IBM acquires CrossIdeas to Expand Security Offerings with Identity
Intelligence
IBM收购意大利云安全厂商CrossIdeas
>> Today my mood is: <<
Roles can't be built in a day
![]() |
| Marco |
According to the Kuppinger Cole report: Hidden Gems are vendors which are (still) relatively small, less known then "the big ones", and which definitively offer innovative solutions that are worth considering. These vendors are not (yet) stars in the worldwide IAM, GRC, and Cloud markets.It is in the nature of grinding Hidden Gems that some will not become the sparkling diamonds we expect today. Some will become acquired. However, there are strong opportunities in selecting products and services of innovative, young vendors – of the Hidden Gems.The selected vendors are distributed into four categories. Besides GRC, categories include IAM, IT Security and Cloud.

Actor: the subject (e.g. user that can be mediated by roles, ...) for whom the authorization is evaluated. Example Mr. X with the “Senior Bank Operator” roleand it is based on four entities:
Permission: is an action on the Resource (also called Operation). Example: Trading.
Resource: is the Application element to protect. Example: Stocks.
Constraints: are the Conditions that must be validated to grant the authorization. Two or more Constraints can be merged with a boolean combination of their values. Examples: Trading depends upon the user geographical area; Transfer limit is based on user characteristics; SoD conflict verification in real time.
Exceptions: are other conditions that can further limit the authorization decision and that allow for the creation/evaluation of more complex business logic. Example: Trading not allowed for companies where the user is involved.that rely on a Role Management infrastructure.

In the category “Best IAM Project in Cloud Computing”, […]The award was received by Piaggio Group of Italy for a hosted IAM solution based on products by Engiweb and focusing on defined, enterprise-wide business processes […] Both the number of nominees for the European Identity Award 2010 and the quality of the project submitted far surpassed last year. This is seen by Kuppinger Cole as a general sign of increasing maturity in IAM and GRC solutions. Especially notable was the number of nominations in the category “Cloud Computing”, a trend that the analyst group feels will be sure to continue over the next few years.
Lorenzo highlighted how even the “basic” password reset functionality was sufficient to justify project investments. As a matter of fact, he is now using these early successful results to support internal marketing activities, in order to more fully involve all stakeholders and gain more support for future development.
announced as one of Gartner’s “Cool Vendors” for 2010, in the Application Security category. This is all thanks to the IDEAS platform that, even if could be best positioned as part of the market segment of “Access Governance Platform”, among other things provides additional support for Entitlement Management.“When organizations are selecting their required IAM solution, a large amount acquire the solution of their preferred supplier and only 18% perform a vendor selection in order to select a ‘best of breed’ solution”It is easy to guess who these “very very large” preferred vendors are…. however this may result in a “hidden” failure for the customer: licenses acquired and at once abandoned with no project that was implemented at all! (Hard to believe, but not everybody realizes that the implementation of a project is the biggest cost for an IM initiative).
Il nostro Abbondio, non nobile,non ricco, coraggioso ancor meno s’era accorto, prima quasi di toccare gli anni della discrezione, d’essere in quella società, come un vaso di terra cotta, costretto a viaggiare in compagnia di molti vasi di ferro.

This event is a great networking opportunity for smart, innovative, and forward thinking people to get together to learn about and discuss today's most significant technology topics on IAM.“Munari’s life (1907-1998) and career spanned the 20th century, and he wasBut let me tell you why I’m speaking of Bruno Munari in this blog.among the most seminal exponents of Italian design and graphic design. Yet he never received the accolades and recognition on an international scale that he so richly deserved. What sets Munari apart from other designers is that he engaged in a quiet, playful revolution, inventing and designing with humorous and modest creativity, challenging all conventions and stereotypes intelligently but without flamboyance.”
What is happening in the present Enterprise Role management vendor acquisition fever is quite typical.
this Consortium, EII is particularly active on the project Spagic that aims at enlarging the OW2 Consortium code-base to support the development of business applications according to the SOA (Service Oriented Architecture) paradigm."Spagic is a solution composed by a set of visual tools and back-end applications oriented towards planning, realization, deploy and monitoring of ESB infrastructures adherent to the SOA paradigm. By means of visual tools, Spagic can be easily adopted by different categories of users involved in integration projects, such as: analysts defining the integration processes, developers realising application services, users monitoring and managing the entire system."

Most Identity related information is consolidated in the IDEAS master repository (based on a RDBMS) using specific connectors to Target Resources. But there is also an interface to other repositories to provide the required attributes without any need to move information from the existing user repository, thus providing a combined view of all user data.


In a large Organization environment there are many "Applications” managing both authentication and authorisation using (for instance) Active Directory groups.
In this context, with a single technological target (AD) connected to the IAM, there are multiple, associated “Applications”. On that level, into IAM environment, “target system” is a technology concept, whereas "Application” is a IAM business concept.
Note that in this context "Application" can be seen as a resources container (in this case AD groups).
Even AD groups set, used for users “Infrastructural” access, could be seen as an "Application". Following this point of view, we can group the “Infrastructural Resources” groups set (Internet, Mail OWA, VPN, FTP etc..) in a container (Application) and give it a name. (e.g. Infrastructure Resources).
This “Application” concept is very important in an IAM environment. Through “Applications” many administrative processes can be easily managed. Especially so are such processes where the “Target” concept does not fit because it is not expressive enough, and the “Resource” concept does not fit because it has too little granularity.
Some examples are:Most IAM tools refer to technological concepts such as Targets or simple Resources thus resulting in a very low expressivity and administrative complications.
- Application is a Business language while “Target” or “Resource” are technical languages.
- Dynamic management of IAM administrators “scope” on specific applications (an administrator can only approve requests referring to specific “Applications”).
- Policy writing is much more expressive and simple if referring to Applications instead of always identifying a set of resources.
- Event grouping under an Application is extremely expressive both from operational and auditing aspects.
If you want to introduce the Application concept where it is not “out-of-the-box”, you must analyze the impact, define data model and implement all business intelligence associated with the concept.
Instead, with a tool natively supporting this data model, processes implementation related to this concept are direct and prompt.
Referring to the above Active Directory example: with IDEAS by Engiweb Security, once the Active Directory technological connector is created, the creation of an "Application”, its relative “Resources” association and connection to the reference “Target”, is really simple.
Only a few parameters need to be defined, such as:
- Target.
- Synchronisation Options (Automatic, Manual NoSync). It is interesting to note that native Applications management, based on “Sync. Options”, make the synchronisation chain work in a different way. In fact, in the case of Automatic Sync, if a user is assigned an Entitlement or a Role which includes a resource from this application (e.g. an AD group), the system generates an outbound event towards the connector which automatically associates the group with the user. On the contrary, Manual Sync generates an event which is retrieved from a file to run a Batch Synchronisation (everything out-of-box).
- Resources connected.
For registration to this webcast, click here.
Yes, at least in Italy, most customers we work with are very clever at imagining every level of nuance when “theoretically” defining roles in their organization.
But fortunately, we are used to facing their anarchy and we know how to prevent the awkward problem of “role explosion”.
In this case, an authorized administrator accesses target1 and adds Profile1 to user John.