The Experts below are selected from a list of 219 Experts worldwide ranked by ideXlab platform

Denis Royer - One of the best experts on this subject based on the ideXlab platform.

  • Enterprise Identity Management: Towards an Investment Decision Support Approach
    2013
    Co-Authors: Denis Royer
    Abstract:

    The introduction of Enterprise Identity Management Systems (EIdMS) in organizations even beyond the purely technological level is a costly and challenging endeavor. However, for decision makers it seems difficult to fully understand the impacts andopportunitiesarising from the introduction of EIdMS. This book explores the relevant aspects for an ex-ante evaluation of EIdMS. Thereforeit examines this domain by employing a qualitative expert interview study to better understand the nature of EIdMS, as they are situated between security and productive IT systems. To this regard, the focus is put on the general nature of EIdMS projects and the constructs being relevant for analyzing such projects in the decision support phase. Based on the derived constructs and thematic topics from the interviews, an explanatory model for EIdMS introductions is derived and iteratively improved and evaluated. Finally, a possible application use-case for the creation of adequate decision support tools is presented.

  • Enterprise Identity management
    IFIP International Summer School on the Future of Identity in the Information Society, 2013
    Co-Authors: Denis Royer
    Abstract:

    When introducing Enterprise Identity management systems (EIMS), organisations have to face various costs for the planning, the implementation, and the operation of such systems. Besides the technological issues, it is important that organisational aspects are incorporated into the development of an Enterprise Identity management (EIdM) solution as well. Indeed, without a proper assessment of the costs and the organisational settings (e.g. stakeholders, processes), companies will not see the benefit for introducing EIdM into their IT infrastructure and their business processes. This paper proposes initial ideas for a generic approach for assessing the value of investing in the introduction of EIMS (Type 1 IMS), which can be used for decision support purposes and the planning phase. Furthermore, the organisational aspects are discussed and possible solutions for integrating all relevant parties into the planning process are presented.

  • ECIS - Development of a Theoretical Model for Explaining and Predicting the Impacts of Enterprise Identity Management Introductions
    2010
    Co-Authors: Denis Royer
    Abstract:

    The introduction of Enterprise Identity Management Systems (EIdMS) in organisations is a costly and challenging endeavour, beyond the technological level. Especially for decision makers it seems difficult to fully understand the impacts and potentials from introducing EIdMS, such as the relevant aspects, for an ex-ante evaluation. The qualitative expert interview study presented in this paper was conducted to better understand the “hybrid” nature of EIdMS, being situated between security and productive IT systems. To this regard, the focus is put on the general nature of EIdMS projects and categories being relevant for analysing such. Based on the derived categories and insights from the interviews, a theoretical model for the evaluation of EIdMS introductions is developed, which can be used to derive adequate decision support systems.

  • Enterprise Identity Management – Towards a Decision Support Framework Based on the Balanced Scorecard Approach
    Business & Information Systems Engineering, 2009
    Co-Authors: Denis Royer, Martin Meints
    Abstract:

    Enterprise Identity Management Systems (EIdMS) are an IT-based infrastructure that needs to be integrated into various business processes and related infrastructures. Assessment and preparation of decisions for the introduction need to take the costs, benefits, and the organizational settings into consideration. A variety of methods for the evaluation and decision support of new IT (e. g. EIdMS) are discussed in the literature – however, these are typically based on single dimensions (e. g. financial or technology aspects). This paper proposes a multidimensional decision support framework, based on the Balanced Scorecard concept. The presented approach introduces four perspectives and a related set of initial decision parameters to support decision making. The perspectives are (a) financial/monetary, (b) business processes, (c) supporting processes and (ICT) infrastructure and (d) information security, risks and compliance. Perspectives and adaptable sets of decision parameters also may serve as foundation for software-based decision support instruments.

  • Betriebliches Identitätsmanagement
    WIRTSCHAFTSINFORMATIK, 2009
    Co-Authors: Denis Royer, Martin Meints
    Abstract:

    Enterprise Identity Management Systems (EIdMS) are an IT-based infrastructure that needs to be integrated in various business processes and related infrastructures. Assessment and preparation of decisions for the introduction need to take the costs, benefits, and the organizational settings into consideration. A variety of methods for the evaluation and decision support of new IT (e. g. EIdMS) are discussed in the literature – however, these are typically based on single dimensions (e. g. financial or technology aspects). This paper proposes a multidimensional decision support framework, based on the Balanced Scorecard concept. The presented approach introduces four perspectives and a related set of initial decision parameters to support decision making. The perspectives are (a) financial/monetary, (b) business processes, (c) supporting processes and (ICT) infrastructure and (d) information security, risks and compliance. Perspectives and adaptable sets of decision parameters also may serve as foundation for software-based decision support instruments. Systeme für das betriebliche Identitätsmanagement (Enterprise Identity Management, EIdMS) stellen eine IT-basierte Infrastruktur dar, die in verschiedenen Geschäftsprozessen und zugehörigen Infrastrukturen integriert werden muss. Die Bewertung und Vorbereitung von Entscheidungen für eine Einführung eines EIdMS muss die Kosten, den Nutzen und die organisatorische Umgebung berücksichtigen. Eine Vielzahl von Methoden für die Beurteilung und die Entscheidungsunterstützung neuer IT im Allgemeinen, als auch für EIdMS, werden in der Literatur diskutiert. Allerdings basieren diese Methoden typischerweise auf einzelnen Dimensionen (z. B. finanziellen oder technologischen Aspekten). Dieser Beitrag schlägt ein multidimensionales Entscheidungsunterstützungsrahmenwerk auf Basis des Balanced-Scorecard-Konzepts vor. Der dargestellte Ansatz führt vier Perspektiven und eine zugehörige Menge initialer Entscheidungsparameter ein, um die Entscheidungsfindung zu unterstützen. Diese Perspektiven sind (a) finanzielle / monetäre Aspekte, (b) Geschäftsprozesse, (c) unterstützende Prozesse und (IKT-) Infrastruktur sowie (d) Informationssicherheit, Risiken und Compliance. Die Perspektiven und die anpassbare Menge der Entscheidungsparameter können auch als Grundlage für softwarebasierte Entscheidungsunterstützungsinstrumente dienen.

Martin Meints - One of the best experts on this subject based on the ideXlab platform.

  • Enterprise Identity Management – Towards a Decision Support Framework Based on the Balanced Scorecard Approach
    Business & Information Systems Engineering, 2009
    Co-Authors: Denis Royer, Martin Meints
    Abstract:

    Enterprise Identity Management Systems (EIdMS) are an IT-based infrastructure that needs to be integrated into various business processes and related infrastructures. Assessment and preparation of decisions for the introduction need to take the costs, benefits, and the organizational settings into consideration. A variety of methods for the evaluation and decision support of new IT (e. g. EIdMS) are discussed in the literature – however, these are typically based on single dimensions (e. g. financial or technology aspects). This paper proposes a multidimensional decision support framework, based on the Balanced Scorecard concept. The presented approach introduces four perspectives and a related set of initial decision parameters to support decision making. The perspectives are (a) financial/monetary, (b) business processes, (c) supporting processes and (ICT) infrastructure and (d) information security, risks and compliance. Perspectives and adaptable sets of decision parameters also may serve as foundation for software-based decision support instruments.

  • Betriebliches Identitätsmanagement
    WIRTSCHAFTSINFORMATIK, 2009
    Co-Authors: Denis Royer, Martin Meints
    Abstract:

    Enterprise Identity Management Systems (EIdMS) are an IT-based infrastructure that needs to be integrated in various business processes and related infrastructures. Assessment and preparation of decisions for the introduction need to take the costs, benefits, and the organizational settings into consideration. A variety of methods for the evaluation and decision support of new IT (e. g. EIdMS) are discussed in the literature – however, these are typically based on single dimensions (e. g. financial or technology aspects). This paper proposes a multidimensional decision support framework, based on the Balanced Scorecard concept. The presented approach introduces four perspectives and a related set of initial decision parameters to support decision making. The perspectives are (a) financial/monetary, (b) business processes, (c) supporting processes and (ICT) infrastructure and (d) information security, risks and compliance. Perspectives and adaptable sets of decision parameters also may serve as foundation for software-based decision support instruments. Systeme für das betriebliche Identitätsmanagement (Enterprise Identity Management, EIdMS) stellen eine IT-basierte Infrastruktur dar, die in verschiedenen Geschäftsprozessen und zugehörigen Infrastrukturen integriert werden muss. Die Bewertung und Vorbereitung von Entscheidungen für eine Einführung eines EIdMS muss die Kosten, den Nutzen und die organisatorische Umgebung berücksichtigen. Eine Vielzahl von Methoden für die Beurteilung und die Entscheidungsunterstützung neuer IT im Allgemeinen, als auch für EIdMS, werden in der Literatur diskutiert. Allerdings basieren diese Methoden typischerweise auf einzelnen Dimensionen (z. B. finanziellen oder technologischen Aspekten). Dieser Beitrag schlägt ein multidimensionales Entscheidungsunterstützungsrahmenwerk auf Basis des Balanced-Scorecard-Konzepts vor. Der dargestellte Ansatz führt vier Perspektiven und eine zugehörige Menge initialer Entscheidungsparameter ein, um die Entscheidungsfindung zu unterstützen. Diese Perspektiven sind (a) finanzielle / monetäre Aspekte, (b) Geschäftsprozesse, (c) unterstützende Prozesse und (IKT-) Infrastruktur sowie (d) Informationssicherheit, Risiken und Compliance. Die Perspektiven und die anpassbare Menge der Entscheidungsparameter können auch als Grundlage für softwarebasierte Entscheidungsunterstützungsinstrumente dienen.

  • Enterprise Identity management towards a decision support framework based on the balanced scorecard approach
    Web Intelligence, 2009
    Co-Authors: Dipl Wirt Inf Denis Royer, Martin Meints
    Abstract:

    Enterprise Identity Management Systems (EIdMS) are an IT-based infrastructure that needs to be integrated into various business processes and related infrastructures. Assessment and preparation of decisions for the introduction need to take the costs, benefits, and the organizational settings into consideration. A variety of methods for the evaluation and decision support of new IT (e. g. EIdMS) are discussed in the literature – however, these are typically based on single dimensions (e. g. financial or technology aspects). This paper proposes a multidimensional decision support framework, based on the Balanced Scorecard concept. The presented approach introduces four perspectives and a related set of initial decision parameters to support decision making. The perspectives are (a) financial/monetary, (b) business processes, (c) supporting processes and (ICT) infrastructure and (d) information security, risks and compliance. Perspectives and adaptable sets of decision parameters also may serve as foundation for software-based decision support instruments.

  • Planung und Bewertung von Enterprise Identity Managementsystemen
    Datenschutz und Datensicherheit - DuD, 2008
    Co-Authors: Denis Royer, Martin Meints
    Abstract:

    Wie kann man Enterprise Identity Managementsysteme (EldMS) in der Planung und im laufenden Betrieb bewerten? Der vorliegende Beitrag stellt einen Ansatz für ein auf der Balanced Scorecard basierendes Kennzahlensystem vor und entwickelt mögliche Kennzahlen für die Sicherheitsfunktionen von Enterprise Identity Management (EldM) aus relevanten Normen und Standards.

Florian Dotzler - One of the best experts on this subject based on the ideXlab platform.

  • Biometric Authentication as a service for Enterprise Identity management deployment: A data protection perspective
    Proceedings of the 2011 6th International Conference on Availability Reliability and Security ARES 2011, 2011
    Co-Authors: Christian Senk, Florian Dotzler
    Abstract:

    Biometric Authentication as a Service is an innovative approach for strong authentication in web environments based on the Software as a Service model. However, both the adoption of SaaS systems and biometric technologies negatively correlate with perceived privacy and data protection risks. We specify a list of evaluation criteria for BioAaaS systems from a data protection point of view including elements specific to both biometrics and SaaS. We further apply these criteria on a prototypical implementation of a SaaS-compliant biometric authentication service based on keystroke dynamics for Enterprise deployment. The assessment shows that for the most part the prototype conforms to technical data protection requirements. At the organizational level the selection and control of a trust-worthy provider and the conclusion of the service agreement remain.

  • Biometric Authentication as a Service for Enterprise Identity Management Deployment
    2011
    Co-Authors: Christian Senk, Florian Dotzler
    Abstract:

    Biometric Authentication as a Service is an innovative approach for strong authentication in web environments based on the Software as a Service model. However, both the adoption of SaaS systems and biometric technologies negatively correlate with perceived privacy and data protection risks. We specify a list of evaluation criteria for BioAaaS systems from a data protection point of view including elements specific to both biometrics and SaaS. We further apply these criteria on a prototypical implementation of a SaaS-compliant biometric authentication service based on keystroke dynamics for Enterprise deployment. The assessment shows that for the most part the prototype conforms to technical data protection requirements. At the organizational level the selection and control of a trust-worthy provider and the conclusion of the service agreement remain.

  • ARES - Biometric authentication as a service for Enterprise Identity management deployment: a data protection perspective
    2011 Sixth International Conference on Availability Reliability and Security, 2011
    Co-Authors: Christian Senk, Florian Dotzler
    Abstract:

    Biometric Authentication as a Service is an innovative approach for strong authentication in web environments based on the Software as a Service model. However, both the adoption of SaaS systems and biometric technologies negatively correlate with perceived privacy and data protection risks. We specify a list of evaluation criteria for BioAaaS systems from a data protection point of view including elements specific to both biometrics and SaaS. We further apply these criteria on a prototypical implementation of a SaaS-compliant biometric authentication service based on keystroke dynamics for Enterprise deployment. The assessment shows that for the most part the prototype conforms to technical data protection requirements. At the organizational level the selection and control of a trust-worthy provider and the conclusion of the service agreement remain.

Günther Pernul - One of the best experts on this subject based on the ideXlab platform.

  • ICISSP - Analyzing quality criteria in role-based Identity and access management
    Proceedings of the 1st International Conference on Information Systems Security and Privacy, 2015
    Co-Authors: Michael Kunz, Ludwig Fuchs, Michael Netter, Günther Pernul
    Abstract:

    Roles have turned into the de facto standard for access control in Enterprise Identity management systems. However, as roles evolve over time, companies struggle to develop and maintain a consistent role model. Up to now, the core challenge of measuring the current quality of a role model and selecting criteria for its optimization remains unsolved. In this paper, we conduct a survey of existing role mining techniques and identify quality criteria inherently used by these approaches. This guides organizations during the selection of a role mining technique that matches their company-specific quality preferences. Moreover, our analysis aims to stimulate the research community to integrate quality metrics in future role mining approaches.

  • ICISSP (Revised Selected Papers) - How to Discover High-Quality Roles? A Survey and Dependency Analysis of Quality Criteria in Role Mining
    Communications in Computer and Information Science, 2015
    Co-Authors: Michael Kunz, Ludwig Fuchs, Michael Netter, Günther Pernul
    Abstract:

    Roles have evolved into the de facto standard for access control in Enterprise Identity Management. However, companies struggle to develop and maintain a role-based access control state. For the initial role deployment, role mining is widely used. Due to the high number and complexity of available role mining algorithms, companies fail to perceive which is selected best according to their needs. Furthermore, requirements on the composition of roles such as reduction of administration cost are to be taken into account in role development. In order to give them guidance, in this paper we aggregate existing role mining approaches and classify them. For consideration of individual prerequisites we extract quality criteria that should be met. Later on, we discuss interdependencies between the criteria to help role developers avoid unwanted side-effects and produce RBAC states that are tailored to their preferences.

  • analyzing recent trends in Enterprise Identity management
    Database and Expert Systems Applications, 2014
    Co-Authors: Michael Kunz, Matthias Hummer, Ludwig Fuchs, Michael Netter, Günther Pernul
    Abstract:

    Recent data breaches caused by highly-privileged insiders (e.g. the NSA/Snowden case) as well as the proliferation of mobile and cloud applications in Enterprises imposes new challenges for Identity Management. To cope with these challenges, business analysts have predicted a variety of trends for Enterprise Identity Management. In this paper, we conduct a thorough literature analysis to examine to which extent the scientific community seizes upon these trends and identify major research areas therein. Results show that despite the analysts' predictions, research stagnates for attribute-based access control and privileged user management, while for cloud-based IdM and bring your own device it corresponds to the analysts' forecast.

  • DEXA Workshops - Analyzing Recent Trends in Enterprise Identity Management
    2014 25th International Workshop on Database and Expert Systems Applications, 2014
    Co-Authors: Michael Kunz, Matthias Hummer, Ludwig Fuchs, Michael Netter, Günther Pernul
    Abstract:

    Recent data breaches caused by highly-privileged insiders (e.g. the NSA/Snowden case) as well as the proliferation of mobile and cloud applications in Enterprises imposes new challenges for Identity Management. To cope with these challenges, business analysts have predicted a variety of trends for Enterprise Identity Management. In this paper, we conduct a thorough literature analysis to examine to which extent the scientific community seizes upon these trends and identify major research areas therein. Results show that despite the analysts' predictions, research stagnates for attribute-based access control and privileged user management, while for cloud-based IdM and bring your own device it corresponds to the analysts' forecast.

Birgit Pfitzmann - One of the best experts on this subject based on the ideXlab platform.

  • privacy in Enterprise Identity federation policies for liberty 2 single sign on
    Information Security Technical Report, 2004
    Co-Authors: Birgit Pfitzmann
    Abstract:

    Abstract Cross-domain Identity management is gaining significant interest in industry. A well-known example is the Liberty Alliance's specifications for single sign on of web users across different Enterprises. The Liberty Alliance stresses that account linking is voluntary for the users and that privacy is an important consideration. We evaluate the privacy of these specifications in detail. We point out some ambiguities and propose a concrete privacy policy together with a few changes to the Liberty processing rules. Our analysis demonstrates that Identity-management policies need detailed advance planning even in a limited context. Identity management, federation, single sign on, privacy, pseudonyms, user tracking.

  • Privacy in Enterprise Identity federation – policies for Liberty 2 single sign on
    Information Security Technical Report, 2004
    Co-Authors: Birgit Pfitzmann
    Abstract:

    Abstract Cross-domain Identity management is gaining significant interest in industry. A well-known example is the Liberty Alliance's specifications for single sign on of web users across different Enterprises. The Liberty Alliance stresses that account linking is voluntary for the users and that privacy is an important consideration. We evaluate the privacy of these specifications in detail. We point out some ambiguities and propose a concrete privacy policy together with a few changes to the Liberty processing rules. Our analysis demonstrates that Identity-management policies need detailed advance planning even in a limited context. Identity management, federation, single sign on, privacy, pseudonyms, user tracking.

  • privacy in Enterprise Identity federation
    Privacy Enhancing Technologies, 2003
    Co-Authors: Birgit Pfitzmann
    Abstract:

    Cross-domain Identity management is gaining significant interest in industry. A recent example is the Liberty Alliance’s specifications for single signon of users across a federation of Enterprises. These specifications stress that the federation process is voluntary for the users and that privacy is preserved, e.g., by using pseudonyms. We evaluate the privacy of these specifications in detail. We point out ambiguities and propose a concrete privacy policy together with a few changes to the Liberty processing rules. Our analysis demonstrates that Identity-management policies are non-trivial even in a limited context. We also discuss how such low-tech proposals from industry relate to high-tech privacy-enhancing proposals from the research community.

  • privacy in Enterprise Identity federation policies for liberty single signon
    Privacy Enhancing Technologies, 2003
    Co-Authors: Birgit Pfitzmann
    Abstract:

    Cross-domain Identity management is gaining significant interest in industry. A recent example is the Liberty Alliance's specifications for single signon of users across a federation of Enterprises. These specifications stress that the federation process is voluntary for the users and that privacy is preserved, e.g., by using pseudonyms. We evaluate the privacy of these specifications in detail. We point out ambiguities and propose a concrete privacy policy together with a few changes to the Liberty processing rules. Our analysis demonstrates that Identity-management policies are non-trivial even in a limited context. We also discuss how such low-tech proposals from industry relate to high-tech privacy-enhancing proposals from the research community.

  • Privacy Enhancing Technologies - Privacy in Enterprise Identity federation: Policies for Liberty single signon -
    2003
    Co-Authors: Birgit Pfitzmann
    Abstract:

    Cross-domain Identity management is gaining significant interest in industry. A recent example is the Liberty Alliance's specifications for single signon of users across a federation of Enterprises. These specifications stress that the federation process is voluntary for the users and that privacy is preserved, e.g., by using pseudonyms. We evaluate the privacy of these specifications in detail. We point out ambiguities and propose a concrete privacy policy together with a few changes to the Liberty processing rules. Our analysis demonstrates that Identity-management policies are non-trivial even in a limited context. We also discuss how such low-tech proposals from industry relate to high-tech privacy-enhancing proposals from the research community.