Government Technology
Government Technology: State & Local Government News Articles

Behind the Screen

Bookmark and Share
Comment

Feb 3, 2004, By Linda Formichelli

When you think of managing identities, user names and passwords probably come to mind first. But this standard feature of computer life can be more cumbersome than helpful -- even if it does provide some measure of security -- due to the multitude of systems found within any one government agency.

Contra Costa County's Department of Information Technology, for example, uses products from Sun Microsystems, IBM, Microsoft, PeopleSoft, Computer Associates and Vanguard Integrity Professionals, in addition to a security application written and maintained in-house. "The challenges of integrating identity management with other applications are significant because it requires competing vendors to work together and share sometimes-proprietary solutions," said Kevin Dickey, the county's deputy CIO and chief information security officer. "This is almost never successfully done, which is why you always hear the complaint that users have too many user IDs and passwords."

Ignoring the proliferation of IDs and passwords comes with a price. While much attention is focused on the potential for outside cyber-attacks, more threatening are internal pressures from employees who changed positions, retired or were released. All too often, their user names and passwords remain on systems long after they leave, creating situations they can easily exploit. A PricewaterhouseCoopers survey of 138 CEOs in 2002 found that ex-employees and on-site contractors pose far more of a security hazard than hackers.

The challenge for CIOs is how to achieve identity management -- by balancing ease of access for citizens and companies doing business with their governmental employers, while restricting access only to those who need it. There is no one solution to this conundrum, but CIOs are tackling this tangled issue and making headway.


Building the Foundation
To avoid proliferating user IDs -- the passwords for which can invariably be found on sticky notes under keyboards -- Phil Windley, former CIO of Utah, suggests CIOs start on identity management by developing an enterprise information architecture (EIA). This would determine which businesses the agency is in and how those businesses should fit together.

"Security is a part of the architecture, but there's more to digital identity management than throwing up a defensive perimeter and firewalls," said Windley, who is now an IT consultant. "I view identity management as a positive, opportunistic activity rather than a defensive activity. A good [identity management] infrastructure allows an organization to proactively associate with partners and give them the things they need to do their work. It allows an organization to interface with customers in a friendly, knowing way. These aren't things you get from a security outlook."

By creating an EIA, said Windley, a CIO will account for which resources must be accessed by which citizens, employees, suppliers and businesses; the level of access appropriate for different types of users; and how those entities will interact with the resources.

"Identity management is really about policy," said Windley. "It's probably too large a task to build a single database authentication system that encompasses every vendor and resource."

Arizona is in the blueprint stage, said Lee Lane, information security manager for the Arizona Department of Administration's Information Security Services Division. "We've identified an LDAP [lightweight directory access protocol] as a critical component. We know that we need an information directory; now we're working on who needs this information and why, with the goal of establishing a trust model between all involved entities."

An architecture can help organizations group data in terms of security and accessibility needs. "There used to be one gate or firewall that would either let Brian Anderson in or keep him out," said Brian Anderson, program director of security market management for IBM Tivoli Software. "Now governments have recognized they need to let almost everyone in, whether as customers or partners."

Today's government portal might consist of three perimeters: the first


Latest Government Technology News


Industry Solutions for Government

Read real world deployments of technology in government from our sponsors.

View All Industry Solutions

Related Products and Services

Marketplace


Get Public CIO's Bi-Weekly Newsletter
This section
brought to you by:

CA RC Q1 2010 Resource Center

Take our Identity
Lifecycle Management (ILM) Survey

Can your organization keep pace with its growing demands while enforcing security controls?

Mainframe

White Paper: The Mainframe Opportunity IT Strategies For Achieving Breakthrough Value

Forrester conducted interviews with CIOs/CTOs of mainframe users in the US and Europe to better understand their strategies in the use of the mainframe.

Strategy Paper: CA's Mainframe 2.0 Strategy Roadmap

Fully capitalize on the potential value offered by the mainframe as the availability of mainframe professionals becomes increasingly constrained.

MF 2.0 Product Brochure

Mainframe 2.0 is CA’s new and far-reaching initiative that is changing the way the mainframe is managed forever.


Cybersecurity

IDC White Paper - Identity Lifecycle Management: Bringing Together Security, Identity and Compliance

Read this to learn about the technology and best practices needed to manage your identities throughout their lifecycle.

I Am Who I Say I Am

This paper discusses the drivers, responses and challenges associated with information security in Government.

Simplify and Secure: Managing User Identities Throughout their Lifecycles

Find solutions that simplify, automate and secure the activities for creating and modifying user identities and roles throughout the organization.

Virtualization / Cloud Computing

White Paper: Integrated Infrastructure and Performance Management for Virtualized Environments

Government agencies use virtualized environments to decrease costs, consolidate data centers and reduce environmental impacts.

CA Virtualization Management

CA Virtualization Management solutions provide integrated end-to-end management, automation and security which drive better outcomes.

Working Together to Maximize Business Value of Your IT Investments

VMware and CA have responded to your requirements by forging a solid partnership focused on your enterprise's needs.

Project and Portfolio Management

A Life Cycle Approach to Grants Management

Using project management at every stage of grant administration can maximize funds now and for the future.

A Platform for the New Transparency: Meeting the Challenge of ARRA Grants Management in State and Local Government

The sheer size of ARRA and new grant opportunities has had a tremendous impact on the workload of grants management staff. But the size of the program is only part of the story.

Success Stories: IT Governance: Making the Difference in Cities, Counties and States

Decision-makers need to align IT projects with organizational goals.  See how three agencies achieved this.

Government Jobs

Browse hundreds of public sector career opportunities in GovTech's new jobs section. Popular job searches: government IT, public safety, GIS, transportation, CIO, security, health