安全身份管理

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

安全身份管理understandingthebigpicture广州紫光北美科技有限公司©October1,20192::::OpeningthedoortoWebservicesNovellexteNd™SecurelygettingtherightinformationtotherightpeopleNovellNsure™ThebestfoundationforyourmixedenvironmentNovellNterprise™TheexperiencetosolveyourbusinessproblemsNovellNgageNovellNsure方案把身份管理提高到一个新的层次,Novell的相关产品获得多项大奖,Novell的方案是把产品,客户以及合作模式结合的解决方案,此方案的核心是访问控制——把资源权限安全、方便、高效地分配给合理的人Novell的“一体化网络”战略SM©October1,20193Inthenexthour…1.什么是安全身份管理2.为什么人们关心这个问题3.如何解决目标企事业单位面临的安全身份管理问题©October1,20194Youcan’tunderstandasubject分而治之盲人与象©October1,20195Youalsohavetounderstand全局考虑©October1,20196Secureidentitymanagement涵盖很多内容PersonalizedUserInterfaceContentAggregationSelfServiceWebBasedAccessAuthenticationSingleSign-onRemoteAccessAuthoritativeIdentitySourcingPolicyDrivenWorkflowRoleBasedProfilingPasswordManagementAuditing&IntrusionDetection©October1,20197secureidentity分为三个主要部分ProvideaccesstoresourcesbasedonauthenticatedidentityKnowwhoyou’redealingwithDeliverservicesbasedonaperson’sroleorpreferences123accessmanagement访问管理identitymanagement身份管理personalizeddeliveryofapplicationsandcontent应用和内容的个性化分发©October1,20198exploringsecureidentitymanagement一个商务环境的例子员工B2B合作伙伴客户企业财务经济市场销售客户服务©October1,20199员工B2B合作伙伴客户财务经济市场销售客户服务Roles&responsibilitiesAcceptableuseDataclassificationsPasswordpoliciesComplianceprocedures安全策略Identity身份管理Secureidentitymanagement始于安全策略©October1,201910HRE-mailComputerPhoneWhitePages对于新的员工,一起都轻而易举.Newemployeesreceiveaccessandresourcesquickly&automatically,basedonroles&responsibilities策略:Policiesestablish哪些人可以访问哪些资源©October1,201911业务Whoareyou?Whatisyourrole?Whatdoyouneedaccessto?Accesspoliciesbasedonroles简化管理©October1,201912CustomerSupplier信任证:Trustedcredentials允许对授权的资源进行安全访问Employee©October1,201913HRE-mailComputerPhoneWhitePagesNewemployeesreceiveaccessandresourcesquickly&automatically,basedonroles&responsibilities员工离开的时候,问题也变得简单.Terminatedemployeeshaveaccessrevokedcompletely&immediatelyacrossallsystemsPoliciesalsodetermine什么时候让访问权限失效©October1,201914Novell的解决方案ofsecureidentitymanagement•Nsure–随时,随地,把需要的权限赋予需要的人.•NovellNsuresecureidentitymanagementsolutionsenableyoutosecurelyextendresourcestothepeoplewhopoweryourbusiness,leveragingyourcurrentsystems−跨平台−基于单一业务过程−基于工业标志•Combinationofourdirectory,meta-directory,provisioning,accessmanagement,andProfessionalServicescapabilitiesNsure©October1,201915NAMDirXMLTheNovellproductsthatpowerNsuresolutionsNovellNsureSecureIdentityManagementNetDirectoryHostNT/2000/XPCustomersPartners/SuppliersWebServersNAMNsureResourcesEmployeesSecureLoginBorderManageriChainDirXML©October1,201916SecureIdentityManagement1.什么是安全身份管理2.为什么人们关心这个问题3.如何解决©October1,201917分析家:sayweshouldallcareaboutSecureIdentityManagement“Whilewestillexpectareturnto3Agrowthfromincreasedactivityinthesecuritymanagementarea,webelievethatidentitymanagementandWebservicessecurity,withtheirbroadconsumptionof3Atechnologies,willrevitalizethemarket.However,thesenewinitiativeswilldemandintegrationamongpreviouslyseparateproducts.Therefore,thistransitionwillcreateevengreaterturmoilinthe3Amarketforatleastthenext12-24months.”(认证/授权/审计)AnthonyC.Picardi,IDC(December2002)“Identityhasbecomeastrategicbusinessissue…Integratedidentityandaccessmanagementinfrastructureis“in”…EnterprisesmustcreateanIdentityManagementarchitectureandstrategy.”(身份管理体系结构和策略)JamieLewis,BurtonGroup(October30,2002)“ThoughITbudgetsremaintight,organizationsarecontinuingtoinvestinidentitymanagementbecauseitaddressescriticalbusinessissuesanddeliversaquantifiablereturnoninvestment(ROI).”(投资回报)JonathanPenn,GigaInformationGroup(October22,2002)“NoCIOchecklistfor2003canbecompletewithoutanitemonsecurity.Concerns,bothrealandimaginary,willcontinuetotesttheresolveandthebudgetsofISorganizations.Demandandexpectationforbusinesstransparencybycustomers,partnersandregulatorscontinuetoincrease.Thisvirtualizationcreatesastrategicbusinesschallengetoprovideaccesssimply,safelyandeconomicallytoeveryonewhoneedsitandsimultaneouslypreventunauthorizedordestructiveaccess.During2003,CIOsshouldreviewandupdatethecomplexissuesofidentityandaccessmanagement(IAM)policesandmethods.J.Mahoney,Gartner,Inc.(December24,2002)“Convergenceandsecurityconcernswilldriveenterprisedirectoryservicesadoption(2002+),reinforcingtheneedforidentitymanagement(2002-04).NOSupgrades,strongauthentication,andhigherdemandsforidentitymanagementwilldriveincreasinglycomplexintegrationofmulti-vendor/platformdirectoryinstances(2003+),resultinginmoreuseofEAI-likeintegration“toolkits.”EarlPerkins,MetaGroup(November4,2002)©October1,201918案例一:TransUnionCredit信托公司reportingandfinancialservicescompany“WeliveanddiebylonglistsofFTCregulations…Ourentirebusinessisbasedontheabilitytoprovidetherightpeoplewithsecureaccesstoenormousvolumesofhighlysensitive,regulatedinformation.Secureidentitymanagementisahugedealforus.”EmployeesB2BPartnersCustomersFinanceMarketingSalesCustomerserviceIdentity•Heavilyregulatedenvironment•Securityatopconcern•Millionsofcreditreportsprocesseddaily•Growthfrom38,000-150,000eCommerceusers©October1,201919案例二:MountSinaiNYUHealthSy

1 / 44
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功