Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Monday, July 23, 2007

Business-driven Identity Management

Enterprises are increasingly managing IT from a business perspective, to reduce costs, improve availability, tune capacity, optimise resource utilization, deal with risks and regulatory compliance.
In this context, the ITIL (IT Infrastructure Library) framework defines a set of best practices focused on aligning IT with businesses. This applies to a “Service-oriented Culture”, where there is an understanding that IT exists to support the business, that there is a commitment to deliver agreed level of service and that customers’ satisfaction comes first.
ITIL core disciplines are centred on Service Support and Service Delivery. ITIL provides guidance in terms of Configuration Management, Change Management, Incident Management, Security Management (based on ISO/IEC 17799) and Audit Management.
Considering the increased importance that Identity Management has in enterprises and the trend towards “Identity Services” (see here), I see the key role that ITIL is going to have in defining best practices and “Identity Controls” for Identity Management.
Ultimately, I believe that “Identity Management” (in enterprise contexts) will evolve towards “Business-driven Identity Management” – so related Identity Management solutions will …

No comments: