- +
Strategies for Dealing With IT Complexity 24/12/2007 10:30:47
Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business. - +
Process Trip 04/02/2008 13:07:03
Why Maritz Travel revamped key business processes — and how business and IT came together to make it workWhen Rich Phillips became COO OF Maritz Travel about two and-a-half years ago, he sat down and took a hard look at the big industry picture
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Taking On Demand CRM Integration to the Next Level
Improving Sales Productivity: An Opportunity for Sales and IT Leadership
Cutting printer costs
Solve Exchange Mailbox Storage Issues Once and for All
Wireless LANs: Is my enterprise at risk?
Best Practice in Building an Integrated Information Management Strategy
Revolutionising Back-up and Recovery
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Oracle on Wednesday announced a new project to tackle one of the thorniest problems facing enterprises: the proliferation of sensitive identity information across enterprise networks.
The Identity Governance Framework is an initiative to develop specifications for sharing identity data across heterogeneous applications. The project has the support of identity and access management (IAM) vendors Ping Identity, Sun Microsystems and Securent, as well as CA and Novell. The framework and will eventually be turned over to a standards-setting body, according to Amit Jasuja, vice president of product development for Oracle's security and identity management products.
The Identity Governance Framework (IGF) grew out of Oracle's efforts to integrate identity and access management technology it acquired from Thor Technologies, OctetString and other companies, Jasuja said.
"We realized that a solution that just works with the Oracle stack is not what customers need," he said.
Instead, problems such as lost data on laptops and identity theft point to the need for overarching standards that govern all the sensitive data squirreled away in data repositories across an enterprise, such as human resources, customer relationship management and custom-built internal applications. Oracle estimates that between 60 and 80 percent of sensitive data reside in these kinds of repositories, rather than in better protected enterprise databases, he said.
"Finding out where all that information is turns out to be a huge forensic exercise," Jasuja said. "You have to root through every application repository and application logic and code to figure out how the [sensitive data] is being used."
IGF addresses that problem by establishing a governance model that allows organizations to create "contracts" between applications and repositories of identity data. The model would cover how data flows within an enterprise and outside the enterprise to supply chain or business partners, he said.
IGF has the following four components:
-- CARML, the Client Attribute Requirement Markup Language, is an XML-based language used by application developers to define contracts that specify how applications can use certain kinds of data.
-- CARML API is an Application Programming Interface that application developers can use to consume identity data in a way that conforms to the policies that govern that data.
-- AAPML or Attribute Authority Policy Markup Language, defines policy rules regarding the use of identity-related information from an identity source.
-- Identity Service is a service for securely accessing identity data from multiple identity sources based on established policies.
Open source and standards groups, including Eclipse.org and OASIS, are also working on the problem of federating identity information, but OASIS' SPML (Service Provisioning Markup Language) and Eclipse's Higgins Trust Framework are more about creating consistent user identities that work between systems, rather than managing sensitive data, he said.
"Nobody's asking whether I can propagate a social security number outside my country boundary and put it into system somewhere else," he said.
Still, Oracle believes that IGF properly belongs under the umbrella of some standards setting organization, he said.
The company plans to reach a deal to hand off its API, as well as AAPML and CARML work to such a group within the next 90 days or so. While Jasuja wouldn't say which group Oracle was considering. However, he acknowledged that a top concern is the speed with which the group can shepherd the IGF specifications through to standards.
Both OASIS and Eclipse are possible partners for IGF. Notoriously slow IEEE is not high on the list of groups that might take over Oracle's work, he said.
"Our goal is to take this into a standards organization as quickly as possible to get the (intellectual property) stuff figured out, and not sit around and waste a lot of time and energy," he said.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Internet Service Providers offer new unlimited Online Backup from F-Secure 2008-10-09 19:42:00+10
Dude! You Say I Need an Application-Layer Firewall?!
Proxy firewall technologies have proven time and again to be more secure than “stateful” firewalls. They will also prove to be more secure than “deep inspection” firewalls. High-performance proxy firewalls are available today which are easily capable of handling gigabit-level traffic. Discover more by reading on.










