twelve diagrams to save your identity bacon

59
Venn and the art of Identity Relationship Management

Upload: forgerock

Post on 20-Jun-2015

281 views

Category:

Software


0 download

DESCRIPTION

ROBERT LAPES, Head of Identity Advisory Services, Capgemini, at the European IRM Summit 2014.

TRANSCRIPT

Page 1: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Venn and the art of Identity Relationship

Management

Page 2: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Using diagrams to save your identity bacon

Page 3: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Robert Lapes

• 30 years experience in I.T.• 10 years of identity program

assurance• Head of IAM Advisory Services• Capgemini UK’s IAM practice• 120,000 staff in 40 countries• 200+ identity specialists worldwide

Page 4: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Agenda

1. IRM context2. Why diagrams?3. What diagrams?– Identity– Relationships– Management

4. Summary and questions

Page 5: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

context

Page 6: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

IRMis the new

IAM

Page 7: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

IRM’s four business pillars

1. CONSUMERS and THINGS over employees2. ADAPTABLE over predictable3. TOP LINE REVENUE over operating

expense4. VELOCITY over process

Page 8: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

IRM’s four technical pillars

1. INTERNET SCALE over enterprise scale2. DYNAMIC INTELLIGENCE over static

intelligence3. BORDERLESS over perimeter

4. MODULAR over monolithic

Page 9: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

scale complexityadaptable

dynamicbigger faster

connected diverse

decentralisationnon-linearity

Page 10: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

IRM

Scale

Complexity

IxMInternet

Page 11: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Why diagrams?

Page 12: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

We learn mainly by sight

Sight Hearing Touch Smell Taste0%

10%

20%

30%

40%

50%

60%

70%

80% 75%

13%

6%3% 3%

Page 13: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

We can process large amounts of visual data

Page 14: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Writing is a recent invention

Page 15: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

identity diagrams

Page 16: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Georg Hegel

PhilosopherNewspaper editorHeadmaster1770 – 1831

Page 17: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Hegelian Dialectic

Page 18: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Georg Hegel

“Identity is the identity of identity and non-identity.”

particularity

universality

individuality

Page 19: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

• " CryptographerPrivacy expert

b. 1973 Canada

Inventor of the “Nymity Slider”

Prof. Ian Goldberg

Page 20: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

• "“Privacy and national

security are like opposite ends of a

slider,“

Page 21: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

• " "Technology is like a magnet that allows

individuals to pull that slider back toward

themselves.“

Page 22: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

The Nymity Slider

Page 23: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

John Venn

TheologianLogicianCricketer1837 – 1923

Inventor of theVenn diagram

Page 24: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON
Page 25: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Similar to Euler diagram

Page 26: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON
Page 27: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON
Page 28: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Business Partners

Anonymous

CustomersMyAccount

Page 29: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

relationship diagrams

Page 30: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Prof. Jiro Kawakita

AnthropologistMountain climberPlant collector1920 – 2009

Inventor of theAffinity diagram

Page 31: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

“Let the facts speak for themselves”

•Too many facts or ideas in apparent chaos• Issues are too large and complex to grasp •Group consensus

Page 32: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

KJ Method or Affinity diagram

Page 33: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Prof. Peter Chen

Computer scientistInventor of the Entity-Relationship modelb. 1947

Page 34: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

“Entities and relationships are a natural way to organize physical things as well as information … “

Page 35: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

“… The ER concept is the basic fundamental principle for conceptual modelling. It has been with us since thousands of years ago and will be with us for many years to come.”

Page 36: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON
Page 37: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Entity–relationship model

2 Registrar5 Attribute Authority

Registers for identity

Issues identifier

Enrols for service

Assur

ance

4 Credential Authority

Asserts access claim

Issues credential

Authe

ntica

tion

Provides service

Circle of Trust

Authorisation

1 Policy 6 Governance

Subject

Identity service

Authentication service

Reliant party

Access service

2 Entity3 Service

or Resource

Page 38: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON
Page 39: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Prof. Shigeru Mizuno

Quality management guru

Inventor of matrix diagram

Page 40: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Matrix diagram

4

3

2

1

0

Minimal

Minimal

Minimal

Minimal

1

Low

Low

Low

Minimal

2

Moderate

Moderate

Low

Minimal

3

High

Moderate

Low

Minimal

4

Str

ength

of

Regis

trati

on

Strength of Authentication Mechanism

Page 41: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Matrix diagram

Source: Eve Maler

Page 42: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Matrix diagram

SAP Microsoft IBM

Security strong positive strong positive strong positive

Functionality strong positive neutral positive

Integration positive positive positive

Interoperability positive neutral positive

Usability positive neutral neutral

Innovativeness positive neutral positive

Market Position positive strong positive strong positive

Financial Strength

strong positive strong positive strong positive

Ecosystem positive strong positive strong positive

Page 43: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Matrix diagramTOGAF Policy

Entities & Identity

Resources & Assets

Authentication & Credentials

Authorization & Access

Operation & Governance

1 Vision

2Business Architecture

3Information System Architecture

4Technology Architecture

5Opportunities & Solutions

6Migration Planning

7Implementation Governance

8Change Management

9 Requirements

Page 44: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Y-Matrix Diagram

Page 45: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

management diagrams

Page 46: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Dr W. Edwards Deming

Father of modernquality control

Quality management

guru

1900 - 1993

Page 47: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

“It is not enough to do your best; you must know what to do and then do your

best.”

Page 48: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

The Deming Cycle

Page 49: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

The Deming Cycle

Do

Check

Act

Plan

PolicyReview

EntityReview

ResourceReview

Authentication

Review

AccessReview

Governance&

OperationalReview

Entityscope

Collection and

consolidation

Verificationand

validation

Reconcile &remediation

Authoritativeentities

Resourcescope

Impact analysis

Resource classificatio

n

Classification

remediation

Authoritative

classification

Enrolment and

authorisation scope

Collection and

consolidation

Mapping andvalidation

Reconcile and

remediation

Authoritativeaccess control

Contextscope

Workflow and event collection

Context analysis

Review and certify

Authoritativecontext

Identifier andcredential

scope

Collection and

consolidation

Mapping andvalidation

Reconcile and

remediation

Authoritative identifiers

and credentials

Policyscope

Collection and

consolidation

Policy review

Policyremediation

Authoritativepolicy

Page 50: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Matthew Henry Phineas Riall Sankey

Engineer 

Introduced the first energy flow diagram

1853 – 1926 Ireland

Page 51: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON
Page 52: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON
Page 53: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Internet traffic 2010

Page 54: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

summaryand

questions

Page 55: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

scale complexityadaptable

dynamicbigger faster

connected diversedecentralisation

non-linearity

IRM is the new IAM

Page 56: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Why diagrams?

• Data can be hard to understand especially in written form.

• Diagrams help us understand complex data and information and identify complex relationships.

• We learn better visually.

Page 57: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

These people developed diagrams to make life easier

to understand

Page 58: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Thank you

Page 59: TWELVE DIAGRAMS TO SAVE YOUR IDENTITY BACON

Contact information

Insert contact picture

Robert LapesIdentity [email protected]

Capgemini UK | Bristol (Toltec)Tel: +44 0 870 194 6658

Insert contact picture

Andrew CritchleyIAM Proposition Lead andrew.critchley @capgemini.com

Capgemini UK | SaleTel: + 44 (0)7891 154281