Security Conference 2009 : Present and Future of IAM

03-Dec-2009

Evolutions of Access Control and Identity Management

A two day conference on the Present and Future of Access Control, IAM and Identity Management : Identity and Access Management, Identity Lifecycle management, Single Sign On, eID developments, Physical and Logical Access Control, Federated Identities, Multi-factor Authentication, … : presentations, customer cases, technology focus, market developments, panel discussions, …

This event is made possible with the kind support of our partner :


Secur-IT



Governance, Risk and Compliance continue to be the main drivers for Identity and Access Management installations and services, according to a recent survey by KPMG and Everett. Some of these projects are becoming increasingly of strategic importance to many companies, not only to be able to control the identities, but increasingly to facilitate all sorts of activities.
During this two-day conference, we aim to bring together most of the important players and projects from 2009 and try to present a glimpse on the next year in terms of IAM activities.


The objective of this conference will be to :
- Update the evolutions and developments in de Belgian market and abroad on IAM
- Present customer cases and market experiences
- Give insight in the most interesting evolutions and challenges in today’s market environment
- Give insight on how IAM could be valuable in the current economic climate
- Federation
- Concerns on privacy protection
- 11 million eID’s, so what’s next
- …

With a special focus on convergence : where physical and logical identities meet.
- Governing risk and compliance both logical and physical access
- Single sign on in applications, Multiple entries in reality

Some other topics to be addressed :
- Identities in the Cloud
- IAM and ILM


Physical and Logical Access Control Combined : a world of converging technologies

For reasons of cost reduction, economies of scale, control or just ease of use, an increasing number of companies are considering the use of the same access control system (or at least integrated) between physical and logical access control. Considerations for using the same token (RFID card, biometrics, password, ...) have already been implemented over the last years.


What considerations are companies following to have a joint or integrated system for both? Who should be in charge of those systems : facilities, security management, HR, IT, or both? What is the basic business case, and how should we see the evolutions of such systems? Are there ways to integrate my access control system with my Identity Management System(s), should I prepare this in my IAM business case?


Identities in the Cloud

Security in the cloud is a significant concern, and requires fresh thinking about how siloed security frameworks can be modified to deal with an emerging compute model. Identity management vendors have been wrestling for some time with the transition toward a loosely coupled architecture based on a set of common standards. This transition will gain pace as enterprises look to take advantage of the cost efficiencies and flexibility of cloud services yet still maintain a set of appropriate access controls and event monitoring to satisfy compliance requirements.


Federated Identities

New evolutions of Role based access, such as ABAC (attribute based access control), CBAC (context based) have appeared. Also locally, Federated Identity Systems have seen the light in 2009. Who has access to what, who is who, and who verified who? When is who giving access to what? Why has who access to what? Who controls who should have access to what? Who controls that access, or when does he or she have access?


Federation takes these questions and concerns a step further; Either putting the who in charge, or the organisation controlling the who.


IAM and ILM

From a perspective on storing and retrieving information in the world of Information Lifecycle Management (ILM) to a world of access to information, systems, applications and even access to building, rooms, doors, ... from the world of Identity and Access Management (IAM).

Managing and storing information is a practice that was there long before computer even existed. Allowing access to those electronic data, storing vast quantities of data, meeting regulatory requirements for retention and protection and deciding upon critical and sensitive information that might require another risk management profile than regular data is a challenge for any organization both from a business and an IT perspective.


Learn from the leaders in Identity and Access Management services and solutions

According to Forrester worlds of Data Governance And Content Governance will collide. Ownership, accessibility, availability, trustworthiness, security, and compliance are problems faced on both the structured and unstructured sides of the information management coin. The organizational methodologies for governing structured data and unstructured content are actually quite similars. Maximize the potential value of a governance investment with a methodology that can get you started without forcing you to break the data/content siloes.

Final Program

Thursday, December 3rd

9.00 : Welcome & Registation
9.40 : Introduction & Opening Notes by Ulrich Seldeslachts
9.50 : Keynote Opening Presentation by . Peter Strickx, FEDICT : 10 million eID’s and kids ID’s, so now what?

By the end of 2009, there will be about 9 million electronic ID’s and numerous kids ID’s. This makes Belgium one of the leading countries in the world having this unique identifier as technology.
What are the next steps? What type of applications can be used and how should it be considered by business as a means to authenticate or to get access to systems and infrastructures.

10.35 : Results of the KPMG Identity and Access Management Survey 2009 by Benny Bogaert, KPMG

In 2009, KPMG and Everett with the support of EEMA and LSEC, organized the yearly interactive survey on Identity and Access Management.
With a clear development towards Governance, Risk and Control, also the economical climate have obviously had its impacts on the current situation. How do you relate that into your organisation and what are the key learnings of the study?

11.20 : Coffee Break

11.40 : Putting the User back in Charge over his Idenity, A case for User Centric IDM by John Harrison, Edentity

The Personal Information Brokerage (PIB). Working in collaboration with three UK universities, a large telco, and payment systems company,PIB envisages that an individual will be able to select one or more ‘information brokers’ from a managed market. Each broker will enable the individual to authenticate to, and communicate with, multiple organisations and other individuals (jointly counterparties), all at the appropriate level of security and using a coherent set of authentication steps.
As well as single-sign-on, and the various communication tools, the broker will enable the individual to give fine-grained transaction-based permission for the transmission of personal information to, and between, counterparties. It can be thought of as a grown-up and distributed version of social networking: the individual can invite new counterparties to ‘link’ to his broker account; and can then decide which ‘profile’ a new counterparty should see.

12.30 : Lunch Break

13.15 : Use Case with KBC : using multiple authentication methods on the same website with Webseal and trustbuilder C-Man, combining both Vasco Digipass, DIgipass Card Reader, smartcard and usb X.509 certificates by Dirk Verbiest, KBC

14.05 : Security and the essential role of IAM in the Cloud by John Van Westeneng, Traxion

What is the role of IAM in the cloud. Besides the standard federated components for amongst other single sign on, provisioning of identities, but also of access rights play a giant role in facilitating enterprise cloud services. Next to that, the following themes will be discussed :

- the strategic steps an organisation had to make to start using cloud services,
- the business case for the use of cloud services including the required infrastructures,
- the suppliers of service providers and what could not yet work as such
- the security elements that need (and need not) to be resolved

15.00 : Access Governance by Joris Ter Hart, KPMG

Access control is one of the key control mechanisms in place to protect sensitive (financial) information. Due to the economic crisis, information breaches through misusing access rights are increasing. Also the regulations around managing user access are getting stricter and an organisation has to proof that access controls are operating effectively. Validation of access rights is not completely new. In rather every organisation some kind of verification of access rights is implemented. However this is often done on an ad-hoc basis in a manual manner with a limited scope and profundity.Access Governance is an efficient process, with use of advanced analytics tools, to review user access to and within applications on a frequent basis to achieve regulatory compliance and improved security. In the presentation Access Governance will be elaborated in detail based on a case study and also the relationship with Identity & Access Management as a whole will be discussed.

15.55 : Closing Notes

16.00 : End of Day 1

Friday, December 4th

9.00 : Welcome Coffee & Registration

9.45 : Opening Notes by Ulrich Seldeslachts, CEO LSEC

10.00 : Convergence of Physical and Logical Identities, by Thomas van Vooren, Everett

Increasingly, the security of IT-services and the physical security of spaces and environment are being seen combined. Where traditionally the one the environment is of IT, the other a facility service, today often combined access means, monitoring and security models are being used. During this talk, some of the more important drivers of this development will be discussed, as well as the architectre including a central place for Identity and Access Management.
Finally, some examples will be discussed.

10.50 : Case Study : How a logical IAM systems had been implemented to ensure physical and logical access control, by Rik van Bruggen, EMEA VP Imprivata

11.40h : Physical Access Control in reality, an evolution in the world of access control, by Michael Andauer, KABA

12.20h : Lunch Break

13.00h : Discussion : ILM & IDM, the next challenge Identity in the Cloud and Federated models with SUN Microsystems

13.45h :  Securing Web Services in the Cloud, by Jan Van den Bergh, ACA-IT

The rise of Software as a Service (SaaS) leads to some interesting security problems. Moving infrastructure, applications and services to the cloud holds many benefits, but also introduces some interesting security challenges. The organization’s trust boundary is greatly extended and moves beyond the control of IT. This results in loss of control that challenges established governance and control models, and can even impede the adoption of cloud services. A well established IAM system becomes an essential component for a smooth transition to the cloud. For service providers, the use of industry IAM standards can greatly accelerate the adoption of new cloud services.
Federation protocols (SAML, ID-FF) can be used to solve the security problems that have to do with authentication and authorization: it then becomes possible to integrate web applications of different organizations and let users access them while their identity is passed automatically. Web services can be protected in a similar way, by adding assertions to the messages to guarantee the identity of the caller. Typically a Secure Token Service or STS is used to generate and validate the tokens containing these assertions, but other solutions exist as well.
In this presentation we will describe these concepts in more detail and tell you how they can be used in real-life applications. There will also be a small demo where Sun OpenSSO is used for federation and web service security.

14.30h : Centralizing authentication and authorization in a Unix World, by Wim Remes, Bull

Does an out of the box solution solve the the objective of having several flavours of machines and OS-es working integratedly together in an SSO? Or is there a better fit with totally integrated model based upon Open Source?

15.05h : STORK, the European eID Interoperability Platform by Marc Stern, Approach

The aim of the STORK project is to establish a European eID Interoperability Platform that will allow citizens to establish new e-relations across borders, just by presenting their national eID.
Cross-border user authentication for such e-relations will be applied and tested by the project by means of five pilot projects that will use existing government services in EU Member States. In time however, additional service providers will also become connected to the platform thereby increasing the number of cross-border services available to European users.

Thus in the future, you should be able to start a company, get your tax refund, or obtain your university papers without physical presence; all you will need to access these services is to enter your personal data using your national eID, and the STORK platform will obtain the required guarantee (authentication) from your government.

15.45h : Closing Notes

16.00h : Close of Conference

Advanced Role Based Access Mechanisms and Information Access Management : the perspectives from the user and the organization
Information Lifecycle Management : the perspectives from the data and information flowing in the organization.
Information Risk Management (IRM) in relation to Information Lifecycle Management
What is the impact of the lifecycle of information on Identity and Access Management (IAM)
Identity Enabled Information Lifecycle Management
The needs for Information Lifecycle Management : compliance, cost & control
The needs for Identity & Access Management : compliance, cost & control
Data Protection and ILM
Frameworks for considering and planning data protection
Understanding storage technology from the standpoint of data protection
Architecting more effective backup/restore solutions
Leveraging core computer security concepts and strategies to protect your most critical data
Securing your entire storage infrastructure, not just servers
Using policy-driven data protection and Data Lifecycle Management (DLM) to improve security and reduce cost
Using ILM to identify your highest-value data and choose the right ways to protect it

Information lifecycle management (ILM) entails the process of managing information from conception until disposal, in a manner that optimizes storage and access at a cost, relative to its value. Especially predicting the way people need to access information and define storage needs could be challenging as the business grows.
If the current economical climate doesn’t allow for massive investments and companywide projects, for any organization it remains sensible to investigate the impact of its information management systems and to consider potential future evolutions and trends. During this seminar the aim is to explore the evolutions of managing the lifecycle of information not only from an access perspective, but also from a storage and control perspective even over time. How to start taking both into account from the beginning? How to define where both concepts will be challenged at the same time? Or can they continue to be separated programs in your company?

Bring a colleague or friend and attend for free

With this event, again we want to create awareness on the evolution of Idenity and Access Management in Belgium and abroad.

If you send us an email with the forwarded invitation (securityforum2009 @ lsec.be), or copy us in the forwarded invitation to a colleague of your organization, or maybe a friend at another organization, you will be allowed free access to this event.
Alternatively, the access fee for 1 day seminar is 150 € (excl VAT), and 250 € (excl. VAT) for the combined days.

Practical Details

150 € (excl. VAT) for 1 day, 250 € (excl. VAT) for 2 days.
Free upon presentation prior to the event of the forwarded invitation.


Grotere kaart weergeven



For more information about this event, please email to securityconference2009 @ lsec.be or

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< September 2010 >>

S M T W T F S
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 1 2

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Bluekrypt

Security Expert in Crypto, Information Security and Training

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: arrowUp

arrowUp - member of the Lykos Group

Expert: Research In Motion - RIM - Blackberry

Research In Motion - RIM - Blackberry

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: Traxion

Traxion - Identity Management - cornerstone for your company

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: Approach

Approach specializes in Application Security, Identity Management and financial transactions.

Expert: Global Knowledge

Global Knowledge is the worldwide leader in IT and business training.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Novell

Comprehensive Identity, Security and Systems Management Solutions.

Expert: Exclusive Networks

Value added Distributor specialized in information security. Operational in Belgium, France, Switzerland and Luxemburg.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: D Soft

D Soft is an expert in electronic distribution of digital documents.

Expert: Scanit

Scanit is an IT security boutique specializing in ethical hacking, penetration testing, vulnerability assessments and security configuration reviews.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: Microsoft

At Microsoft, we're motivated and inspired every day by how our customers use our software to find creative solutions to business problems.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: Intesi

Intesi Belgium is the R&D competence center of Intesi Group, focusing on Internet Security, using state-of-the-art ICT technologies.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Cisco

Cisco Internet Protocol (IP)-based networking solutions are the foundation of the Internet.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: BT - British Telecom

One of the world's leading providers of communications solutions.

Expert: Alcatel Lucent

Alcatel provides communications solutions to telecommunication carriers, Internet service providers and enterprises for voice, data and video.

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: IBM

A world leader in Information Technology with a large professional organization in Belgium and a series of security experts.

Expert: Norkom Technologies

Norkom is a market-leading provider of innovative financial crime and compliance solutions to the global financial services industry.

Expert: Telindus

Telindus has expertise in all aspects of modern telecommunications technology, including LAN, WAN, Internet and e-networking, network access and security, VOIP (Voice over Internet Protocol), VPN, fixed and mobile communications.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.