Newsletters Select newsletters below and click the button to sign up!
Internetnews BloggersRecent Entries
Archives
Monthly ArchivesSearch The Blog
« Every cloud has a silver lining - we hope |
Richard Adhikari Blog
| Nine trends shaping the security field »
CA strengthens ID management with IDFocus purchaseToday, CA announced that it has acquired IDFocus LLC and its ACE identity management technology to strengthen its own identity management offerings. The ACE application will be rolled into CA's Identity and Access Management suite, which CA has been strengthening for some time. In May, CA agreed to resell Eurekify's Enterprise Role Manager, thus adding role-based ID management to its portfolio. In early June, CA unveiled various tools to automate compliance management, creating online workflow and tying in to remediation. All involve identity management. Identity management is important because it helps prevent security and compliance breaches in-house, by controlling the access of staff and contractors of a company to applications. Part of that control involves retiring or rescinding access when a person is promoted, transferred or leaves the company. Failing to retire or rescind accounts leads to orphaned accounts, which are a known security flaw. One of the features IDFocus brings to CA's products is a separation of duties (SoD) capability. SOD is critical to security as it creates a system of checks and balances. Essentially, SoD means that different people handle different aspects of a task. That's the reason why, in a business, the accounts payable and accounts receivable departments are separate. Failure to maintain SoD allowed rogue systems administrator Terry Childs to hold the City of San Francisco hostage when he created a super password that locked everyone but him out of accessing the city's network. 0 TrackBacksListed below are links to blogs that reference this entry: CA strengthens ID management with IDFocus purchase. TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/5464 1 CommentsLeave a comment |
||||||||||||||||||||||||||||||||||||||||||||
I think that is a pretty cheap shot against Terry Childs. IT management is forever pushing to have stronger passwords and maintain security of a system. Mr Childs was doing exactly that. There has been no proof demonstrated that he was up to anything nefarious.
I expect he will be vindicated.
Thanks for the "MIS Information".