Home > Security Tips > Network Security Tactics > 2006 Products of the Year: Identity and access management
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

2006 Products of the Year: Identity and access management


Staff
02.01.2006
Rating: --- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RSA ClearTrust
RSA Security, www.rsasecurity.com

"The struggle between security and usability is no greater anywhere than in health care," says Chris Gervais, senior research analyst/technologist for Partners Healthcare. Partners' challenge was to give community-based medical and administrative personnel easy, secure access to patient records throughout its extensive Massachusetts network of hospitals and clinics.

The solution, RSA Security's RSA ClearTrust, provided the convenient Web portal Partners needed, with the security that management -- and HIPAA requirements -- demanded. It's the kind of experience that spurred voters to make ClearTrust the gold-medal winner for identity and access management.

In the past, Partners' highly mobile employees had to rely on VPN access -- which meant using digital certificates, sending out installation CDs and giving direct network access to laptops vulnerable to spyware and other malicious code. This was both a management burden and an impediment to adoption.
More information on access management

Learn everything you need to know about access management in Lesson 2 of our Training for CISSP Certification.

Visit our resource center for tips and expert advice on access management.

 

"Clinicians and admins use ClearTrust to arrange care; largely, it's made it invisible," says Gervais. "They know they log in to a secure site with strong credentials."

Partners had a history with RSA, using RSA SecurID for strong authentication. But what sold Gervais -- and the organization's steering committee -- on ClearTrust over other Web-based access management products was confidence that RSA would provide more functionality out of the box and could get up and running quickly.

"We had an aggressive timeline. Time to market was important," Gervais says. "RSA brought the necessary resources to bear."

Readers gave ClearTrust some of the highest grades across the board in our Products of the Year survey, with particular emphasis on security and performance.

ClearTrust provides Web-based single sign-on capability with highly granular and flexible access control policies through what RSA calls Smart Rules technology. Smart Rules allows organizations to leverage existing data repositories to permit real-time authorization decisions and speed deployment. It supports a wide range of authentication options. Its comprehensive auditing and reporting features were a powerful persuader for Partners.

"Obviously, we have to comply with HIPAA, and we have to go through a bunch of audits," Gervais says. "With ClearTrust, our information security office sets up procedures; inside the application, we have clinical security policies down to the patient level. We can audit changes in patient records going back two years. It's nice, finely grained audit data."




Novell eDirectory
Novell, www.novell.com

At the heart of Novell's identity and access management offerings beats eDirectory, a mature and very solid directory product that draws reader praise for overall quality and security.










Sun Java System Directory Server Enterprise Edition
Sun Microsystems, www.sun.com

Sun's respected directory shines brightly, drawing reader kudos for performance and overall quality, with a strong vote for security.






Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network Security Tactics
IE 8 beta 2 security features may mark improvements for browser security
Screencast: How to use Nipper to create network security reports
Mining enterprise SIM logs for relevant security event data
How to configure NAP for Windows Server 2008
Exploring Microsoft's Network Access Protection policy options
Screencast: How to use Wikto for Web server assessment
How to avoid DLP implementation pitfalls
Microsoft Baseline Security Analyzer: Do updates offer improved Windows security?
How to patch Kaminsky's DNS vulnerability
Directory services and beyond: The future of LDAP

Enterprise Single Sign-On (SSO)
Sun launches open source OpenSSO for identity management
What are the pre-requisites for implementing single sign-on (SSO) in an organization?
Startup Symplified delivers SSO in the cloud
SaaS Offering Handles SSO
Kerberos security evolves for B2B, mobile tech
IBM acquires Encentuate for single sign-on software
Security360: Identity management market
Top 10 access-related controls for PCI compliance
What type of protections should security question and answer authentication credentials have?
Traditional single sign-on (SSO) products versus federated identities
Enterprise Single Sign-On (SSO) Research

PKI and Digital Certificates
What is the best way to administer exams to students via computer?
Should computer exams be transmitted as PDF files or Word files?
Should PKI systems be used for laptop encryption?
Email authentication showdown: IP-based vs. signature-based
VeriSign to shed businesses, return to security roots
How do anonymous credentials and selective disclosure certificates affect enterprise IAM?
Choosing from the top PKI products and vendors
Can the symmetric encryption algorithm for S/MIME messages be changed?
Securing VoIP Networks: Threats, Vulnerabilities and Countermeasures
Creating a personal digital certificate
PKI and Digital Certificates Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
single sign-on  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts