Welcome to TechNet Blogs Sign in | Join | Help

Enterprise IT Identity & Access Management

A Buyer's & Integrator's Guide - WebLog Version 1.0

Syndication

News

Hi, I've moved into an Information Security Research & Strategy role from an IAM Architecture role. So this blog site is retired. I may launch a security blog in the future. Thank you all for visiting!

Browse by Tags

Introduction to IAM Buyer's Guide
“Our vision for security is to create a world where there is greater trust — where people and organizations can use a range of devices to be more reliably and securely connected to the information, services and people that matter most to them.” - Bill Read More...

Posted Tuesday, April 01, 2008 12:00 PM by Yale Li | 0 Comments

Major IAM Vendors
Vendor selection is critical in IT business. I still remember an old story when I joint big blue family last Century: a wise advice was spread among IT decision makers globally: “You will never be fired if you buy from IBM”. It had worked for a long while. Read More...

Posted Tuesday, April 01, 2008 12:00 PM by Yale Li | 2 Comments

Filed under:

RSA 2007 Conference Take Aways
There was no much exciting news at RSA2007. I think I need to write a few things down here or otherwise I will no longer remember them: - Information Centric Security: The information is the king. However, the king can not live in a castle all the time. Read More...

Posted Saturday, February 10, 2007 1:00 AM by Yale Li | 0 Comments

Review - Microsoft CLM Certificate Lifecycle Manager Beta 2
I reviewed CLM Beta 1 half year ago and rated it low. Now, CLM Beta 2 is ready for prime time and I'm going to deploy it in production environment. I've seen a lot of improvements in Beta 2 so many cons in Beta 1 are removed. Base CSP Smart Card support Read More...

Posted Wednesday, October 25, 2006 2:00 PM by Yale Li | 0 Comments

Review - ADFS v1 & Preview - ADFS v2
Active Directory Federation Service (ADFS) is a component of Active Directory released as part of Windows Server 2003 R2. ADFS v1 can be used in various B2B/B2E/B2C Web Single Sign On and Identity Federation scenarios. Pros: - Enable Federated SSO between Read More...

Posted Wednesday, October 25, 2006 2:00 PM by Yale Li | 2 Comments

IAM in TwC
I attended 2006 Microsoft EE & TwC Forum recently and tried to find out if there is any relationship between IAM and TwC. It is interesting that TwC (Trustworthy Computing) has Identity and Access Control as a grand child. At top level, TwC has four Read More...

Posted Saturday, June 10, 2006 1:00 AM by Yale Li | 0 Comments

Filed under:

IAM Strategy
IAM is a combination of processes, technologies, and policies enabled by software to manage digital identities in their lifecycle and specify how they are used to access resources. IAM is a superset of AAA (Authentication, Authorization, Auditing)*. Here Read More...

Posted Thursday, June 08, 2006 8:00 AM by Yale Li | 0 Comments

Filed under:

How to Reduce TCO of Identity & Access Management
Identity & Access Management is an expensive investment in IT. Here are some tips to reduce Total Cost of Ownership: Follow the rule of economy of scale - If more people use the same solution, the unit cost of the solution will decrease. Therefore, Read More...

Posted Wednesday, June 07, 2006 8:00 AM by Yale Li | 0 Comments

Filed under:

Authentication Strategy
Authentication is the procedure through which a user or a device or a service (or application) provides sufficient credentials to satisfy access requirements to another service, application, or system. User Authentication Strategy: · Prepare and plan Read More...

Posted Tuesday, June 06, 2006 8:00 AM by Yale Li | 0 Comments

Filed under:

Authorization Strategy
Authorization (or establishment or entitlement) defines a user's (or process') rights and permissions to a resource. After a user (or process) is authenticated, authorization determines what that user can do to the resource. Here are some authorization Read More...

Posted Monday, June 05, 2006 8:00 AM by Yale Li | 0 Comments

Filed under:

Auditing Strategy
Auditing (also referred as Audit or Accounting or Accountability) ensures that the activities associated with user access are logged for monitoring, regulatory and investigative purposes. Auditing Strategies for IAM to be compliance: Identify regulations Read More...

Posted Sunday, June 04, 2006 8:00 AM by Yale Li | 0 Comments

Filed under:

How to Improve Security with Identity & Access Management
Every time I told a friend I got an IT security job, I was always asked a similar question "Do you catch hackers or virus?". Of course, the popularity of the Internet definitely puts external threats and attacks on enterprise IT security's radar. However, Read More...

Posted Saturday, June 03, 2006 4:00 AM by Yale Li | 0 Comments

Filed under:

How to Increase Productivity with Identity & Access Management
With right IAM solutions, your business can increase employee's productivity (or avoid the loss) significantly. Before you look into IAM solutions, you should identify major factors impacting employee's productivity in your business. Some common factors Read More...

Posted Friday, June 02, 2006 4:00 AM by Yale Li | 0 Comments

Filed under:

How to Help Regulatory Compliance with Identity & Access Management
You can use IAM solutions to help demonstrating regulatory compliance such as SOX Section 404 and 302, HIPPA, GLB, Basel II Capital Accord, FDA 21-CFR-11, HSPD-12, EU Privacy Directive, PIPEDA, and LSF. SOX: There are many SOX compliance tools and you Read More...

Posted Thursday, June 01, 2006 11:00 PM by Yale Li | 0 Comments

Filed under:

Authentication Protocols and Standards
Some of most popular authentication protocols and standards are: · KERBEROS v5: Kerberos is an open standard for distributed systems authentication ( RFC 1510 ). It relies on shared secret (or password) authentication by users to an authentication server Read More...

Posted Thursday, June 01, 2006 10:00 PM by Yale Li | 0 Comments

Filed under:

More Posts Next page »
Page view tracker