Welcome! Subscribe Here

Your email:

Courion Corporation

Current Articles | RSS Feed RSS Feed

Identity Challenge in the Cloud - RSA Conference

  
 

Identity Challenge in the Cloud - RSA Conference

I was at the RSA conference last week and out of all the sessions I attended, the most packed room was a session about Cloud and identity challenges.  The presenter discussed the subtleties between Cloud, SaaS, hosted, grid, etc, the presenter talked about the pain points in the consumer and enterprise worlds.  A common theme was security, and managing identity (provisioning), identifying the need for access assurance solutions able to address this new segment.

Identity as a Service (IDaaS) was discussed along with Authentication as a Service (AaaS).  While we'd all like to get to a single identity and pass claims and assertions around, this seems unlikely.  It will be difficult to get all parties involved to use the same technologies, standards, and more importantly, agree to trust each other.  It reminds me of SSO and centralized directories.  ESSO was supposed to get rid of all enterprise passwords.  Centralized directories were going to consolidate directories.  In the end businesses will get some consolidation, but still have a handful.

Whether applications are in the cloud or in house, it seems likely that the same needs and concepts will apply.  You'll need to manage access through its lifecycle (hire, change, terminate).  You'll need to get access set up properly, and with least privilege.  Check policy, enforce policy, etc.... 

Comments

Currently, there are no comments. Be the first to post one!
Post Comment
Name
 *
Email
 *
Website (optional)
Comment
 *

Allowed tags: <a> link, <b> bold, <i> italics