<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
  <id>http://blog.aniljohn.com/</id>
  <updated>2013-06-19T22:29:14-04:00</updated>
  <title>Anil John | Blog</title>
  <subtitle type="html">On Architecture, Digital Security, Privacy...</subtitle>
  <icon>http://blog.aniljohn.com/img/favicon.ico</icon>
  
  <link rel="alternate" type="text/html" href="http://blog.aniljohn.com" />
  <author>
    <name>Anil John</name>
    <email>noreply@aniljohn.com</email>
    <uri>http://www.aniljohn.com/</uri>
  </author>
    
  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/AnilJohn" /><feedburner:info uri="aniljohn" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><logo>http://lh4.googleusercontent.com/-bdzCv-OkbiM/UN3mPNGG7QI/AAAAAAAAAUk/iADZchWRUXc/s800/aniljohnblog.png</logo><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2FAnilJohn" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><entry>
    <id>http://blog.aniljohn.com/2013/06/castles-with-glass-doors</id>
    <published>2013-06-19T22:00:00-04:00</published>
    <updated>2013-06-19T22:00:00-04:00</updated>
    <title>Castles with Glass Doors</title>
    <content type="html">&lt;p&gt;&lt;img class="scale-with-grid" style="display: block; margin-left: auto; margin-right: auto;" iph="http://blog.aniljohn.com/img/1x1.png" src="http://blog.aniljohn.com/img/castle_with_glass_door.png" /&gt;&lt;/p&gt;

&lt;p&gt;An all too familiar sight these days...&lt;/p&gt;
&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=oCzWs4T4Cs0:mTzAyVvH7-o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=oCzWs4T4Cs0:mTzAyVvH7-o:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=oCzWs4T4Cs0:mTzAyVvH7-o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=oCzWs4T4Cs0:mTzAyVvH7-o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=oCzWs4T4Cs0:mTzAyVvH7-o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=oCzWs4T4Cs0:mTzAyVvH7-o:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=oCzWs4T4Cs0:mTzAyVvH7-o:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/oCzWs4T4Cs0" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/oCzWs4T4Cs0/castles-with-glass-doors.html" title="Castles with Glass Doors" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/06/castles-with-glass-doors.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/06/backpacker-tech-tools</id>
    <published>2013-06-16T18:00:00-04:00</published>
    <updated>2013-06-16T18:00:00-04:00</updated>
    <title>Tools for the Connected Backpacker</title>
    <content type="html">&lt;p&gt;In this time of always on connectivity, I hike and backpack to enjoy the outdoors and step away from the pace of daily life. Provided you do not let them overpower your reasons for being in the back-country, these are some of the gear and technologies that I've found useful in the backcountry.&lt;/p&gt;

&lt;p&gt;&lt;img class="scale-with-grid" style="display: block; margin-left: auto; margin-right: auto;" iph="http://blog.aniljohn.com/img/1x1.png" src="http://blog.aniljohn.com/img/connected-backpacker-tools.png" /&gt;&lt;/p&gt;

&lt;p&gt;I recently got to introduce my son to overnight backcountry backpacking.  While he has been with me on numerous day hikes, last night was his first experience with an overnight stay in the backcountry. We hiked a section of the Appalachian Trail and spent the night in a camping area near the Rocky Run Shelter on the A.T. It was a great experience and one we are planning on repeating. Given that we are both gadget geeks, there was definitely a technology component to our trip.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;iPhone + &lt;a href="http://www.lifeproof.com/en/iphone/" title="Lifeproof Case for iPhone 4S"&gt;Lifeproof Case&lt;/a&gt;&lt;/strong&gt;: I bring an iPhone 4S, but not for being connected to the grid. After all, the point is to not be tethered to the world. This is typically not a problems since where I go, there is often no mobile phone reception. I use it as a GPS and as a Camera (more on both below). But it is important to protect the phone from the harsh conditions on the trail, and I have found the waterproof, dirtproof, shockproof Lifeproof case to be outstanding for that purpose.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="http://campl.us/" title="Camera+ Photo App"&gt;Camera+ Photo App&lt;/a&gt;&lt;/strong&gt;: This is my go-to photo app and allows me to bring out the best of the iPhone camera. The feature set is outstanding and includes grid support, self-timer, effects and more.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Leki Trekking Poles + &lt;a href="http://www.rei.com/product/812557/leki-aergon-photoadapter-camera-mounting-kit" title="Leki Aergon Photoadapter Camera Mounting Kit"&gt;Camera Adapter&lt;/a&gt;&lt;/strong&gt;: I use a pair of Leki Corklite Aergon SpeedLock trekking poles, but what I absolutely love about it is the photo-adapter camera mounting kit which turns the pole's grip into a mono-pod with a universal threaded camera mount.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="http://www.istabilizer.com/store/mount.html" title="iStabilizer Camera Mount"&gt;iStabilizer Camera Mount&lt;/a&gt;&lt;/strong&gt;: By attaching this iStabilizer camera mount to the leki's camera adapter, I get something I can easily mount my iPhone to, and allows me to take very stable photos or group shots with a self-timer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="http://www.inreachdelorme.com/product-info/inreach-smartphone.php" title="inReach Satellite Communicator"&gt;inReach Satellite Communicator + GPS App&lt;/a&gt;&lt;/strong&gt;: This was one of the best investments I have made for piece of mind and safety in the back-country. Global network coverage for text messages using the Iridium satellite network, GPS tracking, SOS Search and Rescue response, free companion app with topo maps and more. On my last &lt;a href="http://blog.aniljohn.com/2012/08/backpacking-rocky-mountain-natl-park.html" title="Backpacking in the Rocky Mountain National Park"&gt;multi-day backpack into the Rocky Mountain National Park&lt;/a&gt;, I had no cell phone reception, but was checking in with the family every night via text messages. Massive WAF (Wife Acceptance Factor)!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href="https://www.goalzero.com/shop/p/133/Guide-10-Plus-Battery-Pack/2:8/" title="GoalZero Guide 10 Plus Battery Pack"&gt;Goal Zero Guide 10 Plus Battery Pack&lt;/a&gt;&lt;/strong&gt;: The rechargeable power unit, which can be charged from an outlet or from a solar panel, allows me to re-charge my iPhone or my inReach unit if I run out of power. It also doubles as an LED flashlight.&lt;/li&gt;
&lt;/ol&gt;

&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=WUd6fNDQCI4:OeQKKu1-ZPA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=WUd6fNDQCI4:OeQKKu1-ZPA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=WUd6fNDQCI4:OeQKKu1-ZPA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=WUd6fNDQCI4:OeQKKu1-ZPA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=WUd6fNDQCI4:OeQKKu1-ZPA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=WUd6fNDQCI4:OeQKKu1-ZPA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=WUd6fNDQCI4:OeQKKu1-ZPA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/WUd6fNDQCI4" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/WUd6fNDQCI4/backpacker-tech-tools.html" title="Tools for the Connected Backpacker" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/06/backpacker-tech-tools.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/06/icam-day-vendor-expo</id>
    <published>2013-06-12T18:00:00-04:00</published>
    <updated>2013-06-12T18:00:00-04:00</updated>
    <title>FICAM Information Sharing Day and Vendor Expo [Event]</title>
    <content type="html">&lt;table class="table table-bordered" border="1" cellspacing="0" cellpadding="5"&gt;
&lt;tr&gt;
&lt;td valign="top" width="30%"&gt;Date:&lt;/td&gt;
&lt;td valign="top" width="70%"&gt;June 18, 2013&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Time:&lt;/td&gt;
&lt;td valign="top"&gt;9:30 a.m. to 11:30 a.m. &lt;br /&gt;
(Full Event: 8:00 a.m. to 4:00 p.m.)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Event:&lt;/td&gt;
&lt;td valign="top"&gt;&lt;a href="http://info.idmanagement.gov/2013/06/federal-icam-information-sharing-day.html"&gt;Federal ICAM Information Sharing Day and Vendor Expo&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Topics:&lt;/td&gt;
&lt;td valign="top"&gt;&lt;p&gt;&lt;strong&gt;Panel Discussion: Attribute Exchange and Information Sharing in Action&lt;/strong&gt;&lt;br/&gt;
Panelists will share the latest updates on technology and approaches for attribute exchange and the importance of information sharing and safeguarding to the national cybersecurity agenda.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Panel Discussion: Externalizing Authentication&lt;/strong&gt;&lt;br/&gt;
Panelists will provide insights into how Agencies can externalize authentication using shared services. Participants include members of the OMB MAX Authentication Team as well as members of the Federal Cloud Credential Exchange (FCCX) Team.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Host:&lt;/td&gt;
&lt;td valign="top"&gt;U.S. Federal CIO Council's ICAMSC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Venue:&lt;/td&gt;
&lt;td valign="top"&gt;GSA OCS Building&lt;br /&gt;
1275 First Street NE&lt;br /&gt;
Washington, DC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Registration:&lt;/td&gt;
&lt;td valign="top"&gt;&lt;a href="http://www.gsa.gov/ICAMexpo"&gt;Click here to register&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;



&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=f9HUMwqA_4A:9y69WzUysWY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=f9HUMwqA_4A:9y69WzUysWY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=f9HUMwqA_4A:9y69WzUysWY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=f9HUMwqA_4A:9y69WzUysWY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=f9HUMwqA_4A:9y69WzUysWY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=f9HUMwqA_4A:9y69WzUysWY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=f9HUMwqA_4A:9y69WzUysWY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/f9HUMwqA_4A" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/f9HUMwqA_4A/icam-day-vendor-expo.html" title="FICAM Information Sharing Day and Vendor Expo [Event]" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/06/icam-day-vendor-expo.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/06/purity-pragmatism-in-profile-compliance</id>
    <published>2013-06-09T12:00:00-04:00</published>
    <updated>2013-06-09T12:00:00-04:00</updated>
    <title>Purity and Pragmatism in Standards Profile Compliance</title>
    <content type="html">&lt;p&gt;Profiles of standards allow for interoperability and standards based implementation across disparate systems. As such, they are critical from an enterprise perspective to ensure that investments and choices made regarding technical infrastructure are not vendor specific, and the conformance to a profile can be independently verified to ensure interoperability. I've &lt;a href="http://blog.aniljohn.com/2011/10/standards-compliance-balancing-purity.html" title="Standards Compliance - Balancing Purity and Pragmatism"&gt;written about this before&lt;/a&gt;, but in this blog post, wanted to focus a bit more on the choices available to relying parties when it comes to conforming to identity federation protocol profiles.&lt;/p&gt;

&lt;p&gt;&lt;img class="scale-with-grid" style="display: block; margin-left: auto; margin-right: auto;" iph="http://blog.aniljohn.com/img/1x1.png" src="http://blog.aniljohn.com/img/user-csp-rp-interface.png" /&gt;&lt;/p&gt;

&lt;p&gt;My perspective is shaped by the needs of relying parties, so what I am focused on is the &lt;strong&gt;CSP-RP Interface&lt;/strong&gt; as shown in the graphic above. Typically an organization requires that its applications, which are in the relying party role, only communicate using a specific protocol profile. Provided that the protocol profile chosen is flexible and full featured, this choice allows the organization to leverage existing expertise in implementation, makes testing and verification consistent, and reduces the cost of integration.&lt;/p&gt;

&lt;p&gt;But in this scenario, how does an organization take advantage of new protocols?  Couple of options are:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Directly support additional protocol profiles at the RP.&lt;/strong&gt; While this is a valid approach, it negates many of the benefits of supporting a single last mile integration profile. In addition, it requires the organization to develop and maintain multiple protocol profiles. But at the same time, if the number of RPs in the enterprise is low and there is in house technical expertise to understand and implement, some organizations may find this to be a viable option.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Use a "broker-in-the-middle" approach to normalize multiple CSP supported protocols to a single RP supported protocol profile.&lt;/strong&gt; A broker typically acts as an RP to the actual CSP, and as a CSP to the actual RP. As such, the point of integration with the real RP can always be profile compliant. In addition to the infrastructure and O&amp;amp;M costs of the broker, there is also the requirement that the broker be a trusted entity and has been designed (and independently verified) to support the profile requirements of the RP.&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;Any additional options that folks are currently using?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;RELATED INFO&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blog.aniljohn.com/2011/10/standards-compliance-balancing-purity.html" title="Standards Compliance - Balancing Purity and Pragmatism"&gt;Standards Compliance - Balancing Purity and Pragmatism&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.aniljohn.com/2013/01/how-wayf-implements-informed-consent.html" title="How WAYF implements informed consent for attribute release without storing PII"&gt;How WAYF implements informed consent for attribute release without storing PII&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=960wRZwOy8Y:ddLjYHzX6Ww:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=960wRZwOy8Y:ddLjYHzX6Ww:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=960wRZwOy8Y:ddLjYHzX6Ww:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=960wRZwOy8Y:ddLjYHzX6Ww:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=960wRZwOy8Y:ddLjYHzX6Ww:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=960wRZwOy8Y:ddLjYHzX6Ww:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=960wRZwOy8Y:ddLjYHzX6Ww:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/960wRZwOy8Y" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/960wRZwOy8Y/purity-pragmatism-in-profile-compliance.html" title="Purity and Pragmatism in Standards Profile Compliance" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/06/purity-pragmatism-in-profile-compliance.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/06/identity-privacy-context</id>
    <published>2013-06-05T21:45:00-04:00</published>
    <updated>2013-06-05T21:45:00-04:00</updated>
    <title>Identity? Privacy? Authorization? It is all about Context!</title>
    <content type="html">&lt;p&gt;When we speak of identity, privacy and authorization, we note that their fidelity and granularity are contextual.&lt;/p&gt;

&lt;p&gt;So what is context?&lt;/p&gt;

&lt;p&gt;Michel Prompt, the CEO and Founder of &lt;a href="http://www.radiantlogic.com/" title="Radiant Logic"&gt;Radiant Logic&lt;/a&gt;, has an absolutely stellar series of thought provoking blog posts on this subject. Highly recommended reading if you are interested in these topics.&lt;/p&gt;

&lt;p&gt;Check them out:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.radiantlogic.com/2013/04/30/in-context-the-next-frontier-of-your-digital-identity/" title="In Context: The Next Frontier of Your Digital Identity"&gt;In Context: The Next Frontier of Your Digital Identity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.radiantlogic.com/2013/05/07/from-groups-to-roles-to-context-the-emergence-of-attributes-in-authorization/" title="From Groups to Roles to Context: The Emergence of Attributes in Authorization"&gt;From Groups to Roles to Context: The Emergence of Attributes in Authorization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.radiantlogic.com/2013/05/21/attributes-predicates-and-sentences-the-building-blocks-of-context/" title="Attributes, Predicates, and Sentences: The Building Blocks of Context"&gt;Attributes, Predicates, and Sentences: The Building Blocks of Context&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.radiantlogic.com/2013/06/05/man-and-machine-speaking-the-same-language/" title="Man and Machine: Speaking the Same Language"&gt;Man and Machine: Speaking the Same Language&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=uLsBZX6Uwzc:RC-Ep9xhOGM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=uLsBZX6Uwzc:RC-Ep9xhOGM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=uLsBZX6Uwzc:RC-Ep9xhOGM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=uLsBZX6Uwzc:RC-Ep9xhOGM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=uLsBZX6Uwzc:RC-Ep9xhOGM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=uLsBZX6Uwzc:RC-Ep9xhOGM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=uLsBZX6Uwzc:RC-Ep9xhOGM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/uLsBZX6Uwzc" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/uLsBZX6Uwzc/identity-privacy-context.html" title="Identity? Privacy? Authorization? It is all about Context!" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/06/identity-privacy-context.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/06/value-of-loa1</id>
    <published>2013-06-01T18:15:00-04:00</published>
    <updated>2013-06-01T18:15:00-04:00</updated>
    <title>What is the Value of an Assertion of Identity at LOA 1?</title>
    <content type="html">&lt;p&gt;As described in "&lt;a href="http://csrc.nist.gov/drivers/documents/m04-04.pdf" title="E-Authentication Guidance for Federal Agencies (OMB-M04-04)"&gt;E-Authentication Guidance for Federal Agencies (OMB-M04-04) [PDF]&lt;/a&gt;", at level 1 there exists little to no confidence in an asserted identity. At the same time, there are many differences of opinion and expectations of what LOA 1 can deliver. This blog post is a summary of some thoughts regarding various expectations of security and privacy, at level 1, within the context of delivering public sector online services.&lt;/p&gt;

&lt;p&gt;&lt;img class="scale-with-grid" style="display: block; margin-left: auto; margin-right: auto;" iph="http://blog.aniljohn.com/img/1x1.png" src="http://blog.aniljohn.com/img/mynamis.png" /&gt;&lt;/p&gt;

&lt;p&gt;During a recent conversation with one of my mentors, who has been around the identity block many times and is now happily retired, I mentioned how I was struggling to articulate the value of utilizing a federated level 1 credential at any medium/high value online public sector service.&lt;/p&gt;

&lt;p&gt;My position was that given the lack of confidence in the identity, the &lt;strong&gt;value of a level 1 credential&lt;/strong&gt; lies solely in &lt;strong&gt;decreasing the burden to users in having to manage multiple identity credentials&lt;/strong&gt; and &lt;strong&gt;reducing, to some degree, the relying party infrastructure and operational costs&lt;/strong&gt; to manage those credentials.&lt;/p&gt;

&lt;p&gt; I was making level 1 into a rather binary or a "buyer beware" choice from the relying party perspective. But my mentor's response was that while the point regarding the lack of confidence in the asserted identity holds true, at level 1 there is also an &lt;strong&gt;expectation that the credential service provider (or IdP) is operating in a manner that protects the information that an applicant/user has entrusted to it&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I am feeling a bit challenged on how one could develop a light-weight trust criteria for level 1, given that it &lt;em&gt;feels&lt;/em&gt; like a blending of both security and privacy factors. Some potential items that may be applicable are:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;An effort must be made to make sure the the applicant has a unique identifier at the CSP/IdP&lt;/li&gt;
&lt;li&gt;Transmission of sensitive data must take place over a protected session (e.g. TLS/SSL)&lt;/li&gt;
&lt;li&gt;??&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;What else?  Since this is level 1, there is no identity proofing and anonymity and pseudonymity are perfectly acceptable here. Is there an expectation of privacy component here? I am curious as to whether or not anyone has done any further thinking in this area and if so, would appreciate pointers to that work.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;RELATED INFO&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://csrc.nist.gov/drivers/documents/m04-04.pdf" title="E-Authentication Guidance for Federal Agencies (OMB-M04-04)"&gt;E-Authentication Guidance for Federal Agencies (OMB-M04-04) [PDF]&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=gg2YkzGJk1E:pjiPkV5xcak:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=gg2YkzGJk1E:pjiPkV5xcak:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=gg2YkzGJk1E:pjiPkV5xcak:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=gg2YkzGJk1E:pjiPkV5xcak:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=gg2YkzGJk1E:pjiPkV5xcak:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=gg2YkzGJk1E:pjiPkV5xcak:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=gg2YkzGJk1E:pjiPkV5xcak:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/gg2YkzGJk1E" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/gg2YkzGJk1E/value-of-loa1.html" title="What is the Value of an Assertion of Identity at LOA 1?" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/06/value-of-loa1.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/05/sia-government-summit</id>
    <published>2013-05-29T18:50:00-04:00</published>
    <updated>2013-05-29T18:50:00-04:00</updated>
    <title>SIA Government Summit 2013 [Event]</title>
    <content type="html">&lt;table class="table table-bordered" border="1" cellspacing="0" cellpadding="5"&gt;
&lt;tr&gt;
&lt;td valign="top" width="30%"&gt;Date:&lt;/td&gt;
&lt;td valign="top" width="70%"&gt;June 4, 2013&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Time:&lt;/td&gt;
&lt;td valign="top"&gt;10:15 a.m. to 11:15 a.m. &lt;br /&gt;
(Full Event: June 4-5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Event:&lt;/td&gt;
&lt;td valign="top"&gt;&lt;a href="http://www.siaonline.org/content.aspx?id=9390"&gt;Security Industry Association Government Summit 2013&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Topic:&lt;/td&gt;
&lt;td valign="top"&gt;&lt;a href="http://www.siaonline.org/content.aspx?id=10002"&gt;Identity, Cybersecurity and Privacy&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Host:&lt;/td&gt;
&lt;td valign="top"&gt;Security Industry Association&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Venue:&lt;/td&gt;
&lt;td valign="top"&gt;The W Hotel&lt;br /&gt;
515 15th Street NW&lt;br /&gt;
Washington, DC 20004&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign="top"&gt;Registration:&lt;/td&gt;
&lt;td valign="top"&gt;&lt;a href="https://siamembers.siaonline.org/eweb/DynamicPage.aspx?WebCode=CSCEventInfoSC&amp;evt_key=5addf3d8-5cc1-45c2-a330-cce8e650323b"&gt;Click here to register&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;



&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=MyOVR0u_rt0:jmhpLSSwyaM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=MyOVR0u_rt0:jmhpLSSwyaM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=MyOVR0u_rt0:jmhpLSSwyaM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=MyOVR0u_rt0:jmhpLSSwyaM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=MyOVR0u_rt0:jmhpLSSwyaM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=MyOVR0u_rt0:jmhpLSSwyaM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=MyOVR0u_rt0:jmhpLSSwyaM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/MyOVR0u_rt0" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/MyOVR0u_rt0/sia-government-summit.html" title="SIA Government Summit 2013 [Event]" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/05/sia-government-summit.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/05/an-emerging-standard-for-identity-proofing-and-verification</id>
    <published>2013-05-25T10:00:00-04:00</published>
    <updated>2013-05-25T10:00:00-04:00</updated>
    <title>An Emerging Standard for Identity Proofing and Verification</title>
    <content type="html">&lt;p&gt;The Identity Proofing and Verification (IDPV) Standard Development Project (ANSI/NASPO-IDPV-2013) at the &lt;a href="http://www.naspo.info/" title="North American Security Products Organization (NASPO)"&gt;North American Security Products Organization (NASPO)&lt;/a&gt;, which is an ANSI-accredited standards development organization, is &lt;strong&gt;developing minimum standards for the assertion, evidence and verification of personal identity&lt;/strong&gt;. To my knowledge, this is currently the most comprehensive, data-driven, and privacy respecting effort in the area of identity assurance that has active practitioner engagement.&lt;/p&gt;

&lt;p&gt;&lt;img class="scale-with-grid" style="display: block; margin-left: auto; margin-right: auto;" iph="http://blog.aniljohn.com/img/1x1.png" src="http://blog.aniljohn.com/img/one-in-crowd.png" /&gt;&lt;/p&gt;

&lt;p&gt;I recently attended the &lt;a href="http://www.naspo.info/calendar/idp-v-6th-plenary-meeting-may-15-17-2013" title="6th plenary meeting of the IDPV National Standard Project"&gt;6th plenary meeting of the IDPV National Standard Project&lt;/a&gt; and was impressed by both the rigor of the work, as well as the active engagement of practitioner focused subject matter experts from both private and public sector organizations. The focus of the work is NOT about the initial establishment of an identity, but about:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Developing &lt;strong&gt;minimum requirements&lt;/strong&gt; for (a) &lt;strong&gt;Reconciling an asserted identity to a single individual&lt;/strong&gt; (b) &lt;strong&gt;Proofing the asserted identity&lt;/strong&gt; by verifying corroborative evidence and by looking for symptoms of fraud&lt;/li&gt;
&lt;li&gt;Providing &lt;strong&gt;guidance for implementation and privacy concerns&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;The proposed standard identifies sets of &lt;strong&gt;core identity attributes&lt;/strong&gt; across the dimensions of Name, Location, Time and Identifier that in most cases, &lt;strong&gt;allows for resolution to a single identity&lt;/strong&gt;. It also provides a &lt;strong&gt;list of supplemental attributes that can be used to prevent collisions in cases where the core attributes are not enough&lt;/strong&gt;. The basis of these core and supplemental attributes are not theoretical, but based on extensive data modeling and analysis done on data sets that covered the U.S. population.&lt;/p&gt;

&lt;p&gt;At the same time, the group has been very cognizant of the privacy aspects of this work and, from the start, baked in the &lt;a href="http://blog.aniljohn.com/2011/05/FIPPs.html" title="Fair Information Practice Principles (FIPPs)"&gt;Fair Information Practice Principles (FIPPs)&lt;/a&gt; in a contextually sensitive manner regarding the information being requested.&lt;/p&gt;

&lt;p&gt;While the foundation appears solid, and applicable equally to jurisdictions outside the U.S., there is still work that needs to be done to make it more consumable to non-experts.&lt;/p&gt;

&lt;p&gt;The work is open to anyone and the group feels that, as it stands now, the work would benefit from wider scrutiny and input. If you have an interest in identity assurance and its associated privacy aspects, I would  encourage you to take a look at the work, get engaged, and provide feedback.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;RELATED INFO&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blog.aniljohn.com/2011/05/FIPPs.html" title="Fair Information Practice Principles (FIPPs)"&gt;Fair Information Practice Principles (FIPPs)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.naspo.info/" title="North American Security Products Organization (NASPO)"&gt;North American Security Products Organization (NASPO)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.naspo.info/calendar/idp-v-6th-plenary-meeting-may-15-17-2013" title="6th plenary meeting of the IDPV National Standard Project"&gt;6th plenary meeting of the IDPV National Standard Project&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=fBoFTBgthjw:W3g-o8uxA-8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=fBoFTBgthjw:W3g-o8uxA-8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=fBoFTBgthjw:W3g-o8uxA-8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=fBoFTBgthjw:W3g-o8uxA-8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=fBoFTBgthjw:W3g-o8uxA-8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=fBoFTBgthjw:W3g-o8uxA-8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=fBoFTBgthjw:W3g-o8uxA-8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/fBoFTBgthjw" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/fBoFTBgthjw/an-emerging-standard-for-identity-proofing-and-verification.html" title="An Emerging Standard for Identity Proofing and Verification" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/05/an-emerging-standard-for-identity-proofing-and-verification.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/05/likelihood-alien-invasion-assurance-levels</id>
    <published>2013-05-18T15:00:00-04:00</published>
    <updated>2013-05-18T15:00:00-04:00</updated>
    <title>Likelihood of Alien Invasions and Assurance Levels</title>
    <content type="html">&lt;p&gt;One of the first steps taken to protect a system from authentication errors is the determination of its assurance level requirement. That risk assessment process takes as input &lt;em&gt;potential harm&lt;/em&gt; and &lt;em&gt;likelihood of harm&lt;/em&gt;. This blog post looks at the applicability of the &lt;em&gt;likelihood&lt;/em&gt; factor when assessing assurance level requirements for Internet connected systems.&lt;/p&gt;

&lt;p&gt;&lt;img class="scale-with-grid" style="display: block; margin-left: auto; margin-right: auto;" iph="http://blog.aniljohn.com/img/1x1.png" src="http://blog.aniljohn.com/img/iday.png" /&gt;&lt;/p&gt;

&lt;p&gt;The classic "&lt;a href="http://csrc.nist.gov/drivers/documents/m04-04.pdf" title="E-Authentication Guidance for Federal Agencies (OMB-M04-04)"&gt;E-Authentication Guidance for Federal Agencies (OMB-M04-04) [PDF]&lt;/a&gt;" defines risk from authentication error as a function of two factors: (a) potential harm or impact and (b) the likelihood of such harm or impact. The categories of harm and impact and how to apply them, per OMB-04-04, can be found in my earlier blog post on &lt;a href="http://blog.aniljohn.com/2011/10/how-to-conduct-risk-assessment-to.html" title="HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials"&gt;HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The key point to note is that most risk assessment methodologies allow for “tuning” the risk using a “likelihood of harm/impact” factor, which looks something like this:&lt;/p&gt;

&lt;p class="text-center"&gt;&lt;strong&gt;Risk of Authentication Error = Potential Impact/Harm * Likelihood of Impact/Harm&lt;/strong&gt;&lt;/p&gt;


&lt;p&gt;But how does one determine the "likelihood of harm" number? The two classic approaches are to explore "&lt;a href="http://en.wikipedia.org/wiki/Base_rate"&gt;base rates&lt;/a&gt;" or to consult with experts. But there is a gotcha with experts:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The simplest and most intuitive advice we can offer [...] is that when you’re trying to gather good information and reality-test your ideas, go talk to an expert. Here’s what is less intuitive: Be careful what you ask them. Experts are pretty bad at predictions. But they are great at assessing base rates.&lt;/p&gt;
&lt;cite&gt;&lt;a href="http://heathbrothers.com/books/decisive/"&gt;Decisive: How to Make Better Choices in Life and Work&lt;/a&gt;&lt;/cite&gt;
&lt;/blockquote&gt;


&lt;p&gt;So a prediction by an expert may not be all that valuable. But what about the base rates? My concern there is the &lt;strong&gt;constantly evolving threat environment that is the Internet&lt;/strong&gt;, and how base rates that are based on past data are an unreliable predictor of the future.&lt;/p&gt;

&lt;p&gt;So my recommendation in this particular case is rather simple. In this type of evaluation set the "likelihood" factor equal to 1. &lt;strong&gt;DO NOT discount the likelihood of harm, and ALWAYS assume there is a likelihood of harm&lt;/strong&gt;:&lt;/p&gt;

&lt;p class="text-center"&gt;&lt;strong&gt;Risk of Authentication Error = Potential Impact/Harm * 1&lt;/strong&gt;&lt;/p&gt;


&lt;p&gt;What that means is that, if as part of your assurance assessment you need to factor in the impact or harm from an alien invasion, do not discount the likelihood! Stand firm, fully account for it, and put into place compensating controls to mitigate the consequences.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;RELATED INFO&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://csrc.nist.gov/drivers/documents/m04-04.pdf" title="E-Authentication Guidance for Federal Agencies (OMB-M04-04)"&gt;E-Authentication Guidance for Federal Agencies (OMB-M04-04) [PDF]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.aniljohn.com/2011/10/how-to-conduct-risk-assessment-to.html" title="HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials"&gt;HOW-TO Conduct a Risk Assessment to Determine Acceptable Credentials&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=3qQAN5tUYnA:QeXvWk_xzDw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=3qQAN5tUYnA:QeXvWk_xzDw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=3qQAN5tUYnA:QeXvWk_xzDw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=3qQAN5tUYnA:QeXvWk_xzDw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=3qQAN5tUYnA:QeXvWk_xzDw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=3qQAN5tUYnA:QeXvWk_xzDw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=3qQAN5tUYnA:QeXvWk_xzDw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/3qQAN5tUYnA" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/3qQAN5tUYnA/likelihood-alien-invasion-assurance-levels.html" title="Likelihood of Alien Invasions and Assurance Levels" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/05/likelihood-alien-invasion-assurance-levels.html</feedburner:origLink></entry>
  
  <entry>
    <id>http://blog.aniljohn.com/2013/05/how-to-visualize-access-control-use-cases</id>
    <published>2013-05-12T14:40:00-04:00</published>
    <updated>2013-05-12T14:40:00-04:00</updated>
    <title>HOW TO Visualize Access Control Use Cases</title>
    <content type="html">&lt;p&gt;Identity, authentication, attribute management and authorization domain experts tend to seek clear distinctions between each of those facets. The operational folks who actually deal with these issues often blur the boundaries between them. This blog post shows an example of laying out access control use cases from an operational perspective that I found rather educational.&lt;/p&gt;

&lt;p&gt;With the current buzz around mobility and BYOD, there is sometimes a belief that the infrastructure and choices that exist today will have to be completely re-done in order to accommodate new devices. While I am not sure about that, I recently saw a public NASA ICAM presentation that outlined a framework for how to look at access control from an operational perspective that I found relevant.&lt;/p&gt;

&lt;p&gt;I've kept the concept, but changed some of the details for the sake of clarity:&lt;/p&gt;

&lt;p&gt;&lt;img class="scale-with-grid" style="display: block; margin-left: auto; margin-right: auto;" iph="http://blog.aniljohn.com/img/1x1.png" src="http://blog.aniljohn.com/img/access_mgmt_requirements.png" /&gt;&lt;/p&gt;

&lt;p&gt;The key to the above visualization is to know that no one does credentialing and authentication for its own sake but as a means to an end to manage access to a system or resource. From an operational perspective, it allows for calling out an end to end process using natural language; &lt;em&gt;"A person who is anonymous, using an organization managed PC, on the organization's network, wants to access administrator level functions during normal business hours"&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;You can then lay out the use case variations using a tabular format:&lt;/p&gt;

&lt;table class="table table-bordered" auto;" border="1" cellspacing="0" cellpadding="5"&gt;
&lt;tr&gt;&lt;th&gt;Use Case&lt;/th&gt;&lt;th&gt;Applicability&lt;/th&gt;&lt;th&gt;Priority&lt;/th&gt;&lt;th&gt;Criteria A&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10.10.10.10.10&lt;/td&gt;
&lt;td&gt;NO&lt;/td&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;30.10.10.10.10&lt;/td&gt;
&lt;td&gt;YES&lt;/td&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;td&gt;...&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;


&lt;p&gt;It immediately gives you a way to articulate possibilities that may or may not apply to you; &lt;em&gt;What if it was a Smartphone instead of the PC? What if the connection is from the Internet? etc.&lt;/em&gt; It also provides you insights into what aspects change, what aspects still remain the same.&lt;/p&gt;

&lt;p&gt;Do you have any pointers to frameworks like these that help to clarify choices people need to make regarding access controls?&lt;/p&gt;
&lt;hr/&gt;These are solely my opinions and do not represent the thoughts, intentions, plans or strategies of any third party, including my employer&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=jvpRDTfH5As:3DuUS9ct-Fo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=jvpRDTfH5As:3DuUS9ct-Fo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=jvpRDTfH5As:3DuUS9ct-Fo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=jvpRDTfH5As:3DuUS9ct-Fo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=jvpRDTfH5As:3DuUS9ct-Fo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/AnilJohn?a=jvpRDTfH5As:3DuUS9ct-Fo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/AnilJohn?i=jvpRDTfH5As:3DuUS9ct-Fo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AnilJohn/~4/jvpRDTfH5As" height="1" width="1"/&gt;</content>
    <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/AnilJohn/~3/jvpRDTfH5As/how-to-visualize-access-control-use-cases.html" title="HOW TO Visualize Access Control Use Cases" />
    <author>
      <name>Anil John</name>
      <email>noreply@aniljohn.com</email>
      <uri>http://www.aniljohn.com/</uri>
    </author>
  <feedburner:origLink>http://blog.aniljohn.com/2013/05/how-to-visualize-access-control-use-cases.html</feedburner:origLink></entry>
  

</feed>
