Presenter(s): Candace Soderston Matt Sargent Bill Yock Date:November 16, 2011 Time:2:30 to 3:30 pm Help Shape the Future of Open Source Identity and Access.

Slides:



Advertisements
Similar presentations
National HIT Agenda and HIE John W. Loonsk, M.D. Director of Interoperability and Standards Office of the National Coordinator Department of Health.
Advertisements

CRI- Common Review Initiative Reducing Lender Review Redundancy.
June 10-15, 2012 Growing Community; Growing Possibilities Benn Oshrin, The Oshrinium, LLC Keith Hazelton, UW-Madison, Internet2 CIFER Community Identity.
Course: e-Governance Project Lifecycle Day 1
The Internet2 NET+ Services Program Jerry Grochow Interim Vice President CSG January, 2012.
Presenter(s): Candace Soderston Matt Sargent Bill Yock Date:November 16, 2011 Time:2:30 to 3:30 pm Help Shape the Future of Open Source Identity and Access.
Bill Yock University of Washington Coordinating Education and Research Communities to radically improve Identity and Access Management. Shel.
Federal Student Aid Technical Architecture Initiatives Sandy England
On Privacy-aware Information Lifecycle Management (ILM) in Enterprises: Setting the Context Marco Casassa Mont Hewlett-Packard.
July 12, 2005 CSU SIMI Workshop - Melding Policy and Technology to Manage Identity1 Provisioning Services Collaborative CSU, East Bay and CSU, San Bernardino.
Identity and Access Management IAM. 2 Definition Identity and Access Management provide the following: – Mechanisms for identifying, creating, updating.
Creating a Secured and Trusted Information Sphere in Different Markets Giuseppe Contino.
1 Data Strategy Overview Keith Wilson Session 15.
Presenter(s): Candace Soderston Matt Sargent Bill Yock Date:November 16, 2011 Time:2:30 to 3:30 pm Help Shape the Future of Open Source Identity and Access.
Siebel CRM On Demand – MHC Network Express Integrated Solution.
April 2, 2013 Longitudinal Data system Governance: Status Report Alan Phillips Deputy Director, Fiscal Affairs, Budgeting and IT Illinois Board of Higher.
Aegis Identity Software, Inc. presents Trends in Identity and Access Management in Higher Education to US Federations June 20, 2012 Janet Yarbrough – Director.
Candace Soderston & Matt Sargent ARC/TRC meeting Indiananapolis, Indiana November 18, RICE UX & BA REPORT-- INPUT FROM INSIDE & OUTSIDE THE KUALI.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
OSIAM4HE Proposed org structure Authored by the strategy and organization team.
Candace Soderston & Matt Sargent Collab team meeting December 12, RICE UX & BA REPORT-- INPUT FROM INSIDE & OUTSIDE THE KUALI COMMUNITY.
County of San Diego Acute & Long-Term Care Integration Project (ALTCI) — Information Technology Assessment Findings and Recommendations June 22, 2005.
AAF Middleware update February Presented by Terry Smith Technical Manager and Heath Marks Manager.
Demystifying the Business Analysis Body of Knowledge Central Iowa IIBA Chapter December 7, 2005.
- 1 - Roadmap to Re-aligning the Customer Master with Oracle's TCA Northern California OAUG March 7, 2005.
Open source administration software for education software development simplified Kuali – IDM Requirements Summary Eric Westfall - Indiana University Matt.
SALSA-NetAuth Joint Techs Vancouver, BC July 2005.
INTEGRATION WITH OTHER IDM SOLUTIONS Remember… The primary goal of KIM was to build a service- oriented abstraction layer for Identity and Access Management.
EMI INFSO-RI SA2 - Quality Assurance Alberto Aimar (CERN) SA2 Leader EMI First EC Review 22 June 2011, Brussels.
IAM REFERENCE ARCHITECTURE BRICKS EMBEDED ARCHITECTS COMMUNITY OF PRACTICE MARCH 5, 2015.
KUALI IDENTITY MANAGEMENT Provides services for Identity and Access Management in Kuali Integrated Reference Implementations User Interfaces An “integration.
Page 1Prepared by Sapient for MITVersion 0.1 – August – September 2004 This document represents a snapshot of an evolving set of documents. For information.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
Top Issues Facing Information Technology at UAB Sheila M. Sanders UAB Vice President Information Technology February 8, 2007.
UCLA Enterprise Directory Identity Management Infrastructure UC Enrollment Service Technical Conference October 16, 2007 Ying Ma
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
Assessment of Portal Options Presented to: Technology Committee UMS Board of Trustees May 18, 2010.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Considering Community and Open Source Lois Brooks Stanford Terry Ryan UCLA A Decision Framework for Selecting.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
June 10-15, 2012 Growing Community; Growing Possibilities Dedra Chamberlin, UCSF/UC Berkeley Eric Westfall, Indiana University.
Presenter(s): Candace Soderston, Rice User eXperience Architect Matt Sargent, Rice Business Analyst Date:November 16, 2011 Time:1:15 to 2:15 p.m. Creating.
The Impact of Evolving IT Security Concerns On Cornell Information Technology Policy.
State of e-Authentication in Higher Education August 20, 2004.
E-Authentication in Higher Education April 23, 2007.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Imagining a Community Source Student Services System Leo Fernig Richard Spencer SOA Workshop Vancouver March 24, 2006.
CIFER (Community Identity Framework for Education and Research) Overview for Prospective Contributors ciferproject.org Bill Yock Director, Enterprise Information.
Systems Accreditation Berkeley County School District School Facilitator Training October 7, 2014 Dr. Rodney Thompson Superintendent.
Information Security IBK3IBV01 College 3 Paul J. Cornelisse.
KIM: Kuali Abstraction Layer for Identities, Groups, Roles, and Permissions.
University of Washington Collaboration: Identity and Access Management Lori Stevens University of Washington October 2007.
Portal Services & Credentials at UT Austin CAMP Identity and Access Management Integration Workshop June 27, 2005.
State of Georgia Release Management Training
1 CREATING AND MANAGING CERT. 2 Internet Wonderful and Terrible “The wonderful thing about the Internet is that you’re connected to everyone else. The.
Kuali Identity Management: Introduction and Implementation Options Jasig - Spring 2010 Wednesday, March 10, :30 am.
INTRODUCTION TO IDENTITY FEDERATIONS Heather Flanagan, NSRC.
Quarterly Customer Meeting Office 365 License Activation and Office 365 Cloud Services Assessment Status April 2014.
Building a Public Health Informatics Division. OSDH Public Health Informatics Division Identify the needs Develop the proposal Establish division Reality.
OpenRegistry MACE-Dir 5/18/09 1 OpenRegistry Initiative Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University May 2009.
OpenRegistry Jasig Dallas OpenRegistry Initiative Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University March 2009.
OpenRegistry LSM 10/7/09 1 OpenRegistry Revisiting the Management of Electronic Identity Benjamin Oshrin Rutgers University July 2009.
FIFER Jasig May FIFER: The Free Identity Framework For Education and Research: Blackened Swan Benjamin Oshrin The Oshrinium LLC.
OpenRegistry: What’s New Jasig San Diego 3/10 1 What’s New With OpenRegistry Scott Battaglia Benjamin Oshrin March 2010.
Innovative Solutions from Internet2
InCommon Steward Program: Community Review
ESA Single Sign On (SSO) and Federated Identity Management
Kuali Student: Student System Solutions Already Making a Difference
Module 1.4 Vision for the Master Facility List
Presentation transcript:

Presenter(s): Candace Soderston Matt Sargent Bill Yock Date:November 16, 2011 Time:2:30 to 3:30 pm Help Shape the Future of Open Source Identity and Access Management for Higher Education

Introductions What topics do you hope we get time for during this hour? And we’ll start with a few questions for you!

Facets of Identity Management

Questions:  What software tools do you use in managing identities and access?  What do you like most about these tools? What do you like least?  What is the single-most important requirement you would look for in an identity and access management solution?

Staff at 12 Universities Responded to an IDM Survey before Kuali Days 2011 Carleton College Duke University Lehigh University MIT Ohio Northern University Rensselaer Polytechnic Institute University of Connecticut University of Iowa University of Maryland University of Saskatchewan University of Southern California University of Washington

Identity and Access Management Survey - Results For Discussion -

They rated 10 Potential Investment Areas: Person Registration and Profile Management w/Directory Delegated Administration and Self Service Identity Reconciliation Reporting and Alerts Compliance and Privacy Provisioning and De-provisioning Identity Data Workflow Connect-ability and Batch Processing/Syncing Identifier Authenticator, Group, Role, Access/Permission/Privilege, and Attribute Management Authentication, Authorization, and Single Sign-on with Presence and Location awareness

Definitions Person Registration and Profile Management w/Directory A single, central registry with tools for adding and managing person and non-person entities Identity Reconciliation Tools for administering and limiting the number of potential duplicate entries in a registry. Including tooling for identifying (matching) and consolidating (merging) duplicates Compliance and Privacy Tools to ensure information being collected adheres to various local and federal compliance and privacy handling laws, and to track access to these data Identity Data Workflow Structured processes for approval and notification of all aspects of identity management Identifier Authenticator, Group, Role, Access/Permission/Privilege, and Attribute Management Tools for defining, administering, and managing person, security, and access management attributes

Definitions continued Delegated Administration and Self Service Rich tools for centralized and self-service management for validation and updating of personal information Reporting and Alerts Reports and alerts for critical monitoring of all aspects of identity management Provisioning and De-provisioning Automated, real-time tools to expedite the setup or removal of access and permissions Connect-ability and Batch Processing/Syncing An infrastructure for communication and collaboration with existing IdM solutions as well as the ability to easily import, process, or sync data from external applications Authentication, Authorization, and Single Sign-on with Presence and Location awareness Tools and attachment points for the management and monitoring of identities and access

Do These Results Represent You?

Do These Results Represent You? (cont)

Other Data You May Be Interested In (Large study by Mark Sheehan, et.al.): See ECAR's 2011 Study of Identity Management in Higher Education (recorded July 13, 2011 at

Focus is Increasing on Identity Management? See ECAR's 2011 Study of Identity Management in Higher Education (recorded July 13, 2011 at

Comments? See ECAR's 2011 Study of Identity Management in Higher Education (recorded July 13, 2011 at

Comments? See ECAR's 2011 Study of Identity Management in Higher Education (recorded July 13, 2011 at

Comments? See ECAR's 2011 Study of Identity Management in Higher Education (recorded July 13, 2011 at

OK – Let’s Shift Gears! Work on An Open Source Identity Management Solution For Higher Education?

Open Source IdM for Higher Ed (OSIdM4HE) (a working code name) 1.The OSIdM4HE Joint Development Proposal 2.Drivers leading to the OSIdM4HE Proposal 3.Benefits and Key Differentiators of OSIdM4HE 4.What is the Status of the OSIdM4HE 5.Proposed OSIdM4HE Startup Governance Structure 6.How to participate in OSIdM4HE

Joint Development Proposal Many Higher Ed Institutions (and their community efforts like Jasig, Internet2, Kuali, etc.) have been building Identity and Access Management (IAM) solutions largely disconnected from each other. OSIdM4HE is a proposal to Join Forces to collaborate and create a diverse and comprehensive suite of IAM solutions.

Drivers Leading to the Proposal Commercial vendor contract lock ins, forced migrations Many different commercial products, hard to compare, hard to integrate Commercial products do not meet all Higher Ed requirements, costly customizations Significant expertise in this problem space within Higher Ed communities Considerable Higher Ed development already underway (Kauli KIM, Jasig CAS, Jasig OpenReg, Internet 2 Grouper, Internet2 Shibboleth, etc.)

Benefits and Key Differentiators Backed by proven, established Open Source Leaders A well coordinated and focused development effort by Higher Ed Ability to accelerate development efforts by targeting and maximizing resources of contributing members Lower Cost of Ownership (No licensing fees, community support, no binding vendor contracts) The best minds in the Higher Ed sector solving the problems together Able to leverage, build on and reconfigure existing code bases (Kauli KIM, Jasig CAS, Jasig OpenReg, Internet 2 Grouper, Internet2 Shibboleth, etc.)

What is the Status of the Proposal? Many volunteers met over the summer of 2011 to document current state and identify gaps in an overall IAM suite Four subcommittees formed: Registries, Provisioning, Access Management, Strategy and Organization A “Coordination Agreement” document was drafted which includes: Product Vision and Reference Architecture Governance Framework and Development Principles Common Configuration and Deployment Requirements Proposal being reviewed by many interested parties

Proposed Startup Governance Structure Initial work to begin around Registry and Provisioning Identity matching and resolution in the Registry Registry-to-Provisioning engine interfaces Kuali Rice targeted as “Caretaker” for Registry work and Internet2 MACE targeted as “Caretaker” of Provisioning work Caretaker organizations provide coordination and logistical support of development work and agree to long term support Caretakers for Access Management and Authentication still being discussed A startup Coordination Committee to be appointed by consensus of the initial contributing members

How to Participate Review and sign the “Coordination Agreement” acknowledging vision and strategy Review and sign the “Memorandum of Understanding” for the Registry - Identity Matching work Contribute resources towards the Registry – Identity Matching work Assume institutions already contributing to Higher Ed communities (Kuali, Internet2, Jasig, etc.) will make additional targeted contributions towards OSIdM4HE

Other Topics of interest - (from flip chart generated by the group) Group Discussion Q & A

Get Involved! OSIdM4HE Initiative Visithttps://spaces.internet2.edu/x/HpeKAQ Kuali Rice Information Visithttp://kuali.org/rice Test Drivehttp://demo.rice.kuali.org Downloadhttp://kuali.org/download-form Get Involvedhttp://kuali.org/membership Contact