Once our service provider worked out all the kinks, Phil Becker at Digital ID World and I finally got to record our chat about identity management as a project versus as a lifestyle. There were three major points I took from Phil.
Managing the Project
Phil and I both had agreed that managing your identity project, regardless of technology, is critical. This requires an understanding on all parts: vendor, implementer, and customer. Biting off less than you can chew is the way to go. Further, regardless of technology: access management, password management, user provisioning, etc., you can find quick wins that show real value. I know this sounds like basic project management, and it is, but it is vitally important in identity management.
Policy
Phil and I spent time talking about linking business and identity policy systems and integrating policy engines. Correlating business policy and procedure down to identity management systems is a tough job. Often, it is done by a few individuals who tackle it in their spare time. Tighter integration is needed. However, this requires system to system communication and policy interpretation and this is quite difficult. Furthermore, there has been little work in the vendor community to express policies in a neutral language let alone the transport and transformation of said policy.
what others say