CA’s Acquisition of IDFocus

Yesterday CA announced its acquisition of IDFocus,  a small Israeli company.  Among other abilities, IDFocus provides a finer-grained segregation of duty (SoD) analysis engine.  CA has previously integrated this engine into Identity Manager, their user provisioning tool.

This is an interesting wrinkle in an ever-changing market.  CA now possesses a preventive-controls engine with the ability to look further into the security stack of an application.  This engine allows customers to make SoD decisions below the role or group level, at the lower ACL/security object levels.  Provisioning vendors have until now done this by calling external services provided by Enterprise Application Controls Management (EACM) vendors.

On one hand, CA has partially obviated the need to integrate with an SAP, Oracle, or Approva by integrating the IDFocus capabilities into CA Identity Manager.  On the other hand, CA’s move may have made things more confusing for customers.  By increasing the number of controls repositories that a customer has to maintain, integration of IDFocus makes compliant provisioning deployments more challenging.  What would be really slick is if CA could find a way to work with the EACM vendors to synchronize SOD tests so that a customer could use the same test for both detective and preventive applications.

I was speaking on this very topic in Europe last week.  I commented on the various architectures for integrating EACM into user provisioning to provide compliant provisioning services.  (For more on this subject, check out Lori’s report on the matter.)  CA has now introduced a fourth deployment model in which the provisioning engine owns the entire compliant provisioning event from the request through the SoD test to the provisioning event itself. An interesting alternative. I’ll be curious to see where CA takes this.

Part 3 of my compliant provisioning series

The final installment of my series on compliant provisioning is up on Audit Trail.

For those of you headed to Digital ID World, let me know and we can catch up. (I’m looking at you members of the Mark MacAuley supper club.)

Partial automation is equivalent to partial deployment

Part two of my three part series on Audit Trail.

Hardwired entitlements lead to brittle provisioning

Part one of my thee part series over at Audit Trail on the challenges of provisioning complex, core business systems.

A Simple Description of User Provisioning

I have a bad habit.  (Well, there’s a lot of those, but we don’t have time for that.)  I tend to come up with really great explanations for things and a) forget to write them down and b) forget what I said in the first place.  The same thing tends to happen when I write a blog entry or whitepaper… I go back and look at it and think “Wow!  How did I ever come up with that?”  Recently, I came up with an easy to follow explanation of user provisioning.  This time, for once, someone actually captured it so I can reuse it.  And better still, it was videotaped: Introduction to Identity Management and User Provisioning via Approva’s Audit Trail