Agenda
| Wednesday, 05.05.2010 | ||
| 07:30-10:00 |
Check-in & Registration |
|
| 08:30-09:00 |
The Role as a Role Model Niels von der Hude, Beta Systems Software
In many enterprises, modeling the permissions for a new employee on those of a member of staff whose job description involves similar tasks is still the established practice. Our presentation not only points out the dangers of working in this way, but also describes the procedural method that is to be aimed for, especially with regard to compliance considerations. This method combines the functions involved in the creation of roles (role mining), the use of roles in provisioning, and the authorization of changes by means of workflow components, thus providing a homogeneous whole that describes the entire life cycles of roles. The presentation demonstrates how this procedural model takes the functional view of an employee's role and translates it into concrete technical permissions that are immediately usable in the day-to-day work environment, and whose logic is clear to all concerned. Based on our practical experience in role management projects, we will also present solutions for working with dynamic roles and handling the numerous dependencies that exist between roles. |
|
| 09:00-09:30 |
Extending the Principles of Service-Oriented Security to Cloud Computing John Aisien, Oracle Corporation
Cloud computing adoption is adversely affected by security and privacy concerns. Enterprises are often perplexed by the many challenges of cloud security and how to maintain compliance and governance in this new IT paradigm. This session will outline how to leverage existing identity and access management infrastructure, and how to extend Service-Oriented Security and standards-based interactions to successfully secure assets in the cloud; and will include customer examples. |
|
| 09:30-10:00 |
On Cloud 9 or Lost In (that) Space Prof. Dr. Eberhard von Faber, T-Systems
Cloud Computing has a variety of terrific characteristics. Some are really new. Some other are well known for years and just come in different form or flavour. Best situation to discover and learn from long-term trends, point at today’s critical issues or smoothly direct the discussion back on track. What processes do user organizations need to manage cloud security risks? Do our experts come across with issues which are considered fundamental five years from now? What impact have all-round cloud self-service for enterprise security management and consistency? The cloud scales. Will security and even identities scale, or do we get stuck in identity silos? Those are the type of questions which guide to new insides, point to discussions in other track sessions and maybe induce others. |
|
| 10:00-10:30 |
Coffee Break, Expo Area |
|
|
Best Practices I Moderator: Sebastian Rohr, KuppingerCole
|
|
| 10:30-11:30 |
Identity Management & Cloud Computing in the Automotive Industry Dr. Barbara Mandl, Daimler AG
On the on hand cloud computing bares great opportunities for corporations. But if you take a closer look especially under identity management aspects a significant number of challenges arises. We are trying to look into the possibilities of today, existing show stoppers and how a perspective of cloud computing in the automotive industry might look like. Lorenzo Mastropietro, Piaggio & C S.p.a.
|
|
| 11:30-12:30 |
Bringing BMW’s New Central Identity and Access Management System into Life Dr. Andreas Neumann, Logica Deutschland GmbH & Co. KG
Jürgen Skerhut, BMW
At BMW, a large number of applications based on the major IT platforms Windows, Mainframe, CA, SAP... are in use. In the past several custom made management applications have been developed and deployed to manage accounts and access rights on these different platforms, sometimes using different processes. Over time these systems developed into a state of unsustainable complexity due to increasing business demands with correspondingly high support and maintenance costs. This situation lead to a demand to improve the management of accounts in order to meet the evolving security needs of BMW Group. Furthermore changes in international law exacerbated the situation and the need for action. IdAS – BMW’s new Identity and Access Management System – has been designed and developed to address this situation. With IdAS formerly disparate management and provisioning processes are integrated and automated fulfilling the needs for flexibility, security and speed. IdAS has been successfully launched in late summer 2009.The international step-wise migration and rollout has been conducted in a short time frame in the second half of 2009. The presentation will cover the following topics:
Adrian Castillo, HID Global
Kristian Koljatic, KING ICT d.o.o.
Nino Talian, KING ICT d.o.o.
In the early years of this century, corporate telephone networks have become an integral part of unified communications systems operating as part of the IT infrastructure and no longer as a stand alone network. This second decade is seeing a new trend in IT resources rationalization driven in part by the fact that workers are more mobile and IT networks are being exposed to the outside world thus no longer making the physical perimeter of the company's facilities the boundary of the network. As a result, the physical access control system is progressively being merged into the IT infrastructure so the directory of users and their access rights become an additional user repository that is managed by centralized Identity Management Systems. HID will show how King ICT, Croatia is prototyping a system that integrates physical access control with their central Active Directory based infrastructure. |
|
| 12:30-14:00 |
Lunch Break, Expo Area |
|
|
Best Practices II: Public Services, Health Moderator: Tim Cole, KuppingerCole
|
|
| 14:00-15:00 |
German National ID – Privacy by Design Andreas Reisen, Federal Ministry of the Interior, Germany
The EC STORK Project - Approaches, Challenges, ResultsMarc Sel, PwC Belgium
This talk will address the STORK project, its challenges, approaches followed and results achieved so far. STORK stands for Secure Identities Across Borders Linked, aiming to achieve interoperable electronic identities across Europe. Against a background of the EC Treaty which establishes freedom of establishment and freedom of provision of service via the Services Directive (to be implemented by the end of 2009 – including remote aspects), there remain many challenges, particularly in the area of IAM. eGovernment is supporting the single market, and the Council Conclusions on eGovernment (20 Nov. 2003, 14671/03) underlines importance of interoperability. Furthermore, the ”Raising the game” of DG InfoSoc requires interoperable e-identity. However …. while there is an e-signature directive, there is no e-identity directive. There are widely diverging approaches across the member states for National e-Identity (NeID), and as a consequence the current NeID’s are not interoperable. STORK aims at establishing an EU-wide interoperable e-identity and access mechanism. As such, STORK is the common ground for other pilots, such as PEPPOL (electronic procurement). |
|
| 15:00-16:00 |
SPOCS - Crossborder Access to eGovernment Services Martin Spitzenberger, Austrian Federal Chancellery
SPOCS (Simple Procedures Online for Cross-border Services) is a pilot project launched by the European Commission which aims to improve the existing implementations of the Services Directive in Europe. It will deliver specifications and tools for a version 2.0 of the Points of Single Contact established throughout Europe by the end of 2009. In order to build interoperable, seamless and smarter cross border services various components that require identity and access management have to be integrated. Some of the questions involved are: how to identify a legal person and bind a user to that person, how to verify electronic documents, how to authorise access to electronic document repositories (eSafes), how to identify a registered user of an electronic delivery service. These questions have to be answered in a cross border context between member states that have heterogeneous systems as well as legal frameworks in place. SPOCS will make use of the results achieved by its "sister projects" STORK and PEPPOL in relation to mutual recognition for the use of electronic identity, documents and signatures. Simon Leutner, University Hospital of Munich
Dr. Walter Swoboda, University Hospital of Munich
At the Hospital of the University of Munich many different systems are used for sampling, storing, and processing data for clinical and administrative purposes. Hence several identity databases are existing, i.e. an SAP HR database for personnel management, Microsoft AD for user-registration on clients, a special SAP database for eprocurement, and some others. Now a new area-wide hospital information system (HIS, Siemens i.s.h.med) makes particular demands, because it handles with medical data which are directly used for treatment of patients. Therefore the HIS, its devices, and its network can be seen as a combined medical-engineering device with very high requirements on data security and data privacy by law (see DIN EN 80001). As a specific challenge the HIS handles not only with the identity of the actual user, but also with the identity of a “responsible person”, normally a high qualified physician who can order x-rays and invasive examinations. In many cases the “responsible person” is identical to the user, but not on cases like preparing clinical orders by medical assistants (i.e. order for x-ray examination). Because of limited personal resources in clinical daily routine users will not accept frequent re-registering: single-sign-on is highly recommended. We need one single system for authorization on many systems with very high safety requirements. Method. Lessions learned |
|
| 16:00-16:30 |
Coffee Break, Expo Area |
|
| 16:30-17:30 |
From Creative Chaos to Modern Service Provisioning Dr. Nicola Stein, German Aerospace Center
The presentation describes the developement of the identity management processes in the German Aerospace Center (DLR) within the last 5 years. It will in particular deal with the organisational aspects and present the individual solution of DLR:
Rudolf Gisler, Migros
Dr. Peter Schill, SafeNet
Migros, Switzerland's leading retailer and one of the top retailing groups in Europe successfully implemented a comprehensive security solution, that went far beyond the initial need for a solution intended to simplify logon procedures. Together with SafeNet, Migros was able to streamline employee logon and access to multiple corporate applications and portals. While Migros’ strategic goal was to create a comprehensive security access solution that would increase employee productivity and security, user acceptance, ease-of-use and convenience were also critical factors in assessing a potential solution. By now, users need only a single SafeNet smart card to carry out multiple functions: single logon to multiple applications, secure remote access, corporate ID badge, building access to name just a few. |
|
| 17:30-18:00 |
Identity in the Cloud – Finding Calm in the Storm André Durand, Ping Identity
|
|
| 18:00-18:30 |
Follow the Money: How Cloud Providers' Business Needs Drive Enterprise Identity & Security Dale Olds, Novell
Cloud computing has enabled new business models, and these business models, not cloud computing directly, are driving an upheaval in identity and security needs into the enterprise. A handful of new and old technologies have combined to produce cloud computing, which has enabled a seismic shift in the business models of services and applications. This shift in turn is driving new security and identity needs back to the enterprise. It is imperative that enterprises understand how hosters, MSPs, Iaas/PaaS vendors, and SaaS providers make their money -- and how this works with or against enterprise security needs. In this session we will identify types of cloud-based services, the monetary incentives for the service providers, and the resulting impacts on the enterprise security. We will detail steps enterprises can take to maximize effective identity and security policies in cloud services, as well as what to look for in service providers. We will also look at it from the perspective of the service provider -- how they can maximize their value and the loyalty of their enterprise customers. |
|
| 18:30-19:00 |
An Information Society Perspective on Electronic Identity Management Dr. Dirk van Rooy, European Commission, DG Information Society and Media
With the proliferation of networked electronic communication came daunting capabilities to collect, process, combine and store data, resulting in hitherto unseen transformational pressures on trust, security and privacy as we know it. The burgeoning development of the Information Society, particularly during the past fifteen years, transcended the societal readiness to respond to the transformational change evoked by ICT. The Future Internet will bring about a world that combines physical and digital elements. Technologies for pattern analysis and superpositioning, data linking, mining and collection will unleash unseen capabilities of access to personal data in a wide sense, and provide mechanisms for undesired privacy intrusion. In this context, the creation and management of identity related data and means to control their long-term use have emerged as some of the central challenges of digital life. In order to preserve trust in digital life, the European Commission recognizes that appropriate measures need to combine technology development with legal means, with user awareness and tools that support data controllers to comply with law in an accountable and transparent manner and that empower users with a controlling stake in managing their identity data. Activities are underway at many levels. European RTD programmes play their role in supporting research in trustworthy ICT, electronic identity management technologies, privacy-by-design in service layers as well as in networks, enabling technologies such as cryptography, and in generalized frameworks for trust and privacy-protective identity management. |
|
| 19:00-22:00 |
European Identity Awards Ceremony & Buffet Dinner |
|

