<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bluenog</title>
	<atom:link href="http://www.bluenog.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.bluenog.com</link>
	<description>Smart thinking. Delivered.</description>
	<lastBuildDate>Wed, 22 May 2013 18:00:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Bluenog launches Information Management Practice</title>
		<link>http://www.bluenog.com/bluenog-creates-new-information-management-practice</link>
		<comments>http://www.bluenog.com/bluenog-creates-new-information-management-practice#comments</comments>
		<pubDate>Fri, 08 Mar 2013 19:36:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Home - What's New]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=658</guid>
		<description><![CDATA[The new practice enables Bluenog to offer enhanced Information Management Solutions]]></description>
			<content:encoded><![CDATA[<p>The new practice enables Bluenog to offer enhanced Information Management Solutions</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/bluenog-creates-new-information-management-practice/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bluenog Launches New Information Management Practice</title>
		<link>http://www.bluenog.com/bluenog-creates-new-information-management-practice</link>
		<comments>http://www.bluenog.com/bluenog-creates-new-information-management-practice#comments</comments>
		<pubDate>Fri, 08 Mar 2013 19:31:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News & Events]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=654</guid>
		<description><![CDATA[Piscataway, New Jersey – March 08, 2013 – Bluenog Corporation, an enterprise services and software company that specializes in delivering solutions to meet needs for Service Oriented Architecture (SOA), Business intelligence and Enterprise 2.0 (Portals and Content Management), today announced the creation of its Information Management Practice, which provides comprehensive services in the design, development, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 13px; line-height: 19px;">Piscataway, New Jersey – March 08, 2013 – Bluenog Corporation, an enterprise services and software company that specializes in delivering solutions to meet needs for Service Oriented Architecture (SOA), Business intelligence and Enterprise 2.0 (Portals and Content Management), today announced the creation of its Information Management Practice, which provides comprehensive services in the design, development, implementation of Information Management solutions. The new practice enables Bluenog Corporation to offer enhanced and uncompromised Analytics, Business Intelligence, Data Warehousing, Database Management and Administration, Data Modeling, Data Governance, Extract-Transform-Load (ETL) technologies, Integration of Data Sources and Master Data Management solutions.</span></p>
<p>&nbsp;</p>
<p>Bluenog’s Information Management team will be led by Chuck Lewis who has been appointed head of the new practice. Mr. Lewis will be responsible for services in five areas comprised of: Analytics, Business Intelligence, Data Warehousing, Database Management and Administration, Data Modeling, Data Governance, Extract-Transform-Load (ETL) technologies, Integration of Data Sources and Master Data Management. </p>
<p>“Bluenog already delivers superior technical solutions and measurable business outcomes to Fortune 1000 companies nationally and internationally,” said Sastry Taruvai, President, Bluenog Corporation. “Chuck will contribute to our management team’s expertise, further enhance the needs required in today’s digital business and deliver the most comprehensive and relevant Information Management solution to our clients.”</p>
<p>&nbsp;</p>
<p>About Bluenog Corporation<br /> Bluenog Corp. is an enterprise services and software company that specializes in delivering practical solutions to meet our customers’ needs for security, SOA, business intelligence and Enterprise 2.0. Leading organizations rely on Bluenog Corp. to deliver enterprise solutions based on leading software technologies. Bluenog maintains deep technology expertise and broad implementation skills; provides end-to-end consulting capabilities from architecture, best practices and strategy to post implementation needs and keeps all this simple to deliver real business value as quickly and seamlessly as possible. Headquartered in Piscataway, N.J., Bluenog is an Oracle Platinum Partner and Reseller. For more information, please visit www.bluenog.com.</p>
<p>&nbsp;</p>
<p>Contact:<br /> Bluenog Corporation<br /> 53 Knightsbridge Rd., 2nd Floor<br /> Piscataway, NJ 08854<br /> Phone: 732.584.2378<br /> Email: info@bluenog.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/bluenog-creates-new-information-management-practice/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bluenog and Oracle would like to invite you to enjoy an evening of Philly Hockey!</title>
		<link>http://www.bluenog.com/bluenog-and-oracle-would-like-to-invite-you-to-enjoy-an-evening-of-philly-hockey-2</link>
		<comments>http://www.bluenog.com/bluenog-and-oracle-would-like-to-invite-you-to-enjoy-an-evening-of-philly-hockey-2#comments</comments>
		<pubDate>Fri, 22 Feb 2013 16:52:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News & Events]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=599</guid>
		<description><![CDATA[&#160; The Philadelphia Flyers vs. Florida Panthers game will be held on February 21st. We hope to see you there! &#160; Date: 2/21 Time: 7:00pm Place: Wells Fargo Center Section: Mid Level Suite #68]]></description>
			<content:encoded><![CDATA[<p><img class=" wp-image-602 alignnone" title="Bluenog Supports Flyers" src="http://www.bluenog.com/wp-content/uploads/nhl-flyers.png" alt="" width="602" height="244" /></p>
<p>&nbsp;</p>
<p>The Philadelphia Flyers vs. Florida Panthers game will be held on February 21st. We hope to see you there!</p>
<p>&nbsp;</p>
<p><strong>Date:</strong> 2/21<br /><strong> Time:</strong> 7:00pm<br /><strong> Place:</strong> Wells Fargo Center<br /><strong> Section:</strong> Mid Level Suite #68</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/bluenog-and-oracle-would-like-to-invite-you-to-enjoy-an-evening-of-philly-hockey-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bluenog and Oracle teamup to co-sponsor a NHL event</title>
		<link>http://www.bluenog.com/bluenog-and-oracle-would-like-to-invite-you-to-enjoy-an-evening-of-philly-hockey-2</link>
		<comments>http://www.bluenog.com/bluenog-and-oracle-would-like-to-invite-you-to-enjoy-an-evening-of-philly-hockey-2#comments</comments>
		<pubDate>Fri, 22 Feb 2013 16:45:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Home - What's New]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=591</guid>
		<description><![CDATA[Bluenog and Oracle would like to invite you to enjoy an evening of Philly Hockey!]]></description>
			<content:encoded><![CDATA[<p>Bluenog and Oracle would like to invite you to enjoy an evening of Philly Hockey!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/bluenog-and-oracle-would-like-to-invite-you-to-enjoy-an-evening-of-philly-hockey-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bluenog to co-host Engineered Systems Roundtable</title>
		<link>http://meeting-reg.com/oracle/itanium-roundtable-jan24/</link>
		<comments>http://meeting-reg.com/oracle/itanium-roundtable-jan24/#comments</comments>
		<pubDate>Fri, 04 Jan 2013 17:31:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Home - What's New]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=611</guid>
		<description><![CDATA[The Roundtable will feature the evolution of Oracle&#8217;s Engineered Systems strategy]]></description>
			<content:encoded><![CDATA[<p>The Roundtable will feature the evolution of Oracle&#8217;s Engineered Systems strategy</p>
]]></content:encoded>
			<wfw:commentRss>http://meeting-reg.com/oracle/itanium-roundtable-jan24/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It’s All About The Data:  Protecting Your Most Valuable Asset</title>
		<link>http://www.bluenog.com/its-all-about-the-data-protecting-your-most-valuable-asset</link>
		<comments>http://www.bluenog.com/its-all-about-the-data-protecting-your-most-valuable-asset#comments</comments>
		<pubDate>Mon, 30 Jul 2012 13:19:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=559</guid>
		<description><![CDATA[Over the past year news of data theft has become as commonplace as changes in the weather.  Nary a week goes by where we don&#8217;t hear of another major leak of sensitive data, from customer personal information to credit card data to corporate secrets.  What has changed over time is the frequency and impact of [...]]]></description>
			<content:encoded><![CDATA[<p>Over the past year news of data theft has become as commonplace as changes in the weather.  Nary a week goes by where we don&#8217;t hear of another major leak of sensitive data, from customer personal information to credit card data to corporate secrets.  What has changed over time is the frequency and impact of data theft, which can be attributed in part to the expansion of access to data in new network architectures (e.g., cloud, hosted networks, private computing devices/BYOD, etc.).</p>
<p>&nbsp;</p>
<p>But there are two more fundamental reasons for this increase in data theft, reasons are magnified due to the changing technology landscape:  companies do not value their data as a top business asset, and they focus on securing the technology, not the data itself.  Stealing your customer and company information is becoming much easier to do.  Companies spend millions on security technology rather than thousands on risk assessments and process (governance) improvements in information management.  Companies almost never have a full accounting of all data they create, transact and store, but they have detailed inventories of the servers on which that data resides.  If you&#8217;re not paying attention to the data itself, you don&#8217;t value that data enough to effectively protect it from the bad guys who value it more than you do.</p>
<p>&nbsp;</p>
<p>Addressing this increasingly urgent problem is not easy.  It requires a fundamental change in the way you think about your data.  Believe it or not, you probably already have a pretty good idea of what that new mindset is.  Consider the security you employ in your personal life.  You lock the doors and windows to your house when you leave, but it doesn&#8217;t stop someone from breaking in and stealing your television, which you consider an acceptable risk.  But maybe you do lock up your more treasured valuables, such as jewelry, in a fireproof box and hide that in your closet.  And maybe you lock up your most treasured items, such as family heirlooms, in a bank&#8217;s safety deposit box.  The same holds for your data.  Here is a simplified version of the steps we perform with our clients in protecting their data:</p>
<p>&nbsp;</p>
<ol>
<li>Perform an information inventory of all of the data you create, transact and store.  Inventory representatives of different levels from every department and record what data they deal with daily to conduct the company&#8217;s business.  Then go out and perform a full risk assessment of all of that data and verify where the data resides.</li>
</ol>
<p>&nbsp;</p>
<ol>
<li>Classify all data according to industry standards and create a framework in which the data will be protected commensurate with its classification level.  Account for how the data will be stored, copied, transmitted and destroyed, as well as investigation and reporting processes in case the data is stolen or mishandled.</li>
</ol>
<p>&nbsp;</p>
<ol>
<li>Assign roles and responsibilities for the protection of data to all employees and third-parties who may use the data.  Include this information in your company information security policy.</li>
</ol>
<p>&nbsp;</p>
<ol>
<li>Create an information management policy that specifies how the data protection framework will be carried out, and implement that framework in the IT environment.</li>
</ol>
<p>&nbsp;</p>
<ol>
<li>Now you can purchase the security technology you need to enforce compliance.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/its-all-about-the-data-protecting-your-most-valuable-asset/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SOA Enablement – The Need For A Strategy</title>
		<link>http://www.bluenog.com/soa-enablement-the-need-for-a-strategy</link>
		<comments>http://www.bluenog.com/soa-enablement-the-need-for-a-strategy#comments</comments>
		<pubDate>Mon, 09 Jul 2012 17:57:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=554</guid>
		<description><![CDATA[Service Oriented Architecture (SOA) is a concept for distributed computing that transforms IT for the enterprise.  The term “SOA” is used very broadly and at times loosely by vendors. SOA typically consist of a combination of technologies, products, infrastructure extensions and various frameworks/APIs. Some of the vendors with SOA implementation stacks are Oracle, IBM, Tibco, [...]]]></description>
			<content:encoded><![CDATA[<p>Service Oriented Architecture (SOA) is a concept for distributed computing that transforms IT for the enterprise.  The term “SOA” is used very broadly and at times loosely by vendors. SOA typically consist of a combination of technologies, products, infrastructure extensions and various frameworks/APIs. Some of the vendors with SOA implementation stacks are Oracle, IBM, Tibco, Microsoft, JBoss, WSO2 and many more. We will discuss some of the common mistakes and how to mitigate them while going through SOA enablement.</p>
<p>&nbsp;</p>
<p>In today’s world of acquisitions, mergers and consistently changing business needs, the ability for an IT organization to respond to these changes in a quick and timely fashion is quite vital. While businesses recognize the need for enterprise integration and SOA based solutions, many organizations tend to embark on the SOA journey without proper planning and therefore lack a strong execution strategy. More often than not customers are eager to get to the “implementation” phase by picking a toolset and getting down to business without the due diligence that is necessary before arriving at such a decision.</p>
<p>&nbsp;</p>
<p>The goal with a SOA based solution is to bring business and IT closer. Increasingly, one of the biggest pain points for Business owners is the lack of understanding exhibited by their IT in relating to requirements which always translates into a significant gap in the end product from the target state.  The key is to get the Business owners and IT on the same page in order to deliver a quality solution that can scale and expand as the company evolves. Typically, this is accomplished with a team of Enterprise Architect(s), Business Users and IT leadership often referred as the “SOA Advisory Board” that can understand the Business needs and goals and put together a strategy to address current problems and lay a strong foundation for the future. The Enterprise Architects at Bluenog have been very successful in helping our customers develop this very SOA strategy and define a roadmap for a successful SOA implementation.</p>
<p>&nbsp;</p>
<p>Tool selection is a critical step in the SOA adoption process. There are plenty of choices for both enterprise commercial vendors as well as open source based solutions. Oracle, IBM, Tibco, Microsoft are of the prime commercial vendors and JBoss, Fuse, Sonic, Apache Mix etc with their open source based offerings.  Once a SOA strategy is ironed out, the next step is to identify a platform for SOA. Although Web Services are a huge part of any SOA based solution, SOA is not all Web Services and one size does not fit all. Every environment is different and every solution is unique in its own way. Most organizations have some form of IT systems and applications in their environment. Platform selection should also factor in the type of systems and applications that are deployed in the environment. For example, if the organization runs Java based applications then it makes sense to build a solution with a Java based platform instead of .Net and vice versa. With that said, due to the nature of IT today, organizations tend to have a combination of Java, .Net and other technologies. The SOA platform must be able to handle integration across heterogeneous systems with standards based implementation as supposed to proprietary frameworks. Most SOA platforms today are built on open standards so how do we decide on one?</p>
<ol>
<li><strong>Ease of development</strong> – Toolset and skills of the IT team. For e.g. a Java based IT team will benefit from a SOA platform with Java background. Although there will be a learning curve, it will be a smaller one. Toolset should be efficient, intuitive and easy to use for development and testing.</li>
<li><strong>Standards based</strong> – Standards based implementation and integration frameworks/adapters for pertinent applications (e.g. SAP, PeopleSoft, MQ, Mainframes etc).</li>
<li><strong>Monitoring &amp; Maintenance</strong> – Often overlooked in tool selection. Any SOA solution deployed should provide insight into the infrastructure. A good toolset will provide visibility with various troubleshooting and monitoring features to monitor and notify on failures. Increasingly, organizations are mandating four 9’s or even five 9’s uptime. Having an enterprise monitoring tool for end-to-end visibility enables operations to be proactive in identifying problems.</li>
</ol>
<p>&nbsp;</p>
<p>SOA implementation is a multi-phase, multi-year initiative and the costs are higher for the initial services. However, the TCO for a SOA platform reduces considerably as more (reusable) services are deployed over time. Bluenog can assist with the SOA adoption process starting with laying out a strategy and going through the implementation and deployment. A governance process is key for a successful SOA adoption and just as important as having a SOA strategy. Governance is a topic by itself and I will be dedicating my next blog solely to discuss the importance of governance.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/soa-enablement-the-need-for-a-strategy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Make your Portal Usable – Why Usability?</title>
		<link>http://www.bluenog.com/make-your-portal-usable-why-usability</link>
		<comments>http://www.bluenog.com/make-your-portal-usable-why-usability#comments</comments>
		<pubDate>Mon, 25 Jun 2012 14:35:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=550</guid>
		<description><![CDATA[We often talk with our clients interested in portal and content management systems and the technical capabilities that specific platforms make available. They will focus on technical point, counter-point about features, but we are often surprised that the role of users and how they will work with a system is not given as much consideration. [...]]]></description>
			<content:encoded><![CDATA[<p>We often talk with our clients interested in portal and content management systems and the technical capabilities that specific platforms make available. They will focus on technical point, counter-point about features, but we are often surprised that the role of users and how they will work with a system is not given as much consideration. We have seen great successes where clients have a clear vision for a usable system as well as clear goals for the business outcomes driving their projects. Turning a discussion from technical details and feature checklists into one focused on a users real problems can lead to better solutions in the end, ones that are adopted enthusiastically because they are useful to the business and usable by their users.</p>
<p>&nbsp;</p>
<p>Add more usability into your projects and get better results. Here are a few resources to help you show your teams what usability is and why it matters:</p>
<ol>
<li><a href="http://www.useit.com/alertbox/20030825.html">Usability 101: Introduction to Usability</a></li>
<li><a href="http://www.upassoc.org/usability_resources/about_usability/index.html">What is usability?</a></li>
<li><a href="http://www.usability.gov/basics/index.html">Usability Basics </a></li>
<li><a href="http://uxdesign.com/ux-defined">UX Design Defined</a></li>
<li><a href="http://www.cio.com.au/article/407419/enterprise_software_why_usability_matters/">Enterprise software: Why usability matters</a></li>
<li><a href="http://market-by-numbers.com/2011/12/why-ux-why-now/">Why UX? Why now?</a></li>
<li><a href="http://www.webnauts.net/usability.html">Why usability is important to you</a></li>
<li><a href="http://www.usefulusability.com/ecommerce-roi-why-usability-always-beats-advertising/">eCommerce ROI: Why Usability ALWAYS Beats Advertising</a></li>
</ol>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/make-your-portal-usable-why-usability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Oracle Database Appliance (ODA)</title>
		<link>http://www.bluenog.com/why-oracle-database-appliance-oda</link>
		<comments>http://www.bluenog.com/why-oracle-database-appliance-oda#comments</comments>
		<pubDate>Tue, 19 Jun 2012 12:04:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=546</guid>
		<description><![CDATA[I recently attended a deep dive on the Oracle Database Appliance (ODA) and let me tell you, there is a lot to love with this product. Briefly, it’s a single 4-RU appliance that contains a pair of servers and 12 TB (raw) of SAS disk storage. The servers are clustered using internal redundant 1 GbE [...]]]></description>
			<content:encoded><![CDATA[<p>I recently attended a deep dive on the Oracle Database Appliance (ODA) and let me tell you, there is a lot to love with this product. Briefly, it’s a single 4-RU appliance that contains a pair of servers and 12 TB (raw) of SAS disk storage. The servers are clustered using internal redundant 1 GbE interconnects, and support both 1 GbE and 10 GbE external networking connectivity. Hence, this will easily fit into both 1 &amp; 10 GbE environments. Each server, running Oracle Linux, comes with a pair of 6-core Intel Xeon CPUs and 96 GB of RAM.</p>
<p>&nbsp;</p>
<p>Four 73 Gb Solid-State disks (SSDs) provide extremely fast access to the Oracle redo logs. Also, this appliance supports both Oracle RAC and <a href="http://www.oracle.com/us/products/database/options/rac-one-node/overview/index.html">Oracle Rac One Node</a> for “active-active” or “active-passive” failover of the database. As a matter of fact, the only issue I see with the ODA, is that (currently) you MUST triple mirror and hence get only 4 TB of usable storage. Supporting both OLTP and DW applications, ODA could fit in a number of deployments. Every deployment? Probably not, although IT IS A very versatile tool in our toolbox.</p>
<p>&nbsp;</p>
<p>Bluenog specializes in building applications based on the Oracle Middleware, SOA, and Identity Management stacks. Most of these components do have minor database needs by themselves, but If we were building an application that had large storage needs of its own, then it may be considered. Another possibility would be a situation where the data needed to remain isolated for, say, compliance reasons. In this situation, it may not be acceptable to keep the data on the same large storage array used by other facets of the company.</p>
<p>&nbsp;</p>
<p>We also have a very active Engineered Systems practice that is currently involved in a number of Exadata and Exalogic systems; also game changing products. In a situation where the customer didn’t need the capacity of an Exadata, ODA could fit very nicely.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/why-oracle-database-appliance-oda/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Critical Role of Identity &amp; Access Management</title>
		<link>http://www.bluenog.com/the-critical-role-of-identity-access-management</link>
		<comments>http://www.bluenog.com/the-critical-role-of-identity-access-management#comments</comments>
		<pubDate>Mon, 11 Jun 2012 15:28:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.bluenog.com/?p=526</guid>
		<description><![CDATA[In the thousands of networks, systems and applications I&#8217;ve assessed and audited in my career I&#8217;ve encountered two vulnerabilities far more than any other: weak user account security and poor passwords contributing to unauthorized access to company assets. Rarely does a security assessment go by where I don&#8217;t find a user account that had never [...]]]></description>
			<content:encoded><![CDATA[<p>In the thousands of networks, systems and applications I&#8217;ve assessed and audited in my career I&#8217;ve encountered two vulnerabilities far more than any other: weak user account security and poor passwords contributing to unauthorized access to company assets. Rarely does a security assessment go by where I don&#8217;t find a user account that had never been used and that I was able to penetrate using a standard default password that the administrators issued for all new accounts. I can&#8217;t count how many times I&#8217;ve discovered vendor application accounts configured with the default password, most often the same word as the account itself. On more occasions than you would believe, I&#8217;ve cracked into the root (UNIX/Linux) or Administrator (Windows) accounts because the passwords were embedded in backup scripts, set up for convenience and not properly protected. And of course, the most common security vulnerability of them all, poor user account passwords that are never changed, never expired, and not forced-configured with complexity (symbols, numbers, etc.), account for the most instances of unauthorized access.</p>
<p>&nbsp;</p>
<p>The problem is so widespread that it is the underlying reason for the most talked-about &#8220;hacks&#8221; in the news. The theft of credit cards, intellectual property (IP), health records and other sensitive information can be attributed in large part (even more so than SQL injection attacks) because of a poorly protected user or system account that were penetrated. From my experience the reason why this issue is so prevalent is because companies do not have the resources – people and time – to properly administer their user accounts and access to their networks and systems. Companies are also increasingly outsourcing their IT operations to third party service providers who sometimes don&#8217;t do any better at securing user accounts. As IT staff has shrunk over the past four years, the effective security of user accounts and access has diminished. It is becoming more and more evident that automating the management of user accounts and passwords, or identity and access in the security vernacular, is the key to addressing this problem.</p>
<p>&nbsp;</p>
<p>According to Wikipedia, identity and access management (sometimes abbreviated as IDM or IAM) &#8220;describes the management of individual identities, their authentication, authorization, and privileges/permissions within or across systems and enterprise boundaries with the goal of increasing security and productivity while decreasing cost, downtime and repetitive tasks.&#8221; In other words, an IDM product suite, such as Oracle Identity Management 11g, provides a centralized capability to manage and secure user accounts and access including ensuring that user accounts are valid, users have only the access to what they have a valid business need for, passwords are secure and consistently applied to all systems and applications according to company security policy, and that the company can monitor and audit user activities to ensure that access is not abused. These products can also provide additional benefits such as single sign-on and reporting for compliance purposes. With these kinds of protections in place my job of penetrating your systems and stealing your sensitive data is that much more difficult, and that&#8217;s a good thing.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bluenog.com/the-critical-role-of-identity-access-management/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
