<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bob&#039;s Identity Management Blog &#187; Access Management</title>
	<atom:link href="http://www.bobbobel.com/tag/access-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bobbobel.com</link>
	<description>&#34;Anyone can hold the helm when the sea is calm.&#34; - Syrus Publilius</description>
	<lastBuildDate>Mon, 16 Jan 2012 21:47:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Just-in-Time Access Provisioning</title>
		<link>http://www.bobbobel.com/just-in-time-access-provisioning/</link>
		<comments>http://www.bobbobel.com/just-in-time-access-provisioning/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 04:56:04 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Entitlement]]></category>
		<category><![CDATA[Access Management]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Athentication and Authorization]]></category>
		<category><![CDATA[Google Apps provsioning]]></category>
		<category><![CDATA[Just in time provisoning]]></category>
		<category><![CDATA[SAML]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=863</guid>
		<description><![CDATA[While I was in college I worked summers for a glass company. My job was in the engineering drafting department where I drafted furnace parts, conveyor belts and paint bands that hides the goo they use to stick your windshield to your car. During this time American automakers struggling cope with the explosion of Japanese [...]]]></description>
			<content:encoded><![CDATA[<p>While I was in college I worked summers for a glass company. My job was in the engineering drafting department where I drafted furnace parts, conveyor belts and paint bands that hides the goo they use to stick your windshield to your car. During this time American automakers struggling cope with the explosion of Japanese imported cars. Japanese cars had a reputation of low cost and good quality, but the Japanese automakers also had a secret weapon that made them more efficient &#8211; Just-in-Time manufacturing.</p>
<p>Just-in-Time manufacturing is a simple concept &#8211; rather than keep all the unassembled car parts in expensive warehouses, have them delivered to the factory at the time they are needed to assemble a car.  This idea stuck with me and has been rattling around in the back of my mind for the past twenty years. Dell later used a similar concept steal market share away from IBM and Gateway who were building huge numbers of PCs and storing them until they were sold &#8211; while Dell built PCs that were already sold.</p>
<p>A project I have been working on for the past year or so was applying Just-in-Time concept to the process of granting users access to applications or data. The idea is that when a user attempts to access a resource for which they have not been granted access &#8211; the access attempt kicks of a self-service process or an automatic grant of access.</p>
<p>While I have seen other applications perform similar activities, many people have seen Microsoft SharePoint&#8217;s basic request access feature. The challenge I see with SharePoint is that it only allows generic requests that don&#8217;t allow the user to select the level of access they wish nor does it tell the user the state of their access request. Both are needed and both must be components of any more complete solution. A more complete solution must also provide access to more than just SharePoint; files, folders and applications access are also desperately needed.</p>
<p>Today, we posted a technical preview of Just-in-Time Access Provisioning called the ActiveRoles AuthX Provider The provider not only integrates authentication using SAML between AD users and Google Apps, it also can trigger a self-service access request through ActiveRoles if the user does not yet have an account. Once the request is approved a Google account is created. The next time the user points his/her browser to Google Apps URL the Provider seamlessly authenticates the user by doing an account mapping of AD user to the Google account and creates a SAML token that automatically signs the user into their Google Apps account. We created a 2 minute video showing the process so you can see how this works. The video was a little long and choppy at some points so I cut it down to about 2 minutes.</p>
<p><code><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/RN6pYgnQaa8&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/RN6pYgnQaa8&amp;hl=en&amp;fs=1" allowfullscreen="true" allowscriptaccess="always"></embed></object></code></p>
<p> <code><a href="http://www.bobbobel.com/wp-content/uploads/2010/04/ActiveRolesAccessProvider.wmv">Video:ActiveRoles Access Provider</a></code></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/just-in-time-access-provisioning/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
<enclosure url="http://www.bobbobel.com/wp-content/uploads/2010/04/ActiveRolesAccessProvider.wmv" length="2003011" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>My next web cast:Access Accountability and Sustained Compliance</title>
		<link>http://www.bobbobel.com/my-next-web-castaccess-accountability-and-sustained-compliance/</link>
		<comments>http://www.bobbobel.com/my-next-web-castaccess-accountability-and-sustained-compliance/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 23:19:21 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[access accountability]]></category>
		<category><![CDATA[Access Management]]></category>
		<category><![CDATA[ActiveRoles Server]]></category>
		<category><![CDATA[Provisioning]]></category>
		<category><![CDATA[SharePoint Compliance]]></category>
		<category><![CDATA[Sustained Compliance]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=747</guid>
		<description><![CDATA[On January 27th I&#8217;ve been asked to deliver another web cast showing  how you can ac hive Access Accountability and Sustained Compliance with Quest&#8217;s ActiveRoles Server. I&#8217;m going to demonstrate the new features of ActivceRoles Server and Self-Service Manager that allow you to get control over the access granted within your organization while at the [...]]]></description>
			<content:encoded><![CDATA[<p>On January 27th I&#8217;ve been asked to deliver another web cast showing  how you can ac hive Access Accountability and Sustained Compliance with Quest&#8217;s ActiveRoles Server. I&#8217;m going to demonstrate the new features of ActivceRoles Server and Self-Service Manager that allow you to get control over the access granted within your organization while at the same time sustaining compliance; a happy auditor is a quite auditor.</p>
<p>To register visit: <a href="http://www.quest.com/events/listdetails.aspx?contentid=10866&amp;searchoff=true&amp;technology=&amp;prod=183&amp;prodfamily=&amp;loc">http://www.quest.com/events/listdetails.aspx?contentid=10866&amp;searchoff=true&amp;technology=&amp;prod=183&amp;prodfamily=&amp;loc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/my-next-web-castaccess-accountability-and-sustained-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If Compliance is a only a symptom, what is the disease?</title>
		<link>http://www.bobbobel.com/if-compliance-is-a-onlly-a-symptom-what-is-the-disease/</link>
		<comments>http://www.bobbobel.com/if-compliance-is-a-onlly-a-symptom-what-is-the-disease/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 11:57:49 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Access Management]]></category>
		<category><![CDATA[Attestation]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Compliance Controls]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Section 404]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=612</guid>
		<description><![CDATA[Most of the directory owners to which I speak, have for a number of years, been living with legal or regulatory compliance.  Most have followed a predictable pattern of first sweating out their initial audit then later rationalizing better ways to implement whatever compliance policy to which they must adhere for sustained compliance.  First Audits are [...]]]></description>
			<content:encoded><![CDATA[<p>Most of the directory owners to which I speak, have for a number of years, been living with legal or regulatory compliance.  Most have followed a predictable pattern of first sweating out their initial audit then later rationalizing better ways to implement whatever compliance policy to which they must adhere for sustained compliance.  First Audits are often completed with brute force in a forest-killing documentation exercise. If that experience was painful enough (and it usually is)  they progress to looking at the underlying issue driving the compliance requirement to which they find themselves victim.  Ultimately this rationalization leads them to conclude that they must reach out to the enterprise and build compliance in business processes at which point they begin treating the root problem rather than its compliance audit symptoms.</p>
<p>You would think this would have been obvious from the start, but after reading the actual compliance equipments themselves it is easy to see why this causes so many people trouble. For example, the Sarbanes-Oxley Act of 2002 (SOX) was created to protect shareholders of public companies from financial miss-doings that could impact their investment. I will spare you the joy of reading section 404 of the SOX requirements which deals with the IT aspect of compliance and simply tell you, you would be underwhelmed by the lack of detail and direction it contains.</p>
<p> What is clearly spelled out in SOX is that the owner of an application or data should be responsible for controlling access to that owner&#8217;s resource and further there needs to be a set of controls to make sure this happens. The reasoning is simple, the application or data owner is in the best position to know and understand the business justifications for granting access to their resource. SOX doesn&#8217;t recommend what type of controls are needed only that they must exist.  </p>
<p>The lack of detail around IT controls &#8211; leaves everything open to interpretation as to what is required on the part of IT to comply with the regulation. Because experience and competence varies by auditor and IT team, recommendations can be anything from a paper-based procedures to implementing a new compliance layer of audit software or worse. The directory owners I see who are able to achieve sustained compliance implement software based process controls. These software based controls should always automate and enforce governance be self-document and should support real-world demonstration that the controls are in place and effective. Once these controls are in place audit preparation time drops to hours rather than the weeks or months a first audit typically would require.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/if-compliance-is-a-onlly-a-symptom-what-is-the-disease/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

