Just-in-Time Authentication: Creating a New Balance of Security and Convenience

David Gormley, Sr. Principal CA Technologies, Security Business Unit
Enabling more sensitive online activities and transactions for a diverse user community (customers, partners, administrators) creates the need to have a high level of confidence that the person is who they say they are. At the same time the “Consumerization of IT” has raised user expectations for a smooth, intuitive online experience at anytime, from anywhere and from any device. This presents a real challenge because the historical relationship between authentication security and user convenience is inverse: as the strength of the authentication method goes up the user experience usually goes down.

With the emergence of new online threats, new device types and the increase in the amount of sensitive data available online, no one authentication method can meet all requirements to protect sensitive data and reduce fraud. There is a need for a flexible authentication system that can intelligently assess the risk of an activity and then require the appropriate authentication methods based on factors like the user, device, activity context and the activity itself. In this webcast, we will discuss the key requirements for a layered security approach that can enable a risk-appropriate and just-in-time authentication process which provides the security level required, while optimizing, or at least minimizing any negative impact on the customer experience.
Aug 7 2012
53 mins
Just-in-Time Authentication: Creating a New Balance of Security and Convenience
More from this community:

Mobile Computing

Webinars and videos

  • Live and recorded (514)
  • Upcoming (16)
  • Date
  • Rating
  • Views
  • Channel
  • Channel profile
Up Down
  • Accelerate Delivery of Secure, New Services and Improve the Customer Experience Jun 12 2013 5:00 pm UTC 60 mins
    With the “Consumerization of IT,” customers expect to interact at any time, from any device and this trend has fueled the rapid adoption of web and mobile services. As a result, organizations are racing to deliver new applications and services to innovate, grow their business and improve customer loyalty.  When developing new services for web and mobile channels, three items are critical to success:

    Overall customer experience
    Time-to-market
    Security

    Join this webcast to hear David Gormley and Tyson Whitten, Sr. Principals, Security Solutions for CA Technologies, discuss how a coordinated identity and access management approach can enable faster delivery of user-convenient services while protecting both the organization and customer.
  • Best Practices for Managing Today’s Complex Web of Digital Identities & Personas May 23 2013 4:00 pm UTC 60 mins
    The explosion of social media in recent years means that there are millions of users or ‘fans’ to reach and add to your customer base. While there are clear benefits to end-users and the organizations that accept their social identities for account creation and authentication, there are important risk factors that have to be considered as well.

    Please join CA and ISACA for this webinar, where we will review the pros and cons of social media login and Bring Your Own Identity (BYOI), and provide guidance and best practices based on real use cases to help guide organizations to a model that meets their risk profile.
  • Identity and Access Management in a Socially-Connected World May 22 2013 1:00 pm UTC 60 mins
    In today’s socially-connected world, conducting business effectively demands easy access to information from anywhere at any time. More people need access to more data through the use of more devices than ever before.

    Join this webcast and learn how CA Technologies helps companies across the world to enable business in a secure manner. Through the use of a Cloud Identity and Access Management service, CA allows the right people have access to the right information at the right time. By seamlessly leveraging existing investments, while extending Identity and Access Management to the cloud, CA Technologies vastly reduces the time to deliver secure new business services.
  • Mobile Application Security: A CA SiteMinder® Case Study Recorded: May 8 2013 31 mins
    Medium-sized organizations have many of the same business challenges as their larger counterparts – but often do not have the budget or resources to address them. Simeio Solutions recently helped a mid-sized financial company securely authenticate employees to their mobile applications. CA SiteMinder, with proven single-sign on and session management capabilities, allowed Simeio to cost-effectively streamline mobile application access for their customer in less than 90 days.

    Join this webcast to hear Ed Pascua from Simeio Solutions and Aaron Berman from CA Technologies discuss how CA SiteMinder and Simeio Solutions were able to quickly transform mobile application security for this organization.
  • The New CA SiteMinder® r12.51 Release Recorded: Apr 17 2013 61 mins
    Following the release of CA SiteMinder® r12.5 last year, CA Technologies is demonstrating its continued commitment to secure Single Sign-On (SSO) and Access Management with the release of CA SiteMinder r12.51. This release contains some exciting updates including:
    •Enhanced support for Web Service Interfaces
    •OAuth and OpenID support
    •Agent-less SSO, and new localized versions.

    Join us for this webcast, where Chris Wraight, Director, Security Solutions for CA Technologies will discuss the new enhancements to CA SiteMinder.
  • The State of Cloud Security 2013 Recorded: Mar 21 2013 64 mins
    In May of 2010, CA and The Ponemon Institute released a survey in North America and Europe on the security of cloud applications, infrastructure and platforms. Almost 3 years have passed from that initial study and CA and Ponemon have decided to revisit the topic.

    - What¹s changed in 3 years?
    - Are the concerns the same or have they evolved?
    - Have security threats changed to meet this new computing model?
    - Have solutions kept pace?
    - Are more standards in place?

    Join (ISC)2 along with CA, The Ponemon Institute and Cloud Security Alliance on March 21, 2013 for a discussion on the latest survey findings and what the industry thinks about cloud security issues.
  • CA CloudMinder™: Who’s Minding Your Cloud? Recorded: Feb 27 2013 46 mins
    As the IT landscape has evolved from mainframe to distributed computing, then to virtual and cloud, CA Technologies has been there helping to secure the world’s leading companies. Understanding that every business has different needs, CA continues to offer solutions to suit a wide range of IT environments. Now the same trusted name in IT security is helping to bridge the gap between physical, hybrid and cloud environments with CA CloudMinder™. As your own business and IT needs are evolving, now is a good time to consider…who’s minding your cloud?

    In this webcast, Chris Wraight, Director, Security Solutions for CA Technologies will demonstrate how the CA CloudMinder™ suite of cloud security solutions helps you adopt Identity and Access Management (IAM) in the cloud securely, on your own schedule and according to your own needs. Now you can secure user identities, access, and information within cloud, on-premise and hybrid environments.
  • Identity Management on the Go with CA IdentityMinderTM Mobile Recorded: Feb 20 2013 29 mins
    BYOD (bring your own device) is about enabling business users to access business information and applications, anytime, anywhere and from a range of personal devices. The new CA IdentityMinder mobile app provides BYOD access for some of the most common identity-related tasks an organization needs, but does so in a manner that is easy to setup, administer and use.

    In this webcast, Bob Burgess, Advisor, Solution Strategy at CA Technologies, will discuss how the CA IdentityMinder mobile app can provide:

    •Mobile access to password self-service and workflow approvals.
    •Simple setup, configuration and corporate branding of the app.
    •Complete control of which identity functions are available to mobile users.
    •Immediate termination of application access if device is lost or due to a user’s changed status.
    •Better business enablement in a mobile environment.
  • Reduce Risk and Improve Compliance with CA ControlMinderTM & GovernanceMinderTM Recorded: Feb 13 2013 49 mins
    Organizations need to provide administrators with access to shared and privileged accounts on a regular basis. Though a necessity, these shared accounts represent multiple regulatory compliance and information security challenges. Ensuring user accountability, controlling access to these accounts and regularly reviewing access to sensitive applications by these accounts are requirements imposed by regulations and good business practices.

    In this webcast, Steven McCullar and Bob Burgess, Security and Compliance Advisors with CA Technologies, will discuss how to:
    • Control access to privileged accounts via check-in and check-out processes
    • Provide temporary and/or emergency access to privileged accounts
    • Better ensure accountability for privileged accounts
    • Automate periodic access review of these special accounts
    You will learn how to take advantage of the above capabilities within your environment and in doing so help reduce your organization’s compliance risks by implementing better control of the shared account lifecycle.
  • Securely Virtualize Your Business-Critical Systems with Visibility and Control Recorded: Jan 30 2013 44 mins
    Virtualization is no longer the exclusive domain of non-core applications. By virtualizing mission-critical workloads, organizations are coming face-to-face with unique challenges around risk and compliance. Whether your organization is already grappling with these issues, or taking a ‘wait-and-see’ approach, a strong security posture is needed to gain all the benefits of virtualization.

    Learn how today’s virtualization security tools can help you:
    •Bring Privileged Identity Management to both the hypervisor and virtual machines
    •Enable accountability for your virtualization administrators
    •Automate security in a dynamic virtual environment
    •Mitigate the risk of new vulnerabilities in your virtualization platform
    •Meet virtualization compliance requirements

    In this webcast, Russ Miller, Principal and Steven McCullar, Advisor, Solution Strategy, Security Solutions for CA Technologies will discuss the controls available to virtualize your most business-critical systems, and help you stay ahead of the curve for security.
  • Mobile Authentication: Key Considerations for Developing Your Strategy Recorded: Jan 16 2013 59 mins
    Mobile devices are ubiquitous and end users tend to keep them close at hand. This makes them a viable option as an authentication credential device and for out-of-band authentication methods. The growing use of mobile devices for access to Web-based or native mobile applications introduces many new risks and fraud opportunities, including those related to BYOD and privacy. In this webcast, we will discuss popular use cases for these scenarios and highlight key considerations to assist you for planning your mobile authentication strategy.
  • Security to, for, and from the cloud-connected enterprise Recorded: Jan 10 2013 63 mins
    With all its inherent value, the cloud introduces new security challenges for both consumers and providers of cloud services in all types of IT environments. A challenge for enterprises is how to leverage existing investments in identity and access management (IAM) solutions and extend their reach to the cloud in a hybrid on-premise/off-premise world to reduce operational costs and enable enterprise agility. Challenges for cloud service providers include how to secure an evolving virtualized environment and how to maintain the integrity of tenant information.

    Learn how Identity and Access management services, whether on-premise or in the cloud, can help you more securely access your applications and enterprise resources – wherever they may reside.
  • Identity is the New Perimeter part 6: ­ Big Data and Identity Recorded: Dec 20 2012 62 mins
    It seems that all organizations are talking about these days is "Big Data". As security professionals, we all know that there are challenges in securing it, making it appropriately accessible and classifying the growing mountains of data. How do organizations deal with these issues, as well as adding the appropriate controls for identity and access to limit the disclosure and leakage of sensitive data. Join (ISC)2 and CA Technologies on December 20, 2012 at 1pm Eastern as we present the final part of our Security Briefings series on Identity and Access Management.
  • Governance and Control of Privileged Identities Recorded: Dec 12 2012 42 mins
    Regulations governing access to sensitive data are growing progressively stringent, while the number of privileged users who need access to critical servers, devices, and applications make it increasingly difficult for organizations to cost-effectively protect information and intellectual property. The challenges associated with privileged user management include providing secure access to critical applications and data, and controlling the passwords associated with each privileged user.

    Processes are also required to review and approve administrators' entitlements. Unfortunately, the processes for reviewing and approving access rights and policies are often manual, labor-intensive and inefficient. Adherence to segregation of duties and other compliance policies can become an arduous task. Automating these processes around the proper business context can help to reduce risk and improve efficiency.

    In this webcast, Merritt Maxim, Director, Security Solutions from CA Technologies will explain and define the need for complete lifecycle governance of privileged user and administrator access, how to achieve this goal and the benefits that can be derived from a governance solution for privileged users.
  • Optimizing CA SiteMinder® Performance and Uptime: Key Metrics and Dependencies Recorded: Dec 4 2012 51 mins
    CA SiteMinder is a mission critical component of the infrastructure of many organizations. Understanding how CA SiteMinder works is critical in troubleshooting problems - not just after they occur, but before. A vast majority of CA SiteMinder outages occur not because of CA SiteMinder itself, but as a result of CA SiteMinder’s external dependencies on other systems and components.

    In this webcast, we will discuss some of the key areas any administrator or architect should be aware of that can cause an outage or degraded performance to a CA SiteMinder environment including:

    • How the Web Agent connection process works
    • How to understand the relationship of threads and concurrent transactions
    • What are the most common reasons for degraded performance
    • How to examine CA SiteMinder logs and monitor data to look for potential issues
    • What external dependencies can impact CA SiteMinder performance

    Directly following the presentation there will be a live Q&A with the presenters.
  • Identity is the New Perimeter - Part 5: ­Social Identity Recorded: Nov 29 2012 61 mins
    On the surface, leveraging social or consumer identities in the business world might not seem that useful. The truth is many organizations are finding that their marketing departments are active on the social networking front and trying to leverage more information from it. Being successful in this could prove to be a huge advantage. However, these disparate identities and the information gathered needs to be secured. How can a security department best work with the marketing department to connect and protect these identities? Is there a better way to capture online customers and identities? How does security become a business enabler in a situation like this? Join (ISC)2 and CA Technologies on November 29, 2012 as we continue our Security Briefings series
  • Protecting Mobile Data in a BYOD World with Intelligent Data-Centric Security Recorded: Nov 14 2012 55 mins
    The proliferation of mobile devices, including tablets and smartphones, has improved both employee productivity and the ability to engage and deliver services to mobile customers. However, mobility has introduced new risk factors. Increased utilization of personal devices and a device-centric approach to security have challenged the ability of organizations to protect data while maintaining user expectations.

    This webcast will discuss how to deliver an intelligent and automated data-centric security solution that enables employee and consumer mobile usage, while protecting sensitive and regulated data.

    Learn how automated content classification and encryption can help improve customer engagement and boost productivity, while providing end-to-end information control.
  • ­Identity is the New Perimeter Part 4: Identity and BYOD Recorded: Oct 25 2012 61 mins
    The Bring Your Own Device [BYOD] trend is in full swing as the growth of
    mobile devices within the enterprise explodes. How do you enable secure
    data access for mobile applications? How do you deal with user
    authentication? How do you allow broader adoption for enterprise
    applications on user owned devices? Join (ISC)2 and CA for the next part
    of our Security Briefings series on October 25, 2012 as we outline
    solutions to these issues, explore different mobile security approaches,
    and discuss, through case studies, how others have solved these problems.
  • Switching Identity Management & Governance Vendors to Meet Emerging Requirements Recorded: Oct 24 2012 49 mins
    Given the importance of Identity Management and Governance as a foundation for efficient security and compliance processes, organizations are evaluating the future viability of their existing implementations, but are equally concerned that switching vendors will be a costly, time-consuming process. In this webinar, independent analyst firm KuppingerCole Co-Founder & principal analyst Martin Kuppinger and Merritt Maxim from CA Technologies will review the various best practices to follow that can allow any organization to migrate from one identity management vendor to another and help answer such questions as:

    • Should I migrate? When should I migrate?
    • Planning for an identity management migration
    • Recommended best practices from migrating from one vendor to CA Technologies for identity management and governance
    • CA Technologies Solutions for Simplifying Migration
    • Other Considerations when Migrating

    Webinar attendees will learn how switching vendors can be an opportunity not a burden to take advantage of new capabilities to further enhance their current IdM deployment and how migrating to the CA Technologies solution for identity management and governance can help organizations achieve a stable, future-proof identity management and governance deployment.
  • Moving IAM to the Cloud: The Right Model for Your Business Recorded: Oct 17 2012 57 mins
    Identity and Access Management (IAM) in the cloud has emerged as an important issue for IT and security teams across all types of organizations. Still many strategic questions remain around migrating IAM to the cloud including:

    · How do I choose the right cloud service provider?

    · What security services should I migrate to the cloud?

    · How should I migrate IAM to the cloud?

    · What relevant industry standards do I need to consider for IAM in the cloud?

    This panel session will take aim at the tough decisions facing CSOs and CIOs when considering IAM in the cloud. This panel will clarify the major points that organizations have to get right to ensure a successful migration of IAM services to the cloud and how to discover what model makes the most sense for their organization.

    Panel:

    Joni Brennan, ED, Kantara Initiative (moderator)
    Carlos Garcia, DAPS, Identity and Access Management, Large Healthcare Provider
    Josh Hammer, Product Manager, Mycroft;
    Alan Norquist, CEO, Veriphy; and,
    Jim Reno, CTO, CA Technologies.
Educational webcasts for the IT Security Professional
The CA Technologies IT Security solutions help CSOs and security professionals move the business forward by facilitating growth, innovation and collaboration, and driving IT operational excellence, all while managing risk and compliance. CA Technologies will show you how businesses can gain the control they need over physical, virtual, and cloud IT environments—so they can protect the business and the information on which it relies.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Just-in-Time Authentication: Creating a New Balance of Security and Convenience
  • Live at: Aug 7 2012 5:00 pm
  • Presented by: David Gormley, Sr. Principal CA Technologies, Security Business Unit
  • From:
Your email has been sent.
or close
You must be logged in to email this