![]() |
|||||||||||||||||
|
On the face of it identity is a simple concept to understand. We have been using digital identities in some form or other for years; we have used ATM machines, sent e-mails, logged onto our computers at work, and various other activities requiring us to identify ourselves. However, while the basics are well understood, it is an issue that is currently occupying the minds of governments, commercial organisations and technology vendors alike.So why is identity important? At the most basic level, identity proves who somebody or something is. This concept of identity could be the subject of fierce philosophical debate (not least of all within commissum), but is core to the world of secure networked computing. All users, resources, objects, devices, programs, etc, must have a unique identity, and depending on the entitlements attributed to their identity, they are authenticated, authorised, granted access, administered and transacted with accordingly.When it comes to conducting business electronically, it is essential that commercial organisations and governments trust the identities of those with whom they conduct business and reciprocate an acceptable level of trust and assurance. The challenge for the information security industry has been to provide a secure, yet cost effective identity management solution to establish this trust.The need for competitive advantage has driven organisations into opening up their network to their customers, employees and business partners. This brings the benefits and new opportunities that e-commerce presents but, presents higher business risks and a more complex identity management problem. In this environment, where users can be anyone, anywhere and access resources at anytime, the level of trust and strength of authentication mechanism will depend on the attributes associated with the resource, method and device used to access it. For example, it may be sufficient to authenticate a user by password to access information of little value from a PC with a trusted internet address on a LAN network; but it might require multiple authentication mechanisms, including biometrics, to authenticate the same user to access a critical business application from a laptop or PDA device via the internet.The current industry approach to identity management is that the only way to prove identity and provide trusted access to resources is by reference to a secure, efficient and trusted directory service. A secure directory coupled with single sign on capability is the basis upon which today's technologies are designed. Thus, a user only signs in once to a network, leveraging the identity profile and its associated business and security policies throughout the entire logon session. This, arguably, is where the real value of identity management lies.Identity management is playing an important role in the advancement of e-business and the level of activity in this area has been very significant in the last twelve months. Identity management is a rapidly emerging and evolving industry. Announcements of new identity management solutions from major technology players, new business models supported by emerging standards for federated identity, and government online initiatives all illustrate the growing strategic importance and the beginnings of a roadmap for digital identity. These measures, combined with appropriate investment in the technologies, and a more effective legislative framework, will be a major factor in driving more consumers and businesses online, improving consumer confidence and allowing businesses to thrive in a world of opportunity and profitability.Unfortunately, security breaches hitting the headlines show how common it still is for systems to be compromised, with resulting damaging publicity both for businesses impacted directly, and e-commerce in general. Even with the adoption of identity management technologies proposed, security breaches will continue to plague the industry; social engineering attacks, misconfigurations and software engineering flaws will continue as conventional crime has for centuries. Nonetheless, as with any mature information security management programme, the objective is to manage and control risk rather than to believe in unrealistic concepts such as total security. Looked at in this manner identity management technologies have a role to play; they are a useful addition to the toolkit of risk control, but only where appropriately selected and integrated within an adequate security architecture.
and Finally...On the subject of trust..
What we've gone through in the last several years has caused some people to question 'Can we trust Microsoft?' Steve Ballmer
As for butter versus margarine, I trust cows more than chemists. Joan Gussow
Those you trust the most can steal the most. Lawrence Lief
I haven't trusted polls since I read that 62% of women had affairs during their lunch hour. I've never met a woman in my life who would give up lunch for sex. Erma Bombeck Journalist
The trust of the innocent is the liar's most useful tool. Stephen King
Never trust a husband too far, nor a bachelor too near. Helen Rowland
I never trust a man unless I've got his pecker in my pocket. Lyndon B. Johnson
There's no trust, no faith, no honesty in men; all perjured, all forsworn, all naught, all dissemblers. William Shakespeare
To believe with certainty we must begin with doubting. Stanislaus I of Poland |
||||||||||||||||
|
|||||||||||||||||