Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Monday, December 1, 2008

A Fine Balance 2008: Privacy Technologies in Action

On November, 27th I attended the UK “A Fine Balance 2008: Privacy Technologies in Action” event. It provided different and interesting perspectives (from the technological, social and legislative angles) on privacy. Presentations are soon going to be made available online:

“Following the success of the 2006 and 2007 Fine Balance events, four of the government's Knowledge Transfer Networks present the third in this series of independent forums that are already helping industry, government and academia achieve a balance between ensuring privacy and enjoying the benefits of new technology.”

--- NOTE: my original HP blog can be found here ---

Wednesday, November 19, 2008

Article: Changing business landscape makes IAM key to IT Security

Here is a recent, interesting article, called “Changing business landscape makes identity and access management key to IT security”:

“In an age of significant layoffs and corporate restructuring, the burgeoning problem of identity and access management for IT operations and data centers has escalated into a critical security issue. Managing who gets access to which resources for how long — and under what circumstances — has become a huge and thorny problem. Improper and overextended access to sensitive data and powerful applications can cause massive risk as many employees find themselves in flux.”

This article provides some excerpts from a discussion with Dan Rueckert (worldwide practice director for security and risk management in HP’s Consulting and Integration group); Archie Reed (distinguished technologist in HP’s security office in the Enterprise Storage and Server Group), and Mark Tice (vice president of identity management at Oracle).

Friday, November 14, 2008

Part II: On Applying Modelling and Simulation Techniques to Identity Management

Thanks to the readers that sent comments to me (interestingly, by email …), about my previous post on “Applying Modeling and Simulation techniques to Identity Management”. Feel also free to post your comments directly on the blog.

An interesting question I received was about the overall scope of the R&D work on Identity Analytics, i.e. if it only strictly applies to the Identity Management space.

I would say that the scope is wide. The goal is to include also economics aspects, people’s behaviours, privacy and privacy management elements along with any IT and business aspects of relevance for the analysed scenario/case study. Our models and simulations indeed represent the (risk mitigation) effects of identity controls: they do it in the context of the scenario of interest, by including the representation of involved processes, data storage, information flows along with relevant applications and services.

The outcomes of our models can vary, depending on the questions we want to answer, such as ROIs in using specific IdM solutions, trade-offs in investments, impact of controls and security on usability, etc.

Hope this answer the question.

Please have also a look at the Demos2k model attached to our recent HP Labs Technical Report HPL-2008-186, for a few illustrative examples of the above points.

--- NOTE: my original HP blog can be found here ---

Friday, November 7, 2008

On Applying Modelling and Simulation Techniques to Identity Management

At HP Labs, within the “Identity Analytics” project, we are researching how to apply modeling and simulation techniques to the domain of Identity Management, to explore and predict:
  • the consequences of potential decisions made by decision makers (e.g. in terms of strategic policies and adoption of controls) on key aspects such as security risks, costs, impact on reputation, etc.;
  • the impact of identity management solutions on IT infrastructures, people and business contexts;
  • the implications of people behaviours on security and privacy aspects.


The aim is to help decision makers to assess the consequences of their decisions and explore investment trade-offs. In particular, assessing the impacts on security risks and costs is very important: given the current global financial situation, the “cost” dimension is going to play more and more a key role.

We published a few HP Labs Technical Reports to provide an overview of our R&D work, including HPL-2008-186 and HPL-2008-84. In particular, the most recent HPL-2008-186 report provides and example of a model (based on the Demos2K simulation framework) we used to carry out our simulations and trade-off analysis in a “data sharing collaborative scenario”.

Many case studies can potentially be explored with our approach, including Web 2.0 collaborative services, access and protection of critical business applications and services, user account lifecycle management processes, data flows and lifecycle management, identity theft scenarios, etc.

I would be interested in discussing this topic with this community, in particular about related work and exploring any specific requirement or case study you might have in this space.


--- NOTE: my original HP blog can be found here ---

Wednesday, November 5, 2008

Research Study: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk

This interesting article, called “Identity Theft Risks: Huge Amount of Sensitive Data Still on Redundant Computer Hard Disk” provides an overview of a research study to be published soon – warning about the risk of data left on devices to be decommissioned:

"Ongoing research to be published in the International Journal of Liability and Scientific Enquiry suggests that there is a huge amount of sensitive data still on redundant computer hard disks. These devices are often disposed of or sold into the second-hand market by corporations, organizations, and individuals with the data intact. The report's authors say that this data represents a significant level of risk for commercial sabotage, identity theft, and even political compromise, and suggest that better education is essential to reduce the risk of harm. ...
The 2007 study is being made available in its entirety through the International Journal of Liability and Scientific Enquiry. The team is now completing the 2008 analysis and will announce those results shortly as well. However, the initial results for the 2008 study show that there is still a long way to go regarding the decommissioning of computer hard disk drives. The team expects that the complete 2008 study will be made available for publication by the end of the year."
This is an area where “classic” identity management (based on control points) shows its limits. The explicit management of IdM strategic policies, related processes and risks should be a key part of “identity management”.

“Identity Analytics” could also be of some help here, to understand the implications of policies and possible strategic decisions (given specific IT and IdM frameworks), along with exploring investment trade-offs.

--- NOTE: my original HP blog can be found here ---

Monday, November 3, 2008

Policy 2009: International Symposium on Policies for Distributed Systems and Networks

The CfP for Policy 2009 (International Symposium on Policies for Distributed Systems and Networks) is now available online. Topics of interest include, but are not limited to:

  • Privacy and Security
  • Policy Models and Languages
  • Policy Applications

This year, Policy features a special track on the policy lifecycle and usability issues related to policy-based management of privacy and security.

Of course, papers discussing the application of policies to the identity management domain are welcome.

Abstracts are due by 23 February 2009, whilst papers are due by 02 March 2009.


--- NOTE: my original HP blog can be found here ---

Tuesday, October 28, 2008

Top 5 Mistakes of Privacy Awareness Programs?

Jay Cline, in an interesting article called “Opinion: Top 5 Mistakes of Privacy Awareness Programs”, lists the top five shortcuts that many large corporations take when dealing with privacy awareness programs:
  • Doing separate training for privacy, security, records management and code of ethics
  • Equating "campaign" with "program"
  • Equating "awareness" with "training"
  • Using one or two communications channels
  • No measurement

Have a look.

--- NOTE: my original HP blog can be found here ---

Monday, October 27, 2008

Part II: TSB EnCoRe Project – Ensuring Consent and Revocation

In a previous post of mine, I announced the UK TSB EnCoRe project, focusing on research on Consent and Revocation.

A new version of the EnCoRe web site is now available online.

I would be interested in getting your views and input on two aspects:

  • Prior art and work in the space of consent and revocation. In a first analysis, very little work is available in terms of automation of revocation of consent, in a wide sense. Any known work/solution in this space?
  • Your (user) requirements in the space of consent and revocation


--- NOTE: my original HP blog can be found here ---

Wednesday, October 22, 2008

PrivacyOS: Thematic Network for Privacy Protection

PrivacyOS (Privacy Open Space) is “a thematic network for privacy protection infrastructure within the current European Commission´s ICT Policy Support Programme. The Project has started at the beginning of June 2008 and brings together industry, SMEs, Government, Academia and Civil Society to foster development and deployment of privacy infrastructures for Europe.”

More details can be found here.

Last week I attended the first PrivacyOS Conference (Strasbourg, 13-15 October 2008). It has been very interesting and stimulating, considering the heterogeneous background of the audience, their presentations and subsequent discussions. I would encourage the members of this community to attend in the future (the next conference is going to happen in April 2009).

In this context, I gave a presentation on "Enabling Privacy-aware Information Lifecycle Management in Enterprises", describing work done at HP Labs and in the EU PRIME project (Framework VI), in the space of “Management of Parametric Privacy Obligation Policies”.

--- NOTE: my original HP blog can be found here ---

Tuesday, October 21, 2008

Online Dialog on Health Information Technology and Privacy

As highlighted by this article, called “OMB sponsors online discussion of privacy issues”:

“The Office of Management and Budget has asked the National Academy of Public Administration to hold a public discussion this month of health care privacy issues through an interactive Web site.”

This online dialog will take place the week of October, 27, at: http://www.thenationaldialogue.org/.

--- NOTE: my original HP blog can be found here ---

Thursday, October 2, 2008

Identity Management in the Cloud

This article, called “ID Management In the World of Cloud Services” (and a related podcast) is quite interesting, as it is thought provoking.

The advent of cloud services and services on demand is indeed likely to change the identity management landscape: most of current identity management solutions are focused on the enterprise and/or a very controlled, static environment. User-centric identity management solutions (such as various federated identity management) also make some assumptions on the involved parties (e.g. SP, IdP parties) and their related services.

In a world where services are offered on demand, in the cloud and they can continuously evolve, some of these models are going to be challenged, for example, in terms of trust assumptions, privacy implications and operational aspects of authentication and authorization.

Is anybody aware of studies in this space? What is your view?

--- NOTE: my original HP blog can be found here ---

Friday, September 19, 2008

Announcing EnCoRe (Ensuring Consent and Revocation): a new UK IT Collaborative Project

A new UK IT collaborative project has been officially announced: EnCoRe – Ensuring Consent and Revocation (some initial press releases: here and here):

“As more and more personal information flows from individuals to organisations when they interact online, people are becoming more and more concerned that they can not effectively control what this information is used for, with which other organisations it is shared, and where it is stored. They may have given their consent, often in vague terms and implicitly, for its use, sharing and storage, but they have no real control over the specifics of these, nor the ability to revoke their consent and be sure that their wish is respected. In summary, they are not able to control where their personal information flows to, and this makes them uneasy about interacting online.

The overall vision of this project is to make giving consent as reliable and easy as turning on a tap, and revoking that consent as reliable and easy as turning it off again.”

This £3.6m project consortium is multi-disciplinary, spanning across a number of IT and social science specialisms. The project partners are Hewlett-Packard Laboratories, HW Communications, QinetiQ, the London School of Economics, the Ethox Centre of the University of Oxford and the University of Warwick.

The EnCoRe project runs from June 2008 to November 2011. It receives funding from the UK Government’s Technology Strategy Board, Economic & Social Research Council and Engineering & Physical Sciences Research Council.


--- NOTE: my original HP blog can be found here ---

Thursday, September 11, 2008

On Gartner’s Magic Quadrant for Identity Management

You might be interested in having a look at Gartner’s Magic Quadrants for Identity Management. In particular, a recent article (15 August 2008) published by Earl Perkins and Perry Carpenter focused on the “Magic Quadrant for User Provisioning”:

“User provisioning delivers capabilities to manage users' identities across systems, applications and resources. Driven by compliance (security effectiveness) and security efficiency, the market is maturing, but identity governance and role-based access concerns raise new issues for customers.”

On one hand this kind of reports provides good insights about the current state of the art (in this case about user provisioning). On the other hand, some criticisms have been given about the overall evaluation of current IdM solutions and their positioning in the “magic quadrant”. For example, have a look at this article by Dave Kearns.


--- NOTE: my original HP blog can be found here ---

Thursday, September 4, 2008

Part II: Risk Management for Unstructured Data in Enterprises

In a recent post published on the Netweaver Identity Manager Weblog, the author has made a few comments about my post on “Risk Management for Unstructured Data in Enterprises” (well, actually the published URL to my post is apparently broken …).

Thanks for this input, in particular about three main points that I (tried to) summarise as it follows:

1) Meaning of unstructured data (or the fact that unstructured data does not exist by definition …)
2) Narrowness of perception of approaches and incompleteness of my list of required solutions
3) Availability of comprehensive methodology for implementing enterprise wide risk management

About point 1), this looks pretty much a philosophical discussion. No doubt that, at the end, we talk about information that has some sort of structure (well, an email has a header, a body with some texts and attachments; a document is made of paragraphs or lines of text; …). However, the (maybe over-hyped) “unstructured data” term is currently used to (a) identify specific types of information and (b) contrast it against classic “structured data” (e.g. information stored in RDBMS repositories, etc.). I think I will stick with this terminology …

Back to the key point, recent reports (including the Ponemon Institute’s survey on “Governance of Unstructured Data” and other market and research reports) indeed highlight that the management of unstructured data in enterprises is a raising concern for enterprises, both in terms of governance and risk management. I think this is what really matters – independently from the terminology.

No doubt that classification of data is an important point, especially if you ever manage to “find” where this “unstructured data” is, within a complex enterprise environment … I would say that, given the particular nature of “unstructured data”, a preliminary “data discovery” phase might be required, indeed followed by a classification and assessment of its value (considering though, that the value of some of this information might also come from aggregations and correlations …).

About point 2), by no means my post was meant to provide a definitive or comprehensive assessment and answer to the problem of information risk management or, more specifically, on “unstructured” information risk management. It was just a statement of some “desirable” properties and capabilities that I would like to see (and I know it would be of some help to customers …).

I am well aware of the complexity of the overall (security) “enterprise risk assessment and management” problem, its extent and the fact that, when assessing and managing (security) risks, many factors are involved, including business goals, IT, other assets, people, processes, awareness/education, etc.

(Security) risk assessment and management techniques/methodologies/frameworks and standards/etc. are indeed out there (e.g. ISO 27005/2700x, CoBIT, etc.). These “standards” provide guidelines and criteria to be carefully refined, grounded and contextualized in various “operational” realities, along with some good, common sense …

So, no doubt that there are already “comprehensive methodology for implementing enterprise wide risk management”, at least from a consulting perspective, but this was not my main point.

My main point was not so focused on these methodologies but rather on the need to better understand and possibly improve the process of exploring, explaining and predicting the consequences and impacts of strategic (policy) choices and decisions in enterprise contexts and environments, in particular when dealing with security matters.

An approach that we are currently exploring is based on modeling and simulation techniques in the security field, coupled with economic theory and social science. Please have a look at the HPL Technical Report on “Identity Analytics” that I mentioned a few times – to see what I mean, in more details (at least from an “IdM perspective”).

Specifically, one of my R&D interests is in “(semi-) automation” tools and solutions in this space that can indeed help and support professional and consulting services in their risk assessment & management activities. This includes providing decision support and “what-if analysis”, involving modeling and simulation, providing trade-off analysis, etc.

Given the complexity of this space, I deliberately focused on the aspect of “management of unstructured data” and the IdM perspective, well conscious this is just a part of the overall problem and space.

I hope I clarified this point.

About point 3), no doubt about this, as I mentioned above.

However the statement that “comprehensive methodology for implementing enterprise wide risk management is done” sounds (at least to me) sounds a little bit abstract to me …

It would be of some interest to the readers of this blog if this statement could be elaborated (specifically in the space of IdM and information management) along with providing some recommendations/input/directions (hopefully beyond having to hire a consulting company … :-)).

--- NOTE: my original HP blog can be found here ---

Monday, September 1, 2008

Risk Management for Unstructured Data in Enterprises

In the context of the HP Labs’ Security and Identity Analytics project I have been investigating the implications of “unstructured data” (i.e. emails, documents, multimedia files, pages in data sharing sites, messages exchanged with Instant Messaging tools, blog posts, data mash-ups, etc.) within organizations, along with how to explain and predict involved risks and explore the consequences of related security (policy) choices.

Is “unstructured data” really a problem for organizations? If so, where is this problem? Well, the content of unstructured data (and/or an aggregation of it) can be confidential as it might include personal, financial and business-critical information. Because of the nature of unstructured data (and associated, emerging tools to handle and share it), there are many ways this data could leak and/or be misused, ranging from accidental disclosures to aggregations of information posted in public areas.

The threat landscape (including threats to data confidentiality, integrity and availability) is potentially broad as many contextual elements, IT components, processes and behavioral aspects are involved.

Most of the current approaches (I am aware of), that mitigate some of the involved risks, are based on traditional IT security and identity “control points” (such as access control, interception points, complex document lifecycle management tools, etc.), addressing “point problems”.

I believe this is not enough. Solutions are required to help organizations (and decision makers) to: (1) fully understand the nature of the problem, based on their specific context and environment; (2) have a picture of their overall risk exposure; (3) make informed decisions on which approaches to follow, explain and predict the consequences and define appropriate policies; (3) explore trade-offs.

So far I have found no comprehensive approach/solution providing these features. Is anybody aware of any?

--- NOTE: my original HP blog can be found here ---