<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Jim Phelps &#187; CIC</title>
	<atom:link href="http://jimphelps.info/tag/cic/feed/" rel="self" type="application/rss+xml" />
	<link>http://jimphelps.info</link>
	<description>Enterprise Architect , IT Architect in Madison, WI</description>
	<lastBuildDate>Fri, 02 Dec 2011 16:47:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='jimphelps.info' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Jim Phelps &#187; CIC</title>
		<link>http://jimphelps.info</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://jimphelps.info/osd.xml" title="Jim Phelps" />
	<atom:link rel='hub' href='http://jimphelps.info/?pushpress=hub'/>
		<item>
		<title>Break Out Tables at CIC Identity Management</title>
		<link>http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/</link>
		<comments>http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/#comments</comments>
		<pubDate>Thu, 08 Jun 2006 13:44:37 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Work]]></category>
		<category><![CDATA[CIC]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/</guid>
		<description><![CDATA[There were two break out sessions at the CIC Identity Conference. The first was a breakout By Peer Groups. In this break out, Registrars sat together, CIOs sat together, etc. I was in the IT Idenity Management peer group. There were strong themes that came up during this discussion. Interestingly, the strongest themes were around: &#8230; <a href="http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/">Continue reading <span class="meta-nav">&#187;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=113&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There were two break out sessions at the <a href="http://www.cic.uiuc.edu/groups/CIOs/archive/ConferencePresentation/IdentityManagementConference2006/home.shtml">CIC Identity Conference</a>.</p>
<p>The first was a breakout <strong>By Peer Groups</strong>.  In this break out, Registrars sat together, CIOs sat together, etc.  I was in the IT Idenity Management peer group.  There were strong themes that came up during this discussion.  Interestingly, the strongest themes were around:</p>
<ul>
<li>Governance &#8211; how do you establish it on campus, how do you get buy in, who should be on the governance board, </li>
<li>Communication &#8211; the need for a common vocabulary for communicating with campus about Identity Management.</li>
<li>CAF <a href="http://www.cio.gov/eauthentication/documents/TCSPlist.pdf">Credential Assessment Framework PDF</a> &#8211; Especially as a tool to find gaps in the infrastructure and as a communication tool with campus.  If the campus want&#8217;s to use FASTLANE and NIH Grants and other applications, we will have to fill these gaps that are identified in the CAF Process.  </li>
<li>Mapping of Levels of Assurance to Risk Assessments for various applications.  Development of a Framework to map LOAs to <a href="http://www.cio.gov/eauthentication/era.htm">Risk Levels </a>for Applications. </li>
</ul>
<p><span id="more-113"></span></p>
<p>It is interesting that the Technologists didn&#8217;t list a bunch of technologies.  There concerns were mostly around communication, governance and policy.</p>
<p>We then had a break-out by University.  Each University would then gather and discuss what they had learned, their concerns, their thoughts on what their next steps should be.  From the <strong>University of Wisconsin &#8211; Madison break-out</strong>, I had the following list (which aligns with the list that we presented but isn&#8217;t exactly the same):</p>
<ol>
<li>Doing a CAF analysis and obtaining level 1 of LOA </li>
<li>Building a business case for Identity Management for campus.  (Note:  I believe that the CAF process can feed into the business case) </li>
<li>Tracking the Federal eAuthentication, CAF, Federal Identifier and other initiatives.  We need to keep up with the Federal initiatives and changes and to communicate those changes with campus </li>
<li>Build out of Identity Management infrastructure (specifically our PASE initiative which manages Groups and Entitlements). </li>
</ol>
<p><strong>Report out from all of the Universities:</strong></p>
<p>Common threads were:</p>
<ul>
<li>Establishing Governance, building a common vocabulary and Funding and Prioritization and Staffing. </li>
<li>Going through some version of the CAF process (maybe not bringing in the OMB but working through the analysis internally). </li>
<li>Dealing with &#8220;Privilege Bloat&#8221; &#8211; users accumulating access as they move around campus and change jobs</li>
<li>Federating with Federal Government especially around Research. </li>
<li>Separating Authentication from Authorization.</li>
<li>Education of the population &#8211; how to protect their own data and the institutional data.</li>
<li>How to serve affiliated populations &#8211; like distance ed, research collaborators, etc</li>
<li>2-factor Authentication came up at U-Minn. </li>
<li>Look at joining inCommon which will push people to document what they do.</li>
</ul>
<p><em>Next Steps</em></p>
<ol>
<li>Each University submit their summary / prioritized list so that they can be published as a group</li>
<li>The Universities that are going through the CAF process would like to gather to compare notes</li>
<li>Work together and join InCommon so we can federate with each other and to show vendors that we think this is important</li>
<li>Sharing notes on Governance &#8211; especially those who are building new governance structures &#8211; what are you trying, how is it going, documentation that might be sharable and adaptable</li>
<li>Should there be a regular CIC Identity Management Meeting?  Take this up via email and the CIC CIOs planning group</li>
<li>Generate common requirements for software that we could use with vendors.  Note: there are two flavors of this:  (1) What the software should do now and (2) what the vendors should be working towards.  The second is where the CIC might want to focus</li>
</ol>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/113/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/113/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=113&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2006/06/08/break-out-tables-at-cic-identity-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
		<item>
		<title>CIC Identity Managment &#8211; Federated Identity and Sharing Resources</title>
		<link>http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/</link>
		<comments>http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/#comments</comments>
		<pubDate>Mon, 05 Jun 2006 18:45:38 +0000</pubDate>
		<dc:creator>jimphelps</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[CIC]]></category>
		<category><![CDATA[Federation]]></category>
		<category><![CDATA[IdentityManagement]]></category>

		<guid isPermaLink="false">http://www.jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/</guid>
		<description><![CDATA[Session Details This panel session discussed Federated Identity Management and Sharing Resources. The slides are here as a PDF I was the moderator for the session. The panelists were: Kevin Morooney, PSU, Senior Director, Academic Services Kenneth Forstmeier, PSU, Director Office of Research Information Systems Mike Grady, UIUC, Sr. Technology Architect &#38; Strategist Phyllis Davidson, &#8230; <a href="http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/">Continue reading <span class="meta-nav">&#187;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=111&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Session Details</strong></p>
<p>This panel session discussed Federated Identity Management and Sharing Resources.  The slides are <a href="http://arch.doit.wisc.edu/jim/wp-content/uploads/2006/06/CICFederatedIdM.pdf">here as a PDF</a></p>
<p>I was the moderator for the session.  The panelists were:</p>
<ol>
<li>Kevin Morooney, PSU, Senior Director, Academic Services</li>
<li>Kenneth Forstmeier, PSU, Director Office of Research Information Systems</li>
<li>Mike Grady, UIUC, Sr. Technology Architect &amp; Strategist</li>
<li>Phyllis Davidson, IU, Interim Assistant Dean for Digital and I.T. Services</li>
</ol>
<p>Below are the highlights that I took away from the panel.</p>
<p><span id="more-111"></span></p>
<p><em>Kevin Morooney</em></p>
<p>Penn State University (PSU) has moved along way down the identity management roadmap.  They have two levels of internal authentication with their WebAccess for most applications and SecureID for higher level of assurance applications.  They are using Shibboleth to handle federated IdM with several outside service providers.</p>
<p>Kevin lists many of the Web2.0 applications (like Flickr, Wikis et al) as an interesting case that we need to think about.   Much of our students and faculty are using these applications.  Should the University provide a federated IdM process for their faculty and students to access these applications?  Which ones should be brought in house?</p>
<p><em>Kenneth Forstmeir</em></p>
<p>Researchers interacting with the federal government need to manage dozens of user accounts and passwords.  Each of the applications that they use have their own username/password pair and their own policies regarding password change policies.  The researcher cannot synchronize their usernames across these systems.  Federation would help with part of this problem but the solution must include a method for researchers to maintain their account information when they change institutions.  The researcher must be able to remap their identity with the government to a new set of credentials.</p>
<p><em>Mike Grady</em></p>
<p>UIUC started looking at using Shibboleth for library content &#8211; specifically content providers like Elsevier et al.   The contracts with the content providers are often based on a fixed set of IP addresses and they are often for multiple years.  The change to federation would allow UIUC to move groups to new IP ranges.  The change to a federated system would cause users to log in to resources which they were used to accessing automatically (because they were in the IP address range).</p>
<p>UIUC also uses federation intra-institutional.  Federation technology (like Shibboleth) can be used inside the institution to federate between separate identity management systems.</p>
<p><em>Phyllis Davidson</em></p>
<p>Phyllis presented several interesting use cases for federated identity management.  One of which is &#8220;Chat Reference&#8221;.  The library provides reference support via chat 24 hours a day.  They would like to be able to share the resources with other libraries.  Each library would provide some hours of support but be able to reduce their overall cost.  Other use cases involve Digitized Collections which could be hosted at various institutions but shared amongst the whole.</p>
<p>IP based access does not let you control levels of access based on Roles.  This is another thing that would come with federated identity and access management.</p>
<p><em>The Q and A </em></p>
<p>Where do Help Desk Questions go?  When a user can&#8217;t log in to a resource, who do they call?  How do they know who to call?  This is negotiated in the SLA between the Service Provider and the Identity Provider.  Scott Cantor states that it must be the Service Provider first.</p>
<p>The legal agreements between the Service Provider and Service Consumer need to include agreements about how help desk issues will be dealt with.  This agreement then needs to be communicated to the end users so they know who to call.</p>
<p>JimPhelps, ITArchitect, IT-Architecture, IdM, IdentityManagment,</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/jimphelps.wordpress.com/111/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/jimphelps.wordpress.com/111/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/jimphelps.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/jimphelps.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/jimphelps.wordpress.com/111/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=jimphelps.info&amp;blog=228285&amp;post=111&amp;subd=jimphelps&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://jimphelps.info/2006/06/05/cic-identity-managment-federated-identity-and-sharing-resources/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b30db657c63fbfc0b146d3da24a0ecfb?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jimphelps</media:title>
		</media:content>
	</item>
	</channel>
</rss>
