In Depth
Identity Management in the Real World
What's identity management? Ask 20 vendors, get 20 answers. But CSOs aren't waiting for a universal definition; they're busy tackling whatever projects meet their business needs.
By Deborah Radcliff
"We're seeing that the average user has roughly 15 user IDs and passwords
For example, Motorola, using existing user directories, has reduced sign-on for "tens of thousands of employees" to two primary account passwords
The trick is to avoid being seduced by the word single in single sign-on. Boni says reducing sign-on to a number of other applications proved too problematic from a technology standpoint. BellSouth's project demonstrates a second benefit of reduced sign-on: faster service time. "In a highly sensitive call center environment, it's critical to take as little time as possible per call. So not having to log in with a lot of credentials and passwords to different applications saves time and money," says Monique Shivanandan, vice president of information technology strategy, security and business continuity for BellSouth. Since January 2003, BellSouth has converted 20 percent of its busiest call center applications into one sign-on, with plans to convert remaining applications during their regular new-release schedules (so long as there are no functional conflicts). Packing Provisions BellSouth's work illustrates a common result among today's identity management projects. Those who start and succeed with a single manageable task often find their systems being stretched to take on additional functionality.
Shivanandan says that almost from the onset of the company's sign-on reduction project, IT and business managers started envisioning new uses for identity management
Eventually, for example, a provisioning system would also achieve regulatory compliance for access audit trails, stabilize the system by creating a common identity structure and dramatically reduce the cost of account administration, she continues. In particular, the process of getting a new worker up and running with all his resources could potentially be cut to an hour instead of taking several days to a week.
For BellSouth, those provisioning dreams face some technical hurdles. For now, it's difficult to provision across a wide swath of applications because of the middleware-agent model these tools use
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



