<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.ca.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Management : Kantara Initiative</title><link>http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx</link><description>Tags: Kantara Initiative</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Thank you CNN for some Pre-RSA PR</title><link>http://community.ca.com/blogs/iam/archive/2012/02/16/thank-you-cnn-for-some-pre-rsa-pr.aspx</link><pubDate>Thu, 16 Feb 2012 16:11:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:8574</guid><dc:creator>Merritt Maxim</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/iam/archive/2012/02/16/thank-you-cnn-for-some-pre-rsa-pr.aspx#comments</comments><description>&lt;p&gt;CNN published an &lt;a href="http://www.cnn.com/2012/02/15/tech/web/government-online-id/index.html?hpt=hp_t2" target="_blank"&gt;article&lt;/a&gt; yesterday, &amp;quot;&lt;a href="http://www.cnn.com/2012/02/15/tech/web/government-online-id/index.html?hpt=hp_t2" target="_blank"&gt;Will a standardized system for verifying Web identity ever catch on?&lt;/a&gt;&amp;quot;&amp;nbsp; I highly recommend this article, if only because it describes the web identity challenge in simple terms without resorting to the usual acronym soup and jargon that often dominates these discussions (present company included).&lt;/p&gt;
&lt;p&gt;Articles like this appearing in mainstream sites such as CNN are evidence that the internet identity problem is real and not theoretical.&amp;nbsp; While discussions on internet identity generally focus on the problems it poses for end-users, the identity problem is equally concerning for any web property that provides identity or consumes identities.&amp;nbsp; The internet identity problem can lead to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Poor user experience (leading to customer defection/attrition)&lt;/li&gt;
&lt;li&gt;High management costs (for providers) and &lt;/li&gt;
&lt;li&gt;Increased risk.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/iam/Flickr%20pro%20ID%20badge%202-16%20sec%20mgt%20blog.jpg"&gt;&lt;img style="WIDTH:154px;HEIGHT:272px;" border="0" hspace="2" align="left" src="http://community.ca.com/blogs/iam/Flickr%20pro%20ID%20badge%202-16%20sec%20mgt%20blog.jpg" width="154" height="250" alt="" /&gt;&lt;/a&gt;While there seems to be universal agreement that internet identity is a problem, solutions have been slow to develop.&amp;nbsp; Fortunately, we have seen some progress over the last 18 months with the emergence of trust frameworks.&amp;nbsp; Simply put, trust frameworks are an entire ecosystem for managing identities.&amp;nbsp; A good analogy is the existing credit card processing networks.&amp;nbsp; Yes, these networks are closed, but there are clear definitions of roles and responsibilities among all members and most importantly, of the liability exposure for each involved party.&amp;nbsp; As a result, most consumers do not even think twice when pulling out the plastic to pay for groceries, gas or anything else.&lt;/p&gt;
&lt;p&gt;We need the equivalent for the online world.&amp;nbsp; The emergence of trust frameworks such as &lt;a href="http://kantarainitiative.org/" target="_blank"&gt;Kantara&lt;/a&gt;, &lt;a href="http://openidentityexchange.org/" target="_blank"&gt;OIX&lt;/a&gt; and &lt;a href="http://www.nist.gov/nstic/" target="_blank"&gt;NSTIC&lt;/a&gt; are all very positive steps.&amp;nbsp; While the author of this article correctly points out some of the limitations and issues impeding progress of these initiatives, the existence of these initiatives is proof that there is considerable interest in finding a solution to this problem.&amp;nbsp; Multiple frameworks can and will co-exist as they offer different capabilities.&amp;nbsp; Some initial deployments in the US government have identified considerable cost savings from standardizing identity interactions in a trust framework.&lt;/p&gt;
&lt;p&gt;And now for the shameless plug:&amp;nbsp; I will be speaking on this very topic at the &lt;a href="https://ae.rsaconference.com/US12/scheduler/eventcatalog/eventCatalog.do" target="_blank"&gt;RSA Conference&lt;/a&gt; in San Francisco on Wednesday February 29, 2012 at 9:30 PST in room 304.&amp;nbsp; If you are attending RSA, I invite you to join and learn more about trust frameworks, the benefits they provide and what individual organizations can do to best take advantage of these frameworks. &amp;nbsp;If you will not be attending RSA, please chime in on the comments section and let&amp;#39;s take this discussion online. &lt;/p&gt;
&lt;p&gt;&lt;a title="_GoBack" name="_GoBack"&gt;&lt;/a&gt;&lt;i&gt;&lt;a href="http://www.flickr.com/photos/larimdame/4239385/" target="_blank"&gt;Flickr ID&lt;/a&gt; image used under Creative Commons License courtesy of &lt;a href="http://www.flickr.com/photos/larimdame/" target="_blank"&gt;LarimdaME&lt;/a&gt;.&lt;/i&gt;&lt;/p&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=8574" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/Federal/default.aspx">Federal</category><category domain="http://community.ca.com/blogs/iam/archive/tags/IAM+Trends/default.aspx">IAM Trends</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Identity+Management/default.aspx">Identity Management</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Internet/default.aspx">Internet</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx">Kantara Initiative</category><category domain="http://community.ca.com/blogs/iam/archive/tags/NSTIC/default.aspx">NSTIC</category><category domain="http://community.ca.com/blogs/iam/archive/tags/OIX/default.aspx">OIX</category><category domain="http://community.ca.com/blogs/iam/archive/tags/RSA+Conference/default.aspx">RSA Conference</category></item><item><title>Catalyst 2010 in Prague</title><link>http://community.ca.com/blogs/iam/archive/2010/06/30/catalyst-2010-in-prague.aspx</link><pubDate>Wed, 30 Jun 2010 12:42:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:5537</guid><dc:creator>Matthew Gardiner</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/iam/archive/2010/06/30/catalyst-2010-in-prague.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://community.ca.com/blogs/iam/Avatar%20at%20Catalyst_3281.jpg"&gt;&lt;/a&gt;I recently returned from Burton Catalyst 2010 in Prague where I did what you are supposed to do at such conferences - present, listen, and socialize.&amp;nbsp; &amp;nbsp;As part of the first full day of the conference, where identity was the central theme of one of the three tracks, I sat on a panel on Identity Assurance &lt;a class="" href="http://kantarainitiative.org/wordpress/2010/05/kantara-initiative-announces-identity-assurance-framework-2-0/" target="_blank"&gt;Frameworks&lt;/a&gt; (IAFs) with Bob Blakely of Burton and Tony Nadalin of Microsoft.&amp;nbsp; I was there representing &lt;a class="" href="http://kantarainitiative.org/index.php" target="_blank"&gt;Kantara Initiative&amp;#39;s&lt;/a&gt; IAF.&amp;nbsp; The takeaway for me is that assurance frameworks are necessary for identity federations to be set up and operated amongst more loosely coupled organizations and inevitable with the rise of cloud computing and its inherently hyper-distributed approach to computing.&amp;nbsp; The next six to nine months will be critical to see if the IAF snowball continues to pick up speed. &lt;/p&gt;
&lt;p&gt;I listened to a lot of sessions both within and outside the identity track.&amp;nbsp; I was thoroughly informed and entertained as usual by Kim Cameron of Microsoft and Bob Blakely and Ian Glazer of Burton and somewhat befuddled by content in the SOA track.&amp;nbsp; SOA seems to continue to suffer from too much theory and not enough practice.&amp;nbsp; Hasn&amp;#39;t that been part of the problem for the last 10 years?&amp;nbsp; Finally on the socialize front, CA put together a great (I had nothing to do with it) hospitality suite on the theme of Avatar.&amp;nbsp; The décor, food, and &lt;a class="" href="http://www.fotostyle.cz/avatar/" target="_blank"&gt;ambiance&lt;/a&gt; were really well done and the room was packed all night.&amp;nbsp; I plan to be at &lt;a class="" href="http://www.catalyst.burtongroup.com/NA10/index.html" target="_blank"&gt;Catalyst 2010 in San Diego&lt;/a&gt; doing another round of presenting, listening, and socializing.&amp;nbsp; Please join me if you can.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://community.ca.com/blogs/iam/Avatar%20at%20Catalyst_3281.jpg"&gt;&lt;img style="WIDTH:966px;HEIGHT:632px;" height="662" src="http://community.ca.com/blogs/iam/Avatar%20at%20Catalyst_3281.jpg" width="1007" border="0" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=5537" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/Identity+Assurance+Framework/default.aspx">Identity Assurance Framework</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx">Kantara Initiative</category></item><item><title>Kantara Initiative One Year Later (Almost)</title><link>http://community.ca.com/blogs/iam/archive/2010/02/22/kantara-initiative-one-year-later-almost.aspx</link><pubDate>Tue, 23 Feb 2010 01:45:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:4460</guid><dc:creator>Matthew Gardiner</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/iam/archive/2010/02/22/kantara-initiative-one-year-later-almost.aspx#comments</comments><description>&lt;p&gt;At this year&amp;#39;s RSA 2010 Conference the &lt;a class="" href="http://kantarainitiative.org/" target="_blank"&gt;Kantara Initiative&lt;/a&gt; is celebrating its first birthday with a day-long workshop entitled &lt;a class="" href="http://kantarainitiative.org/confluence/display/GI/Kantara+Initiative+Workshops" target="_blank"&gt;&lt;b&gt;Technology, Policy, and Compliance for Identity Services in 2010 &amp;amp; Beyond&lt;/b&gt;&lt;/a&gt;&lt;b&gt;.&amp;nbsp; &lt;/b&gt;It was just a year ago at the RSA Conference 2009 that a number of organizations publicly announced their intention to found this identity focused industry consortium.&amp;nbsp; Soon after, in June of 2009, the Kantara Initiative was officially born.&amp;nbsp; This prompted my first &lt;a class="" href="http://community.ca.com/blogs/iam/archive/2009/06/17/why-ca-supports-the-kantara-initiative.aspx" target="_blank"&gt;blog&lt;/a&gt; about the organization.&lt;/p&gt;
&lt;p&gt;In many ways this workshop shows both the progress of and the need for Kantara.&amp;nbsp; As the identity industry has matured and broadened so must the collaboration around the issues of technology, policy, privacy, and compliance.&amp;nbsp; No longer is identity an exclusively large enterprise issue.&amp;nbsp; Like with other technologies, what is for the consumer and what is for the enterprise are blurring and colliding.&amp;nbsp; Just look at the participating organizations for the workshop, in addition to identity and security vendor mainstays such as CA and Oracle, you have well known organizations that at first blush might not be considered identity-centric organizations, such as PayPal, NTT, Google, NIH and others.&amp;nbsp; This workshop really represents a microcosm of the broader identity marketplace - all in one convenient room at the Moscone Center.&lt;/p&gt;
&lt;p&gt;In my session, Identity as Security Glue for the Cloud, I will be presenting with Chris Sharp of MEDecision.&amp;nbsp; Without tipping my hand too much, I plan to review the models of cloud computing (SaaS, PaaS, IaaS) and how categories of identity and access management and related standards play a central role in how security must be managed both for and in the cloud.&amp;nbsp; As a live example, Chris will discuss his healthcare related service and how he is using standards-based identity services to keep operations running smoothly.&lt;/p&gt;
&lt;p&gt;If you are coming to the RSA Conference I encourage you to &lt;a class="" href="http://www.rsaconference.com/2010/usa/agenda-and-sessions/monday-seminars.htm" target="_blank"&gt;register&lt;/a&gt; for this Kantara workshop and take part in the celebration.&lt;/p&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=4460" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx">Kantara Initiative</category><category domain="http://community.ca.com/blogs/iam/archive/tags/RSA+Conference/default.aspx">RSA Conference</category></item><item><title>Should Cloud Providers Be Security Black Boxes?</title><link>http://community.ca.com/blogs/iam/archive/2010/01/22/should-cloud-providers-be-security-black-boxes.aspx</link><pubDate>Fri, 22 Jan 2010 22:10:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:4249</guid><dc:creator>Matthew Gardiner</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/iam/archive/2010/01/22/should-cloud-providers-be-security-black-boxes.aspx#comments</comments><description>&lt;p&gt;Reading about Microsoft General Counsel Brad Smith&amp;#39;s recent &lt;a class="" href="http://www.cio.com/article/520063/Microsoft_Calls_for_Cloud_Computing_Transparency" target="_blank"&gt;speech&lt;/a&gt; at the Brookings Institution got me thinking about the issue of security and privacy related transparency at Cloud providers.&amp;nbsp; I fully agree with his statement that &amp;quot;... it should not be enough for service providers simply to say that their services are private and secure....there needs to be some transparency about why this is the case.&amp;quot;&amp;nbsp; However, a key word here is &amp;quot;some.&amp;quot;&amp;nbsp; There has to be a balance, but it shouldn&amp;#39;t be achieved through legislation. That process would be so slow and would only further murk-up the balancing process.&amp;nbsp; Security and privacy professionals don&amp;#39;t agree on how much security is enough, so we certainly can&amp;#39;t expect legislators to do a good job of it.&amp;nbsp; There are plenty of areas that should keep the law-makers busy, such as modernizing existing laws that never contemplated the Internet and Cloud models, as well as sorting out conflicting international laws (where you must do something in one jurisdiction, but doing so puts you in violation in another jurisdiction).&lt;/p&gt;
&lt;p&gt;How do we find the balance?&amp;nbsp; It should stay with the open market and be further matured through industry codes of conduct and certifications.&amp;nbsp; Security and privacy should be a feature of the various Cloud service offerings, and organizations such as the &lt;a class="" href="http://www.cloudsecurityalliance.org/" target="_blank"&gt;Cloud Security Alliance&lt;/a&gt; and the &lt;a class="" href="http://kantarainitiative.org/" target="_blank"&gt;Kantara Initiative&lt;/a&gt; are working to help Cloud providers find the balance.&lt;/p&gt;
&lt;p&gt;I find it helpful to compare what is going on now - in this context of the Cloud - with what we experienced in past years in traditional enterprise IT.&amp;nbsp; If we look at how enterprises &amp;quot;managed and secured&amp;quot; their sensitive data and applications of the years, I think overall we can say it was very messy with breaches and spills seemingly around every corner. Only over the past few years have we witnessed more effective control.&amp;nbsp; Over-simplified, enterprises did a relatively poor job of IT security because it was allowed (or forced) to operate as a black box, with non-IT management either not understanding or not caring enough to know what was going on with sensitive applications and data.&amp;nbsp; This let the security/privacy investment balance go out of balance for too long.&lt;/p&gt;
&lt;p&gt;I would like to say that I see an aggressive and proactive position on security and privacy from the Cloud providers, but I don&amp;#39;t.&amp;nbsp; There is this unfortunate tendency toward the security black-box again, which when done to extremes is unhealthy.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Buyers of Cloud services, let your money do the talking.&amp;nbsp; Demand effective security and privacy and be willing to pay for it.&amp;nbsp; And don&amp;#39;t accept security and privacy as a pure promise, as Brad Smith points out.&lt;/p&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=4249" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/Cloud+Security/default.aspx">Cloud Security</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Cloud+Security+Alliance/default.aspx">Cloud Security Alliance</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx">Kantara Initiative</category></item><item><title>Report from ISSE 2009 &amp; Thoughts on Emerging IT Clouds</title><link>http://community.ca.com/blogs/iam/archive/2009/10/26/report-from-isse-2009-amp-thoughts-on-emerging-it-clouds.aspx</link><pubDate>Mon, 26 Oct 2009 19:06:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:3236</guid><dc:creator>Matthew Gardiner</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/iam/archive/2009/10/26/report-from-isse-2009-amp-thoughts-on-emerging-it-clouds.aspx#comments</comments><description>&lt;p class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;font face="Calibri" size="3"&gt;I recently returned from attending and presenting at the &lt;/font&gt;&lt;a class="" href="http://www.isse.eu.com/" target="_blank"&gt;&lt;font face="Calibri" size="3"&gt;ISSE 2009&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; conference in The Hague, Netherlands.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;I particularly like this annual security conference in part because it brings together European security professionals from a very broad set of communities, covering governments, academic institutions, and industry – which is very healthy.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;At this conference you get the European view of things in a few days – and you cover a very comprehensive set of topics, from cryptology to security awareness of children, and everything in between.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;font face="Calibri" size="3"&gt;I specifically presented on two topics, the &lt;/font&gt;&lt;a class="" href="http://www.kantarainitiative.org/" target="_blank"&gt;&lt;font face="Calibri" size="3"&gt;Kantara Initiative&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; and its &lt;/font&gt;&lt;a class="" href="http://kantarainitiative.org/confluence/display/certification/Identity+Assurance+Certification+Program" target="_blank"&gt;&lt;font face="Calibri" size="3"&gt;Identity Assurance Framework&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; (IAF) as well as best practices for security for services.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;For the Kantara Initiative I focused on the purpose of the organization and the IAF in particular to drum up more collaboration between them and relevant people and programs in Europe, such as &lt;/font&gt;&lt;a class="" target="_blank"&gt;&lt;font face="Calibri" size="3"&gt;STORK&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;font face="Calibri" size="3"&gt;As an attendee of the conference I particularly enjoyed two of its sessions on cloud security.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;With the cloud in its nuclear, over-hyped, breathless stage it is really nice to hear from two seasoned professionals with a more balanced and reasoned perspective.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;So kudos from me to Gerry Gebel of the &lt;/font&gt;&lt;a class="" href="http://www.burtongroup.com/" target="_blank"&gt;&lt;font face="Calibri" size="3"&gt;Burton Group&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; and Rick Gordon of the &lt;/font&gt;&lt;a class="" href="http://www.civitasgroup.com/default.htm" target="_blank"&gt;&lt;font face="Calibri" size="3"&gt;Civitas Group&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; for offering up their balanced thinking on cloud security.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;Some interesting points I jotted down from their sessions:&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;"&gt;&lt;span style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;There are clearly some valid economic reasons pushing organizations to start cloud-ifying their IT operations, such as greater specialization, economies of scale, increased flexibility and agility&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="MARGIN:0in 0in 0pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;"&gt;&lt;span style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;But there are also significant security and privacy issues that mitigate these potential advantages, such as greater vulnerability to DNS attacks; lack of transparency of people, process, and technologies; lack of control over data management; and many other issues&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="MARGIN:0in 0in 10pt 0.5in;TEXT-INDENT:-0.25in;mso-list:l0 level1 lfo1;"&gt;&lt;span style="FONT-FAMILY:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore;"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="FONT:7pt &amp;#39;Times New Roman&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri" size="3"&gt;Different layers of the IT stack, from hardware to applications and everything in between, have very different dynamics and thus need to be considered separately.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;font face="Calibri" size="3"&gt;Gerry’s takeaway was “Enterprises should &lt;u&gt;not&lt;/u&gt; use public clouds for sensitive data” and should lean toward building private or internal clouds, which can gain much of the economic benefits of clouds without being impacted as significantly by the tricky security and privacy issues of going public.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;I agree with this assessment and would add - you can’t outsource something externally until you can abstract (outsource) that IT function internally for your enterprise.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;So use the step of a private IT cloud get some benefits in the short and intermediate term and prepare your organization to leverage public services when they become available and your organization becomes ready.&lt;/font&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="MARGIN:0in 0in 10pt;"&gt;&lt;font face="Calibri" size="3"&gt;After the ISSE 2009 conference I also presented at the Edge User Conference in Amsterdam on Security for Services.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;My next blog will cover my takeaways from that event.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://community.ca.com/aggbug.aspx?PostID=3236" width="1" height="1"&gt;</description><category domain="http://community.ca.com/blogs/iam/archive/tags/Cloud+Security/default.aspx">Cloud Security</category><category domain="http://community.ca.com/blogs/iam/archive/tags/IAM+Trends/default.aspx">IAM Trends</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Identity+Assurance+Framework/default.aspx">Identity Assurance Framework</category><category domain="http://community.ca.com/blogs/iam/archive/tags/ISSE+2009/default.aspx">ISSE 2009</category><category domain="http://community.ca.com/blogs/iam/archive/tags/Kantara+Initiative/default.aspx">Kantara Initiative</category></item></channel></rss>