SlideShare a Scribd company logo
1 of 13
Download to read offline
Information Security in a 
  Recovering Economy

         Robin Wilton
 Director – Future Identity Ltd
           May 2009
                
Agenda
  Opening Keynote Presentation for
  Global Security Solutions, Johannesburg, South Africa
  Identity Management and Privacy Conference 2009



 Why me? ­ Future Identity's stakeholder engagement strategy
 Principles
 Policies
 Practicalities
 Problems to solve ... 

                             2
Why me?
 Future Identity Ltd: founded Jan 2009 on 25 years' experience
 Previous posts at IBM, JCP Trustbase and Sun Microsystems
 2005­2009: Sun's Corporate Architect for Federated Identity
 2006­2008: Co­chair of Liberty Alliance Public Policy Expert Group 


 Consulting engagements with public sector and Kantara Initiative
 Director of Privacy and Public Policy, Liberty Alliance


 Particular focus on privacy, and the policy/technology interface



                                  3
Future Identity's
       Stakeholder Engagement Strategy
                              • Policymakers – define the
                              privacy landscape we must
 Key constituencies:
                              inhabit and cross
    Policymakers
                              • Adopters – (CPOs, users...) -
    Adopters                 have to resolve the tension between
    Regulators               motivation and risk


                              • Regulators – are our protection
 The neat trick is           against poor policy, inadequate
                              legislation and flawed adoption
  often translating           (including 'toxic' market forces)
  successfully between 
  them                        Ignoring any of these stakeholder
                              communities leads to worse privacy
                              outcomes ...


                          4
What's the intersection between
        'information security' and 'privacy'?

                                                               Raw
                                       Discipline
                                                             Materials
 A Maslovian hierarchy of 
  information and 
  disciplines:                    • Privacy Assurance:       Attributes

 It's hard to address the 
                                  • Privacy Management:      Personas
  upper layers without 
  competence in the lower         • Identity Management:     People
  layers;
                                  • Information Management
 In practice, “progress” 
                                  (including information
  usually means “unlocking        and data security):        Accounts
  the next set of problems”


                              5
All else being equal...

                                                        Pre­2009: data
... it is cheaper and easier to:
 Store vs. destroy 
  (especially selectively)
 Share vs. 
  compartmentalise
 Aggregate vs. segregate
 Visualise vs. conceal
Technology tends to reinforce 
this trend. 


The principal counter­force is 
governance, which is people­
intensive, and expensive, and 
suffers accordingly when 
                                   2009: mashup
money is scarce.


                                          6
However, all else is not (currently) 
                        equal ...
                                     • Reduced commercial activity
 IT vendors and adopters are        • Reduced revenues

  used to:                           • “Sweat” assets – including personal data
                                     • Pressure to reduce 'cost of compliance'
    Decades of growth;
    Sustained investment;
                                                    Commercial
    A “price/performance” 
                                                       Sector
      equation to match;                                             Public
    The innovation                                                  Sector

      “ecosystem” all this 
                                     • Reduced economic activity
      combines to create.            • Reduced tax revenues
                                     • Pressure to reduce 'cost of collection'
                                          • CCTV parking fines
 We now have to adapt to:                • Speed cameras, ANPR
                                     • Automate, and process only exceptions
   Changed assumptions
                                     None of these factors makes more,
   Shifts in balance
                                     or better governance more likely
   New tensions
                                 7
The Balance of Technology
                              and Governance
    Failures of process and culture take more sustained effort to address.
    A technical ('quick') fix is soon trumped.

Distorted cost/risk equation:


      Extracting 500 records 

      from 25 million;
      Process for applying 

      security technology;
vs.
      Disclosing all records.



Cost was immediate; risk 
was remote in time and 
place...

                                         8
Policy: how might it shape the 
                            landscape?
 Cost:
    One policy response is to offload 
      cost (e.g. to industry) 
 Risk:
    What happens to risk in this 
      model? Who 'owns' the problem, 
      and who feels responsible?
 Regulation:
    Regulatory picture changes from 
      being centralised and 'internal' to 
      being distributed among multiple 
      (commercial) third parties.
 Technology:
    Heterogeneous, 'market led';
    Doomed if cost, risk and regulatory 
      factors are not addressed.

                                       9
Practicalities: 
                        Governance Revisited

 Requirements may be:                                                  “Raw
                                              Discipline
                                                                     Materials”
    Country­specific
    Industry­specific
                                                                    Ethical principles
                                         • Privacy Management:
    Cross­industry and cross­
     border
                                                                      LoA, Risk,
 Industry response is sometimes                                      Contractual
                                         • Identity Assurance:
  to pre­empt regulation (e.g.                                        Frameworks
  Binding Corporate Rule)
                                                                    Joiners/Movers/
                                         • Identity Management:
 Whether externally imposed or                                      Leavers, Roles
  internally adopted, governance 
  assumes healthy disciplines                                        Good practice
  (technical, procedural,                                            e.g. BS7799,
                                         • Information Management
  cultural...)                                                       PIAs, Audit,
                                         (including information
                                                                     Inventories
 As before, a hierarchy can be          and data security):
                                                                     of PII ...
  sketched out.

                                    10
Exercises for the reader
             (there are still plenty to go round...)

                                            Requirements may be:
• Balance of technology and policy
                                               Country­specific
                                                 Industry­specific
 • Climbing the hierarchy:                       Cross­industry and cross­
                                                  border
                                            In the hierarchy, there's always 
                     Attributes
                                             something to aspire to...
                  Personas
           Credentials
      Accounts


• Managing contexts & relationships
                                            Some of these problems are yet to 
• Metaphors, metadata and
                                             be comprehensively defined, let 
'sticky policy'
                                             alone solved...



                                      11
Conclusions
 Principles:
         Well­defined, or definable
     
         Often philosophical/ethical in nature
     
         Need to account for all the stakeholder groups
     
 Policy:
         Likely to be tested by recession/recovery
     
         Pressure will be on to cut (or outsource) cost
     
         Governance measures will feel the pinch
     
 Practicalities:
         Disciplines further up the hierarchy are still being 
     
         developed (identity assurance, privacy management)
         A road­map can be drafted, though
     
         What is practical depends on context and adoption 
     
         readiness 
 Problems: 
         Still plenty of scope for innovation, if the economic 
     
         climate permits it.



                                                  12
Thank You



Robin Wilton
Director
Future Identity Ltd

Director of Privacy and Public Policy
Liberty Alliance

mail@futureidentity.eu
+44 (0)705 005 2931




                         13

More Related Content

Viewers also liked

หลักสูตรสถานศึกษา23
หลักสูตรสถานศึกษา23หลักสูตรสถานศึกษา23
หลักสูตรสถานศึกษา23mariamsamadeng
 
Senior project pictures
Senior project picturesSenior project pictures
Senior project picturescheshire4
 
Enquadramento do estudo energético do concelho de vieira do minho
Enquadramento do estudo energético do concelho de vieira do minhoEnquadramento do estudo energético do concelho de vieira do minho
Enquadramento do estudo energético do concelho de vieira do minhoMicael Gonçalves
 
Leasingrückgabe flyer fahrzeugklinik
Leasingrückgabe flyer fahrzeugklinikLeasingrückgabe flyer fahrzeugklinik
Leasingrückgabe flyer fahrzeugklinikfahrzeugklinik GmbH
 
Educator Autonomy: Common Themes and Barriers
Educator Autonomy:  Common Themes and BarriersEducator Autonomy:  Common Themes and Barriers
Educator Autonomy: Common Themes and Barriersppageegd
 
Generacionesdelascomputadoras 120308180659-phpapp01
Generacionesdelascomputadoras 120308180659-phpapp01Generacionesdelascomputadoras 120308180659-phpapp01
Generacionesdelascomputadoras 120308180659-phpapp01Vifredo Gomez
 
Invista Presentation
Invista PresentationInvista Presentation
Invista PresentationKyle McCurdy
 
Success Vision Through Life Experience (HK & HR)
Success Vision Through Life Experience (HK & HR)Success Vision Through Life Experience (HK & HR)
Success Vision Through Life Experience (HK & HR)Nihal Shiroya
 
1 introducción a los sistemas informáticos
1 introducción a los sistemas informáticos1 introducción a los sistemas informáticos
1 introducción a los sistemas informáticosconrado perea
 
El mundo del tuning cada vez es más extenso
El mundo del tuning cada vez es más extensoEl mundo del tuning cada vez es más extenso
El mundo del tuning cada vez es más extensoMartincalvo
 
Procesos vrs programas
Procesos vrs programasProcesos vrs programas
Procesos vrs programasVifredo Gomez
 

Viewers also liked (19)

หลักสูตรสถานศึกษา23
หลักสูตรสถานศึกษา23หลักสูตรสถานศึกษา23
หลักสูตรสถานศึกษา23
 
Senior project pictures
Senior project picturesSenior project pictures
Senior project pictures
 
Enquadramento do estudo energético do concelho de vieira do minho
Enquadramento do estudo energético do concelho de vieira do minhoEnquadramento do estudo energético do concelho de vieira do minho
Enquadramento do estudo energético do concelho de vieira do minho
 
Acentuacion diptongo hiato
Acentuacion diptongo hiatoAcentuacion diptongo hiato
Acentuacion diptongo hiato
 
Trenamento Mc3
Trenamento Mc3Trenamento Mc3
Trenamento Mc3
 
Riena onrap econ-2011
Riena onrap econ-2011Riena onrap econ-2011
Riena onrap econ-2011
 
Leasingrückgabe flyer fahrzeugklinik
Leasingrückgabe flyer fahrzeugklinikLeasingrückgabe flyer fahrzeugklinik
Leasingrückgabe flyer fahrzeugklinik
 
practica n.1 de word
practica n.1 de wordpractica n.1 de word
practica n.1 de word
 
T3001 Larissa
T3001 LarissaT3001 Larissa
T3001 Larissa
 
Mt
MtMt
Mt
 
3
33
3
 
Educator Autonomy: Common Themes and Barriers
Educator Autonomy:  Common Themes and BarriersEducator Autonomy:  Common Themes and Barriers
Educator Autonomy: Common Themes and Barriers
 
Generacionesdelascomputadoras 120308180659-phpapp01
Generacionesdelascomputadoras 120308180659-phpapp01Generacionesdelascomputadoras 120308180659-phpapp01
Generacionesdelascomputadoras 120308180659-phpapp01
 
Invista Presentation
Invista PresentationInvista Presentation
Invista Presentation
 
Success Vision Through Life Experience (HK & HR)
Success Vision Through Life Experience (HK & HR)Success Vision Through Life Experience (HK & HR)
Success Vision Through Life Experience (HK & HR)
 
War
WarWar
War
 
1 introducción a los sistemas informáticos
1 introducción a los sistemas informáticos1 introducción a los sistemas informáticos
1 introducción a los sistemas informáticos
 
El mundo del tuning cada vez es más extenso
El mundo del tuning cada vez es más extensoEl mundo del tuning cada vez es más extenso
El mundo del tuning cada vez es más extenso
 
Procesos vrs programas
Procesos vrs programasProcesos vrs programas
Procesos vrs programas
 

Similar to RW Keynote IDM2009

CFITS Disaster Recovery 2009
CFITS Disaster Recovery 2009CFITS Disaster Recovery 2009
CFITS Disaster Recovery 2009cfits
 
Information Security - The Missing Elements
Information Security - The Missing ElementsInformation Security - The Missing Elements
Information Security - The Missing Elementsahmed_vr
 
Missouri Issues in Workers’ Compensation General Session
Missouri Issues in Workers’ Compensation General SessionMissouri Issues in Workers’ Compensation General Session
Missouri Issues in Workers’ Compensation General SessionKurt Madel
 
ISSA DLP Presentation - Oxford Consulting Group
ISSA DLP Presentation - Oxford Consulting GroupISSA DLP Presentation - Oxford Consulting Group
ISSA DLP Presentation - Oxford Consulting Groupaengelbert
 
InfoSecurity Magazine - Data Loss Prevention
InfoSecurity Magazine - Data Loss PreventionInfoSecurity Magazine - Data Loss Prevention
InfoSecurity Magazine - Data Loss PreventionSimon Perry
 
Prefix Capabilities Summary
Prefix Capabilities SummaryPrefix Capabilities Summary
Prefix Capabilities Summaryrcdb0lton
 
Getting Management Buy In Your Top 7 Actions
Getting Management Buy In   Your Top 7 ActionsGetting Management Buy In   Your Top 7 Actions
Getting Management Buy In Your Top 7 ActionsAndrewLi
 
IT Optimization & Risk Management
IT Optimization & Risk ManagementIT Optimization & Risk Management
IT Optimization & Risk ManagementJeromie Jackson
 
Business Resilience
Business ResilienceBusiness Resilience
Business Resiliencerix57
 
LINKIES. NEWS II / 2009
LINKIES. NEWS II / 2009LINKIES. NEWS II / 2009
LINKIES. NEWS II / 2009LINKIES.
 
Emids Morning Security Virtual India V3
Emids Morning Security Virtual India V3Emids Morning Security Virtual India V3
Emids Morning Security Virtual India V3techcouncil
 
Credit Risk Msia
Credit Risk MsiaCredit Risk Msia
Credit Risk MsiaTommy Seah
 
Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008
Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008
Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008Ian Jindal
 
PS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommercePS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommerceIan Jindal
 
PS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommercePS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommerceguest904b2b
 
The Rational Approach to Disruptive Information Security
The Rational Approach to Disruptive Information SecurityThe Rational Approach to Disruptive Information Security
The Rational Approach to Disruptive Information SecurityRavila White
 
Conscientia Consulting
Conscientia ConsultingConscientia Consulting
Conscientia Consultingswindlehurst
 
Company Presentation En 2009
Company Presentation En 2009Company Presentation En 2009
Company Presentation En 2009nicebob2004
 
Company Presentation En 2009
Company Presentation En 2009Company Presentation En 2009
Company Presentation En 2009nicebob2004
 

Similar to RW Keynote IDM2009 (20)

CFITS Disaster Recovery 2009
CFITS Disaster Recovery 2009CFITS Disaster Recovery 2009
CFITS Disaster Recovery 2009
 
Information Security - The Missing Elements
Information Security - The Missing ElementsInformation Security - The Missing Elements
Information Security - The Missing Elements
 
Missouri Issues in Workers’ Compensation General Session
Missouri Issues in Workers’ Compensation General SessionMissouri Issues in Workers’ Compensation General Session
Missouri Issues in Workers’ Compensation General Session
 
ISSA DLP Presentation - Oxford Consulting Group
ISSA DLP Presentation - Oxford Consulting GroupISSA DLP Presentation - Oxford Consulting Group
ISSA DLP Presentation - Oxford Consulting Group
 
InfoSecurity Magazine - Data Loss Prevention
InfoSecurity Magazine - Data Loss PreventionInfoSecurity Magazine - Data Loss Prevention
InfoSecurity Magazine - Data Loss Prevention
 
Prefix Capabilities Summary
Prefix Capabilities SummaryPrefix Capabilities Summary
Prefix Capabilities Summary
 
Getting Management Buy In Your Top 7 Actions
Getting Management Buy In   Your Top 7 ActionsGetting Management Buy In   Your Top 7 Actions
Getting Management Buy In Your Top 7 Actions
 
IT Optimization & Risk Management
IT Optimization & Risk ManagementIT Optimization & Risk Management
IT Optimization & Risk Management
 
Business Resilience
Business ResilienceBusiness Resilience
Business Resilience
 
LINKIES. NEWS II / 2009
LINKIES. NEWS II / 2009LINKIES. NEWS II / 2009
LINKIES. NEWS II / 2009
 
Emids Morning Security Virtual India V3
Emids Morning Security Virtual India V3Emids Morning Security Virtual India V3
Emids Morning Security Virtual India V3
 
Credit Risk Msia
Credit Risk MsiaCredit Risk Msia
Credit Risk Msia
 
Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008
Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008
Ian Jindal: Presentation to the "Future of Digital Marketing", June 2008
 
PS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommercePS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommerce
 
PS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommercePS067-bazaarvoice-socialcommerce
PS067-bazaarvoice-socialcommerce
 
The Rational Approach to Disruptive Information Security
The Rational Approach to Disruptive Information SecurityThe Rational Approach to Disruptive Information Security
The Rational Approach to Disruptive Information Security
 
Conscientia Consulting
Conscientia ConsultingConscientia Consulting
Conscientia Consulting
 
Company Presentation En 2009
Company Presentation En 2009Company Presentation En 2009
Company Presentation En 2009
 
Company Presentation En 2009
Company Presentation En 2009Company Presentation En 2009
Company Presentation En 2009
 
Business Redesign with Decision Management
Business Redesign with Decision ManagementBusiness Redesign with Decision Management
Business Redesign with Decision Management
 

Recently uploaded

Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Neo4j
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024BookNet Canada
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsHyundai Motor Group
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfngoud9212
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 

Recently uploaded (20)

Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdf
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 

RW Keynote IDM2009

  • 1. Information Security in a  Recovering Economy Robin Wilton Director – Future Identity Ltd May 2009  
  • 2. Agenda Opening Keynote Presentation for Global Security Solutions, Johannesburg, South Africa Identity Management and Privacy Conference 2009  Why me? ­ Future Identity's stakeholder engagement strategy  Principles  Policies  Practicalities  Problems to solve ...  2
  • 3. Why me?  Future Identity Ltd: founded Jan 2009 on 25 years' experience  Previous posts at IBM, JCP Trustbase and Sun Microsystems  2005­2009: Sun's Corporate Architect for Federated Identity  2006­2008: Co­chair of Liberty Alliance Public Policy Expert Group   Consulting engagements with public sector and Kantara Initiative  Director of Privacy and Public Policy, Liberty Alliance  Particular focus on privacy, and the policy/technology interface 3
  • 4. Future Identity's Stakeholder Engagement Strategy • Policymakers – define the privacy landscape we must  Key constituencies: inhabit and cross  Policymakers • Adopters – (CPOs, users...) -  Adopters have to resolve the tension between  Regulators motivation and risk • Regulators – are our protection  The neat trick is  against poor policy, inadequate legislation and flawed adoption often translating  (including 'toxic' market forces) successfully between  them Ignoring any of these stakeholder communities leads to worse privacy outcomes ... 4
  • 5. What's the intersection between 'information security' and 'privacy'? Raw Discipline Materials  A Maslovian hierarchy of  information and  disciplines: • Privacy Assurance: Attributes  It's hard to address the  • Privacy Management: Personas upper layers without  competence in the lower  • Identity Management: People layers; • Information Management  In practice, “progress”  (including information usually means “unlocking  and data security): Accounts the next set of problems” 5
  • 6. All else being equal... Pre­2009: data ... it is cheaper and easier to:  Store vs. destroy  (especially selectively)  Share vs.  compartmentalise  Aggregate vs. segregate  Visualise vs. conceal Technology tends to reinforce  this trend.  The principal counter­force is  governance, which is people­ intensive, and expensive, and  suffers accordingly when  2009: mashup money is scarce. 6
  • 7. However, all else is not (currently)  equal ... • Reduced commercial activity  IT vendors and adopters are  • Reduced revenues used to: • “Sweat” assets – including personal data • Pressure to reduce 'cost of compliance'  Decades of growth;  Sustained investment; Commercial  A “price/performance”  Sector equation to match;  Public  The innovation  Sector “ecosystem” all this  • Reduced economic activity combines to create. • Reduced tax revenues • Pressure to reduce 'cost of collection' • CCTV parking fines  We now have to adapt to: • Speed cameras, ANPR • Automate, and process only exceptions  Changed assumptions None of these factors makes more,  Shifts in balance or better governance more likely  New tensions 7
  • 8. The Balance of Technology and Governance Failures of process and culture take more sustained effort to address. A technical ('quick') fix is soon trumped. Distorted cost/risk equation: Extracting 500 records   from 25 million; Process for applying   security technology; vs. Disclosing all records.  Cost was immediate; risk  was remote in time and  place... 8
  • 9. Policy: how might it shape the  landscape?  Cost:  One policy response is to offload  cost (e.g. to industry)   Risk:  What happens to risk in this  model? Who 'owns' the problem,  and who feels responsible?  Regulation:  Regulatory picture changes from  being centralised and 'internal' to  being distributed among multiple  (commercial) third parties.  Technology:  Heterogeneous, 'market led';  Doomed if cost, risk and regulatory  factors are not addressed. 9
  • 10. Practicalities:  Governance Revisited  Requirements may be: “Raw Discipline Materials”  Country­specific  Industry­specific Ethical principles • Privacy Management:  Cross­industry and cross­ border LoA, Risk,  Industry response is sometimes  Contractual • Identity Assurance: to pre­empt regulation (e.g.  Frameworks Binding Corporate Rule) Joiners/Movers/ • Identity Management:  Whether externally imposed or  Leavers, Roles internally adopted, governance  assumes healthy disciplines  Good practice (technical, procedural,  e.g. BS7799, • Information Management cultural...)  PIAs, Audit, (including information Inventories  As before, a hierarchy can be  and data security): of PII ... sketched out. 10
  • 11. Exercises for the reader (there are still plenty to go round...)  Requirements may be: • Balance of technology and policy  Country­specific  Industry­specific • Climbing the hierarchy:  Cross­industry and cross­ border  In the hierarchy, there's always  Attributes something to aspire to... Personas Credentials Accounts • Managing contexts & relationships  Some of these problems are yet to  • Metaphors, metadata and be comprehensively defined, let  'sticky policy' alone solved... 11
  • 12. Conclusions  Principles: Well­defined, or definable  Often philosophical/ethical in nature  Need to account for all the stakeholder groups   Policy: Likely to be tested by recession/recovery  Pressure will be on to cut (or outsource) cost  Governance measures will feel the pinch   Practicalities: Disciplines further up the hierarchy are still being   developed (identity assurance, privacy management) A road­map can be drafted, though  What is practical depends on context and adoption   readiness   Problems:  Still plenty of scope for innovation, if the economic   climate permits it. 12