<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Enterprise IT Identity &amp; Access Management : 7. How To's</title><link>http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx</link><description>Tags: 7. How To's</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>How to Reduce TCO of Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/07/422893.aspx</link><pubDate>Wed, 07 Jun 2006 10:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422893</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422893.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422893</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422893</wfw:comment><description>&lt;P&gt;Identity &amp;amp; Access Management&amp;nbsp;is an&amp;nbsp;expensive investment in IT.&amp;nbsp;Here are some tips to&amp;nbsp;reduce Total Cost of Ownership:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Follow the rule&amp;nbsp;of economy of scale -&amp;nbsp;If more people use the same solution, the unit cost of the solution will decrease. Therefore, you should&amp;nbsp;always search and&amp;nbsp;use the most popular out of shelf IAM solution in the market place first.&amp;nbsp; Your own custom built solution should be the last resource only when no other commercial solutions are available or they can not meet your needs.&lt;/LI&gt;
&lt;LI&gt;Automate repeating manual tasks - Labor time is always expensive than machine time. You should identify the repeating manual IAM tasks and automate them as much as possible.&amp;nbsp;Most of those tasks can be done by scripting. Technet Script Center is a good resource for Microsoft solutions such as Active Directory: &lt;A href="http://www.microsoft.com/technet/scriptcenter/default.mspx"&gt;http://www.microsoft.com/technet/scriptcenter/default.mspx&lt;/A&gt;. I'll provide more IAM script in Sample Code category in the future.&lt;/LI&gt;
&lt;LI&gt;Outsource your IAM operations - If your company's IT team is based in North America or Europe, you should definitely consider outsourcing IAM Tier 1 or Tier 2 support to offshore, such as India or China. The cost could&amp;nbsp;be reduced to 1/8th for US companies. It will also help to outsource IAM Tier 3 and Architecture/Integration work to larger&amp;nbsp;IT service companies such as Microsoft*, IBM and HP.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;In TCO, hardware is the smallest portion,&amp;nbsp;support is the largest portion, and software is in the middle. Currently, Microsoft MIIS is the lowest cost solution for&amp;nbsp;identity lifecycle management service&amp;nbsp;and Microsoft CA is the lowest cost solution for certificate service.&lt;/P&gt;
&lt;P&gt;*Note:&amp;nbsp;Microsoft has a new IT service offering called Microsoft Managed Solutions. This is different from Microsoft Consulting Service.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422893" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item><item><title>How to Improve Security with Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/03/422895.aspx</link><pubDate>Sat, 03 Jun 2006 06:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422895</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422895.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422895</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422895</wfw:comment><description>&lt;P&gt;Every time I told&amp;nbsp;a friend&amp;nbsp;I&amp;nbsp;got&amp;nbsp;an IT security job,&amp;nbsp;I&amp;nbsp;was always&amp;nbsp;asked a similar question "Do you&amp;nbsp;catch hackers or virus?".&amp;nbsp;Of course, the popularity of&amp;nbsp;the Internet definitely puts&amp;nbsp;external threats and attacks on enterprise IT security's radar.&amp;nbsp;However, I still personally believe internal threats and attacks cost more damage.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;According to a 2003 study by the Computer Security Institute (CSI) and the United States Federal Bureau of Investigations (FBI), nearly half of all security breaches—an astounding 45 percent—come from within the enterprise by disgruntled or malicious employees. Industry analyst firm The Gartner Group estimates that more than 70 percent of unauthorized access to information systems is committed by employees and believes that more than 95 percent of intrusions result in significant financial losses.&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;SUA,&amp;nbsp;LPA and SAT are good&amp;nbsp;IAM defense weapons&amp;nbsp;against internal identity theft:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;SUA (Strong User Authentication): Password is always weak. You should plan for 2 factor authentication (see Technology Category for definition) such as&amp;nbsp;Smart Card, USB Token, or RSA SecurID. When you&amp;nbsp;evaluate/buy a technology, an important thing is&amp;nbsp;to give equal weight to associated&amp;nbsp;lifecycle management system.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;LPA (Least Privileged Authorization or Access): A strategy to minimize internal security risk is to reduce attack surface area. LPA is an&amp;nbsp;execution of this strategy. First, you need to classify your data. Then, the access will be granted for different class of data on a "need to know" basis. A suite of software products could be used to&amp;nbsp;help LPA&amp;nbsp;(such as group management, role management, rule management, authorization management, access management, self service, workflow&amp;nbsp;etc.). &lt;o:p&gt;&lt;/o:p&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;SAT (Security Awareness Training): IAM is about process and software is just an enabler. One import process is user security awareness training.&amp;nbsp;For&amp;nbsp;example, it is easier to prevent social engineering&amp;nbsp;through this training process and it is hard (or even&amp;nbsp;not possible)&amp;nbsp;through technology.&amp;nbsp;You need to develop training courses and deliver it to all users. &lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;An IAM project to improve security will cost money. Here is a rough estimate formula to calculate cost justification:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;value of all data&amp;nbsp;($) × &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;probability of breach (%) &amp;gt; cost of project ($)&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422895" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item><item><title>How to Increase Productivity with Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/02/422894.aspx</link><pubDate>Fri, 02 Jun 2006 06:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422894</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422894.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422894</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422894</wfw:comment><description>&lt;P&gt;With right IAM solutions, your business can increase employee's productivity (or avoid the loss) significantly. Before you look into IAM solutions, you should identify&amp;nbsp;major factors impacting employee's productivity&amp;nbsp;in your business. Some common factors are:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;New employee setup time - the waste time to get a new network/system account and proper permissions to access resources. An employee could loss up to&amp;nbsp;two day's productivity.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Existing employee transition time - the waste time to get proper permissions to access new resources. An employee could loss up to&amp;nbsp;one day's productivity.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Employee password (or PIN) reset time - the waste time to get a new password or PIN after it's forgotten. An employee could loss up to&amp;nbsp;half day's productivity.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;Business merger/acquisition transition time - the waste time to consolidate identity and access for two or more organizations. This is also referred as business agility problem.&lt;o:p&gt;&lt;/o:p&gt; 
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;IAM service/support overhead - the waste time to get a new IAM related service or support.&lt;o:p&gt;&lt;/o:p&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;The productivity loss can be calculated by average lost hours multiplied by average wage.&amp;nbsp;In the case of&amp;nbsp;the password reset, industry data shows the productivity loss is from near $100 to over $200 per employee per year. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;After you analyze&amp;nbsp;business productivity loss, you&amp;nbsp;can&amp;nbsp;look for&amp;nbsp;effective IAM&amp;nbsp;solutions (which of course should cost less than the lost dollars). In this area, the IAM solutions are:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Automated real-time provisioning management - the system will create/update accounts and groups instantly in Directory after data in authoritative HR system is updated. For example, you run SAP&amp;nbsp;as HR system and MIIS as Meta Directory/Lifecycle Manager, your&amp;nbsp;will need&amp;nbsp;MIIS SAP connector (such as Microsoft MIIS SAP MA&amp;nbsp;Beta or M-Tech ID-Sync MIIS SAP MA). &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Self Services - the intranet web applications (some with a workflow engine at back) enabling employees to help themselves. For example, a Q/A based Password Reset web app will allow employees to reset password instantly&amp;nbsp;(such as Microsoft MIIS 2003 SP2 or M-Tech P-Sync). &lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Automated group/entitlement management &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;- similar to automated provisioning, the system will take care employee’s group membership and entitlement automatically without manual intervention. Currently, this type of IAM solution is new and not mature in the market (such as Quest ActivRoles Server, upcoming Microsoft MIIS code name Gemini, and Microsoft Mission Ridge).&lt;/P&gt;
&lt;P&gt;You don't have to spend extra dollars for a dedicated IAM product&amp;nbsp;to resolve the&amp;nbsp;agility problem. This solution should be just a bulk provisioning feature in&amp;nbsp;a good&amp;nbsp;provisioning management product.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422894" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item><item><title>How to Help Regulatory Compliance with Identity &amp; Access Management</title><link>http://blogs.technet.com/yaleli/archive/2006/06/01/422896.aspx</link><pubDate>Fri, 02 Jun 2006 01:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:422896</guid><dc:creator>Yale Li</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/yaleli/comments/422896.aspx</comments><wfw:commentRss>http://blogs.technet.com/yaleli/commentrss.aspx?PostID=422896</wfw:commentRss><wfw:comment>http://blogs.technet.com/yaleli/rsscomments.aspx?PostID=422896</wfw:comment><description>&lt;P&gt;You can use&amp;nbsp;IAM solutions to help demonstrating regulatory compliance such as SOX Section 404 and 302, HIPPA, GLB, Basel II Capital Accord, FDA 21-CFR-11, HSPD-12, EU Privacy Directive, PIPEDA, and LSF.&lt;/P&gt;
&lt;P&gt;SOX: There are many SOX compliance tools and you may wonder why IAM is needed. SOX compliance tools are very good at roles and SoD (separation of duties) analysis, but are weak at workflow management, reverse synchronization, and integration with multiple target systems, etc. IAM solutions are strong in those area and can&amp;nbsp;meet following SOX requirements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Controlling the accessibility of financial information 
&lt;LI&gt;Monitoring and auditing financial information accessibility in real time as well as periodically&amp;nbsp; 
&lt;LI&gt;Making sure that users access permissions to financial data are added and removed in a timely manner 
&lt;LI&gt;Making sure that these controls are applied to all systems associated with financial or business transactions and not only to the traditional financial systems&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;HIPPA: Similarly, IAM&amp;nbsp;provides very specific solutions to help healthcare organizations meet&amp;nbsp;following HIPAA requirements and reduce overall organizational risk:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Each user must be uniquely identified before being granted access to confidential information. 
&lt;LI&gt;Access to PHI must be restricted to only those persons who need access as part of their role, and the conditions of this access must be clear. 
&lt;LI&gt;PHI must be reasonably safeguarded against intentional or inadvertent disclosure. 
&lt;LI&gt;Access to protected resources must be tracked, so that complete access reports can be generated. 
&lt;LI&gt;Login attempts must be tracked so that suspicious login attempts can be analyzed and corrective action taken. 
&lt;LI&gt;Access to protected resources must be terminated quickly when an employee leaves the company. 
&lt;LI&gt;A user's session can be terminated after a specific period of inactivity. 
&lt;LI&gt;For large corporations, procedures must be implemented to protect private information of a healthcare entity from access by someone in the&lt;BR&gt;larger organization. 
&lt;LI&gt;Procedures for creating and managing passwords must be implemented.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;GLB: IAM solutions will help addressing following&amp;nbsp; GLB requirements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Evaluate IT environments and understand the security risks 
&lt;LI&gt;Establish information security policies 
&lt;LI&gt;Conduct independent assessments 
&lt;LI&gt;Provide training and security awareness programs fro employees 
&lt;LI&gt;Scrutinize business relationships to ensure adequate security 
&lt;LI&gt;Upgrade security programs that are in place&lt;/LI&gt;&lt;/UL&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=422896" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/yaleli/archive/tags/7.+How+To_2700_s/default.aspx">7. How To's</category></item></channel></rss>