ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Oracle proposes safe-data standards

Joris Evers CNET News.com

Published: 30 Nov 2006 09:06 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Oracle has proposed new technology standards to safeguard sensitive data as it flows through corporate software applications. But is that where leaks happen?

The proposed standards, dubbed the Identity Governance Framework, would let companies apply privacy and security controls to information as it moves from one business application to another. This should help safeguard personal data such as credit card details, Oracle said on the release of IGF on Wednesday.

"A lot of data security breaches are happening because identity information is in far too many places within an enterprise," said Amit Jasuja, vice president of development, security and identity management at Oracle. "Most often people don't even know that there is identity information that they need tighter controls over."

The IGF would let companies with sensitive data, such as banks, control how identity attributes are used by applications. Identity attributes are items such as names, addresses and bank account numbers associated with a customer or partner, and the applications that use them might include customer service, payroll and manufacturing programs. The specifications should help compliance with regulatory requirements such as the European Data Protection Initiative, Sarbanes-Oxley, and Gramm-Leach-Bliley, Oracle said.

The business software maker developed the IGF on its own, but has garnered the support of CA, Layer 7 Technologies, Novell, Ping Identity, Securent and Sun. These companies plan to help develop full specifications, Oracle said.

But the proposals don't solve the problem of data breaches, Forrester Research analyst Jonathan Penn said. They give better visibility into the use of sensitive personal information, but that's all.

"It looks like too much effort for not enough reward," he said. "What is being proposed is an application-to-application architecture. That wouldn't have any effect on, say, misuse of the customer relationship management system to gain access to customers' personal data."

Even if the effort does come up with a standard way to increase visibility into the use of data by applications, it could be hobbled by the absence of several big players, Penn said. Noticeably missing are SAP, IBM and Microsoft. "That is a problem," Penn said.

Microsoft may not support it because the Oracle proposal seems biased towards the Liberty Alliance and the SAML standard for exchanging authentication and authorisation data, which Microsoft has never officially backed, Penn said. IBM has its own Tivoli Privacy Manager, a tool that does much of what Oracle is proposing, he added.

Filling a gap
Oracle may not solve the data breach problem, but the proposals do fill a standards gap and seek to provide a solution for a real issue, Burton Group analyst Bob Blakley said.

"There are a lot of identity technologies out there that allow you to exchange identity information, and those technologies will not realise their full potential until the systems that use them know what identity attributes to exchange," he said.

The IGF complements work on identity-related standards done in the Liberty Alliance, Oasis (Organization for the Advancement of Structured Information Standards), Higgins and Microsoft's CardSpace, Oracle said.

Those initiatives focus on making sure user information is collected with the appropriate consent and is efficiently transferred to a company's system, Jasuja said. Oracle's proposal builds another level on top of these efforts, he noted.

"They are really about the first mile. But then, once this data is in the enterprise, who makes sure that as it flows from one application to another, or is shared from one company to a partner, that the same privacy rules are followed?" he asked. Oracle has produced two draft specifications. It has also come up with a developer tool, called an application programming interface, or API, to work with these specifications. The company plans to submit its work to a yet-to-be-determined standards body within the next 90 days and to make it freely accessible.

 

The two draft IGF specifications are Client Attribute Requirement Markup Language (CARML) and Attribute Authority Policy Markup Language (AAPML). CARML is an XML-based set of definitions provided by an application's developer that includes the usage requirements of the application; AAPML is a set of policy rules regarding the use of identity-related information. More details are available on Oracle's IGF website.

The Redwood City, California-based company said it also intends to include the work in its upcoming Fusion business applications, due in 2008.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
354 out of 413 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

IT Security analyst - Security qualified - Wintel - hands on - BANKING

Encryption Monitoring, Alerting and Auditing (SIEM) Directory Services Intrusion Prevention/Detection Systems Security Protocols ...

Middleware Developer - Investment Banking - Front Office Derivatives

You will have excellent knowledge of MessageBroker, building messagebroker flows and strong MQ Series experience. There is the opportunity to learn ...

CRM Consultant / Manager - Communications & High Technology

Campaign Management - Lead & Opportunity Management - Account / Subscription Management - Customer Interaction Management - Order Management - ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation