Presentation is loading. Please wait.

Presentation is loading. Please wait.

1 Governance in Identity Management Federations Clair Goldsmith, Ph.D. The University of Texas System Administration.

Similar presentations


Presentation on theme: "1 Governance in Identity Management Federations Clair Goldsmith, Ph.D. The University of Texas System Administration."— Presentation transcript:

1 1 Governance in Identity Management Federations Clair Goldsmith, Ph.D. The University of Texas System Administration

2 2 Governance: A Definition “ It is the process through which a group of people make decisions that direct their collective efforts.” Institute on Governance It is fluid, time-consuming and unpredictable It is fluid, time-consuming and unpredictable Complicated by number and variety of stakeholders Complicated by number and variety of stakeholders Focuses on strategic aspects of decision- making Focuses on strategic aspects of decision- making

3 3 Why is Governance Needed? Oversight and Conflict Resolution Oversight and Conflict Resolution Establish and manage trust agreements Establish and manage trust agreements Determine direction and formulate policy Determine direction and formulate policy Ensure services meet business needs while maintaining the appropriate security and compliance with legal requirements Ensure services meet business needs while maintaining the appropriate security and compliance with legal requirements Establish and communicate operational standards and processes Establish and communicate operational standards and processes

4 4 What is the Alternative? Collection of one-to-one agreements Collection of one-to-one agreements Conflicting agendas and no common goal Conflicting agendas and no common goal No technology standards and inconsistency in operating practices No technology standards and inconsistency in operating practices No assurance of appropriate security and compliance with legal requirements No assurance of appropriate security and compliance with legal requirements

5 5 Governance Models Homogeneous Institutions Operating Standards and Practices may vary from institution to institution, but… Operating Standards and Practices may vary from institution to institution, but… Governance policies should be relatively consistent, and… Governance policies should be relatively consistent, and… Legal requirements should be similar if not the same Legal requirements should be similar if not the sameConsiderations Governance may be more tightly structured Governance may be more tightly structured Governance through Executive Committees or Governing Boards Governance through Executive Committees or Governing Boards Key executives make decisions Key executives make decisions

6 6 Governance Models (cont.) Diverse Institutions Operating Standards and Practices vary from institution to institution, and… Operating Standards and Practices vary from institution to institution, and… Governance policies are not consistent, and… Governance policies are not consistent, and… No formal authority to force a decision, and… No formal authority to force a decision, and… Legal requirements may not be similar at all. Legal requirements may not be similar at all.Considerations Governance may be more loosely organized Governance may be more loosely organized Reliance on advisory groups to formulate recommendations Reliance on advisory groups to formulate recommendations Guidance through Steering Committees Guidance through Steering Committees Collegiality as opposed to strong governance Collegiality as opposed to strong governance

7 7 Where Does The University of Texas System Fit? Homogeneous Homogeneous Share a common MissionShare a common Mission Same governance body and consistent governance policiesSame governance body and consistent governance policies Same legal requirementsSame legal requirements And Also Diverse And Also Diverse Significant differences in size and budgets Significant differences in culture Institutions enjoy considerable autonomy 16 “stovepipes” 16 Institutions 16 Institutions 9 General Academic institutions9 General Academic institutions 6 Health institutions6 Health institutions 1 System Administration1 System Administration

8 8 The most common examples are: The most common examples are: Governance Models in Shibboleth Federations DiverseHomogeneous InQueue InCommonUT SystemEAF

9 9 UT System IdM Federation Test Identity Management Federation Exists Test Identity Management Federation Exists Initially, for UT institutions only: Sixteen UT member institutions Initially, for UT institutions only: Sixteen UT member institutions UT System Identity Management Federation Board appointed UT System Identity Management Federation Board appointed Policy Documents created Policy Documents created Will operate under the authority of the UT System Board of Regents Will operate under the authority of the UT System Board of Regents

10 10 UT System IdM Federation (cont.) Five Shibboleth Applications in Production Five Shibboleth Applications in Production The guest wireless network at System Administration The guest wireless network at System Administration The Monthly Financial Reporting application (MFR) is used by budget coordinators from each UT institution. The Monthly Financial Reporting application (MFR) is used by budget coordinators from each UT institution. Shibboleth version of Blackboard at the UT Health Science Center at Houston to provide courses offered by the Health Science Center to students at M.D. Anderson. Shibboleth version of Blackboard at the UT Health Science Center at Houston to provide courses offered by the Health Science Center to students at M.D. Anderson. Research Collaborations Inventory application at UT System Administration Academic Affairs to report on collaborative research efforts throughout the UT System. Research Collaborations Inventory application at UT System Administration Academic Affairs to report on collaborative research efforts throughout the UT System. Time Sheet application at the Office of Facilities Planning and Construction used project managers at several UT institutions Time Sheet application at the Office of Facilities Planning and Construction used project managers at several UT institutions

11 11 What is Needed? Vision Vision Business Drivers Business Drivers A Plan A Plan Executive Buy-In Executive Buy-In Funding Funding It Is AContinualProcess

12 12 UT System IdM Federation: Governance

13 13 Governance: Issues to Ponder The Technical implementation aspects of Federation can get way ahead of Policy and Governance Governance entangled with power / autonomy conflicts Governance entangled with power / autonomy conflicts Priorities vary by institutionPriorities vary by institution Conventions may be seen as dictatesConventions may be seen as dictates Managing trust relationships is complex enough when dealing with institutions within the same system (among “family”.) Complexity increases as diversity of membership increases

14 14 Governance: Issues to Ponder (cont.) Indemnification What happens when something goes wrong? Who is liable? How to handle intra-institutional trust and indemnification Federation to Federation Trust Agreements

15 15 THANK YOU


Download ppt "1 Governance in Identity Management Federations Clair Goldsmith, Ph.D. The University of Texas System Administration."

Similar presentations


Ads by Google