How Should Businesses Manage Online Identity Risk?

129 views
•
May 1, 2014
by
RSAC Cybersecurity
YouTube video player
How Should Businesses Manage Online Identity Risk?

TL;DR

Businesses should begin with a risk assessment, then select an identity system whose technical and contractual controls match their data sensitivity, threats, and access requirements. Because existing law remains ambiguous, organizations should carefully examine privacy obligations, liability allocation, and operating rules, while seeking opportunities to help shape the trust frameworks that govern multi-party identity arrangements.

Transcript

Hi, I'm Tom Field, Vice President of Editorial with Information Security Media Group. I'm talking about online identity today. I'm talking with Tom Smedinghoff. He's a partner with the law firm of Edwards Wildman Palmer LLP. Tom, thanks so much for joining me today. Thanks for having me. Just as an introduction to our audience, tell us a little bit... Read More

Key Insights

  • Online identity management is becoming complex and expensive for businesses to operate independently, encouraging them to rely on third parties through federated identity arrangements that distribute identity verification and information-sharing responsibilities across multiple participating organizations.
  • Privacy is a central legal issue because identity systems collect, verify, and communicate personal information. Every organization participating in a multi-party arrangement must understand how the system's rules affect its handling and use of that information.
  • Liability is uncertain when one party asserts an identity incorrectly and another party relies on that assertion. Ambiguous existing law makes the resulting risk difficult to predict and can discourage organizations from participating in proposed online identity projects.
  • Identity is a critical component of security because organizations must know who receives access to their servers, databases, and sensitive information. The reliability required from an identity system therefore depends on the access and transaction risks involved.
  • The law governing identity transactions has three layers: generally applicable law, government-driven regulation or voluntary public structures, and private contractual trust frameworks that establish operating rules for organizations participating in a particular identity system.
  • Private trust frameworks give participating organizations a practical means to specify operating requirements, allocate risk, and establish reliable identity processes. These contractual rules can address functionality, privacy, and liability where broader legal requirements remain unclear.
  • A business risk assessment is the necessary starting point for selecting an identity system. Organizations must identify their assets, needs, threats, vulnerabilities, and risk points before determining the appropriate strength of identity verification and related controls.
  • Identity assurance must match transaction sensitivity. Self-asserted information, such as information supplied through Facebook Connect, may suit simple uses without guarantees, while access to sensitive aerospace and defense data requires substantially more robust technical and legal controls.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What legal risks arise from federated identity management?

Federated identity management creates privacy and liability risks because several parties participate in verifying or communicating personal information. Privacy concerns arise from handling identity data, while liability becomes important if one party makes an incorrect identity assertion and another party relies on it. Existing law is ambiguous about how these transactions are treated, so contractual operating rules are important for defining responsibilities and allocating risk.

Q: Why is liability a major concern in online identity systems?

Liability becomes a major concern when an identity provider supplies incorrect information and another organization acts on it. The affected parties may not know who bears responsibility for the resulting harm because existing law is ambiguous and its application to identity transactions is still developing. This uncertainty can become a barrier to online identity projects unless participants use contractual rules to allocate risk clearly.

Q: What are the three legal layers governing identity transactions?

The first layer consists of general existing laws that apply across many transactions, although their application to identity systems may be uncertain. The second involves government-driven regulation or voluntary public structures, including activity in Europe and the United States NSTIC program. The third consists of private trust frameworks or operating rules, which contractually define how a particular identity system functions and how participating parties allocate risk.

Q: Why are private trust frameworks important for businesses?

Private trust frameworks allow participants to establish rules for how identity information is supplied, accepted, and used. They can allocate risk among different parties, define functional responsibilities, and make identity assertions more trustworthy. These contractual arrangements are particularly important because broader law remains uncertain, leaving businesses to manage privacy and liability concerns through rules tailored to the identity system in which they participate.

Q: How should an organization assess online identity vulnerabilities?

An organization should start with a risk assessment focused on its individual business environment. It must identify what information and systems it has, what threats and vulnerabilities it faces, where its main risk points exist, and what level of identity confidence its operations require. Without that foundation, the organization cannot sensibly choose an identity system or determine which technical and legal controls are appropriate.

Q: How should identity controls vary by transaction sensitivity?

Identity controls should become stronger as the sensitivity and potential consequences of a transaction increase. A simple website login may rely on self-asserted information provided through Facebook Connect, which offers no guarantees beyond passing along available information. By contrast, third-party access to sensitive aerospace and defense data requires a robust system that combines stronger identity processes, technical safeguards, and legal controls.

Q: How can businesses influence online identity operating rules?

Businesses can seek a voice by participating in groups and programs developing approaches to identity management. The interview identifies the NSTIC process, Open Identity Exchange, Kantara, SAFE BioPharma, the federal program, and the Identity Ecosystem Steering Group as possible venues. Participation can help organizations shape operating rules before they are finalized, rather than merely evaluating and accepting rules developed by others.

Q: What should a business review before joining an identity system?

A business should closely review the identity system's operating rules, including how they affect privacy, liability, security, access control, and the reliability of identity assertions. It should compare those rules with its own needs, vulnerabilities, threats, and risk points. If the organization can help shape the rules, it should participate early. If it joins later, it must fully understand their business impact.

Summary & Key Takeaways

  • Online identity management becomes legally complicated when businesses rely on third parties to verify users or supply identity information. These federated arrangements involve personal information, creating privacy concerns. They also raise uncertain liability questions when an identity assertion is wrong and another participant relies on it when making an access or transaction decision.

  • The legal environment has three layers: general laws that may apply uncertainly, government-driven regulation or voluntary public programs, and private trust frameworks established through contracts. For participating businesses, contractual operating rules are especially important because they define system behavior, allocate risk among parties, and support confidence in the identity information exchanged.

  • Organizations should assess their assets, threats, vulnerabilities, business needs, and risk points before joining an identity system. Low-stakes access may tolerate self-asserted information without guarantees, while sensitive aerospace and defense data requires robust identity verification. Appropriate systems combine technical safeguards with legal controls and clearly understood participation rules.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚