Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Thursday, February 28, 2008

Lost mobile devices account for most UK data leaks …

This is what is reported by a recent NetworkWorld article, based on the findings of a Ponemon Survey:

“The average cost of a data breach is £47 ($94) per compromised record, according to a path breaking survey from the Ponemon Institute.

For security blunders in the financial services sector, that cost rises to £55 per compromised record.

Lost or stolen laptops and mobile devices account for most data breaches in the U.K., according to the research … Thirty six per cent of data breaches resulted from lost and stolen laptops or other mobile devices.”

This says a lot about current practices, in terms of storing data and protecting it. The remaining part of the article provides additional details on the impact this has on businesses and end users.
--- NOTE: my original HP blog can be found here ---

Thursday, February 21, 2008

Updated Liberty ID-WSF Open Source Toolkits …

This might be of interest to those monitoring developments in the Liberty Alliance’s “Advanced Client Technologies” specs… Conor Cahill, in a recent blog post, announced that he has updated his Liberty ID-WSF Open Source Toolkits. See below:

“I've updated my Liberty ID-WSF Open Source Toolkits again. This time to reflect the minor changes made in the Advanced Client specifications as they were finalized within the Alliance.
For those of you who aren't familiar with this code, I have two toolkits available -- a C++ client and an Axis1/Java Server -- which implement the Liberty ID-WSF protocols (both the basic framework and substantial portions of several services).
This new release of the toolkit does not add new functionality -- it only brings the code up to match the final specifications.
Have fun!”

--- NOTE: my original HP blog can be found here ---

Sunday, February 17, 2008

Four-part Webcast series on Identity Assurance

Liberty Alliance has announced a four-part Webcast series on Identity Assurance that can be attended by registering online:

“Date: February 20, 8 am PT
Topic: Identity Assurance Framework: Common Organization Service Assessment Criteria
Moderator: Jim Gross, Sr. Vice President, WellsSecure Identity Assurance, Wells FargoThis webcast will discuss and gather feedback on the Common Organization Service Assessment Criteria section of the IAF. This section outlines the criteria for a Credential Service Provider's general business and organizational conformity of its services and its providers as it pertains to the four Levels of Assurance in the IAF. The review session will have a particular focus on elements such as enterprise & service maturity, information security management, operational infrastructure, external services & components, secure communications, etc.
Registration: https://ieee-istolargeroom.webex.com/ieee-istolargeroom/k2/j.php?ED=102106312&UID=141346749

Date: March 5, 8 am PT
Topic: Identity Assurance Framework: Credential Management Service Assessment Criteria
Moderator: Vijay Takanti, Exostar VP, Security Services; CertiPath, CTO and Policy Chair; TSCP, Design Authority Lead
This webcast will focus on the Credential Management Service Assessment Criteria. This section outlines the criteria for the functional conformity of a CSP's credential management services and those of its providers to comply with the Four Levels of Assurance. The review session will focus on the various credential-related processes including the operating environment, issuance, revocation, status management and validation/authentication of credentials.
Registration: https://ieee-istolargeroom.webex.com/ieee-istolargeroom/k2/j.php?ED=102106602&UID=322922647

Date: March 12, 8 am PT
Topic: Identity Assurance Framework: Identity Proofing Service Assessment Criteria
Moderator: Dr. Peter Alterman, Asst. CIO for EAuthentication, NIH and Chair, Federal PKI Policy AuthorityThis webcast will focus on the Identity Proofing Service Assessment Criteria section of the IAF. This section outlines the criteria for a CSP's functional conformity of its identity proofing practices within the Four Levels of Assurance. The review session will focus on identity proofing elements such as Identity Proofing Policy, Identity verification practices, verification records, etc.Registration: https://ieee-istolargeroom.webex.com/ieee-istolargeroom/k2/j.php?ED=102106317&UID=948676821

Date: March 26, 8 am PT
Topic: Identity Assurance Framework: Certification/Accreditation Business Rules
Moderator: Nathan Faut, Senior Associate, Federal practice, KPMGThis webcast will focus on the Certification/Accreditation Business Rules -This section covers the business rules associated with participation in the Liberty Framework. The review session will focus on roles and responsibilities of CSP's, the role of the Federation Operator and a best practices guideline for relying parties. In addition, this section will discuss the process for accrediting assessors/auditors of CSP's for certification to the Liberty IAF.
Registration: https://ieee-istolargeroom.webex.com/ieee-istolargeroom/k2/j.php?ED=102106687&UID=926656135”

--- NOTE: my original HP blog can be found here ---

Wednesday, February 13, 2008

EU PRIME “Primer” available online …

The EU “Privacy for Identity Management in Europe” (PRIME) Project is going to officially finish by the end of February 2008.

Lots of material is available online, and new documents will be added in this final phase of the project. A PRIME Primer has been recently released in the PRIME web site.

--- NOTE: my original HP blog can be found here ---

Monday, February 11, 2008

New Forrester’s Report: “Identity Management Market Forecast: 2007 to 2014”

An article written by Tim Wilson, called “Identity Management Ready to Skyrocket”, provides an overview of the content of a new Forrester’s Report, “Identity Management Market Forecast: 2007 to 2014”. Have a look to get same insights …

The executive summary of this Forrester’s report follows:

“The identity management — or identity and access management (IAM) — market will grow from nearly $2.6 billion in 2006 to more than $12.3 billion in 2014 (including revenues from both products and implementation services). Provisioning accounts for half of IAM market revenues today, but it will account for nearly two-thirds of all IAM revenues by 2014. Even after years of healthy adoption rates, the IAM market is actually just beginning its trajectory toward broad adoption and deep penetration. Moreover, during the next seven years, we will also see buying behavior migrating from point products to identity suites — and, to a lesser extent, from products to managed services. Meanwhile, vendors will decompose products into service-oriented architecture (SOA)-enabled functions, repackaged in the form of identity-as-a-service (IDaaS)”.

I read the actual report. I found the section on “Future Directions for Identity Management” interesting but, in my view, there are no major surprises …

--- NOTE: my original HP blog can be found here ---

Friday, February 8, 2008

Update on PLING Interest Group …

New use cases have been recently added to the W3C PLING Interest Group Wiki Site, related to:
  • Location-based Access Control Policies and Privacy in Pervasive and Distributed Environments
  • Federated Policy Management
  • Privacy Policy Management

An up-to-date list of use cases is available here. It would help if you could share your experiences in terms of the following points:

  • Are you using, in practice (e.g. in some operational environments), any policy language at all? Which ones and in which context?
  • If so, what are the pros and cons of this language?
  • Any open issue, problem and/or requirement?
  • Any interoperability need in case multiple policy languages/frameworks are used?

The Wiki page containing a review of known Policy Languages and Framework has also been updated. Please have a look and feel free to contribute.

--- NOTE: my original HP blog can be found here ---

Wednesday, February 6, 2008

2008 National Survey on Access Governance: Business Risks and Challenges

A new survey on “access governance” has been released by the Ponemon Institute, as anticipated by this Businesswire article:

“According to the 2008 National Survey on Access Governance released on February 5th by the research firm Ponemon Institute, organizations are facing significant business risks because of inconsistent approaches to access management across the enterprise.
This survey of almost 700 experienced IT practitioners show that vast majority believe that employees, temporary employees and independent contractors have too much access to information assets that are not pertinent to their job function, and that access policies are not being regularly checked or enforced by their organization. This report describes the five major challenges identified by the survey respondents to implementing an effective access governance framework:
  • User access rights are poorly assigned
  • Policies are not regularly checked and enforced
  • Organizations are not able to keep pace with changes to users’ roles and they face serious noncompliance and business risk as a result
  • Senior management lacks understanding of the importance of access governance
  • Collaboration is viewed as critical but is not being achieved”


This survey can be downloaded online, from here.


--- NOTE: my original HP blog can be found here ---

Monday, February 4, 2008

Announcing TrustBus 2008

The Call for Papers of 5th International Conference on Trust, Privacy and Security in Digital Business (TrustBus’08) is now available, online.

This conference aims at providing an international forum for researchers and practitioners to exchange information regarding advancements in the state of the art and practice of trust and privacy in digital business.

The submission deadline is March, 3rd. TrustBus 2008 is interested in papers, work-in-progress reports, and industrial experiences describing advances in all areas of digital business applications related to trust and privacy, including, but not limited to:

- Anonymity and pseudonymity in business transactions
- Common practice, legal and regulatory issues
- Delivery technologies and scheduling protocols
- Economics of Information Systems Security
- Enterprise management and consumer protection
- Intellectual property and digital rights management
- Languages for description of services and contracts
- Models for access control and authentication
- New cryptographic building-blocks for e-business applications
- PKI & PMI
- P2P transactions and scenarios
- Reliability and security of content and data
- Reputation in services provision
- Security and Privacy models for Pervasive Information Systems
- Shopping, trading, and contract management tools
- Transactional Models
- Usability of security technologies and services
- Business architectures and underlying infrastructures
- Cryptographic protocols
- Design of businesses models with security requirements
- Electronic cash, wallets and pay-per-view systems
- Identity and Trust Management
- Intrusion detection and information filtering
- Management of privacy & confidentiality
- Multimedia web services
- Online transaction processing
- Public administration, governmental services
- Real-time Internet E-Services
- Reliable auction, e-procurement and negotiation technology
- Secure process integration and management
- Security Policies
- Smartcard technology
- Trust and privacy issues in mobile commerce environments

--- NOTE: my original HP blog can be found here ---

Sunday, February 3, 2008

Are Legal Obstacles Delaying Federated Identity Management?

This is a key point made in Thomas J. Smedinghoff’s article, titled “Legal Obstacles Delaying Federated Identity Management”:

“Without some type of a legal framework to address these issues, however, a federated identity model will likely not scale. At least in the case of economically significant transactions, the risks to each of the parties of such unresolved issues are simply too great to justify reliance on the federated process. These questions, and others like them, are the legal land mines that stand in the way of a viable federated identity management infrastructure.”

The issues mentioned above are about: Identification Process, Personal Information, Scope of Assertion, Use of Assertion and Liability.

I agree that having a proper legal framework in place can help. I would argue, though, that proper “identity assurance” must also be put in place in the context of federated identity management, as discussed in a HPL Technical Report.

--- NOTE: my original HP blog can be found here ---

Wednesday, January 30, 2008

On the “Identity Self-Defence Course” …

Have a look at this interesting post by Doug Pollack, titled “Are you Well Protected?”:

“As we look forward to what is in store for us in 2008, The Identity Theft Resource Center is projecting an increase in both the number of security breaches and incidents of identity theft. With this as a backdrop, we've developed a set of recommendations for people to protect themselves. As part of our ID Self-Defense Academy, a component of our subscription services member website, this Self-Defense Checklist includes both common sense suggestions that you are likely to be familiar with, as well as others that are new this year given the evolution in the use of the internet and computers in identity theft.”

Actually, this post provides an “ID self-defence check list” about:
  • Protecting yourself at home
  • Protecting your computer and Internet access
  • Protecting yourself on the road

Of course, all this is pretty much based on common sense, but it provides a useful reminder …

--- NOTE: my original HP blog can be found here ---

Monday, January 28, 2008

What are the actual ID Card plans in UK?

An interesting article by Telegraph.co.uk highlights some of the “confusion” that exists in current UK plans for ID cards:

“The future of the Government's identity card scheme is in confusion as it emerged that plans for a national fingerprint database may be quietly dropped.

At the same time, it appears that ministers are considering introducing a compulsory ID scheme by stealth, with plans that would require young people to obtain a card before being granted a driving licence.

The proposals were disclosed in two leaked Home Office documents and expose the lack of agreement within the Government over the extent to which ministers should continue with the commitment to ID cards. …”

More details can be found in the Telegraph’s article.

--- NOTE: my original HP blog can be found here ---

Friday, January 25, 2008

Article on Identity Governance Framework (IGF) published by SOX Compliance Journal

As already announced in Phil Hunt’s blog, an article has recently been published by the SOX Compliance Journal about how Identity Governance Framework can help to address Privacy and SOX Compliance aspects.

This article is called “Identity Governance Framework: Liberty Alliance’s Initiative Addressing Privacy and SOX” and its authors are: Phil Hunt (Oracle) and Marco Casassa Mont (HP Labs).

As pointed out by Phil, “this article is a good introduction to the problems of privacy and compliance as it relates to personal information and how IGF is intended to make the compliance of applications and the businesses that deploy them much easier to achieve.”

More information about the Liberty Alliance’s Identity Governance Framework initiative can be found here.

--- NOTE: my original HP blog can be found here ---

Wednesday, January 23, 2008

PLING Interest Group: Additional Policy Use Cases/Requirements

I'd like to share two additional (high-level) policy use cases and related requirements with this community (I’ve already submitted them to the Policy Languages Interest Group – PLING mailing list) about:

(1) Privacy Policy Management;
(2) Federated Policy Management - Use Case & Requirements

Details follow.

1) Privacy Policy Management - Use Case & Requirements

A recurrent use case that I came across in various contexts (EU PRIME Project, interactions with customers, etc.) is how to use policies to deal with privacy enforcement and compliance checking in organisational contexts. This is pretty much consistent with some of the points already highlighted in Michael Wilson's use case.

Organisations and enterprises collect a lot of personal data and sensitive information, in order to enable their businesses. In doing this, they need to comply with laws, legislation (HIPAA, COPPA, EU Data Protection, etc.) standards of business conduct, guidelines, etc.

Threw key aspects are of interest:
(a) policy representation
(b) enforcement of (privacy) policies
(c) policy compliance checking

Basic privacy constraints require handling users' consent, allowing access to the data only for agreed purposes and managing the lifecycle (e.g. data transformation, minimisation, deletion, etc.) of personal data driven by privacy principles. However, also other aspects such has security and business constraints need to be kept into account.

Personal data can be stored in a variety of data repositories (databases, LDAP directories, file systems, etc.) and be accesses by people, applications, services. This data can be processed and disclosed to third parties.

A "blend" of personal preferences, business, security and privacy constraints need to be kept into account into "policies" dictating how to access, use process and disclose this information.

Some common requirements that I came across are:

- need for more "integration" of business, security and privacy policies
- need to leverage state-of-the-art Identity Management solutions (that might use, in some cases, proprietary/ad-hoc policy languages ...)
- need to measure and demonstrate compliance to guidelines, laws and legislation

Policies (and policy management frameworks) can play a key role to deal with privacy enforcement and compliance checking tasks. However, one of the current limitations is that these aspects are currently addressed in a "compartmentalised" way, by using different policy languages and policy management systems (for security, privacy, etc.) that do not interoperate i.e. act in stand-alone ways. This creates issues in terms of alignment of policies, their consistency and overall impact.

How to make progress by recognising than on one hand there are multiple policy languages and policy management systems and, on the other hand, more coordination and integration is required?

2) Federated Policy Management - Use Case & Requirements

This use case is, in some way, a generalisation of the previous one: I came across it both in enterprise and telecom contexts.

An enterprise/organisation uses a broad variety of IT tools and solutions. The enterprise IT infrastructure includes systems, tools and solutions deployed at different levels of abstractions: network, system, OS, information, application, service, business, etc. levels.

Many of the involved systems, tools and solutions are configured with and driven by "local policies", defined by using specific (sometimes ad-hoc ...) languages. These "local policies" are often the effect of (human-based) "refinements" and "deployments" of high level business/security/etc. policies. Different policies, policy decision points and policy enforcement points are used for security, business, privacy and other aspects.

- How to make sense of all of them?
- How to ensure that their overall impact on the IT infrastructure is consistent with the high level policies and guidelines?
- How to understand what the impact of changes of "local policies" (let's say at network level or at the application level) is on the
high level policies?
- How to understand what the impact of changes of high-level policies is on some of these "local policies"?

This is what I call a "federated policy management" use case i.e. a use case where there is the need to understand and keep into account the overall set of policies deployed in an IT infrastructure and have an "integrated, coordinated and consistent" management of these policies.

In this use case many different policy languages are used, operating on different IT entities (at different levels of abstraction) and enforced by different policy enforcement points. It is unlikely that all these existing (local) policy languages are going to be replaced by a unique "comprehensive" language ...

Some requirements are about having a consistent "meta-representation/abstraction" of the core principles/aspects/constraints expressed by various "local policies" along with ways of defining dependencies and relationships between them.

This would help to better understand the overall heterogeneous set of operational policies, link them back to high-level policies and reason on top of it.

Did you come across similar use cases? What is your view?

--- NOTE: my original HP blog can be found here ---

Monday, January 21, 2008

Central Identity Management is a High Priority, whilst Biometrics is Not …

An interesting article (called “Securing the Future: Central identity management systems are now a chief priority, but biometric technologies continue to disappoint”), recently published by Information Age, discusses how Central Identity Management is becoming a high priority in enterprises, whilst the adoption level of Biometrics is low:

“… Identity (ID) management is a case in point. The technology, which is intended to restrict access to vital information, ranked second out of 30 technology strategies IT directors are planning to implement within the next 12 months. Of those 25% of corporations that have already implemented such a system, an encouraging 45% regard the technology as ‘quite effective’ with a further 31% responding that it is ‘very effective’.

With a total of 76% of respondents rating the technology as ‘effective’ or ‘very effective’, ID management does well in the overall rankings, coming in as the 6th most effective IT strategy overall. These results also indicate a slight improvement on last year.

Analyst group Gartner identifies five broad classes of identity and access management tools: directory technologies, identity administration, identity auditing, identity verification and access management.

However, of these broad groups, one – identity verification – remains highly problematic for today’s enterprise. Biometrics – the use of a variety of unique physical characteristics such as fingerprints, voice patterns or facial contours to identify individuals – has long been touted as the ideal enterprise identity-verification tool, being supposedly both easy-to-use and highly secure; it has consistently failed to deliver.

As the survey shows, adoption levels of biometrics remain woefully low – just 9% of respondents use biometrics today. A meagre 11% more plan to implement the technology within the next year.”

--- NOTE: my original HP blog can be found here ---

Friday, January 18, 2008

Liberty Alliance “Identity Assurance Special Interest Group (IASIG)”

The kick-off meeting of the Liberty Alliance “Identity Assurance Special Interest Group (IASIG)” is going to happen on January, 30th 2008 to discuss the Identity Assurance Framework and the proliferation of standard Levels of Assurance in digital commerce:

“The IASIG was formed alongside the Identity Assurance Expert Group (IAEG), as a public Special Interest Group (SIG) within the Liberty Alliance to continue and extend the Trust Framework of the EAP (Electronic Authentication Partnership), the Credential Assessment Framework of the US E-Authentication Initiative, and other industry contributions, into a harmonized, best-of-breed industry standard operational framework for managing trusted credentials across identity federations to foster inter-federation on a global scale.”

More details about this event can be found here.

--- NOTE: my original HP blog can be found here ---