English   Deutsch

Product Report: Axiomatics Policy Server and Policy Auditor

This product report covers the Axiomatics Policy Server and the accompanying Policy Auditor. These products fall into the category of Entitlement Management solutions. They use the XML-based XACML standard – Extensible Access Control Markup Language – to define authorisation policies and make access control decisions. Agents are available for the Java and .NET platform that work together with the Policy Server in order to enforce the policies.

Axiomatics has distinguished itself from other vendors in this space by focusing on a solution that consistently implements and complies with the XACML standard. Axiomatics internally uses XACML for policy storage and authoring as well as the XACML query/response language for Policy Enforcement Points. This is different from the approach of some other vendors who have implemented the XACML query/response language on top of existing access control engines which then also may use a different (usually simpler) model to author policies. The approach chosen by Axiomatics therefore comes with the promise of higher flexibility – but at the expense of complexity. The product comes with a graphical user interface that allows administrators to define XACML policies without having to edit raw XML files. However, a deep knowledge on XACML is still required. The accompanying Policy Auditor allows for the testing of policies and the definition of “what-if” scenarios. These can then be evaluated to verify the correctness of the defined policies against simulated requests. In that area, the direct linkage to the underlying policies causing the results is currently missing. For its deployments, Axiomatics recommends more application specific PAP interfaces with point-and-click capabilities that are provided by its professional services organisation during the deployment project once the attribute context is better known and such an interface can be drafted in a meaningful way. However, that still means some effort to reduce the inherent complexity.



Download
Date Title Price
11.03.10 Product Report: Axiomatics Policy Server and Policy Auditor

by Felix Gaehtgens
fg@kuppingercole.com

€95.00 ORDER 
Current surveys
IAM-Studie 2011/2012
PARTICIPATE 
Information
Newsletter
Kuppinger Cole Identity Management Newsletter
Services
KC provides strategic consulting services for vendor and user companies covering all areas of identity & access management.
Reports
Use KC as an independent, objective, and neutral authority on the Market for Identity Management products and solutions
Podcasts
Free audio and video presentations on important IAM-topics
Blogs
Martin Kuppinger
31.01.2012 13:10
LinkedIn – the next bad guy
READ 
Dave Kearns
31.01.2012 13:01
Evil, or just different
READ 
Sebastian Rohr
27.01.2012 10:31
Personal Data Vault – putting YOUR data in YOUR hands
READ 
Tim Cole
27.01.2012 10:24
Stopping a Clapper Over WikiLeaks
READ 
Mike Small
13.12.2011 12:48
EVERY MOVE YOU MAKE I’LL BE WATCHING YOU
READ 
European Identity Conference Blog
16.11.2011 19:14
KuppingerCole on Google+
READ 
Craig Burton
28.10.2011 10:49
More on the Open API Revolution
READ 
Joerg Resch
24.10.2011 10:55
Hunting for the latest Android Release?
READ 
Sachar Paulus
06.06.2011 14:50
News from the Analyst Summit in London
READ 
Links
 KuppingerCole News

 KuppingerCole on Facebook

 KuppingerCole on Twitter

 KuppingerCole on Google+

 KuppingerCole on LinkedIn

 Our group at Xing

 Our group at LinkedIn

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2012 Kuppinger Cole