Home > Security News > Companies share identity management struggles
Security News:
EMAIL THIS

Companies share identity management struggles

By Robert Westervelt, News Editor
14 Nov 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

SAN FRANCISCO -- Jim Raub, director of IT security at broadband services provider Paetec Communications, had limited time to get Oracle's Identity Manager rolled out to streamline naming conventions and user provisioning to tighten access control across the company.

Business has been growing steadily for Paetec. With a number of planned acquisition targets, Raub was under pressure to get an identity management solution in place to meet compliance demands and scalability issues.

Like many companies implementing identity management tools, the company experienced a number of problems Raub attributes to the need to get a system online quickly. The company didn't have an adequate test environment, data cleansing was an issue, getting various data holders to agree on an ID format also was a challenge, he said. And custom connectors had to be built to connect to several Unix-based applications.

More information on identity management

Implementing ID and access management (Part 2)

IT Management Guide: Identity management for the SMB

"There was just too much going on and some upheaval because we had to get it in quickly," he said. "If we weren't trying to integrate the company so quickly, the whole process would have been easier."

Raub shared his Oracle Identity Manager implementation experience during a panel discussion Tuesday at Oracle's OpenWorld user conference. Despite their challenges, employees are seeing the value of identity management software. While companies have been struggling with various problems implementing an identity management software -- whether it be during the data cleansing phase or instituting a common naming structure -- the best way to begin an implementation is just before company growth, when the company is small and agile, the panelists said.

Oracle has done a good job buying its way into the identity market. It acquired provisioning software from Thor Technologies in 2005 and since then analysts say it has become a big player. It threatens CA, IBM and Sun for outright leadership, said Mark Diodati, an analyst with Midvale, Utah-based Burton Group.

Oracle security:

Podcast: The state of Oracle security


Oracle bulletins will rank patches, offer more detail

Oracle DBAs mixed on security progress

"Oracle has made a whole slew of acquisitions in 2005 from purchasing Web access management products and federation," Diodati said. "You can tell by the acquisitions that they've done that they clearly value the identity management space. They are a full-fledged player and arguably with the most complete set of identity management products in their suite."

And Oracle has been making progress selling their identity manager to their own customers as well as marketing the products to new customers, Diodati said. Still, point solutions exist and companies should examine their options.

Kenny Gilbert, director of technology solutions at Sunnyvale, Calif.-based semiconductor installations provider Silicon Image, said his company didn't even consider other vendors for identity management. The company recently completed a $120,000 five-month implementation.

"Compliance absolutely was a major driver for us," Gilbert said. "It was also critical to have a single source for employee information."

Gilbert said if he had to do the project over, he would have tweaked the naming convention to avoid issues with multiple systems. The company could have also been more proactive to get its Unix systems all on the same patch set, he said.

Rex Thexton, chief technology officer of Bedminster, N.J.-based consulting firm Entology, said most of his firm's customers are driven to identity management to meet Sarbanes Oxley and other regulations.

"Either they are planning acquisitions or getting ready to go public," he said.

Raub said the company is so pleased with its implementation that the plan is to start rolling it out to other non-Sarbanes Oxley systems, such as the company's ID badge system.

"They improved their processes and the result has been a much better company," he said.



Tags: Two-Factor and Multifactor Authentication StrategiesEnterprise User Provisioning ToolsActive Directory and LDAP SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Two-Factor and Multifactor Authentication Strategies
Two-factor authentication, vigilance foil password theft
Security on a budget: How to make the most of authentication tools
Best Authentication Products
Best Identity and Access Management Products
Are 'strong authentication' methods strong enough for compliance?
PCI compliance requirement 7: Restrict access
PCI compliance requirement 9: Physical access
Best practices: How to implement and maintain enterprise user roles
Changing times for identity management
RSA researcher Ari Juels: RFID tags may be easily hacked

Enterprise User Provisioning Tools
Content-aware IAM: Uniting user access and data rights
Is Identity Management as a Service (IDaaS) a good idea?
Top tactics for endpoint security
How to edit group policy objects to give a user local admin rights
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
Lesson 3: How to implement secure access
Best practices for a privileged access policy to secure user accounts
Risk management must include physical-logical security convergence
PCI compliance requirement 7: Restrict access

Active Directory and LDAP Security
How to edit group policy objects to give a user local admin rights
Using IAM tools to improve compliance
Ease the compliance burden with automation
Changing times for identity management
Product Review: Symark PowerADvantage 1.5
Do the Group Policy Object and 'Password Never Expires' flag interact?
Directory services and beyond: The future of LDAP
What are the benefits of identity managed as a service?
Enterprise role management: Trends and best practices
Identity Management Suites Enable Integration, Interoperability
Active Directory and LDAP Security Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
AAA server  (SearchSecurity.com)
authentication  (SearchSecurity.com)
authentication, authorization, and accounting  (SearchSecurity.com)
federated identity management  (SearchSecurity.com)
Kerberos  (SearchSecurity.com)
password hardening  (SearchSecurity.com)
typeprint analysis  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts