Endpoint

4/26/2018
01:15 PM
Sara Peters
Sara Peters
Slideshows
Connect Directly
Twitter
RSS
E-Mail
100%
0%

12 Trends Shaping Identity Management

As IAM companies try to stretch 'identity context' into all points of the cybersecurity market, identity is becoming 'its own solar system.'
Previous
1 of 13
Next

(Image by DRogatnev, via Shutterstock)
(Image by DRogatnev, via Shutterstock)

You may have noticed the RSA Conference last week having a disproportionate number of sessions about identity, and far more companies nudging their way under the umbrella of identity and access management (IAM) with terms like "identity governance," "identity context," "privileged access management," "privacy," "behavior biometrics," "biometric platforms" and "human-centric security" splashed on their booths. Get used to it.  

If the cybersecurity market is a globe, with each market segment taking its piece - one continent for endpoint security, an archipelago for threat intelligence - where would identity and access management fit?

"Identity is its own solar system," says Robert Herjavec, CEO of global IT security firm Herjavec Group, and Shark Tank investor. "Its own galaxy."

"The problem with users is that they’re interactive," he explains. The reason identity management is such a challenge for enterprises is because users get hired, get fired, get promotions, access sensitive filesystems, share classified data, send emails with potentially classified information, try to access data we don't have access to, try to do things we aren't supposed to try to do. Set-and-forget doesn't work on us.

Luckily, great IAM is getting easier to come by. Herjavec points to identity governance tools like Sailpoint and Saviynt and privileged access management tools like CyberArk, saying that now "not only are they manageable, they’re fundamentally consumable from a price point." 

Not a moment too soon. The need for IAM has always been high, but recent breaches (Equifax), new compliance pressures (GDPR), and privacy revelations (Cambridge Analytica/Facebook) have increased the pressure on identity security and governance alike. As Ping Identity's senior technical architect Sarah Squire puts it, "Facebook's security team is awesome - that was bad governance. Equifax was bad security."

What forces are forming the shape of this identity galaxy? Read on for more. 

 

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Previous
1 of 13
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2018 | 11:18:25 PM
not only are they manageable, theyre fundamentally consumable from a price point
This item has monumental importance. For IAM and PAM to gain widespread acceptance it needed to become some what of a commodity amongst the different organziational sectors. 
What We Talk About When We Talk About Risk
Jack Jones, Chairman, FAIR Institute,  7/11/2018
Ticketmaster Breach Part of Massive Payment Card Hacking Campaign
Jai Vijayan, Freelance writer,  7/10/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Locked device, Ha! I knew there was another way in.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-0341
PUBLISHED: 2018-07-16
A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authenticated, remote attacker to perform a command injection and execute commands with the privileges of the web server. The vulnerability is due to insufficie...
CVE-2018-0360
PUBLISHED: 2018-07-16
ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.
CVE-2018-0361
PUBLISHED: 2018-07-16
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.
CVE-2018-0366
PUBLISHED: 2018-07-16
A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to...
CVE-2018-0368
PUBLISHED: 2018-07-16
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient security restrictions imposed by the affected software. An attacker could exploit this vulne...