<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tuesdaynight &#187; didw</title>
	<atom:link href="http://www.tuesdaynight.org/tag/didw/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tuesdaynight.org</link>
	<description>spots of thoughts: ian glazer and friends rant, rave and ruminate</description>
	<lastBuildDate>Sun, 11 Sep 2011 18:33:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>More coverage of Cisco and Securent</title>
		<link>http://www.tuesdaynight.org/2007/11/02/more-coverage-of-cisco-and-securent.html</link>
		<comments>http://www.tuesdaynight.org/2007/11/02/more-coverage-of-cisco-and-securent.html#comments</comments>
		<pubDate>Fri, 02 Nov 2007 20:46:33 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[Burton Group]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[defrag]]></category>
		<category><![CDATA[didw]]></category>
		<category><![CDATA[securent]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/2007/11/02/more-coverage-of-cisco-and-securent.html</guid>
		<description><![CDATA[<p>I think that Phil&#8217;s take on this sits somewhere in between Dave&#8217;s cynicism and Eric&#8217;s unabashed joy.</p> <p>I do agree with Dave in that I doubt that this acquisition signals a market consolidation &#8211; the entitlement market is too new.  Look at the role management market as an example: it&#8217;s been around for a few [...]]]></description>
			<content:encoded><![CDATA[<p>I think that <a href="http://identityblog.burtongroup.com/bgidps/2007/11/on-ciscos-agree.html" title="Phil Schacter - Burton Group">Phil&#8217;s</a> take on this sits somewhere in between <a href="http://vquill.com/2007/11/cisco-gets-entitled.html" title="Dave Kearns">Dave&#8217;s cynicism</a> and <a href="http://defragcon.com/Blog/?p=167" title="Eric Norlin">Eric&#8217;s unabashed joy</a>.</p>
<p>I do agree with Dave in that I doubt that this acquisition signals a market consolidation &#8211; the entitlement market is too new.  Look at the role management market as an example: it&#8217;s been around for a few years, lived longer than most expected, and just now are we seeing consolidation.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2007/11/01/your-network-ate-my-fine-grained-auth-engine-cisco-to-acquire-securent.html" rel="bookmark" class="crp_title">Your network ate my fine-grained auth engine: Cisco to acquire Securent</a></li><li><a href="http://www.tuesdaynight.org/2007/03/09/no-identifiers-just-attributes-uniqueness-wheres-the-context.html" rel="bookmark" class="crp_title">No identifiers, just attributes, uniqueness: Where&#8217;s the context?</a></li><li><a href="http://www.tuesdaynight.org/2007/09/05/now-it-is-official-oracle-buys-bridgestream.html" rel="bookmark" class="crp_title">Now it is official: Oracle buys Bridgestream</a></li><li><a href="http://www.tuesdaynight.org/2008/01/14/erm-and-the-organization-kevins-response.html" rel="bookmark" class="crp_title">ERM and the organization: Kevin&#8217;s response</a></li><li><a href="http://www.tuesdaynight.org/2006/02/07/roles-courion-a-prediction-for-2006-and-rsa.html" rel="bookmark" class="crp_title">Roles, Courion, a Prediction for 2006, and RSA</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2007/11/02/more-coverage-of-cisco-and-securent.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIDW: Sun&#8217;s deployment of Sun Identity Manager</title>
		<link>http://www.tuesdaynight.org/2007/09/24/didw-suns-deployment-of-sun-identity-manager.html</link>
		<comments>http://www.tuesdaynight.org/2007/09/24/didw-suns-deployment-of-sun-identity-manager.html#comments</comments>
		<pubDate>Mon, 24 Sep 2007 21:16:06 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[deloitte]]></category>
		<category><![CDATA[didw]]></category>
		<category><![CDATA[sun]]></category>
		<category><![CDATA[user provisioning]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/2007/09/24/didw-suns-deployment-of-sun-identity-manager.html</guid>
		<description><![CDATA[<p>I love customer deployment stories.  I especially love hearing about vendors deploying their own products.  In this case, Sun and Deloitte were talking about deploying Sun Identity Manager internally at Sun.</p> <p>They covered the usual tips for a successful deployment:</p> Involve the business Planning makes all the difference Don&#8217;t bite off more than you can [...]]]></description>
			<content:encoded><![CDATA[<p>I love customer deployment stories.  I especially love hearing about vendors deploying their own products.  In this case, Sun and Deloitte were talking about deploying Sun Identity Manager internally at Sun.</p>
<p>They covered the usual tips for a successful deployment:</p>
<ul>
<li>Involve the business</li>
<li>Planning makes all the difference</li>
<li>Don&#8217;t bite off more than you can chew</li>
</ul>
<p>Pretty standard stuff that always bear repeating.<br />
There were some very interesting other observations:</p>
<ul>
<li>For complex systems, like ERP, get the vendor involved in the provisioning project</li>
<li>Plan for testing early in the project</li>
<li>Plan for sustaining the deployment, turning it from a project to a program early in the project</li>
</ul>
<p>The idea of getting the complex system vendor involved in the provisioning project strikes me as both novel and extremely effective. The nuances of complex systems like ERP and mainframe security can bedevil a provisioning project.  Might as well go to the experts early.</p>
<p>Their last point on planning for sustaining the project echoes a point the Phil Becker and I made last year on identity management as a lifestyle and not a project.  You&#8217;re going to live with you decision for a lot longer than you probably expect.  You have to plan on how to sustain the deployment and turn it into a key thread in the fabric of business services the organization relies upon.</p>
<p>Deloitte speaking across all of their deployments, not just Sun&#8217;s, had some interesting observations as well:</p>
<ul>
<li>Half of all identity management deployments end up as shelf-ware (I think I hear Bill Malik chuckling somewhere)</li>
<li>The true return on investment is not in the technology but in the re-engineering of process</li>
</ul>
<p>A common misconception is that deploying a user provisioning product requires a massive process re-engineering effort.  That is not strictly true.  Mature provisioning products these days can accommodate most business processes, no matter how arcane.  That being said, deploying provisioning certainly encourages process re-engineering.  The deployment gives an organization an excuse to examine what it does and how it does.  &#8220;Do we really need five approvers just to give someone email and why do we have to fill these forms out to do so?&#8221;</p>
<p>So far, DIDW has not disappointed.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2006/01/05/truer-words-were-never-spoken.html" rel="bookmark" class="crp_title">Truer words were never spoken</a></li><li><a href="http://www.tuesdaynight.org/2008/09/04/thinking-about-matts-simple-question-correlating-accounts-and-people.html" rel="bookmark" class="crp_title">Thinking about Matt&#8217;s Simple Question: Correlating accounts and people</a></li><li><a href="http://www.tuesdaynight.org/2006/03/28/a-supposedly-fun-thing-ill-probably-do-again.html" rel="bookmark" class="crp_title">A supposedly fun thing I&#8217;ll probably do again</a></li><li><a href="http://www.tuesdaynight.org/2007/05/11/if-you-dont-know-where-you-are-going-no-road-will-take-you-there.html" rel="bookmark" class="crp_title">If you don&#8217;t know where you are going, no road will take you there</a></li><li><a href="http://www.tuesdaynight.org/2008/03/17/considering-identity-consolidation.html" rel="bookmark" class="crp_title">Considering identity consolidation</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2007/09/24/didw-suns-deployment-of-sun-identity-manager.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A small indicator of why Digital ID World is legit</title>
		<link>http://www.tuesdaynight.org/2007/09/24/a-small-indicator-of-why-digital-id-world-is-legit.html</link>
		<comments>http://www.tuesdaynight.org/2007/09/24/a-small-indicator-of-why-digital-id-world-is-legit.html#comments</comments>
		<pubDate>Mon, 24 Sep 2007 20:45:03 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[didw]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/2007/09/24/a-small-indicator-of-why-digital-id-world-is-legit.html</guid>
		<description><![CDATA[<p>It&#8217;s day one of Digital ID World 2007.  This is my third or fourth trip to DIDW.  This ever-growing event always impresses with the level and quality of conversation.  During the keynotes this morning, I got a glimpse of something small and to me something quite telling.  I saw Phil Becker and Eric Norlin, the [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s day one of Digital ID World 2007.  This is my third or fourth trip to DIDW.  This ever-growing event always impresses with the level and quality of conversation.  During the keynotes this morning, I got a glimpse of something small and to me something quite telling.  I saw Phil Becker and Eric Norlin, the brains and brawn (I&#8217;ll let you figure out which one is which), sitting on the floor off to the side of the packed meeting room.  These guys have always put the emphasis on hearing real world deployment stories and in doing so have always elevated their audiences to active participants.  To see the heads of the conference sitting on the floor to allow more attendees to have a place to sit is, to me at least, a sign of their character &#8211; totally legit.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2006/10/26/are-we-there-yet.html" rel="bookmark" class="crp_title">Are we there yet?</a></li><li><a href="http://www.tuesdaynight.org/2007/09/24/didw-suns-deployment-of-sun-identity-manager.html" rel="bookmark" class="crp_title">DIDW: Sun&#8217;s deployment of Sun Identity Manager</a></li><li><a href="http://www.tuesdaynight.org/2005/11/14/attack-of-the-yams-thoghts-on-the-role-management-panel-at-digital-id-world.html" rel="bookmark" class="crp_title">Attack of the YAMS: Thoughts on the Role Management Panel at Digital ID World</a></li><li><a href="http://www.tuesdaynight.org/2008/10/17/finding-the-ah-ha-moment-in-an-oh-crap-world.html" rel="bookmark" class="crp_title">Finding the &#8220;ah ha&#8221; moment in an &#8220;oh crap&#8221; world</a></li><li><a href="http://www.tuesdaynight.org/2006/09/07/out-nac-in-n-idm.html" rel="bookmark" class="crp_title">Out: NAC, In: N-IdM?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2007/09/24/a-small-indicator-of-why-digital-id-world-is-legit.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Part 3 of my compliant provisioning series</title>
		<link>http://www.tuesdaynight.org/2007/09/20/part-3-of-my-compliant-provisioning-series.html</link>
		<comments>http://www.tuesdaynight.org/2007/09/20/part-3-of-my-compliant-provisioning-series.html#comments</comments>
		<pubDate>Fri, 21 Sep 2007 01:54:49 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[approva]]></category>
		<category><![CDATA[Compliant Provisioning]]></category>
		<category><![CDATA[didw]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/2007/09/20/part-3-of-my-compliant-provisioning-series.html</guid>
		<description><![CDATA[<p>The final installment of my series on compliant provisioning is up on Audit Trail.</p> <p>For those of you headed to Digital ID World, let me know and we can catch up. (I&#8217;m looking at you members of the Mark MacAuley supper club.)</p> Related Posts:Hardwired entitlements lead to brittle provisioningPartial automation is equivalent to partial deploymentA Simple Description of User ProvisioningUpcoming webinar on compliant provisioningA Clear Business Case for Compliant Provisioning]]></description>
			<content:encoded><![CDATA[<p>The final installment of my series on compliant provisioning is up on <a href="http://www.approva.net/audittrail/2007/09/20/user-provisioning-series-part-three/">Audit Trail</a>.</p>
<p>For those of you headed to Digital ID World, let me know and we can catch up.  (I&#8217;m looking at you members of the Mark MacAuley supper club.)</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2007/08/22/hardwired-entitlements-lead-to-brittle-provisioning.html" rel="bookmark" class="crp_title">Hardwired entitlements lead to brittle provisioning</a></li><li><a href="http://www.tuesdaynight.org/2007/09/05/partial-automation-is-equivalent-to-partial-deployment.html" rel="bookmark" class="crp_title">Partial automation is equivalent to partial deployment</a></li><li><a href="http://www.tuesdaynight.org/2007/08/06/a-simple-description-of-user-provisioning.html" rel="bookmark" class="crp_title">A Simple Description of User Provisioning</a></li><li><a href="http://www.tuesdaynight.org/2007/07/08/upcoming-webinar-on-compliant-provisioning.html" rel="bookmark" class="crp_title">Upcoming webinar on compliant provisioning</a></li><li><a href="http://www.tuesdaynight.org/2007/05/02/a-clear-business-case-for-compliant-provisioning.html" rel="bookmark" class="crp_title">A Clear Business Case for Compliant Provisioning</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2007/09/20/part-3-of-my-compliant-provisioning-series.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Now it is official: Oracle buys Bridgestream</title>
		<link>http://www.tuesdaynight.org/2007/09/05/now-it-is-official-oracle-buys-bridgestream.html</link>
		<comments>http://www.tuesdaynight.org/2007/09/05/now-it-is-official-oracle-buys-bridgestream.html#comments</comments>
		<pubDate>Wed, 05 Sep 2007 14:28:45 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[didw]]></category>
		<category><![CDATA[erm]]></category>
		<category><![CDATA[oracle-bridgestream]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/2007/09/05/now-it-is-official-oracle-buys-bridgestream.html</guid>
		<description><![CDATA[<p>The deal is done.  To Ed, Volker, and all my friends over at Bridgestream &#8211; a hearty congratulations.</p> <p>I have to figure that people are going to start clamoring about market consolidation in the ERM space and it will reach a climax at Digital ID World just a few weeks away.  Anyone want to through [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.oracle.com/corporate/press/2007_sep/bridgestream.html" title="Oracle buys Bridgestream">The deal is done.</a>  To Ed, Volker, and all my friends over at Bridgestream &#8211; a hearty congratulations.</p>
<p>I have to figure that people are going to start clamoring about market consolidation in the ERM space and it will reach a climax at Digital ID World just a few weeks away.  Anyone want to through a prediction of who the next ERM company to get acquired will be?</p>
<p>So Ron Rymon of Eurekify <a href="http://www.tuesdaynight.org/2007/08/31/oracle-buys-bridgestream.html#comments" title="Ron's comments">threw it out there</a>:</p>
<blockquote>
<p align="left"> &#8230;As a whole, I believe that Role Management (the combination of RMM and RA) is BIGGER than Provisioning. So again, you only see the tip of the iceberg now.</p>
</blockquote>
<p>I think we are going to mark 2007 as the year that a shift occurred in user provisioning.  It shifted from being an end in-and-of-itself to the vehicle for service delivery.  We&#8217;ll see.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2007/12/04/the-enterprise-role-management-integration-challenge.html" rel="bookmark" class="crp_title">The Enterprise Role Management Integration Challenge</a></li><li><a href="http://www.tuesdaynight.org/2007/08/31/oracle-buys-bridgestream.html" rel="bookmark" class="crp_title">Oracle buys Bridgestream?</a></li><li><a href="http://www.tuesdaynight.org/2007/10/17/oracle-buys-logicalapps-redux.html" rel="bookmark" class="crp_title">Oracle buys LogicalApps: Redux</a></li><li><a href="http://www.tuesdaynight.org/2008/01/14/erm-and-the-organization-kevins-response.html" rel="bookmark" class="crp_title">ERM and the organization: Kevin&#8217;s response</a></li><li><a href="http://www.tuesdaynight.org/2007/05/15/sap-buys-maxware-column-fodder-in-the-fight-against-oracle.html" rel="bookmark" class="crp_title">SAP buys MaXware: Column Fodder in the Fight against Oracle</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2007/09/05/now-it-is-official-oracle-buys-bridgestream.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If you don&#8217;t know where you are going, no road will take you there</title>
		<link>http://www.tuesdaynight.org/2007/05/11/if-you-dont-know-where-you-are-going-no-road-will-take-you-there.html</link>
		<comments>http://www.tuesdaynight.org/2007/05/11/if-you-dont-know-where-you-are-going-no-road-will-take-you-there.html#comments</comments>
		<pubDate>Fri, 11 May 2007 21:35:39 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[didw]]></category>
		<category><![CDATA[mark-macauley]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/2007/05/11/if-you-dont-know-where-you-are-going-no-road-will-take-you-there.html</guid>
		<description><![CDATA[<p>Apologies to Lewis Carol and the Cheshire Cat. </p> <p>Mark MacAuley makes me laugh. He is a funny guy, but that&#8217;s not why he makes me laugh. He makes me laugh when he finds situations like this one:</p> <p>I spoke to a non-US Government Agency yesterday about their Identity Management initiative. Turns out they are [...]]]></description>
			<content:encoded><![CDATA[<p>Apologies to Lewis Carol and the Cheshire Cat.  </p>
<p>Mark MacAuley makes me laugh.  He is a funny guy, but that&#8217;s not why he makes me laugh.  He makes me laugh when he finds situations <a href="http://identitystuff.blogspot.com/2007/05/its-all-about-business-process-folks.html">like this one</a>:</p>
<blockquote><p>I spoke to a non-US Government Agency yesterday about their Identity Management initiative. Turns out they are hung up on an architecture. Why? Because there is no identifiable (or identified) business process for them to build for. The business users are saying &#8211; Just buy a tool and it&#8217;ll take care of it that&#8217;s what their workflows are for&#8217;. Those of us who do this for a living are probably smirking or laughing out loud at the comment. Typical, but one of the leading causes of unsuccessful projects.</p></blockquote>
<p>Why is this funny?  Because I already know this project is doomed to fail and all you can do is shrug your shoulders and laugh.  </p>
<p>Having &#8220;the business&#8221; abdicate its role as the driver of any project like this is criminally irresponsible.  (For you hardcore cynics, I don&#8217;t care that this is a government example; that&#8217;s not an excuse.)  Identity Management is waking up from its speed and feeds adolescence.  More importantly, the market is starting to snap out of its IT-induced hypnosis, and it is business that will benefit.  The business cannot simply punt on an opportunity like this.</p>
<p>I literally just got out of Courion&#8217;s user conference, Converge.  I would say that about half of the presentations from customers, analysts, and Courion staff alike related to the business drivers and the business view of identity management projects.</p>
<p>Simple example &#8211; from a business perspective, identity management often gets attestation wrong.  Unless you have the absolutley most friendly Active Directory group names in the world, presenting a list of groups to a manager and asking, &#8220;Are these the groups that Ian should have?&#8221; is essentially useless.  Now presenting a list of business functions as the content of an attestation event &#8211; that makes sense.  Instead of sending AD group SHRPT1_ENG and CITRIX_PRESSRV_02_SAP863 to my manager, send &#8220;Access to the Engineering Sharepoint server&#8221; and &#8220;Access to SAP Instance 863 via Citrix Presentation Server.&#8221;  It is simple things like this that turn IdM projects into true business enablers.</p>
<p>I&#8217;ll be back soon with some other thoughts from Converge and an interesting conversation Phil Becker and I seem to always be in the midst of.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2007/09/24/didw-suns-deployment-of-sun-identity-manager.html" rel="bookmark" class="crp_title">DIDW: Sun&#8217;s deployment of Sun Identity Manager</a></li><li><a href="http://www.tuesdaynight.org/2006/01/05/truer-words-were-never-spoken.html" rel="bookmark" class="crp_title">Truer words were never spoken</a></li><li><a href="http://www.tuesdaynight.org/2008/01/14/erm-and-the-organization-kevins-response.html" rel="bookmark" class="crp_title">ERM and the organization: Kevin&#8217;s response</a></li><li><a href="http://www.tuesdaynight.org/2006/09/07/out-nac-in-n-idm.html" rel="bookmark" class="crp_title">Out: NAC, In: N-IdM?</a></li><li><a href="http://www.tuesdaynight.org/2008/07/14/combining-business-and-it-roles-has-a-strange-familiarity.html" rel="bookmark" class="crp_title">Combining business and IT roles has a strange familiarity</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2007/05/11/if-you-dont-know-where-you-are-going-no-road-will-take-you-there.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

