English   Deutsch

Sebastian Rohr: Identity Management: Challenge Outsourcing

Identity Management: Challenge Outsourcing
by Sebastian Rohr
sr@kuppingercole.com

In fact there are a number of good reasons why you should think about IAM (Identity & Access Management) every time you think about GRC (Governance, Risk & Compliance). Despite all the efforts to secure externally managed services and applications through policies and technology, gaps in the safety nets set up by those in charge of GRC remain. Third-party access to outsourced data is a good example. Just take maintenance and management services: written agreements on security standards and policies notwithstanding, reality shows that controlling, audit trails and internal compliance assurance measures are often incapable of closing every loophole.

What are the real problems? Take as an example hosted applications operated by one service provider but originally developed by another. The company information being processed is probably both valuable and restricted. How do you ensure that it isn't compromised when the developer has to run an update? And how is the developer to perform the necessary tests to ensure that the application won't crash once the update has been performed? Finally, how do you ensure that neither service provider can access the confidential data in the system itself?

Again, the answer is IAM when the situation calls for managing access rights, persons and identities in cases where external identities (service personnel) come in contact with internal data. Solving these issues requires legal and contractual procedures on the one hand and technical measures on the other. Given that all this is happening outside the administrative jurisdiction of the company itself, ensuring central management of access rights may very well require an external operations service provider, too.

But what path to follow? For existing installations, technical auditing may be the right answer in order to determine the true current status of access rights and protections. Based on the results, appropriate measures can be decided on and taken. Technically, these may consist in implementing Identity Federation between the three parties involved so as to reduce administration overhead. In the case of new applications, the best strategy is probably to switch to claims-based rights management which does away with individual user and rights management, substituting one-time definition of access privileges for certain resources using challenge-response instead, thus enhancing the federation concept.

One thing is clear, however: In compliance, it never pays to underestimate the potential complexity. For instance, there are data protection issues and information leakage risks, as well as everyday garden-variety IT security problems. If you plan to outsource, these all need to be resolved. And while this may appear simple when dealing with a single outsourcing provider, it may prove a nightmare when a multiplicity of "cloud computing" providers are involved.

Created: 06.10.09, modified: 19.10.09

Information
Newsletter
Kuppinger Cole Identity Management Newsletter
Services
KCP provides strategic consulting services for vendor and user companies covering all areas of identity & access management.
Reports
Use KCP as an independent, objective, and neutral authority on the Market for Identity Management products and solutions
Podcasts
Free audio and video presentations on important IAM-topics
Current surveys
Marktstudie IT Service Management
PARTICIPATE 
Blogs
Martin Kuppinger
11.03.2010 11:57
Versatile authentication – break-through for mass adoption of strong authentication?
READ 
Tim Cole
09.03.2010 08:25
The business of business is trust
READ 
Sebastian Rohr
24.02.2010 19:23
Ever had trouble securely sharing data with business partners?
READ 
Felix Gaehtgens
19.02.2010 17:40
Gerry Gebel joins Axiomatics
READ 
Joerg Resch
17.02.2010 11:15
Identity Management is key to Smart Grid Security
READ 
European Identity Conference Blog
12.02.2010 13:16
EIC 2010 Agenda Preview
READ 
Links
 Kuppinger Cole News

 Kuppinger Cole Podcasts

 Kuppinger Cole on Facebook

 Kuppinger Cole on Twitter

 Visit us at Xing

 IAM-Wiki

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2010 Kuppinger Cole + Partner