Information

Date:
17.04. - 20.04.2012
Location:
Munich, Germany
Registration fee:
€1695.00
Contact person:

Mr. Levent Kara
+49 211 23707710
lk@kuppingercole.com





Identity & Access Management

If you are responsible for IAM in your company, if you manage IAM related projects or if you are an IT architect or otherwise involved in IAM projects, this is the track to not miss. Learn about the newest trends from KuppingerCole analyst and Industry Expert thought leadership, learn about best practices, and get the information you need to successfully run your projects around all areas of IAM.

Moderation:

Wednesday, 18.04.2012
08:00-18:00 Check-in & Registration
08:30-09:00 tba
Prof. Dr. Eberhard von Faber, T-Systems
09:00-09:30 Securing Critical Banking Infrastructures in the Age of Cyber Warfare
Dr. Waldemar Grudzien, Association of German Banks
09:30-10:00 tba
Berthold Kerl, Deutsche Bank AG
10:00-10:30 Coffee Break, Expo Area
Craig Burton What to Focus on for Future-Proof IAM
Moderator:
Craig Burton, KuppingerCole
10:30-11:30 The Business Value of IT
Increase Value to the Business: The KuppingerCole IT Model
Martin Kuppinger, KuppingerCole
How IAM can Catalyze the Secure Enterprise
Craig Burton, KuppingerCole
Gerry Gebel, Axiomatics Americas
Martin Kuppinger, KuppingerCole
Mike Neuenschwander, Oracle

IAM (Identity & Access Management) is one of the cornerstones of Information Security. Thinking in identities and putting the security of information and the access to information in the center of attention is the foundation for improving information security. Moving away from device-centric and network-centric security to information-centric security allows to better understand information risks and the required actions to mitigate these risks and better secure your enterprise. Leading industry experts, all with an analyst background, and KuppingerCole analysts discuss the role IAM plays for information security and the future of IT Security in general in this panel.

11:30-12:30 The Future IT Organization
Winds of Change in your IT Organization: Get ready for the Future
Craig Burton, KuppingerCole
Martin Kuppinger, KuppingerCole
12:30-14:00 Lunch Break, Expo Area
Fulup Ar Foll IAM Architecture
Moderator:
Fulup Ar Foll, KuppingerCole
14:00-15:00 Identity Federation
Identity Federation Challenges and how to approach them
Thomas Gundel, IT Crew
Patrick Harding, Ping Identity
Colin Wallis, New Zealand Government

In recent times where the term "federation" is slipped into the conversation as if it were a straight forward hassle free process, there lurks a multitude of technical challenges. Chief amongst those are the "session state" issues of SLO and idle time-out. This panel session will unpick the problem and touch on various approaches being used to solve it, manage it, or avoid it.

Best Practice in Out-sourced Federation: WAYF
David Simonsen, WAYF
15:00-16:00 Privileged Access
Best Practice: Managing Privileged Users
PCI-DSS, SOX, Basel: How to Manage Privileged Access and Pass the Audit
Udi Mokady, Cyber-Ark

Privileged accounts like root, sysadmin or Oracle system, are necessary to run and manage databases, middleware and operating systems. These accounts obviously are very powerfull as they allow access to any type of business information. So if somebody would want to severely damage your business for whatever reason, attacks targeting these privileged accounts would be the way to do it.

This leads us to the question: would you at least find out if a privileged account is being misused? In other words: Do you actually know, who is using such accounts and wether this usage is necessary and allowed? If this is a question you are asking yourself from time to time - the auditor would dive much deeper and and also ask, what exactly root had been doing during a certain session. Considering, that according to the Ponemon Institute 2012 Cybercrime Survey, 62% of respondents reported malicious insider breaches, we can assume that the auditor´s questions are reasonable and it would be good to have an answer

In this panel discussion, we will look into the reliability of currently available solutions and talk about the different approaches to reach compliance with PCI-DSS, SOX, Basel and comparable regulations.

16:00-17:00 Coffee & Networking, Expo Area
17:00-18:00 Directories
Single Point of Access: The IAM Strategy at Teleflex
Nick Sabinske, Teleflex

Working across six continents, Teleflex provides medical devices used in critical care and surgeries across the globe. Their products help protect patients from infections and enables surgeons to do safer, less invasive procedures ranging from vascular access, anesthesia and airway management among many others.

Teleflex Incorporated (www.teleflex.com) has a core identity management strategy: one point of access. Beginning as just a temporary fix to decommission the company's Sun LDAP directory, Teleflex began their use of a virtual directory. The virtual directory allowed the company to link all of their separate directory information into one enterprise directory. Using directory virtualization, Teleflex was able to eliminate custom scripting, serving up employee data from SQL databases to the receiving applications without scheduling synchronization tasks.

The enterprise directory has now become a significant part of Teleflex's identity management strategy to improve facilitation of acquisitions, eliminate custom scripting to obtain employee data from Teleflex's HR Vista system and to unify and simplify both application access and the end user experience.

One Identity Service, Many Initiatives: Exploring Use Cases for Identity Virtualization
Fulup Ar Foll, KuppingerCole
Nick Sabinske, Teleflex
Ulrich Schulz, Radiant Logic

Modern identity infrastructures are a tangled web of identity sources, protocols, and varies security means. This panel discussion will focus on the challenges around unifying a disparate identity infrastructure for identity management and federation initiatives. The panel will explore how an identity service, enabled by virtualization, can be used to tackle many kinds of identity management challenges, and facilitate the addition of new identity stores and populations. Nick Sabinske’s experience at Teleflex will serve as a catalyst for the panel discussion, while Ulrich Schulz of Radiant Logic will extend the discussion with other real-life deployments, and Fulup ar Foll from KuppingerCole will provide an objective, third party view of the industry.

Some of the points to discuss:

  • Integrating identities stored in Active Directory with the rest of the identity infrastructure, including multiple directories, databases, and web-based applications
  • Why a single access point is an essential starting point for many identity management and federation initiatives
  • When to choose an on-premise identity management solution compared to a hosted solution
  • Achieving single sign on across disparate identity sources and federated systems
  • Improving user experience by minimizing credentials and providing uniformity
18:00-18:20 tba
André Durand, Ping Identity
18:20-18:40
18:40-21:00 European Identity Awards Ceremony & Buffet Dinner

Thursday, 19.04.2012
08:00-18:00 Check-in & Registration
08:30-09:00 How Identity Management and Access Governance as a Service make your Cloud Work and your Business more Agile
Ralf Knöringer, Atos IT Solutions and Services GmbH

Identity and access management has evolved from the needs of large organizations and international operating enterprises. Automated user and entitlement management enabled the IT organizations to reduce costs and increase efficiency.

Today, legal and regulatory compliance dominates the deployment of identity and access management solutions. The level of control therefore follows the risk exposure and the transparent risk taking of the business owners. Identity and access governance with comprehensive analysis and reporting functionalities ensure transparency of rights, roles and entitlements.

Customers demand modular and service-oriented offerings managing identity and access for on-premise environments and cloud infrastructures.

Enterprise customers and service providers benefit from perimeter-less security services like cloud SSO and entitlement services for mixed environments (on-premise, private, public and hybrid cloud). This key note will present a look on existing and future scenarios.

09:00-09:30 tba
Prof. Dr. Kai Rannenberg, Goethe University in Frankfurt
09:30-10:00 Trust and Complexity in Digital Space
Dr. Jacques Bus, Digital Enlightenment Forum

The concepts of trust and security are deeply embedded in our society and are therefore strongly affected by the societal transformation caused by the digitization. Societal and technical change is strongly influenced by the growing complexity of society related to the emergence of easy worldwide communication, the Web and mass data collection. In this paper I discuss security and trust as fundamental drivers for self-organizing communities in our society. I highlight the concepts of trustworthy technology and trust in the societal context, as well as the difference between accepting technology and trusting technology. An important observation is that a complex system cannot be fully understood through reductionism. The discussion leads to some cautious conclusions on future actions.

10:00-10:30 Coffee & Networking, Expo Area
Dr. Horst Walther IAM Architecture
Moderator:
Dr. Horst Walther, Kuppinger Cole
10:30-11:30 Re-engineering IAM
Re-engineering IAM to better serve your Business Needs
Martin Kuppinger, KuppingerCole

Identity and Access Management like most of the organizations have implemented is on change. Provisioning as the core element in former days still plays some role, but with Access Governance becoming established, new concepts like Access Intelligence (in its still somewhat undefined form), integration to SIEM, re-thinking of established IT concepts like Message Queueing for the role they can play in Identity and Access Management and many other influencing factors, Identity and Access Management has to be re-thought where it is still established. The art of re-engineering is the balance between an advanced solution and architecture on one hand and the protection of investments. How can you leverage what you have towards a more mature, more flexible, more future-proof, business-focused solution? What will you need in the future and what does it need ot go there? And what about dealing with new groups of users like your customers and trends like BYOD (bring your own device)? And how about the changing requirements around privacy and information security?

KuppingerCole strongly believes that it is time to re-engineer Identity and Access Management and to rethink the established approaches. Martin Kuppinger will present the future view of Identity and Access Management and explains how to best re-engineer it.

Building Identity & Access Management as a Public Administration Service for the Trento Autonomous Province
Fabrizio Russo, Trento Autonomous Province
11:30-12:30 Authentication
Case Study: Large Scale Authentication, Australian Government
Trish Porter, Australian Department of Innovation, Industry, Science and Research
Malcolm Young, Australian Department of Innovation, Industry, Science and Research

VANguard is a suite of authentication and security services provided by the Department of Innovation, Industry, Science and Research on behalf of the Australian Government. VANguard’s services include a browser based single sign on service, a security token service a signature verification service and a timestamping service. These services are available to all three tiers of government within Australia and cater specifically to business to government and government to government transactions. VANguard brokers a range of credentials and is built upon broadly supported standards. Over the past twelve months, VANguard has processed over thirty million transactions.

This case study will begin by examining the history of VANguard including the policy decisions leading to its creation, the challenges inherent in providing a whole of government solution and the progression from concept to implementation. The second part of the case study will focus on the technical and physical implementation of the services and the lessons learned as the project has developed.

12:30-14:00 Lunch Break, Expo Area
Dr. Horst Walther IAM Architecture
Moderator:
Dr. Horst Walther, Kuppinger Cole
14:00-15:00 Security Intelligence
Best Practices for Lean, Efficient and Focused Information Security Projects
Dr. Horst Walther, Kuppinger Cole
Identity and Security Intelligence
Kim Cameron, Microsoft
Matthew Gardiner, RSA
Robert Griffin, RSA, the Security Division of EMC

Security is now as much a question of visibility as it is of controls. Enterprises need to be able to see what’s happening throughout their physical and virtual environments, including both in house and in the cloud. This session discusses the role of identity management in security intelligence, including the kinds of information that enterprises need to collect, the kind of analysis that needs to be performed and the ways that the resulting security intelligence can be applied in making effective security decisions.

15:00-16:00 Access & Entitlements
Introducing an Entitlement Managment System - a Travel Report
Manuel Schneider, Generali Deutschland Informatik Services
Access & Entitlements
Gerry Gebel, Axiomatics Americas
Manuel Schneider, Generali Deutschland Informatik Services
Marco Venuti, CrossIdeas
16:00-16:30 Coffee & Networking, Expo Area
16:30-17:30 IAM Open Source Software
Identity Management & Open Source
Michael Kleinhenz, tarent AG
17:30-18:00 Closing Keynote

« Return to the full agenda

© 2012 Kuppinger Cole