Home > Security News > Companies seek identity, access management strategies
Security News:
EMAIL THIS

Companies seek identity, access management strategies

By Ira Apfel, Contributor
20 Sep 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Like any other information security sector, the identity and access management market always has its eye on the horizon for new technologies. Unified digital identity is years away but major industry players already are laying the groundwork, said Sally Hudson, an analyst with IDC.

You have large companies acquiring and deploying identity management suites that are integrated and should get better integrated over time.
Ray Wagner,
vice president, Gartner Inc.

"Between access management and authentication products and different form factors you'll see more choice and a lot of smart cards and combinations of biometrics and smart cards," Hudson Said. "You'll also see more development in Web services and federation that will allow more companies to work securely together."

But it begins with the basics, says Ray Wagner, managing vice president at Stamford, Conn.-based research firm Gartner Inc. "We just sent out a note for 2007 that basically says, 'You need to get back to the basics and build that platform,'" he said. "Then you can build federation and identity."

Wagner suggests that companies document their current processes before throwing new identity and access management technology at the problem. It's all well and good to automate user provisioning, but creating roles in the enterprise takes a great deal of thought, he said.

"If you try to define every IT role you end up with more roles than you have employees," Wagner said. "Thirty to 100 roles is enough. If you have 800 roles then you're focusing too much on defining roles."

Parts of the identity and access management field, like Web access and platform access control, are mature, said Wagner. "If you were to look at heavy Microsoft-based enterprises or Oracle-based enterprises, this stuff is not a problem at all," he said.

The maturing market is driving vendors to seek new customers in the high-end, mid-market.

"What we've seen is a huge tightening of the market, a lot of acquisitions, a lot of platform vendors like IBM, Novell, HP and Sun, snapping up best-of-breed vendors who did Web access management," said Wagner. "Now they're starting on vendors who do federation and role management. You have large companies acquiring and deploying identity management suites that are integrated and should get better integrated over time."

Wagner estimates that 20% of the market has an access management infrastructure in place and another 30-40% are thinking about, ensuring plenty of growth in the years ahead.

Hudson believes the identity and access management will grow from $3 billion in 2005 to $5.1 billion in 2010. "There's going to be more full-fledged implementation," she said. "Larger enterprises will play more with full-fledged suite sellers like CA and IBM. A company like MasterCard uses products from CA and IBM."

Regulatory compliance is driving much of the growth, according to industry analysts.

"It's not the IT group that has the budget; people are trying to deal with SOX and HIPAA," Wagner said. "You wonder how long this compliance interest will last."

Even if HR, legal and accounting departments lose their zeal for identity access management, companies likely will need to upgrade anyway. That's because the quick-fix products they bought to comply with new industry standards won't meet new security threats.

"Many Band-Aids have been put into place that will be augmented or replaced over time," said Hudson. "That doesn't mean they're bad solutions; they're just not capable enough to meet new challenges. But that's the way IT is always run."

Ira Apfel is a freelance writer in Washington DC.



Tags: Enterprise User Provisioning ToolsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Enterprise User Provisioning Tools
Quiz: Compliance-driven role management
Identity lifecycle management for security and compliance
Content-aware IAM: Uniting user access and data rights
Is Identity Management as a Service (IDaaS) a good idea?
Top tactics for endpoint security
How to edit group policy objects to give a user local admin rights
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
Lesson 3: How to implement secure access
Best practices for a privileged access policy to secure user accounts

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
AAA server  (SearchSecurity.com)
authentication, authorization, and accounting  (SearchSecurity.com)
federated identity management  (SearchSecurity.com)
logon  (SearchSecurity.com)
onboarding and offboarding  (SearchSecurity.com)
password synchronization  (SearchSecurity.com)
RADIUS  (SearchSecurity.com)
role mining  (SearchSecurity.com)
role-based access control (RBAC)  (SearchSecurity.com)
user profile  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts