Cargando…

Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall”

Single Sign-On (SSO) projects are a special case of Identity and Access Management (IAM) projects. They are usually undertaken with the aim of increasing the user friendliness of Corporate IT systems’ user log-on processes. This should result in abolishing the use of multiple username and password c...

Descripción completa

Detalles Bibliográficos
Autor principal: Lasance, Marcus
Formato: Online Artículo Texto
Lenguaje:English
Publicado: 2010
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7121900/
http://dx.doi.org/10.1007/978-3-8348-9788-6_5
_version_ 1783515303835074560
author Lasance, Marcus
author_facet Lasance, Marcus
author_sort Lasance, Marcus
collection PubMed
description Single Sign-On (SSO) projects are a special case of Identity and Access Management (IAM) projects. They are usually undertaken with the aim of increasing the user friendliness of Corporate IT systems’ user log-on processes. This should result in abolishing the use of multiple username and password combinations the user has to remember and change at different intervals. The SSO aim should be achieved without jeopardizing information security in any way. Increasing user convenience in such a manner will increase user satisfaction with the IT department along with general productivity levels. Cost control related to IT help desks resetting forgotten passwords should follow. SSO can also help organizations address information security compliance requirements, through the central logging (and audit facilities) of all access attempts and authorization decisions granted in relation to the organization’s restricted information resources. Sometimes compliance objectives are in fact the major business driver for SSO. In the consumer space customer loyalty and retention rates are often cited as an important commercial driver for SSO projects. With the advent of the de-perimeterized organization and increased scepticism around ‘Cloud Security’ is SSO still a viable worthwhile goal for organisations? This paper takes a closer look at special security issues arising when an organization attempts to create an Enterprise Single Sign-On (ESSO) solution that includes both legacy applications hosted within traditional organizational firewalls and a new breed of ‘Cloud Based’ solutions that are following the Software as Service (SaaS) model and therefore can be hosted with any number of Service Providers (SP) ‘in the cloud’.
format Online
Article
Text
id pubmed-7121900
institution National Center for Biotechnology Information
language English
publishDate 2010
record_format MEDLINE/PubMed
spelling pubmed-71219002020-04-06 Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall” Lasance, Marcus ISSE 2010 Securing Electronic Business Processes Article Single Sign-On (SSO) projects are a special case of Identity and Access Management (IAM) projects. They are usually undertaken with the aim of increasing the user friendliness of Corporate IT systems’ user log-on processes. This should result in abolishing the use of multiple username and password combinations the user has to remember and change at different intervals. The SSO aim should be achieved without jeopardizing information security in any way. Increasing user convenience in such a manner will increase user satisfaction with the IT department along with general productivity levels. Cost control related to IT help desks resetting forgotten passwords should follow. SSO can also help organizations address information security compliance requirements, through the central logging (and audit facilities) of all access attempts and authorization decisions granted in relation to the organization’s restricted information resources. Sometimes compliance objectives are in fact the major business driver for SSO. In the consumer space customer loyalty and retention rates are often cited as an important commercial driver for SSO projects. With the advent of the de-perimeterized organization and increased scepticism around ‘Cloud Security’ is SSO still a viable worthwhile goal for organisations? This paper takes a closer look at special security issues arising when an organization attempts to create an Enterprise Single Sign-On (ESSO) solution that includes both legacy applications hosted within traditional organizational firewalls and a new breed of ‘Cloud Based’ solutions that are following the Software as Service (SaaS) model and therefore can be hosted with any number of Service Providers (SP) ‘in the cloud’. 2010-12-28 /pmc/articles/PMC7121900/ http://dx.doi.org/10.1007/978-3-8348-9788-6_5 Text en © Vieweg+Teubner Verlag | Springer Fachmedien Wiesbaden GmbH 2011 This article is made available via the PMC Open Access Subset for unrestricted research re-use and secondary analysis in any form or by any means with acknowledgement of the original source. These permissions are granted for the duration of the World Health Organization (WHO) declaration of COVID-19 as a global pandemic.
spellingShingle Article
Lasance, Marcus
Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall”
title Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall”
title_full Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall”
title_fullStr Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall”
title_full_unstemmed Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall”
title_short Single Sign-on(SSO) to Cloud based Services and Legacy Applications “Hitting the IAM wall”
title_sort single sign-on(sso) to cloud based services and legacy applications “hitting the iam wall”
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7121900/
http://dx.doi.org/10.1007/978-3-8348-9788-6_5
work_keys_str_mv AT lasancemarcus singlesignonssotocloudbasedservicesandlegacyapplicationshittingtheiamwall