PRWeb The Leader Press Release Distribution
See How PRWeb Works

We're here to help 1-866-640-6397

Login Create Free Account


All Press Releases for June 18, 2008 Subscribe to this News Feed    
 

SailPoint Calls for Industry Collaboration on Role Interoperability

Identity Risk Management Leader Jumpstarts Industry Initiative to Standardize Role Exchange.

Austin, TX (PRWEB) June 18, 2008 -- SailPoint Technologies today issued an open call for the development of a new standard that addresses the need to integrate roles and role models between tools and systems. The goal of this initiative is to bring the identity management community together to define role interoperability standards that will solve difficult integration problems and simplify role-based governance across diverse identity infrastructures. An interactive forum has been created at www.openroleexchange.org to organize the industry effort and to facilitate the collaboration needed to define the model and foster adoption of the new standard.

In order to address the need for role-based governance today, organizations must invest significant time and money building and deploying custom integration between the various role models throughout the enterprise, including provisioning, entitlement management, network access control and business applications. The result is an expensive, brittle, and complex role model system that is difficult to deploy and hard to maintain. If a standard model for role exchange were available, organizations could avoid custom integration and immediately benefit from effective oversight and policy enforcement based on a centralized role management.

Mike Neuenschwander, general manager of Mycroft Inc.'s strategy practice, puts it this way: "Large organizations need to leverage roles across their vast, diverse, and complex IT infrastructures. But today, the concept of 'roles' is contextual and nuanced. Organizations grapple with applying policy to organizational roles, business roles, functional roles, IT provisioning roles, resource roles, etc. If roles are to be applicable at a broad scale and across business boundaries, some forum needs to take up the difficult discussion around role interoperability."

"Role interoperability is a pervasive issue for companies addressing identity governance," said Darran Rolls, SailPoint's CTO. "As an identity management community, I believe it's our responsibility to define a standardized operational exchange model for roles. This effort will reduce the need for custom integration and will lower the cost and complexity of deploying and maintaining integrated role-based systems." Rolls is a identity management standards veteran, having served as the chair of the OASIS Provisioning Services Technical Committee where he led a two-year industry effort to develop the Service Provisioning Markup Language (SPML) specification.

To foster collaboration around the call for role exchange standards, SailPoint is encouraging live debate at the Burton Catalyst Conference June 23-27 in San Diego, and will host an interactive webcast on July 16th. Companies and individuals interested in participating can go to www.openroleexchange.org, an open forum designed to facilitate an interactive dialogue. The forum also features technical information on the need for a role exchange standard, and will provide updates on the effort moving forward.

The Open Role Exchange seeks to provide a forum to discuss the requirements for role interoperability and to identify areas where new standardization is needed. In an open letter to the industry, Rolls suggests that the industry should begin by addressing five key requirements for role interoperability:

 
  • A Common Exchange Format to describe the role-based access control (RBAC) structure and control rules between systems;
  • Query and Exchange Operations so that structure, allocation and usage requests can flow between systems;
  • Change Control and Delegated Administration to determine how systems can extend or modify a shared model;
  • A Role Mapping and Resource Referencing scheme; and
  • A Common State Model for shared RBAC systems.

About SailPoint
SailPoint Technologies, Inc. (http://www.sailpoint.com) develops identity risk management software that helps organizations gain control over user access to critical systems and data, streamline costly IT compliance processes and reduce the risks of fraud, corporate data loss or theft and failed audits. Founded in December 2005, SailPoint is based in Austin, Texas.

###

Technorati Tags

Bookmark -  Del.icio.us | Furl It | Technorati | Ask | MyWeb | Propeller | Live Bookmarks | Newsvine | TailRank | Reddit | Slashdot | Digg | Stumbleupon | Google Bookmarks | Sphere | Blink It | Spurl


Other Releases by this Member
OPTIONS
Printer Friendly Version
Download PDF Version
Download Reader Version
BlogThis
ShareThis
CONTACT INFORMATION
Kari Hanson
SailPoint
978-373-4003
Email us Here
ATTACHED FILES

There are no multimedia files attached to this release. If this is your release, you may add images or other multimedia files through your PRWeb News Management Console.

ABOUT PRESS RELEASES
If you have any questions regarding information in these press releases please contact the company listed in the press release. Please do not contact PRWeb. We will be unable to assist you with your inquiry. PRWeb disclaims any content contained in these release. Our complete disclaimer appears here.
 
Close Move