<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Research on Identity Management (by Marco Casassa Mont)</title><link>http://www.communities.hp.com/online/blogs/mcm/default.aspx</link><description>Marco Casassa Mont’s “Research on Identity Management” Blog. The focus of this blog is on trends, new technologies/solutions and innovative aspects of Identity Management - in a variety of contexts. I am a researcher at HP Labs: I am very keen to explore and discuss technical and social aspects of Identity Management that are going to affect individuals, enterprises and other organizations in the medium/long terms. What is the next big thing in this space?
</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/ResearchOnIdentityManagement" type="application/rss+xml" /><item><title>EEMA e-Identity: Presentation on the Future of the Identity in the Cloud </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/tTzFrSXvRdk/92647.aspx</link><pubDate>Mon, 29 Jun 2009 22:30:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92647</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92647.aspx#comments</comments><description>&lt;p&gt;I recently attended the &lt;a href="http://www.revolutionevents.plus.com/eema/index.htm"&gt;EEMA e-Identity Conference&lt;/a&gt;, in London, 25-26 June 2009. There have been interesting presentation and good talks.&lt;/p&gt;
&lt;p&gt;I also gave a presentation on &amp;quot;&lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Documents/Papers/HPL-IdentityCloud%20-%20EEMA-%20marcocasassamont.ppt"&gt;The Future of Identity in the Cloud: Requirements, Risks and Opportunities&lt;/a&gt;&amp;quot;:&lt;/p&gt;
&lt;p&gt;&amp;quot;This presentation aims at: setting the context about Identity in the Cloud; discussing related identity management issues along with core requirements (coming from users and organisations); illustrating, from an HP Labs&amp;#39; perspective, future possible models, approaches and IT infrastructures to handle Identity in the Cloud.&lt;/p&gt;
&lt;p&gt;The introduction of the presentation sets some background: it gives an overview of Cloud Computing and its implications, in terms of service provisioning, security, privacy and identity management. In particular it discusses the paradigm shift from a close &amp;amp; controlled approach (within enterprises) to potentially, on-the-fly composable and customisable services, in the Cloud. &lt;/p&gt;
&lt;p&gt;Use cases are introduced to illustrate &amp;quot;common&amp;quot; usage and management tasks involving Identity in the Cloud - from both user and organisational perspectives, including the implications of having to deal with Identity in composable and dynamic services. New emerging, related threats and risks are briefly discussed, such as the potential growth of bogus service providers, targeted attacks to the weakest points in the service provisioning chain and identity thefts.&lt;/p&gt;
&lt;p&gt;This will lead to a discussion of key requirements, determined by new interaction models and service-provisioning paradigms in the Cloud, including: control of identity flows and management of distributed user accounts; trust and reputation about service providers in the Cloud; identity assurance; transparency about security practices; privacy (including consent and revocation). &lt;/p&gt;
&lt;p&gt;I will then discuss current (categories of) identity management solutions and approaches that deal with aspects of Identity in the Cloud (such as identity federation, identity brokering, Identity 2.0, etc.), along with their pros and cons and failures to address some of the core requirements (such as assurance, trust and privacy control).&lt;/p&gt;
&lt;p&gt;The final part of this presentation challenges current assumptions and approaches and illustrates future directions, by presenting HP Labs&amp;#39; medium and long-term vision about how the underlying Cloud infrastructure is going to evolve along with its implication in terms of Identity and Identity Management. This includes the paradigm shifts introduced by the usage of trusted virtualisation, remote attestation of platform capabilities (Trusted Computing Platforms) and identity-driven computational environment (coming from the cloud) that could run on local systems (e.g. at the user side); new emerging identity management models driven by identity-aware platforms and policy-driven delegation of credentials; the role that Security and Identity Analytics can play, by using modelling and simulation, to help organisations to evaluating and predicting the consequences of using services in the Cloud, based on assumptions made on the underlying identity management model and existing threats.&amp;quot;&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92647" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/tTzFrSXvRdk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/identity+management/default.aspx">identity management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92647.aspx</feedburner:origLink></item><item><title>Another New HP Labs Technical Report: Using Security Metrics Coupled with Predictive Modelling and Simulation to Assess Security Processes </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/NXGSDP1r5AQ/92646.aspx</link><pubDate>Mon, 29 Jun 2009 22:27:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92646</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92646.aspx#comments</comments><description>&lt;p&gt;Another new HP Labs Technical Report has been recently released, called &amp;quot;&lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-142.html"&gt;Using Security Metrics Coupled with Predictive Modelling and Simulation to Assess Security Processes&lt;/a&gt;&amp;quot; (authors: Yolanta Beres, Marco Casassa Mont, Jonathan Griffin, Simon Shiu):&lt;/p&gt;
&lt;p&gt;&amp;quot;It is hard for security practitioners and decision-makers to know what level of protection they are getting from their investments in security, especially when they have invested in a number of technologies and processes which interact and combine together. It is even harder to estimate how well these investments can be expected to protect their organizations in the future as security policies, regulations and the threat environment are constantly changing. In this paper we propose that for measuring the effectiveness of security processes in large organizations, a greater emphasis needs to be put on process-based metrics, in contrast to the more commonly used symptomatic lagging indicators. We show how these process-based metrics can be combined with executable, predictive models, based on a sound mathematical foundation, to both assess organizations&amp;#39; security processes under current conditions and predict how well they are likely to perform in potential future scenarios, which may include changes in working practices, policies or threat levels, or new investments in security. We present two case studies, in the areas of vulnerability threat management, and identity and access management, as significant examples to illustrate how this modeling and simulation-based approach can be used to provide a rich picture of how well existing security processes are protecting the organization and to answer &amp;quot;what- if&amp;quot; questions, such as exploring the effects of a change in security policy or an investment in new security technology. Our approach enables the organization to apply the metrics that are most relevant to its business, and provide a comprehensive view that shows the benefits and losses to the different stakeholders&amp;quot; &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92646" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/NXGSDP1r5AQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Analytics/default.aspx">Security Analytics</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92646.aspx</feedburner:origLink></item><item><title>New HP Labs Technical Report: Towards an Analytic Approach to Evaluate Enterprises’ Risk Exposure to Social Networks </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/Nbd2RVVGFiY/92644.aspx</link><pubDate>Mon, 29 Jun 2009 22:22:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92644</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92644.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;
&lt;p&gt;A new HP Labs Technical Report has been recently released, called &lt;a href="http://www.hpl.hp.com/techreports/2009/HPL-2009-138.html"&gt;&amp;quot;Towards an Analytic Approach to Evaluate Enterprises&amp;#39; Risk Exposure to Social Networks&amp;quot; &lt;/a&gt;(authors: Anna Squicciarini, Marco Casassa Mont, Sathya Dev Rajasekaran):&lt;/p&gt;
&lt;p&gt;&amp;quot;This paper aims at exploring the impact on enterprises of the adoption of Social Networks by employees. It analyses the risks that enterprises could face and suggests a methodology to answer questions, such as: what are the actual risks for an organization, given a specific context? How to assess these risks? What are the most significant approaches that can be taken to mitigate them? What are the financial and organizational implications for an organization in implementing any of the possible approaches?&amp;quot; &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92644" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/Nbd2RVVGFiY" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+Analytics/default.aspx">Identity Analytics</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/30/92644.aspx</feedburner:origLink></item><item><title>HP Labs - Second Annual Innovation Research Awards </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/4KWHqXM24CE/92306.aspx</link><pubDate>Tue, 16 Jun 2009 16:04:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92306</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/17/92306.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;HP Labs have announced the Recipients of the Second Annual Innovation Research Awards (&lt;/span&gt;&lt;a href="http://finance.yahoo.com/news/HP-Announces-Recipients-of-bw-15522893.html?.v=1"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;http://finance.yahoo.com/news/HP-Announces-Recipients-of-bw-15522893.html?.v=1&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;):&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&amp;ldquo;Sixty projects from 46 universities in 12 countries will receive awards from &lt;/span&gt;&lt;a href="http://us.lrd.yahoo.com/_ylt=Au31FwkYKQkh4922chQFo3OvMncA/SIG=14sd9af2m/**http%3A/cts.businesswire.com/ct/CT%3Fid=smartlink%26url=http%253A%252F%252Fwww.hpl.hp.com%252F%26esheet=5986478%26lan=en_US%26anchor=HP%2BLabs%26index=2"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;HP Labs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;, the company&amp;rsquo;s central research arm. The program is designed to create opportunities for colleges, universities and research institutes to conduct breakthrough collaborative research with HP.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;Building on the success of last year&amp;rsquo;s program, HP increased the number of projects it will fund by more than 30 percent &amp;ndash; up from 45 projects at 35 institutions worldwide in 2008. Furthermore, given the significant contributions achieved in last year&amp;rsquo;s program &amp;ndash; including 61 published papers and 13 invention disclosures &amp;ndash; HP extended a second year of funding to 31 professors in 2009. &amp;hellip;&amp;rdquo;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;--- Posted by Marco Casassa Mont (&lt;/span&gt;&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt; and &lt;/span&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;)&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/span&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;mirror blog&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92306" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/4KWHqXM24CE" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/HP+Labs+Innovation+Research+Awards/default.aspx">HP Labs Innovation Research Awards</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/17/92306.aspx</feedburner:origLink></item><item><title>W3C Policy Interest Group (PLING) Charter Extended</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/br4ky1II0RM/92305.aspx</link><pubDate>Tue, 16 Jun 2009 15:43:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:92305</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/16/92305.aspx#comments</comments><description>&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;The W3C Policy Interest Group (&lt;/span&gt;&lt;a href="http://www.w3.org/Policy/pling/wiki/Main_Page"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;PLING&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;) Charter has been extended till 31 December 2009.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;We are looking for additional case studies and requirements, in particular in emerging areas such as Cloud Computing and Social Networking.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;Please share your thoughts, input and experience. Feel free to &lt;/span&gt;&lt;a href="mailto:public-pling-request@w3.org"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;subscribe to the PLING mailing list&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt; to get periodic updates on discussions and topics of interest.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;--- Posted by Marco Casassa Mont (&lt;/span&gt;&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt; and &lt;/span&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Times New Roman;"&gt;)&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;---&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-ansi-language:EN-US;" lang="EN-US"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;--- NOTE:&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;use this &lt;/span&gt;&lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;mirror blog&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt; if you prefer posting on an external blog site &lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;---&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size:small;font-family:Times New Roman;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=92305" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/br4ky1II0RM" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/W3C+PLING/default.aspx">W3C PLING</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/06/16/92305.aspx</feedburner:origLink></item><item><title>A few Thoughts on Security Assurance …</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/xrhKJxSsQ58/91838.aspx</link><pubDate>Wed, 27 May 2009 13:50:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:91838</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/27/91838.aspx#comments</comments><description>&lt;p&gt;Based on various interactions and discussions that I had with organizations, customers and various people, I understand that dealing with &amp;quot;Security Assurance&amp;quot; is currently a major concern and issue.&lt;/p&gt;
&lt;p&gt;How can a CIO/CISO be sure that their organization is making the right bets on the right security investments? How to be sure that these investments are effectively addressing the right security issues (of relevance to the business), especially in an ever changing IT and social environment (with dynamic threat environments)? How to get proper feedback about the current, overall situation, have a reasonable understanding of involved risks and exposures and be in the position to make informed decisions?&lt;/p&gt;
&lt;p&gt;This is actually a &amp;quot;recursive problem&amp;quot; involving various decision makers and managers in the organization ladder. It impacts their ability to define proper policies and protect organizational assets.&lt;/p&gt;
&lt;p&gt;&amp;quot;Security Assurance&amp;quot; is of particular relevance in case of outsourcing and/or usage of services in the Cloud, when organization loses control on their IT stacks and related &amp;quot;control points&amp;quot;. &amp;nbsp;Just relying on contractual agreements and hoping that everything is going to be fine is not a satisfactory approach.&lt;/p&gt;
&lt;p&gt;I do not think that current bottom-up &amp;quot;security monitoring&amp;quot; and risk assessment tools/solutions can address this kind of challenges. This is really and area open to contributions and innovation.&lt;/p&gt;
&lt;p&gt;Incidentally, all the above points also apply to the &amp;quot;Identity Management&amp;quot; vertical (Identity Assurance ...).&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=91838" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/xrhKJxSsQ58" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Security+Assurance/default.aspx">Security Assurance</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/27/91838.aspx</feedburner:origLink></item><item><title>Part III: The Future of Identity in the Cloud: Requirements, Risks and Opportunities</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/n2mjAoqxRJQ/91837.aspx</link><pubDate>Wed, 27 May 2009 13:46:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:91837</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/27/91837.aspx#comments</comments><description>&lt;p&gt;I am surprised by the number of people and organizations that have been asking me to give a rerun of the presentation on &amp;quot;The Future of Identity in the Cloud: Requirements, Risks and Opportunities&amp;quot; - that I previously gave at the Open Group Security Practitioners Conference, London, 27 April 2009.&lt;/p&gt;
&lt;p&gt;A copy of this presentation is now available &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Documents/Papers/HPL-IdentityCloud%20-%20marcocasassamont.ppt"&gt;here&lt;/a&gt;, in my web page. &lt;/p&gt;
&lt;p&gt;I am currently working on a new version of it (for the &lt;a href="http://www.revolutionevents.plus.com/eema/index.htm"&gt;EEMA e-Identity Conference 2009&lt;/a&gt;), to keep into account recent developments and new interesting aspects/concerns related to Identity in the Cloud. &lt;/p&gt;
&lt;p&gt;I still believe that &amp;quot;Security Assurance&amp;quot; is the hot topic for Cloud Computing and&amp;nbsp; specifically &amp;quot;Identity Assurance&amp;quot; is a key concern for Identity in the Cloud.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=91837" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/n2mjAoqxRJQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+in+the+Cloud/default.aspx">Identity in the Cloud</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/27/91837.aspx</feedburner:origLink></item><item><title>IEEE Policy 2009 – Call for Sponsorship</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/xt81mrEBBwU/ieee-policy-2009-call-for-sponsorship.aspx</link><pubDate>Mon, 04 May 2009 22:20:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:89301</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/05/ieee-policy-2009-call-for-sponsorship.aspx#comments</comments><description>&lt;p&gt;The IEEE Policy 2009 Symposium (&lt;a href="http://www.ieee-policy.org/"&gt;http://www.ieee-policy.org/&lt;/a&gt;), to be held in London, UK, 20-22 July 2009, has now received the sponsorship of both IEEE Computer Society and IEEE Communication Society (technical co-sponsorship).&lt;/p&gt;
&lt;p&gt;A draft program is also available at &lt;a href="http://www.policy-workshop.org/program.html"&gt;http://www.policy-workshop.org/program.html&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;We are now looking for sponsors from the industry and academy.&amp;nbsp; Have a look at the &amp;quot;Call for Sponsors&amp;quot; (&lt;a href="http://www.policy-workshop.org/POLICY2009-CallForPatrons.pdf"&gt;http://www.policy-workshop.org/POLICY2009-CallForPatrons.pdf&lt;/a&gt;), &lt;/p&gt;
&lt;p&gt;In case of interest, please contact&amp;nbsp; &lt;a href="mailto:ieeepolicy2009@googlemail.com?subject=POLICY+2009+Sponsorship"&gt;mailto:ieeepolicy2009@googlemail.com?subject=POLICY+2009+Sponsorship&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=89301" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/xt81mrEBBwU" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/IEEE+Policy+2009/default.aspx">IEEE Policy 2009</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/05/ieee-policy-2009-call-for-sponsorship.aspx</feedburner:origLink></item><item><title>Identity and Privacy Forum, 14-15 May 2009, London</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/ui0c2cunB4A/identity-and-privacy-forum-14-15-may-2009-london.aspx</link><pubDate>Mon, 04 May 2009 22:16:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:89300</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/05/identity-and-privacy-forum-14-15-may-2009-london.aspx#comments</comments><description>&lt;span&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;
&lt;p&gt;This community might be interested in attending the Identity and Privacy Forum, London, 14-15 May 2009, &lt;a href="http://www.identityandprivacy.com/"&gt;http://www.identityandprivacy.com/&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=89300" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/ui0c2cunB4A" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+and+Privacy+Forum/default.aspx">Identity and Privacy Forum</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/05/identity-and-privacy-forum-14-15-may-2009-london.aspx</feedburner:origLink></item><item><title>Part II: The Future of Identity in the Cloud: Requirements, Risks and Opportunities</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/-Yk_q98CrgQ/part-ii-the-future-of-identity-in-the-cloud-requirements-risks-and-opportunities.aspx</link><pubDate>Mon, 04 May 2009 22:07:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:89299</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/05/part-ii-the-future-of-identity-in-the-cloud-requirements-risks-and-opportunities.aspx#comments</comments><description>&lt;p&gt;The presentation on &amp;quot;The Future of Identity in the Cloud: Requirements, Risks and Opportunities&amp;quot; that I gave at the Open Group Security Practitioners Conference, London, 27 April 2009, is now available online, at &lt;a href="http://www.opengroup.org/conference-live/"&gt;http://www.opengroup.org/conference-live/&lt;/a&gt;&amp;nbsp; along with the ones of the other presenters (Security Plenary Presentation Section). &lt;/p&gt;
&lt;p&gt;Thanks to the people who provided me with inputs and material about this topic.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=89299" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/-Yk_q98CrgQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+in+the+Cloud/default.aspx">Identity in the Cloud</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/05/05/part-ii-the-future-of-identity-in-the-cloud-requirements-risks-and-opportunities.aspx</feedburner:origLink></item><item><title>The Future of Identity in the Cloud: Requirements, Risks and Opportunities</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/bgqN8KHWWo8/the-future-of-identity-in-the-cloud-requirements-risks-and-opportunities.aspx</link><pubDate>Fri, 17 Apr 2009 14:14:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:89017</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/17/the-future-of-identity-in-the-cloud-requirements-risks-and-opportunities.aspx#comments</comments><description>&lt;p&gt;I am preparing my presentation, called &amp;quot;The Future of Identity in the Cloud: Requirements, Risks and Opportunities&amp;quot;&amp;nbsp; (&lt;a href="http://www.opengroup.org/london2009-spc/mont.htm"&gt;http://www.opengroup.org/london2009-spc/mont.htm&lt;/a&gt;) for the coming Open Group Security Practitioners Conference, London, 27 April 2009.&lt;/p&gt;
&lt;p&gt;In particular I am very keen in discussing current models and architectures underpinning both Cloud Computing and Identity in the Cloud, along with discussions of risks, issues and (users&amp;#39; and organisations&amp;#39;) requirements.&lt;/p&gt;
&lt;p&gt;This is a good opportunity to get additional input from this community, in particular related to Identity in the Cloud, if you have specific concerns, issues or you would like to share requirements.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=89017" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/bgqN8KHWWo8" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Identity+in+the+Cloud/default.aspx">Identity in the Cloud</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/17/the-future-of-identity-in-the-cloud-requirements-risks-and-opportunities.aspx</feedburner:origLink></item><item><title>CfP for 5th  ACM Workshop on Digital Identity Management – DIM 2009</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/FHTWounRdiI/cfp-for-5th-acm-workshop-on-digital-identity-management-dim-2009.aspx</link><pubDate>Fri, 17 Apr 2009 14:12:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:89016</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/17/cfp-for-5th-acm-workshop-on-digital-identity-management-dim-2009.aspx#comments</comments><description>&lt;p&gt;The CfP of the 5&lt;sup&gt;th&lt;/sup&gt; ACM Workshop on Digital Identity Management, DIM 2009, is now available online: &amp;nbsp;&lt;a href="http://www2.pflab.ecl.ntt.co.jp/dim2009/"&gt;http://www2.pflab.ecl.ntt.co.jp/dim2009/&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Please consider submitting a paper.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=89016" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/FHTWounRdiI" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/ACM+DIM+2009/default.aspx">ACM DIM 2009</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/17/cfp-for-5th-acm-workshop-on-digital-identity-management-dim-2009.aspx</feedburner:origLink></item><item><title>BIdS 2009</title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/vBefXYTWuUk/bids-2009.aspx</link><pubDate>Thu, 16 Apr 2009 15:44:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88999</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/16/bids-2009.aspx#comments</comments><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a class="" title="OLE_LINK6" name="OLE_LINK6"&gt;&lt;/a&gt;The CfP of the first IEEE International Conference on Biometrics, Identity and Security is now available online:&amp;nbsp; &lt;a href="http://ieee-biometrics.org/bids2009/"&gt;http://ieee-biometrics.org/bids2009/&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88999" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/vBefXYTWuUk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/BIdS+2009/default.aspx">BIdS 2009</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/16/bids-2009.aspx</feedburner:origLink></item><item><title>Cloud Security Alliance </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/7urs9dmfp6w/cloud-security-alliance.aspx</link><pubDate>Fri, 03 Apr 2009 09:38:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88753</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/03/cloud-security-alliance.aspx#comments</comments><description>&lt;span&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;span&gt;&lt;font size="3"&gt;&lt;font face="Times New Roman"&gt;
&lt;p&gt;You might be interested in knowing that a &lt;a href="http://www.cloudsecurityalliance.org/"&gt;Cloud Security Alliance&lt;/a&gt; has been recently created and it will be launched at RSA.&lt;/p&gt;
&lt;p&gt;I am interested in getting more details about their approach to handle IAM (and related issues) in the Cloud ...&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88753" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/7urs9dmfp6w" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Cloud+Security+Alliance/default.aspx">Cloud Security Alliance</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/04/03/cloud-security-alliance.aspx</feedburner:origLink></item><item><title>The Economics of Identity and Access Management (IAM) </title><link>http://feedproxy.google.com/~r/ResearchOnIdentityManagement/~3/p3ZCkWZH4ag/the-economics-of-identity-and-access-management-iam.aspx</link><pubDate>Fri, 20 Mar 2009 17:33:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:88486</guid><dc:creator>marcocasassamont</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/21/the-economics-of-identity-and-access-management-iam.aspx#comments</comments><description>&lt;p&gt;What are the Economics of Identity and Access Management (IAM)? &amp;nbsp;This is a key area that needs to be explored, to really understand, from an economic perspective, the actual value that IAM provides to organizations based on its impact on aspects of relevance to decision makers (such as loss prevention and risk mitigation) and the threat landscape. &lt;/p&gt;
&lt;p&gt;A few core aspects need to be researched:&lt;/p&gt;
&lt;p&gt;1) What are the key &amp;quot;aspects/metrics&amp;quot; that characterize the impact of IAM investments on an enterprise, for example in terms of preventing/reducing losses? In a first analysis important &amp;quot;macro&amp;quot; aspects include: security breaches (B), productivity loss (P), compliance violations (C) and costs (K)... &lt;/p&gt;
&lt;p&gt;2) How do these aspects/metrics relate to the basic IAM &amp;quot;levers&amp;quot; that decision makers (e.g. CIO/CISO/Risk Managers) can act on i.e. configuration, enforcement and audit reporting tools (compliance checking tools)? We need to capture the relevant causal dependencies, for example: what are the consequences and the impact of investing more on audit/compliance checking, rather than in configuration or enforcement? What are the consequences of acting on enforcement in terms of productivity and costs?&lt;/p&gt;
&lt;p&gt;3) Which utility functions, U(B,P,C,K) can effectively model the impact of IAM (e.g. in terms of losses) on security breaches, productivity loss, compliance violations&amp;nbsp; and costs by factoring in the investments in the &amp;quot;configuration, enforcement and audit&amp;quot; levers?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;4) How to effectively use systems modeling to estimate these utility functions, by animating the causal dependencies and inter-relationships among these &amp;quot;levers&amp;quot; and their impact on metrics, inclusive of assumptions on the threat landscape?&lt;/p&gt;
&lt;p&gt;So far I found very little literature and related work in this space - I would be keen to get any reference or link, if available.&lt;/p&gt;
&lt;p&gt;I am going to pursue research in this space, in the context of the &lt;a href="http://www.hpl.hp.com/personal/Marco_Casassa_Mont/Projects/IdentityAnalytics/IdentityAnalytics.htm"&gt;Identity Analytics&lt;/a&gt; activity (HP Labs Security Analytics project, &lt;a href="http://www.hpl.hp.com/research/systems_security/"&gt;Systems Security Lab&lt;/a&gt;), as I believe this (as for the Economics of Privacy and the Economics of Information Security) can: &lt;/p&gt;
&lt;p&gt;- provide a more rational way to describe and analyse the impact and value that IAM actually offers to organizations; &lt;/p&gt;
&lt;p&gt;- provide key decision makers with a decision support tool that operates at their level of abstraction.&lt;/p&gt;
&lt;p&gt;--- Posted by Marco Casassa Mont (&lt;a href="http://www.communities.hp.com/online/blogs/mcm/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;here&lt;/a&gt;)&amp;nbsp; ---&lt;/p&gt;
&lt;p&gt;--- NOTE:&amp;nbsp; use this &lt;a href="http://research-on-identitymanagement.blogspot.com/"&gt;mirror blog&lt;/a&gt; if you prefer posting on an external blog site &amp;nbsp;---&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=88486" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/ResearchOnIdentityManagement/~4/p3ZCkWZH4ag" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+Management/default.aspx">Economics of Identity Management</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+IAM/default.aspx">Economics of IAM</category><category domain="http://www.communities.hp.com/online/blogs/mcm/archive/tags/Economics+of+Identity+and+Access+Management/default.aspx">Economics of Identity and Access Management</category><feedburner:origLink>http://www.communities.hp.com/online/blogs/mcm/archive/2009/03/21/the-economics-of-identity-and-access-management-iam.aspx</feedburner:origLink></item></channel></rss>
