directory Server (now known as &amp;#8220;DSEE&amp;#8221;, Directory Server Enterprise Edition&amp;#8221;) at no additional cost. Being an important cornerstone of very large and complex directory deployments, it fits like a glove into the directory service and extends it by offering extensive request routing functionality, high availability and performance features and simple mapping features. Previously, only the CA eTrust directory had these features.&lt;/p&gt;
&lt;p&gt;I can talk all day about deploying telco directory services, because I&amp;#8217;ve used to do it for a living, and am still fascinated by the sheer volume and raw power involved &lt;img src='http://blogs.kuppingercole.com/gaehtgens/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /&gt;  But there&amp;#8217;s another two very glorious aspects of directory services, and they can be found in the enterprise and in the still fairly recent embedded directory segment.&lt;/p&gt;
&lt;p&gt;The enterprise directory segment is where most of the innovation is happening. Enterprises are typically not as focused on performance, and often more interested in integration, security and manageability. Integration is a very big topic, because the directory service is a crucial piece in any identity management infrastructure. And we&amp;#8217;re usually not talking about &amp;#8220;a&amp;#8221; directory either &amp;#8211; most enterprises have many different directory servers, containing either different user populations, or part of the same users but for different purposes. It is in the integration area where much innovation has happened in the directory area. Is doesn&amp;#8217;t surprise me that most enterprise directories nowadays feature simple virtual directory functions. That was not the case five years ago, when I worked for a virtual directory vendor. At that time directory service vendors did not foresee virtualisation features as being an important part of their portfolio &amp;#8211; perhaps because some of those vendors were also selling an &amp;#8220;identity manager&amp;#8221; type provisioning system and thought that any directory integration could be solved by deploying a full-blown provisioning system and brute force copying data around &lt;img src='http://blogs.kuppingercole.com/gaehtgens/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /&gt;  Well, this wasn&amp;#8217;t really a feasible solution in all cases, so it is only natural that virtual directory companies such as OctetString and Maxware were acquired, and other vendors are &amp;#8220;rolling their own&amp;#8221; virtualisation features.&lt;/p&gt;
&lt;p&gt;Some of the features that are not obvious, but extremely useful in the enterprise scenario are exactly those that allow a directory server to easily interoperate with provisioning, virtualisation and synchronisation products. Technically, the features in LDAP server that are relevant here are persistent queries, incremental updates and proxy auth. These are low-level features that are absolutely crucial when identity &amp;#8220;managers&amp;#8221; and provisioning services interface with directory servers.&lt;/p&gt;
&lt;p&gt;Some other desired features within the enterprise directory segment are about password services and policies. In the vast list of featureds to be found in most modern directory servers are sophisticated access control lists that are expressive enough to configure a finely grained access control policy for deciding who gets access to what type of information. This used to be very important in the past but is getting less important as access control rules on the directory servers tend to be simpler nowadays, because changes typically ocurr through provisioning systems, and not that much any more directly to the LDAP server. Password policies are also a typical feature used in enterprise directory servers (you know &amp;#8211; minimum length, character combination, auto-lockout,auto-expiry, and all those things). And of course, keeping track of when users last logged on &amp;#8211; very helpful in order to identity dormant accounts.&lt;/p&gt;
&lt;p&gt;Another important detail is also how passwords are stored, and how they can be migrated from one server to the other. As a general rule, it&amp;#8217;s always good to offer administrators choice. Obviously passwords need to be well protected. But the approach of some directory vendors (specifically Microsoft and Novell) to &amp;#8220;secure&amp;#8221; their directories has backfired &amp;#8211; the directory servers hoard the passwords and don&amp;#8217;t even offer any possibility for administrators to export encrypted password hashes. You may wonder whether this &amp;#8220;secure&amp;#8221; feature is actually a hidden &amp;#8220;lock-in trap&amp;#8221;! That has created a secondary market around password &amp;#8220;synchronisation solutions&amp;#8221; in order to overcome the deficiency in the product itself, where the product&amp;#8217;s designers thought they had to be smarter than the poor administrators who actually need to deploy, migrate and maintain them.&lt;/p&gt;
&lt;p&gt;Last but not least, let&amp;#8217;s not forget about one of the very important aspects of enterprise directory services. They need to be simple to deploy, administer and maintain! In the telco area it may be considered acceptable if the directory administrator team features several fully trained relational database administrators, but in enterprise environments that can be too much overhead. Directory servers that make use of relational databases for storing their directory data, such as Oracle&amp;#8217;s OID and IBM&amp;#8217;s Tivoli Directory Server can point to the advantages of running a directory services platform on a rock-solid database foundation (in these cases, Oracle and DB2 respectively). But the extra administration overhead can be considerable. CA has traditionally used the Ingres relational database for its eTrust Directory Server, but has now in the latest Version 12 switched to something called &amp;#8220;DXgrid&amp;#8221; &amp;#8211; a revolutionary internal memory-mapped storage that not only offers incredible throughput, but also eliminated a significant portion of administration. Sun has since always used a simpler, but very fast and highly scalable data store for its directory server called BerkeleyDB &amp;#8211; the same used also in most installations of OpenLDAP.&lt;/p&gt;
&lt;p&gt;After mumbling on for quite a discourse I actually wanted to get to the point of Sun&amp;#8217;s OpenDS, and the question that I wrote in the beginning of this entry. Why reinvent from scratch (OpenDS) what is already a perfectly great product (Sun DSEE)? As it turns out, there&amp;#8217;s been a new segment for directory server that is steadily growing: the one of embedded directory services. For example, packaged solutions that require a directory server internally. Or &amp;#8220;black box&amp;#8221; appliances with a provisioning interface that contain &amp;#8211; guess what &amp;#8211; a directory server. A few years back, it was OpenLDAP that was typically shipped with those solutions, because it was free, open and could be embedded easier than other full-fledged directory server products. Now it is OpenDS that is continuously gaining ground, and for good reason. With its incredibly easy set-up, minimal administration, OpenDS epitomises what an embedded directory stands for. And on top of that, the scalability and performance are world-class. Development on OpenDS is, as the name implies, well &amp;#8211; open. The development team features Sun employees and others outside Sun, just like OpenSSO. The release cycle is short and new features list is growing at an incredible rate.&lt;/p&gt;
&lt;p&gt;So will OpenDS one day replace DSEE? Most likely. But this is still far in the future &amp;#8211; for the next few years Sun is actively investing in DSEE as its flagship directory whilst continuing to nurture OpenDS and offering it as an embedded directory server, as well as to anyone interested in quickly deploying a directory server. Now, when I say &amp;#8220;quickly&amp;#8221; &amp;#8211; I&amp;#8217;ve managed to install it, extend the schema and load some data into it in less than fifteen minutes! Now that&amp;#8217;s what I would call &amp;#8220;quickly&amp;#8221;. And once I had it up and running on my slow and overloaded laptop, I ran the &amp;#8220;slamd&amp;#8221; LDAP benchmark tool against it on the same laptop, and got back thousands of searches per second. Not bad at all! Now that&amp;#8217;s what I call innovation in the world of LDAP &lt;img src='http://blogs.kuppingercole.com/gaehtgens/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /&gt; &lt;/p&gt;
&lt;p&gt;I&amp;#8217;ll be speaking at TEC on Wednesday the 25th of March, on the topic &amp;#8220;Cool LDAP Innovations&amp;#8221;. OpenDS will definitely get a mention. On the presentation, I&amp;#8217;ll also talk about some other real innovations that happened over the last few years in the directory services area. If you&amp;#8217;re there, be sure to drop by!&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/TiSnYucR1YQ" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 20 Mar 2009 00:00:00 +0100</pubDate>
			<title>Wer war Root? Was Sie über Privileged Account Management (PAM) wissen sollten</title> 
			<link>http://www.kuppingercole.com/podcasts/wer_war_root.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/wer_war_root.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Der Umgang mit privilegierten Benutzerkonten, wie beispielsweise "ROOT", birgt hohe Risiken. In diesem Webinar führen wir Sie in die Grundlagen des Privileged Account Management (PAM) ein und geben Ihnen wertvolle Praxistipps, wie Sie Ihr Netzwerk wirksam gegen interne und externe Bedrohung schützen können.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/wer_war_root.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/KO6IvWbXOqI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 11 Mar 2009 00:00:00 +0100</pubDate>
			<title>Fraud Prevention and Multi-factor Authentication</title> 
			<link>http://www.kuppingercole.com/podcasts/multi-factor_authentication.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/multi-factor_authentication.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In this webinar, Kuppinger Cole´s founder and principal analyst will give you an overview on the market for risk- and context-based, multi-factor authentication and authorization solutions for fraud detection, followed by Stefan Dodel, middleware solutions specialist at Oracle, who will talk about his experiences from numerous projects.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/multi-factor_authentication.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/5h9Jm4XOqjM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 11 Mar 2009 00:00:00 +0100</pubDate>
			<title>Getting Attestation Right - Improving Audit Performance, Lowering Costs</title> 
			<link>http://www.kuppingercole.com/podcasts/getting_attestation_right.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/getting_attestation_right.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In this webinar, Martin Kuppinger, Principal Analyst at Kuppinger Cole give an overview on an automated and risk-based approach to access certification, followed by a discussion with industry thought leaders on how to significantly improve the operational efficiency and accuracy of the attestation process, ensuring the goals of corporate accountability and compliance are met.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/getting_attestation_right.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/OiURQW4XkMw" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 02 Mar 2009 00:00:00 +0100</pubDate>
			<title>Risk Management Trends</title> 
			<link>http://www.kuppingercole.com/podcasts/risk_management_trends.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/risk_management_trends.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; The webinar will discuss risk management trends as well as the evolution of the market for risk management tools.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/risk_management_trends.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/-WHl7WSDMkk" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 13 Feb 2009 00:00:00 +0100</pubDate>
			<title>Key Risk Indicators (KRIs) als Frühwarnsystem zur Verringerung operationeller Risiken</title> 
			<link>http://www.kuppingercole.com/podcasts/key_risk_indicators.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/key_risk_indicators.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Martin Kuppinger stellt in diesem Webinar den aktuellen Kuppinger Cole Report zu diesem Thema vor und beschreibt die Verwendung dieser KRIs für einen risikobasierten Management-Ansatz. Im Anschluß daran wird Thomas Reeb, Vorstand econet AG, über seinen Ansatz einer Key Performance Indicator (KPI)-Matrix an Hand eines Beispiels (Sicherheit in Dateisystemen) sprechen, mit deren Hilfe sich aus den KRIs Strategien sowie Reifegradmodelle ableiten lassen.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/key_risk_indicators.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/DCzOqohwCQg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 13 Feb 2009 00:00:00 +0100</pubDate>
			<title>Zehn Gründe, warum Sie gerade jetzt in IAM und GRC investieren sollten</title> 
			<link>http://www.kuppingercole.com/podcasts/iam_und_grc_investierenwmv.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/iam_und_grc_investierenwmv.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Martin Kuppinger nennt und erläutert zehn Gründe dafür, warum man gerade jetzt in IAM und GRC investieren sollte, um die IT besser und Unternehmen leistungs- und wettbewerbsfähiger zu machen und Risiken zu reduzieren.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/iam_und_grc_investierenwmv.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/QQtvLq9gx2Q" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 13 Feb 2009 00:00:00 +0100</pubDate>
			<title>Reducing Compliance Costs through Risk-Based Segregation of Duties Management</title> 
			<link>http://www.kuppingercole.com/podcasts/reducing_compliance_costs.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/reducing_compliance_costs.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In this Webinar, Kuppinger Cole´s Principal Analyst Martin Kuppinger will highlight the challenges of risk based segregation of duties management, and will discusses technology solutions for continuous monitoring that deliver affordable and effective compliance.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/reducing_compliance_costs.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/MzvJ_PMJV2o" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 30 Jan 2009 00:00:00 +0100</pubDate>
			<title>Cutting Costs through Lean Role Management</title> 
			<link>http://www.kuppingercole.com/podcasts/cutting_costs_through_lean_role_management.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/cutting_costs_through_lean_role_management.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; In tough economic times, IT departments are required to tighten their belts. This webinar explores cost saving potentials of enterprise role management initiatives.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/cutting_costs_through_lean_role_management.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/Plqn4pX2lrM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 23 Jan 2009 00:00:00 +0100</pubDate>
			<title>Service Oriented Security (SOS)</title> 
			<link>http://www.kuppingercole.com/podcasts/service_oriented_security.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/service_oriented_security.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Service-Oriented Security aligns with the overall Application-Centric approach of Identity and Access Management solutions - with the goal of providing a comprehensive, standards-based, developer-friendly platform. By leveraging and sharing many of the common Identity "Services", Service-Oriented Security allows developers to spend the effort on where it counts the most - the application logic itself. Security will be just a service that can be invoked over a well defined hetrogenous interfac...&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/service_oriented_security.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/z7yYkYUDD7o" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 20 Jan 2009 00:00:00 +0100</pubDate>
			<title>Entitlement Management - Business and Technical Perspectives</title> 
			<link>http://www.kuppingercole.com/podcasts/entitlement_management_perspectives.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/entitlement_management_perspectives.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; The question on how to control and secure access to resources has become an even more critical topic, as monolithic applications more and more become legacy and service oriented architectures (SOA) are taking over the regime. In this webinar we will give an overview of the emerging field of Entitlement Management and the XACML standard as a possibility to externalize identity management into an abstraction layer across multiple applications and services.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/entitlement_management_perspectives.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/GRfDCGxt6lc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 20 Dec 2008 00:00:00 +0100</pubDate>
			<title>IAM and GRC Market Today and 2009</title> 
			<link>http://www.kuppingercole.com/podcasts/iam_grc_today_2009.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/iam_grc_today_2009.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; The final Kuppinger Cole Webinar in 2008 will provide a conclusion of what we have observed in our research during 2008 - trends, interesting vendors and concepts, emerging standards, remarkable best practices. Based on this, we will also talk about our view on what we expect to happen in 2009.&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/iam_grc_today_2009.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/v23c1BgRvgQ" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 20 Dec 2008 00:00:00 +0100</pubDate>
			<title>Trendstudie Rollenmanagement</title> 
			<link>http://www.kuppingercole.com/podcasts/trendstudie_rollenmanagement.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/trendstudie_rollenmanagement.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Kuppinger Cole Webinar recording&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/trendstudie_rollenmanagement.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/y_y7KQibcTs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 20 Dec 2008 00:00:00 +0100</pubDate>
			<title>Reducing Authentication &amp; Authorization Risks in Today's Open Flexible Business Environments</title> 
			<link>http://www.kuppingercole.com/podcasts/reducing_aa_risks.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/reducing_aa_risks.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Kuppinger Cole Webinar recording&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/reducing_aa_risks.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/djV1toI2Xpc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 09 Dec 2008 00:00:00 +0100</pubDate>
			<title>Enterprise Role Management</title> 
			<link>http://www.kuppingercole.com/podcasts/enterprise_role_management.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/enterprise_role_management.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Kuppinger Cole Webinar recording&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/enterprise_role_management.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/F3rExsYstaw" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 19 Nov 2008 00:00:00 +0100</pubDate>
			<title>Identity Management Roadmap 2009</title> 
			<link>http://www.kuppingercole.com/podcasts/idm_roadmap_2009.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/idm_roadmap_2009.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 10 minutes audio-enhanced presentation&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/idm_roadmap_2009.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/htFUQi4PHxI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 19 Nov 2008 00:00:00 +0100</pubDate>
			<title>Integration - die Zukunft des Risikomanagements</title> 
			<link>http://www.kuppingercole.com/podcasts/integration_die_zukunft_des_risikomanagements.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/integration_die_zukunft_des_risikomanagements.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 9-min&amp;uuml;tige Pr&amp;auml;sentation&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/integration_die_zukunft_des_risikomanagements.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/vEi-qwtHJVA" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 19 Nov 2008 00:00:00 +0100</pubDate>
			<title>Regeln für erfolgreiches Rollenmanagement</title> 
			<link>http://www.kuppingercole.com/podcasts/regeln_fuer_erfolgreiches_rollenmanagement.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/regeln_fuer_erfolgreiches_rollenmanagement.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 10-min&amp;uuml;tige Pr&amp;auml;sentation&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/regeln_fuer_erfolgreiches_rollenmanagement.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/1lI8jPa-9m4" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 19 Nov 2008 00:00:00 +0100</pubDate>
			<title>Identity Management and GRC Trends 2009-2019</title> 
			<link>http://www.kuppingercole.com/podcasts/idm_and_grc_trends_2009-2019.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/idm_and_grc_trends_2009-2019.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 9 minutes audio-enhanced presentation&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/idm_and_grc_trends_2009-2019.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/DwvxIo3U6FA" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 04 Nov 2008 00:00:00 +0100</pubDate>
			<title>Webinar: Microsoft´s new Geneva Claims based Platform</title> 
			<link>http://www.kuppingercole.com/podcasts/311008-geneva.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/311008-geneva.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Recording of a Webinar held by Kuppinger Cole Senior Analyst Felix Gaehtgens on Microsoft&amp;acute;s new Identity Platform &amp;quot;Geneva&amp;quot;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/311008-geneva.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/oYRT4gbynCc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 20 Oct 2008 00:00:00 +0200</pubDate>
			<title>GRC Panel: Bridging the gap</title> 
			<link>http://www.kuppingercole.com/podcasts/grc_panel.mp3</link> 
			<guid>http://www.kuppingercole.com/podcasts/grc_panel.mp3</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Join &lt;strong&gt;Martin Kuppinger&lt;/strong&gt;, founder of &lt;em&gt;Kuppinger Cole&lt;/em&gt;, as he discusses the perception and evolution of Enterprise and IT GRC with &lt;strong&gt;Martin Kling&lt;/strong&gt;, Solutions Manager GRC at &lt;em&gt;IDS Scheer&lt;/em&gt;, &lt;strong&gt;Dave Anderson&lt;/strong&gt;, Director of Marketing, &lt;em&gt;SAP&lt;/em&gt; Solutions for GRC and &lt;strong&gt;Kristin Lovejoy&lt;/strong&gt;, Director of GRM &amp;amp; Corporate Security Strategy at &lt;em&gt;IBM Tivoli&lt;/em&gt;.&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/grc_panel.mp3"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/8iN-1At4fbE" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 07 Jun 2008 10:28:27 +0200</pubDate>
			<title>Yubikey – New Hardware for Strong Authentication</title> 
			<link>http://blogs.kuppingercole.com/resch/2008/06/07/yubikey-new-hardware-for-strong-authentication/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2008/06/07/yubikey-new-hardware-for-strong-authentication/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F06%2F07%2Fyubikey-new-hardware-for-strong-authentication%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F06%2F07%2Fyubikey-new-hardware-for-strong-authentication%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;Recently I came across YubiKey, which is a hardware token generator from a young Swedisch comapny called &lt;a href="http://www.yubico.com"&gt;Yubico&lt;/a&gt;. YubiKey is a small and slim USB device with just one button. If you push it, the device produces a 1-time password and sends it to the server. Compared to token generators in card format, you don´t need to manually enter your 1-time password anymore through a computer keyboard, which makes YubiKey unreachable for trojans directly listening to keyboard entries. One more remarkable thing is, that Yubico offer an identity platform for their device, which already contains an OpenID Server.&lt;/p&gt;
&lt;p&gt;If this device holds it´s promise, there should be reason to worry for the other players in the strong authentication market. I wrote a mail to Yubico´s CEO &lt;a href="http://www.yubico.com/about/people/"&gt;Stina Ehrensvärd&lt;/a&gt;, asking for some background and a sample device, and got an answer within minutes. So I´now waiting for the YubiKey and will keep you informed.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/eQ3RByBD_yo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 06 Jun 2008 10:18:34 +0200</pubDate>
			<title>CardSpace “hacked”?</title> 
			<link>http://blogs.kuppingercole.com/resch/2008/06/06/cardspace-hacked/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2008/06/06/cardspace-hacked/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F06%2F06%2Fcardspace-hacked%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F06%2F06%2Fcardspace-hacked%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;I´m definately amongst the last ones to join the crowd blaming German Universities to lag behind international standards with regards to their educational program, especially in the fields of technology and computer sciences.  But reading &lt;a href="http://demo.nds.rub.de/cardspace/PR-HGI-TR-2008-003-EN.pdf"&gt;this press release&lt;/a&gt;, issued by  the &lt;a href="http://www.nds.rub.de/index_en.html"&gt;Faculty of Network and Data Security at University Bochum&lt;/a&gt; (sorry, the English version of their website seems to not work), makes me think.&lt;/p&gt;
&lt;p&gt;The press release says, that two students of said faculty &amp;#8220;broke&amp;#8221; Microsoft´s CardSpace through some kind of man-in-the-middle-attack, where they took over an existing session between a user authenticated with an InformationCard and Microsoft´s InfoCard sandbox in manipulating a DNS server. Reading through &lt;a href="http://demo.nds.rub.de/cardspace/"&gt;the description of this &amp;#8220;attack&amp;#8221;&lt;/a&gt; shows, that the sophisticated part of their work was to manually change the DNS settings of their client computer in a way, that it resolved webadresses through an internal DNS service within their institute (where they have admin access to) which they had manipulated before in adding a round robin entry for the sandbox server, redirecting every second client request to an evil system, which then stole the session token.&lt;/p&gt;
&lt;p&gt;So, what are the learnings from this intended act of creative distruction? Yes, once again we learn (what we have known for decades now), that without a proper client certificate, man-in-the-middle-attacks are possible, independently from the authentication methods and tools used, and that SSL/TLS provide means to avoid the risk of such attacks, as well independently from the authentication methods and tools in place.&lt;/p&gt;
&lt;p&gt;It is great that University Bochum is teaching their students how these things work and eventually, we may have a generation of well educated IT experts knowing how to make corporate IT infrastructures and the Internet more secure. Maybe, they should add some HTML training courses to their timetable as well. If you look at this &lt;a href="http://www.nds.rub.de/lehre/praktika/hackerprakt/index.html"&gt;description of a &amp;#8220;hacker course&amp;#8221;&lt;/a&gt; that university is offering, some nice error messages coming from malformed HTML are displayed, like this one:&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #ff0000;"&gt;System Message: WARNING/2 (&lt;tt class="docutils"&gt;&amp;lt;string&amp;gt;&lt;/tt&gt;, line 11)&lt;br /&gt;
Block quote ends without a blank line; unexpected unindent.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;But what is the message behind that press release saying that University Bochum students broke &amp;#8220;Microsoft´s Identity Metasystem CardSpace&amp;#8221;? Just to feed some outdated opinion about Microsoft producing error-prawn and insecure Software? To my opinion, this is not enough for some productive discussion on how to increase security.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/Suw4aett-fY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 06 Jun 2008 00:18:59 +0200</pubDate>
			<title>Is GRC something different in Europe than it is in the US?</title> 
			<link>http://blogs.kuppingercole.com/resch/2008/06/05/is-grc-something-different-in-europe-than-it-is-in-the-us/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2008/06/05/is-grc-something-different-in-europe-than-it-is-in-the-us/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F06%2F05%2Fis-grc-something-different-in-europe-than-it-is-in-the-us%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F06%2F05%2Fis-grc-something-different-in-europe-than-it-is-in-the-us%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;Today &lt;a href="http://sailpoint.libsyn.com/index.php?post_id=346135 "&gt;I listened to a podcast&lt;/a&gt; where Kevin Cunningham and Darran Rolls from &lt;a href="http://www.sailpoint.com/company/management.php"&gt;Sailpoint Software&lt;/a&gt; talk in an interview with Jackie Gilbert about their impressions they brought back home from &lt;a href="http://www.id-conf.com/eic2008"&gt;EIC 2008&lt;/a&gt;. Besides describing EIC as an event not to miss next year (thanks!), they compare the US and European identity management markets and agree that there are more similarities than differences when it comes to GRC. Yes, compliance requirements are increasing everywhere in the world and SOX is not the only framework responsible for this increase.&lt;/p&gt;
&lt;p&gt;I think it was Kevin who mentionned one important difference: Privacy and data protection for employees  seem to be stronger regulated here in Europe than it is in the US. This may be true, although they don´t really play a role in reality, as recent  &lt;a href="http://www.dw-world.de/dw/article/0,2144,3371190,00.html"&gt;espionage cases like the one within Deutsche Telekom&lt;/a&gt; impressively show.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/abvZms-PUCw" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Mon, 05 May 2008 00:00:00 +0200</pubDate>
			<title>Round table discussion of the identity bus concept</title> 
			<link>http://www.kuppingercole.com/podcasts/round_table.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/round_table.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; Round Table with Felix Gaehtgens, Dale Olds, Jackson Shaw, Kim Cameron, and Dave Kearns 							at the 2nd European Identity Conference&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/round_table.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/FHzEin5Dwmw" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with Paul Heiden, BHOLD</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-heiden.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-heiden.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Felix Gaehtgens interviews Paul Heiden, BHOLD at the 2nd European Identity Conference &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-heiden.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/rp-zqjzAqI4" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with Keith Grayson, SAP</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-grayson.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-grayson.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Felix Gaehtgens interviews Keith Grayson, SAP during the 2nd European Identity Conference&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-grayson.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/eIrFpiRFpRs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with Ariel Gordon, Orange/France Telecom</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-gordon.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-gordon.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Felix Gaehtgens interviews Ariel Gordon, Orange/France Telecom during the 2nd European Identity Conference&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-gordon.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/L4p8J80nttg" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with Amit Jasuja, Oracle</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-jasuja.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-jasuja.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Felix Gaehtgens interviews Amit Jasuja, Oracle at the 2nd European Identity Conference&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-jasuja.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/viFe019GXRQ" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with Volker Smid, Novell</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-smid.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-smid.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Felix Gaehtgens interviews Volker Smid, Novell at the 2nd European Identity Conference&lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-smid.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/AzoKY5xNuDY" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with John Aisien, Oracle</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-aisien.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-aisien.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Martin Kuppinger interviews John Aisien, Oracle during the 2nd European Identity Conference &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-aisien.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/_7FuJ5zeGZs" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with Siegfried Schallenmueller, Siemens</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-schallenmueller.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-schallenmueller.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;span id="BeginvidDescVPYkX5JdC8"&gt; 	Felix Gaehtgens interviews Siegfried Schallenmueller, Siemens at the 2nd European Identity Conference&lt;/span&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-schallenmueller.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/EGdXpOejTAo" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sun, 04 May 2008 00:00:00 +0200</pubDate>
			<title>Interview with Dave Kearns</title> 
			<link>http://www.kuppingercole.com/podcasts/eic-interview-kearns.avi</link> 
			<guid>http://www.kuppingercole.com/podcasts/eic-interview-kearns.avi</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; &lt;p&gt;Martin Kuppinger interviews Dave Kearns at the 2nd European Identity Conference &lt;/p&gt;&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/eic-interview-kearns.avi"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/fdCFmc90hPc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 29 Feb 2008 00:00:00 +0100</pubDate>
			<title>IAM und SOA</title> 
			<link>http://www.kuppingercole.com/podcasts/iam_und_soa.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/iam_und_soa.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 8 Minutes audio enhanced presentation&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/iam_und_soa.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/51lW7g9Z3kc" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 29 Feb 2008 00:00:00 +0100</pubDate>
			<title>Auswahlkriterien für Provisioning-Produkte</title> 
			<link>http://www.kuppingercole.com/podcasts/auswahlkriterien_provisioning.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/auswahlkriterien_provisioning.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 7 Minutes audio enhanced presentation&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/auswahlkriterien_provisioning.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/EVAqjYivITM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Sat, 26 Jan 2008 18:38:35 +0100</pubDate>
			<title>It is not possible, that a single trader like Jerome Kerviel burns 5bn Euro</title> 
			<link>http://blogs.kuppingercole.com/resch/2008/01/26/it-is-not-possible-that-a-single-trader-like-jerome-kerviel-burns-5bn-euro/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2008/01/26/it-is-not-possible-that-a-single-trader-like-jerome-kerviel-burns-5bn-euro/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F01%2F26%2Fit-is-not-possible-that-a-single-trader-like-jerome-kerviel-burns-5bn-euro%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F01%2F26%2Fit-is-not-possible-that-a-single-trader-like-jerome-kerviel-burns-5bn-euro%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;It is absolutely impossible, that somebody in a position like Jerome Kerviel can hold trading positions for 50 bn Euros and burn 10% of that amount. It is impossible, because&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;banks nowadays would never rely on simple password protection for their trading systems.&lt;/li&gt;
&lt;li&gt;they all have state-of-the-art identity management in place and manage business roles in a way that one single trader could not crash the whole bank&lt;/li&gt;
&lt;li&gt;such big deals would always be routed through acknowledgement processes where duties are segregated&lt;/li&gt;
&lt;li&gt;Strong Authentication techniques and strict authorization would let all employees of a bank feel, that it is impossible to operate with multiple identities falsifying acqunowledgement processes&lt;/li&gt;
&lt;li&gt;risk dashboards would turn red and start screaming long before such a damage occurs&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And, just to be complete: no, it is not possible to attack PIN/TAN online banking transactions, ATM Cards cannot be falsified and it never rains in Hamburg.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/CYIsGWOWdeQ" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 09 Jan 2008 16:51:48 +0100</pubDate>
			<title>identity theft &amp; offline fraud in banking industry</title> 
			<link>http://blogs.kuppingercole.com/resch/2008/01/09/identity-theft-offline-fraud-in-banking-industry/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2008/01/09/identity-theft-offline-fraud-in-banking-industry/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F01%2F09%2Fidentity-theft-offline-fraud-in-banking-industry%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2008%2F01%2F09%2Fidentity-theft-offline-fraud-in-banking-industry%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;In a &lt;a href="http://blogs.kuppingercole.de/resch/2007/11/20/uk-public-services-pushing-identity-theft-to-a-new-level/"&gt;recent post&lt;/a&gt;, I  wrote about those 25 Million British people, whose bank information had been &amp;#8220;lost&amp;#8221;. Jeremy Clarkson, a British TV presenter, wrote in his Sun newspaper column, that such a loss is of no value for somebody who may now own this data. To proof this, he published his own Barclays Bank account information. He now had to admit, that somebody exploited this information and transferred 500 GBP from his account to some welfare organization. So he either was lucky or didn´t have more on his account, I suppose.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/cDvjj2naW-A" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Thu, 20 Dec 2007 17:05:01 +0100</pubDate>
			<title>Customer Identities at Vodafone</title> 
			<link>http://blogs.kuppingercole.com/resch/2007/12/20/customer-identities-at-vodafone/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2007/12/20/customer-identities-at-vodafone/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F12%2F20%2Fcustomer-identities-at-vodafone%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F12%2F20%2Fcustomer-identities-at-vodafone%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;Today, I had to put an end to a story lasting for months now, where I tried to change my mobile phone contract I have had at Vodafone since 1996, through cancelling any contract which may exist under my name/my address/my bank account number/my customer number(s).  It all started, when my employer was generous enough to take over my phone contract. Therefore, invoice address and bank account information had to be changed. I wanted to take this occasion and get rid of some add-ons I had been chased to subscribe to through aggressive telemarketing, which I actually never used and did not miss. And I wanted to change from one flatrated type to another one suiting better my phone habits.&lt;/p&gt;
&lt;p&gt;As telcos in general may not be too famous in terms of customer service quality, I did not expect it to be easy.  But what happened was far beyond my imagination:&lt;/p&gt;
&lt;p&gt;The first trial (phone, eMail) did not have any effect.&lt;br /&gt;
After the second trial, my contract had been changed, add-ons were not cancelled, bank account information was not changed, invoice adress was not changed.&lt;/p&gt;
&lt;p&gt;Next attempt: they still cash my bank account with a rising amount of money. But I don´t get any invoices any more. When I phone them, they cannot trace any changes in their CRM database Everything up to now seems to have reached at some wrong place. They then sent me a form by post where I have to apply for bank account and invoice address change. Several days after I did so, I received a written confirmation to my private address, that&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;They do not have a mobile phone contract under my customer number&lt;/li&gt;
&lt;li&gt;I signed the mobile phone contract in August 2003&lt;/li&gt;
&lt;li&gt;My bank information is (private bank account)&lt;/li&gt;
&lt;li&gt;My invoice address is (private address)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;They enclosed a photocopy of my non-existent contract which they say was dated August 2003, but in fact contains August 1996 as contracting date. This photocopy is the only piece of correct information I received. Which does not help me too much, as I have it myself.&lt;/p&gt;
&lt;p&gt;Today I received a call from a person from Vodafone service or telemarketing (I don´t know, and I don´t care anymore) who tried to explain, why invoices do not reach me anymore. The person phoning me did not know, that bank account information and invoice address had changed or should have been changed. Nor did that person know anything about contract changes. He then said, that he will call Vodafone and ask about the status. Hä?&lt;/p&gt;
&lt;p&gt;I hope for the future of that company, that I am a grand exception.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/fuhhOX7aECI" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 20 Nov 2007 22:39:44 +0100</pubDate>
			<title>UK Public Services Pushing Identity Theft to a new Level</title> 
			<link>http://blogs.kuppingercole.com/resch/2007/11/20/uk-public-services-pushing-identity-theft-to-a-new-level/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2007/11/20/uk-public-services-pushing-identity-theft-to-a-new-level/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F11%2F20%2Fuk-public-services-pushing-identity-theft-to-a-new-level%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F11%2F20%2Fuk-public-services-pushing-identity-theft-to-a-new-level%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;According to &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/7103566.stm"&gt;BBC news&lt;/a&gt;, UK Chancellor Alistair Darling has admitted &amp;#8220;loss&amp;#8221; of 25m records by UK Revenue and Customs. 2 disks containing personal information including names, birth dates, National Insurance Numbers and bank account details of 25 million people, essentially of all families resident in the UK with at least one child under 16. He added, that there has been no evidence that this data has fallen into the hands of bad guys, but adviced those 25 million people to watch their bank accounts.&lt;/p&gt;
&lt;p&gt;Translated from political into real world language, this means that those disks have indeed fallen into wrong hands, and that most probably some identity theft and fraud activity is already going on.&lt;/p&gt;
&lt;p&gt;I don´t know much about how UK public services are dealing with IT governance, with compliance issues and wether they are aware of the risks related with large collections of identity information. But I assume that it is not so different to the situation over here in Germany, where governmental institutions&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;are absolutely resistant against any external IT related expert advice&lt;/li&gt;
&lt;li&gt;have little or no internal expertise in that field&lt;/li&gt;
&lt;li&gt;always insist on having access to any kind of data collection, even if it does not make any sense and even if they do not have the manpower to extract identity  information from that data&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Sad enough but true &amp;#8211; governments themselves are amongst the biggest threats to modern civilization.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/N7AqA3PVO10" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Fri, 12 Oct 2007 14:08:36 +0200</pubDate>
			<title>Bye Bye CRM</title> 
			<link>http://blogs.kuppingercole.com/resch/2007/10/12/bye-bye-crm/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2007/10/12/bye-bye-crm/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F10%2F12%2Fbye-bye-crm%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F10%2F12%2Fbye-bye-crm%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;On this year´s &lt;a href="http://conference.digitalidworld.com/2007/"&gt;Digital ID World&lt;/a&gt; in San Francisco, &lt;a href="http://blogs.law.harvard.edu/doc/"&gt;Doc Searls&lt;/a&gt; held a keynote on &lt;a href="http://cyber.law.harvard.edu/projectvrm/Main_Page"&gt;Vendor Relationship Management (VRM)&lt;/a&gt;, a concept he has been contributing to as a Harvard (&lt;a href="http://cyber.law.harvard.edu/home/"&gt;Berkman Center&lt;/a&gt;) fellow. According to Doc, VRM is the inverse of &lt;a href="http://en.wikipedia.org/wiki/Customer_relationship_management"&gt;Customer Relationship Management (CRM)&lt;/a&gt; and provides methods and tools for individuals to deal with customers.&lt;/p&gt;
&lt;p&gt;VRM being still quite early in it´s evolution, definately is extremely interesting, as it is one of the first initiatives to look into what can be done on top of &lt;a href="http://identitygang.org/"&gt;User Centric Identity&lt;/a&gt;, besides decentralized authentication and some kind of Web-SSO. VRM puts customers into the lead position, and thus improves the relationship between demand and supply.&lt;/p&gt;
&lt;p&gt;In the &lt;a href="http://cyber.law.harvard.edu/projectvrm/Mailing_list"&gt;VRM mailing list&lt;/a&gt;, which is very interesting to listen to, there has been some discussion around the question, who actually owns identity related information. I posted the following contribution:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Information cannot be owned&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I would like to point to the fact that &lt;em&gt;information cannot be owned&lt;/em&gt;, because it is not kind of an object which may be attributed to a subject by law (which itself is information as well). There is a very good publication about the ownership of information from Jean Nicolas Druey: &lt;a href="http://cyber.law.harvard.edu/home/uploads/339/Druey.pdf"&gt;http://cyber.law.harvard.edu/home/uploads/339/Druey.pdf&lt;/a&gt; . &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p&gt;So, talking about the persistence and flow of identity information between parties and through market places, we should not try to think, that we can own that information. If I understand the VRM discussion and the concept of user centric identity right, it is about creating a more balanced position between parties taking part in whatever market place, where some kind of “rules layer” on top of the information layer gives me the power to influence it´s flow. I´m not the owner of my doctor´s diagnosis, even if it concerns me. But I may have some rights influencing the distribution of this diagnosis, because it affects me. We need a home for these rights, instead of trying to own information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p&gt;VRM, how I understand it, is about creating kind of a rules metasystem above or beyond the walled gardens we currently have.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/55EpJFekz84" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Wed, 26 Sep 2007 21:18:00 +0200</pubDate>
			<title>Orange / France Telecom release OpenID Service</title> 
			<link>http://blogs.kuppingercole.com/resch/2007/09/26/orange-france-telekom-release-openid-service/</link> 
			<guid>http://blogs.kuppingercole.com/resch/2007/09/26/orange-france-telekom-release-openid-service/</guid> 
			<description>In &lt;a href="http://blogs.kuppingercole.com/resch"&gt;Joerg Resch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;div class="tweetmeme_button" style="float: right; margin-left: 10px;"&gt;&lt;a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F09%2F26%2Forange-france-telekom-release-openid-service%2F"&gt;&lt;img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblogs.kuppingercole.com%2Fresch%2F2007%2F09%2F26%2Forange-france-telekom-release-openid-service%2F" height="61" width="51" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;Ariel Gordon and Aude Pichelin from &lt;a href="http://www.francetelecom.com"&gt;France Telecom&lt;/a&gt; (FT) yesterday announced at the &lt;a href="http://conference.digitalidworld.com/2007/"&gt;6th Digital ID World&lt;/a&gt; in San Francisco release of an OpenID service to their 40 million subscribers. Congratulations to the OpenID community for this big success. It is not surprising that it is FT with it´s Orange brand being the first company running an internet scale OpenID service. On the one hand, it´s a smart company. They strongly contributed to the emergence of the SAML standard and pushed IBM into the Liberty Alliance some 3 years ago. On the other hand, if there is any industry which can make a business out of running OpenID services, it´s the telcos, because they are wired right through to our purses.&lt;/p&gt;
&lt;p&gt;But OpenID was only a smaller part of FT´s advanced identity management strategy, which consumed less than 3% of their total project budget and therefore shouldn´t have been too difficult to give it a go. The rest of the budget went into something I would call the foundation of the future (post-UMTS) telco business modell, converging management of identities for voice and non-voice services through wireline and wireless and using the SAML v2 standard to open up the whole infrastructure for plug &amp;amp; play style partnership business.&lt;/p&gt;
&lt;p&gt;Telcos on their own haven´t been too good in creating services needed or otherwise attractive enough to be broadly used, since they invented SMS. So they need partners taking care for this in order to survive.&lt;/p&gt;
&lt;p&gt;Being more and more reduced to an IP tunnel provider, telcos at least should try to make the most out of it in offering a powerful  infrastructure for mobile and wireline services. FT have done their homework in an obviously excellent way, clearly focussing on the improvement of the user experience through simplifying sign-on within their SAML based converged infrastructure. They pull authentication  information from the DSL and appliance level, add available user  information and use these to provide reliable identities even without forcing them through login and account creation processes.&lt;/p&gt;
&lt;p&gt;Ariel described, that during downtimes of their identity system with users being forced to sign on manually, online service sales drop by 50%. Even if this does not necessarily mean, that they have doubled sales, because part of those 50% would just return after the service is back up, there seems to be space for a pretty quick return on investment and revenue growth.&lt;/p&gt;
&lt;p&gt;I have invited Aude, Ariel and Hervé, the latter on being technically responsible, to come to Munich for next years &lt;a href="http://www.id-conf.com/"&gt;European Identity Conference&lt;/a&gt; and talk about latest developments.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/FVS7YlE1rgM" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 03 Jul 2007 00:00:00 +0200</pubDate>
			<title>Enterprise Identity Management Strategies &amp; Trends</title> 
			<link>http://www.kuppingercole.com/podcasts/e-iam-7-minutes.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/e-iam-7-minutes.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 7 Minutes audio enhanced presentation on Enterprise Identity Management strategies &amp;amp; trends&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/e-iam-7-minutes.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/H18KmcjWQD8" height="1" width="1"/&gt;</description>
		</item>
				<item> 
			<pubDate>Tue, 03 Jul 2007 00:00:00 +0200</pubDate>
			<title>Enterprise Single Sign-on Strategies &amp; Trends</title> 
			<link>http://www.kuppingercole.com/podcasts/e-sso-7-minutes.wmv</link> 
			<guid>http://www.kuppingercole.com/podcasts/e-sso-7-minutes.wmv</guid> 
			<description>In &lt;a href="http://www.kuppingercole.com/podcasts"&gt;Kuppinger Cole Podcasts&lt;/a&gt;&lt;br&gt;&lt;br&gt; 7 Minutes audio enhanced presentation on E-SSO Strategies &amp;amp; Trends&lt;br/&gt;&lt;a href="http://www.kuppingercole.com/podcasts/e-sso-7-minutes.wmv"&gt;Download&lt;/a&gt;&lt;img src="http://feeds.feedburner.com/~r/kuppingercole/~4/1amYJrZAFNE" height="1" width="1"/&gt;</description>
		</item>
			</channel>
</rss>
