Government Technology
Government Technology: State & Local Government News Articles

An End to Multiple Identities?

Bookmark and Share
Comment

Feb 2, 2007, By David Raths

Thomas Board can give a perfect example of why higher-education CIOs listed security and identity (ID) management as their No. 1 strategic concern in a 2006 Educause survey.

As director of information system architecture at Northwestern University in Evanston, Ill., Board worries about granting data access and issuing IDs to as many as 1,000 researchers from around the country working on grant-funded projects with Northwestern faculty.

"They are difficult to issue with a high level of trust," he said.

Northwestern is about one-third of the way through replacing its internally developed campuswide ID management infrastructure with Sun Microsystems' Identity Manager, Board said, and the number of applications that required IDs and passwords grew faster than the university's IT department could keep up with them. "We started out a long time ago providing access to modem pools and e-mail," he said. "Since then, the ID system we created has become the basis for access to all sorts of applications with varying levels of sensitivity, which forced us to look for a better service than we could create. We had to buy our way out of the problem."

To cope with outside researchers accessing its network, the university is now considering joining a higher-education "identity federation" called InCommon, in which institutions vouch for each other's users. Identity federation is broadly defined as agreements, standards and technologies that make identity portable across organizational boundaries. "With identity federation, a school like UC Berkeley would handle the vetting process of their researchers for us," Board said, "and eliminate that bureaucratic overhead and some degree of risk."


Sticky Situation
The evolution of distributed computing and the Internet have forced both public- and private-sector CIOs to focus more attention on ID management infrastructure issues. IT organizations are finding that partners, customers, employees and contractors all need access to their Web-enabled services, and CIOs are starting to recognize that they must be active participants in setting standards and working on interoperability issues.

The ID management software market is expected to grow to more than $8.5 billion by 2008, according to a 2005 study by the Radicati Group. In the private sector, regulatory requirements such as the Sarbanes-Oxley Act and Health Insurance Portability and Accountability Act (HIPAA) in health care are driving forces behind tighter controls and access to audit trails. Public-sector CIOs are grappling with disparate silos of identities across applications and agencies. The poster child for this problem is the employee's computer keyboard covered with four or five yellow sticky notes with passwords scribbled on them.

Governments must cross these boundaries both for internal government functions and provide more services to constituents. Most agencies have taken the first steps toward unifying and strengthening their identity infrastructure. "CIOs everywhere are concerned about the cost and hassle of maintaining multiple identities," said Nalneesh Gaur, a principal with Diamond Management and Technology Consultants. In addition, a well implemented ID management platform is a deterrent against identity theft, a concern for IT executives at all levels of government.

But beyond improving security, CIOs are starting to see potential efficiency gains. For instance, many organizations are moving to "single-sign-on" capability, so that once employees or constituents have logged into one application, they can move through other applications on the network without having to remember additional passwords or log on again. Applications can also be linked so that as a person's government ID is created, it is immediately added to other databases the user should have access to.

"It really is cheaper, better [and] faster to do authentication at an enterprise level rather than for each application," said Dan Combs, president of Global Identity Solutions in Falls Church, Va. "Just at the level of password changes, your costs could be spread across 10 applications, and you'd see a dramatic cost reduction." Call center costs related to ID authentication


Latest Government Technology News


Industry Solutions for Government

Read real world deployments of technology in government from our sponsors.

View All Industry Solutions

Related Products and Services

Marketplace


Get Public CIO's Bi-Weekly Newsletter
This section
brought to you by:

CA RC Q1 2010 Resource Center

Take our Identity
Lifecycle Management (ILM) Survey

Can your organization keep pace with its growing demands while enforcing security controls?

Mainframe

White Paper: The Mainframe Opportunity IT Strategies For Achieving Breakthrough Value

Forrester conducted interviews with CIOs/CTOs of mainframe users in the US and Europe to better understand their strategies in the use of the mainframe.

Strategy Paper: CA's Mainframe 2.0 Strategy Roadmap

Fully capitalize on the potential value offered by the mainframe as the availability of mainframe professionals becomes increasingly constrained.

MF 2.0 Product Brochure

Mainframe 2.0 is CA’s new and far-reaching initiative that is changing the way the mainframe is managed forever.


Cybersecurity

IDC White Paper - Identity Lifecycle Management: Bringing Together Security, Identity and Compliance

Read this to learn about the technology and best practices needed to manage your identities throughout their lifecycle.

I Am Who I Say I Am

This paper discusses the drivers, responses and challenges associated with information security in Government.

Simplify and Secure: Managing User Identities Throughout their Lifecycles

Find solutions that simplify, automate and secure the activities for creating and modifying user identities and roles throughout the organization.

Virtualization / Cloud Computing

White Paper: Integrated Infrastructure and Performance Management for Virtualized Environments

Government agencies use virtualized environments to decrease costs, consolidate data centers and reduce environmental impacts.

CA Virtualization Management

CA Virtualization Management solutions provide integrated end-to-end management, automation and security which drive better outcomes.

Working Together to Maximize Business Value of Your IT Investments

VMware and CA have responded to your requirements by forging a solid partnership focused on your enterprise's needs.

Project and Portfolio Management

A Life Cycle Approach to Grants Management

Using project management at every stage of grant administration can maximize funds now and for the future.

A Platform for the New Transparency: Meeting the Challenge of ARRA Grants Management in State and Local Government

The sheer size of ARRA and new grant opportunities has had a tremendous impact on the workload of grants management staff. But the size of the program is only part of the story.

Success Stories: IT Governance: Making the Difference in Cities, Counties and States

Decision-makers need to align IT projects with organizational goals.  See how three agencies achieved this.

Government Jobs

Browse hundreds of public sector career opportunities in GovTech's new jobs section. Popular job searches: government IT, public safety, GIS, transportation, CIO, security, health