Skip to content


Gartner IAM – Keynote

The second speaker during keynotes at the Gartner IAM conference was Bruce Schneier who is chief security technology office for BT. The title of his talk was The Intersection of Identity, Privacy and Securityand it was fascinating. One comment that really struck home was about how organizations struggle with trying to implement RBAC at an enterprise scale. His point was that most businesses were so dynamic that the roles were constantly changing and would become un-managable very quickly. I call this “role proliferation” and it is pretty common to see scalability limits reached quickly in organizations using RBAC.

Post to Twitter

Posted in Active Directory.

Tagged with , , , , , .


2 Responses

Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.

  1. David says

    Bob, what do you think is the solution giving the requirement of using RBAC?

  2. Bob Bobel says

    There are several new technologies that are being used around validated attribute and policy that reduce or eliminate the need for RBAC. There are even on-going projects using these new Attribute Based Access Control systems to solve the scalability problems found in traditional the RBAC approach.



Some HTML is OK

or, reply to this post via trackback.

Powered by WP Hashcash