<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Netweaver Identity Manager Weblog</title>
	<atom:link href="http://sgciam.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://sgciam.wordpress.com</link>
	<description>Extracting maximum value from Identity and Access Management</description>
	<lastBuildDate>Mon, 09 Nov 2009 04:40:10 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='sgciam.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/d6a5f03985d9da8666db046c22b97adc?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Netweaver Identity Manager Weblog</title>
		<link>http://sgciam.wordpress.com</link>
	</image>
			<item>
		<title>&#8216;Smooth Sailing&#8217; Fallacy in ERP Security</title>
		<link>http://sgciam.wordpress.com/2009/11/09/smooth-sailing-fallacy-in-erp-security/</link>
		<comments>http://sgciam.wordpress.com/2009/11/09/smooth-sailing-fallacy-in-erp-security/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 04:40:10 +0000</pubDate>
		<dc:creator>jagannathanvaman</dc:creator>
				<category><![CDATA[Enterprise Risk Management]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=599</guid>
		<description><![CDATA[This smooth-sailing fallacy in IS Security arises when we mistake a measure for reality. Competent management always looks deeper than the numbers, deeper than the current measures. Incompetent management just focuses on the metrics that are based on past reality. And that’s how we get into these troubles. We really have to think about the redesign ERP and SAP security &#38; its measurement. This lesson is fundamental: you cannot manage by just looking at the results meter.  You have to have a big picture view of Security by applying constant changes in security protocols and metrics. That means your Security policy which may be 5 years old is useless and you have no security in place. <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=599&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I just read an essay with interesting observations made by <span style="line-height:21px;color:#444444;font-size:15px;"><span style="color:#444444;font:normal normal bold 15px/normal georgia, serif;display:inline;font-weight:bold;margin:0;padding:0;">Richard Rumelt in <a href="http://www.mckinseyquarterly.com/Management_lessons_from_the_financial_crisis_A_conversation_with_Lowell_Bryan_and_Richard_Rumelt_236">McKinsey Quarterly</a>. He says &#8220;</span> There’s been a dramatic failure in management governance. And so our basic doctrines of how we manage things are in question and need revision.</span></p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;">At the heart of this failure is what I call the <strong>“smooth sailing” fallacy</strong>. Back in the 1930s, the Graf Zeppelin and the Hindenburg were the largest aircraft that had ever flown. The Hindenburg was as big as the <em>Titanic</em>. Together these vehicles had made 620-odd successful flights when one evening the Hindenburg suddenly burst into flames and fell to the ground in New Jersey. That was May 1937.&#8221;</p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;">Years ago, I had the chance to chat with a guy who had actually flown over Europe in the Hindenburg. And he had this wistful memory that it was a wonderful ride. He said, “It seemed so safe. It was smooth, not like the bumpy rides you get in airplanes today.” Well, the ride in the Hindenburg <em>was</em> smooth, until it exploded. And the risk the passengers took wasn’t related to the bumps in the ride or to its smoothness. If you had a modern econometrician on board, no matter how hard he studied those bumps and wiggles in the ride, he wouldn’t have been able to predict the disaster. The fallacy is the idea that you can predict disaster risk by looking at the bumps and wiggles in current results.</p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;">The history of bumps and wiggles—and of GDP and prices—didn’t predict economic disaster. When people talk about Six Sigma events or tail risk or Black Swan, they’re showing that they don’t really get it. What happened to the Hindenburg that night was not a surprisingly large bump. It was a design flaw.</p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;">To see the disaster coming, you had to have looked beyond the data about flight bumpiness—beyond the professionalism of the staff—and really think, “Does it make any sense to have people riding in a gondola, strapped to a giant sack of flammable hydrogen gas?” There’s just not a data series that lets you think about that. But it’s not that hard to think about.</p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;">If we apply this logic to SAP Security &#8211; I find many SAP customers suffer from the Smooth Sailing fallacy. &#8216;Well &#8211; we implemented SAP 10 years back, IBM is managing the support, we have no problems! Our Security incidents are insignificant.&#8217; &#8216;OH we have installed SAP GRC solutions but no one uses them!&#8217;</p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;"><strong>This smooth-sailing fallacy in IS Security arises when we mistake a measure for reality</strong>. Competent management always looks deeper than the numbers, deeper than the current measures. Incompetent management just focuses on the metrics that are based on past reality. And that’s how we get into these troubles. We really have to think about the redesign ERP and SAP security &amp; its measurements. This lesson is fundamental: you cannot manage by just looking at the results meter.  You have to have a big picture view of Security by applying constant changes in security protocols and metrics. That means your Security policy which may be 5 years old is useless and you have no security in place.</p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;">CEOs and CFOs will use the smooth sailing argument &#8211; Hey! We never had a security issue in the past 2 years? So why now?</p>
<p style="font-family:Georgia, serif;font-size:15px;line-height:21px;color:#444444;margin:0;padding:0 20px 15px 0;">You have to show them what Rumelt said about Hindenburg! A small design flaw can blow them out of the window.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/599/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=599&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/11/09/smooth-sailing-fallacy-in-erp-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Vaman</media:title>
		</media:content>
	</item>
		<item>
		<title>Is NetWeaver IdM really replacing CUA?</title>
		<link>http://sgciam.wordpress.com/2009/11/08/is-netweaver-idm-really-replacing-cua/</link>
		<comments>http://sgciam.wordpress.com/2009/11/08/is-netweaver-idm-really-replacing-cua/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 06:46:31 +0000</pubDate>
		<dc:creator>mhessler</dc:creator>
				<category><![CDATA[IAM General]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=642</guid>
		<description><![CDATA[So far &#8211; despite all efforts from SAP on the Marketing front &#8211; I have not seen this to become a reality. CUA is no longer one of SAP&#8217;s beloved children &#8211; meaning no major functionality upgrades will be provided through enhancements. But to tell you the truth, it works. So if you only care [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=642&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>So far &#8211; despite all efforts from SAP on the Marketing front &#8211; I have not seen this to become a reality. CUA is no longer one of SAP&#8217;s beloved children &#8211; meaning no major functionality upgrades will be provided through enhancements. But to tell you the truth, it works. So if you only care about SAP user provisioning (like me) then CUA is good enough. On the flip side CUA has nothing to do with Identity Management. Its intend was to simplify role assignments across complex system landscapes, not to automate user management. It&#8217;s still not capable of mirroring best practices for onboarding, position changes and terminations. The manual workload is tremendous and here and there in the mist of Excel spreadsheets and e-mails from HR orphan user id&#8217;s are as inevitable as candy at Halloween.</p>
<p>So I say it&#8217;s time to retire the good old box and get something in place that makes SU01 and SU10 go away forever. Time it is indeed.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/642/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/642/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/642/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=642&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/11/08/is-netweaver-idm-really-replacing-cua/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">mhessler</media:title>
		</media:content>
	</item>
		<item>
		<title>Adaptation Risks</title>
		<link>http://sgciam.wordpress.com/2009/10/28/adaptation-risks/</link>
		<comments>http://sgciam.wordpress.com/2009/10/28/adaptation-risks/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 17:37:16 +0000</pubDate>
		<dc:creator>Gregg Dippold</dc:creator>
				<category><![CDATA[IAM General]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=640</guid>
		<description><![CDATA[I have posted a brief discussion on the risk in adapting new technologies, or upgrades and a general guideline for addressing the problem.  The post is available at Risk Intelligence.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=640&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I have posted a brief discussion on the risk in adapting new technologies, or upgrades and a general guideline for addressing the problem.  The post is available at <a href="http://sgcri.wordpress.com/2009/10/28/a-death-in-the-desert/" target="_self">Risk Intelligence.</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/640/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=640&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/10/28/adaptation-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">gdippold</media:title>
		</media:content>
	</item>
		<item>
		<title>Latest Post at Risk Intelligence is Up</title>
		<link>http://sgciam.wordpress.com/2009/09/17/latest-post-at-risk-intelligence-is-up/</link>
		<comments>http://sgciam.wordpress.com/2009/09/17/latest-post-at-risk-intelligence-is-up/#comments</comments>
		<pubDate>Thu, 17 Sep 2009 16:57:28 +0000</pubDate>
		<dc:creator>Gregg Dippold</dc:creator>
				<category><![CDATA[IAM General]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=636</guid>
		<description><![CDATA[My latest post can accessed be here.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=636&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>My latest post can accessed be <a href="http://wp.me/puaZI-20">here</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/636/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=636&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/09/17/latest-post-at-risk-intelligence-is-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">gdippold</media:title>
		</media:content>
	</item>
		<item>
		<title>Dead Quiet</title>
		<link>http://sgciam.wordpress.com/2009/08/31/dead-quiet/</link>
		<comments>http://sgciam.wordpress.com/2009/08/31/dead-quiet/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 05:23:53 +0000</pubDate>
		<dc:creator>Gregg Dippold</dc:creator>
				<category><![CDATA[IAM General]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=631</guid>
		<description><![CDATA[It&#8217;s hard to believe that it has been more than sixty days since I have posted anything. I was busy on a small project, that was followed by research/writing for a book on IdM and recently developing a proposal and solution for a complex security problem.  I hope to get back to blogging a little [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=631&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>It&#8217;s hard to believe that it has been more than sixty days since I have posted anything. I was busy on a small project, that was followed by research/writing for a book on IdM and recently developing a proposal and solution for a complex security problem.  I hope to get back to blogging a little more frequently.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/631/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/631/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/631/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/631/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/631/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/631/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/631/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/631/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/631/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/631/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=631&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/08/31/dead-quiet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">gdippold</media:title>
		</media:content>
	</item>
		<item>
		<title>Building a Business Case for Identity &amp; Access Management</title>
		<link>http://sgciam.wordpress.com/2009/06/30/building-a-business-case-for-identity-access-management/</link>
		<comments>http://sgciam.wordpress.com/2009/06/30/building-a-business-case-for-identity-access-management/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 03:53:12 +0000</pubDate>
		<dc:creator>Gregg Dippold</dc:creator>
				<category><![CDATA[IAM General]]></category>
		<category><![CDATA[Implementation]]></category>
		<category><![CDATA[Business Case]]></category>
		<category><![CDATA[IAM Business Case]]></category>
		<category><![CDATA[IAM economic model]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=622</guid>
		<description><![CDATA[When I worked for a large corporation I was frequently tasked with building a business case without a budget, that is, I wasn&#8217;t able to hire any consultants to assist me.  In some cases deadlines were relatively short so it was fairly difficult to get it completed.  When the Internet came around more than once [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=622&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>When I worked for a large corporation I was frequently tasked with building a business case without a budget, that is, I wasn&#8217;t able to hire any consultants to assist me.  In some cases deadlines were relatively short so it was fairly difficult to get it completed.  When the Internet came around more than once I was saved by people willing share business cases they had developed.  Therefore I have uploaded a economic impact model that comprises two documents, an excel spreadsheet and word document that should cover the basic needs of a user.  I have other more sophisticated models besides this one (for example, a business process and knowledge management re-engineering model that compares the economics of the current state versus the future state) but for the majority this should suffice to help you get started.  If you find it useful just leave me a comment.</p>
<p>It can be downloaded <a href="http://www.riskhorizon.net/downloads/IAM_Model.zip" target="_blank">here</a>.</p>
<p>Update:  Fixed the link.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/622/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/622/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/622/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=622&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/06/30/building-a-business-case-for-identity-access-management/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">gdippold</media:title>
		</media:content>
	</item>
		<item>
		<title>Preventing SUNburn?</title>
		<link>http://sgciam.wordpress.com/2009/06/24/preventing-sunburn/</link>
		<comments>http://sgciam.wordpress.com/2009/06/24/preventing-sunburn/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 15:02:41 +0000</pubDate>
		<dc:creator>mattpollicove</dc:creator>
				<category><![CDATA[IAM General]]></category>
		<category><![CDATA[Business Case]]></category>
		<category><![CDATA[crisis]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[decision bias]]></category>
		<category><![CDATA[enterprise risk]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[netweaver identity management backend database]]></category>
		<category><![CDATA[Provisioning]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=619</guid>
		<description><![CDATA[So it&#8217;s finally beginning.  Identity Management vendors are percieving the departure of Sun IDM from the landscape.   CA is now offering Sun Users the ability to switch over to CA&#8217;s IDM product.
I&#8217;ve not heard much lately about what the eventual plans are for Sun IDM, but something&#8217;s going to have to be announced soon before the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=619&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>So it&#8217;s finally beginning.  Identity Management vendors are percieving the departure of Sun IDM from the landscape.   <a title="CA Delivers Identity and Access Management Alternatives for Businesses Affected by Oracle's Acquisition of Sun Microsystems" href="http://sev.prnewswire.com/high-tech-security/20090623/NY3679723062009-1.html" target="_blank">CA</a> is now offering Sun Users the ability to switch over to CA&#8217;s IDM product.</p>
<p>I&#8217;ve not heard much lately about what the eventual plans are for Sun IDM, but something&#8217;s going to have to be announced soon before the other IdM vendors pull the rug out from under Sun/Oracle.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/619/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/619/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/619/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/619/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/619/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/619/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/619/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/619/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/619/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/619/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=619&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/06/24/preventing-sunburn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">mattpollicove</media:title>
		</media:content>
	</item>
		<item>
		<title>How Many Problems with Persistent Data Does a Unique Identifier Solve?</title>
		<link>http://sgciam.wordpress.com/2009/06/23/how-many-problems-with-persistent-data-does-a-unique-identifier-solve/</link>
		<comments>http://sgciam.wordpress.com/2009/06/23/how-many-problems-with-persistent-data-does-a-unique-identifier-solve/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 23:33:09 +0000</pubDate>
		<dc:creator>Gregg Dippold</dc:creator>
				<category><![CDATA[Data Synchronization]]></category>
		<category><![CDATA[Implementation]]></category>
		<category><![CDATA[Netweaver IdM General]]></category>
		<category><![CDATA[Netweaver Identity Managment Database]]></category>
		<category><![CDATA[GUID]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=614</guid>
		<description><![CDATA[The answer is zero.  A unique identifier adds nothing to any logical problem we have with our data.  Let’s see why this is true.  I have two sets of data from different systems, which represent information or attributes about a real world user.  Those data elements are indistinguishable from each other.  Perhaps they are first [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=614&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The answer is zero.  A unique identifier adds nothing to any logical problem we have with our data.  Let’s see why this is true.  I have two sets of data from different systems, which represent information or attributes about a real world user.  Those data elements are indistinguishable from each other.  Perhaps they are first name, last name, city and state.  They are identical as far as I can tell.  If I add a unique identifier do I know anything more about them?  I just know they are no longer identical and yet they may be in the real world the same person. By adding a unique identifier I may have made a distinction, which is false.  It’s impact will only be deleterious never beneficial.  The unique identifier becomes ornamental.  Metaphorically it is like placing a medallion around the neck of the famous twins and still not knowing if it’s Tweedledee or Tweedledum.  At least in this case I could re-name them to something like Dee and Notdee, which would be meaningful to an observer.  However, in the foregoing example, we are dealing already with a representation of an entity and it adds nothing. Now let’s add several more attributes, for example, title and department.  If I can now distinguish easily whether they are the same person or not I have accomplished my goal and I still have not added a unique identifier.  The smallest subset of elements that distinguishes one set from another is a suitable key if the data is in a database and I still haven’t added a unique identifier.  So then how are unique identifier’s useful?  They are useful within a context in which we are programmatically creating many closely similar but not identical objects whose existence is ephemeral.  When we are combining data from many different contexts, they solve nothing; they are just another attribute.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/614/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/614/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/614/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/614/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/614/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/614/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/614/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/614/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/614/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/614/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=614&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/06/23/how-many-problems-with-persistent-data-does-a-unique-identifier-solve/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">gdippold</media:title>
		</media:content>
	</item>
		<item>
		<title>HCM and NetWeaver Identity Management Integration Tips</title>
		<link>http://sgciam.wordpress.com/2009/06/11/hcm-and-netweaver-identity-management-integration-tips/</link>
		<comments>http://sgciam.wordpress.com/2009/06/11/hcm-and-netweaver-identity-management-integration-tips/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 13:36:22 +0000</pubDate>
		<dc:creator>Gregg Dippold</dc:creator>
				<category><![CDATA[Data Synchronization]]></category>
		<category><![CDATA[Netweaver Identity Managment Database]]></category>
		<category><![CDATA[Virtual Directory Server]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[Netweaver IdM Integration]]></category>
		<category><![CDATA[SAP HCM]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=607</guid>
		<description><![CDATA[The landscape document from SAP that explains how to export from HCM to VDS to Identity Center has sections that are less than clear so I thought I would list common issues that have caused problems in the past.  First the architecture.  The way the export works is as follows:

A report is run in SAP [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=607&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The landscape document from SAP that explains how to export from HCM to VDS to Identity Center has sections that are less than clear so I thought I would list common issues that have caused problems in the past.  First the architecture.  The way the export works is as follows:</p>
<ol>
<li>A report is run in SAP HCM which extracts the necessary data formated as LDAP data.</li>
<li>SAP connects to the VDS and pushes the data.</li>
<li>VDS connects to the Identity Center information store and uploads the data.</li>
</ol>
<p>A couple common problems I have seen.</p>
<ul>
<li>The field names inside SAP are misnamed or the export names to LDAP are.</li>
<li>The LDAP libraries in SAP Basis are not installed.</li>
<li>VDS Template:  The one you want to use is this one “HR Export to IdM Identity Center.xml” this one will <strong><em>not</em></strong> work &#8220;HCM LDAP EXTRACT for IDM.xml&#8221;</li>
<li>Bad credentials or passwords (of course)</li>
<li>VDS Tree for HCM is broken in some way.  If in doubt recreate your setting from the template.</li>
</ul>
<p>Troubleshooting Tips.</p>
<ul>
<li>First determine where you are broken.</li>
<li>Turn on verbose logging at VDS and see if HCM is even connecting.</li>
<li>If you are connecting to VDS but no data is reaching the Identity Store then check the LDAP extract for misspellings.   One error in your path and the whole thing breaks.</li>
<li>If VDS shows database errors then check the error logs in the identity center for problems with the task configuration</li>
</ul>
<p>Finally, because HCM does not support event triggers &#8212; which can be tricky &#8212; I usually filter at HCM LDAP report for the data I want.  In most cases a nightly run is sufficient.  SAP recommends a full upload every time but this is not practical for large numbers of employees.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/607/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=607&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/06/11/hcm-and-netweaver-identity-management-integration-tips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">gdippold</media:title>
		</media:content>
	</item>
		<item>
		<title>Application Centric Identity?</title>
		<link>http://sgciam.wordpress.com/2009/06/09/application-centric-identity/</link>
		<comments>http://sgciam.wordpress.com/2009/06/09/application-centric-identity/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 07:23:49 +0000</pubDate>
		<dc:creator>mattpollicove</dc:creator>
				<category><![CDATA[IAM General]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[enterprise risk]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[Provisioning]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk control]]></category>
		<category><![CDATA[unstructured data; semi-structured data;]]></category>

		<guid isPermaLink="false">http://sgciam.wordpress.com/?p=604</guid>
		<description><![CDATA[I&#8217;ve been listening / reading to information lately on &#8220;Application Centric Identity &#8221; and how it&#8217;s supposed to be the new wave in Identity Management.  Frankly I&#8217;m a bit confused.
Basically it sounds like what&#8217;s being discussed is the creation of an authoritative store, something I&#8217;ve been working with in Identity Management for about 5 years [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=604&subd=sgciam&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;ve been listening / reading to information lately on &#8220;Application Centric Identity &#8221; and how it&#8217;s supposed to be the new wave in Identity Management.  Frankly I&#8217;m a bit confused.</p>
<p>Basically it sounds like what&#8217;s being discussed is the creation of an authoritative store, something I&#8217;ve been working with in Identity Management for about 5 years now.</p>
<p>The &#8220;newness&#8221; to this offering seems to be the implementation of SOA / Web-services architectures to make it more interesting and accessible to authentication / authorization services.</p>
<p>I&#8217;ve always felt that by gathering the authoritative attributes from each enterprise repository and linking them together in an authoritative store (metadirectory) you create the clearest picture of what each identity &#8220;looks&#8221; like.  Furthermore, these authoritative entries can then be used as the basis for provisioning new application entries and update existing ones.</p>
<p>To me it seems like the backers of this school of thought are finding a new way to talk about the integration of Enterprise level ERP systems with Identity Management.  This is not a bad thing.  The one thing we need to do is break out of the idea that Identity Management is solely provisioning or Access Management. One without the other is worse than useless given the potential for malicious behavior.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sgciam.wordpress.com/604/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sgciam.wordpress.com/604/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sgciam.wordpress.com/604/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sgciam.wordpress.com/604/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sgciam.wordpress.com/604/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sgciam.wordpress.com/604/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sgciam.wordpress.com/604/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sgciam.wordpress.com/604/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sgciam.wordpress.com/604/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sgciam.wordpress.com/604/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sgciam.wordpress.com&blog=3969875&post=604&subd=sgciam&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sgciam.wordpress.com/2009/06/09/application-centric-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">mattpollicove</media:title>
		</media:content>
	</item>
	</channel>
</rss>