Feet on the Street: RSA Highlights Cloud and Cybersecurity

This week, several members of the SailPoint team made the annual trek to the industry’s biggest security event, the RSA Conference. As always, the conference was a high-paced mix of conference sessions, technology debates, and meetings with customers and partners.
I’m always interested in what themes get the most play at RSA. This year, I’d have [...]

Achieving Auditable Compliance with NERC CIP Reliability Standards

Beginning in 2010, energy producers and distributors face a looming challenge – to become “auditably compliant” with the Critical Infrastructure Protection (CIP) standards by the July 1, 2010 deadline. Developed by NERC, an independent, not-for-profit organization whose mission is to ensure the reliability of the bulk power system in North America, and given the force [...]

Market Pulse Survey: Divide Between Business and IT Persists

We recently conducted our third Market Pulse Survey, which focused on the key drivers of access certifications and how organizations ensure their access privileges align with business policy. According to the 150 respondents, including many readers of this blog, there is clear evidence business users involved in these processes don’t fully understand what they are [...]

Predictions for 2010: The IT World Has Changed (for the Better)

Despite the economic challenges, this has been a record year for SailPoint as we’ve doubled our customer base and expanded into Europe and APAC. As we look forward to 2010, we have been reflecting upon the recession and how it will impact next year – particularly in regard to how companies consume, purchase and view [...]

Gartner IAM Summit Recap (Part 2): Our Customers Speak

As I mentioned in yesterday’s post, two SailPoint customers presented case studies last Wednesday at the Gartner IAM Summit. Bravely taking on the 8 a.m. time slot (which was well attended for the early hour) was Andy Weeks, Risk and Compliance Manager for Humana. Andy gave a very compelling overview of Humana’s IAM journey over [...]

Counting Down to the New Model Audit Rule

In less than three months, the new Model Audit Rule (MAR) will go into effect. Beginning January 1st, many non-public insurers will for the first time be required to comply with more stringent regulatory provisions, and public insurers that are already subject to SOX will be subject to additional reporting requirements. One key aspect of [...]

Roles and Communism at Burton Catalyst

One of the things I enjoy most about Burton Catalyst is the chance to hear first-hand from client organizations about their identity management deployments. For the most part, these sessions deal honestly with issues and challenges, are relatively hype-free, and focus on the pragmatic vs. the visionary. This year’s Catalyst featured an interesting set of [...]

A Technical View of BPM & Identity Governance

Building on Mark’s post from earlier this week, I want to add that I think the industry needs to get out of the mindset of thinking of “the business of identity” as an IT tools problem. For sure, provisioning has the potential to provide a consistent transactional “bus” for the identity change activity. But today’s [...]

Business Process Management: A Key Element of Identity Governance

Last week, I was very pleased to see Burton Group publish a report entitled “Access and Identity Governance: Leading to Transparency and Visibility?” The report, authored by Gerry Gebel, describes how an access and identity governance layer has emerged to address enterprise needs for greater transparency, visibility and business controls. The report is notable in [...]

The World is Flat When Integrating Governance and Compliance

In his recent Network World column, “The Regional, Cultural and National Differences of Identity Management,” Dave Kearns discussed a panel he moderated at last week’s European Identity Conference:
On a panel called “Is there a difference between the European way of doing IAM/GRC and the rest of the world?” I was quickly informed that, in reality, [...]