In the last article, we discussed how to establish appropriate challenge questions to facilitate password self-service. But that’s just half of the password self-service equation. The other half has to do with initial passwords, which is the topic of this article. Initial passwords All users are assigned an initial password of some sort, which must [...]
Building the Foundation for Successful Password Self-Service Part 4: Initial Passwords
Building the Foundation for Successful Password Self-Service Part 3: Challenge Questions
So far we have established the value of properly implementing password self-service and successfully tackled building effective password governance. The next step is to develop “challenge questions.” Challenge questions – definitely a double-edged sword A key benefit of any password self-service system is the “forgot password” feature. If a user forgets their password, they click [...]
Building the Foundation for Successful Password Self-Service Part 2: Password Governance
In my last article, we explored how a properly implemented password self-service mechanism can yield a quick and early return on the identity management journey. Password self-service is a cornerstone in the foundation for reduced sign-on (which is essentially what SSO promised to be). But before we jump in on the password self-service technology, let’s [...]
Building the Foundation for Successful Password Self-Service: Part 1
Note from Michael: this month we’re going to try something different with this series by breaking the articles up into smaller chunks and serve them on a weekly basis. Same series, same great content, delivered in smaller chunks. Cool? By now, you’re so sick of userID cleanup that you’re probably wondering why you didn’t select [...]
Data Cleanup Part 2: Other UserIDs
By: Ioana Bazavan Justus Did last month’s exercise of mapping primary userIDs kill you? Is it still killing you? Unless a number of full-time resources were allocated on a project basis, the cleanup for a large organization can easily take months to complete so if you’re still working on it, don’t worry – you’re not [...]
Data Cleanup Part 1: Primary UserIDs

Welcome to the February issue of Identity Management in 13 Easy Steps. In most parts of the country the weather is cold and dreary, and what better weather for an ID cleanup? So roll up the sleeves, find the glasses, and brew a lot of extra-strong coffee – it’s time to tackle those primary userIDs. [...]
Driving Compliance: What We Have versus What We Need

By Jim McFee A common statement an auditor hears is, “our IT department is mature; we have everything we need for an IT Audit.” A common thought an auditor thinks is, “yeah, right.” So which of these statements is more accurate? More importantly, which one increases or decreases risk? Without creating a laundry list, let’s [...]
Prioritizing Systems Integrations

Avoiding the biggest mistake The biggest mistake that identity management implementers make is biting off way more than they can chew – we all have grandiose ideas of integrating all of the company’s systems and fully automating them, too! It never sounds that hard when the team is sitting around the conference room table, excitedly [...]
The First Brick: Understanding Identity Management
What is Identity Management? Identity Management (IDM), or Identity and Access Management (IAM), is a suite of products that work together (more or less cohesively) to manage users and their access/passwords across the enterprise. Most identity management product suites consist of three or sometimes four parts: - Role manager - Identity manager - Access manager [...]
Amplifying the Good: The Security Catalyst Online Experience 2010
As the snow starts to cover the ground in Upstate New York, my thoughts are already turning to the year ahead. I’m not at all disenchanted with the Holidays; I’m just excited about the journey ahead with the Catalyst onTour RV adventure. Equally exciting to me is the programming that will be presented by the [...]
Engage with Michael