<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Discovering Identity &#187; Identity</title>
	<atom:link href="http://www.discoveringidentity.com/tag/identity/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.discoveringidentity.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 16 Jul 2010 23:28:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>National Strategy for Trusted Identities in Cyberspace</title>
		<link>http://www.discoveringidentity.com/2010/07/15/national-strategy-for-trusted-identities-in-cyberspace/</link>
		<comments>http://www.discoveringidentity.com/2010/07/15/national-strategy-for-trusted-identities-in-cyberspace/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 15:52:00 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[Identity Ecosystem]]></category>
		<category><![CDATA[IdentityManagement]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/07/15/national-strategy-for-trusted-identities-in-cyberspace/</guid>
		<description><![CDATA[On June 25, 2010, the US Federal Government released a draft document entitled, “National Strategy for Trusted Identities in Cyberspace.” This document proposes a strategy that:
… defines and promotes an Identity Ecosystem that supports trusted online environments.&#160; The Identity Ecosystem is an online environment where individuals, organizations, services, and devices can trust each other because [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.dhs.gov/xlibrary/assets/ns_tic.pdf"><img style="border-right-width: 0px; margin: 5px 0px 5px 10px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" align="right" src="http://www.discoveringidentity.com/wp-content/uploads/2010/07/image10.png" width="220" height="148" /></a>On June 25, 2010, the US Federal Government released a draft document entitled, “<a href="http://www.dhs.gov/xlibrary/assets/ns_tic.pdf" target="_blank">National Strategy for Trusted Identities in Cyberspace</a>.” This document proposes a strategy that:</p>
<blockquote><p>… defines and promotes an Identity Ecosystem that supports trusted online environments.&#160; The Identity Ecosystem is an online environment where individuals, organizations, services, and devices can trust each other because authoritative sources establish and authenticate their digital identities.&#160; </p>
<p>The Identity Ecosystem enables:&#160; </p>
<ol>
<li><strong>Security</strong>, by making it more difficult for adversaries to compromise online transactions;&#160;&#160;&#160; </li>
<li><strong>Efficiency</strong> based on convenience for individuals who may choose to manage fewer passwords or accounts than they do today, and for the private sector, which stands to benefit from a reduction in paper-based and account management processes;&#160; </li>
<li><strong>Ease-of-use</strong> by automating identity solutions whenever possible and basing them on technology that is easy to operate with minimal training; </li>
<li><strong>Confidence</strong> that digital identities are adequately protected, thereby increasing the use of the Internet for various types of online transactions;&#160; </li>
<li><strong>Increased privacy</strong> for individuals, who rely on their data being handled responsibly and who are routinely informed about those who are collecting their data and the purposes for which it is being used; </li>
<li><strong>Greater choice</strong>, as identity credentials and devices are offered by providers using interoperable platforms; and&#160; Opportunities for innovation, as service providers develop or expand the services offered online, particularly those services that are inherently higher in risk; </li>
</ol>
</blockquote>
<p>The strategy proposes four primary goals and nine actions to implement and promote the Identity Ecosystem:</p>
<p><strong>Goals</strong></p>
<blockquote><ol>
<li>Develop a comprehensive Identity Ecosystem Framework </li>
<li>Build and implement an interoperable identity infrastructure aligned with the Identity Ecosystem Framework </li>
<li>Enhance confidence and willingness to participate in the Identity Ecosystem </li>
<li>Ensure the long-term success of the Identity Ecosystem </li>
</ol>
</blockquote>
<p><strong>Actions</strong></p>
<blockquote><ol>
<li>Designate a Federal Agency to Lead the Public/Private Sector Efforts Associated        <br />with Achieving the Goals of the Strategy </li>
<li>Develop a Shared, Comprehensive Public/Private Sector Implementation Plan </li>
<li>Accelerate the Expansion of Federal Services, Pilots, and Policies that Align with        <br />the Identity Ecosystem </li>
<li>Work Among the Public/Private Sectors to Implement Enhanced Privacy        <br />Protections </li>
<li>Coordinate the Development and Refinement of Risk Models and Interoperability Standards </li>
<li>Address the Liability Concerns of Service Providers and Individuals </li>
<li>Perform Outreach and Awareness Across all Stakeholders&#160; </li>
<li>Continue Collaborating in International Efforts&#160; </li>
<li>Identify Other Means to Drive Adoption of the Identity Ecosystem across the        <br />Nation </li>
</ol>
</blockquote>
<p>The Strategy Document doesn&#8217;t discuss any specific technologies, but rather, addresses the needs and general concepts required for a national Identity Ecosystem.</p>
<p>If you would like to make public comments on the strategy, a good place to visit is this <a href="http://www.nstic.ideascale.com/" target="_blank">IdeaScale page</a> hosted by the Department of Homeland Security. Reading comments from other parties on that page is quite interesting.</p>
<p>In other areas of Cyberspace, the reactions to this strategy are mixed.&#160; For example, an active proponent is my friend <a href="http://www.youtube.com/watch?v=ZuFGIw4bnBw">Dazza Greenwood</a>, who encourages everyone to become familiar with the strategy and actively give feedback:</p>
<p> <center><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/ZuFGIw4bnBw&amp;hl=en_US&amp;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/ZuFGIw4bnBw&amp;hl=en_US&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object></center>
<p>At the other end of the spectrum is a blogger, Arnold Vintner, whom I do not know, who shares a much more pessimistic view. In his post, “<a href="http://www.fortliberty.org/obama-administration-moves-to-reduce-online-privacy.html" target="_blank">Obama Administration Moves to Reduce Online Privacy</a>,” Mr. Vintner opines:</p>
<blockquote><p>The Obama administration is proposing a new <a href="http://www.tech-faq.com/identity-management.html">identity management</a> system for the Internet which is calls “Identity Ecosystem.” This new system will replace individually managed usernames and passwords with a taxpayer-funded federally-managed system.</p>
<p>The scheme is outlined in the <a href="http://www.dhs.gov/xlibrary/assets/ns_tic.pdf">National Strategy for Trusted Identities in Cyberspace</a>. The planned system will tie together <strong>all</strong> of your accounts into one national <strong>online</strong> identity.&#160; This will enable the federal government to easily track all online activity of every American.</p>
<p>The system will start with the federal government requiring the ID’s for use in accessing federal web sites — such as for filing your taxes online.&#160; The federal government will then force businesses to adopt the system, starting with banks and credit card companies and slowly spreading to encompass the entire online environment. Once fully implemented, Internet users will no longer be able to comment anonymously on blogs or web forums, because all online identities will be verified with the U.S. government.</p>
</blockquote>
<p>Where do you stand?&#160; I personally like the idea of public dialog on this issue and the call for public and private entities to participate in a solution.&#160; I look forward to giving feedback and tracking progress.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:45d6373a-5fe8-4496-bc68-55968fee483a" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>,<a href="http://technorati.com/tags/IdentityManagement" rel="tag">IdentityManagement</a>,<a href="http://technorati.com/tags/Privacy" rel="tag">Privacy</a>,<a href="http://technorati.com/tags/Identity+Ecosystem" rel="tag">Identity Ecosystem</a>,<a href="http://technorati.com/tags/Security" rel="tag">Security</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/07/15/national-strategy-for-trusted-identities-in-cyberspace/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Why face recognition isn&#8217;t scary &#8212; yet</title>
		<link>http://www.discoveringidentity.com/2010/07/13/why-face-recognition-isnt-scary-yet/</link>
		<comments>http://www.discoveringidentity.com/2010/07/13/why-face-recognition-isnt-scary-yet/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 04:52:47 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[Facial Recognition]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/07/13/why-face-recognition-isnt-scary-yet/</guid>
		<description><![CDATA[Thanks to Malisa Vincenti, leader of the LinkedIn Group Security &#38; Technology &#8211; Critical Infrastructure Network &#38; Forum, for highlighting the CNN article entitled “Why face recognition isn&#8217;t scary – yet.”
 
Much of the article was dedicated to describing the benefits and deficiencies of facial recognition software used by online services like Facebook, Picasa and [...]]]></description>
			<content:encoded><![CDATA[<p>Thanks to <a href="http://www.linkedin.com/in/malisavincenti" target="_blank">Malisa Vincenti</a>, leader of the LinkedIn Group <a href="http://www.linkedin.com/groups?home=&amp;gid=1824094&amp;trk=anet_ug_hm">Security &amp; Technology &#8211; Critical Infrastructure Network &amp; Forum</a>, for highlighting the CNN article entitled “<a href="http://www.cnn.com/2010/TECH/innovation/07/09/face.recognition.facebook/index.html" target="_blank">Why face recognition isn&#8217;t scary – yet</a>.”</p>
<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/07/image7.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.discoveringidentity.com/wp-content/uploads/2010/07/image_thumb4.png" width="564" height="319" /></a> </p>
<p>Much of the article was dedicated to describing the benefits and deficiencies of facial recognition software used by online services like Facebook, Picasa and iPhoto to make it easier for users to keep track of photographs.&#160; Speaking of such functionality,&#160; <a href="http://www.linkedin.com/pub/michael-a-sipe/2/621/927" target="_blank">Michael Sipe</a>, vice president of product development at <a href="http://www.pittpatt.com/" target="_blank">Pittsburgh Pattern Recognition</a>, a Carnegie Mellon University split-off company that makes face-recognizing software said these types of photo programs are a response to the hassles of keeping track of growing digital photo collections.</p>
<blockquote><p>&quot;In general, there&#8217;s this tsunami of visual information &#8212; images and video &#8212; and the tools that people have to make sense of all that information haven&#8217;t kept pace with the growth of the production of that information,&quot; he said. &quot;What we have is a tool to help extract meaning from that information by using the most important part of that media, which is people.&quot;</p>
</blockquote>
<p>It is interesting that one of the most distinguishing attribute of a person’s identity – his or her face – is so difficult for computers to recognize.&#160; We humans often say, “I can remember faces much better than names,” yet computers are just the opposite.&#160; It turns out that a person’s smile, which may be one of the most easily-remembered feature of the human face (for us humans, at least), is the most difficult for computers to comprehend:</p>
<blockquote><p><a href="http://www.cse.msu.edu/%7Ejain/">Anil Jain</a>, a distinguished professor of computer science at Michigan State University, said it&#8217;s still not easy, however, for computers to identify faces from photos &#8212; mostly because the photos people post to the internet are so diverse. </p>
<p>Computers get confused when a photo is too dark, if it&#8217;s taken from a weird angle, if the person is wearing a scarf, beard or glasses or if the person in the photo has aged significantly, he said.</p>
<p>Smiling can even be a problem.</p>
<p>&quot;The face is like a deformable surface,&quot; he said. &quot;When you smile, different parts of the face get affected differently. It&#8217;s not just like moving some object from one position to another,&quot; which would be easier for a computer to read.</p>
</blockquote>
<p>So … what will happen when this technology matures and makes the leap from family-friendly Facebook to applications in real live security or survellance applications?</p>
<blockquote><p><a href="http://epic.org/epic/staff/rotenberg/" target="_blank">Marc Rotenberg</a>, executive director of the <a href="http://epic.org/">Electronic Privacy Information Center</a>, said the motives behind the technology are what worry him.</p>
<p>Governments and corporations intend to use facial recognition software to track the public and to eliminate privacy, he said, noting that automatically identifying people in public in the U.S., when they are not suspected of a crime, could be a violation of constitutional rights. </p>
<p>When facial recognition comes to surveillance cameras, which are already in place, &quot;you&#8217;re no longer racing through iPhoto to figure out how many pictures of Barbara you have,&quot; Rotenberg said. &quot;You&#8217;re walking around in public and facing cameras that know who you are. And I think that&#8217;s a little creepy.&quot;</p>
</blockquote>
<p>I suppose this is like many other technologies – there are an abundance of positive applications, and the potential for terribly nefarious uses.</p>
<p>For example, if facial recognition can be used to identify&#160; terrorists so they could be detained prior to boarding airplanes, we would generally think that was a good application.&#160; </p>
<p>Similarly, if I could be granted entrance to my corporate office building or be logged onto necessary computer systems just by smiling (or frowning) into a camera, the building and computer systems might be more secure and the present-day use of passwords or ID cards might go the way of the <a href="http://www.discoveringidentity.com/?s=buggy+whip" target="_blank">buggy whip</a>.</p>
<p>However, if an abusive husband used facial recognition software to stalk his estranged wife, or if the government successfully tracked every movement its citizens made in the normal course of events, we would generally think of those applications as negative.</p>
<p>I have a crazy habit of smiling and waving at security cameras I see in airports or banks or convenience stores. Who knows what is happening on the other side?&#160; At the present level of today’s technology, I’m probably being recorded and not much more.&#160; In a few years, however, the sophisticated software behind the camera will probably recognize Mark Dixon and report my antics to the <a href="http://www.discoveringidentity.com/2010/07/07/are-you-a-perfect-citizen-i-will-listen-and-find-out/" target="_blank">NSA</a>.&#160; That will surely make me frown, not smile, when I wave to the ubiquitous cameras.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:51931fa6-72a2-44da-bf0b-8429436a3c8b" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>,<a href="http://technorati.com/tags/Privacy" rel="tag">Privacy</a>,<a href="http://technorati.com/tags/Security" rel="tag">Security</a>,<a href="http://technorati.com/tags/Facial+Recognition" rel="tag">Facial Recognition</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/07/13/why-face-recognition-isnt-scary-yet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are You a Perfect Citizen? I Will Listen and Find Out.</title>
		<link>http://www.discoveringidentity.com/2010/07/07/are-you-a-perfect-citizen-i-will-listen-and-find-out/</link>
		<comments>http://www.discoveringidentity.com/2010/07/07/are-you-a-perfect-citizen-i-will-listen-and-find-out/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 04:47:19 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Surveillance]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/07/07/are-you-a-perfect-citizen-i-will-listen-and-find-out/</guid>
		<description><![CDATA[The Wall Street Journal published an excellent article today entitled, “U.S. Program to Detect Cyber Attacks on Infrastructure” (subscription required),&#160; reviewing a large U.S. government program, named “Perfect Citizen,” with the stated objective to: 
“… detect cyber assaults on private U.S. companies and government agencies running critical infrastructure such as the electricity grid and nuclear [...]]]></description>
			<content:encoded><![CDATA[<p>The Wall Street Journal published an excellent article today entitled, “<a href="http://online.wsj.com/article/SB10001424052748704545004575352983850463108.html?mod=djemalertNEWS" target="_blank">U.S. Program to Detect Cyber Attacks on Infrastructure</a>” (subscription required),&#160; reviewing a large U.S. government program, named “Perfect Citizen,” with the stated objective to: </p>
<blockquote><p>“… detect cyber assaults on private U.S. companies and government agencies running critical infrastructure such as the electricity grid and nuclear power plants, according to people familiar with the program.”</p>
</blockquote>
<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/07/image.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.discoveringidentity.com/wp-content/uploads/2010/07/image_thumb.png" width="544" height="217" /></a> </p>
<p>We all know that the national infrastructure is vulnerable, as I mentioned recently in my blog about <a href="http://www.discoveringidentity.com/2010/06/30/protecting-the-electric-grid-in-a-dangerous-world/" target="_blank">NERC Critical Infrastructure Protection (CIP) Cyber Security Standards</a>. The object of this program appears to be an attempt to discover security holes that may not be CIP compliant, and detect patterns of attack before harm can be done.</p>
<blockquote><p>U.S. intelligence officials have grown increasingly alarmed about what they believe to be Chinese and Russian surveillance of computer systems that control the electric grid and other U.S. infrastructure. Officials are unable to describe the full scope of the problem, however, because they have had limited ability to pull together all the private data.</p>
</blockquote>
<p>How do you tackle this challenge?&#160; Just monitor the network and find “unusual activity” that may suggest a pending cyber attack.</p>
<blockquote><p>The surveillance by the National Security Agency, the government&#8217;s chief eavesdropping agency, would rely on a set of sensors deployed in computer networks for critical infrastructure that would be triggered by unusual activity suggesting an impending cyber attack, though it wouldn&#8217;t persistently monitor the whole system.</p>
</blockquote>
<p>This accumulation and analysis of vast amounts of data from numerous sensors is a fascinating topic.&#160; Last September, I blogged about <a href="http://www.discoveringidentity.com/2009/09/15/digital-id-world-day-2/" target="_blank">work led by Jeff Jonas</a> to <a href="http://jeffjonas.typepad.com/jeff_jonas/2009/08/your-movements-speak-for-themselves-spacetime-travel-data-is-analytic-superfood.html" target="_blank">analyze large data sets</a> to detect the types of anomalies the NSA are seeking – all to catch threats to the Las Vegas gaming industry.&#160; It would be interesting to know if the NSA is building upon his work to find terrorists before they strike.</p>
<p>Of course, any surveillance program led by the NSA is bound to be controversial, and this is no exception:</p>
<blockquote><p>Some industry and government officials familiar with the program see Perfect Citizen as an intrusion by the NSA into domestic affairs, while others say it is an important program to combat an emerging security threat that only the NSA is equipped to provide.</p>
</blockquote>
<p>Who knows … perhaps some day the NSA wizards might think my blogging efforts are a threat to national security and plant sensors to detect my email, blogging and social networking communications activity to see if something fishy is going on.&#160;&#160; After all, I am not a “Perfect Citizen,” whatever that means.&#160; No one is.</p>
<blockquote><p>&quot;The overall purpose of the [program] is our Government&#8230;feel[s] that they need to insure the Public Sector is doing all they can to secure Infrastructure critical to our National Security,&quot; said one internal Raytheon email, the text of which was seen by The Wall Street Journal. &quot;Perfect Citizen is Big Brother.&quot;</p>
</blockquote>
<p>It will be fascinating, in an apprehensive way, to see how this all comes together:</p>
<blockquote><p>Because the program is still in the early stages, much remains to be worked out, such as which computer control systems will be monitored and how the data will be collected. NSA would likely start with the systems that have the most important security implications if attacked, such as electric, nuclear, and air-traffic-control systems, they said.</p>
</blockquote>
<p>I doubt that covert surveillance of US citizens is the initial intent of this program, but unintended consequences are what trouble me.&#160; For some diabolical reason, increasing the amount of power vested in any one person or group of people tends to lead to oppression of others.&#160; And it sounds like this program will put vast informational power in the hands of a few.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:f3a448f9-db54-49d0-aa29-150bf70e782f" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Indentity" rel="tag">Indentity</a>,<a href="http://technorati.com/tags/Privacy" rel="tag">Privacy</a>,<a href="http://technorati.com/tags/Security" rel="tag">Security</a>,<a href="http://technorati.com/tags/Surveillance" rel="tag">Surveillance</a>,<a href="http://technorati.com/tags/NSA" rel="tag">NSA</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/07/07/are-you-a-perfect-citizen-i-will-listen-and-find-out/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Protecting the Electric Grid in a Dangerous World</title>
		<link>http://www.discoveringidentity.com/2010/06/30/protecting-the-electric-grid-in-a-dangerous-world/</link>
		<comments>http://www.discoveringidentity.com/2010/06/30/protecting-the-electric-grid-in-a-dangerous-world/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 00:07:58 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[FERC]]></category>
		<category><![CDATA[IdentityManagement]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[NERC]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/06/30/protecting-the-electric-grid-in-a-dangerous-world/</guid>
		<description><![CDATA[ When I woke up this morning, I read an intriguing tweet from my son Eric, who lives about a mile away from our house:
“Power has been out for 30 minutes. We have like 15 candles lit&#8230; And it&#8217;s starting to heat up.”

Well, for young Eric and his wife, a temporary power outage might be [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.npr.org/templates/story/story.php?storyId=110997398"><img style="border-right-width: 0px; margin: 5px 0px 5px 10px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" align="right" src="http://www.discoveringidentity.com/wp-content/uploads/2010/06/image6.png" width="260" height="188" /></a> When I woke up this morning, I read an intriguing tweet from my son <a href="http://www.twitter.com/ericsdixon">Eric</a>, who lives about a mile away from our house:</p>
<blockquote><p>“Power has been out for 30 minutes. We have like 15 candles lit&#8230; And it&#8217;s starting to heat up.”</p>
</blockquote>
<p>Well, for young Eric and his wife, a temporary power outage might be a romantic diversion, but we are all tremendously dependent upon available, reliable electricity distribution.&#160; We simply expect the lights to go on when we flip a switch or power our laptops when we plug them in.</p>
<p>In order for that to happen, the national <a href="http://en.wikipedia.org/wiki/Electrical_grid">electrical grid</a> or Bulk Electrical System (BES) must reliably carry energy from generating plants to our homes and places of business.&#160; We have grown to rely on that happening, 24&#215;7x365.</p>
<p>However, according to a <a href="http://www.oracle.com/go/?&amp;Src=7011679&amp;Act=5&amp;pcode=WWMK10035444MPP002">new white paper</a> published by Oracle, </p>
<blockquote><p>“there is mounting evidence that North America’s bulk power systems are dangerously exposed to threats from both within and abroad.”&#160; </p>
</blockquote>
<p>A few warning signs include:</p>
<ul>
<li><em>In June 2007, the Department of Homeland Security (DHS) leaked a video that showed how researchers launched a simulated attack that brought down a diesel electrical generator, leaving it coughing in a cloud of smoke, through a remote hack that was dubbed the Aurora vulnerability.</em> </li>
<li><em>In January 2008, a CIA analyst revealed that a number of cyber attacks had cut power to several cities outside the U.S.</em> </li>
<li><em>In May 2008, the Government Accountability Office (GAO) issued a scathing report on the number of security vulnerabilities at the Tennessee Valley Authority, the nation’s largest public power company.</em> </li>
<li><em>In April 2009, The Wall Street Journal reported, according to unnamed current and former national security officials, that Russian and Chinese attackers penetrated the U.S. power grid, installing malware that could potentially be used to disrupt delivery.</em> </li>
<li><em>In July 2009, NERC CSO Michael Assante told the House subcommittee on Emerging Threats, Cyber security, and Science and Technology, “Cyber threats to control systems are</em> </li>
</ul>
<p>In response to these and other conditions:</p>
<blockquote><p>”the federal government has responded to this threat with a set of security standards for protecting cyber assets that comprise the BES, and set an aggressive schedule for mandatory compliance, beginning in 2007, with all covered entities required to be in ‘audit compliance’ by June 2010. Non-compliance could cost power companies up to $1 million per day in penalties.</p>
<p>“The <a href="http://www.nerc.com/" target="_blank">North American Energy Reliability Corporation</a> (NERC) <a href="http://www.nerc.com/page.php?cid=2|20" target="_blank">Critical Infrastructure Protection (CIP) cyber security standards</a>, mandated through the approval of the <a href="http://www.ferc.gov/" target="_blank">Federal Energy Regulatory Commission</a> (FERC), provide a broad, though not very prescriptive guide to implement a comprehensive cyber security program, stressing responsibility and accountability for protecting the organization’s critical assets.”</p>
</blockquote>
<p><a href="http://www.oracle.com/go/?&amp;Src=7011679&amp;Act=5&amp;pcode=WWMK10035444MPP002" target="_blank"><img style="border-right-width: 0px; margin: 5px 0px 5px 10px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" align="right" src="http://www.discoveringidentity.com/wp-content/uploads/2010/06/image7.png" width="244" height="113" /></a>The new Oracle white white paper, entitled, “<a href="http://www.oracle.com/go/?&amp;Src=7011679&amp;Act=5&amp;pcode=WWMK10035444MPP002">Protecting the Electric Grid in a Dangerous World</a>,” describes how Oracle Identity Management solutions and the Oracle data security portfolio offer an effective, defense-in-depth security strategy to help meet this challenge, playing a key role in NERC CIP compliance, security and efficient use of resources.</p>
<p><strong>Identity Management:</strong> </p>
<blockquote><p>“Oracle Access Manager, Oracle Identity Manager, Oracle Identity Analytics and other products in the suite of Oracle Identity Management solutions provides application and system-level security, giving power providers and distributors the tools to create sustainable, manageable and auditable controls over access to their critical assets. Identity management and access control are essential components in CIP-003, CIP-004, -005, -006, -007, and are applicable in -008, -009.” </p>
</blockquote>
<p><strong>Data Security:</strong> </p>
<blockquote><p>“Oracle’s comprehensive data security portfolio, including Oracle Advanced Security, Oracle Data Masking, Oracle Database Vault, Oracle Label Security and Oracle Audit Vault, allow managing critical information throughout the data protection lifecycle by providing transparent data encryption, masking, privileged user and multi-factor access control, as well as continuous monitoring of database activity. Database security, especially data access controls and privileged user management are essential in CIP&#8211;003, -004, -005, -006, -007, -008 and -009.”</p>
</blockquote>
<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/06/image9.png"><img style="border-bottom: 0px; border-left: 0px; margin: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" align="left" src="http://www.discoveringidentity.com/wp-content/uploads/2010/06/image_thumb3.png" width="79" height="74" /></a>It’s great to be a associated with a <a href="http://oracle.com" target="_blank">company</a> whose products can play a major role in the protection of our electrical grid upon which we depend so much.</p>
<p>However, I must admit, lighting a few candles after dark may be enjoyable as well!</p>
<p>PS:&#160; The grid map shown above comes from an interesting <a href="http://www.npr.org/templates/story/story.php?storyId=110997398" target="_blank">interactive map</a> on the NPR.org website.&#160; Enjoy!</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:f33420ea-1343-4066-999e-7038fdf00421" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>,<a href="http://technorati.com/tags/IdentityManagement" rel="tag">IdentityManagement</a>,<a href="http://technorati.com/tags/Information+Security" rel="tag">Information Security</a>,<a href="http://technorati.com/tags/Security" rel="tag">Security</a>,<a href="http://technorati.com/tags/FERC" rel="tag">FERC</a>,<a href="http://technorati.com/tags/NERC" rel="tag">NERC</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/06/30/protecting-the-electric-grid-in-a-dangerous-world/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Exploring the Value of Identity</title>
		<link>http://www.discoveringidentity.com/2010/06/25/exploring-the-value-of-identity/</link>
		<comments>http://www.discoveringidentity.com/2010/06/25/exploring-the-value-of-identity/#comments</comments>
		<pubDate>Fri, 25 Jun 2010 13:10:24 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[Value]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/06/25/exploring-the-value-of-identity/</guid>
		<description><![CDATA[Value: “relative worth, merit, or importance”
 I have been intrigued for a long time about the concept of the “Value” of “Identity”.&#160; Consequently, I plan to devote several posts over the next period of time to this subject.&#160; At this point, I don’ t know just what I will write.&#160; I feel like I am [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://dictionary.reference.com/browse/value" target="_blank">Value</a>: <em>“relative worth, merit, or importance”</em></p>
<p><a href="http://barryruddllc.com/Gallery1/Southwestern/Cowboy_Horse_1_1" target="_blank"><img style="border-bottom: 0px; border-left: 0px; margin: 5px 0px 5px 10px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" align="right" src="http://www.discoveringidentity.com/wp-content/uploads/2010/06/image4.png" width="186" height="244" /></a> I have been intrigued for a long time about the concept of the “Value” of “Identity”.&#160; Consequently, I plan to devote several posts over the next period of time to this subject.&#160; At this point, I don’ t know just what I will write.&#160; I feel like I am entering a new phase of “Discovering Identity.”</p>
<p>Perhaps this train of thought has been triggered by the reality that businesses seek value in each procurement they make – including Identity and Access Management system purchases.&#160; Nearly every customer meeting I have attended recently inevitably gets around to the addressing the need for a solid business case before a purchase can be made.</p>
<p>But I believe the value of Identity goes farther than business cases.&#160; In his song, “<a href="http://www.metrolyrics.com/which-way-does-that-old-pony-run-lyrics-lyle-lovett.html" target="_blank">Which Way Does that Old Pony Run</a>,” Lyle Lovett reminds us,&#160; “…what’s riches to you just ain’t riches to me …”.&#160; The value placed on anything, including Identity, must be determined by individual people – the stakeholders in a given situation.</p>
<p>So, if you are so inclined to join me, let’s get on the old pony and explore the world of the Value of Identity.&#160; If you have suggestions or ideas, please share them.&#160; It will be a fun ride.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:1ae708dd-c06e-4b57-a5ed-0a8de8cd9857" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>,<a href="http://technorati.com/tags/Value" rel="tag">Value</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/06/25/exploring-the-value-of-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Love and Forgery</title>
		<link>http://www.discoveringidentity.com/2010/05/21/love-and-forgery/</link>
		<comments>http://www.discoveringidentity.com/2010/05/21/love-and-forgery/#comments</comments>
		<pubDate>Fri, 21 May 2010 20:35:07 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[Counterfeit]]></category>
		<category><![CDATA[Forgery]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/05/21/love-and-forgery/</guid>
		<description><![CDATA[I received the following email forward from by brother-in-law this week.&#160; If the story isn’t true, it is quirky enough that it deserves to be:
Running stop light = $100.00     DUI = $5000.00      Not wearing a seat belt = $50.00      Putting you [...]]]></description>
			<content:encoded><![CDATA[<p>I received the following email forward from by brother-in-law this week.&#160; If the story isn’t true, it is quirky enough that it deserves to be:</p>
<blockquote><p align="center">Running stop light = $100.00     <br />DUI = $5000.00      <br />Not wearing a seat belt = $50.00      <br />Putting you <i>&amp; your girlfriend </i>on your fake drivers license = <b>PRICELESS</b></p>
<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/05/clip_image001.jpg"><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="clip_image001" border="0" alt="clip_image001" src="http://www.discoveringidentity.com/wp-content/uploads/2010/05/clip_image001_thumb.jpg" width="424" height="319" /></a></p>
<p>REMEMBER!! When making a fake ID, attach a picture of yourself ONLY, no matter how much you love your girl.&#160; &#8230;&#160; This is an actual drivers license from a traffic stop.</p>
</blockquote>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:78120f46-353a-41ab-860b-a2bc1b93827f" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>,<a href="http://technorati.com/tags/Forgery" rel="tag">Forgery</a>,<a href="http://technorati.com/tags/Counterfeit" rel="tag">Counterfeit</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/05/21/love-and-forgery/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Business Value vs. Speeds &amp; Feeds</title>
		<link>http://www.discoveringidentity.com/2010/05/20/business-value-vs-speeds-feeds/</link>
		<comments>http://www.discoveringidentity.com/2010/05/20/business-value-vs-speeds-feeds/#comments</comments>
		<pubDate>Thu, 20 May 2010 19:11:04 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[IdentityManagement]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Value]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/05/20/business-value-vs-speeds-feeds/</guid>
		<description><![CDATA[ I had a conversation with a colleague this morning about the tension between two sales approaches:

Focusing on business value derived from implementation certain technology
Focusing on technical capabilities (AKA speeds and feeds) of certain technology

Our unified position was that the the second position only really made sense if aligned with the first.&#160; Technology by itself [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/05/image5.png"><img style="border-bottom: 0px; border-left: 0px; margin: 5px 0px 5px 5px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" align="right" src="http://www.discoveringidentity.com/wp-content/uploads/2010/05/image_thumb1.png" width="170" height="170" /></a> I had a conversation with a colleague this morning about the tension between two sales approaches:</p>
<ol>
<li>Focusing on business value derived from implementation certain technology</li>
<li>Focusing on technical capabilities (AKA speeds and feeds) of certain technology</li>
</ol>
<p>Our unified position was that the the second position only really made sense if aligned with the first.&#160; Technology by itself is certainly interesting, but in real world markets, it is becoming increasingly difficult to justify purchase of any technology unless it is very clear how that technology can deliver business value.</p>
<p>Therefore I spend most of my time focused on the business value of various Identity and Security technologies, rather than the technical details of how they are implemented.&#160; Unless we can really make a positive impact on the business whom buy our products and services, our market is not sustainable.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:999fcd9b-d738-491d-89bd-018d066216ed" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>,<a href="http://technorati.com/tags/IdentityManagement" rel="tag">IdentityManagement</a>,<a href="http://technorati.com/tags/Business" rel="tag">Business</a>,<a href="http://technorati.com/tags/Value" rel="tag">Value</a>,<a href="http://technorati.com/tags/Technology" rel="tag">Technology</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/05/20/business-value-vs-speeds-feeds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity Services for Cloud Computing</title>
		<link>http://www.discoveringidentity.com/2010/02/09/identity-services-for-cloud-computing/</link>
		<comments>http://www.discoveringidentity.com/2010/02/09/identity-services-for-cloud-computing/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 23:57:39 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[CloudComputing]]></category>
		<category><![CDATA[IDaaS]]></category>
		<category><![CDATA[IdentityManagement]]></category>
		<category><![CDATA[SOA]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/02/09/identity-services-for-cloud-computing/</guid>
		<description><![CDATA[To support recent discussions about Identity Management and Cloud computing, I divided the types of Identity Services that might be needed to support Application services into three major categories as shown in the following diagram and explained in a bit more detail below:
 
The specific services provided in each category could include:
Identity Administration Services

Create, update, [...]]]></description>
			<content:encoded><![CDATA[<p>To support recent discussions about Identity Management and Cloud computing, I divided the types of Identity Services that might be needed to support Application services into three major categories as shown in the following diagram and explained in a bit more detail below:</p>
<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/02/IDaaS.jpg"><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="IDaaS" border="0" alt="IDaaS" src="http://www.discoveringidentity.com/wp-content/uploads/2010/02/IDaaS_thumb.jpg" width="470" height="433" /></a> </p>
<p>The specific services provided in each category could include:</p>
<p><strong>Identity Administration Services</strong></p>
<ul>
<li>Create, update, delete identities</li>
<li>Password/credential management</li>
<li>Entitlement definition/management</li>
<li>Provision/de-provision access privileges</li>
<li>Role engineering/management</li>
<li>Policy definition/management</li>
</ul>
<p><strong>Identity Enforcement Services</strong></p>
<ul>
<li>Authentication</li>
<li>Authorization</li>
<li>Access control</li>
<li>Federation</li>
<li>Web services security</li>
</ul>
<p><strong>Identity Audit Services</strong></p>
<ul>
<li>Reporting</li>
<li>Evaluation</li>
<li>Attestation</li>
<li>Validation</li>
<li>Remediation</li>
</ul>
<p>Did I miss any services that you think should be present?&#160; Any input on the categories or types of services?&#160; Any input or criticism would be most welcome.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:882db36b-0c72-4443-8522-d4062cbe5df2" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>, <a href="http://technorati.com/tags/IdentityManagement" rel="tag">IdentityManagement</a>, <a href="http://technorati.com/tags/CloudComputing" rel="tag">CloudComputing</a>, <a href="http://technorati.com/tags/IDaaS" rel="tag">IDaaS</a>, <a href="http://technorati.com/tags/SOA" rel="tag">SOA</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/02/09/identity-services-for-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Users of Cloud-based Services</title>
		<link>http://www.discoveringidentity.com/2010/02/04/users-of-cloud-based-services/</link>
		<comments>http://www.discoveringidentity.com/2010/02/04/users-of-cloud-based-services/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 16:54:19 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[CloudComputing]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/02/04/users-of-cloud-based-services/</guid>
		<description><![CDATA[The following chart may be helpful as we consider the different types of users that should be addressed by Identity and Access Management (IAM) technology and processes in cloud computing. 
 At the Platform as a Service (PaaS) and Infrastructure as a Service (IaaS) layers, the only users are administrators of the platform or infrastructure [...]]]></description>
			<content:encoded><![CDATA[<p>The following chart may be helpful as we consider the different types of users that should be addressed by Identity and Access Management (IAM) technology and processes in cloud computing. </p>
<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/02/CloudUsers.jpg"><img style="border-bottom: 0px; border-left: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px" title="CloudUsers" border="0" alt="CloudUsers" src="http://www.discoveringidentity.com/wp-content/uploads/2010/02/CloudUsers_thumb.jpg" width="544" height="327" /></a> At the Platform as a Service (PaaS) and Infrastructure as a Service (IaaS) layers, the only users are administrators of the platform or infrastructure services, respectively.&#160; However, these administrative users may be either on the provider side or on the recipient or enterprise side.&#160; End users, whether within the enterprise (employees or contractors) or external to the enterprise (customers and partners), only exist at the application layer or Software as as Service (SaaS) layer.</p>
<p>This illustrates how cloud computing introduces increased complexity into IAM. Not only do the different layers (PaaS, IaaS and SaaS) have unique requirements, but multiple organizations (e.g. provider and enterprise) need to be considered.</p>
<p>For example, the nature of PaaS services will require provider administrators to have root access to the operating system, while enterprise administrators at the SaaS level may only need access to application configuration functions and external SaaS users only need to access to selected application functions.</p>
<p>Hopefully, this provides food for thought as we explore IAM in cloud computing.&#160; I’d be grateful to hear your comments.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:5b8ce862-103f-479f-919c-d9e9d6d77a91" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/CloudComputing" rel="tag">CloudComputing</a>, <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>, <a href="http://technorati.com/tags/IdentityManagement" rel="tag">IdentityManagement</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/02/04/users-of-cloud-based-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity-Enabled Patient Consent Management</title>
		<link>http://www.discoveringidentity.com/2010/01/28/identity-enabled-patient-consent-management/</link>
		<comments>http://www.discoveringidentity.com/2010/01/28/identity-enabled-patient-consent-management/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 22:47:27 +0000</pubDate>
		<dc:creator>Mark Dixon</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[Healthcare]]></category>
		<category><![CDATA[IdentityManagement]]></category>
		<category><![CDATA[MasterPatientIndex]]></category>
		<category><![CDATA[PatientConsent]]></category>

		<guid isPermaLink="false">http://www.discoveringidentity.com/2010/01/28/identity-enabled-patient-consent-management/</guid>
		<description><![CDATA[Last Thursday, January 21st, I gave a presentation at the Sun Horizons conference, “Healthcare Integration Through a New Perspective.”&#160; The title of my talk was “Identity Management: Securing Information in the HIPAA Environment.”&#160; I explored how the complementary functionality of Identity Management and Master Patient Index technologies can enable effective Patient Consent Management, a vital [...]]]></description>
			<content:encoded><![CDATA[<p>Last Thursday, January 21st, I gave a presentation at the Sun Horizons conference, “<a href="https://meeting-reg.com/hhiesummit/index.php">Healthcare Integration Through a New Perspective</a>.”&#160; The title of my talk was “Identity Management: Securing Information in the HIPAA Environment.”&#160; I explored how the complementary functionality of Identity Management and Master Patient Index technologies can enable effective Patient Consent Management, a vital requirement for online health information networks.</p>
<p>A copy of my presentation deck is available for download <a href="http://www.discoveringidentity.com/resources/Horizons_Identity_04.pdf" target="_blank">here</a>.</p>
<p>At the heart of my the presentation was the following diagram, which illustrates major components required in a Patient Consent Management system:</p>
<p><a href="http://www.discoveringidentity.com/wp-content/uploads/2010/01/consent1.jpg"><img style="border-bottom: 0px; border-left: 0px; margin: 0px auto; display: block; float: none; border-top: 0px; border-right: 0px" title="consent" border="0" alt="consent" src="http://www.discoveringidentity.com/wp-content/uploads/2010/01/consent_thumb1.jpg" width="564" height="321" /></a> </p>
<p>A brief explanation of key components follows:</p>
<p><strong>Identity and Role Repository</strong></p>
<p>IAM technology and methods provide the foundation for an effective patient consent management system.&#160; An Identity and Role Repository contains Identities, roles and access control credentials necessary to support the consent system.&#160; This repository includes:</p>
<ul>
<li>Patients</li>
<li>Providers</li>
<li>Access Rights</li>
<li>Roles (map business responsibilities to access rights)</li>
<li>Override Rights (Only users with specific roles can perform override without consent) </li>
</ul>
<p><strong>Consent Registry</strong></p>
<p>A consent registry is required to specify what permissions have been granted by patients, within the allowable limits specified by each applicable jurisdiction.&#160;&#160; Some of the key attributes include:</p>
<ul>
<li>Consent Permissions for </li>
<ul>
<li>Patients</li>
<li>Organizations</li>
<li>Users</li>
</ul>
<li>System-wide mask (everyone)</li>
<li>Fine gained access</li>
<li>Include or exclude attributes</li>
<li>Accommodation for multiple jurisdictions </li>
</ul>
<p><strong>Master Patient Index</strong></p>
<p>A Master Patient Index enables correlation of patient data across multiple repositories.&#160; This is essential because patient records are typically help in multiple locations.&#160; In other cases, if patient records exist in the same physical data warehouse, they are often logically separated.&#160; </p>
<p><strong>Federated Data Access</strong> </p>
<p>If patient data is located in physically or logically separate locations, Federated data access controlled allows access across domain boundaries without compromising the privacy or integrity of individual patient record repositories. </p>
<p><strong>Data Access Services</strong> </p>
<p>By providing a set of centralized data access services governed by IAM, the Consent Registry and the Master Patient Index, a secure method of patient data access is possible.</p>
<div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:efd4aef5-1f6b-4ad7-b1a8-39743cc0c15e" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/Identity" rel="tag">Identity</a>, <a href="http://technorati.com/tags/IdentityManagement" rel="tag">IdentityManagement</a>, <a href="http://technorati.com/tags/Healthcare" rel="tag">Healthcare</a>, <a href="http://technorati.com/tags/PatientConsent" rel="tag">PatientConsent</a>, <a href="http://technorati.com/tags/MasterPatientIndex" rel="tag">MasterPatientIndex</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.discoveringidentity.com/2010/01/28/identity-enabled-patient-consent-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
