Dynamic Authorization
Facebook Twitter LinkedIn

Dynamic Authorization

Combined Session
Thursday, May 07, 2015 14:30—15:30
Location: AMMERSEE I

Adaptive Policy-Based Access Management: Beyond ABAC and RBAC

Over the past several years, there have been a lot of discussions around terms such as RBAC (Role Based Access Control), ABAC (Attribute Based Access Control), Dynamic Authorization Management (DAM) and standards such as XACML. Other terms such as RiskBAC (Risk Based Access Control) have been introduced more recently.

In particular, a frequent discussion has been going on between RBAC and ABAC enthusiasts, as to whether attributes should or must replace roles. However, most RBAC approaches in practice rely on more than purely role (i.e. on other attributes), while roles are a common attribute in ABAC. In practice, it is not RBAC vs. ABAC, but rather a continuum.

During this session, Martin Kuppinger will open the discussion on the different ways how access is granted - in a static, ACL-like approach or more dynamically, based policies and contextual information - and what the challenges are when moving to a more dynamic approach.

Adaptive Policy-Based Access Management: Beyond ABAC and RBAC
Presentation deck
Adaptive Policy-Based Access Management: Beyond ABAC and RBAC
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Martin Kuppinger
Martin Kuppinger
KuppingerCole
Martin Kuppinger is Founder and Principal Analyst at KuppingerCole, a leading analyst company for identity focused information security, both in classical and in cloud environments. Prior to...

The Future of Authorization

In this panel, the participants will look at where authorization is today and where it should be in an ideal world. They will discuss the trends and evolution in that area, such as the growing relevance of OpenAZ. They will discuss whether there are gaps in standards and technology that must be addressed. They will discuss how to solve the challenge, that the vast majority of applications is not ready for APAM (Adaptive Policy-Based Access Management). They will provide hints on how to solve the gap from both an organizational and technical perspective and how to make APAM a reality. And if it’s not APAM, they will introduce new ideas for better authorization.

The Future of Authorization
Presentation deck
The Future of Authorization
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Gerry Gebel
Gerry Gebel
Axiomatics
Gerry is responsible for sales, marketing and business development for the Americas region. In addition, he contributes to product strategy and manages Axiomatics’ global partner relations....
Martin Kuppinger
Martin Kuppinger
KuppingerCole
Martin Kuppinger is Founder and Principal Analyst at KuppingerCole, a leading analyst company for identity focused information security, both in classical and in cloud environments. Prior to...
Darran Rolls
Darran Rolls
SailPoint
Mr. Darran Rolls is the Chief Technology Officer and Chief Information Security Officer and at SailPoint, where he is responsible for directing the company’s technology strategy and security...
Markus Weber
Markus Weber
ForgeRock
Frank Wittlich
Frank Wittlich
Talanx Systeme AG
He started his professional career as consultant for safety critical applications at TUV Rheinland Group, changed over as project manager and IT process consulatant in the software development...
Subscribe for updates
Please provide your email address